Policy brief 12 · Chatbots

Chatbot Parental Controls

Let parents decide what role a chatbot plays at home.

Most American teens have used an AI companion. The leading chatbots now offer parental tools, but each company writes its own rules, and at OpenAI and Character.AI the tools start only if the teenager agrees. Congress should give every family the same tools: a view of how the chatbot is used, a switch for each risky feature, crisis alerts, and controls a teenager cannot quietly undo.

The Problem

Seven in ten American teenagers have used an AI companion, and a third of those users have taken a serious matter to one instead of to a person.1 Parents usually know when a tutor, a counselor, or a new friend enters a child's life. A chatbot can play all three roles at any hour, unseen.

Parents are left with a blunt choice: forbid the tools and lose the homework help, or allow them and lose any say over romance, memory, and late-night talk. The companies swing between the same poles. Character.AI announced it would end open-ended chat for users under 18 by November 25, 2025;2 Meta, having promised parents controls over its AI characters, instead paused teens' access to them in January 2026.3

Where controls exist, each company sets its own terms. Three weaknesses stand out:

  1. Each app has different switches. ChatGPT lets parents turn off memory and voice and set quiet hours;4 Meta's plan let parents turn off its AI characters, but its AI assistant stays available to teens.3
  2. Crisis alerts are voluntary. OpenAI alerts parents when its reviewers see signs of acute distress in a linked teen's account, unless the parents opt out.4 No federal rule says when an alert must go out, or when one could put a child at risk.
  3. The teen holds the key. OpenAI's controls work only after a teen accepts a parent's invitation, and a teen can unlink at any time (the parent is notified).4 Character.AI's weekly reports reach a parent only if the teen sends the invitation.5

Why legislation: COPPA gives parents consent rights over data collected from children under 13;6 it says nothing about a 15-year-old's companion features, memory, or hours of use. California enacted detailed chatbot parental controls on September 10, 2026, operative July 2027,7 and a bipartisan Senate bill requiring family accounts cleared the Commerce Committee in August 2026.8 Families elsewhere get whatever each company offers. Parents, not platforms, should decide what part a machine plays in a child's life.

The Solution

A four-step staircase: each step stands alone, and each step up adds parental authority. Scope: consumer chatbots used by minors, with verified parental consent for accounts under 13 and for a minor's use of companion features; older teens keep a restricted informational mode with protective defaults.

Step 1 — Show parents the pattern. Give parents a plain summary of time spent, features used, and characters engaged, with conversation access graduated by the child's age, and tell children what their parents can see. For most families, the pattern matters more than the transcript.

Step 2 — Put each feature on its own switch. Let parents separately turn off companion and romantic features, cross-session memory, proactive messages, voice personas, outside tools, and purchases, and set daily limits, school and overnight hours, reminders, and a pause that follow the child across devices. Homework help stays on. Expose the settings through a standard interface so families can use third-party safety apps, as Sammy's Law would require of social media.9

Step 3 — Alert parents in a crisis. Define when a credible, imminent risk triggers an alert, connect the child with human crisis help, and withhold alerts from an adult who may be the danger. California's new law includes the same exception.7 Tell families plainly what automated detection can miss.

Step 4 — Make the controls hold. Let parents start the link, verify adult authority proportionately, and allow revocation and correction. Bar chatbots from coaching children around controls, notify parents when settings change, retest settings after every product update, and charge nothing for them. Controls add to a company's safety duties; they never replace them.

Where to start: Step 1 is the floor. Step 2 is the heart: the switches that turn an all-or-nothing choice into a family decision.

Administration and enforcement: The FTC writes rules within 12 months; compliance follows six months later. State attorneys general share enforcement, with civil penalties for missing, ineffective, or misleading controls.

Risks and Mitigations

  • Oversight versus privacy: Parents see patterns before transcripts, teens are told what is shared, and confidential health services and children facing abuse are protected. Where family access ends and adolescent privacy begins is a choice Congress must make on purpose.
  • Age checks create databases: Rely on age signals that phones and app stores already pass to apps, which California's Digital Age Assurance Act requires apps to request,10 and delete verification data after use. Shared accounts will still slip through.
  • Whose values: The law supplies switches and a common safety floor; parents supply the values, and no agency prescribes a family's views. Controls also must not become a company's excuse: the SAFE KIDS Act, pending in the Senate, would bar treating a parent's settings as a defense to most claims,11 and this proposal should do the same.
  • Controls or a ban: Some would bar minors outright. California's governor vetoed a broad 2025 bill, warning it "may unintentionally lead to a total ban";12 controls keep useful tools available, though they leave more risk in place than a ban would.

Similar Bills

Fit measures similarity to this proposal's mechanisms: High = direct precedent; Partial = useful component with material differences; Related = adjacent approach.

Federal

Proposal or bill Relevant provisions and fit Fit
S. 4407 — CHATBOT Act
Cruz (R-TX), Schatz (D-HI), Curtis (R-UT), Schiff (D-CA)
Ordered reported with a substitute · Aug. 5, 2026
Introduced §§3–5 require family accounts for children under 13 and verifiable parental consent for teens; parents can limit time, disable rewards, notifications, purchases, and unprompted outputs, set how long inputs stay in memory, see full conversation records, and get alerts on bypass attempts, with the most protective settings as defaults. Closest framework for Steps 1, 2, and 4; full transcript access goes further than this draft. Compares introduced text. High
S. 4855 — SAFE KIDS Act
Curtis (R-UT), Schiff (D-CA)
Referred to committee · June 23, 2026
§4(a)(7) requires parental settings for memory, training use, time-of-day limits, and each feature, with PIN protection, alerts on de-linking, and notice when a child changes settings; §4(a)(4) requires crisis alerts to linked parents unless not in the child's best interest. Direct precedent for Steps 2–4; also mandates risk assessments and audits. High
H.R. 2657 — Sammy's Law
Wasserman Schultz (D-FL), Carter (R-GA) + 21 cosponsors
Forwarded by subcommittee · Dec. 11, 2025
§4 requires large social media platforms to offer real-time interfaces through which families delegate account management to registered third-party safety software. Model for Step 2's standard interface; social media only. Partial
Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506
Enacted Oct. 21, 1998
§6502 requires verifiable parental consent before collecting personal information from children under 13. Established consent model for Step 4; covers data rather than features or time, and stops at age 13. Partial

State

Proposal or bill Relevant provisions and fit Fit
California — SB 1119 (2026)
Signed Sept. 10, 2026 · Main duties operative July 1, 2027
§21812(d)(3) sets child defaults only a parent can change (memory and push notifications off, one-hour sessions, two hours a day) and lets parents disable access under 16; crisis alerts go to linked parents unless that risks serious harm; controls must be tested with children and parents. Enacted precedent for Steps 2–4. High
South Carolina — S. 1037 (2026)
Referred to committee · March 19, 2026; no later action recorded
Would allow a limited-access mode without consent but require a verified parental account and consent before enabling memory-based personalization, proactive outreach, extended sessions, or relationship simulation; parents could limit time and features and delete data. Close precedent for Steps 2 and 4. High
Florida — SB 1344 (2026)
Died in committee · March 13, 2026
Would have required minors' companion accounts to link to a verified parental account with verifiable parental consent, plus hourly notices that the bot is not human. Consent-gate precedent for Step 4; no feature-level switches. Partial

What this adds: California's SB 1119 and the Senate's CHATBOT and SAFE KIDS bills set strong models. This proposal makes the baseline national, adds a standard interface for third-party family tools, puts the link in the parent's hands, and keeps chatbots available to teenagers. It governs features and time; content ratings for social media and a ban on minors' chatbot use are separate briefs.

Notes

  1. Common Sense Media, Talk, Trust, and Trade-Offs: How and Why Teens Use AI Companions, July 16, 2025, Key Findings 1 and 9. Self-reported; nationally representative NORC survey of 1,060 U.S. teens ages 13–17, April 30–May 14, 2025. 72% had ever used an AI companion; 33% of users had chosen one over a person for "important or serious matters." ↩

  2. Character.AI, "Taking Bold Steps to Keep Teen Users Safe on Character.AI," October 29, 2025. ↩

  3. Adam Mosseri and Alexandr Wang, Meta, "Empowering Parents, Protecting Teens: Meta's Approach to AI," October 17, 2025, updated January 23, 2026 ("temporarily pausing teens' access to existing AI characters globally"). ↩ ↩2

  4. OpenAI, "Introducing parental controls," September 29, 2025, updated July 13, 2026. Text verified from the Internet Archive copy of September 1, 2026. ↩ ↩2 ↩3

  5. Character.AI, "Parental Insights," accessed September 23, 2026. Reports show time on the platform and top characters, not chat content. ↩

  6. 15 U.S.C. § 6501(1) ("child" means under 13); § 6502(b)(1)(A)(ii) (verifiable parental consent). ↩

  7. SB 1119, Cal. Bus. & Prof. Code §§ 21810–21818 (Stats. 2026, ch. 190), approved September 10, 2026; § 21812(d)(1)(B) (parent notice "if that notification does not risk a threat of serious harm to the child"). Most duties operative July 1, 2027. ↩ ↩2

  8. S. 4407, CHATBOT Act, 119th Cong. (introduced text), sponsored by Cruz (R-TX) with Schatz (D-HI), Curtis (R-UT), and Schiff (D-CA); Congressional Record Daily Digest, August 5, 2026, p. D812 (ordered reported with a substitute). ↩

  9. H.R. 2657, Sammy's Law, 119th Cong. § 4(a) (introduced text). ↩

  10. Legislative Counsel's Digest to SB 1119 (2026), describing the Digital Age Assurance Act's requirement that apps request age-bracket data from the operating system or app store. ↩

  11. S. 4855, SAFE KIDS Act, 119th Cong. § 4(a)(7)(D) (introduced text). Settings may still be relevant to a claim premised on that subparagraph itself. ↩

  12. Gov. Gavin Newsom, veto message on AB 1064, October 13, 2025. ↩