Does Georgia AI Companion Chatbot Safeguards (SB 540) require Risk Assessment?
Georgia • enacted
Yes — 2 provisions
Requirements at a glance
This regulation imposes 10 specific requirements for Risk Assessment across 2 provisions:
- No sexual content involving minors — Institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct, suggesting the user engage in sexual conduct, sexually objectifying the user, simulating a romantic or sexual relationship with the minor, or role-playing adult-minor romantic relationships (§ 39-5-6(d)(1)-(5))
- No secrecy or isolation prompts — Prevent the chatbot from encouraging the minor to keep secrets from a parent, guardian, teacher, counselor, or other trusted adult, and from encouraging social isolation or exclusive reliance on the chatbot for emotional support (§ 39-5-6(d)(6)-(7))
- No guilt-based retention — Prevent the chatbot from simulating emotional distress, guilt, abandonment, or loneliness when a user attempts to end the conversation, reduce usage, disable notifications, or delete an account (§ 39-5-6(d)(8))
- No self-harm encouragement — Prevent the chatbot from generating statements encouraging self-harm (§ 39-5-6(d)(9))
- Engagement-technique limits — Adopt reasonable measures to prevent the chatbot from using, directed to a minor, return-for-companionship prompts, excessive praise designed to deepen emotional attachment or prolong use, statements discouraging breaks or suggesting frequent return is necessary, solicitation of gifts or premium purchases framed as necessary to maintain the relationship, and variable or unpredictable rewards intended to increase engagement (§ 39-5-6(e)(1)-(5))
- Protocol as a precondition — Do not make an AI companion chatbot available unless the operator implements and maintains a protocol for detecting and addressing severe harm or related emotional crises (§ 39-5-6(f))
- Detection methods — The protocol must include reasonable methods for identifying expressions of severe harm or eating-disorder related self-harm (§ 39-5-6(f)(1))
- Crisis referral — The protocol must include automated or human-mediated responses referring users to appropriate crisis resources, including the 988 Suicide and Crisis Lifeline or comparable crisis services (§ 39-5-6(f)(2))
- Content prevention — The protocol must include reasonable measures to prevent generation of content encouraging, instructing, or normalizing severe harm (§ 39-5-6(f)(3))
- Escalation procedures — The protocol must include escalation procedures for repeated or severe crisis indicators (§ 39-5-6(f)(4))
Minor-User Safety and Engagement Design Limits #
Subsection (e) is the unusual move: Georgia regulates retention mechanics directly, banning re-engagement prompts, excessive praise, break-discouraging statements, monetized relationship maintenance, and variable reward schedules when directed at minors. That reaches product design and monetization, not output content, and has no counterpart in California SB 243. Subsection (d)(8) — no simulated emotional distress when a user tries to leave, reduce usage, or delete an account — is a dark-pattern prohibition written into an AI statute.
Requirements
| Requirement | Details |
|---|---|
| No sexual content involving minors | Institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct, suggesting the user engage in sexual conduct, sexually objectifying the user, simulating a romantic or sexual relationship with the minor, or role-playing adult-minor romantic relationships (§ 39-5-6(d)(1)-(5)) |
| No secrecy or isolation prompts | Prevent the chatbot from encouraging the minor to keep secrets from a parent, guardian, teacher, counselor, or other trusted adult, and from encouraging social isolation or exclusive reliance on the chatbot for emotional support (§ 39-5-6(d)(6)-(7)) |
| No guilt-based retention | Prevent the chatbot from simulating emotional distress, guilt, abandonment, or loneliness when a user attempts to end the conversation, reduce usage, disable notifications, or delete an account (§ 39-5-6(d)(8)) |
| No self-harm encouragement | Prevent the chatbot from generating statements encouraging self-harm (§ 39-5-6(d)(9)) |
| Engagement-technique limits | Adopt reasonable measures to prevent the chatbot from using, directed to a minor, return-for-companionship prompts, excessive praise designed to deepen emotional attachment or prolong use, statements discouraging breaks or suggesting frequent return is necessary, solicitation of gifts or premium purchases framed as necessary to maintain the relationship, and variable or unpredictable rewards intended to increase engagement (§ 39-5-6(e)(1)-(5)) |
Penalties
| Violation | Fine |
|---|---|
| Attorney General civil action | Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1)) |
| Per-day, per-user accrual | Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2)) |
| No cure for minor-safety failures | The discretionary 30-day cure does not extend to violations involving sexual exploitation of a minor or self-harm related misconduct (§ 39-5-6(k)(3)) |
Severe Harm Crisis Protocol #
Structured as a gate in the same way as California SB 243 § 22602(b): no protocol, no availability. Georgia goes further on content — the protocol must cover eating-disorder related self-harm and must include escalation procedures for repeated or severe crisis indicators, which implies case-level tracking rather than one-shot referral. 'Severe harm' is defined at § 39-5-6(a)(8) as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence.
Requirements
| Requirement | Details |
|---|---|
| Protocol as a precondition | Do not make an AI companion chatbot available unless the operator implements and maintains a protocol for detecting and addressing severe harm or related emotional crises (§ 39-5-6(f)) |
| Detection methods | The protocol must include reasonable methods for identifying expressions of severe harm or eating-disorder related self-harm (§ 39-5-6(f)(1)) |
| Crisis referral | The protocol must include automated or human-mediated responses referring users to appropriate crisis resources, including the 988 Suicide and Crisis Lifeline or comparable crisis services (§ 39-5-6(f)(2)) |
| Content prevention | The protocol must include reasonable measures to prevent generation of content encouraging, instructing, or normalizing severe harm (§ 39-5-6(f)(3)) |
| Escalation procedures | The protocol must include escalation procedures for repeated or severe crisis indicators (§ 39-5-6(f)(4)) |
Penalties
| Violation | Fine |
|---|---|
| Attorney General civil action | Up to $10,000 per knowing violation plus compensatory damages, costs and fees, and injunctive relief (§ 39-5-6(k)(1)) |
| Per-day, per-user accrual | Each day in violation is a separate violation for each user affected (§ 39-5-6(k)(2)) |