top of page

California Youth Social Media Laws Put AI Chatbots and Addictive Feeds Under New Rules

Sep 12
13 min read

California youth social media laws now put two influential technologies under one child-safety framework, despite objections from privacy and technology groups. Governor Gavin Newsom signed 13 related bills on September 10, 2026. The package restricts addictive platform features for users under 16 and imposes detailed safeguards on companion chatbots used by minors.

The laws move California beyond warnings and parental dashboards. They regulate product design, require age-related decisions, create new auditing duties, and increase companies’ potential liability. Social media platforms must reconsider personalized feeds and autoplay. Chatbot operators must assess foreseeable risks before launching or substantially modifying products.

That approach creates the central conflict. California says companies should identify young users and remove risky features before harm occurs. Critics argue that the required age assurance could reduce privacy and lawful access for every user. Meta also maintains that personalization can help teenagers find relevant people and interests when suitable safeguards exist.

The result is not a straightforward ban on youth technology. It is a state-directed redesign of how engagement, memory, advertising, and emotional interaction work for minors. Whether that redesign survives legal challenges will determine how far California’s model travels.

California Youth Social Media Laws Change Product Design

California is regulating the engagement mechanisms themselves, not only the content that appears through them.

Newsom’s child safety package spans social media, AI companions, school devices, student data, online exploitation, and digital wellness. The two central measures are Assembly Bill 1709 and Senate Bill 1119, known as Adam’s Law.

AB 1709 prohibits covered platforms from providing addictive features to California users under 16. Its definition includes autoplay and an addictive feed. Such a feed recommends or prioritizes user-generated media using information connected to a person or device.

The distinction matters because the measure does not automatically prohibit a young teenager from maintaining an account. A platform can retain an under-16 account if it removes the prohibited features. A chronological feed based on expressly requested accounts could remain available if it meets the law’s conditions.

This structure targets the system that chooses and continuously presents content. It focuses on signals such as viewing history, previous interactions, and profile data. These signals help platforms predict what will keep a person watching, scrolling, or returning.

The law also reaches beyond services formally labeled social networks. A covered platform can include a website, online service, or mobile application where addictive features form a significant part of the service. Commercial transaction sites, review services, and cloud-storage feeds receive specific exclusions.

Before offering an addictive feature, a covered platform must verify a user’s age through California’s existing age-assurance framework. If the system identifies someone under 16, the company must withhold those features or remove the account and associated information.

The AB 1709 text authorizes public prosecutors to seek civil penalties. A knowing violation can carry a penalty of up to $50,000 per affected minor. A negligent violation can bring up to $25,000 per affected minor.

A separate measure, AB 2, raises the possible cost when a large social platform negligently injures a child. It creates statutory damages of $5,000 per violation, capped at $1 million per child, or three times actual damages. The law covers platforms with more than $100 million in annual gross revenue.

Those provisions do not make every negative online experience actionable. Plaintiffs must still establish the required legal elements, including injury and a failure to exercise ordinary care. However, the higher potential damages increase the consequences when a court finds that failure.

The package therefore combines prevention with liability. AB 1709 tells platforms which engagement systems they cannot provide to younger users. AB 2 raises the financial stakes if a large platform’s negligence causes a child’s injury.

That combination pressures companies to document design decisions before litigation begins. Product teams will need evidence showing how they identify minors, restrict features, and respond when safeguards fail. A parental-control page alone will not answer those questions.

Adam’s Law Treats AI Companionship as a Safety System

Adam’s Law assumes that an emotionally responsive chatbot needs safeguards closer to a safety-critical service than an ordinary entertainment product.

SB 1119 applies to companion chatbots, meaning systems designed to sustain conversational relationships rather than answer isolated requests. It builds on California’s existing requirement that chatbots disclose their artificial nature and maintain protocols addressing suicide or self-harm content.

Beginning July 1, 2027, operators must conduct documented child-safety risk assessments before releasing a new or substantially modified companion chatbot in California. A substantial modification is an update that materially changes the system’s functionality or performance.

The assessment must consider reasonably foreseeable physical, financial, psychological, emotional, privacy, and discrimination harms. Operators must describe their evaluation methods and identify relevant public benchmarks or research. They must also document measures taken to reduce identified risks.

The Adam’s Law text creates a choice for operators. They can determine users’ ages and apply child-specific protections. Alternatively, they can extend most of those protections to everyone when reliable age information remains unavailable.

That choice connects the chatbot rules to the broader privacy debate. An operator can collect or receive age information, then segment the experience. It can also use safer defaults broadly, reducing the need to distinguish children from adults.

For known child users, the law requires crisis-response procedures. When an operator identifies a credible and imminent threat of suicide or self-harm, it must take at least one prescribed action. That can include notifying a linked parent when notification would not create a serious threat.

The alternative is a streamlined connection to the 988 Suicide and Crisis Lifeline or an equivalent provider. The operator must also give children age-appropriate notice that parental notification can occur under specific circumstances.

Default settings address the design choices that can make a chatbot feel persistent and demanding. Push notifications must be disabled. A continuous session must be limited to one hour, while daily chatbot use must be limited to two hours.

Persistent conversational memory must also be disabled by default for younger users. This form of memory lets a system incorporate earlier conversations into later interactions. For users aged 16 or 17, limited exceptions exist when operators install additional controls against safety degradation.

Parents can adjust those defaults through parental controls. They must also be able to disable access entirely for a child under 16. Without a linked parent account, the default settings cannot be changed.

The law goes further than screen-time management. Operators must take reasonable measures to stop a companion from claiming consciousness, simulating romantic interest, or encouraging emotional dependence. The chatbot cannot ask children to conceal usage or bypass parental controls.

Other prohibited behaviors include encouraging self-harm, substance use, disordered eating, or severe harm to others. A chatbot cannot present itself as diagnosing or treating a child unless it qualifies under applicable medical-device and privacy rules.

Advertising and personal information receive separate limits. Operators cannot sell information gathered from a child through the chatbot. Cross-context behavioral advertising is prohibited, while any permitted contextual advertisement must be clearly labeled.

These duties turn conversation design into a compliance surface. Tone, memory, reminders, relationship language, escalation behavior, and advertising logic all become reviewable features. A model’s general safety policy will not be enough if its product interface encourages dependency.

The Rules Shift Responsibility Toward Platforms

The package rejects the idea that children and parents should carry the full burden of resisting systems optimized for continued engagement.

Supporters describe the laws as a product-safety intervention. Their argument is that sophisticated companies design recommendation and conversational systems, measure their effects, and control their defaults. Families rarely possess equivalent information or technical leverage.

Newsom framed the measures around responsibility rather than opposition to technology. At the signing event, he said California was addressing scrolling, algorithms, and the engineering behind them. That framing separates the package from a broad moral objection to screens.

Assemblymember Rebecca Bauer-Kahan offered a similar comparison. Governments already expect manufacturers to make cribs, chairs, and car seats safe. Digital products used by children, supporters contend, should face a comparable expectation of foreseeable-risk management.

Adam’s Law grew from a particularly painful case. Adam Raine died by suicide in 2025 after extensive interactions with ChatGPT. His parents sued OpenAI and alleged that the system provided information related to suicide methods.

The allegations remain subject to litigation, and the law does not resolve the facts of that case. However, Adam’s mother, Maria Raine, argued that parents did not understand the risks of AI companionship when her son began using it. She supported mandatory safeguards and crisis procedures.

OpenAI publicly supported SB 1119 before Newsom signed it. That position illustrates an important division within the industry. A chatbot company can accept tailored safety obligations while technology trade groups oppose broader restrictions on access or personalization.

The AI measure also reflects lessons California drew from an earlier attempt. In 2025, Newsom vetoed a stricter bill that would have restricted chatbot access for anyone under 18 unless operators prevented specified harmful conversations. He argued that an outright approach could deny young people beneficial uses of AI.

SB 1119 follows a different route. It allows minors to use companion chatbots but controls memory, session duration, advertising, emotional behavior, and crisis escalation. The state moved from a threshold access question toward ongoing product governance.

Social media regulation has followed a similar progression. California previously required parental consent before an operator knowingly provided an addictive feed to a minor. The new law removes that option for users under 16 and directly prohibits the covered features.

That shift pressures Meta, TikTok, YouTube, and other feed-based services. Their products rely on ranking systems that personalize content and reduce pauses between items. Those systems also support advertising by generating more behavioral data and attention.

Meta defended personalization after the signing. The company said tailored experiences help teenagers connect with family, friends, and interests when suitable guardrails are present. That argument identifies what platforms believe the law risks losing.

The disagreement is not simply safety against profit. Personalized recommendations can expose a teenager to educational material, niche communities, and creators they would not find through a chronological list. The same machinery can repeatedly surface distressing or compulsive material.

California has resolved that tradeoff differently for younger users. It places the burden on platforms to provide a non-addictive experience until a user reaches 16. Companies must now prove that their alternatives remain useful without relying on prohibited engagement mechanisms.

The package also creates an e-Safety Advisory Commission within the state Department of Justice. Its members will bring expertise in child development, technology, online safety, public health, education, and marginalized youth.

The commission is advisory, not an enforcement agency. Still, its reports can shape future regulations and definitions. That makes the initial statutes a foundation rather than the final specification.

Privacy and Speech Concerns Complicate the Safety Case

The laws can reduce manipulative design while still creating serious risks for privacy, anonymity, and young people’s access to lawful speech.

The Electronic Frontier Foundation opposed AB 1709 and urged Newsom to veto it. The organization argues that the law functions as a social media ban for users under 16, even though its text permits accounts without addictive features.

That disagreement turns on what remains after the restricted systems disappear. Many platforms organize their primary experience around recommendation, autoplay, infinite presentation, and notifications. Removing those functions could leave a service technically accessible but substantially less usable.

EFF also argues that age assurance affects adults. A platform cannot reliably exclude younger users from particular features without deciding whether every user belongs above or below the threshold. That process can invite new data collection.

California’s framework seeks to reduce direct document collection by moving age signals through operating systems and application stores. However, implementation still matters. Users will want to know what data is transmitted, how long it remains available, and whether companies can reuse it.

The privacy critique warns that companies might adopt identification or biometric methods when other signals prove inconclusive. Centralizing sensitive identity information can increase the consequences of breaches, misuse, or government demands.

Free-speech concerns are equally important. Teenagers use online communities to discuss health, identity, disability, family conflict, and local politics. Some rely on those spaces because safe support is unavailable at home or school.

A uniform age restriction can therefore produce unequal effects. A teenager with strong offline support might experience fewer recommendations and more parental supervision. Another teenager might lose access to a community that provided important information or personal connection.

AB 1709 attempts to preserve direct communications and expressly requested content. It excludes private messages from the addictive-feed definition. It also allows material selected because a user explicitly requested a particular creator, subject, or sequence.

Those exceptions create a possible middle path. Platforms could build youth modes around followed accounts, deliberate searches, saved lists, and finite sessions. Discovery would become more intentional and less dependent on behavioral prediction.

Yet enforcement will test the distinction between a useful recommendation and an addictive feed. A platform can recommend the next lesson in an educational sequence. It cannot simply use accumulated behavior to keep selecting unrelated material that maximizes attention.

Chatbot safeguards bring their own difficult boundaries. A companion should not encourage emotional reliance, but useful conversational systems often communicate warmth and continuity. Regulators, auditors, and courts will need to distinguish supportive language from manipulative dependency.

Parental notification also requires careful judgment. Informing a parent about a credible and imminent self-harm threat can save a life. In some homes, notification could expose a child to punishment, rejection, or violence.

SB 1119 recognizes that risk by conditioning parental notice on whether it threatens serious harm. It also offers direct crisis connection as another required response. Operators must turn that legal standard into a decision process that works during unpredictable conversations.

False positives can erode trust. If harmless discussion repeatedly triggers warnings or escalation, teenagers might avoid seeking information. False negatives carry far more severe consequences when a system misses an imminent threat.

The law does not eliminate that technical and ethical problem. It requires operators to assess it, document mitigations, and submit to external review. That is greater accountability, but it is not a guarantee of accurate detection.

Legal challenges remain likely, particularly around AB 1709. Courts have scrutinized youth-access and age-verification laws in several states. Judges often weigh child protection against anonymous access, adult speech, and the breadth of restricted services.

California’s more targeted language could help its defense. The state regulates defined engagement features rather than banning every under-16 account. Still, a court will examine practical effects, not only statutory labels.

Audits and Liability Turn Safety Claims Into Evidence

The most consequential change is that companies must produce records showing how their safeguards work before a crisis reaches a courtroom.

SB 1119 requires documented risk assessments for new or substantially modified companion chatbots. These assessments must describe evaluation methods, relevant benchmarks, expert consultation, identified harms, and mitigation steps.

That requirement changes the launch process. A company cannot treat youth safety as a policy document added after engineering decisions. Teams must test how models, interfaces, memory systems, notifications, and advertising interact before deployment.

Independent child-safety audits add another layer. Initial audits generally arrive by January 1, 2029, or before an operator first makes a chatbot publicly available, whichever is later. Follow-up audits occur every two years.

A new audit can also be required before a substantial modification when the associated assessment shows increased child-safety risk. This provision matters because conversational products can change rapidly through model replacements, new memory tools, or revised system instructions.

Auditors must examine internal controls, testing, mitigation, responsible personnel, and material deviations from the law. The lead auditor must certify the results under penalty of perjury. Financial interests between an operator and auditor are restricted.

Operators must send a summary to the attorney general within 30 business days after receiving an audit. They must publish a high-level summary within 90 days. The attorney general can request the full report for cause, although submitted reports remain confidential.

These rules will not expose every model test or internal conversation. Trade secrets, cybersecurity information, and personal data receive protection. Still, the public summaries can reveal whether an operator maintains a credible child-safety program.

The audit requirement creates pressure for repeatable measurements. A company must define what behavior it tests, which user profiles it simulates, and what failure rate it accepts. It must also show whether mitigations remain effective across product changes.

That process could encourage a market for specialized AI child-safety auditors. It could also create inconsistent results if evaluators use different methods. California’s separate registry and independence standards for AI auditors may help align expectations.

AB 1709 creates a parallel need for product evidence. Platforms must show reasonable measures that keep addictive features away from under-16 users. They must document age-signal handling, restricted accounts, feature eligibility, and deletion decisions.

AB 2 makes those records important during negligence litigation. A platform facing a child-injury claim will want evidence that it recognized foreseeable risks and responded with reasonable care. Missing records could weaken that defense.

The reported law package arrives as litigation already challenges social media design. States and families have accused major platforms of knowingly deploying features that encourage compulsive use among minors.

The new statutes do not automatically validate those accusations. They do, however, define clearer expectations for future conduct. Companies can no longer argue that every design choice falls outside product-safety oversight.

Compliance will involve more than lawyers. Machine-learning engineers must test model behavior. Designers must make controls visible. Trust and safety teams need escalation procedures. Privacy teams must minimize age and conversation data.

Executives will also need to decide which products remain available to minors. Some companies may build a distinct youth experience. Others may apply protective defaults to everyone. Smaller operators might block child access rather than maintain specialized compliance systems.

The result could favor large companies that can fund audits and dedicated safety teams. That concern deserves attention because a compliance regime can improve safety while increasing barriers for smaller competitors.

SB 1119 temporarily addresses part of this issue. Operators with less than $500 million in prior-year gross revenue receive limited relief from specified audit requirements before 2032. Core child protections still matter, however, and the exemption does not erase every obligation.

This tension will shape the market. Strong requirements can prevent companies from externalizing safety costs onto families. Poorly calibrated requirements can also concentrate users among the largest incumbents.

Three Signals Will Show Whether California’s Model Works

The next test is not another announcement. It is whether companies can create safer youth products without replacing engagement risks with surveillance or exclusion.

The first signal will be the implementing guidance around age assurance and covered platforms. California’s attorney general can adopt regulations and refine which services fall within AB 1709.

Those rules should clarify acceptable age signals, data retention, dispute processes, and treatment of uncertain cases. They should also explain how platforms can preserve private communication, explicit follows, and user-directed discovery.

A privacy-preserving implementation would strengthen California’s case. It would show that feature restrictions do not require every person to upload identification. A system that encourages document or biometric collection would support critics’ warnings.

The second signal will be product changes before July 1, 2027. Social platforms must decide what an under-16 experience looks like without addictive feeds or autoplay. Chatbot operators must implement safer defaults, session limits, crisis procedures, and parental controls.

Useful youth modes would strengthen the law’s central premise. They would show that companies can separate core communication or educational value from attention-maximizing systems. Mass account closures would suggest the compliance burden overwhelms that distinction.

Watch how companies explain these changes to families. Clear controls and understandable notices would indicate genuine redesign. Confusing eligibility errors and hidden appeal paths would show that formal compliance has outpaced usability.

The third signal will come from litigation and audit evidence. Courts will decide whether the social media provisions respect constitutional protections and fit with existing federal law. Early chatbot assessments will reveal whether operators can test relational risks consistently.

Published audit summaries deserve close attention. Readers should look for specific evaluation categories, repeatable tests, known limitations, and evidence that mitigations changed the product. Vague claims about responsible AI will provide little assurance.

Enforcement patterns will matter too. Public prosecutors can target knowing or negligent violations, but selective cases will define the practical boundaries. Early actions could establish how California distinguishes a design failure from an unavoidable individual outcome.

Families should also watch what companies do outside California. A platform may maintain state-specific experiences, but that approach adds technical and operational complexity. National adoption would show that California has effectively set a broader product standard.

Other states will study the same outcomes. New York, Utah, and several international governments have already pursued youth social media or chatbot restrictions. California’s scale and technology industry make its implementation especially influential.

The California youth social media laws ultimately test a larger proposition. Can policymakers regulate recommendation and relational design without regulating every online conversation? The statutes answer yes, but implementation must still prove it.

For parents and users, the useful question is concrete: do the new settings reduce compulsive use and dangerous chatbot behavior while preserving privacy and meaningful access? Track the regulations, product redesigns, and first independent audits. Those results will show whether California created a workable safety standard or another contested age gate.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page