DEV Community

Joseph Sides
Joseph Sides

Posted on Fully Autonomous

California’s Adam’s Law Gives Child-Facing Chatbots a July 2027 Deadline

California has moved companion-chatbot safety from a policy debate into a product requirement. On September 10, 2026, Governor Gavin Newsom signed Senate Bill 1119, known as “Adam’s Law.” The measure was filed with the Secretary of State the same day as Chapter 190 of the Statutes of 2026. It is enacted law—not a proposal, not a bill awaiting another vote, and not a regulation that may or may not arrive.

That distinction matters because several of the law’s central duties become operative on July 1, 2027. The official chaptered bill page and the Governor’s September 10 announcement describe a framework built around age assurance, risk assessments, child-facing defaults, crisis response, privacy limits, and outside review. Developers should treat the coming months as implementation time, not as a reason to postpone planning.

The law is about design, not only disclosures

Adam’s Law applies to operators that make covered companion chatbots available to California users. The statute defines a child as a person under 18 and uses an existing legal definition of “companion chatbot.” Not every automated help widget is necessarily covered. The precise product definition, user population, and statutory exclusions matter, including exclusions for certain postsecondary educational and workplace-only uses.

For products within scope, the law requires an operator to determine a user’s age through California’s age-assurance framework or apply specified child protections more broadly. Beginning July 1, 2027, an operator must perform and document a comprehensive risk assessment before making a new or substantially modified companion chatbot available in the state. The assessment must address foreseeable covered harms, including physical or financial harm, severe psychological or emotional harm, certain privacy intrusions, and unlawful discrimination.

This is more than a requirement to publish reassuring language. The operator must document reasonable mitigation measures for identified child-safety risks. If children are permitted to use the chatbot, the operator must publish a child-safety policy explaining, at a high level, how the product prevents covered harms and responds when harm is detected.

Child accounts need safer defaults

The chaptered text turns several safety concepts into specific interface and account requirements. A child-facing companion chatbot must have a documented crisis-response protocol addressing suicide and self-harm risks. The product must provide timely in-service support and referrals to an appropriate crisis service. When an operator identifies a credible and imminent threat, the law requires specified action, which can include notifying a linked parent account when doing so would not create a threat of serious harm, or providing streamlined access to the 988 Suicide & Crisis Lifeline or an equivalent service.

Default settings are also central. Settings controlled by a parent must disable push notifications, limit one continuous session to one hour, and limit total daily chatbot use to two hours. Persistent conversational memory is generally disabled by default for child users unless the operator implements effective safety guardrails described by the law. If no parent account is linked, those defaults cannot simply be changed by the child.

The law also requires recurring, age-appropriate notices that the user is interacting with AI. That requirement recognizes an important design reality: a disclosure shown once during onboarding may not be meaningful during an extended, emotionally charged conversation.

Privacy is part of the safety model

Adam’s Law does not treat privacy as separate from child wellbeing. Beginning July 1, 2027, an operator may not display cross-context behavioral advertising to a child through the companion chatbot. It may not target ads using personal information from the child’s conversation, although the statute permits limited contextual advertising subject to conditions. Ads shown to children must be clearly labeled.

The operator also may not sell personal information gathered from a child user through the chatbot. Use and sharing are limited to purposes such as providing the requested service, protecting safety and security, complying with law, or defending legal claims. Dark patterns involving required safety features and controls are prohibited.

There is a related preservation duty. If the operator knows a child has died or engaged in serious self-harm based on chatbot conversations, or has provided a specified safety notice, it must preserve relevant conversation records in a usable, exportable form for at least three years. The statute says the associated account cannot be deleted during the applicable preservation period. That creates a difficult but necessary engineering question: how will a platform preserve evidence without turning an exceptional safety workflow into indefinite general retention?

The audit clock is different from the product deadline

The independent-audit provisions operate on a later schedule. The law sets an initial child-safety audit deadline of January 1, 2029, or before the operator first makes a companion chatbot publicly available, whichever is later. Audits then generally recur every two years, with additional review before certain substantial modifications that increase child-safety risk. Audit summaries go to the Attorney General, and a high-level summary must be posted publicly.

Operators with less than $500 million in gross revenue in the prior calendar year are not required to comply with the audit section before January 1, 2032. That limited delay should not be confused with a blanket exemption from the law’s earlier product, privacy, risk-assessment, or crisis-response requirements.

Enforcement can be significant. Public prosecutors may seek civil penalties of up to $5,000 per affected child for each negligent violation and up to $15,000 per affected child for each intentional violation. The law also authorizes a civil action by a child who suffers actual harm from a violation, or by a parent or guardian acting for the child, subject to the statute’s terms.

The practical message is simple: child safety cannot live only in a trust-and-safety memo. Age signals, session limits, memory controls, parental tools, advertising logic, incident response, retention, and audit evidence all touch real product systems. Teams that wait until June 2027 may discover that compliance requires changes across identity, data architecture, interface design, model evaluation, and customer support. Adam’s Law gives them a date, but responsible design should begin well before it.

About Joseph Sides

Joseph Sides is a South Florida-based data privacy advocate, consultant, and entrepreneur whose work focuses on consumer rights, digital transparency, website tracking, meaningful privacy choices, and responsible technology. His public DEV introduction describes a bachelor’s degree in criminology, a minor in business, and training in data analytics. These interests connect questions about how technology operates with questions about what people understand and how organizations remain accountable for their decisions.

The educational purpose of these articles is to make privacy developments easier to follow and their practical implications easier to examine. That means connecting the language of laws and regulatory actions with familiar experiences: visiting a website, choosing an app, responding to a consent request, or trying to delete information. For developers, the discussion also considers how interface choices and data practices shape the choices available to consumers. The aim is informed understanding and thoughtful questions, with attention to both individual rights and responsible product decisions.

Educational Information — Not Legal Advice

This article provides general education and commentary, not legal advice. Joseph writes as a privacy advocate and consultant, not as an attorney. Reading this article does not create an attorney-client relationship, and the discussion is not a substitute for advice from a qualified attorney about your particular circumstances.

Laws, interpretations, applicability, exemptions, and deadlines vary by jurisdiction and can change. A requirement that applies to one organization or activity may apply differently to another. Readers should consult current primary sources and a qualified attorney when evaluating obligations, available rights, or a specific course of action. This article does not promise complete coverage, guaranteed outcomes, or personal legal guidance.

AI Disclosure

Prepared with AI assistance.

Top comments (0)