Requires A separate cluster regulates AI companions — the consumer chatbots people confide in — rather than clinical tools. Every law in it is built on the same duty: detect a user in crisis, and hand them to a human service.
The two originals — New York and California New York was first in the nation and has been in effect since Nov 5, 2025. The law arrived as Part U of the FY2026 budget bill (S3008-C) rather than as a standalone act — which is why several trackers still point at A6767, a different bill that died in the Senate — and is codified at Gen. Bus. Law Art. 47. Under §1701 it is unlawful to operate an AI companion unless it runs a protocol to address a user's expression of suicidal ideation or self-harm and refers that user to a crisis service; §1702 requires notice at the start of the interaction and at least every three hours that the user is not talking to a human. The Attorney General enforces it (§1703). California SB 243 (Ch. 677, Stats. 2025, signed Oct 13, 2025) took effect Jan 1, 2026: a crisis-referral protocol, AI disclosure and break reminders for minors, and annual reports to the state's Office of Suicide Prevention beginning Jul 1, 2027 — backed by a private right of action for the greater of actual damages or $1,000 per violation.
The 2026 wave Connecticut (Public Act 26-15, approved May 27, 2026; the AI-companion sections take effect Jan 1, 2027) requires an evidence-based protocol to detect a user expression indicating risk of suicide, self-harm, or imminent violence and to refer the user to the 988 lifeline and on to treatment "consistent with clinical best practices"; the companion may not claim to be a human being; and for minors it may not offer mental-health services at all unless it is designed to deliver them using clinical best practices and displays, clearly and conspicuously at the start of each interaction, a statement that it is not a licensed mental health professional.
Oregon and Iowa Oregon (SB 1546, approved Mar 31, 2026, effective Jan 1, 2027) requires a suicidal-ideation detection protocol and a referral carrying contact information and a hyperlink for 988 — or a youthline for a user under 25 — restricts simulated emotional dependence and romantic role-play for minors, and gives users a private right of action for the greater of actual damages or $1,000 per violation. Iowa (SF 2417, approved May 2, 2026; by its own terms the act applies July 1, 2027) requires conspicuous AI disclosure to minor account holders and a protocol referring users to a crisis service, and bars an operator from knowingly programming the service to represent that it provides professional psychology or behavioral-health services that would require a license — enforced by the Attorney General at up to $500,000 per operator, with no private right of action.
Hawaii Hawaii (SB 3001 CD1, the Artificial Intelligence Disclosure and Safety Act) is the 2026 wave's first to be in effect: Governor Green signed it as Act 248 on July 14, 2026 (Gov. Msg. No. 1350), and it takes effect on approval. It requires operators of conversational-AI services to clearly disclose that a user is interacting with AI rather than a human; adds safeguards for minors — limits on manipulative engagement techniques and sexually explicit content, plus tools for parents and guardians to manage screen time and account settings; and requires a protocol to respond to a user expressing suicidal ideation or self-harm by directing them to crisis-intervention resources such as suicide hotlines and crisis text lines. Beginning January 1, 2028, operators must file annual reports with the Department of Health's Behavioral Health Administration. It is enforced as an unfair or deceptive trade practice.
Washington and Georgia Two more land in 2027, and both are worth reading for how far the duty now reaches. Washington HB 2225 (Ch. 168, Laws of 2026, approved Mar 24, 2026; effective Jan 1, 2027) conditions deployment itself on the protocol: "An operator may not make available or deploy an AI companion chatbot unless it maintains and implements a protocol for detecting and addressing suicidal ideation or expressions of self-harm by users." The protocol must cover expressions "including eating disorders," refer users to a suicide hotline or crisis text line, and prevent content describing how to self-harm — and the operator must publicly disclose both the protocol and the number of crisis referrals it issued the prior calendar year. Violations are unfair or deceptive acts under ch. 19.86 RCW, which carries a private right of action. Unlike most of this cluster, the duty runs to all users, not only minors. Georgia SB 540 (O.C.G.A. §39-5-6, effective Jul 1, 2027) requires a protocol for "severe harm or related emotional crises" — identification methods, automated or human-mediated referral to the 988 lifeline, prevention of content that encourages or normalizes severe harm, and escalation procedures for repeated or severe indicators — plus a plain-language public summary and an annual crisis-referral count. It also bars programming a companion to represent that it is "licensed, certified, or otherwise authorized to provide professional mental health, behavioral health, medical, or counseling services" unless it lawfully is — the same red line as CA AB 489 and DE HB 191. The Attorney General enforces it at up to $10,000 per knowing violation.
Read this one carefully These are operator duties, not provider duties. Connecticut and Oregon both expressly carve out software that assists or supports patient or resident care services in a facility. If you run an AI scribe or a clinical decision-support tool, these eight laws are not aimed at you — the ones that are aimed at you are Rhode Island's, Vermont's, Louisiana's, Texas SB 1188, and the therapy bans above.