On April 1, 2026, The Spokesman-Review reported that Washington Governor Bob Ferguson had signed a trio of AI protection bills covering chatbot safety, content provenance, and synthetic child sexual abuse material. The centerpiece is HB 2225, which KING 5 calls the first comprehensive AI chatbot safety law in the United States. Its core is one sentence: a companion chatbot must say up front that it is not human, route users showing signs of self-harm to crisis resources, and never serve explicit content or manipulative engagement patterns to a known minor.
This is not a symbolic law. KING 5’s reporting notes that the bill carries a private right of action — individual users can sue — and its obligations take effect on January 1, 2027, leaving product teams less than a year of runway. With the White House still urging Congress in late March to preempt state AI laws that Congress has already rejected twice, state law is once again the actual compliance frontier for AI in America.
Three Laws Signed: Chatbots, Provenance, and Synthetic CSAM
At a March 24 ceremony in Olympia, Ferguson signed two bills together: HB 2225 for chatbot safety and HB 1170 for AI disclosure. The first covers “AI companion chatbots” — natural-language systems that produce adaptive, human-like responses. The second obliges large AI platforms, those with monthly active users in the millions, to provide commercially and technically reasonable ways for Washingtonians to tell whether content was created or substantially modified by AI. Video, photos, and audio recordings that AI created or enhanced must carry distinguishable provenance data. The Spokesman-Review adds that a third bill was signed the previous week: it bans possessing, distributing, or viewing computer-generated sexually explicit conduct involving minors, giving prosecutors a clear basis for synthetic CSAM cases. Ferguson did not mince words — the state must use every tool it has to protect young people from AI’s harmful effects.
The Four Hard Requirements in HB 2225
Unpacked, HB 2225 hands operators four concrete obligations:
- Identity disclosure: state clearly at the start of an interaction that the bot is a machine, not a human
- Self-harm response: maintain suicide-ideation and self-harm detection protocols for users of all ages, and guide them to crisis hotlines and related resources
- Minor protections: when the operator knows a user is a minor, prevent explicit sexual content and manipulative engagement techniques
- Timeline: everything above goes live on January 1, 2027, and it applies to consumer-facing interactive AI
The Private Right of Action: The Sharpest Tooth
Most state AI statutes are enforced by attorneys general. HB 2225’s defining difference is that it puts the sword in individual hands: affected users can sue for damages directly. That changes the risk math entirely. This is not a one-time fine with a statutory cap — it is a potential cause of action behind every mishandled self-harm conversation and every undisclosed bot identity. Set this against the White House’s March 20 national AI policy framework, which still asks Congress to preempt state law, and Washington is deliberately moving the opposite way: legislators used a private right of action to make sure the statute grows teeth even while the preemption fight drags on. For teams running multi-state compliance, that means reprioritizing. Administrative penalties can be negotiated; civil damages cannot.
Why Now: Teen Usage Data and the Bill That Died
The legislative speed was pushed by usage data. A Pew Research Center survey from December found that nearly two-thirds of US teenagers have used an AI chatbot, and 28 percent use one daily. A Common Sense Media survey the year before found 35 percent of teens aged 13 to 18 had encountered AI-created content. At the signing, Ferguson argued that without guardrails, “young people are more likely to engage in harmful emotional relationships with these chatbots.” Not everything passed, though: a bill creating civil liability for suicides tied to AI systems never got a floor vote in either chamber. In other words, the legislature chose the behavioral-obligation route over the after-the-fact liability route. It also confirms the bet we made in our 2026 opening outlook: when the federal level stalls, state law is what actually drives compliance work.
A To-Do List for Product Teams
Nine months remain before the January 1, 2027 deadline. Four items belong on the board now:
- Scope check: audit whether your product falls under the “AI companion chatbot” definition — a natural-language interface plus adaptive, human-like responses very likely qualifies
- Disclosure and crisis routing: add non-human disclosure at the start of conversations, and build self-harm signal detection with crisis-hotline handoff for all age bands
- Age assurance and minor mode: block explicit content and manipulative design whenever the user is known to be a minor
- Provenance pipeline: if your platform is large enough, start marking AI-generated or AI-enhanced media with distinguishable provenance data now, to line up with HB 1170
Sources
- Ferguson signs AI protection bills as public increasingly embraces AI — The Spokesman-Review
- Washington enacts first AI chatbot safety law — KING 5
- Double win: Washington Gov. Ferguson signs two major AI safety bills into law — Transparency Coalition
AI-assisted summary compiled from the sources above, reviewed by a human before publishing.
