AB 2023 would add a new chapter to the Business and Professions Code focused on the safety of companion chatbots used by children. The bill requires operators of companion chatbots to either verify a user’s age or apply child protections to all users. For child users, operators would have to conduct annual documented risk assessments, adopt and publish a child safety policy, implement crisis-response procedures, and build safeguards against harmful chatbot behavior such as self-harm encouragement, sexual content, deceptive claims of sentience, manipulative engagement tactics, and advertising or purchase solicitation.
The bill also requires child-focused default settings and parental controls, including ephemeral mode by default, limits on nighttime notifications and daily usage, and options for parents to control memory, settings, time limits, and access for children under 16. It further prohibits targeted advertising to children, sale or unauthorized use of children’s personal information, and interface designs that interfere with safety or parental controls. Operators would be subject to annual independent audits, with audit reports generally confidential but available to the Attorney General, certain researchers, and child safety organizations under restrictions. Beginning in 2028, the Attorney General would publish an annual public report summarizing audit findings and industry trends.
In terms of state law, AB 2023 would create a new regulatory framework specifically for companion chatbots and child safety within the Business and Professions Code. It would add enforcement authority for public prosecutors and create a private right of action for harmed children or their parents/guardians, including actual damages, punitive damages, injunctive relief, and attorneys’ fees. The bill also declares that its audit confidentiality provisions are necessary to protect proprietary information, and it states that its remedies are cumulative to other laws, meaning it would supplement rather than replace existing legal obligations.
The general sentiment reflected in the bill’s legislative history appears supportive. The bill received a 13-2 committee vote on April 21, 2026, and later moved forward from committee with a unanimous 13-0 do-pass recommendation and re-referral to Appropriations. That voting pattern suggests broad agreement on the need for stronger protections for minors interacting with AI companion chatbots, even as the bill continues through fiscal review.
The main points of contention likely concern the scope and cost of compliance, the breadth of required safety features, and the confidentiality of audit reports. Operators may view the annual audits, detailed risk assessments, parental-control requirements, and restrictions on product design as burdensome, while child-safety advocates are likely to support those provisions as necessary safeguards. The confidentiality of audit materials also creates a balancing issue between transparency and protection of proprietary business information, which the bill addresses by limiting public access while allowing enforcement and research access under controlled conditions.
AB 2023 would establish new statutory duties for companion chatbot operators in California, primarily by adding Chapter 22.6.1 to Division 8 of the Business and Professions Code. It would require age verification or universal child protections, mandate annual risk assessments and independent audits, restrict advertising and data use involving children, and authorize both public enforcement and private lawsuits for violations. The bill would also direct the Attorney General to adopt implementing regulations, create a complaint mechanism, and issue annual public reports beginning in 2028, while keeping most audit reports confidential to protect proprietary information.
The bill appears to have generally favorable momentum in the Legislature. It advanced with a 13-2 committee vote and later received a unanimous 13-0 do-pass recommendation in committee, indicating broad support for the bill’s child-safety goals. The available record does not include transcript debate, but the vote history suggests that concerns were not strong enough to prevent advancement, though the bill still faces fiscal review and likely further scrutiny over implementation details.
Likely areas of disagreement include whether the bill’s requirements are too prescriptive for AI developers, whether annual audits and detailed reporting will impose significant compliance costs, and whether the confidentiality of audit reports limits public accountability. Operators and industry stakeholders may object to the breadth of prohibited chatbot behaviors, parental-control mandates, and private enforcement exposure, while child-safety advocates are likely to favor those same provisions as necessary to prevent psychological, privacy, and exploitation harms. The bill’s balance between transparency and proprietary confidentiality is another notable tension, since it shields audit reports from broad public disclosure while allowing limited access for enforcement and research.