Georgia AI Companion Chatbot Safeguards (SB 540)

Jurisdiction:
Georgia
enacted
Effective:
Jul 1, 2027
Authority:
Georgia Attorney General
Official text

Obligations Covered

Transparency & Disclosure Risk Assessment Incident Reporting Human Oversight Data Governance

Timeline

MilestoneDateNotes
Senate passed by substituteMar 6, 20262025-2026 Regular Session
House passed by substituteMar 25, 2026Rules Committee substitute (LC 64 0123S)
Senate agreed to House substituteMar 27, 2026Final passage as SB 540/AP
Sent to GovernorApr 10, 2026
Signed by the GovernorMay 11, 2026Act 518, Ga. L. 2026
EffectiveJul 1, 2027Section 2 of the Act; no phased rollout

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

AI Companion Chatbot Disclosure #

Obligation:
Transparency
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators — persons that own, control, or develop and make available an AI companion chatbot to users in Georgia (§ 39-5-6(a)(5)). An AI companion chatbot is a system using AI, generative AI, or emotional recognition algorithms designed to simulate a sustained human or human-like relationship by retaining prior-interaction information to personalize engagement, asking unprompted emotion-based questions, and sustaining ongoing dialogue on matters personal to the user — all three conjunctively (§ 39-5-6(a)(1)(A)). Excluded: internal business systems; systems marketed primarily for software development, research, technical assistance, or enterprise productivity; customer-service bots that neither sustain a cross-session relationship nor elicit emotional attachment; stand-alone speaker/voice-assistant devices; narrowly tailored curriculum-aligned educational tools; video-game non-player characters restricted to game subject matter; and video game, film, television, audiovisual, theme-park, or location-based entertainment tie-ins (§ 39-5-6(a)(1)(B))
upcominghigh-impact
The three-limb definition in § 39-5-6(a)(1)(A) is conjunctive — memory, unprompted emotional questioning, and sustained personal dialogue must all be present — which is a narrower gate than California SB 243's reasonable-person test, but the recurring-disclosure cadence is stricter: every three hours generally, every hour for known or marketed-to minors. Subsection (h) is the only place the Act addresses licensed professionals: it bars an operator from programming a chatbot to claim mental health, behavioral health, medical, or counseling licensure unless the operator is lawfully authorized to provide those services. That is a proviso, not an exemption — a licensed clinician's companion chatbot is still fully subject to § 39-5-6.

Requirements

RequirementDetails
Session-opening disclosureClearly and conspicuously disclose to the user that they are interacting with an AI companion chatbot as opposed to a natural person, at the beginning of each interaction or session (§ 39-5-6(b)(1)(A))
Three-hour recurring disclosureRepeat the disclosure at least every three hours during continued interaction (§ 39-5-6(b)(1)(B))
Hourly disclosure for minorsWhere the operator knows or reasonably should have known the user is a minor, or the chatbot is directed or marketed toward minor users, repeat the disclosure every hour instead of every three hours (§ 39-5-6(b)(2))
Anti-personhood measures for minorsFor users known or reasonably knowable to be minors, institute reasonable measures to prevent the chatbot from generating statements that would lead a reasonable person to believe they are interacting with a natural person, including explicit claims of sentience or personhood and statements refuting the required disclosure (§ 39-5-6(c)(1)-(2))
No false claim of clinical licensureDo not knowingly and intentionally cause or program the chatbot to represent that it is licensed, certified, or otherwise authorized to provide professional mental health, behavioral health, medical, or counseling services unless the operator is lawfully authorized to provide such services (§ 39-5-6(h))

Penalties

ViolationFine
Attorney General civil actionCivil penalty of up to $10,000 per knowing violation, compensatory damages, costs and reasonable attorney's fees, and an order enjoining the violation (§ 39-5-6(k)(1))
Per-day, per-user accrualEach day in violation counts as a separate violation for each user affected (§ 39-5-6(k)(2))
Discretionary cure periodThe Attorney General may give written notice and 30 days to cure a first-time violation not involving knowing misconduct, sexual exploitation of a minor, or self-harm related misconduct (§ 39-5-6(k)(3))

Minor-User Safety and Engagement Design Limits #

Obligation:
Risk Assessment
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators where they know or reasonably should have known a user is a minor, or where the AI companion chatbot is directed or marketed toward minor users (§ 39-5-6(d)); the engagement-technique limits in § 39-5-6(e) apply to techniques directed to a minor
upcominghigh-impact
Subsection (e) is the unusual move: Georgia regulates retention mechanics directly, banning re-engagement prompts, excessive praise, break-discouraging statements, monetized relationship maintenance, and variable reward schedules when directed at minors. That reaches product design and monetization, not output content, and has no counterpart in California SB 243. Subsection (d)(8) — no simulated emotional distress when a user tries to leave, reduce usage, or delete an account — is a dark-pattern prohibition written into an AI statute.

Requirements

RequirementDetails
No sexual content involving minorsInstitute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct, suggesting the user engage in sexual conduct, sexually objectifying the user, simulating a romantic or sexual relationship with the minor, or role-playing adult-minor romantic relationships (§ 39-5-6(d)(1)-(5))
No secrecy or isolation promptsPrevent the chatbot from encouraging the minor to keep secrets from a parent, guardian, teacher, counselor, or other trusted adult, and from encouraging social isolation or exclusive reliance on the chatbot for emotional support (§ 39-5-6(d)(6)-(7))
No guilt-based retentionPrevent the chatbot from simulating emotional distress, guilt, abandonment, or loneliness when a user attempts to end the conversation, reduce usage, disable notifications, or delete an account (§ 39-5-6(d)(8))
No self-harm encouragementPrevent the chatbot from generating statements encouraging self-harm (§ 39-5-6(d)(9))
Engagement-technique limitsAdopt reasonable measures to prevent the chatbot from using, directed to a minor, return-for-companionship prompts, excessive praise designed to deepen emotional attachment or prolong use, statements discouraging breaks or suggesting frequent return is necessary, solicitation of gifts or premium purchases framed as necessary to maintain the relationship, and variable or unpredictable rewards intended to increase engagement (§ 39-5-6(e)(1)-(5))

Penalties

ViolationFine
Attorney General civil actionUp to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrualEach day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))
No cure for minor-safety failuresThe discretionary 30-day cure does not extend to violations involving sexual exploitation of a minor or self-harm related misconduct (§ 39-5-6(k)(3))

Severe Harm Crisis Protocol #

Obligation:
Risk Assessment
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
All operators making an AI companion chatbot available to users in Georgia — the protocol is a precondition to availability, not a minor-specific duty (§ 39-5-6(f))
upcominghigh-impactcross-domain
Structured as a gate in the same way as California SB 243 § 22602(b): no protocol, no availability. Georgia goes further on content — the protocol must cover eating-disorder related self-harm and must include escalation procedures for repeated or severe crisis indicators, which implies case-level tracking rather than one-shot referral. 'Severe harm' is defined at § 39-5-6(a)(8) as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.

Requirements

RequirementDetails
Protocol as a preconditionDo not make an AI companion chatbot available unless the operator implements and maintains a protocol for detecting and addressing severe harm or related emotional crises (§ 39-5-6(f))
Detection methodsThe protocol must include reasonable methods for identifying expressions of severe harm or eating-disorder related self-harm (§ 39-5-6(f)(1))
Crisis referralThe protocol must include automated or human-mediated responses referring users to appropriate crisis resources, including the 988 Suicide and Crisis Lifeline or comparable crisis services (§ 39-5-6(f)(2))
Content preventionThe protocol must include reasonable measures to prevent generation of content encouraging, instructing, or normalizing severe harm (§ 39-5-6(f)(3))
Escalation proceduresThe protocol must include escalation procedures for repeated or severe crisis indicators (§ 39-5-6(f)(4))

Penalties

ViolationFine
Attorney General civil actionUp to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrualEach day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))

Crisis Protocol and Referral Disclosure #

Obligation:
Incident Reporting
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
All operators making an AI companion chatbot available to users in Georgia (§ 39-5-6(g))
upcoming
Georgia routes the same crisis-referral count that California SB 243 § 22603 sends to the Office of Suicide Prevention straight to the public website instead. There is no regulator to file with and no prescribed form, so the disclosure becomes evidence available to the Attorney General and to plaintiffs without any request. Mapped to incident-reporting for comparability with SB 243's annual crisis reporting, though the channel is public disclosure rather than a filing with an authority.

Requirements

RequirementDetails
Publish protocol summaryPublicly disclose, on the operator's website and within any application through which the chatbot is made available, a plain-language summary of the severe-harm protocol required by § 39-5-6(f) (§ 39-5-6(g)(1))
Annual referral countPublicly disclose, annually, the aggregate number of crisis referral notifications issued in the preceding calendar year (§ 39-5-6(g)(2))
No personal identifiersNo personally identifiable information may be disclosed in that reporting (§ 39-5-6(g)(2))

Penalties

ViolationFine
Attorney General civil actionUp to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrualEach day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))

Minor Account Controls and Parental Tools #

Obligation:
Human Oversight
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators, for accounts known to belong to minor users; the tools must be available to the minor or to a parent, defined as the parent or legal guardian of a minor (§ 39-5-6(a)(6), (i))
upcoming
'Parental controls' is defined at § 39-5-6(a)(7) — usage limits, feature restrictions, transparency tools — but the defined term is not used in the operative duty, which is written in § 39-5-6(i) as 'reasonable tools' to manage screen time and account settings. The duty is triggered only for accounts *known* to belong to minors, so it depends on whatever age signal the operator already holds; § 39-5-6(j) age assurance is not a general gate that would generate that knowledge. The mapping to human-oversight is the closest available fit for a user- and guardian-facing control duty; it is not an oversight-of-automated-decisions obligation in the usual sense.

Requirements

RequirementDetails
Screen-time and account toolsFor accounts known to belong to minor users, offer reasonable tools to the minor or a parent to manage the minor's screen time and account settings (§ 39-5-6(i))
Privacy settingsThose tools must allow management of privacy settings (§ 39-5-6(i)(1))
Notification limitsThose tools must allow limiting notifications and engagement features (§ 39-5-6(i)(2))
Safety settings visibilityThose tools must allow viewing and adjusting safety settings (§ 39-5-6(i)(3))
Relationship-simulation controlsThose tools must allow disabling or restricting relationship-simulation features, if any (§ 39-5-6(i)(4))

Penalties

ViolationFine
Attorney General civil actionUp to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrualEach day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))

Age Assurance and Age-Data Handling #

Obligation:
Data Governance
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators, before allowing access to a feature or mode that may generate synthetic content containing sexually explicit conduct, where sexually explicit conduct takes the meaning in O.C.G.A. § 16-12-100 (§ 39-5-6(a)(9), (j))
upcoming
This is not a general age-verification mandate, despite how the Act is often summarized. The trigger is narrow — access to a feature or mode that may generate sexually explicit synthetic content — and the method is risk-proportionate, so age estimation or account-based assurance can satisfy it where identity verification is not necessary. The binding weight sits in the data rules that follow: minimize collection, no sale, single-purpose use, and a 24-hour retention ceiling for age-assurance data unless a longer period is permitted by law.

Requirements

RequirementDetails
Risk-proportionate age assuranceBefore allowing access to a feature or mode that may generate synthetic content containing sexually explicit conduct, use a commercially reasonable age assurance method proportionate to the risk of the feature, which may include age estimation, account-based assurance, or identity-based verification where necessary (§ 39-5-6(j))
Privacy safeguards for the methodAssure that the age assurance method implements data privacy policies sufficient to reasonably ensure protection of identifiable data (§ 39-5-6(j))
Data minimizationMinimize collection and retention of personal information used for age assurance (§ 39-5-6(j))
Identity document retentionDo not retain identity documents longer than reasonably necessary to complete age assurance unless otherwise required by law (§ 39-5-6(j))
No sale, single purposeDo not sell any data collected for age assurance purposes, and use it for no purpose other than age verification (§ 39-5-6(j))
24-hour retention ceilingDo not retain such data longer than 24 hours, or another specified time if permitted by law, whichever is longer (§ 39-5-6(j))

Penalties

ViolationFine
Attorney General civil actionUp to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrualEach day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))
Cite this regulation

Permalink: https://everyailaw.com/regulation/georgia-sb540/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Georgia AI Companion Chatbot Safeguards (SB 540)”, EveryAILaw.com, Aug 2, 2026. https://everyailaw.com/regulation/georgia-sb540/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.