What happened

California has long been the de facto standard-setter for AI regulation in the United States: its population, economic weight, and status as the home of the technology industry mean that a rule made here often becomes a national — even global — baseline. The package signed on 10 September 2026 is notable because, for the first time, it does not target general-purpose models or abstract "transparency" duties. It targets, directly, chatbots designed to behave as if they were the user's friend, confidant, or romantic partner.

According to the Governor's official release, the backbone of the package is SB 1119, which mandates "robust protections" for companion bots. The law is named after Adam Raine, a young person who died following an intense relationship with a chatbot. The naming is not merely symbolic: the entire logic of the law rests on a single idea — if a product is present in a child's most vulnerable moments, its legal responsibility must be measured accordingly.

The package is not a single statute. Alongside SB 1119 sit SB 1276, which expands child sexual-exploitation offences to cover "digitally altered or AI-generated" imagery even where no real child is depicted; SB 867, which extends companion-bot obligations to talking toys; and AB 1856, which requires age-verification signals in software applications. The concern, in other words, is not one product but the entire surface across which children meet AI — chat apps, toys, social platforms, app stores.

Why "companion bot" is a distinct legal category

Unlike a search engine or an enterprise assistant, a companion bot is designed to bond as the product itself: it remembers, compliments, says "I missed you," is endlessly "there," and manufactures a bespoke relationship. That design produces powerful emotional attachment — and a corresponding vulnerability — especially in adolescents, because "stickiness" (engagement) is a direct part of the revenue model.

The legal point is this: when a product deliberately cultivates the user's trust and emotional dependence, the duty of care it owes is heavier than that of ordinary software. In contract terms we frame this as a relationship of heightened trust; in tort terms, through the lens of foreseeable harm. What SB 1119 does is codify precisely that distinction: it defines a companion bot not as a piece of consumer electronics you replace when it breaks, but as a relationship surface that requires care.

This re-categorisation also changes the classic answer to "the AI caused harm — who is liable?" If the harm flows not from one "wrong answer" but from the product's overall design — the sum of decisions engineered to bond, to prolong the conversation, to keep the user inside — then liability must be sought at the level of product design. That is why the statute imposes duties of design and process rather than content moderation.

What SB 1119 actually requires

Drawing on the Governor's release, the core obligations of "Adam's Law" fall into four pillars:

  • Crisis protocols. When a bot detects signs of suicidal ideation or self-harm, it must shift from "naturally" continuing the conversation to a defined intervention flow, directing the user to human resources and crisis support. In legal terms, the "keep chatting" default ceases to be a neutral engineering choice and can become an element of negligence.
  • Parental controls and notice. Tools for parental oversight of minors, and a duty to notify a parent when safety settings are disabled — binding protection to a "second set of eyes" a child cannot supply alone.
  • Independent audits. For the first time nationally, the law requires independent child-safety audits and annual risk assessments. This is the pivotal innovation: safety is tied not to the company's own assertion but to an externally verifiable process. Saying "we are safe" is no longer enough; you must prove it to an independent auditor.
  • "I am not human" clarity. An expectation that the bot make plain, in a way the user grasps, that it is not a real person — aimed at breaking the "real friend" illusion that forms so easily in children. It is a sharper, child-centred version of the transparency logic in the EU AI Act.

Read together, these four pillars describe not classic "content moderation" but product-safety law. The statute regulates less what the bot says than how it must behave in danger and to whom it must answer. This is the approach we have applied to cars and toys for decades — design for foreseeable misuse and for the most vulnerable user — now carried into artificial intelligence.

The rest of the package: synthetic abuse imagery, toys, and age checks

SB 1276 closes perhaps the most disturbing gap. One of the darkest misuses of generative models is synthetic imagery that depicts no real child yet normalises child abuse. SB 1276 expands child sexual-abuse-material offences to cover "AI-generated or digitally altered" imagery even where no real child is depicted — a clear legal answer to the "victimless crime" defence.

SB 867 extends companion-bot duties to talking toys, because whether the bot a child speaks to lives on a screen or inside a plush toy makes no difference to that child — and should make none to the law. As AI-enabled toys proliferate, this is a quiet but important extension.

AB 1856 pushes age-verification signals down to the application layer, so that protection begins from the question "is this user a child?" The package also contains complementary measures on student-data protection, bans on addictive algorithmic feeds in school communication platforms, and reporting mechanisms for child-abuse material. Effective dates were not itemised in the official release; companies should track the final texts and implementation timeline from the primary source.

Where it sits in the global picture

The package signals a quiet shift in direction. Until now, the large frameworks — such as the risk-based, transparency-first approach of the EU AI Act — focused on what the model is (high-risk or general-purpose). California instead offers a harm-based model focused on whom the model affects and on the most vulnerable user. The two are not rivals but complements: one disciplines the system's architecture, the other the human cost of the outcome.

It should be read alongside a year of related developments: South Korea's deepfake sexual-violence legislation, debates over mandatory watermarking of AI-generated content, and questions of liability for the independent actions of autonomous systems. The common thread is constant: a move from abstract "ethical principles" to measurable, auditable product obligations.

What it means for Turkey

Turkey has no dedicated "companion bot" statute; yet the California model creates a powerful precedent and de facto pressure on how our existing law will be applied to this new product class. Several intersections stand out:

  • Data protection and children's data. The emotional disclosures a minor makes to a bot are among the most sensitive personal data. A bot's processing, storage, and re-feeding of that data into the model raises hard questions under explicit consent, purpose limitation, and data minimisation — and the validity of a child's consent, together with parental authorisation, is a problem area in its own right.
  • Liability. Where a bot behaves carelessly in a crisis, defective-service and tort provisions come into play. The fact that the product was designed to create an emotional bond can be treated as an aggravating factor in the foreseeability and standard-of-care analysis — meaning the "it was AI, we couldn't foresee it" defence steadily weakens.
  • Content and protection. On AI-generated child-abuse imagery, the gap SB 1276 closes is one that must also be squarely addressed in Turkey. Whether the "no real child" defence is legally acceptable will be a defining debate of the coming period.
  • Consumer protection. Digital services marketed to minors and engineered to be addictive may also draw scrutiny under consumer and advertising law.

In short, if a product enters the Turkish market as a "companion bot" or "AI friend," California's bar becomes a de facto compliance reference and a source of interpretation for courts and regulators in any dispute.

A practical roadmap for companies

For any company that builds, integrates, or distributes an emotionally bonding product, three priorities emerge:

  • Crisis architecture. A design in which the "keep chatting" default can hand off, on risk signals, to a human-intervention and referral flow. This is no longer an optional feature but a likely legal duty — and, more importantly, an ethical imperative. How the crisis flow is triggered, what it logs, and where it refers must all be documented.
  • Auditability. Safety claims documented so they can withstand independent audit; the annual risk assessment tied to a genuine corporate process. "Safety" must be an externally verifiable chain of evidence, not a marketing line.
  • Age and parent layer. Age signals that treat "this user might be a child" as the default, and parental-notification flows that trigger when protections are weakened. The design's starting point should not be "adult user" but "a user who may be a child until proven otherwise."

These three reduce to a single principle: make safety the founding architecture of the product, not a layer bolted on afterwards. Retrofitted compliance is always more expensive, more fragile, and legally more exposed.

What to watch next

Three developments deserve close attention. First, effective dates and implementing regulations: the secondary rules on how independent audits will operate will matter as much as the statute's spirit. Second, industry response and possible legal challenges: suits framed around "free speech" and "overbreadth" will map the rule's limits. Third, cross-border effect: whether a product that complies in California carries the same architecture globally — which will, in practice, set the de facto standard for many markets, Turkey among them.

Expert Opinion

This section reflects my personal assessment as the founder of this site and an AI ethics & compliance counsel.

In my view, "Adam's Law" is a quiet but foundational threshold in AI regulation. The principles we have debated for years — transparency and accountability — are for the first time being translated into individual design decisions and auditable obligations. A product that turns the cultivation of a user's emotional dependence into its business model is not making a legally neutral choice; that choice carries a heightened duty of care. That the law places "behaviour in a crisis and independent audit" — rather than "content" — at its centre is, to me, exactly right: the law stops chasing a single sentence the bot uttered and instead interrogates the product's overall safety architecture.

That the statute bears a young person's name reminds us the real subject is not technology but people. Regulatory debates often default to "let's not stifle innovation"; yet genuine innovation begins by accepting that a product which cannot protect its most vulnerable user should not exist at all. That is not a stance against innovation — it is the frame that matures it.

For Turkey, my expectation is less a statute written from scratch than the adaptive interpretation of our data-protection regime for children's data, consumer law, and liability provisions to this new product class. My advice to companies offering or integrating emotional-AI products is clear: design crisis protocols, an age layer, and independent auditability not as a line item of legal risk but as the product's founding safety architecture. Because in this field regulation no longer trails technology — it increasingly walks ahead of it, and the companies that move with foresight will win on both law and reputation.

This article is for information only and does not constitute legal advice. The facts are based on the California Governor's official release of 10 September 2026; the analysis and assessments are the author's own. If you or someone you know is struggling with thoughts of self-harm or suicide, please contact your local emergency services or a crisis line.