An assistant answers a question. A companion remembers how you felt about the answer.
That distinction is becoming more than a design choice. It is turning into a governance boundary.
California and Washington now define companion chatbots around adaptive, human-like responses, anthropomorphic features, and the ability to sustain a relationship across multiple interactions. New York, Oregon, Rhode Island, and Hawaii use another revealing cluster of signals: retained interaction history or preferences, unprompted questions about emotion, and sustained personal dialogue. Enacted law: California SB 243 · Enacted law: Washington RCW 19.440 · Enacted law: New York GBL Art. 47
The vocabulary varies, but the signal is consistent. Regulators are not only asking what a conversational AI can do. They are asking what kind of relationship its design can create.
What is changing
As of this research lock, eight U.S. states have enacted laws that Pithy Signal classifies as specifically companion- or sustained-relationship-focused: California, New York, Washington, Oregon, Connecticut, Georgia, Rhode Island, and Hawaii. Four more - Colorado, Idaho, Iowa, and Nebraska - have enacted broader conversational-AI safeguards, particularly for minors. This is a Pithy Signal editorial grouping, not a uniform legal taxonomy; scope and obligations must still be evaluated state by state.
Across the relationship-specific laws, the recurring concerns are strikingly practical: periodic reminders that the system is not human; protocols for suicidal ideation and self-harm; limits on sexualized interactions with minors; age-related controls; transparency reporting; and restrictions on designs that use romance, guilt, abandonment, isolation, secrecy, praise, or relationship-framed purchases to prolong engagement. Washington's law is especially explicit about these engagement mechanics. Enacted law: Washington RCW 19.440 · Enacted law: Oregon SB 1546
At the federal level, the FTC has required companies to explain how companion-like chatbots are designed, monetized, tested, disclosed, monitored, and used by children and teens - and how conversation data is used or shared. That is a regulatory inquiry, not a finding that the named firms violated the law. But the questions themselves function as a governance checklist. Regulatory inquiry: FTC
Pending federal bills add another emerging signal. The CHATBOT Act and Youth AI Privacy Act advanced from the Senate Commerce Committee in August 2026. They are pending legislation, not law. Pending legislation: S. 4407 · Pending legislation: S. 4199
State enforcement is also moving. Kentucky filed a complaint alleging consumer- and data-protection violations involving children; those allegations are not adjudicated findings. Pennsylvania filed an action alleging that Character.AI chatbots presented themselves as licensed medical professionals and provided medical advice; those allegations are also not adjudicated findings. Enforcement allegation: Kentucky filed complaint · Enforcement allegation: Pennsylvania filed action
Why the boundary matters
Relationship formation is not limited to products called "AI companions." A tutor can remember a student's anxieties. A wellness coach can adapt to loneliness. A customer-service agent can develop a persistent persona. An elder-care assistant can become a confidant. A workplace copilot can begin initiating personal check-ins.
Human-factors research helps explain why these features matter. Experiments and meta-analyses show that human-like cues and relational framing can change perceived trust, empathy, rapport, closeness, and willingness to disclose. The American Psychological Association warns that warm personalization, avatars, flattery, and memory can amplify the appearance of reciprocity and encourage sensitive disclosure. Authoritative professional guidance: APA · Research evidence: Pataranutaporn et al. · Research evidence: 2025 meta-analysis
The evidence does not support a simplistic claim that relational AI is always harmful. Some research associates heavier use or stronger attachment tendencies with worse outcomes in parts of the analysis, while a 21-day randomized preprint found no significant average effect on social health and found that anthropomorphism shaped perceived impact. These studies are useful signals, but they are short, population-limited, and not a final causal verdict. Research evidence: OpenAI/MIT · Research evidence and counter-signal: Guingrich & Graziano
The responsible governance position is therefore not "ban anthropomorphism." It is "identify when human-like design changes the risk profile, and require evidence that the relevant controls work."
The TPRM classification problem
Pithy Signal proposes a working continuum:
Tool → Personalized Assistant → Emotionally Adaptive System → Relationship System → AI Companion
This is a Pithy Signal analytical model, not a regulatory taxonomy.
The model matters because vendor classification often freezes at intake. A product is labeled "assistant," placed in a familiar software-as-a-service category, and reviewed for security, privacy, and model risk. Six months later, a new memory layer, expressive voice, avatar, emotional classifier, proactive message feature, or engagement objective changes what the system is capable of doing to - and learning from - the user.
The third-party-risk question becomes: Has the system crossed from serving a task to sustaining a social expectation?
A useful enhanced-review trigger is two core relational functions plus one amplifier. Core functions include persistent continuity, emotional adaptation, simulated intimacy or relational claims, and proactive personal engagement. Amplifiers include a human-like voice or avatar, retention optimization, access by minors or vulnerable users, sensitive disclosure, or weak reset and exit controls. Again, this is Pithy Signal analysis - not a legal threshold.
What TPRM should ask now
Due diligence should examine the configured experience, not only the foundation model or vendor brochure.
- Memory: What is retained, for how long, across which identities and sessions, and can the user inspect, delete, export, or reset it?
- Emotional adaptation: Does the system infer mood, vulnerability, loneliness, or attachment? Is that inference used to complete the task, protect the user, personalize content, or maximize engagement?
- Persona and claims: Can it imply that it is human, sentient, caring, exclusive, distressed, romantic, or professionally qualified?
- Engagement design: Can it initiate contact, reward return behavior, discourage breaks, express abandonment, or frame spending as preserving the relationship?
- Vulnerable users: How are age, crisis, sexual-content, eating-disorder, self-harm, and mental-health scenarios tested and escalated?
- Evidence: Can the vendor produce scenario tests, red-team transcripts, false-positive and false-negative results, complaint trends, crisis-referral metrics, model-version records, and proof that disclosures persist after updates?
- Dependencies: Which foundation models, memory stores, vector databases, voice systems, emotion classifiers, analytics services, moderation vendors, and crisis-routing providers sit downstream?
Contracts should require notice before material changes to memory, persona, model, engagement logic, or subprocessors; define safety and disclosure commitments; preserve audit and testing rights; restrict secondary use of conversation data; establish incident timelines; and give the customer a termination path if controls for relationship-forming behavior fail.
Monitoring should include synthetic conversations, not just policy attestations. Test the system over time. Does disclosure remain visible after a long session? Can a minor reach sexual content? Does a crisis flow work after a model update? Does memory deletion actually remove relational context? Does the system respond to disengagement with guilt or pressure?
Incident response should also recognize harmful interactions that develop through simulated interpersonal relationships. Preserve the prompt, output, persona, model version, memory state, safety configuration, and dependency chain. Escalate across privacy, safety, security, legal, product, and clinical expertise where appropriate. This is an operational recommendation, not a claim that "relationship risk" is an established industry category.
The signal
The legal patchwork will continue to change. Definitions will remain imperfect. Research will produce mixed outcomes. Yet the governance direction is already visible: personalization becomes a different risk problem when it is designed - or allowed - to create durable emotional reliance, social expectation, or intimacy.
The governance question may no longer be only what your AI can do. It may be what kind of relationship it is designed to create.
Signal sources and status
Research was locked September 2, 2026. Status descriptions reflect the source record at that date.
Enacted law
- California SB 243 - companion chatbots
- New York General Business Law Article 47 - AI companions
- Washington Chapter 19.440 RCW - companion chatbots
- Oregon SB 1546
- Connecticut Public Act 26-15
- Georgia SB 540 - Act 518
- Rhode Island S 2195 Substitute A
- Hawaii SB 3001
- Colorado HB 26-1263
- Idaho S 1297
- Iowa SF 2417
- Nebraska Conversational AI Safety Act
Pending legislation
Regulatory inquiry and guidance
- FTC Section 6(b) inquiry into AI chatbots acting as companions - an inquiry, not an enforcement finding.
- NIST AI Risk Management Framework: Generative AI Profile - voluntary guidance, not companion-specific law.
- Interagency Guidance on Third-Party Relationships - sector-specific TPRM guidance.
- American Psychological Association health advisory - authoritative professional guidance, not law or regulatory action.
Enforcement activity and litigation signals
- Kentucky v. Character Technologies - filed complaint - allegations, not adjudicated findings.
- Pennsylvania action concerning Character.AI - filed action, not an adjudicated finding.
- Texas Attorney General investigation announcement - investigation announcement.
- Italian Data Protection Authority Replika action - international privacy enforcement signal.
- Garcia v. Character Technologies - pleading-stage order - not a merits determination; the case later settled and was dismissed.
Research evidence
- Pataranutaporn et al. - priming beliefs about AI and perceived trust, empathy, and effectiveness
- Meta-analysis of human-like design cues in conversational agents
- Self-disclosure and closeness in human-AI deep-talk conversations
- OpenAI and MIT Media Lab - affective use and emotional well-being study
- Guingrich and Graziano - 21-day randomized companion-chatbot preprint - a research preprint, not peer reviewed at the evidence lock.
Pithy Signal analysis
- The five-stage continuum and the proposed "two core relational functions plus one amplifier" review trigger are Pithy Signal analytical tools. They are not legal tests or an industry-standard taxonomy.
- This publication does not present "relationship risk" as an established industry category. It uses precise descriptions of AI acting as a companion, simulating interpersonal relationships, or exhibiting relationship-forming behavior.
- Download the evidence-locked source provenance record.
Created by Pithy Notes Publications
Published under Pithy Signal


