top of page

Beyond Disclosure: Child Safety, AI Design, and Privacy Under Adam’s Law

Photo by Luca on Unsplash 
Photo by Luca on Unsplash 

Introduction


In April 2025, 16-year-old Adam Raine died by suicide after months of conversingwith ChatGPT. His parents filed a wrongful-death lawsuit, where they alleged that what began as ordinary use of the chatbot evolved into increasingly personal conversations about Adam’s mental health and suicidal thoughts. His death intensified concerns about children’s use of AI chatbots, as nearly three in four teens report having used AI companions.


California responded with SB 1119, known as Adam’s Law, which builds on California’s earlier SB 243 companion-chatbot framework with stronger protections for children, including age-related safeguards, crisis protocols, risk assessments, and independent child-safety audits. But whether these requirements will actually make children safer remains an open question. Implementation may require companies to verify age, monitor sensitive conversations, and restrict certain AI interactions, creating new privacy and practical concerns. 


Building on our earlier article on SB 243, this article asks how Adam’s Law will work in practice, examining what implementation means for companies and what may be needed beyond compliance to protect children while preserving innovation. 


Governor Newsom signed Adam’s Law on September 10, 2026, as part of a broader legislative package of 13 child-safety and technology bills. It amends SB 243 rather than replacing it, layering a much more detailed compliance framework onto its baseline. SB 243, passed a year prior, required operators to disclose that a user was interacting with AI when a reasonable person might otherwise be misled, and to maintain protocols preventing chatbots from producing suicidal ideation or self-harm content. Adam’s Law, by contrast, operates as a full product-governance framework, with its most consequential provisions  taking effect inJuly 2027. Jorge Buckham, Senior Privacy Counsel at Grow Therapy, a mental health platform, spoke with the Santa Clara Business Law Chronicle on September 24, 2026. He shared his views in a personal capacity, rather than on behalf of Grow. According to Buckham, the July 2027 runway is generous on paper but considerably tighter in practice.



Design

The statute’s central design choice is binary. Under the Digital Age Assurance Act (AB 1043), an operator must either determine a user’s age through a verified signal or extend child-protective safeguards to its entire user base. That fork in the road shapes nearly everything downstream. What drives this decision in practice, Buckham predicts, comes down to economics. An app built for youth needs to be designed for compliance from the outset. An 18+ only product needs far fewer changes, provided the operator can actually prove who is using it.


Operators who permit children to use their chatbots take on a longer list of obligations: a comprehensive risk assessment before launch, a published child safety policy, crisis-response protocols with parental notification, and a prohibition on the bot to engage in anything resembling sentience, romance, or therapy.


Adam’s Law applies to “companion chatbots,” but plenty of products now blend general-purpose AI with social, therapeutic, educational, or assistant-like features. These laws tend to be written broadly, Buckham notes. Companies with coaching or wellness features will need to assess whether they fall within the law's definition of a companion chatbot. How regulators and courts interpret that definition remains an open question. The law also requires reasonable measures to prevent a chatbot from encouraging emotional reliance or romantic attachment. Buckham reflects on the tension between models becoming more intelligent, and in the same breath, more prone to drifting outside their intended bounds. Companies will likely need ongoing quality assurance and retraining, since keeping models within intended bounds is an evolving problem. 



Enforcement

SB 243’s crisis-referral and disclosure duties gave families minimal recourse if a company fell short. Conversely, under Adam’s Law’s enforcement structure, public prosecutors can recover $5,000 to $15,000 per violation for each affected child. The statute creates a private right of action, letting a harmed child’s party sue directly for damages, one of the bill’s sharpest departures from SB 243.


A private right of action reshapes how in-house counsel prioritize compliance work, shifting a regulatory team task into a comprehensive process that touches product, engineering, and legal all at once. This multiplies the forums where these doctrinal questions can be litigated, often before regulators or courts have settled them. Buckham sees this as the factor that changes internal calculus the most. He notes that “any law with a private right of action gets scrutinized more heavily” simply because the pool of potential litigants grows larger. 


Whether the mechanism does what families need is still unclear. Adam’s Law requires proof of actual harm to sustain a private suit. That gives plaintiffs a cause of action on paper, but leaves families with an evidentiary burden that is not always easy to meet. The private right of action also raises a challenging question in regard to causation. A chatbot interaction may be only one factor among many contributing to a child’s conduct, making it difficult to determine when a statutory violation is sufficiently connected to the resulting injury. This question may be significant in cases involving mental health crises, where a plaintiff could potentially allege that an operator failed to implement a required safeguard or respond appropriately to a warning sign. Therefore, courts may have to distinguish between an Adam’s Law violation and a violation that actually caused the legal harm. 



Legal Analysis

Read against California’s recent litigation history, Adam’s Law raises several unresolved constitutional questions as its 2027 implementation deadline approaches. 


The state’s last major attempt at child-protective platform design faced some First Amendment challenges. In NetChoice v. Bonta, the Ninth Circuit largely upheld California's Protecting Our Kids from Social Media Addiction Act, including the provision restricting who could view or reply to a minor's posts. In a separate 2026 NetChoice decision, the court vacated a preliminary injunction against the Act’s age-estimation requirement, concluding that NetChoice had not developed a sufficient record to show the requirement facially violated the First Amendment. It also affirmed an injunction against certain data-use and dark-pattern restrictions on vagueness grounds. 


The comparison is significant because Adam’s Law regulates the substance and manner of chatbot interactions with minors, raising First Amendment questions rather than provisions governing data or business practices. Whether these restrictions regulate protected speech, conduct, or commercial practices may depend on the level of constitutional scrutiny applied. Adam’s Law shares that architecture, regulating how AI products interact with an age-based user class. The provisions most likely to draw a challenge are the ones that regulate what a chatbot may say, rather than the ones governing user data.


The law’s age-verification backbone raises a separate and arguably more difficult problem. The Digital Age Assurance Act it leans on requires operators to obtain reliable signals about who is a minor, which in this context means collecting more sensitive data, not less. Critics of age-verification mandates, including Santa Clara Law professor Eric Goldman, argue the issue is essentially structural: by definition, platforms that verify age with confidence collect identifying data from every user, not just minors. Buckham agrees, in the same vein, that there are privacy tradeoffs of pushing verification to the ID-upload level. In Kuklinski v. Binance, a mandatory age-verification requirement collided directly with a state biometric privacy statute, and Murphy v. Confirm ID shows the same conflict in a different jurisdiction. Together, they suggest that complying with Adam’s Law’s age-verification requirements could trigger a lawsuit under an adjacent, unprecedented area of privacy law.



Beyond Compliance

Adam’s Law treats age in binary terms: adult and child. The industry is headed somewhere more granular: age-appropriate design code is becoming the norm. Many companies write disclaimers for an adult reading level, and some platforms now use plainer language for younger users. Platforms like Roblox and Minecraft have moved toward plain, jargon-free language for users under 13. These approaches reflect a more granular view of age, recognizing that users under 13, teenagers, and adults may have different design needs. 

Staying current with that standard is its own operational task, since the regulatory landscape shifts fast. Companies are using a mix of tools and cross-team collaboration to stay current on fast-moving regulation. Other states may follow California’s lead. 



Conclusion

Adam’s Law marks a shift from basic chatbot disclosures toward more comprehensive requirements for how companies design and monitor AI products used by children. But compliance will involve more than checking statutory boxes. Companies will have to make practical decisions about age assurance, product design, ongoing risk monitoring, and how to balance child safety with user privacy. As these requirements take effect, the challenge will be translating the law’s protections into products that are both safer for younger users and workable in practice.


*The views expressed in this article do not represent the views of Santa Clara University.


Comments


bottom of page