Written and maintained by CASRAI Editorial Board
Last updated
Last verified: September 25, 2026. Most coverage of California Senate Bill 243 files it under chatbot safety or under child online protection. That framing is not wrong, but it buries what is structurally the most interesting thing about the statute for anyone tracking frontier-AI reporting obligations: SB 243 opens California’s second AI reporting channel, pointed at a different agency, carrying a different kind of data, on a different clock, from the first one.
The first channel is SB 53, the Transparency in Frontier Artificial Intelligence Act, which routes critical safety incidents to the Office of Emergency Services on 15-day and 24-hour clocks. The second is SB 243, which routes crisis-referral counts and the protocols behind them to the Office of Suicide Prevention, annually, beginning 1 July 2027 — and requires that Office to publish what it receives. Same state, same legislative season, two reporting regimes that share no definition, no trigger, and no taxonomy. That last point is not a drafting oversight worth tutting at; it is the concrete illustration of a problem this cluster keeps running into.
The Basics: What SB 243 Is and When It Bites
SB 243 was authored by Senators Padilla and Becker, with Assemblymembers Lowenthal and Pellerin as principal coauthors and Senators Rubio, Stern, and Weber Pierson as additional coauthors. It passed on a majority vote, was approved by the Governor and chaptered on 13 October 2025 as Chapter 677, Statutes of 2025, and adds Chapter 22.6 (commencing with Section 22601) to Division 8 of the Business and Professions Code — sections 22601 through 22606.
The bill contains no urgency clause and required only a majority vote. Under California’s default rule for non-urgency statutes enacted at a regular session, that puts the operator duties in effect from 1 January 2026. The reporting duty in § 22603 is the exception: it carries its own explicit start date of 1 July 2027, which is why a law already in force has a compliance deadline still ahead of it.
For orientation against the other California AI statutes: SB 53 was signed 29 September 2025 and sits at Business and Professions Code § 22757.10 et seq.; the provenance and transparency rules in SB 942/AB 853 are covered separately in our comparison of the California AI Transparency Act and SB 53. SB 243 is a fourth, independent thing.
What Counts as a “Companion Chatbot”
Section 22601 defines a companion chatbot as an artificial intelligence system with a natural language interface that provides adaptive, human-like responses, and that is capable of meeting a user’s social needs — exhibiting anthropomorphic features and sustaining a relationship across interactions rather than treating each exchange as self-contained.
The definition is scoped by exclusion, and the exclusions matter more than the inclusion does. Out of scope are:
- Customer-service bots used for a business’s own transactional or operational purposes.
- Chatbots that are a feature of a video game and whose subject matter is confined to the game.
- Voice-activated virtual assistants of the home-speaker kind, which do not sustain a continuing relationship.
Note what the definition does not turn on. There is no compute threshold, no training-cost floor, no revenue test, no parameter count. SB 53 applies to a “large frontier developer” identified by compute and revenue; SB 243 applies to an “operator” — a person who makes a companion chatbot platform available to a user in the state — identified purely by what the product does in front of a user. A three-person startup and a frontier lab are equally in scope if the product behaves the same way. For a cluster that spends most of its time arguing about which scope test picks out a frontier system, SB 243 is a useful counterexample: a state AI statute whose scope test is entirely behavioural.
The In-Product Duties: Obligations That Attach to Model Behaviour
This is the part that distinguishes SB 243 from most of the corpus. The obligations in a frontier AI framework statute are, overwhelmingly, obligations to produce and maintain documents: write a framework, publish a transparency report, describe your thresholds, disclose your governance structure. SB 243’s duties attach to what the model does in the conversation.
§ 22602(a) — The AI-Not-Human Notice
Where a reasonable person interacting with the chatbot would be misled into believing they are interacting with a human, the operator must issue a clear and conspicuous notification that the companion chatbot is artificially generated and not human. The trigger is the reasonable-person standard, not a blanket labelling rule — which means the compliance question is about how convincingly the product performs personhood, not about a checkbox in a settings screen.
§ 22602(b) — The Crisis Protocol, and the Duty to Publish It
An operator may not make a companion chatbot available unless it maintains a protocol for preventing the production of content about suicidal ideation, suicide, or self-harm, including by referring the user to crisis service providers — a suicide hotline or crisis text line — when the user expresses suicidal ideation, suicide, or self-harm. And then the clause that does the real work: the operator must publish details of that protocol on its internet website.
A published in-product safety protocol is a genuinely unusual artefact in AI governance. Labs publish frameworks describing how they decide what is safe. They do not, as a rule, publish the operational protocol that governs what the model says when a specific user says a specific thing. SB 243 requires exactly that, for one narrow and high-stakes behaviour, from every operator in scope.
§ 22602(c) and § 22604 — The Minor-Specific Duties
Where the operator knows the user is a minor, three additional duties apply. The operator must disclose that the user is interacting with artificial intelligence. It must provide, by default, a clear and conspicuous notification at least every three hours of continuing interaction, reminding the user to take a break and that the chatbot is artificially generated and not human. And it must institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct, or directly telling the minor to engage in sexually explicit conduct.
Separately, § 22604 requires operators to disclose — on the application, browser, or other access format — that companion chatbots may not be suitable for some minors.
The three-hour break reminder is worth pausing on as a governance object. It is a hard-coded, numerically specified, in-product behavioural requirement. Nothing in SB 53, the EU AI Act’s GPAI obligations, the RAISE Act, or any published lab framework contains an equivalent: a statute that specifies an interval, in hours, at which a model must interrupt itself. Whatever one thinks of the policy, it is a different species of obligation from the ones this cluster usually catalogues.
The Second Reporting Channel: § 22603
Beginning 1 July 2027, an operator must report annually to the Office of Suicide Prevention — defined in § 22601 as the Office established pursuant to Section 131300 of the Health and Safety Code, which the State Department of Public Health is authorised to establish. Three items are required:
- The number of times the operator issued a crisis service provider referral notification in the preceding year.
- The protocols put in place to detect, remove, and respond to instances of suicidal ideation by users.
- The protocols put in place to prohibit a companion chatbot response about suicidal ideation or actions with the user.
The report must exclude user-identifying information. The statute also directs operators to use evidence-based methods for measuring suicidal ideation. And § 22603(c) closes the loop: the Office shall post data from a report required by this section on its internet website.
That publication duty is what makes this a reporting channel rather than a filing obligation. SB 53’s critical safety incident reports go to the Office of Emergency Services and are not published incident-by-incident. SB 243’s numbers go to a public health office that must put them online. In principle, from mid-2027, California will have a public, annually refreshed, cross-operator count of how often companion chatbots referred users to crisis services. There is no equivalent public dataset for any other AI safety obligation in any jurisdiction.
The Instrumentation Problem Nobody Is Talking About Yet
Item 1 is a count. You cannot report a count you never instrumented. An operator that stands up a crisis-referral protocol in 2026 without also building the telemetry to count referral events, deduplicate them per the definition it chooses, and retain that count across a reporting year will arrive at 1 July 2027 with a statutory duty and no number. The protocol and the counter are separate engineering problems, and only one of them is obvious from reading § 22602.
Two Channels, No Shared Taxonomy
Set the two California regimes side by side and the mismatch is total. They do not share a definition of a covered entity, a definition of a reportable event, an agency, a clock, an enforcement mechanism, or a publication rule.
| SB 53 § 22757.13 | SB 243 § 22603 | |
|---|---|---|
| Who is covered | Large frontier developer (compute and revenue tests) | Operator of a companion chatbot platform (behavioural test) |
| What is reported | Critical safety incidents, as statutorily enumerated | Crisis-referral counts plus protocol descriptions |
| To whom | Office of Emergency Services | Office of Suicide Prevention |
| Clock | 15 days; 24 hours where imminent risk of death or serious injury | Annual, beginning 1 July 2027 |
| Published? | Not published incident-by-incident | Office must post the data on its website |
| Enforced by | Attorney General, civil penalties | Private right of action |
To be explicit, because it would be easy to imply otherwise: these two regimes do not share a taxonomy, and nothing in either statute attempts to reconcile them. A companion-chatbot interaction that ends in a crisis referral is not a “critical safety incident” under SB 53’s four-part definition, and a model-weight exfiltration is not a “crisis service provider referral notification.” Neither is a subset of the other. A single company could, in principle, owe both reports for the same model in the same year, describing entirely disjoint things, in entirely different vocabularies, to two agencies that have no statutory reason to talk to each other.
This is the concrete, in-force version of the gap documented in the incident-type taxonomy no one has actually published. It is one thing to observe that labs and regulators use “incident” inconsistently across documents. It is another to have two statutes from one legislature, signed a fortnight apart, that each create a mandatory reporting stream and define their reportable unit with no reference to the other.
Enforcement: A Private Right of Action, Not an Attorney General
Section 22605 gives a person who suffers injury in fact as a result of a violation of the chapter a civil action for injunctive relief, damages in an amount equal to the greater of actual damages or $1,000 per violation, and reasonable attorney’s fees and costs.
Three things follow from that structure, and they are worth stating carefully because the enforcement design is more consequential than the dollar figure.
- Enforcement does not depend on regulatory capacity. SB 53’s incident-reporting duty is enforced by the Attorney General, which means enforcement happens at the rate the Attorney General’s office chooses to prioritise it. SB 243’s runs on private initiative.
- “Per violation” is doing enormous work, and the statute does not define the unit. Whether a violation is a user, a session, a missed three-hour notification, or a single message is unresolved on the face of the text, and the gap between those readings is several orders of magnitude.
- Fee-shifting changes who can sue. A $1,000 statutory minimum plus attorney’s fees is a structure that makes representation economically viable for claims that would otherwise never be brought.
We take no position on how courts will read “per violation” — as of this writing there is no published California decision construing Chapter 22.6, and none should be expected for some time.
Why This Belongs in a Frontier-AI-Safety Cluster
SB 243 is not a frontier model statute. It has no compute threshold and would apply to a model far too small to interest any safety institute. It earns its place here for two structural reasons.
First, it is the clearest available example of a legal duty that attaches to in-product model behaviour rather than to framework documentation. The recurring criticism of the SB 53 / RAISE Act / GPAI Code family — that they regulate the paperwork surrounding a model rather than the model — has an obvious retort, which is that regulating behaviour directly is intractable. SB 243 is a working counterexample on a narrow domain: maintain a protocol for one specific conversational situation, publish the protocol, refer the user out, count how often you did, and hand the count to an agency that publishes it. That is a complete, closed loop from behaviour to public data, and it exists.
Second, it demonstrates that AI reporting obligations are accreting per-harm rather than per-system. California now has two, aimed at different harms, defined independently. The likely future is more channels, not consolidation — which makes the absence of a shared reportable-event vocabulary a compounding problem rather than a one-off.
Where NIKOLAI Fits In
The relevant element in CASRAI’s frontier-AI-safety dictionary is incident type, in Track N7 (Incidents), which defines incident type as a controlled value classifying an incident by mechanism and severity class so that similar events can be compared across developers. Its candidate groupings — weight exfiltration and unauthorised access, loss-of-control or deceptive-subversion events, materialised catastrophic-risk harms, and lower-severity precursor or near-miss events — are drawn from the frontier-risk literature, and none of them accommodates a crisis-referral event.
That is a finding about NIKOLAI, not about SB 243. An in-product user-harm referral is a real reportable event, now mandated by a real statute with a real publication duty, and the element’s current candidate set has nowhere to put it. NIKOLAI’s own status for this element is proposed, which is the correct posture for a taxonomy that a live statute has just walked past.
The usual and necessary caveat applies with full force here. NIKOLAI is CASRAI’s own independent dictionary. It is not endorsed by California, by the Office of Suicide Prevention, by the Office of Emergency Services, or by any operator. Every crosswalk row is a shadow mapping — CASRAI’s reading of a published document — unless the organisation concerned has filed a Mapping Declaration confirming it. No California state body has filed one. Nothing on this page should be read as the State of California agreeing with how we have classified anything.
The Research-Administration Angle: An Open Scope Question for IRBs
There is a genuine research-administration issue here, and it is a scope question rather than a compliance certainty.
“Operator” is defined as a person who makes a companion chatbot platform available to a user in the state. It is not, on its face, limited to commercial deployment. A university research group that builds or deploys a companion-style conversational agent and makes it available to human subjects in California — in studies of loneliness, adolescent social development, therapeutic alliance, or AI-mediated support, all active research areas — is arguably making a companion chatbot platform available to users in the state. Whether the Legislature intended academic research deployments to fall within Chapter 22.6 is not addressed anywhere in the statutory text, and we are not aware of any guidance resolving it.
Institutions with active or planned protocols in this space have a reason to work the question now rather than in 2027:
- IRBs already require distress and crisis-escalation protocols for studies that may surface suicidal ideation. Those protocols are reviewed, approved, and confidential to the protocol file. SB 243’s § 22602(b) requires a materially similar protocol to be published on a website. An institution that concludes it is in scope inherits a publication duty that has no analogue in human-subjects practice, and an IRB-approved protocol is not automatically a publishable one.
- The § 22603 report is an annual count filed with a state public health office and posted publicly. That is a disclosure pathway outside the usual research-data governance chain, and it is one an IRB would ordinarily want to see described in a protocol before approval rather than discovered afterwards.
- The private right of action does not care about IRB approval. Institutional review is not a defence to a statutory claim under § 22605.
- Sponsored programs offices reviewing awards that fund companion-agent deployment with human participants have a live question about which party is the “operator” where a platform is built by one institution and deployed by another.
To be clear about the limits of this: we are flagging an unresolved scope question that institutions should put to their own counsel, not asserting that academic deployments are covered. The honest state of the record is that the statute does not exclude them and nobody has yet said whether they are in.
Frequently Asked Questions
When does SB 243 take effect?
The operator duties in §§ 22602 and 22604 took effect 1 January 2026, under California’s default rule for non-urgency statutes chaptered at a regular session — SB 243 was chaptered 13 October 2025 as Chapter 677 and contains no urgency clause. The annual reporting duty in § 22603 has its own start date of 1 July 2027.
Does SB 243 apply only to large AI companies?
No. Unlike SB 53, which uses compute and revenue thresholds to identify a “large frontier developer,” SB 243 applies to any “operator” who makes a companion chatbot platform available to a user in California. The test is what the product does, not how big the company is or how much compute trained the model.
What has to be reported to the Office of Suicide Prevention?
Three things, annually from 1 July 2027: the number of times the operator issued a crisis service provider referral notification; the protocols in place to detect, remove, and respond to instances of suicidal ideation by users; and the protocols in place to prohibit a chatbot response about suicidal ideation or actions with the user. The report must not include user-identifying information, and the Office must post the data on its website.
Do SB 53 and SB 243 use the same incident definitions?
No, and this is a substantive point rather than a technicality. SB 53’s “critical safety incident” is a statutorily enumerated category covering things like weight exfiltration and loss of control, reported to the Office of Emergency Services on 15-day and 24-hour clocks. SB 243’s reportable item is an annual count of crisis-service referrals plus protocol descriptions, filed with the Office of Suicide Prevention. Neither definition is a subset of the other, and neither statute cross-references the other.
How is SB 243 enforced?
Through a private right of action in § 22605. A person who suffers injury in fact from a violation may sue for injunctive relief, the greater of actual damages or $1,000 per violation, and reasonable attorney’s fees and costs. There is no Attorney General enforcement mechanism of the kind SB 53 uses, and the statute does not define what constitutes a single “violation.”
What is excluded from the definition of a companion chatbot?
Customer-service bots used for a business’s transactional or operational purposes, chatbots that are a feature of a video game and confined to game subject matter, and voice-activated virtual assistants that do not sustain a continuing relationship across interactions.
Sources
- California SB 243 (2025–2026 Regular Session), Chapter 677, Statutes of 2025, chaptered 13 October 2025 — enacted text adding Chapter 22.6 (commencing with § 22601) to Division 8 of the Business and Professions Code, §§ 22601–22606. California Legislative Information,
leginfo.legislature.ca.gov. - Legislative Counsel’s Digest to SB 243, on the Office of Suicide Prevention established pursuant to Health and Safety Code § 131300.








