Nothing changed for your child this week. On September 10, 2026, California's governor signed thirteen bills covering AI chatbots, social media feeds, AI toys and school data, and together they are the strictest child-AI rules any state has passed. Almost none of it starts before January 1, 2027. And most of the chatbot protections only reach your family if you link your account to your child's.
That last sentence is the part the coverage skipped, so it is the part I want to spend this post on.
One note before anything else, because one of these laws exists for a hard reason. Adam's Law is named for a teenager who died, and it is built around what a chatbot should do when a child types something frightening. If you are worried about your own child right now, that is a conversation for a person, not a policy: in the United States, call or text 988; in the UK, Samaritans is 116 123 and Childline is 0800 1111. Your family doctor or pediatrician and your school's safeguarding lead can both act, and a chatbot cannot.
What California actually signed
Thirteen bills, announced together on September 10, 2026. The governor's office lists all of them, and four touch a family directly.
SB 1119, Adam's Law, is the big one. It tells companies that run companion chatbots, meaning the ones built to hold a human-sounding conversation rather than answer a support ticket, what they must do when a child is using them. The bill text requires a written crisis response protocol, a referral to real crisis services when a child raises self-harm, and a message to a parent within twelve hours when the company detects serious risk. It requires parental controls that can switch off the chatbot's long-term memory of your child, cap how long they talk to it, and block access altogether for a child under 16. It sets defaults: one hour per conversation, two hours a day, and no push notifications between midnight and 6am or between 8am and 3pm on a school day. It requires the chatbot to keep telling a child, in words a child understands, that it is not a person. And it lets a parent sue.
SB 867 bans the manufacture and sale of toys that contain a companion chatbot. The ban runs, by its own text, until January 1, 2031. A toy here means anything made for play by a child under 18, and the definition of companion chatbot carves out video game characters and plain voice assistants like the speaker in your kitchen.
AB 1709 stops social media companies giving under-16s the features built to keep them scrolling, including algorithmic feeds and autoplay.
A cluster of school bills reaches into your child's classroom: rules on how K-12 pupil data may be used in AI systems, rules on school-issued devices, and digital wellness teaching added to health lessons.
When does any of this actually start?
Not yet, and that is the single most useful thing to know. California bills from a regular session take effect on January 1 following signature unless the bill says otherwise, which puts almost all of this on January 1, 2027. EdSource reported the same date on the day of signing.
Adam's Law is slower still. The version of the bill I read sets most of the duties on chatbot companies running from July 1, 2027, with the independent child safety audits later again, once the Attorney General has written the rules they are audited against.
So: a headline in September, a product change somewhere in 2027, and in between, ten months in which the only protections around your child are the ones you and the platforms have already set up. That gap is where your evening actually is.
The three words that decide whether your family gets any of this
Read the new protections closely and the same condition keeps appearing. The twelve-hour warning goes to a parent if the child's account is linked to a parent's account. The alert when your child switches off a safety setting goes to a parent connected to a child's account. The parental controls exist for a parent who has one.
The If Clause is the three words to look for in any new online safety law: if the account is linked. Adam's Law requires the crisis protocol, the parental controls and the notifications. It does not connect any of them to your phone. That part is still a parent's job, and it takes about ten minutes.
None of this is a loophole. You would not want a law that hands a stranger's phone number your child's private conversations. But it does mean the headline and the reality can sit a long way apart, and the distance between them is one setting in one app.
Pew Research Center surveyed 1,458 US teens aged 13 to 17 and their parents between September 25 and October 9, 2025, and published the results on February 24, 2026. Eighteen percent of parents said their teen does not use AI chatbots, and another 30 percent did not know. Nearly half of American parents, in other words, are not in a position to link an account they do not believe exists. A notification system built on parental accounts reaches the parents who were already paying attention.
Only 18 percent of those parents were comfortable with their teen going to a chatbot for emotional support. It is the one use a majority actively disapproved of, and it is exactly the use Adam's Law was written about. I have written separately about what to do when a teenager is talking to an AI about their feelings. The concern is nearly universal. The account linking is not.
A law can make a company build the alarm. It cannot come into your house and wire it to your phone.
What changes even if you never touch a setting
Some of it lands on every child, linked or not, once the dates arrive.
Default time limits on companion chatbots: one hour in a sitting, two hours a day. No notifications pinging a phone at 2am or in the middle of the school day. Repeated, age-appropriate reminders that the thing being talked to is a machine. A documented crisis protocol behind the scenes and a referral to real help when a child raises self-harm. Companion chatbot toys off the shelves. For under-16s, a social feed that stops being engineered to hold them.
None of that depends on you. All of it depends on the calendar.
Does this reach families outside California?
Probably, and here is my reasoning rather than a promise.
Adam's Law applies to companies making companion chatbots available to users in California, and California is a market no major AI company will exit. Building one version of ChatGPT for Sacramento and another for Denver is expensive and awkward, and what happened after California's privacy law a few years ago is that several large companies decided one build was cheaper than two. My expectation is that most of what is described above quietly becomes the default wherever you live, sometime in 2027.
My expectation is not a protection. If you are outside California, you have no right to the twelve-hour notification and nobody to sue if it never arrives. What you have is a preview of what your child's apps are likely to look like, and ten months to get the account linked before the features show up.
The other reason to read this from Ohio or Ottawa or Oldham: legislatures copy each other. Several states and countries are drafting versions of this right now. The bill Sacramento passed on Thursday is the template.
What I Would Do at Home
I write about this every day, on the podcast and for Forbes, and the honest pattern is that policy news makes parents feel briefly reassured and then changes nothing at the kitchen table. Here is what would actually change something, this week.
Tonight, find out whether the account is linked. In ChatGPT this lives under Settings, then Parental controls, then Add family member. Either of you can send the invite; the other accepts by text or email. Worth knowing before you start: OpenAI's own documentation says parental controls do not give you your teen's conversations, chat history or real-time activity. A safety notification tells you the type of concern, not what was said. If your child unlinks, you get told. That is the whole deal, and I think it is the right deal, but parents who expect a transcript are surprised.
Say why, out loud. A setting imposed in silence gets treated as surveillance and worked around by Friday.
You could say: "I'm turning on the parent link. Not to read your chats, I can't see them. It means if the app thinks something serious is going on, it tells me. I'd rather hear it from the app than not hear it at all."
How that lands depends on the age. Under 8, there is no account to link and no conversation to have: a child that age meets AI through your device, sitting next to you, or not at all. From 8 to 12, the rule I would hold is that the account is yours and they use it with you nearby, which makes the new controls mostly irrelevant and your presence the control. From 13 to 15, link it, say why, and expect to be argued with. From 16 to 18, treat it as a discussion rather than an installation, because a teenager two years away from managing all of this alone needs your reasoning more than your settings.
For an older teenager you could say: "I'm not going to link this behind your back. Here's what it does and what it can't see. Tell me if you'd rather set it up yourself."
Remember what the setting does not cover. From an earlier post here on ChatGPT's parental controls, and it has not stopped being true: controls work in three layers: the account, which is what the app allows; the device, which is what the phone allows; and the conversation, which is what your child tells you. Only the third layer covers the logged-out browser. Adam's Law is an account-layer law. Your child can open a browser in incognito mode and meet an unlinked chatbot in about four seconds.
Ask the school one question. These bills reach school devices and pupil data, and every school in California now needs an answer by January. Ask: which AI tools touch my child's work, and what happens to what my child types into them? Outside California it is the same question with less legal force behind it, and what a parent can actually ask a school for is worth knowing before the meeting.
The AI toy question, before you buy one
The toy ban is written to start on January 1, 2027. Christmas 2026 falls on the near side of it.
So the shelves this December will still hold the products California has decided should not exist, and a legislature deciding to ban a whole category of toy is a reasonable thing to weigh before wrapping one. I have written separately about what to check on an AI toy; the short version is that the questions worth asking are what it records, when it listens, whether the listening can be switched off on the toy itself rather than only in an app, and what happens to your child's recordings if the company is sold.
What these laws cannot do
Age checks are still mostly a child typing a birthday. A determined 14-year-old is 18 in about three seconds, and no statute fixes that.
The crisis protocol is a company process, not a clinician. It can route a child toward help. It cannot assess them, and it cannot sit with them.
The law covers companion chatbots. It does not cover the AI now stitched into search results, homework apps, group chats and the games your child already plays.
And where your school's rules, a platform's own age limit, or a doctor's advice say something different from anything here, they come first. This is a post about a law. It is not advice about your child.
What I am watching next
Whether OpenAI, Google and Meta ship these protections nationally or build a California-only version. Which state copies the bill first. Whether the Attorney General's audit rules have teeth or become a filing exercise. And whether the twelve-hour notification, when it finally arrives in 2027, reaches parents who had no idea their child was using a chatbot at all.
If your child's school has not yet worked out what rules like these mean for its own devices, its own data and what it tells parents, that is the work I do with schools, and a readiness review is where it starts. It is worth forwarding.
I also write a Sunday newsletter that keeps teachers and parents up to date on this without the panic. Parents are very welcome.
And if any of this has raised a worry about your own child rather than a question about the law, please talk to someone who can act: 988 in the United States, Samaritans on 116 123 or Childline on 0800 1111 in the UK, your doctor, or the safeguarding lead at your child's school.
Dan Fitzpatrick is a former assistant headteacher and the founder of The AI Educator. He has trained more than 150,000 teachers across 30 countries and writes about AI in education for Forbes. More about Dan.


