AI Toys Are Listening to Your Child — and Thousands of Their Conversations Were Left Open Online
The Blaick Team 7 min read
Talking plush animals, robot companions and "learning buddies" powered by chatbots are heading for the top of holiday wish lists — and the evidence is piling up that they are reaching children before privacy and safety rules exist. In January 2026, WIRED reported that AI toy maker Bondu had left more than 50,000 chat transcripts between children and their toys reachable through a web portal. Senate staff separately found that Miko had left the toy's audio responses in an unsecured, publicly accessible database — including children's names and details of what they said. Meanwhile, a University of Cambridge study of toys for children up to age five concluded that conversational AI toys are not always built with a child's psychological safety in mind.
The number to hold: 50,000. That is how many private conversations, whispered to a toy in a bedroom or playroom, were exposed by a single company's basic security lapse. These devices record voices, transcribe them, and often capture a child's emotional tone — then send it all to servers you cannot see. Young children do not understand that a "friend" who remembers their favourite colour is also a microphone connected to a company. Here is what the reports found, what the law does and does not yet cover, and what you can do before the next gift-giving season.
The Exposure
50,000+ Child Chat Transcripts Left Reachable
WIRED reported in January 2026 that Bondu exposed more than 50,000 transcripts of children's conversations with its AI toy through a web portal. Senator Maggie Hassan has since pressed the company for answers
The Second Breach
Miko's Audio Responses Sat in an Open Database
Senators Marsha Blackburn and Richard Blumenthal wrote that anyone could download Miko's side of thousands of conversations with children, often containing names and personal details — a "basic cybersecurity lapse"
The Content Risk
Toys Caught Discussing Sex and Dangerous Objects
NBC News reported in December that several AI toys engaged in explicit sexual conversations and advised users on finding dangerous objects — with no adult in the room
The Research
Cambridge: Regulate and Certify Talking Toys
The University of Cambridge's "AI in the Early Years" project, the first systematic study of conversational AI toys for under-fives, calls for tighter regulation, safety kitemarks and limits on toys that encourage children to confide in them
What an AI Toy Actually Collects — and Where It Goes
A traditional toy plays pre-recorded phrases. An AI toy streams your child's voice to a cloud service, where a large language model generates the reply. That architecture means the toy is only as safe as the company's servers, its third-party AI providers, and the guardrails wrapped around the chatbot.
Three things to know before you buy
VOICE
Recordings, transcripts and emotional tone
Researchers found these products collect voice recordings, transcripts and even the emotional tone of a child's speech, often while sitting in a private bedroom or playroom, and that many privacy policies are unclear or missing key details
THIRD PARTIES
Your child's words may pass through other companies
Cambridge researchers recommend tighter controls over third-party access to the AI models behind the toy — meaning the toy brand is often not the only company that handles what your child says
BONDING
Designed to feel like a best friend
The study urges limits on how far toys encourage children to befriend or confide in them. A child who tells a toy a secret has no idea that secret is now stored data
Sources: University of Cambridge "AI in the Early Years" (2026); WIRED, January 2026; NBC News, December 2025; TechRepublic.
"This basic cybersecurity lapse, and the toys' frequent communications back to Miko, Inc., call into question whether your company adequately protects the privacy and security of children's and the toy's data." — Senators Marsha Blackburn and Richard Blumenthal, 2026 letter to Miko
Regulators Are Behind — Parents Are the Safety Layer
Federal and state lawmakers have started to focus on AI built into children's products, and Congress has seen bills aimed at AI toy safety, but there is still no single standard that a toy must pass before it is sold to your family. Existing children's privacy rules such as COPPA require parental consent for collecting data from under-13s, but they were not written for a plush toy that holds open-ended conversations. Until certification exists, the checks fall to you.
Where protection currently stands
PRIVACY
COPPA applies, but enforcement is after the fact
Companies must obtain verifiable parental consent before collecting data from children under 13. Enforcement usually follows a breach — it does not stop one
GAP
No mandatory safety test for what a toy may say
Cambridge researchers are calling for safety kitemarks precisely because no independent check currently confirms a talking toy will stay age-appropriate
"Child-facing products are reaching homes and classrooms before clear privacy, safety, and transparency standards exist." — TechRepublic, 2026
Five Checks Before an AI Toy Comes Home
Read the privacy policy for three answersDoes it store recordings or transcripts? For how long? Which outside companies receive them? If the policy is vague or missing, treat that as your answer.
Test it yourself firstBefore gifting, ask the toy the questions a curious child would: about dangerous items, about bodies, about secrets. Return it if it answers anything you would not want said to a five-year-old.
Keep it in shared spacesA toy that lives in the living room, not the bedroom, means you hear what it says — and it hears less of what should stay private.
Turn off the mic, the cloud and the accountUse physical mute switches, skip optional accounts, avoid entering your child's real name or birthday, and delete stored conversations through the app where the option exists.
Fifth check: teach the "toys are not secret keepers" ruleTell your child in simple words: "The toy can be fun, but it is not a person and it is not private. Tell secrets and big feelings to me." That one sentence counters the design goal of making a toy feel like a confidant.
AI toys are not automatically dangerous, and some are built with real care. But the 2026 reports show a market moving faster than its safeguards. Two breaches, one damning academic review and repeated content failures are enough reason to slow down and ask questions before a microphone-equipped "friend" joins your child's bedroom.
The lesson from 50,000 exposed conversations is simple: if a toy listens, someone else may be listening too. Ask where the words go before you let your child speak.
Know what the AI in your home is doing — before it becomes a headline.
Start a free 14-day Blaick trial — no credit card required.
Blaick monitors the AI tools on your child's devices, alerts you to high-risk interactions, and helps you see where your family's data is going. No credit card needed to start.