Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

California Enacts Several Minors’ Privacy and Safety Laws

By Lindsey Tonsager, Jenna Zhang & Irene Kim on September 21, 2026
Email this postTweet this postLike this postShare this post on LinkedIn
USA & California Flags.
If you like my images, please consider a backlink (in the caption or anywhere applicable) to https://www.drei-kubik.com
Drei Kubik, Unsplash

Recently, California Governor Gavin Newsom signed a sweeping set of laws related to minors’ privacy and safety, including new laws that restrict covered platforms from providing certain features to users under 16, impose a duty of care on social media platforms, revise the state’s Age-Appropriate Design Code, modify the state’s age-assurance requirements governing age signals, and impose safety requirements on AI chatbots. This blog summarizes the key takeaways from these new laws.

  • Age-Appropriate Design Code. AB 2246 repeals and replaces the current California Age-Appropriate Design Code Act with a revised framework that retains many of the original AADC’s core minor privacy and safety protections. The law removes the data protection impact assessment requirement and related provisions, along with the “materially detrimental” and “best interests of children” standards. The law still requires a business that “provides an online service, product, or feature likely to be accessed by children” to take reasonable steps to prevent specified risks of harm to minors, and either estimate the age of minor users with a reasonable level of certainty appropriate to the risks arising from the business’s data management practices or apply the privacy and data protections afforded to minors to all users. The law also requires default privacy settings for minor users to provide a high level of privacy and prohibit certain processing activities or practices, such as profiling or use of dark patterns.
  • Age Signals. AB 1856 amends the current Digital Age Assurance Act, requiring an operating system that operates on a device and has an account setup feature to provide an accessible interface, at account setup, that requires an account holder to indicate age information of the device’s primary user. The existing law requires a developer to request a signal with respect to a particular user from an operating system provider or a covered application store when the application is downloaded onto, and launched from a particular device. The amended law also requires a covered application store to request a signal from the user’s operating system provider and provide the signal to a developer upon request. Additionally, the law now clarifies that “clear and convincing information” includes age information regarding the subaccount user’s age, which may be used by a developer as the primary indicator of age if it is different than the age signal. 
  • Prohibited Features on Covered Platforms. AB 1709 prohibits covered platforms from providing an “addictive feature” to users under 16 and requires implementing reasonable measures to prevent under-16 users from accessing such features. “Addictive feature” is defined as a “psychologically exploitative [feature] intended to maximize engagement that foreseeably lead[s] to compulsive use,” including an “addictive feed,” further defined as a feed based on information provided by, or otherwise associated with, a user or the user’s device (with certain exceptions), autoplay, and any additional features that may be designated in future regulations adopted by the Attorney General. The law also establishes the e-Safety Advisory Commission within the Department of Justice to advise the government on matters related to online safety.
  • Duty of Care. AB 2 enhances statutory damages for a “social media platform” that causes injury to a minor by failing to exercise ordinary care or skill: $5,000 per violation up to a maximum, per minor, of $1 million, or three times the amount of the minor’s actual damages, whichever is larger. The law defines “social media platform” as an internet-based service or application that substantially functions to connect users for social interaction and allows users to (1) construct a public or semi-public profile for purposes of signing into and using the service, (2) establish a list of other users with whom they share social connections, and (3) create or post content viewable by other users, and generates more than $100,000,000 in annual gross revenue.
  • Companion Chatbots. Adam’s Law (SB 1119) requires operators of a “companion chatbot” to determine the age of users consistent with the Digital Age Assurance Act and imposes a series of obligations before making a new or substantially modified companion chatbot available to users, including: (1) perform and document a comprehensive risk assessment related to the design, configuration, and operation of the companion chatbot; (2) document measures that reasonably mitigate the identified minor safety risks; (3) publish a minor safety policy; (4) implement a documented crisis response protocol; (5) implement safeguards for minor users, such as usage reminders and specified disclosures; (6) implement default settings that can only be changed by a parent; (7) provide notice to minor users that they are interacting with an AI system; (8) implement measures to prevent the chatbot from engaging in certain specified behaviors; and (9) implement parental controls and a public incident reporting mechanism. Covered operators are also prohibited from displaying cross-context behavioral advertising, targeted advertising based on a minor’s personal information in a conversational chat, selling a minor’s personal information gathered through the companion chatbot, and using dark patterns. Covered operators must also perform an independent third-party minor safety audit on or before January 1, 2029, or before first making a companion chatbot available, whichever is later. Additionally, another chatbot law, SB 867, prohibits the manufacture, sale, exchange, possession with intent to sell or exchange, and exposition or offer for sale or exchange to a retailer a “toy” that includes a companion chatbot until 2031.
Tags: AI
Photo of Lindsey Tonsager Lindsey Tonsager

Lindsey Tonsager is a recognized leader in representing companies before federal and state regulators, and is renowned for advising on minor protection, AI, and state comprehensive privacy laws.

Lindsey chairs the firm’s global Data Privacy and Cybersecurity practice. She advises clients in their…

Lindsey Tonsager is a recognized leader in representing companies before federal and state regulators, and is renowned for advising on minor protection, AI, and state comprehensive privacy laws.

Lindsey chairs the firm’s global Data Privacy and Cybersecurity practice. She advises clients in their strategic and proactive engagement with the Federal Trade Commission, the U.S. Congress, the California Privacy Protection Agency, and State Attorneys General on proposed changes to data protection laws, and regularly represents clients in responding to investigations and enforcement actions involving their privacy and information security practices.

Lindsey’s practice focuses on helping clients launch new products and services that implicate the laws governing the use of artificial intelligence; data processing for robotics, autonomous vehicles, and other connected devices; biometrics; online advertising; the collection of personal information from children, teens, and students online; e-mail marketing; disclosures of video viewing information; and new technologies.

Lindsey also assesses privacy and data security risks in complex corporate transactions where personal data is a critical asset or data processing risks are otherwise material. In light of a dynamic regulatory environment where new state, federal, and international data protection laws are always on the horizon and enforcement priorities are shifting, she focuses on designing risk-based global privacy programs for clients that can keep pace with evolving legal requirements and efficiently leverage the clients’ existing privacy policies and practices. She conducts data protection assessments to benchmark against legal requirements and industry trends and proposes practical risk mitigation measures.

Read more about Lindsey TonsagerEmail
Show more Show less
Photo of Jenna Zhang Jenna Zhang

Jenna Zhang advises clients across industries on data privacy, cybersecurity, and emerging technologies. 

Jenna partners with clients to ensure their compliance with the rapidly evolving federal and state privacy and cybersecurity laws. She supports clients in designing new products and services, drafting privacy…

Jenna Zhang advises clients across industries on data privacy, cybersecurity, and emerging technologies. 

Jenna partners with clients to ensure their compliance with the rapidly evolving federal and state privacy and cybersecurity laws. She supports clients in designing new products and services, drafting privacy notices and terms of use, responding to cyber and data security incidents, and evaluating privacy and cybersecurity risks in corporate transactions. In particular, she advises clients on substantive requirements relating to children’s and student privacy, including COPPA, FERPA, age-appropriate design code laws, and social media laws.

As part of her practice, Jenna regularly represents clients in data privacy investigations and enforcement actions brought by the Federal Trade Commission and state attorneys general. She also supports clients in proactive engagement with regulators and policymakers to ensure their perspectives are heard.

Jenna also maintains an active pro bono practice with a focus on supporting families in adoptions, guardianships, and immigration matters.

Read more about Jenna ZhangEmail
Show more Show less
Photo of Irene Kim Irene Kim

Irene Kim is an associate in the firm’s Washington, DC office, where she is a member of the Privacy and Cybersecurity and Advertising and Consumer Protection Investigations practice groups. She advises clients on a broad range of issues, including U.S. state and federal…

Irene Kim is an associate in the firm’s Washington, DC office, where she is a member of the Privacy and Cybersecurity and Advertising and Consumer Protection Investigations practice groups. She advises clients on a broad range of issues, including U.S. state and federal AI legislation, comprehensive state privacy laws, and regulatory compliance matters.

Read more about Irene KimEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity, Technology and AI
  • Blog:
    Inside Privacy
  • Organization:
    Covington & Burling LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo