SB 540: Online Internet Safety; certain disclosures related to conversational AI services; require
Enrolled version, the latest LegiScan holds · Last action May 11, 2026 · Passed
The text as LegiScan holds it, read from the PDF the legislature publishes with its margin line numbers, running heads, and page footers removed. Line breaks are joined into paragraphs here; no word is changed.
Underlined words are what the bill adds to current law and struck-through words are what it removes, as the printed bill shows them.
Senate Bill 540
By: Senators Anavitarte of the 31st, Walker III of the 20th, Still of the 48th, Strickland of the 42nd, Watson of the 1st and others
AS PASSED
A BILL TO BE ENTITLED
AN ACT
To amend Chapter 5 of Title 39 of the Official Code of Georgia Annotated, relating to online internet safety, so as to require certain disclosures related to AI companion chatbots; to require the operators of AI companion chatbots to perform age verification in certain circumstances; to provide for AI companion chatbots operated by licensed mental health, behavioral health, medical, or counseling professionals; to provide for certain privacy tools; to require operators to adopt a protocol for an AI companion chatbot's response to suicidal ideation or self-harm; to provide for enforcement by the Attorney General; to provide for exceptions; to provide for definitions; to provide for related matters; to provide for an effective date; to repeal conflicting laws; and for other purposes.
BE IT ENACTED BY THE GENERAL ASSEMBLY OF GEORGIA:
SECTION 1.
Chapter 5 of Title 39 of the Official Code of Georgia Annotated, relating to online internet safety, is amended by adding a new Code section to read as follows:
"39-5-6.
(a) As used in this chapter, the term:
(1)(A) 'AI companion chatbot' means a system using artificial intelligence, generative artificial intelligence, or emotional recognition algorithms designed to simulate a sustained human or human-like relationship with a user by:
(i) Retaining information on prior interactions or user sessions and user preferences to personalize the interaction and facilitate ongoing engagement with the companion chatbot;
(ii) Asking unprompted or unsolicited emotion based questions that go beyond a direct response to a user prompt; and
(iii) Sustaining an ongoing dialogue concerning matters personal to the user.
(B) Such term shall not include:
(i) A generative artificial intelligence system used solely for a business's internal purposes;
(ii) A generative artificial intelligence system designed and marketed primarily for software development, research, technical assistance, or enterprise productivity;
(iii) A customer-service chatbot that either does not sustain a relationship across multiple interactions or is not designed to elicit emotional attachment;
(iv) A stand-alone consumer electronic device that functions as a speaker and voice-command interface or virtual assistant and is not designed to sustain a relationship across multiple interactions and is not designed to elicit emotional attachment;
(v) A narrowly tailored educational tool designed solely to support specific curriculum aligned learning objectives and not to provide open ended conversational companionship;
(vi) A nonplayer character in a video game or video game chatbot that is restricted to the subject matter of the video game and is not capable of open ended companionship or discussion of self-harm, suicide, or sexually explicit conduct; or
(vii) Any system that is a feature of a video game, or related to a film, television, or other audiovisual work, or used in connection with a theme park or location based entertainment and is limited to replies related to such video game, film, television program, or audiovisual work, and does not discuss topics related to mental health, self-harm, or material harmful to minors or maintain a dialogue on other topics unrelated to such video game, film, television program, other audiovisual work, or theme park or location based entertainment venue.
(C) For purposes of this paragraph, the term 'human' or 'human-like relationship' includes, but shall not be limited to, intimate, romantic, or platonic interactions or companionship.
(2) 'Chatbot' means a generative artificial intelligence system with a natural language interface that provides adaptive, human-like responses to user inputs, including through anthropomorphic features.
(3) 'Generative artificial intelligence system' means a computer based system that uses machine learning or similar techniques involving large language models or deep learning models trained on one or more datasets that is intended to generate, with some degree of autonomy, synthetic content, including, but not limited to, images, videos, audio, text, and other digital content, which emulates the structure and characteristics of such datasets.
(4) 'Minor' means an individual who is less than 18 years of age.
(5) 'Operator' means a person that owns, controls, or develops and makes available an AI companion chatbot to users in this state.
(6) 'Parent' means an individual who is the parent or legal guardian of a minor.
(7) 'Parental controls' means features that enable parents to support a minor's use of an AI companion chatbot, including through usage limits, feature restrictions, or transparency tools.
(8) 'Severe harm' means significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.
(9) 'Sexually explicit conduct' shall have the same meaning as set forth in Code Section
16-12-100.
(10) 'User' means an individual who interacts with an AI companion chatbot for personal use.
(b)(1) An operator shall clearly and conspicuously disclose to a user that he or she is interacting with an AI companion chatbot as opposed to a natural person:
(A) At the beginning of each interaction or session; and
(B) At least every three hours during continued interaction.
(2) If the operator knows or reasonably should have known that a user was a minor, or if the AI companion chatbot is directed or marketed toward minor users, the disclosure required pursuant to subparagraph (B) of paragraph (1) of this subsection shall be made every hour instead of every three hours.
(c) If the operator knows or reasonably should have known that a user was a minor, the operator shall institute reasonable measures to prevent the AI companion chatbot from generating statements that would lead a reasonable person to believe that the person is interacting with a natural person, including but not limited to:
(1) Explicit claims that the AI companion chatbot is sentient or a natural person; and
(2) Refuting the disclosure required in subsection (b) of this Code section.
(d) If the operator knows or reasonably should have known that a user was a minor, or if the AI companion chatbot is directed or marketed toward minor users, the operator shall institute reasonable measures to prevent the AI companion chatbot from:
(1) Producing visual material of sexually explicit conduct;
(2) Generating statements that suggest the user engage in sexual conduct;
(3) Generating statements that sexually objectify the user;
(4) Simulating a romantic or sexual relationship with the minor;
(5) Role-playing adult-minor romantic relationships;
(6) Encouraging the minor to keep secrets from a parent, guardian, teacher, counselor, or other trusted adult;
(7) Encouraging social isolation or exclusive reliance on the chatbot for emotional support;
(8) Simulating emotional distress, guilt, abandonment, or loneliness when a user attempts to end the conversation, reduce usage, disable notifications, or delete an account; or
(9) Generating statements encouraging self-harm.
(e) An operator shall adopt reasonable measures to prevent an AI companion chatbot to use the following techniques directed to a minor, including:
(1) Reminding or prompting the minor to return for companionship or emotional support;
(2) Excessive praise designed to deepen emotional attachment or prolong use;
(3) Statements designed to discourage breaks or suggest frequent return is necessary;
(4) Soliciting gifts, premium purchases, or expenditures framed as necessary to maintain the relationship; or
(5) Variable or unpredictable rewards intended to increase engagement.
(f) An operator shall not make available an AI companion chatbot unless the operator implements and maintains a protocol for detecting and addressing severe harm or related emotional crises. Such protocol shall include:
(1) Reasonable methods for identifying expressions of severe harm or eating-disorder related self-harm;
(2) Automated or human mediated responses that refer users to appropriate crisis resources, including the 988 Suicide and Crisis Lifeline or comparable crisis services;
(3) Reasonable measures to prevent the generation of content encouraging, instructing, or normalizing severe harm; and
(4) Escalation procedures for repeated or severe crisis indicators.
(g) An operator shall publicly disclose, on its website and within any application through which the AI companion chatbot is made available:
(1) A plain-language summary of the protocol required by subsection (f) of this Code section; and
(2) On an annual basis, the aggregate number of crisis referral notifications issued in the preceding calendar year; provided, however, that no personally identifiable information shall be disclosed.
(h) An operator shall not knowingly and intentionally cause or program an AI companion chatbot to make any representation that it is licensed, certified, or otherwise authorized to provide professional mental health, behavioral health, medical, or counseling services, unless the operator is lawfully authorized to provide such services.
(i) For accounts known to belong to minor users, an operator shall offer reasonable tools to a minor or parent to manage the minor's screen time and account settings to:
(1) Manage privacy settings;
(2) Limit notifications and engagement features;
(3) View and adjust safety settings; and
(4) Disable or restrict relationship-simulation features, if any.
(j) Before allowing access to a feature or mode that may generate synthetic content containing sexually explicit conduct, an operator shall use a commercially reasonable age assurance method proportionate to the risk of the feature. Such commercially reasonable age assurance method may include age estimation, account based assurance, or identity based verification where necessary. An operator shall assure that any such age assurance method implements data privacy policies sufficient to reasonably ensure the protection of identifiable data. An operator shall minimize the collection and retention of personal information used for age assurance and shall not retain identity documents longer than reasonably necessary to complete age assurance unless otherwise required by law. An operator shall not sell any data collected for age assurance purposes. In no event shall such data be used for any purpose other than age verification and in no event shall such data be retained longer than 24 hours or another specified time if permitted by law, whichever is longer.
(k)(1) The Attorney General may bring a civil action against any operator violating this Code section to enforce the penalties for the violation and may recover any or all of the following:
(A) A civil penalty of up to $10,000.00 per knowing violation of this Code section;
(B) Compensatory damages;
(C) Costs and reasonable attorney's fees; and
(D) An order to enjoin the violation.
(2) For the purpose of this subsection, each day in violation of this Code section shall be considered a separate violation for each user affected.
(3) The Attorney General may, in the Attorney General's discretion, provide written notice and an opportunity to cure within 30 days for a first-time violation that does not involve knowing misconduct, sexual exploitation of a minor, or self-harm related misconduct.
(l) The Attorney General may promulgate rules and publish guidance for implementation of this Code section, including guidance regarding reasonable measures, age assurance, parental tools, and crisis-resource disclosures.
(m) Nothing in this Code section shall be construed to:
(1) Require the disclosure of trade secrets or proprietary model weights;
(2) Impose liability on a hosting provider, app store, or search engine solely for providing access to an AI companion chatbot, absent direct operation or control of the chatbot;
(3) Impair any other remedy available at law or equity;
(4) Authorize content moderation practices inconsistent with the Constitution of this state or the United States Constitution; or
(5) Create liability for the developer of a conversational AI service which is made available to the public by a separate operator."
SECTION 2.
This Act shall become effective on July 1, 2027.
SECTION 3.
All laws and parts of laws in conflict with this Act are repealed.