How does an AI company know when the person talking to its chatbot is a child?
Georgia's Senate Bill 540 does not give one universal answer. It does give companies a long list of duties that apply when they know or reasonably should have known the user was a minor.
For those users, the chatbot must disclose more often that it is not human. Operators must take reasonable measures to stop sexual content, simulated romance, adult-minor role-play, pressure to keep secrets, encouragement of isolation, emotional manipulation when a child tries to leave, and statements encouraging self-harm.
The bill also requires a crisis protocol that detects severe-harm signals, directs users to 988 or comparable services, and escalates repeated or serious indicators. Parents and minors must receive tools for privacy, notifications, safety settings, and relationship-simulation features.
A company cannot reliably apply minor-specific rules without some method for deciding who is a minor. The phrase “reasonably should have known” increases that pressure because doing nothing can become part of the enforcement case.
The Attorney General may seek up to $10,000 for each knowing violation. Each day and each affected user counts separately. The law does not create a private right of action, though it says other legal remedies remain available.
SB540 expressly requires age assurance before a feature that may generate sexually explicit content. The company may use age estimation, account-based assurance, or identity-based verification where necessary. It must minimize the data, cannot sell it, may use it only for verification, and generally cannot keep it longer than twenty-four hours.
Those limits reduce the risk of a permanent identity database. They do not remove the compliance checkpoint a company must build. The broader minor-specific duties also create a practical incentive to classify users outside the explicit-content feature.
Georgia confronted a real harm. A bot should never train a child to hide a relationship from a parent, depend on a machine for affection, or walk toward self-harm.
The law targets that conduct and limits retained identity data. It also makes age detection part of the cost of avoiding a large enforcement case.
Child safety is the purpose. The compliance system built to identify the child still deserves its own guardrails.
For more information on age verification, digital identity, and parent-led online safety, visit Protecting Kids Online, founded by Julie Barrett.
This is our read of the law. We encourage you to read it yourself and reach your own conclusions.
© 2026 InPublic Systems - All Rights Reserved.
Legislative and policy intelligence for conservative advocacy organizations.
(425) 298-6627