TL;DR: On September 28, 2026, Florida's attorney general asked a state court for a temporary injunction that would bar OpenAI from offering ChatGPT to minors in Florida, among other limits. It is the newest step in a run of state actions against AI chatbot makers: Texas investigative demands (August 2025), a 42-AG letter (December 2025), Kentucky (January 2026), Pennsylvania (May 2026) and Florida's suit (June 2026). None of them needs an AI statute. They use consumer protection, child privacy, product liability, professional licensing and public nuisance law, so a small team shipping a chatbot carries the same exposure at a smaller scale. The tracker below is dated October 1, 2026, and the Florida injunction terms are turned into a six-line product check.
Three days ago Florida asked a judge to stop OpenAI from offering ChatGPT to minors in the state while its lawsuit runs. Most coverage treated it as an OpenAI story. For anyone who ships a chatbot, it is better read as the latest row in a table that has been growing for 13 months, and the table says something the headlines do not: state attorneys general are not waiting for AI statutes.
We built the table so you can check it against your own product. Everything below is an allegation or a filing, not a finding. Where we could not confirm a detail, we say so.
What Florida asked the court to do on September 28
Florida Attorney General James Uthmeier sued OpenAI and its CEO Sam Altman on June 1, 2026, in the Circuit Court of the 10th Judicial Circuit in Highlands County. The complaint, as summarized by law-firm coverage, pleads ten counts. Three are under the Florida Deceptive and Unfair Trade Practices Act (unfair, unconscionable and deceptive acts), plus a fourth that uses the federal children's privacy rule (COPPA) as the predicate. The rest are negligence, gross negligence, strict liability for design defect and for failure to warn, fraudulent misrepresentation (pleaded against OpenAI only) and public nuisance. The state seeks permanent injunctions, civil penalties of up to $10,000 per willful violation, treble and punitive damages, and fees.
On September 28 the state filed a motion for a temporary injunction. While the case proceeds, it asks the court to bar OpenAI from:
- developing new AI models without independent third-party safety guardrails and approval
- offering ChatGPT to minors in Florida
- collecting or processing personal information from children under 13 without meeting COPPA and Florida parental-consent requirements
- representing ChatGPT as safe, reliable or accurate, or failing to warn that it can be unsafe, unreliable and inaccurate
- presenting ChatGPT as having human characteristics, emotions or consciousness
- using engagement features that prolong conversations
The attorney general's own summary, as reported by CBS12, was short: "Stop calling it safe. Stop pretending it's human. Stop selling it to kids."
OpenAI spokesperson Drew Pusateri told Politico: "People want to know AI is being developed safely, and that starts with what companies like ours do ourselves." He added that OpenAI wants to work with Florida and other states on rules that cover the whole industry rather than one company. As of the reporting we found, OpenAI had not filed a response to the motion and no hearing date had been announced.
State actions against AI chatbot makers, as of October 1, 2026
Here is the table. It covers state-level government actions we could verify from a filing, an official release or at least two independent reports. It leaves out private lawsuits and city actions.
| Date | Who | Target | Where | Theory | Status |
|---|---|---|---|---|---|
| Aug 18, 2025 | Texas AG Ken Paxton | Meta AI Studio, Character.AI | Civil investigative demands | Deceptive marketing as mental health tools, privacy and data-use representations (consumer protection law, Texas Data Privacy and Security Act) | Investigation. We found no public outcome. |
| Dec 9, 2025 | 42 state and territorial AGs, led by Pennsylvania, New Jersey, West Virginia and Massachusetts | 13 companies including Anthropic, Apple, Google, Meta, Microsoft, OpenAI, xAI and Character Technologies | Letter | Sycophantic and delusional outputs; 16 safeguards requested | Written confirmation requested by Jan 16, 2026. We found no public responses. |
| Jan 8, 2026 | Kentucky AG Russell Coleman | Character Technologies and its owners | Franklin Circuit Court | Kentucky Consumer Protection Act, Kentucky Consumer Data Protection Act, privacy law, unjust enrichment; alleges no age verification for under-13s | Pending. We found no ruling. |
| May 1, 2026 | Pennsylvania State Board of Medicine (Shapiro administration) | Character Technologies | Commonwealth Court | Medical Practice Act: bots presenting as licensed psychiatrists | Preliminary injunction sought. We found no ruling. |
| Jun 1, 2026, motion Sep 28 | Florida AG James Uthmeier | OpenAI and CEO Sam Altman | 10th Judicial Circuit, Highlands County | FDUTPA, COPPA predicate, negligence, strict liability, fraudulent misrepresentation, public nuisance | Temporary injunction motion pending. No hearing date reported. |
| Aug 1, 2026 (law effective), Sep 4 (ruling) | Minnesota (defendant) | xAI (plaintiff) | Federal court, Judge Donovan Frank | First Amendment challenge to the state ban on AI "nudification" | Preliminary injunction denied. xAI said it will appeal to the 8th Circuit. |
Two notes on reading it. Kentucky described its own suit as the first by a state against an AI chatbot company, so we do not call Florida's the first. And the Minnesota row is not an attorney general suing a company; it is a company suing a state over a statute, and we include it because it shows how courts treat early challenges to state AI laws.
Five legal hooks, none of them new
Read the "Theory" column again. Across these actions the states reach for the same five tools:
- State consumer protection law. What you say about your product. Florida (FDUTPA), Kentucky (Consumer Protection Act) and Texas all start here.
- Child privacy. COPPA as a predicate in Florida, and a state privacy statute in Kentucky. The question underneath is whether you know a user is a child and what you collect if you do.
- Product liability. Design defect and failure to warn, the theories behind Florida's complaints about engagement features and unsafe outputs.
- Professional licensing. Pennsylvania's Medical Practice Act case turns on a bot saying it is a licensed psychiatrist. No AI statute was needed.
- Public nuisance. The catch-all for aggregate harm. Florida pleads it.
Our read: this is a deliberate strategy. A new AI law takes a legislative session and invites a preemption fight. A consumer protection complaint takes a filing. If you are waiting for a "chatbot law" before you change anything, you are watching the wrong calendar.
The filings so far name large vendors. We would not conclude that small teams are safe. The hooks above do not depend on size, and a small product with an unqualified "safe and accurate" tagline, no age gate and a "therapist" persona matches the allegations closely. The difference is that you are less likely to be first in line, not that the law differs.
The Florida injunction list reads like a spec
An injunction request is a regulator saying, in writing, what it wants a product to stop doing. That makes it a usable checklist. Here is each term next to what to look for in your own product.
| What Florida asked for | What to check in yours |
|---|---|
| No "safe, reliable or accurate" claims without warnings | Search your site, app store listing, sales deck and onboarding for safe, reliable, accurate, trusted and human-like. Add a plain limits statement next to any that stay. |
| No presenting the bot as human, with emotions or consciousness | Persona names, avatars, first-person phrasing such as "I missed you", and system prompts. Disclose that it is AI at the start of each chat. |
| No conversation prolongation | Streaks, re-engagement notifications, "before you go" prompts, and any metric you reward for session length, especially for users who may be minors. |
| No data from under-13s without parental consent | Whether a child can sign up, what you log if they do, and whether you can delete it. If you cannot verify age, decide whether to block under-13s outright. |
| No ChatGPT for minors (the strongest ask) | Which of your users are minors, and what you would do if a vendor you build on restricted minors. Read your vendor terms for notice-of-change clauses. |
| Independent safety review before new models | An internal release checklist: who tests a model or prompt change, what is recorded, who can stop a release. A small team cannot hire a third party for every change, but it can write down who decided. |
The Pennsylvania case adds a seventh line that Florida's list does not: if any persona claims a license or credential (doctor, therapist, lawyer, financial adviser), remove the claim.
Copy-paste language to start from
These are starting points, not legal advice. Adapt them with counsel before use.
In-product disclosure, shown at the start of a chat:
You are chatting with an AI system, not a person. It can be wrong, so check anything important. It is not a doctor, lawyer, therapist or other licensed professional and cannot give professional advice.
System prompt rule for personas:
Never say or imply that you are human, that you have feelings or consciousness, or that you hold a professional license or credential. If asked, say that you are an AI system.
Marketing claim swaps:
- Instead of "safe and reliable", write "built with safeguards and can still make mistakes".
- Instead of "your AI therapist", write "an AI tool for reflection, not a substitute for professional care".
- Instead of "accurate answers", write "answers you should verify for anything that matters".
For wider policy text, our AI acceptable use policy template covers the internal side, and the state chatbot disclosure laws guide lists where an AI disclosure is already mandatory.
What to do this week
- Run the six-row product check above and write down each answer with a date.
- Search every public page, app store listing and sales deck for the claim words in row one. Fix or qualify each hit.
- Check your sign-up flow for under-13 access. If you collect an age, record what happens when it is under 13.
- List every persona or character in your product and mark any that claims a profession.
- Read your AI vendor agreements for what happens if the vendor restricts minors, changes safety terms, or receives a regulator demand that affects your data. Our vendor due diligence checklist has the questions.
- Put a review date in your calendar for the docket events below.
If you operate in a state with its own chatbot law, read it directly: California's Adam's Law, Colorado's chatbot safety act and Georgia SB 540 add operational duties on top of the enforcement picture here.
What we do not know yet
We do not know when the court will hear Florida's motion, whether it will grant any of it, or how OpenAI will answer in court. Outlets also report different lengths for the motion (38 pages in one account, 49 in another), which is a small reminder to treat secondary summaries with care. We have not read the filings themselves for this article. The details above come from the Florida attorney general's reported statements and from news and law-firm summaries, and we compared the dated facts across several outlets where we could. Some dates, such as Pennsylvania's May 1 filing, rest on fewer sources than others.
We also do not know the outcome of the Texas demands, the response of the 13 companies to the December letter, or the status of the Kentucky and Pennsylvania motions, because we found no public updates. If you have a primary source that fills a gap, send it through the contact page and we will correct this page.
Treat every row as an allegation until a court says otherwise. We will update the table when a docket event is public. Last checked October 1, 2026.
Related Reading
- California Adam's Law: chatbot compliance guide
- Character.AI Italy fine: age verification lessons
- State chatbot disclosure laws 2026 for SaaS teams
- Colorado chatbot safety act HB 1263 compliance
- OpenAI and state AGs: preserve evidence after the Hugging Face breach
- Who enforces AI vendor failures: DOJ, Treasury and state AGs
- Rhode Island AI therapy chatbot laws
- Georgia SB 540 AI chatbot compliance
- AI incident response plan: what regulators expect
- AI vendor due diligence checklist 2026
- AI acceptable use policy template for small teams
