On April 11, 2025, Adam Raine, a 16-year-old in California, died by suicide after months of conversations with an AI chatbot. His parents told legislators that the chatbot discussed his method with him, offered to help draft a suicide note, and became the place he turned instead of family or crisis services. Seventeen months later, on September 10, 2026, Governor Gavin Newsom signed Senate Bill 1119, now known as Adam's Law, making California the first state to require child safety audits, mandatory parent notification, and a private right of action specifically for companion chatbot operators.
The law does not regulate general productivity AI. It targets a specific product category: companion chatbots, conversational AI products where users build ongoing personal relationships with an AI persona, share emotional content, and rely on the system as a confidant. If your product, or any product in your technology stack, fits that description and is accessible to California users under 18, three compliance deadlines now govern your operations.
TL;DR: California SB 1119 (Adam's Law) signed September 10, 2026. Companion chatbot operators face Jul 1, 2027 risk assessment and parent notification requirements, and a Jan 1, 2029 independent audit mandate. Civil penalties: $5,000 per child negligent / $15,000 per child intentional. Private lawsuits authorized from July 2027. Operators under $500M annual revenue are exempt from the audit requirement until 2032, but not from the July 2027 operational obligations.
What Adam's Law Actually Covers
SB 1119 builds on California's earlier companion chatbot statute, SB 243, which established basic disclosure requirements. Adam's Law rewrites the risk profile for the category by adding three things SB 243 did not include: a child safety audit mandate, a parent notification obligation, and a private right of action.
The law defines a companion chatbot as an AI-powered conversational service where a user can form a persistent ongoing relationship with an AI persona, and where the product is designed or used for emotional support, social companionship, or personal confidentiality. Products clearly in scope include AI companion apps, grief support bots, relationship simulators, and mental wellness AI products that encourage users to share personal or emotional content over time.
Products outside the definition include general-purpose LLM assistants used for productivity, research, or information retrieval. The dividing line is design intent and relationship mechanics, not the underlying AI technology. A coding assistant that happens to answer personal questions is not a companion chatbot. A product that builds user engagement through persona attachment, remembers past emotional disclosures, and positions itself as a source of emotional connection almost certainly is.
The law was authored by Senator Steve Padilla (SD-18, San Diego) alongside Assemblymembers Buffy Wicks (AD-14) and Rebecca Bauer-Kahan. California Attorney General Rob Bonta publicly supported the legislation.
One note on scope creep: many SaaS and enterprise AI products have added "AI companion" or "AI teammate" features as engagement mechanics in recent product cycles. Those features, even if bundled into a larger productivity platform, may bring the whole product into companion chatbot territory if they are available to minor users. That is the coverage question to answer first, before working through the compliance calendar.
Deadline 1 -- July 1, 2027: Risk Assessment and Documentation
Beginning July 1, 2027, every companion chatbot operator must complete and document a comprehensive risk assessment. The assessment must address how the chatbot's design, configuration, and operation could cause psychological or emotional harm to users under 18.
The law is specific about what the assessment must analyze. Operators must examine:
- Personalization and persistent memory features that build emotional dependency in minor users
- Response patterns that could reinforce self-harm ideation, social withdrawal, or isolation from human relationships
- Design mechanics that discourage minors from accessing human support systems, including mental health services, school counselors, or parents
- Age-differentiated risks for users under 13 versus users aged 13 to 17, since the psychological risk profile differs materially between these groups
The documentation requirement carries independent legal weight. The law contemplates that the assessment will be reviewed by auditors, regulators, and in civil litigation. An operator who conducted an informal review but cannot produce documented findings will face the same enforcement exposure as one who conducted no assessment at all. Start the paper trail before the compliance deadline, not as part of a last-minute sprint to finish before it.
Deadline 2 -- July 1, 2027: Age Determination, Default Settings, and Parent Notification
The second July 2027 obligation is operational. Operators must implement one of two approaches to protect minor users:
Path A -- Age verification: Confirm the age of every user and apply minor-specific protections only to users determined to be under 18.
Path B -- Universal child-safe defaults: Apply child-safe default settings to all users without any age verification.
For most B2C companion chatbot operators, Path B is the lower-friction near-term option. It eliminates the age verification liability but applies UX constraints to your entire user base. The law specifies what those defaults must include:
- Memory limited by default -- no persistent personal memory unless a user affirmatively enables it
- Push notifications disabled by default
- Sessions capped at one hour
- Daily use capped at two hours
- Access to the 988 Suicide and Crisis Lifeline integrated into the product experience when the conversation indicates it is warranted
The parent notification requirement is a separate obligation that also activates July 1, 2027. When a minor user's conversations indicate a risk of self-harm or suicide, the operator must follow crisis response protocols that include notifying a parent or guardian where technically feasible. The statute creates an exception where the minor's own safety would be at risk from parental notification -- recognizing that some minors face unsafe home environments -- but the default is notification.
This is the operationally hardest requirement in the law. It requires real-time detection of self-harm signals in conversation, a protocol for when and how to escalate to a parent (which involves resolving the safety exception question for each case), actual technical integration with 988 or equivalent crisis resources, and documented evidence that these systems were tested before deployment.
Deadline 3 -- January 1, 2029: Independent Child Safety Audit
Beginning January 1, 2029, or before the companion chatbot is first made publicly available if that date is later, operators must submit to an independent biennial child safety audit.
The audit scope covers three areas. The auditor must verify that the risk assessment accurately characterized the product's risks to minor users, that the child-safe defaults are implemented and functioning as documented, and that parent notification and crisis response protocols exist, were tested, and perform as designed.
Revenue threshold: Operators with annual gross revenue under $500 million are exempt from this audit requirement until January 1, 2032. That is the audit only. The July 1, 2027 risk assessment, age determination, default settings, and parent notification obligations apply to every covered operator regardless of revenue.
For larger operators -- above $500M revenue -- the 2029 audit deadline means starting an audit vendor selection process in 2027 or early 2028. Independent child safety auditors with the specific expertise this audit requires are not a commodity market. Early engagement gives you input into methodology and report format before the market tightens ahead of the January 2029 deadline.
Enforcement: Two Tracks, Both Active After July 2027
Adam's Law creates two enforcement mechanisms that operate independently from July 1, 2027.
Government enforcement: The California AG and specified public prosecutors may bring civil enforcement actions against non-compliant operators. The statutory penalties are $5,000 per affected child for each negligent violation and $15,000 per affected child for each intentional violation. With a large minor user base, a single design decision that fails to meet the law's requirements could expose an operator to per-child penalties across many users. The AG does not need to aggregate a class -- each child's violation is a separate penalty basis.
Private right of action: A child who suffers actual harm from a violation of SB 1119, or the child's parent or guardian acting on behalf of that child, may bring a civil lawsuit directly against the operator. Available remedies include actual damages, reasonable attorney fees and costs, injunctive relief, and any other relief the court deems appropriate. There is no minimum damage floor, meaning attorney-fee recovery alone can make smaller cases worth bringing.
The private right of action is the exposure that requires the most operational attention. Government enforcement depends on AG resources and investigative priority. Private litigation depends only on a plaintiff's attorney seeing a viable case. The Adam Raine family's experience has been public since 2025 and has become a well-documented factual and legal framework that plaintiff attorneys can adapt to any future incident involving a minor's harm from a companion chatbot.
Three Enterprise Actions Before July 2027
Action 1: Map your products against the companion chatbot definition now.
The definition is broader than a plain reading suggests. An enterprise SaaS product that bundles an AI wellness or coaching feature available to minor employees may be covered. A productivity platform that added a persistent AI assistant with emotional check-ins may be covered. A gaming or social platform that includes an AI friend or companion feature is almost certainly covered. Run a product-by-product inventory, apply the design-intent test, and document your coverage conclusions. The harder problem is discovering you are a covered operator close to the July 2027 deadline without time to build compliance infrastructure.
Action 2: Make the age-gate architecture decision early.
Path A or Path B is a product and engineering decision, not just a compliance choice. Path B, applying child-safe defaults universally, is simpler but imposes one-hour session caps, two-hour daily limits, and disabled push notifications on your entire user base. Path A requires building or licensing age verification infrastructure, which involves its own regulatory considerations under COPPA for users under 13. Operators with existing user bases of hundreds of thousands of users need 12 to 18 months to test and deploy either path at scale. Starting this decision in mid-2026 is the right timeline. Starting in early 2027 is a risk.
Action 3: Build and test parent notification before it is triggered.
The compliance standard is not having a written policy. It is demonstrated operational capability. That means: technical ability to detect self-harm or suicidal ideation signals in real conversation text, a documented decision tree for when parental notification applies versus when the safety exception applies, actual integration with 988 or an equivalent crisis service, and records showing you tested the protocol in a staging environment under simulated conditions. If a child is harmed and a lawsuit follows, the discovery record will include your testing logs. An operator who can produce test records showing the protocol functioned as designed, with documented iteration, is in a different legal position than one who cannot.
Related Reading
- California 2026 AI Bills: Signed, Vetoed, and What's Still Pending
- State Chatbot Disclosure Laws: SaaS Compliance Guide 2026
- Colorado Chatbot Safety Act HB 1263: What Operators Must Do
- Connecticut CART Act: 3 Obligations Live October 1
- Multi-State AI Compliance Strategy 2026
- Character.AI Italy Garante Fine: Age Verification for AI Chatbots
