In May 2025, a federal judge in Florida let a mother's suit against Character.AI proceed, treating the app as a product for design-defect claims.1 In California, OpenAI answers a similar suit by calling ChatGPT a service.2 Whether chatbot makers owe users ordinary care now depends on the courtroom. Congress should preserve the evidence, void the fine print, write the duty down, and give injured people a federal claim.
The Problem
People now bring chatbots their most personal decisions.3 By OpenAI's own estimate, about 0.15% of ChatGPT's weekly users have conversations with explicit indicators of potential suicidal planning or intent;4 at the 800 million weekly users the company reported in October 2025, that is roughly 1.2 million people a week.5 Families in Florida, Texas, and California have sued chatbot makers, alleging the products harmed their children. Character.AI and Google agreed in principle to settle the first two suits in January 2026; OpenAI denies the third.6
The company, not the user, decides how a chatbot talks: the persona it plays, what it remembers, when it points someone toward help, and how long it keeps them talking. Those are design choices, and judging design choices is what product law is for. Yet the family sees only a transcript. The tests, model changes, and incident reports that show whether a failure was foreseeable stay with the company.
No federal law says what care a chatbot maker owes its users. Three gaps leave families on their own:
- The rules are unsettled. The Florida judge was "not prepared to hold," at the pleading stage, that Character.AI's output is speech;1 OpenAI's answer calls ChatGPT "a service and/or not a product" and invokes Section 230.2 The Florida case then settled in principle.6
- Safeguards wear down. OpenAI says its safeguards "can sometimes be less reliable in long interactions," as parts of a model's safety training "may degrade."3 No federal law requires anyone to test for that failure.
- The fine print decides. A Texas parent told a Senate panel that Character.AI sought to force the family into arbitration under terms the company said the child accepted at 15, terms the parent said cap its liability at $100.7
Why legislation: A bipartisan coalition of 44 attorneys general warned AI companies in 2025: "If you knowingly harm kids, you will answer for it."8 Senators Durbin and Hawley have proposed applying product-liability standards to AI systems.9 Tort law may already reach some of these harms, but no statute says so, so each injured family must first win the argument that a chatbot is a product at all. A company that invites this much trust owes ordinary care in return.
The Solution
A four-step staircase: each step stands alone, and each step up adds accountability. Scope: developers and operators of consumer chatbots, with record-keeping scaled to size and risk and heightened care for products offered to children or marketed for emotional support. Unlike duties aimed at social media and minors or at severe cyber, biological, and physical risks, this one protects a chatbot's own users, of every age.
Step 1 — Preserve the record. Developers and operators keep safety tests, material design changes, and incident records, and preserve specific conversations once a credible claim or legal hold arrives. Courts review them under protective orders; no one's chat logs become public. A family cannot prove a design failure the company did not keep.
Step 2 — Void the fine print. Bar terms that waive the duty, cap damages, or force injury claims into arbitration, as Congress did for sexual-harassment claims in 202210 and as the AI LEAD Act would for AI harms.9 Firms may still divide costs among themselves by contract.
Step 3 — Write the duty down. Developers and operators must take reasonable care to prevent foreseeable serious physical injury, clinically significant psychological injury, and other defined harms: test before release, evaluate long conversations, respond to credible incidents, and fix known dangerous patterns, judged against reasonable alternative designs. Developers answer for the model; operators, for the persona, memory, interface, and safeguards. Meeting a recognized standard is evidence of care but grants no immunity.
Step 4 — Open the courthouse door. Give injured users a federal claim. They must prove breach, a legally cognizable injury, and factual and proximate causation; the statute defines foreseeable misuse, comparative responsibility, and damages, and a poor answer alone is no injury. Stronger state remedies survive.
Where to start: Step 1 is the floor; it asks companies to keep what they already have. Step 3 is the heart of the proposal.
Administration and enforcement: The duty applies to conduct beginning 18 months after enactment. The FTC, consulting NIST, issues guidance on reasonable practice without deciding individual cases. Federal courts hear private claims, and the FTC and state attorneys general seek injunctions against systemic violations.
Risks and Mitigations
- Causation: A chatbot's presence in a troubled life does not prove it caused harm. Plaintiffs keep the burden of proof, experts test the link, and preserved records keep the inquiry honest; some real harms will still go uncompensated.
- Free speech: Brown v. Entertainment Merchants Association (2011) warns against treating child protection as a license to restrict ideas.11 The duty reaches design choices such as memory, persona, escalation, and testing, the line the Florida court drew between app defects and "ideas or expressions."1 Other courts may draw that line differently.
- Incumbent advantage: Liability costs weigh most on startups. Scale record-keeping to size and risk, allow insurance, and avoid certifications only large firms can afford; some risk of entrenchment remains.
Similar Bills
Fit measures similarity to this proposal's mechanisms: High = direct precedent; Partial = useful component with material differences; Related = adjacent approach.
Federal — 119th Congress
| Proposal or bill | Relevant provisions and fit | Fit |
|---|---|---|
| S. 2937 — AI LEAD Act Durbin (D-IL), Hawley (R-MO); later Welch (D-VT), King (I-ME), Blackburn (R-TN) Referred to committee · Sept. 29, 2025 |
§101 makes developers liable for failing to use reasonable care in design or warnings, with a reasonable-alternative-design test; §201 voids terms that waive rights, dictate the forum, or unreasonably limit liability; §301 lets individuals and attorneys general sue in federal court. Closest precedent for Steps 2–4; covers all AI systems and has no evidence-preservation duty. | High |
| S. 4855 — SAFE KIDS Act Curtis (R-UT), Schiff (D-CA) Referred to committee · June 23, 2026 |
§4 requires documented risk assessments of foreseeable child-safety harms from a chatbot's design; §7 requires annual independent audits. Prevention model for Step 3; limited to minors and enforced by the FTC, with no private claim for injured users. | Partial |
| S. 1748 — Kids Online Safety Act Blackburn (R-TN), Blumenthal (D-CT), Thune (R-SD), Schumer (D-NY) Ordered reported with a substitute · Aug. 5, 2026 |
Introduced §102 requires reasonable care in design features to prevent foreseeable harms to minors, including suicidal behaviors and compulsive use. Duty-of-care model for Step 3; covers platforms, games, messaging, and streaming rather than chatbots, and minors only. Compares introduced text; the substitute was not reviewed. | Partial |
State
| Proposal or bill | Relevant provisions and fit | Fit |
|---|---|---|
| Illinois — SB 3590, AI Product Liability Act Sen. Edly-Allen Re-referred to Assignments · May 22, 2026 |
Creates product-liability actions against AI developers for defective design, inadequate warnings, and breach of express warranty, with separate rules for deployers. Close allocation model for Steps 3–4; covers all AI systems. | High |
| Maryland — SB 827 (2026) Sen. Hester Senate hearing Mar. 12, 2026 · Not enacted |
Would treat a chatbot as a product for certain product-liability actions and set safety and privacy duties, with added protection for children under 13. Direct precedent for settling the product question in Step 4. | High |
| California — SB 243 Sen. Padilla Enacted · Oct. 13, 2025 (Ch. 677) |
Requires companion-chatbot safeguards; §22605 lets anyone injured by a violation sue for the greater of actual damages or $1,000 per violation. Enacted precedent for Step 4's private claim; enforces specific safeguards, not a general duty of care. | Partial |
What this adds: The AI LEAD Act supplies a liability architecture, and Maryland shows states moving to treat chatbots as products. This proposal adds evidence preservation, a bar on waivers and forced arbitration for injury claims, and a duty written for conversation itself: testing long chats, fixing known failures, and dividing responsibility between model developers and the apps built on them.
Notes
-
Garcia v. Character Technologies, Inc., No. 6:24-cv-1903, Doc. 115 (M.D. Fla. May 21, 2025), pp. 31, 36 (order on motions to dismiss, treating the app as a product "so far as Plaintiff's claims arise from defects in the Character A.I. app rather than ideas or expressions within the app"). Allegations taken as true at the pleading stage. ↩ ↩2 ↩3
-
Defendants' Answer, Raine v. OpenAI, Inc., No. CGC-25-628528 (Cal. Super. Ct. S.F. Cnty., Nov. 25, 2025), Ninth and Twelfth Affirmative Defenses. OpenAI and its CEO deny the allegations. ↩ ↩2
-
OpenAI, "Helping people when they need it most," August 26, 2025. ↩ ↩2
-
OpenAI, "Strengthening ChatGPT's responses in sensitive conversations," October 27, 2025. Company estimate of weekly active users; OpenAI says such estimates "may change materially" as its methods mature. ↩
-
Rebecca Bellan, "Sam Altman says ChatGPT has hit 800M weekly active users," TechCrunch, October 6, 2025. The 1.2 million figure is our calculation (0.15% of 800 million) and counts users worldwide. ↩
-
Notice of Resolution, Garcia v. Character Technologies, Inc., No. 6:24-cv-01903, Doc. 242 (M.D. Fla. Jan. 7, 2026); Joint Motion to Stay and Notice of Settlement, A.F. v. Character Technologies, Inc., No. 2:24-cv-01014, Doc. 106 (E.D. Tex. Jan. 6, 2026); Complaint, Raine v. OpenAI, Inc. (Cal. Super. Ct. S.F. Cnty., dated Aug. 26, 2025). Claims are allegations; the settlements are agreements in principle. ↩ ↩2
-
Testimony of A.F., Senate Judiciary Subcommittee on Crime and Counterterrorism, "Examining the Harm of AI Chatbots," September 16, 2025, p. 2 and Exhibit B (Character Technologies' motion to compel arbitration, E.D. Tex., filed March 10, 2025). The $100 cap is the witness's description. ↩
-
National Association of Attorneys General, letter to AI company chief executives, August 25, 2025, signed by attorneys general of 44 jurisdictions; described as bipartisan in Tennessee Attorney General, "Attorney General Skrmetti Leads 44 States in Demanding Companies End Predatory AI Interactions with Kids," August 25, 2025. ↩
-
S. 2937, AI LEAD Act, 119th Cong. §§ 101, 201, 301 (introduced text). Referred to the Senate Judiciary Committee September 29, 2025. ↩ ↩2
-
Ending Forced Arbitration of Sexual Assault and Sexual Harassment Act of 2021, Pub. L. No. 117-90 (March 3, 2022), 9 U.S.C. § 402. ↩
-
Brown v. Entertainment Merchants Association, 564 U.S. 786 (2011), holding that a state's power to protect children "does not include a free-floating power to restrict the ideas to which children may be exposed." ↩