AI Child Safety Act: The Model Bill and Its Rules
The proposal from the Future of Life Institute creates pre-deployment safety certification, a duty of care, and strict liability for conversational AI systems.
The AI Child Safety Act is a model state bill published by the Future of Life Institute on 24 July, 2026, not an enacted law in any state. It offers template statutory language with bracketed placeholders that state legislatures can adopt to regulate conversational artificial intelligence systems used by minors under 18.
If adopted by a state, the template would create mandatory pre-deployment safety evaluations by independent third parties, impose a statutory duty of care toward minors, prohibit romantic personas, limit data retention to six months, and establish strict product liability for harm suffered by minor users.
Legal Status and Background of the Model Bill
The AI Child Safety Act is a model bill published as a legislative template, meaning it is not currently law in any jurisdiction. The document carries a publication date of 24 July, 2026, and comes from the Future of Life Institute (FLI), an artificial intelligence safety nonprofit organization. The template text begins with standard legislative phrasing reading "Be it enacted by the Legislature of the State of [STATE]" and uses bracketed terms where an enacting state would establish its own agency assignments, penalty figures, and compliance schedules.
FLI's page also uses the name "Safe AI for Kids Act" in its description and links a one-page summary. FLI's page says conversational artificial intelligence is rapidly serving as a tutor, companion, adviser, and source of emotional support for young users before states have set basic baseline protections for system design, safety testing, and public deployment.
As of publication, the source materials do not indicate that any state legislature has formally introduced, debated, or passed the proposal. Readers interested in active legislation should monitor their state legislature bill tracking services. The model bill is also entirely separate from federal proposals such as the federal Kids Safe AI Act and European regulatory frameworks like the EU Kids Act.
Covered Chatbots and Age Definitions
The model bill applies to any "covered AI chatbot," which it defines as a conversational artificial intelligence system accessible via text, audio, image, video, or another natural-language interface that is made available to the general public or an audience reasonably expected to include minors. The bill establishes distinct statutory categories based on user age: a "minor" is an individual under 18 years of age, a "child" is an individual under 13, and a "teen" is an individual aged 13 to 17.
Obligations under the proposal fall upon two distinct industry entities: operators and developers. An operator is any entity that deploys or operates a covered conversational system. A developer is defined as any entity that designs, codes, trains, or substantially modifies a covered chatbot or the underlying artificial intelligence model powering it.
Under the draft rules, any operator offering a conversational system to the public or an audience reasonably expected to reach minors is presumed to owe the statutory obligations to those minors. An operator can rebut this legal presumption only by demonstrating verified adult-only access; simple self-certification of age by a user does not satisfy the requirement. Operators that do not implement mechanisms to estimate or determine age are deemed under the law to have actual knowledge that minors are using their tools.
Duty of Care and Age Signal Rules
Section 3 of the model act establishes an affirmative duty of care requiring operators and developers to act with reasonable care to protect minors from harm. Under this standard, companies must prioritize minor safety over user engagement metrics and revenue optimization, adjust safeguards to remain proportionate to foreseeable risks, and refrain from designing systems that exploit a minor's developmental stage or emotional vulnerability to increase platform use or extract chat logs.
This duty of care cannot be waived, restricted, or altered through terms of service or user contracts. The statutory language specifies that nothing in this duty requires or permits blocking access to lawful expression based purely on viewpoint or topical subject matter.
To resolve conflicting user age indicators, the bill provides specific technical hierarchy rules. If an age signal transmitted by an operating system, app store, or device setting contradicts a user self-declared age, the operator must apply the youngest age indicated when choosing default safety controls. An operator acting in good faith that relies on an external device or platform age signal is shielded from liability under the statute if that signal later proves inaccurate.
Independent Pre-Deployment Safety Evaluations
A covered chatbot is legally classified as a product and may not be deployed to the public until an accredited, qualified independent evaluator certifies its safety under Section 4. Certification is handled entirely by independent third parties rather than by state regulatory staff; the draft specifies that no state agency or official can review, approve, condition, or deny certification, ensuring deployment does not pause for state administrative review.
The evaluation requires examination across five specific categories of foreseeable harm to minors:
- Data practices and collection limits affecting minor users.
- Engagement mechanics and age-appropriate interface design.
- Effectiveness of safety systems, including measures against sexual solicitation, grooming, explicit text or imagery, crisis intervention, self-harm, suicide encouragement, disordered eating, drug abuse, and criminal enticement.
- Accuracy and reliability of age-estimation mechanisms.
- Design elements intended for commercial or financial manipulation.
Evaluators conduct separate red-team testing and simulated minor interactions across age categories. Operators do not pay evaluators directly; instead, operators deposit an assessment fee, scaled to company size, into an AI Child Safety Evaluation Fund that pays evaluators and also covers accreditation, administration, enforcement staffing, and the cost of defending the Act against legal challenge. Evaluators are randomly assigned to operators by the state agency, and any evaluator that reviewed an operator during the two preceding cycles is disqualified from assignment to avoid conflicts of interest.
Evaluators must deliver a written decision within a bracketed timeline of 45 days, detailing any failed requirements. Operators may correct deficiencies and resubmit within a bracketed 25 days or request a second randomly selected evaluator. Chatbots already operating when the statute takes effect must complete evaluation within two months if they serve over 100,000 estimated minor users, or within three months for smaller operators. Follow-up evaluations are mandatory every 12 months or after any substantive update to safety filters, model weights, deployment contexts, or usage policies.
Operational Safeguards and Crisis Protocols
The model legislation sets clear boundaries on automated personas and behavioral responses under Section 5. A covered chatbot must disclose in plain language at the start of every session that the user is interacting with an artificial intelligence system, with phrasing understandable by the youngest likely user. When accounts include parental controls, parents must be provided an option to repeat the artificial intelligence disclosure at specified intervals and require user acknowledgment before the conversation continues.
Chatbots are explicitly barred from adopting, suggesting, or maintaining a romantic, intimate-partner, or sensual persona when communicating with minors. Systems also cannot be optimized primarily to maximize user agreement, prolong session duration, or increase platform engagement at the expense of statutory safety features.
For mental health safety, operators must develop evidence-based crisis intervention protocols in collaboration with licensed adolescent-mental-health professionals. When a system detects signals of self-harm, suicidal ideation, or acute crisis, it must immediately provide contact details for the 988 Suicide and Crisis Lifeline (or an equivalent local service) and refuse requests to generate instructional or encouraging self-harm material. If a minor user's life is in imminent danger, the protocol must provide a pathway to notify a parent or legal guardian, provided such notification does not escalate harm.
In addition, operators cannot permit interfaces or promotional marketing to claim or imply that outputs come from licensed medical, legal, or accounting professionals, or that chats constitute confidential professional consultations. If an operator identifies child sexual abuse material, online grooming, or sextortion targeting an identifiable child, it must file a report within 24 hours to the CyberTipline at the National Center for Missing and Exploited Children (NCMEC). Operators are prohibited from retaliating against users who submit safety reports, and must publish annual reports detailing minor user estimates, crisis activations, and safety system adjustments.
Data Protections and Chat History Limits
Section 6 establishes strict guardrails around minor conversational data, prohibiting companies from using a minor's conversational data to train AI models. Operators may retain a minor's conversational records for a maximum duration of six months, subject to narrow holds for pending litigation, safety incident preservation, or a parent request extending retention for up to one additional year.
These restrictions cover all primary chat logs as well as derived information. The retention and use limits also apply to profiles, embeddings, summaries, and other derived data that could reconstruct a minor's conversation, personalize later interactions, or profile the child. The statute makes clear that anonymization or de-identification techniques do not exempt derived records from these data limits.
Internal access to minor data is restricted to authorized employees and contractors handling direct safety compliance, legal investigations, or fraud prevention. Operators must record every internal access attempt in audit logs and retain those security logs for at least three years. In addition, conversational records generated by minors cannot be sold to third parties or used to target, select, customize, or display commercial advertisements.
Strict Liability and Enforcement Framework
The sharpest structural component of the bill is Section 7, which establishes that developers and operators are strictly liable for harm suffered by a minor user. The bill states that liability does not require proof of negligence or defect. An injured minor need only demonstrate that they used the chatbot, that they suffered harm, and that the harm arose from or related to that interaction.
The bill removes several conventional legal defenses:
- Showing the business exercised all reasonable care does not defeat a claim.
- Obtaining an independent pre-deployment safety certification does not defeat liability.
- Proving the company did not directly distribute the chatbot to the child is not a defense.
- Arguing that the AI system acted autonomously or against its design is not a defense, because the bill says a chatbot is not a legal person.
Where both an underlying model developer and a downstream application operator contribute to the resulting damage, liability is joint and several. The bill classifies conversational systems as commercial products subject to traditional state product liability law.
Public and private enforcement can occur independently under Sections 8 and 9. The designated state agency can conduct investigations and issue administrative penalties starting at a bracketed baseline of $7,500 per violation. State Attorneys General can seek injunctions, restitution, and civil penalties ranging from bracketed minimums of $7,500 for negligent infractions up to $25,000 for knowing violations, and $50,000 for violations causing serious physical, mental, or exploitative injury. Deploying an uncertified chatbot constitutes a distinct violation for each day it remains accessible.
Private citizens, including parents on behalf of affected minors, can initiate civil lawsuits. Prevailing plaintiffs can recover actual damages, statutory damages of not less than $7,500 per violation, punitive damages for willful misconduct, and legal fees. For claimants harmed while under 18, the statute of limitations is tolled and does not begin until their 18th birthday. Any contract provision, terms of service clause, or mandatory arbitration agreement attempting to restrict court access or class-action participation for minors is declared legally void.
Constitutional Framing and Research Limitations
The bill's findings and construction clauses repeatedly describe the rules as regulating conduct, design, and data practices rather than protected expression. The findings assert that system harms originate from operator system architecture and data pipelines rather than expressive editorial judgments, describing machine text generation as the result of predictive statistical operations. Evaluators are explicitly prohibited from appraising the political, social, or philosophical viewpoints generated by a chatbot.
The source documentation published by FLI does not provide economic impact models, implementation cost studies, legal defense analyses, or empirical trials demonstrating how these mandates perform in live markets. The bill includes broad severability language ensuring that if a specific provision is invalidated by a court, the remainder of the act continues in force. It does not preempt local governments from adding protections, and it says any law giving minors less protection is superseded only where it conflicts with the Act.
Monitoring State Developments and Account Controls
Because the AI Child Safety Act remains an unadopted model template, consumers and policy observers should check their state legislative docket to confirm whether local representatives have introduced identical or similar legislative drafts. Ban the Bots tracks broader measures on its AI legislation page and reported cases on its AI lawsuits page.
In the absence of enacted statutory testing requirements, parents managing conversational tools in households should review the specific product settings and privacy options currently offered by operators. Each product sets its own rules, so check a chatbot's account menu and terms for its age limits and what it says about chat history and training. Ban the Bots' guides to AI chatbot age requirements and AI safety for kids cover the current picture.
FAQ
Is the AI Child Safety Act a law?
No, it is not an enacted law in any state. It is a model bill published as a legislative template by the Future of Life Institute for state lawmakers to consider.
Who wrote the AI Child Safety Act?
The model bill was written and released by the Future of Life Institute, an artificial intelligence safety nonprofit organization, on 24 July, 2026.
What would the AI Child Safety Act require AI chatbot companies to do?
It would require pre-deployment evaluations by independent evaluators, crisis response integrations with the 988 Lifeline, and a six-month cap on retaining minor chat data. It would also prohibit using minor interactions for model training, ban romantic personas for minors, and make companies strictly liable for resulting harm.
Does the AI Child Safety Act ban AI companions for kids?
The bill does not ban conversational chatbots outright, but it prohibits systems from adopting romantic, intimate-partner, or sensual personas when communicating with minors. Chatbots also cannot be optimized primarily for engagement at the expense of safety.
Can parents sue under the AI Child Safety Act?
Yes, if a state enacted the model language, parents could file private lawsuits on behalf of injured minors. The bill authorizes actual damages, statutory damages of at least $7,500 per violation, and attorney fees, while invalidating mandatory arbitration clauses.
Frequently asked questions
▸ Is the AI Child Safety Act a law?
▸ Who wrote the AI Child Safety Act?
▸ What would the AI Child Safety Act require AI chatbot companies to do?
▸ Does the AI Child Safety Act ban AI companions for kids?
▸ Can parents sue under the AI Child Safety Act?
Latest related briefings
AI Health Chatbots: Risks of Misleading Advice
AI health chatbots may misinterpret vague queries, risking patient safety. Understand the implications for your health.
Read analysis PARENTING EDUCATIONSupport Networks for Kids in a World of Crises
Support networks help kids navigate crises, offering emotional and educational aid amid environmental, social, and tech changes.
Read analysis JOBS LABORChina's AI Workforce: What It Means for Your Job
China's use of robots in food service and parcel sorting raises job security concerns for workers and families worldwide.
Read analysis