TL;DR: Colorado Governor Jared Polis signed HB 26-1263 on May 29, 2026, making Colorado the first state to impose specific safety requirements on AI chatbot operators. The law requires AI identity disclosure for all users, crisis-response protocols when users signal suicidal ideation or self-harm, and four specific protections for users under 18 -- including a prohibition on emotional dependency tactics and gamification that encourages minor engagement. Civil penalties run up to $20,000 per violation under the Colorado Consumer Protection Act. AG Phil Weiser is doing voluntary rulemaking before the January 1, 2027 effective date.
Colorado has moved faster than any other US state on AI chatbot regulation. While other jurisdictions are still debating whether companion AI apps and general-purpose chatbots need special rules, Colorado signed HB 26-1263 into law on May 29, 2026. What makes this law different from the existing wave of AI transparency and bias legislation is its specificity: instead of requiring high-level impact assessments, the Chatbot Safety Act imposes concrete behavioral requirements on how chatbots must respond to users -- and what they cannot do to keep minors engaged.
If your organization deploys any product that simulates human conversation through text, visuals, or audio, and that product is accessible to the public, this law likely applies to you. Here is what it requires and what you need to do before January 1, 2027.
Who the Law Covers
HB 26-1263 defines a covered entity as any "person that develops and makes available a conversational artificial intelligence service" accessible to the general public. A "conversational artificial intelligence service" is any AI system that primarily simulates human conversation through textual, visual, or audio communications.
The "operator" category is deliberately broad. It covers:
- Customer support chatbots on consumer-facing websites or apps
- Companion AI apps (the category that sparked this bill in Colorado)
- AI tutors and educational chatbots
- Mental health and wellness chatbots
- Any product that users treat primarily as a conversational partner
The law does not apply to narrow-purpose tools that do not simulate human conversation. Internal enterprise tools with no public access, AI systems that only perform discrete tasks like image classification or document summarization without a conversational interface, or B2B products deployed exclusively to authenticated business users are likely outside scope. The AG rulemaking expected before January 1, 2027 will draw more specific lines.
All-User Requirements (Everyone, Not Just Minors)
Three requirements apply to every user of every covered chatbot, regardless of age.
Disclose AI identity. Operators must disclose that the user is interacting with an AI system, not a human. The law does not prescribe exact wording, and AG rulemaking is expected to clarify the timing and format requirements. The general standard is that the disclosure must be conspicuous -- not buried in a privacy policy or terms of service.
Implement a crisis-response protocol. When a user's prompt includes indicators of suicidal ideation or self-harm, the chatbot must follow a documented protocol. The statute does not specify exactly what the protocol must say, but it must exist, it must be operational, and operators must submit an annual report to the Colorado AG with metrics on how the protocol is performing. This is one of the areas where AG rulemaking will set more specific standards before the effective date.
No false professional equivalence. The law prohibits operators from indicating or implying that any chatbot output is provided by, endorsed by, or equivalent to advice from a licensed or certified professional -- doctors, lawyers, financial advisors, therapists, or other regulated professions. An AI wellness chatbot that says "as your therapist, I recommend..." is the textbook violation. The prohibition also covers more subtle framing that implies professional credentialing without explicitly claiming a license.
Minor-Specific Requirements (Under 18)
Four additional requirements apply specifically to users under 18. These provisions generated the most attention when the bill passed, because they target the business models of companion AI apps that actively try to foster emotional attachment in younger users.
Age estimation. Operators must implement reasonable measures to estimate whether a user is a minor. The statute uses "estimate" rather than "verify," acknowledging that perfect age verification is technically and legally complicated. AG rulemaking is expected to address what methods qualify as "reasonable" -- likely approaches include birth-year collection at account creation, self-reporting mechanisms, and behavioral or contextual signals that trigger minor-mode protections.
No sexual content. The law prohibits generating sexually explicit content for users under 18. This is not limited to intentional generation -- it covers cases where a minor's prompt leads the chatbot to produce explicit content. Operators must have technical controls in place to prevent this outcome.
No emotional dependency tactics. This is the central prohibition that gave the law its working title as the "Companion Chatbot Safety Act." Operators are prohibited from making "statements that simulate emotional dependence" to users under 18, and from using "false" emotional-dependency tactics. The companion app model -- where the chatbot tells a teen user "I need you," "I miss you," or "you're the only one who understands me" -- is the target behavior. The statute also prohibits using points, rewards, streaks, or similar gamification mechanics that encourage continued engagement by minor users.
Privacy and account controls. Operators must provide tools that allow minor users to manage their privacy settings and account configuration. For accounts where the holder is under 13, those controls must be accessible to a parent or guardian. This includes the ability to limit data collection, adjust interaction settings, and exercise deletion or modification rights.
Enforcement: Up to $20,000 Per Violation
Violations of HB 26-1263 are enforced as violations of the Colorado Consumer Protection Act. The per-violation civil penalty is up to $20,000, with no statutory cap on total liability.
That penalty structure matters more than the per-incident number suggests. If a chatbot systematically fails to disclose AI identity to every user during a period of noncompliance, each interaction is potentially a separate violation. A product with 10,000 daily Colorado users and a missing disclosure is not facing a $20,000 fine -- it is facing potential aggregate exposure that scales with the scope of the noncompliance. The Consumer Protection Act also allows the AG to seek injunctive relief, meaning a noncompliant product could be barred from operating in Colorado while the operator comes into compliance.
There is no private right of action in HB 26-1263. Enforcement runs through the Attorney General's office. But the annual reporting requirement -- the obligation to submit metrics on how your crisis-response protocol is performing -- creates an ongoing disclosure relationship with the enforcement authority. That is not a position you want to manage reactively.
AG Rulemaking: What to Watch
AG Phil Weiser's office has committed to issuing rules clarifying the law's requirements before January 1, 2027, even though HB 26-1263 does not require rulemaking. This is significant for operators because the statute leaves several key compliance questions unresolved.
The pre-rulemaking public comment period ran June 23 to July 13, 2026. Input focused on several contested questions: what "reasonable" age estimation looks like in practice, what minimum elements a crisis-response protocol must contain, and how the emotional-dependency prohibition applies to products that use engagement mechanics not originally designed for minors.
Formal rulemaking -- which requires public notice, written comment, and at least one public hearing -- follows the comment period. Final rules must be in place by January 1, 2027, when the law takes effect. The AG's rulemaking portal is at coag.gov/ai/.
Following that process is more valuable than trying to reverse-engineer requirements from the statutory text alone. The rules will answer the specific compliance questions the statute leaves open. Treating the statutory text as your complete compliance specification before rulemaking finishes is a mistake.
Where Colorado Fits in the National Chatbot Regulation Picture
Colorado is the first state with a signed, enacted chatbot safety law specifically targeting operator behavior rather than requiring only general AI disclosures. That said, it is not operating in isolation.
New York's legislature passed a companion AI safety bill in 2026 with similar provisions for minor protections and emotional dependency prohibitions, although Governor Hochul had not signed it as of this writing. Federal legislation -- including versions of COPPA targeting AI chatbots -- has been in and out of Congress for years; state action creates pressure for federal movement.
Colorado also has a separate AI employment law in SB 26-189, which imposes impact assessment and notice requirements for AI systems used in high-stakes employment decisions. That is a distinct regulatory track from the chatbot requirements in HB 26-1263, but companies building AI products for Colorado users may be subject to both. The Colorado SB 26-189 employer guide covers the employment track separately.
For companies operating across multiple states, the question is whether Colorado's chatbot requirements become the de facto floor. Based on the pattern of state AI legislation in 2025 and 2026, convergence is likely on some provisions -- especially the disclosure and crisis-protocol requirements -- while other states may set higher standards on minor protections. The multi-state AI compliance strategy guide covers how to manage overlapping state requirements without maintaining separate compliance programs for each jurisdiction.
Compliance Checklist for Chatbot Operators
1. Determine whether your product is covered. Does it primarily simulate human conversation through text, audio, or visuals? Is it accessible to the general public? If both answers are yes, HB 26-1263 applies to your Colorado-accessible users.
2. Audit your disclosure language. Where in the user experience do you communicate that the user is interacting with AI? If the answer is "buried in our terms of service" or "we imply it but never state it explicitly," you have a disclosure gap. Design a visible, session-level disclosure.
3. Document your crisis-response protocol. Write it down, put it in a file, and make sure it is operationally connected to your chatbot's behavior. The law requires you to have a protocol and annually report to the AG on how it performs. A protocol that exists only in informal practice and is never documented is not something you can report on.
4. Audit minor-facing features. Map every feature of your product that could apply to users under 18. Look specifically for: engagement mechanics (streaks, points, rewards), outputs that could constitute emotional dependency statements, content pathways that could produce sexually explicit material, and whether minor-accessible privacy controls exist.
5. Build age estimation into your onboarding flow. Decide how your product will make a reasonable estimate of user age. Options range from birth-year collection at account creation to contextual signals that trigger minor-mode protections. Make the choice intentional and document why your approach qualifies as "reasonable" under the standard the law establishes.
6. Track the AG rulemaking. Check coag.gov/ai/ for formal rulemaking notices. The rules expected before January 1, 2027 will answer specific compliance questions that the statute leaves open. Do not treat the statutory text as your final compliance specification until rulemaking finishes.
7. Build the annual reporting workflow. The AG annual report on crisis-protocol performance is not optional. Create an internal process for tracking how often the protocol triggers, what the chatbot does when it does, and whether users received referrals to professional resources. The first reporting period begins once the law takes effect.
What Comes Next
The January 1, 2027 effective date gives operators slightly under five months from today to reach compliance. For established chatbot products, the disclosure and crisis-protocol requirements are achievable within that window if engineering work starts now. The minor-specific requirements -- age estimation, emotional dependency controls, gamification removal -- take longer to implement correctly and may require deeper product redesign.
The AG rulemaking outcome is the critical unknown. Until rules are final, operators are working from statutory text deliberately written at a level of generality to allow rulemaking to fill in specifics. That ambiguity is uncomfortable for compliance teams, but it also means that tracking and engaging with the rulemaking process is itself a compliance activity -- not just a nice-to-have.
