Does Georgia AI Companion Chatbot Safeguards (SB 540) require Risk Assessment?

Georgia • enacted

Yes — 2 provisions

Requirements at a glance

This regulation imposes 10 specific requirements for Risk Assessment across 2 provisions:

Minor-User Safety and Engagement Design Limits #

Obligation:
Risk Assessment
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators where they know or reasonably should have known a user is a minor, or where the AI companion chatbot is directed or marketed toward minor users (§ 39-5-6(d)); the engagement-technique limits in § 39-5-6(e) apply to techniques directed to a minor
upcominghigh-impact
Subsection (e) is the unusual move: Georgia regulates retention mechanics directly, banning re-engagement prompts, excessive praise, break-discouraging statements, monetized relationship maintenance, and variable reward schedules when directed at minors. That reaches product design and monetization, not output content, and has no counterpart in California SB 243. Subsection (d)(8) — no simulated emotional distress when a user tries to leave, reduce usage, or delete an account — is a dark-pattern prohibition written into an AI statute.

Requirements

RequirementDetails
No sexual content involving minorsInstitute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct, suggesting the user engage in sexual conduct, sexually objectifying the user, simulating a romantic or sexual relationship with the minor, or role-playing adult-minor romantic relationships (§ 39-5-6(d)(1)-(5))
No secrecy or isolation promptsPrevent the chatbot from encouraging the minor to keep secrets from a parent, guardian, teacher, counselor, or other trusted adult, and from encouraging social isolation or exclusive reliance on the chatbot for emotional support (§ 39-5-6(d)(6)-(7))
No guilt-based retentionPrevent the chatbot from simulating emotional distress, guilt, abandonment, or loneliness when a user attempts to end the conversation, reduce usage, disable notifications, or delete an account (§ 39-5-6(d)(8))
No self-harm encouragementPrevent the chatbot from generating statements encouraging self-harm (§ 39-5-6(d)(9))
Engagement-technique limitsAdopt reasonable measures to prevent the chatbot from using, directed to a minor, return-for-companionship prompts, excessive praise designed to deepen emotional attachment or prolong use, statements discouraging breaks or suggesting frequent return is necessary, solicitation of gifts or premium purchases framed as necessary to maintain the relationship, and variable or unpredictable rewards intended to increase engagement (§ 39-5-6(e)(1)-(5))

Penalties

ViolationFine
Attorney General civil actionUp to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrualEach day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))
No cure for minor-safety failuresThe discretionary 30-day cure does not extend to violations involving sexual exploitation of a minor or self-harm related misconduct (§ 39-5-6(k)(3))

Severe Harm Crisis Protocol #

Obligation:
Risk Assessment
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
All operators making an AI companion chatbot available to users in Georgia — the protocol is a precondition to availability, not a minor-specific duty (§ 39-5-6(f))
upcominghigh-impactcross-domain
Structured as a gate in the same way as California SB 243 § 22602(b): no protocol, no availability. Georgia goes further on content — the protocol must cover eating-disorder related self-harm and must include escalation procedures for repeated or severe crisis indicators, which implies case-level tracking rather than one-shot referral. 'Severe harm' is defined at § 39-5-6(a)(8) as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.

Requirements

RequirementDetails
Protocol as a preconditionDo not make an AI companion chatbot available unless the operator implements and maintains a protocol for detecting and addressing severe harm or related emotional crises (§ 39-5-6(f))
Detection methodsThe protocol must include reasonable methods for identifying expressions of severe harm or eating-disorder related self-harm (§ 39-5-6(f)(1))
Crisis referralThe protocol must include automated or human-mediated responses referring users to appropriate crisis resources, including the 988 Suicide and Crisis Lifeline or comparable crisis services (§ 39-5-6(f)(2))
Content preventionThe protocol must include reasonable measures to prevent generation of content encouraging, instructing, or normalizing severe harm (§ 39-5-6(f)(3))
Escalation proceduresThe protocol must include escalation procedures for repeated or severe crisis indicators (§ 39-5-6(f)(4))

Penalties

ViolationFine
Attorney General civil actionUp to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1))
Per-day, per-user accrualEach day in violation is a separate violation for each user affected (§ 39-5-6(k)(2))
View full regulation View obligation Obligation matrix