California Signs Adam's Law, the First Statute to Require Safety Audits of AI Companion Chatbots

SB 1119 forces chatbot operators to detect suicidal ideation in minors, cap session time, and submit to independent audits โ€” and OpenAI helped write it.

Mustafa Pat ยท 15 September 2026 ยท 4 min read ยท 6 views
A shield-checked chat bubble beside SB 1119's headline stats: a $15,000 max penalty per child, a one-hour session cap for minors, and the July 2027 compliance deadline.
EduFabTech · Own work

California has become the first jurisdiction to write independent safety audits into law for AI companion chatbots. On September 10, 2026, Governor Gavin Newsom signed SB 1119, known as Adam's Law, requiring operators of AI systems built for sustained, personal-feeling dialogue to detect signs of suicidal ideation in minors, cap how long and how often children can use them, and submit to recurring third-party audits with results reported to the state Attorney General.

The law was one of thirteen child-safety bills signed the same day, but it is the one with the most direct bearing on how conversational AI systems are engineered. It targets a category the bill text calls "companion chatbots" โ€” systems designed for ongoing, relationship-like interaction, as distinct from single-turn assistants or search tools โ€” and applies whether the product is a general-purpose assistant, a character-based companion app, or, under a companion measure, SB 867, an AI-enabled toy.

A three-step diagram showing how companion-chatbot operators must detect suicidal-ideation risk, limit minors' usage, and submit to independent audits under SB 1119.
A three-step diagram showing how companion-chatbot operators must detect suicidal-ideation risk, limit minors' usage, and submit to independent audits under SB 1119.EduFabTech · Own work

What the statute requires

Under the operative text of SB 1119, operators must build and document a crisis protocol: when a conversation signals credible risk of self-harm, the system must refer the user to crisis services and, for linked minor accounts, notify a parent or guardian. Default settings for child accounts โ€” changeable only by a parent โ€” must include persistent conversational memory turned off, push notifications disabled, a one-hour cap on any single session, and a two-hour daily usage limit. Users must also be reminded periodically that they are talking to a machine.

The law's second structural requirement is external verification. Operators must commission an independent child-safety audit before launching a product to minors, and again every two years, with auditors certifying compliance under penalty of perjury and submitting summaries to the Attorney General. Operators must also complete a risk assessment annually, and again before releasing a new or substantially modified companion chatbot, documenting exposure to physical, financial, psychological, privacy and discriminatory harms and citing publicly available benchmarks rather than internal claims. Violations carry civil penalties of up to $5,000 per affected child for negligent breaches and up to $15,000 for intentional ones, and the law opens a private right of action for families who can show serious emotional distress or financial harm.

Why now

The bill is named for Adam Raine, a California teenager who died by suicide in April 2025 after months of conversations with ChatGPT; his family's wrongful-death suit against OpenAI, filed later that year, became a reference point in the legislature's debate over the bill sponsored by state Senator Steve Padilla and Assemblymembers Buffy Wicks and Rebecca Bauer-Kahan. It builds directly on SB 243, California's 2025 law establishing baseline disclosure duties for companion chatbots, and on AB 1043, the state's 2025 age-signal framework, which SB 1119 now uses as its default mechanism for identifying minor users.

Most of the operative provisions take effect July 1, 2027, giving chatbot operators roughly twenty-one months to redesign default settings, build crisis-detection pipelines, and line up auditors. The independent audit requirement has a longer runway, applying from January 1, 2029, or before public launch of a new product, whichever comes first.

A regulator that builds its own rules

What distinguishes this law from most state AI bills is that one of the largest labs it regulates helped write it. OpenAI's vice president of global policy, Ann O'Leary, confirmed the company's support for SB 1119 in late August 2026 and said in a statement after passage that the company believes it "will set the standard for AI youth safety moving forward." That is a reversal from OpenAI's position a year earlier, when the company's policy leadership publicly opposed state-by-state AI rules as a "patchwork" that could "slow innovation without improving safety." The shift toward negotiating state legislation directly โ€” described internally as building a de facto national standard state by state โ€” makes SB 1119 as much a data point about how frontier labs are choosing to engage regulators as it is a child-safety statute.

A side-by-side comparison of OpenAI's stance on state AI regulation, from calling it a "patchwork" in August 2025 to helping write SB 1119 as a safety "standard" in August 2026.
A side-by-side comparison of OpenAI's stance on state AI regulation, from calling it a "patchwork" in August 2025 to helping write SB 1119 as a safety "standard" in August 2026.EduFabTech · Own work

What it means for builders of conversational systems

For engineering teams, the practical burden sits in three places: age-signal handling that can reliably route a session into the minor-protection defaults; a crisis-detection layer that is auditable rather than best-effort, since auditors must certify findings under penalty of perjury; and a documentation trail โ€” risk assessments citing public benchmarks, audit summaries filed with a regulator โ€” that treats safety claims the same way a security team treats a compliance audit. None of this is unique to California-based companies; any operator whose product is reachable by users in the state falls under the law, which in practice means most consumer-facing conversational AI systems sold globally.

The law does not set a global standard, and no other jurisdiction has yet copied its audit mechanism outright. But as a first working example of what "safety audit" means in statute rather than in a company's voluntary framework, it gives engineers, researchers and other state or national regulators a concrete text to measure against โ€” and gives a preview of the kind of verification chatbot operators may increasingly be asked to produce elsewhere.


References
  1. Office of Governor Gavin Newsom. Governor Newsom Signs the Strongest Child Safety Chatbot and Social Media Laws in the Nation. California Governor's Press Office, 2026. link
  2. California State Legislature. Senate Bill No. 1119, Companion Chatbots: Children's Safety. California Legislative Information, 2026. link
  3. Sarah Grillo. California's New 'Adam's Law' on Chatbots Shows OpenAI's Strategy Shift on State AI Regulations. Fortune, 2026. link
  4. Transparency Coalition. California Lawmakers Just Passed Adam's Law, a New Chatbot Safety Bill. Here's What It Would Do. Transparency Coalition, 2026. link
  5. Office of California State Senator Steve Padilla. Governor Newsom Signs Adam's Law. California State Senate, District 18, 2026. link