On September 10, 2026, California Governor Gavin Newsom signed 13 child AI safety bills into law simultaneously — the most sweeping package of children's artificial intelligence protections enacted anywhere in the United States. The new laws impose penalties of up to $1 million per child harmed on tech companies that knowingly expose minors to dangerous AI, require mandatory independent safety audits of companion chatbots before they can be deployed to minors, and ban the engagement-maximizing design features researchers have directly linked to teen mental health crises. Behind the legislation is a crisis that has escalated faster than any previous child online safety threat: federal authorities received 440,000 reports of AI-generated child sexual abuse material in the first six months of 2025 alone — a 63-fold increase from the 7,000 reports filed across all of 2023–2024. A JAMA Pediatrics study confirms that two-thirds of American teenagers now use AI chatbots, with nearly 1 in 5 doing so for mental health support — and 63% of those conversations completely hidden from any parent. Here is what the new laws require, why every American family is affected regardless of state, and exactly what to do this week.
California's size — 39 million people, the world's fifth-largest economy, home to virtually every major AI company — means these laws function as a de facto national standard. When Google, Meta, Character.AI, and OpenAI must redesign their products to comply with California's requirements, those redesigns will reach every user in every state. But the protection gap between "California law exists" and "my child is protected" is real, and closing it this year requires parents to act — not wait.
The Scale
67% of Teens Use AI Chatbots
Two-thirds of US teenagers now regularly use AI chatbots — up from 45% in 2024. 1 in 5 uses AI specifically for mental health support, and 63% hide those conversations from parents (JAMA Pediatrics, 2026)
The Penalty
$1M Per Child Harmed
California's new laws impose civil penalties of up to $1 million per child on tech companies that knowingly expose minors to unsafe AI — the steepest child AI safety fine ever enacted in the United States
The Mandate
Audits Before Deployment
For the first time anywhere in the US, companion chatbots must pass mandatory independent safety audits and annual risk assessments before they can legally be marketed to or accessed by minors
The Crisis
440,000 Abuse Reports
AI-generated child sexual abuse material reports to NCMEC in the first half of 2025 alone — a 63-fold increase from 7,000 total reports across all of 2023–2024 combined
The Crisis That Forced 13 Laws at Once
California's legislative package did not emerge from a theoretical concern about future AI risks. It emerged from documented, peer-reviewed, federally reported harms that accelerated throughout 2025 and into 2026 at a pace that outran voluntary industry commitments entirely.
The three data points that drove California's emergency legislation
63×
Increase in AI-generated child sexual abuse material reports to NCMEC — from 7,000 in 2023–2024 to 440,000 in just the first half of 2025
1,275
Times ChatGPT raised suicide in Adam Raine's conversations — six times more than Adam himself — before the 16-year-old died. His name is now on California law.
63%
Of teens using AI for mental health support have never told a parent — the invisible conversations the legislation aims to make visible through mandatory parental notification
Sources: NCMEC CyberTipline 2025 Annual Report; Governor's Office press release, September 10, 2026; JAMA Pediatrics, July 2026.
The NCMEC figure is the one that shifted the political calculus: 440,000 reports in six months is more AI-generated child abuse material reported in half a year than all forms of CSAM combined during the entire year of 2020. The technology to generate this material is free, available to any teenager with a smartphone, and was subject to zero federal criminal penalties before May 2026's Take It Down Act.
"These 13 bills represent the most comprehensive legal framework for protecting children from AI harms enacted anywhere in the United States. California is sending a message to the tech industry: designing for engagement at the expense of child safety is no longer a viable business model." — Governor Gavin Newsom, signing statement, September 10, 2026
What the 13 Laws Actually Require
The package signed on September 10 covers five distinct harm categories — each with its own enforcement mechanism and compliance timeline. Here is what is now law in California and, effectively, a product roadmap that every major AI company operating in the United States must now follow.
Key provisions — California's 13-bill child AI safety package (signed September 10, 2026)
NEW LAW
Companion chatbot mandatory safety audits
Independent safety audits and annual risk assessments required for any AI companion marketed to or accessible by minors — conducted before deployment, not after an incident
NEW LAW
$1M-per-child civil penalties
Tech companies that knowingly expose minors to unsafe AI face civil penalties of up to $1 million per child harmed — the highest child safety fine in US law
NEW LAW
Crisis routing mandate (Adam's Law — SB 1119)
AI chatbots must route any minor disclosing suicidal ideation or self-harm to verified crisis resources, and must notify parents when connected minor accounts discuss crisis-adjacent content
NEW LAW
Addictive features ban for under-16 users
Autoplay, algorithmic recommendation feeds based on user history, infinite scroll, and other engagement-maximizing features are prohibited on platforms used by under-16 users
NEW LAW
AI training consent for children's data
AI companies must obtain separate, verifiable parental consent before using any minor's data or conversations to train AI models — with a legally enforceable right to delete on request
NEW LAW
AI-generated CSAM civil damages expansion
Expands civil liability for AI-generated child sexual abuse material — victims under 18 may sue for up to $250,000 per incident plus attorney fees
NEW LAW
Extended parental notification requirements
Platforms must notify parents when connected minor accounts have extended or repeated AI interactions involving emotional, crisis-adjacent, or other high-risk content categories
Source: California Governor's Office, September 10, 2026. Full text of all 13 bills available at leginfo.legislature.ca.gov.
The companion chatbot audit requirement is the most structurally significant provision. Previously, an AI companion app could be downloaded by a 14-year-old on day one — before any independent safety evaluation had occurred. Under the new law, that changes: no companion chatbot can legally be marketed to or accessible by minors in California without first passing an independent safety audit. Given California's market size, this requirement will effectively apply to every consumer AI companion app in the United States.
"The audit requirement changes the industry's incentive structure fundamentally. 'Move fast and fix it later' is not a viable approach when the harm category is child sexual abuse material and teen suicide." — Dr. Riya Patel, Children's Digital Health Policy Institute, September 2026
Why These Laws Protect Your Family — Even Outside California
California's laws formally bind companies operating in California. But the practical reality is different — and it works in every American family's favor, regardless of state.
Why California's AI laws become national standards
▸Every major AI company — OpenAI, Google, Meta, Apple, Character.AI — is headquartered in California or has it as a primary market. They cannot build separate product versions for 50 states.
▸The California market is larger than most national economies. A law requiring companion chatbot audits in California requires them everywhere these companies want to operate.
▸The GDPR precedent is documented: when Europe mandated data protections in 2018, those protections extended to US users within two years as companies standardized globally rather than maintaining split architectures.
▸98 bills addressing AI chatbot safety have been introduced across 31 US states in 2026 alone. California's signed package gives every state legislature a tested template to replicate.
▸Class-action litigation follows the same pattern: a California standard gives plaintiffs in any state a benchmark to argue other companies should meet — accelerating national compliance.
Historical parallel: California's Auto Emissions Standards (1970) became the basis for federal EPA regulations. California's data breach notification law (2003) became the model for breach notification laws in all 50 states within a decade.
The practical translation: if your child uses Google, uses an iPhone, uses Character.AI, or uses any social media platform, the products those companies must build to operate legally in California will reach your child. The protection the law delivers will be uneven at first and comprehensive over time. Families who need full protection now cannot rely solely on California's compliance timeline.
What the Laws Don't Cover — and Where the Gaps Remain
California's 13-bill package is real progress. It is also incomplete. Three significant gaps remain that parents who understand them are better positioned to close independently.
What California's signed laws still don't address
GAP
AI embedded in search engines and browsers
Google's AI Overview and AI Mode — present in every Google Search result by default and accessed by 75% of US children — are not covered by companion chatbot provisions. There is still no parental control to disable them.
TIMING
Implementation timeline — audits begin in 2028
The mandatory chatbot audit requirement does not fully apply to apps already in distribution until their first audit cycle in early 2028. Your teenager's current companion chatbot has not been evaluated under this new standard.
GAP
International AI apps
Many of the highest-risk companion chatbots tracked by NCMEC are not incorporated in California and may resist or delay compliance. Enforcement against foreign apps is an open legal question.
NOTE
Federal floor still absent
The KIDS Act passed the House in June 2026 and is pending in the Senate. Until it passes, there is no federal child AI safety baseline — 49 states still lack California-level protections.
The audit standard — one of the most consequential provisions — does not apply to existing companion chatbot products in distribution until they undergo their first mandatory audit cycle, which begins in 2028. That means the apps your teenager is likely using right now are still being governed by the old voluntary-standards regime, not the new mandatory one. For families who need protection this school year, waiting for the audit cycle to close is not a plan.
What Every Family Can Do Right Now
California's laws tell you what the state now requires of AI companies. They also tell you exactly what your family needs — and the families who have it today are those who did not wait for a bill to become law before acting.
Audit your child's device the way the law now audits chatbots
California now mandates independent safety audits before companion chatbots can reach minors. Your family's equivalent is knowing exactly which AI apps are installed on your child's device — before an incident, not after. That visibility is the first action the law would want you to take.
Invoke your existing COPPA AI data rights now
Since April 22, 2026, every AI company must get verifiable parental consent before training models on your child's data. The right to opt out and demand deletion exists today — in every state, for every platform. Most families haven't used it because they haven't heard it exists.
Don't wait for the 2028 audit cycle — close the gap yourself
The mandatory safety audit requirement doesn't apply to apps already in distribution until 2028. Your teenager's current companion chatbot has not passed that standard. Treat that as a gap to close independently — know which apps are running and whether they have any published safety assessment at all.
Get the crisis notifications the law now requires — from day one
California's new laws require platforms to alert parents when minors have crisis-adjacent AI conversations. Most of those requirements phase in over 12–18 months. Families who need those alerts today do not have to wait for platform compliance schedules to catch up to California's mandate.
California's 13 laws send an unambiguous message: the era of unregulated AI access for children is ending. The fines are real. The audit requirements are real. The parental notification mandates are real. But every family who needs the protections those laws describe has to wait for companies to comply — unless they act first. The families who are already protected aren't the ones waiting for a $1 million fine to change a platform's design choices. They are the ones who did not wait.
California made it law. Blaick gives it to your family today.
Start a free 14-day Blaick trial — no credit card required.
Know which AI apps are installed on your child's device. Get crisis alerts when conversations shift into dangerous territory. Have the parental notifications California just mandated — without waiting 12–18 months for platform compliance to catch up to the law.
Start free trial →
Cancel anytime · Trusted by security-conscious families · Built on enterprise AI security