California Governor Gavin Newsom has signed a package of youth-focused technology laws that puts AI chatbots and social platforms under a much brighter regulatory spotlight. The measures are intended to reduce potential harms for minors, but their practical reach—and the tension between safety, privacy, and access to online communities—will likely be debated long after the signatures dry.

The policy bundle addresses several corners of modern digital life at once. It places new requirements on AI companies whose chatbots interact with teens, restricts certain social-media features for users younger than 16, expands the state’s treatment of sexual exploitation to cover some AI-generated or digitally altered images, and adds protections around targeted advertising and the use of K–12 student data by AI systems.

For companies building platforms, assistants, feeds, and tools used by young people, the central message is clear: youth-facing design choices will receive more scrutiny. The difficult part will be defining the line between a feature that makes a product functional and one that is considered potentially addictive, as well as enforcing age-based rules without asking everyone online to reveal more personal information than they otherwise would.

New guardrails for teen interactions with AI chatbots

The chatbot rules focus on how minors can engage with AI systems. They include time limits for teen use, requirements for mental-health resources, and safety procedures for situations in which a minor raises self-harm. Providers must also notify parents when a child turns off safety settings.

Those requirements acknowledge that an AI chatbot is not simply another search box. Conversation-based systems can feel immediate, personal, and always available. For young users especially, that makes safety design more consequential than a standard content warning pasted into a settings menu. The laws push companies toward safeguards that are active during use: limits on time, responses and procedures tied to crisis-related discussions, and an escalation of parental awareness when protections are disabled.

California is also requiring independent child-safety audits and annual risk assessments from AI companies. That shifts part of the discussion from an individual bad interaction to organizational accountability. A company will need to assess risks on an ongoing basis rather than treating child safety as a one-time launch checklist. The laws also create potential legal liability for AI companies that do not meet the requirements.

The state had already moved toward broader frameworks for auditing AI companies’ compliance with California law through measures signed the day before this package. Together, the actions suggest an approach that combines rules for particular youth-safety concerns with a wider expectation that AI developers document, examine, and answer for their systems’ risks.

What California calls potentially addictive social features

The social-media portion is likely to generate the fiercest argument. California now bars social platforms from allowing users under 16 to access features categorized as potentially addictive. That description stretches beyond a single design trick. It includes autoplaying video, notifications, and personalized, algorithm-driven content feeds.

Each of those tools is deeply familiar to anyone who has opened a contemporary app. Autoplay can keep a stream of clips moving without a deliberate next-step decision. Push notifications can pull users back after they leave. Algorithmic feeds can prioritize material predicted to hold attention. The new law treats that collection of engagement machinery as an issue deserving special limits for younger teens.

That could matter well beyond traditional social networks. Many online services borrow the same engagement patterns, whether they are primarily built around video, fandom, live communities, messaging, creative work, or games. The signed measures described here do not spell out how every edge case will be treated, so it remains important not to assume that every online product with a recommendation system will be handled identically. Still, the broad list of covered feature types shows why the policy has drawn such intense attention.

The rule also arrives during a period when major devices and ecosystems are increasingly framed around digital wellbeing, parental controls, and platform-level safety tools. Those broader technology choices are part of the backdrop for questions over who should carry responsibility: families, app makers, operating-system providers, or lawmakers. The changing competition among phone ecosystems is itself a reminder that design and platform policy can shape everyday habits, as seen in this look at the iPhone 18 Pro Max and Galaxy S26 Ultra ecosystem divide.

Safety goals meet privacy and access objections

Not everyone agrees that limiting these features is the right solution. The Electronic Frontier Foundation has argued that the social-media measure effectively functions as a ban on teen social media. Its objection is not merely that young users may spend less time scrolling. The organization contends that cutting minors off from digital forums, or removing basic ways of navigating them, does not necessarily make them safer or healthier in an AI-driven era.

There is a practical enforcement concern beneath that disagreement. To determine whether a user is younger than 16, platforms may need to collect or verify age information. Critics warn that this could mean more people must disclose sensitive personal information simply to establish their age, creating fresh privacy and security risks. That is a familiar criticism of age-verification proposals more broadly: a law designed to protect children can create systems that demand more data from children and adults alike.

This creates a policy puzzle with no frictionless answer. A platform cannot reliably apply a minor-specific feature restriction if it has no credible indication of age. But a system designed to establish age can be invasive depending on what information it collects, how long it keeps it, who processes it, and whether the approach becomes a de facto ID checkpoint for ordinary participation online.

Nor is a personalized feed automatically interchangeable with every other kind of online interaction. Some users rely on recommendation systems to locate niche interests, communities, accessibility-focused material, or timely information. Others may view autoplay and notifications as attention traps that undermine deliberate use. California’s approach takes the latter concern seriously for under-16 users; opponents fear the practical result will deny teens useful participation tools along with the undesirable ones.

AI-made imagery, advertising, and schools are also in scope

The legislation is broader than chatbots and feeds. One newly signed measure expands the definition of child sexual exploitation to include generative-AI-made or digitally altered images. That recognizes how image-generation and editing tools can be misused to produce harmful material involving minors even when the content is synthetic or manipulated rather than a conventional photograph.

Another measure adds protections involving targeted advertising and regulates how AI systems use data about K–12 students. Student information deserves particular care because schools and education-related services can hold details connected to children’s identities, learning, and daily lives. The new protections place that data in the same youth-safety conversation as chatbots and social platforms, rather than treating classroom technology as an entirely separate issue.

For families, educators, developers, and platform operators, California’s legislative package does not settle every major question about young people online. It does, however, establish a more forceful set of expectations. Chatbot makers must build specific protections and submit to safety-focused assessments. Social companies must confront limits around engagement features for users under 16. Developers and services handling AI-generated imagery, advertising, or student data face additional responsibilities as well.

What remains uncertain

The source measures establish the direction of California policy, but several implementation questions remain outside the details available here. The exact systems companies will use to determine age, how feature restrictions will work across different products, and how audits and risk assessments will operate in practice are all areas that can determine whether the laws meet their protective goals without imposing disproportionate privacy costs.

It is also too early to reduce the outcome to a simple win or loss for either side of the debate. Supporters see necessary intervention where products can be designed to hold young people’s attention or where AI interactions may involve serious mental-health concerns. Critics see risks that digital access will shrink while personal-data collection grows. Both perspectives point to the same underlying reality: the features that make online platforms engaging, tailored, and easy to use are often the very features lawmakers are now being asked to examine most closely for minors.