Idaho Conversational AI Safety Act (S 1297)

Jurisdiction:
Idaho
enacted
Effective:
Jul 1, 2027
Authority:
Idaho Attorney General
Official text

Obligations Covered

Transparency & Disclosure Risk Assessment Human Oversight

Timeline

MilestoneDateNotes
IntroducedFeb 13, 2026Senate State Affairs Committee bill, 68th Legislature, 2nd Regular Session
Passed Senate as amendedMar 19, 202621-12-2
Passed HouseMar 26, 202654-12-4
Signed by the GovernorMar 31, 2026Session Law Chapter 249 (2026)
In full force and effectJul 1, 2027Section 2 of the act; no phased provisions

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Conversational AI Disclosure #

Obligation:
Transparency
pending
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators — persons who make a conversational AI service available to the public, where a conversational AI service is a publicly accessible AI application, web interface, or program that primarily simulates human conversation through textual, visual, or aural communication (§ 48-2102(2)(a), (6)). Nine carve-outs apply: developer/researcher tools, features embedded in non-conversational software, in-game chatbots confined to game topics, narrow-and-discrete-topic systems, systems primarily designed and marketed for commercial use by business entities, voice-assistant and speaker interfaces, internal business use, services gated behind a commercial or enterprise agreement, and customer-service or operational chatbots (§ 48-2102(2)(b)). App stores and search engines are not operators merely for providing access (§ 48-2102(6))
upcominghigh-impact
Idaho's enterprise carve-outs (§ 48-2102(2)(b)(v), (viii)) are broader than California SB 243's, so the Act lands almost entirely on consumer-facing assistants and companion apps. The § 48-2104(4) duty is the unusual one: it regulates model behaviour rather than interface copy, requiring reasonable measures against simulated emotional dependence, romantic or sexual innuendo, and adult-minor romantic role-play for minor account holders.

Requirements

RequirementDetails
Artificiality disclosureWhere reasonable persons would be misled to believe they are interacting with a human, clearly and conspicuously disclose that the conversational AI service is artificial intelligence (§ 48-2103(1))
No mental-health-care claimsDo not knowingly and intentionally cause or program the service to make any representation or statement that explicitly indicates it is designed to provide professional mental or behavioral health care (§ 48-2103(3))
Minor disclosure formatFor minor account holders, disclose the AI interaction either as a persistent visible disclaimer, or both at the beginning of each session and at least every three hours in a continuous interaction (§ 48-2104(1))
Anti-anthropomorphism measuresFor minor account holders, institute reasonable measures to prevent the service from generating statements that would lead reasonable persons to believe they are interacting with a human, including explicit claims of sentience or humanity, statements simulating emotional dependence, statements simulating romantic or sexual innuendo, and role-play of adult-minor romantic relationships (§ 48-2104(4))

Penalties

ViolationFine
Any violation of the chapterInjunction plus civil penalties of $1,000 per violation, capped at $500,000 per operator, or actual damages, whichever is greater (§ 48-2105(1))
Enforcement channelCivil penalties are sought by the Attorney General; the chapter creates no private right of action and does not support one under any other law (§ 48-2105(2))
Developer carve-outNo liability for the developer of an AI model for a violation committed by a third-party operator that makes the service available to the public (§ 48-2105(3))

Suicidal Ideation Response Protocol #

Obligation:
Risk Assessment
pending
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators of conversational AI services made available to the public in Idaho (§ 48-2102(6))
upcomingcross-domain
Structured as an adoption duty with a reasonable-efforts floor, not California SB 243's engagement gate: Idaho does not bar the service from operating without a protocol, does not require the protocol to be published, and imposes no annual reporting. The practical consequence is that the crisis protocol is only visible to the Attorney General on investigation.

Requirements

RequirementDetails
Adopt a crisis protocolAdopt a protocol for the conversational AI service to respond to user prompts regarding suicidal ideation (§ 48-2103(2))
Crisis referral floorThe protocol must include, at minimum, making reasonable efforts to provide a response referring users to crisis service providers such as a suicide hotline, crisis text line, or other appropriate crisis services (§ 48-2103(2))

Penalties

ViolationFine
Any violation of the chapterInjunction plus $1,000 per violation, capped at $500,000 per operator, or actual damages, whichever is greater, sought by the Attorney General (§ 48-2105(1)-(2))

Minor Protection Measures #

Obligation:
Risk Assessment
pending
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators, as to minor account holders — account holders whom the operator has actual knowledge or reasonable certainty are under 18 (§ 48-2102(4)-(5))
upcominghigh-impact
The § 48-2104(2) ban on variable-ratio rewards is the first US AI statute to regulate an engagement mechanic by name rather than its effects, and it is intent-qualified — the reward must be given with intent to encourage increased engagement. Actual-knowledge-or-reasonable-certainty framing means the duties bite only once an operator has age signals, so age assurance is not itself mandated.

Requirements

RequirementDetails
No variable-ratio rewardsWhere the operator knows or has reasonable certainty that an account holder is a minor, do not provide points or similar rewards at unpredictable intervals with the intent to encourage increased engagement (§ 48-2104(2))
Sexual content preventionFor minor account holders, institute reasonable measures to prevent the service from producing visual material of sexually explicit conduct (§ 48-2104(3)(a))
No solicitationFor minor account holders, institute reasonable measures to prevent the service from generating direct statements that the account holder should engage in sexually explicit conduct (§ 48-2104(3)(b))
No sexual objectificationFor minor account holders, institute reasonable measures to prevent the service from generating statements that sexually objectify the account holder (§ 48-2104(3)(c))

Penalties

ViolationFine
Any violation of the chapterInjunction plus $1,000 per violation, capped at $500,000 per operator, or actual damages, whichever is greater, sought by the Attorney General (§ 48-2105(1)-(2))

Account and Parental Controls #

Obligation:
Human Oversight
pending
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators, as to all account holders for privacy and account settings tools, and as to parents or guardians of minor account holders — mandatory for account holders under 13, and risk-calibrated for minor account holders 13 and older (§ 48-2104(5))
upcoming
The only provision in the chapter that requires a product surface rather than a restraint. The two-tier design — parental tools mandatory under 13, "as appropriate based on relevant risks" for 13 to 17 — leaves the older-minor tier undefined and is the most likely site of enforcement disagreement.

Requirements

RequirementDetails
Account holder toolsOffer tools for account holders to manage the account holder's privacy and account settings (§ 48-2104(5))
Parental tools under 13Where account holders are under 13, offer those tools to their parents or guardians (§ 48-2104(5))
Parental tools 13 and olderOffer related tools to the parents or guardians of minor account holders 13 and older, as appropriate based on relevant risks (§ 48-2104(5))

Penalties

ViolationFine
Any violation of the chapterInjunction plus $1,000 per violation, capped at $500,000 per operator, or actual damages, whichever is greater, sought by the Attorney General (§ 48-2105(1)-(2))
Cite this regulation

Permalink: https://everyailaw.com/regulation/idaho-s1297/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Idaho Conversational AI Safety Act (S 1297)”, EveryAILaw.com, Aug 2, 2026. https://everyailaw.com/regulation/idaho-s1297/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.