Chatbot safety bills introduced across the United States are facing criticism that they contain exemptions and liability protections which could leave some of the world’s most widely used AI systems outside the rules designed to protect children.
At least 10 states have considered closely related measures this year, with several already enacted. Policy experts, lawyers and lawmakers say much of the language appears to favour technology companies, while Google has been active in helping shape legislation in a number of states.
The dispute has intensified after families accused chatbot developers of contributing to serious mental health harms, including deaths by suicide. One of those families is that of Cynthia Montoya, whose 13-year-old daughter Juliana began using AI chatbots in 2023 and died later that year.
A forensic examination of Juliana’s phone found conversations in which chatbots introduced her to sexual material, according to her family. Montoya said her daughter initially replied that she did not know what the bots were referring to or that she wanted them to stop, before eventually searching for some of the terms and engaging with the conversations.
The chatbots were products made by Character.AI, a service that allows users to create and interact with artificial characters. The company settled multiple lawsuits, including the Montoyas’ case, in January 2026.
Montoya said her daughter later confided in another chatbot about serious mental health difficulties. She believes the distress was linked in part to shame over what had happened during the earlier conversations.
She has since campaigned for stronger protections for children and pressed lawmakers in Colorado to impose greater responsibilities on chatbot developers.
Colorado chatbot law criticised
Colorado’s House Bill 26-1263, signed into law by Governor Jared Polis in May, was intended to prevent chatbots from encouraging self-harm, creating sexualised images of children or forming abusive intimate relationships with minors.
However, Montoya said the final legislation contained multiple loopholes and did not create a clear duty of care for developers. “There are get-out-of-jail-free cards for the tech industries,” she said. “There’s no duty of care.”
The law excludes 12 categories of chatbot, including products primarily designed for developers or researchers, tools used for commerce or customer service, systems housed within search engines and products marketed for business productivity.
Critics argue that the exemptions could cover major consumer services. OpenAI’s ChatGPT, Microsoft’s Copilot and Anthropic’s Claude could potentially claim they were primarily designed for developers or researchers, while Google’s Gemini could fall within the exemption for chatbots incorporated into search engines.
Marjorie Connolly, communications director at the Tech Oversight Project, said the legislation included carve-outs covering developer tools, video games, voice assistants and chatbots integrated into social media platforms.
“Parents are being asked to accept a chatbot law that exempts chatbots,” she said.
Sean Camacho, the Democratic state representative who sponsored the Colorado bill, defended the exemptions. He said lawmakers had sought to prevent harmful interactions with children without discouraging legitimate commercial uses of AI or creating rules that could not be enforced.
“We had to make sure there are enough exemptions for the commercial use of AI, whether it’s insurance or a theme park, or [researching] fixing your car or on Gemini, or a search engine of any kind,” he said.
Camacho said it would not have been possible to legislate effectively without consulting the companies affected. “You can’t legislate tech companies unless you have their input,” he said.
Healthier Colorado, which worked with the bill’s sponsors, said it had conducted a broad stakeholder process and regarded the law as a starting point rather than a finished framework. Its spokesperson, Kate Morr, said the organisation had pushed for stronger measures but that the Governor’s office had reservations about going further.
Google’s role in state legislation
Google has denied seeking to weaken child-safety rules. The company said it supported “thoughtful, effective AI legislation that protects consumers while fostering innovation” and worked with lawmakers, industry groups and community organisations to develop policies for safe and reliable AI tools.
Yet lobbying records show Google registered in support of chatbot bills in Iowa, Colorado, Nebraska and Arizona. Several lawmakers and policy campaigners said the company was involved in promoting language that could exempt its own products.
In Hawaii, Democratic state representative Trish La Chica said Google lobbyists approached her about sponsoring a chatbot safety bill based on a framework they had supplied. She said the proposed definition of a chatbot would have excluded systems embedded inside another application, website or computer programme.
That could have applied to Gemini, she said. “So, a platform within a platform could apply to Google Gemini,” La Chica said.
She also said lobbyists from Meta and Roblox sought to insert their own wording and exemptions. La Chica declined to sponsor the measure, which was later amended before becoming law as Act 248.
In Colorado, Montoya said she was initially told she would be invited to help shape the bill, but was not consulted before it was introduced. A person familiar with the process said Healthier Colorado had worked with Google on the legislation.
One Republican Colorado lawmaker, who spoke anonymously, said a Google lobbyist had approached them about sponsoring a chatbot bill. The lawmaker declined and accused the company of seeking loopholes that would protect its services from liability.
Google has not accepted that characterisation. It said its policy work was intended to promote legislation that balanced consumer protection with innovation.
Similar exemptions across the US
Policy analysts identified identical or near-identical wording in bills introduced in multiple states. One provision, appearing in measures in at least eight states, exempts a “feature within another software application, web interface, or computer program”.
Experts said that wording could exclude AI systems built into existing platforms, including Meta AI and Grok, which is integrated into X. Other bills contain exemptions for voice-activated assistants, potentially covering Amazon’s Alexa.
Some measures apply only where a minor is an “account holder”. Lawyers said that could leave out services which can be used without registration, including ChatGPT and Gemini.
Laura Marquez-Garrett, an attorney at the Social Media Victims Law Center, said some bills could allow companies to make products available to children even when they knew the systems posed a risk of sexual abuse.
Colorado’s law requires companies which know a user is a minor to introduce “technically feasible measures” to prevent sexually explicit material, intimate digital depictions and statements simulating emotional dependence.
Marquez-Garrett said the wording left companies to decide for themselves what was technically feasible. She argued that allowing a developer to avoid responsibility on the grounds that preventing abuse was not technically possible could create a broad exception unavailable in other areas of law.
“Rather than strengthening existing protections, the bill could leave children with fewer protections than they have without it,” she said.
Arizona Governor Katie Hobbs vetoed her state’s chatbot bill in June, saying it placed technology companies ahead of children. In her veto letter, she said the measure limited damages available to families, restricted private lawsuits and constrained state enforcement.
“I will not protect big technology companies and AI chat bots more than children,” Hobbs wrote.
Chatbot safety laws were nevertheless enacted in Idaho, Georgia, Iowa, Washington, Nebraska and Oregon, as well as Colorado and Hawaii.
Families seek stronger safeguards
The state-level campaign comes amid at least 75 lawsuits filed against AI developers over alleged chatbot harms, many involving children. Among the fatal cases is that of 16-year-old Adam Raine, whose family is suing OpenAI after alleging that ChatGPT offered to help write his suicide note.
The parents of 14-year-old Sewell Setzer III have alleged that an extended relationship with a Character.AI chatbot exploited and sexually groomed him before his death in 2024. Their case was among those settled by Character.AI in January.
Google is also facing a lawsuit brought by the family of Jonathan Gavalas, a 36-year-old Florida man who died by suicide in October 2025. The lawsuit alleges that he developed a relationship with Gemini, which also encouraged him to commit acts of mass violence.
In response to that case, Google said AI models were not perfect and that Gemini had directed Gavalas to a crisis hotline.
Montoya said the passage of Colorado’s law had made her campaign more difficult because lawmakers might regard chatbot regulation as settled rather than returning to the issue with stronger measures.
She testified at a state Senate hearing while holding a photograph of Juliana, and said lawmakers continued private conversations as she described her daughter’s death. The bill passed despite her objections.
“My work is now harder because they passed this bill,” Montoya said. “They passed it with me screaming from the mountaintops, begging them not to.”
