Regulation

Washington Enacts the First AI Chatbot Safety Law in the US

Washington's HB 2225 is the first US AI chatbot safety law: non-human disclosure, self-harm crisis routing, minor protections, private right of action. Live Jan 1, 2027.

Washington Enacts the First AI Chatbot Safety Law in the US — article cover
On this page6 SECTIONS
  1. Three Laws Signed: Chatbots, Provenance, and Synthetic CSAM
  2. The Four Hard Requirements in HB 2225
  3. The Private Right of Action: The Sharpest Tooth
  4. Why Now: Teen Usage Data and the Bill That Died
  5. A To-Do List for Product Teams
  6. Sources

On April 1, 2026, The Spokesman-Review reported that Washington Governor Bob Ferguson had signed a trio of AI protection bills covering chatbot safety, content provenance, and synthetic child sexual abuse material. The centerpiece is HB 2225, which KING 5 calls the first comprehensive AI chatbot safety law in the United States. Its core is one sentence: a companion chatbot must say up front that it is not human, route users showing signs of self-harm to crisis resources, and never serve explicit content or manipulative engagement patterns to a known minor.

This is not a symbolic law. KING 5’s reporting notes that the bill carries a private right of action — individual users can sue — and its obligations take effect on January 1, 2027, leaving product teams less than a year of runway. With the White House still urging Congress in late March to preempt state AI laws that Congress has already rejected twice, state law is once again the actual compliance frontier for AI in America.

Three Laws Signed: Chatbots, Provenance, and Synthetic CSAM

At a March 24 ceremony in Olympia, Ferguson signed two bills together: HB 2225 for chatbot safety and HB 1170 for AI disclosure. The first covers “AI companion chatbots” — natural-language systems that produce adaptive, human-like responses. The second obliges large AI platforms, those with monthly active users in the millions, to provide commercially and technically reasonable ways for Washingtonians to tell whether content was created or substantially modified by AI. Video, photos, and audio recordings that AI created or enhanced must carry distinguishable provenance data. The Spokesman-Review adds that a third bill was signed the previous week: it bans possessing, distributing, or viewing computer-generated sexually explicit conduct involving minors, giving prosecutors a clear basis for synthetic CSAM cases. Ferguson did not mince words — the state must use every tool it has to protect young people from AI’s harmful effects.

The Four Hard Requirements in HB 2225

Unpacked, HB 2225 hands operators four concrete obligations:

  • Identity disclosure: state clearly at the start of an interaction that the bot is a machine, not a human
  • Self-harm response: maintain suicide-ideation and self-harm detection protocols for users of all ages, and guide them to crisis hotlines and related resources
  • Minor protections: when the operator knows a user is a minor, prevent explicit sexual content and manipulative engagement techniques
  • Timeline: everything above goes live on January 1, 2027, and it applies to consumer-facing interactive AI

The Private Right of Action: The Sharpest Tooth

Most state AI statutes are enforced by attorneys general. HB 2225’s defining difference is that it puts the sword in individual hands: affected users can sue for damages directly. That changes the risk math entirely. This is not a one-time fine with a statutory cap — it is a potential cause of action behind every mishandled self-harm conversation and every undisclosed bot identity. Set this against the White House’s March 20 national AI policy framework, which still asks Congress to preempt state law, and Washington is deliberately moving the opposite way: legislators used a private right of action to make sure the statute grows teeth even while the preemption fight drags on. For teams running multi-state compliance, that means reprioritizing. Administrative penalties can be negotiated; civil damages cannot.

Why Now: Teen Usage Data and the Bill That Died

The legislative speed was pushed by usage data. A Pew Research Center survey from December found that nearly two-thirds of US teenagers have used an AI chatbot, and 28 percent use one daily. A Common Sense Media survey the year before found 35 percent of teens aged 13 to 18 had encountered AI-created content. At the signing, Ferguson argued that without guardrails, “young people are more likely to engage in harmful emotional relationships with these chatbots.” Not everything passed, though: a bill creating civil liability for suicides tied to AI systems never got a floor vote in either chamber. In other words, the legislature chose the behavioral-obligation route over the after-the-fact liability route. It also confirms the bet we made in our 2026 opening outlook: when the federal level stalls, state law is what actually drives compliance work.

A To-Do List for Product Teams

Nine months remain before the January 1, 2027 deadline. Four items belong on the board now:

  • Scope check: audit whether your product falls under the “AI companion chatbot” definition — a natural-language interface plus adaptive, human-like responses very likely qualifies
  • Disclosure and crisis routing: add non-human disclosure at the start of conversations, and build self-harm signal detection with crisis-hotline handoff for all age bands
  • Age assurance and minor mode: block explicit content and manipulative design whenever the user is known to be a minor
  • Provenance pipeline: if your platform is large enough, start marking AI-generated or AI-enhanced media with distinguishable provenance data now, to line up with HB 1170

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

SHAREXEMAIL