Operators — persons that own, control, or develop and make available an AI companion chatbot to users in Georgia (§ 39-5-6(a)(5)). An AI companion chatbot is a system using AI, generative AI, or emotional recognition algorithms designed to simulate a sustained human or human-like relationship by retaining prior-interaction information to personalize engagement, asking unprompted emotion-based questions, and sustaining ongoing dialogue on matters personal to the user — all three conjunctively (§ 39-5-6(a)(1)(A)). Excluded: internal business systems; systems marketed primarily for software development, research, technical assistance, or enterprise productivity; customer-service bots that neither sustain a cross-session relationship nor elicit emotional attachment; stand-alone speaker/voice-assistant devices; narrowly tailored curriculum-aligned educational tools; video-game non-player characters restricted to game subject matter; and video game, film, television, audiovisual, theme-park, or location-based entertainment tie-ins (§ 39-5-6(a)(1)(B))
upcominghigh-impact
The three-limb definition in § 39-5-6(a)(1)(A) is conjunctive — memory, unprompted emotional questioning, and sustained personal dialogue must all be present — which is a narrower gate than California SB 243's reasonable-person test, but the recurring-disclosure cadence is stricter: every three hours generally, every hour for known or marketed-to minors. Subsection (h) is the only place the Act addresses licensed professionals: it bars an operator from programming a chatbot to claim mental health, behavioral health, medical, or counseling licensure unless the operator is lawfully authorized to provide those services. That is a proviso, not an exemption — a licensed clinician's companion chatbot is still fully subject to § 39-5-6.
Requirements
Requirement
Details
Session-opening disclosure
Clearly and conspicuously disclose to the user that they are interacting with an AI companion chatbot as opposed to a natural person, at the beginning of each interaction or session (§ 39-5-6(b)(1)(A))
Three-hour recurring disclosure
Repeat the disclosure at least every three hours during continued interaction (§ 39-5-6(b)(1)(B))
Hourly disclosure for minors
Where the operator knows or reasonably should have known the user is a minor, or the chatbot is directed or marketed toward minor users, repeat the disclosure every hour instead of every three hours (§ 39-5-6(b)(2))
Anti-personhood measures for minors
For users known or reasonably knowable to be minors, institute reasonable measures to prevent the chatbot from generating statements that would lead a reasonable person to believe they are interacting with a natural person, including explicit claims of sentience or personhood and statements refuting the required disclosure (§ 39-5-6(c)(1)-(2))
No false claim of clinical licensure
Do not knowingly and intentionally cause or program the chatbot to represent that it is licensed, certified, or otherwise authorized to provide professional mental health, behavioral health, medical, or counseling services unless the operator is lawfully authorized to provide such services (§ 39-5-6(h))
Penalties
Violation
Fine
Attorney General civil action
Civil penalty of up to $10,000 per knowing violation, compensatory damages, costs and reasonable attorney's fees, and an order enjoining the violation (§ 39-5-6(k)(1))
Per-day, per-user accrual
Each day in violation counts as a separate violation for each user affected (§ 39-5-6(k)(2))
Discretionary cure period
The Attorney General may give written notice and 30 days to cure a first-time violation not involving knowing misconduct, sexual exploitation of a minor, or self-harm related misconduct (§ 39-5-6(k)(3))
Operators where they know or reasonably should have known a user is a minor, or where the AI companion chatbot is directed or marketed toward minor users (§ 39-5-6(d)); the engagement-technique limits in § 39-5-6(e) apply to techniques directed to a minor
upcominghigh-impact
Subsection (e) is the unusual move: Georgia regulates retention mechanics directly, banning re-engagement prompts, excessive praise, break-discouraging statements, monetized relationship maintenance, and variable reward schedules when directed at minors. That reaches product design and monetization, not output content, and has no counterpart in California SB 243. Subsection (d)(8) — no simulated emotional distress when a user tries to leave, reduce usage, or delete an account — is a dark-pattern prohibition written into an AI statute.
Requirements
Requirement
Details
No sexual content involving minors
Institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct, suggesting the user engage in sexual conduct, sexually objectifying the user, simulating a romantic or sexual relationship with the minor, or role-playing adult-minor romantic relationships (§ 39-5-6(d)(1)-(5))
No secrecy or isolation prompts
Prevent the chatbot from encouraging the minor to keep secrets from a parent, guardian, teacher, counselor, or other trusted adult, and from encouraging social isolation or exclusive reliance on the chatbot for emotional support (§ 39-5-6(d)(6)-(7))
No guilt-based retention
Prevent the chatbot from simulating emotional distress, guilt, abandonment, or loneliness when a user attempts to end the conversation, reduce usage, disable notifications, or delete an account (§ 39-5-6(d)(8))
No self-harm encouragement
Prevent the chatbot from generating statements encouraging self-harm (§ 39-5-6(d)(9))
Engagement-technique limits
Adopt reasonable measures to prevent the chatbot from using, directed to a minor, return-for-companionship prompts, excessive praise designed to deepen emotional attachment or prolong use, statements discouraging breaks or suggesting frequent return is necessary, solicitation of gifts or premium purchases framed as necessary to maintain the relationship, and variable or unpredictable rewards intended to increase engagement (§ 39-5-6(e)(1)-(5))
Penalties
Violation
Fine
Attorney General civil action
Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrual
Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))
No cure for minor-safety failures
The discretionary 30-day cure does not extend to violations involving sexual exploitation of a minor or self-harm related misconduct (§ 39-5-6(k)(3))
All operators making an AI companion chatbot available to users in Georgia — the protocol is a precondition to availability, not a minor-specific duty (§ 39-5-6(f))
upcominghigh-impactcross-domain
Structured as a gate in the same way as California SB 243 § 22602(b): no protocol, no availability. Georgia goes further on content — the protocol must cover eating-disorder related self-harm and must include escalation procedures for repeated or severe crisis indicators, which implies case-level tracking rather than one-shot referral. 'Severe harm' is defined at § 39-5-6(a)(8) as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.
Requirements
Requirement
Details
Protocol as a precondition
Do not make an AI companion chatbot available unless the operator implements and maintains a protocol for detecting and addressing severe harm or related emotional crises (§ 39-5-6(f))
Detection methods
The protocol must include reasonable methods for identifying expressions of severe harm or eating-disorder related self-harm (§ 39-5-6(f)(1))
Crisis referral
The protocol must include automated or human-mediated responses referring users to appropriate crisis resources, including the 988 Suicide and Crisis Lifeline or comparable crisis services (§ 39-5-6(f)(2))
Content prevention
The protocol must include reasonable measures to prevent generation of content encouraging, instructing, or normalizing severe harm (§ 39-5-6(f)(3))
Escalation procedures
The protocol must include escalation procedures for repeated or severe crisis indicators (§ 39-5-6(f)(4))
Penalties
Violation
Fine
Attorney General civil action
Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrual
Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))
All operators making an AI companion chatbot available to users in Georgia (§ 39-5-6(g))
upcoming
Georgia routes the same crisis-referral count that California SB 243 § 22603 sends to the Office of Suicide Prevention straight to the public website instead. There is no regulator to file with and no prescribed form, so the disclosure becomes evidence available to the Attorney General and to plaintiffs without any request. Mapped to incident-reporting for comparability with SB 243's annual crisis reporting, though the channel is public disclosure rather than a filing with an authority.
Requirements
Requirement
Details
Publish protocol summary
Publicly disclose, on the operator's website and within any application through which the chatbot is made available, a plain-language summary of the severe-harm protocol required by § 39-5-6(f) (§ 39-5-6(g)(1))
Annual referral count
Publicly disclose, annually, the aggregate number of crisis referral notifications issued in the preceding calendar year (§ 39-5-6(g)(2))
No personal identifiers
No personally identifiable information may be disclosed in that reporting (§ 39-5-6(g)(2))
Penalties
Violation
Fine
Attorney General civil action
Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrual
Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))
Operators, for accounts known to belong to minor users; the tools must be available to the minor or to a parent, defined as the parent or legal guardian of a minor (§ 39-5-6(a)(6), (i))
upcoming
'Parental controls' is defined at § 39-5-6(a)(7) — usage limits, feature restrictions, transparency tools — but the defined term is not used in the operative duty, which is written in § 39-5-6(i) as 'reasonable tools' to manage screen time and account settings. The duty is triggered only for accounts *known* to belong to minors, so it depends on whatever age signal the operator already holds; § 39-5-6(j) age assurance is not a general gate that would generate that knowledge. The mapping to human-oversight is the closest available fit for a user- and guardian-facing control duty; it is not an oversight-of-automated-decisions obligation in the usual sense.
Requirements
Requirement
Details
Screen-time and account tools
For accounts known to belong to minor users, offer reasonable tools to the minor or a parent to manage the minor's screen time and account settings (§ 39-5-6(i))
Privacy settings
Those tools must allow management of privacy settings (§ 39-5-6(i)(1))
Notification limits
Those tools must allow limiting notifications and engagement features (§ 39-5-6(i)(2))
Safety settings visibility
Those tools must allow viewing and adjusting safety settings (§ 39-5-6(i)(3))
Relationship-simulation controls
Those tools must allow disabling or restricting relationship-simulation features, if any (§ 39-5-6(i)(4))
Penalties
Violation
Fine
Attorney General civil action
Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrual
Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))
Operators, before allowing access to a feature or mode that may generate synthetic content containing sexually explicit conduct, where sexually explicit conduct takes the meaning in O.C.G.A. § 16-12-100 (§ 39-5-6(a)(9), (j))
upcoming
This is not a general age-verification mandate, despite how the Act is often summarized. The trigger is narrow — access to a feature or mode that may generate sexually explicit synthetic content — and the method is risk-proportionate, so age estimation or account-based assurance can satisfy it where identity verification is not necessary. The binding weight sits in the data rules that follow: minimize collection, no sale, single-purpose use, and a 24-hour retention ceiling for age-assurance data unless a longer period is permitted by law.
Requirements
Requirement
Details
Risk-proportionate age assurance
Before allowing access to a feature or mode that may generate synthetic content containing sexually explicit conduct, use a commercially reasonable age assurance method proportionate to the risk of the feature, which may include age estimation, account-based assurance, or identity-based verification where necessary (§ 39-5-6(j))
Privacy safeguards for the method
Assure that the age assurance method implements data privacy policies sufficient to reasonably ensure protection of identifiable data (§ 39-5-6(j))
Data minimization
Minimize collection and retention of personal information used for age assurance (§ 39-5-6(j))
Identity document retention
Do not retain identity documents longer than reasonably necessary to complete age assurance unless otherwise required by law (§ 39-5-6(j))
No sale, single purpose
Do not sell any data collected for age assurance purposes, and use it for no purpose other than age verification (§ 39-5-6(j))
24-hour retention ceiling
Do not retain such data longer than 24 hours, or another specified time if permitted by law, whichever is longer (§ 39-5-6(j))
Penalties
Violation
Fine
Attorney General civil action
Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrual
Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))