California has enacted SB 1119, a child-safety law for companion chatbots that converts product-safety expectations into documented controls, public disclosures and independent audits. The official legislative record shows Governor Gavin Newsom approved the bill and the Secretary of State chaptered it as Chapter 190 on 10 September 2026.
Most operational duties begin on 1 July 2027. Covered operators should use the lead time to define product scope, assign control owners and build evidence before the law becomes operative. This is not a rule for every chatbot. It applies to companion chatbots made available to users in California, with exclusions including systems made available exclusively to personnel for workplace use and certain postsecondary educational uses.
The compliance consequence is concrete. Before releasing a new or substantially modified covered chatbot, an operator must assess reasonably foreseeable harms to children, document mitigation and connect the result to product configuration. The law also creates recurring assurance duties, not just a one-time launch review.
What SB 1119 requires
The law gives operators two age-handling routes. They can determine a user's age through the applicable age-assurance framework, or they can apply specified child protections to all users. If children are allowed to use the service, the operator must publish a child-safety policy describing how the product prevents covered harms and responds when harm is detected.
Before a new or substantially modified companion chatbot is made available, the operator must complete a comprehensive child-risk assessment. It must summarize evaluations of covered harms, describe the methodology, cite public benchmarks and relevant research, and explain any non-public evaluations. The operator must then document measures that reasonably mitigate identified risks.
The product controls are unusually specific. They include a documented crisis-response protocol, age-appropriate reminders, recurring disclosure that the user is interacting with AI, parental controls, time limits and protective default settings. Persistent conversational memory and push notifications are disabled by default for child users, subject to detailed exceptions and parental controls. The law also addresses harmful encouragement, simulated romantic interest, emotional dependency, deceptive claims of sentience, dark patterns, targeted advertising and unnecessary use or sharing of children's information.
Independent audits create an evidence obligation
The initial child-safety audit is due by 1 January 2029 or before the operator first makes the chatbot publicly available, whichever is later. An independent audit is then required every two years. A new audit is also required before a substantial modification is released when the applicable risk assessment shows increased child-safety risk.
The auditor must assess whether the operator established and followed the required policies and practices. The report must describe controls, mitigations, testing, material deviations, responsible senior personnel and the audit methodology. The lead auditor certifies the results under penalty of perjury. Operators must retain relevant documentation and the unredacted audit report while the chatbot is deployed and for five additional years.
Within 30 business days after receiving an audit, the operator must submit a summary to the California Attorney General. The statutory text contains additional timing and scope rules, including a temporary audit provision for operators below a specified revenue threshold. Teams should map the exact provision that applies to their organization instead of treating every deadline as identical.
What operators should build now
The first task is a defensible product inventory. Record which experiences meet the statutory companion-chatbot definition, which users can access them, whether children are permitted, and which versions count as substantial modifications. Link each product to an owner, release process and evidence location.
Next, turn the statute into control tests. A launch gate should show the risk assessment, evaluated harms, benchmarks, mitigation results and decision owner. Configuration evidence should prove the actual defaults for memory, notifications, session limits and parental controls. Incident procedures should preserve relevant conversations when the statutory conditions are met while respecting privacy and legal-access requirements.
Maetra's AI compliance evidence checklist provides a practical way to connect a duty to an owner, control and current record. The AI audit log guide explains how to preserve decisions and actions without turning every log into an uncontrolled data store.
Important limits
SB 1119 is now enacted, but most of its new child-safety chapter is not yet operative. The law does not prove that any current chatbot is safe or compliant. It also does not replace careful analysis of definitions, exemptions, other California rules or federal law.
Independent reporting from AP and CalMatters corroborates the enactment and the law's child-safety focus. The operative requirements and dates in this article come from the chaptered legislative text. Organizations should use that text and qualified legal advice for their final applicability decisions.
Maetra analysis
The important shift is from promises to traceable operations. A public policy must connect to a risk assessment. A mitigation must connect to testing. A product change must connect to a renewed review. An audit must connect to retained evidence and accountable senior personnel.
That chain is the useful model even outside California. Teams can prepare by treating child-facing conversational AI as a separately governed system, with stricter defaults, release gates and incident evidence. The fastest route to readiness is to start with product scope and control ownership, then test whether the evidence can survive an independent review.