New FPF Report Analyzes the Rise in Chatbot Legislation & What’s Ahead
As lawmakers look to regulate how AI systems interact with minors, new report breaks down key state and federal chatbot policy developments
WASHINGTON, D.C. – The Future of Privacy Forum (FPF), a global non-profit focused on data protection, AI, and emerging technologies, today released a new report analyzing one of the most active areas of AI policymaking: chatbot regulation. The report, Regulating the Conversation: The U.S. Landscape of AI Chatbot Legislation, provides practical insight into this rapidly-evolving area of technology law and policy, including why chatbot legislation is emerging now; the core components of chatbot laws and the policy tradeoffs they raise; and the key questions likely to shape the next phase of chatbot regulation.
The report identifies two major forces behind the current wave of chatbot legislation: high-profile litigation alleging chatbot-related harms and policymakers’ desire to respond more quickly than they did to alleged harms of social media. The report examines how themes raised in recent litigation are reflected in emerging requirements in new state laws, such as age assurance, crisis response protocols, parental controls, and design restrictions. Much of this activity has focused on “companion chatbots” and youth safety, as lawmakers reflect on how to approach systems that can simulate friendship, emotional support, or other relationship-like exchanges.
The report highlights how active lawmakers have become: 37 states introduced 124 chatbot-related bills in 2026, and 18 state chatbot-specific laws are currently on the books. The report also examines two of the most recent high-profile companion chatbot bills: California’s SB 1119, recently signed into law by Governor Newsom, and New York’s S 9051, which passed the Legislature and is pending Governor Hochul’s signature.
“What makes chatbots different from other technologies, and from much of AI regulation, is their relational quality: they talk back, remember context, and can create the impression that they know the user. Such qualities draw particular attention in the context of use by children and teens, where lawmakers are trying to address potential risks while still preserving beneficial uses of conversational AI” said Justine Gluck, Policy Analyst, AI Policy and Legislation at FPF and the author of the report. “Lawmakers are increasingly focusing on the relationship that can develop between a user and a chatbot over time, not just the AI system powering it. We hope that this report will be a useful guide for policymakers, development and compliance teams, researchers, and others who are navigating this complex environment.”
The report’s key findings include:
- Chatbot laws largely target the user experience, not the model, and a few key themes are emerging. Most new laws focus on disclosures, crisis protocols, and minor-specific safeguards, a departure from AI legislation aimed at how models are trained or tested.
- There is significant bipartisan interest. Republican lead sponsors introduced 45 percent of chatbot bills, and Democratic sponsors introduced 55 percent.
- Preemption debates remain an open question. States have moved first on chatbot regulation, but Congress has also begun introducing chatbot-specific proposals, with 10 bills introduced to date with differing approaches to the role of state law.
- Emerging risks raise difficult questions and tradeoffs. Concepts such as emotional dependence, crisis detection, parental controls, and sensitive conversational data require balancing user safety with privacy, autonomy, beneficial use cases, and the practical challenges of applying broad statutory concepts to context-dependent chatbot interactions.
- Older adults may be next. Lawmakers have signaled increasing interest beyond minors and companion chatbots to address other vulnerable users or sensitive contexts, such as older adults.
- Chatbots offer a preview of how lawmakers may approach AI agents. As AI systems increasingly begin taking actions on a user’s behalf, such as booking services or making purchases, many chatbot regulatory concepts, including transparency and liability, could influence how lawmakers approach agentic AI.
The full report includes an overview of common requirements in enacted chatbot laws, a state and federal bill tracker, an analysis of how federal chatbot proposals would affect state regulation, and a look at emerging data protection requirements in chatbot laws and proposals. It also examines threshold questions around definitions, carveouts, and implementation as companies and regulators begin applying these requirements in practice. It builds on FPF’s extensive work on chatbot legislation, including a 2026 chatbot legislation tracker and analysis of new laws in Oregon, Washington, Colorado, California, and Connecticut.
FPF will host a webinar on October 7 from 1-2 PM EST featuring an expert panel to discuss the report and the chatbot policy landscape in more detail. Click here for more information and to register for the webinar.
For more information about the Future of Privacy Forum, visit www.fpf.org.
# # #
About Future of Privacy Forum (FPF)
FPF is a global non-profit organization that advances principled and pragmatic data protection, AI, and digital governance practices. We convene leaders across industry, academia, and the public sector to provide expert analysis, benchmarking, and best practices that support responsible innovation and regulatory compliance. FPF has offices in Washington D.C., Brussels, and Singapore. Follow FPF on X and LinkedIn.