Twelve states have enacted companion-chatbot laws in the past year, each requiring AI-disclosure reminders, a working suicide and self-harm crisis-referral protocol, and limits on content served to minors. AxiSentinel evaluates a companion AI product against whichever state's law its users are actually sitting in.
No state had a companion-chatbot-specific law before 2025. California and New York moved first; ten more states followed within months, each with its own disclosure cadence and enforcement mechanism. A twelfth is awaiting a governor's signature.
A published safety policy is a static document. AxiSentinel is built for what happens in the conversation: continuous evidence that a companion product's crisis-referral protocol actually fires when it should, not just that one exists on paper.
Enactment is state-by-state in the US, and the single most demanding companion-AI rule in force anywhere in the world is not American at all. AxiSentinel tracks the growing list, state and international, the same way it tracks every other patchwork.
The first companion-chatbot statute nationwide, with a private right of action carrying damages of at least $1,000 per violation. Three distinct dates: signed October 13, 2025; core duties operative January 1, 2026; annual reporting begins July 1, 2027.
In force since November 5, 2025; the Attorney General can seek civil penalties up to $15,000 per day, directed to a suicide-prevention fund.
Each enacted its own companion-chatbot statute between December 2025 and early 2026, sharing the same disclosure and crisis-protocol core with different penalty structures.
Rounds out the current group of twelve states with an enacted companion-chatbot law as of mid-2026.
Signed July 14, 2026, rounding out the current group of twelve enacted states. Persistent and session-start disclosure, hourly for minors.
Passed the legislature but was vetoed by the governor. Not law, and not part of the twelve-state enacted count, listed here only so a reader can see what did not survive.
Introduced October 28, 2025 by Sen. Hawley with Blumenthal, Britt and Murphy; cleared the Senate Judiciary Committee unanimously around April 29, 2026 but no floor vote has been scheduled in either chamber.
Orders issued around September 11, 2025 to Alphabet, Character Technologies, Meta, OpenAI, Snap and xAI. An open information-gathering inquiry: no report, complaint, or consent order as of today. Not an enforcement action.
Issued by the Cyberspace Administration of China with four further agencies around April 10, 2026, effective July 15, 2026. The most prescriptive companion-AI rule in force anywhere.
Registered September 9, 2025, enforceable from March 9, 2026. Explicitly names AI companion chatbots and AI companion chatbot features.
Articles 5(1)(a) and 5(1)(b) have applied since February 2, 2025 and prohibit manipulative techniques and the exploitation of vulnerabilities including age. Article 50(1) has applied since August 2, 2026 and requires disclosure that a person is interacting with an AI system.
The Italian data protection authority blocked Replika’s processing of Italian users’ data on February 2, 2023 and fined its maker, Luka Inc., five million euro in 2025 for lack of a lawful basis and absence of age verification. Italy’s national AI law, Law 132/2025, in force from around October 2025, sets a minimum age of 14 for a minor’s consent to AI use.
Eight states restrict AI systems that hold themselves out as therapy or mental-health treatment, a narrower duty than general companion-chatbot disclosure and a different buyer conversation. Keeping the two categories separate is what keeps the twelve-state companion count accurate: Illinois HB 1806 (in force August 4, 2025), Nevada AB 406 (in force June 29, 2025), Utah HB 452 (in force May 7, 2025), Tennessee SB 1580 (signed April 1, 2026, effective July 1, 2026), Maine LD 2082 (signed April 13, 2026, effective July 29, 2026), Colorado HB 1195 (signed June 3, 2026, effective August 12, 2026), Vermont H 816 / Act 156 (June 17, 2026), and Rhode Island H 7349 / S 2197 (June 22, 2026).
From a single companion app to a portfolio of conversational AI surfaces, AxiSentinel evaluates the software and evidence continuously, not just at policy-publication time.
Nothing about AxiSentinel's core architecture changes for companion AI. What changes is which RegDef packages are switched on and what telemetry the agents capture.
Agents capture conversation-safety telemetry on the cadence you configure, always-on or scheduled, in full rather than sampled, and never limited to a quarterly cycle.
Every telemetry event evaluated against the applicable state's disclosure and crisis-protocol requirements, per conversation turn.
Every audit record is linked to the one before it in a signed, tamper-evident evidence chain, verifiable from the first event.
A compliance state change on one companion product or an entire chatbot portfolio propagates network-wide as it happens.
Nothing becomes a compliance finding until a qualified auditor reviews and signs it.
AXI-Node agents deploy across companion, character, and general-purpose chatbot surfaces, with the .axibatch format available for products with restricted API access.
Tracks human involvement in crisis-escalation and content-moderation decisions, feeding into AxiSentinel's oversight-gap scoring model.
The same agents generating compliance evidence watch for jailbreak attempts against safety guardrails, disclosure-suppression prompts, and undisclosed model swaps before a re-certified release reaches production.
New rule, jurisdiction, or requirement is added by encoding new RegDef packages. Deployed agents are never rebuilt.
Scoped to your organization during onboarding, not hard-coded into the platform.
A threshold breach becomes a flagged, timestamped, evidence-linked Provisional Alert, reviewed by a certified human auditor before anything counts as a finding.
The same architecture monitoring this industry's AI monitors a trading desk's model or a hospital's diagnostic AI. What changes is which RegDef packages are switched on.
Twelve states already require the disclosure and crisis-referral protocol this page describes, and a federal bill has cleared committee. AxiSentinel's evidence-chain architecture already generates continuous proof for regulated AI; conversational-AI-specific evidence is a new RegDef surface on the same platform, not a new product.
Whether it's a single companion product or a portfolio of conversational AI surfaces across twelve enacted states, AxiSentinel evaluates it the same way it evaluates any AI system: on the cadence you configure, always-on or scheduled, with full evidence, and with a human signature before anything counts as a finding.