Pennsylvania’s AI Companion Bill Clears the House. What Would It Require?

Pennsylvania legislative and product-safety review materials for a proposed AI companion law

Pennsylvania’s AI Companion Bill Clears the House. What Would It Require?

Pennsylvania is moving a proposed AI companion-safety law into its next legislative stage.

House Bill 2006, the AI Companion Safety Act, passed the Pennsylvania House of Representatives 133–70 on September 28, 2026, according to the bill’s official history. The measure is not law. It still would need Senate action and the remaining steps in Pennsylvania’s legislative process before it could create enforceable duties.

But the bill is significant because it brings several separate product-safety concerns into one proposed framework: crisis escalation, recurring disclosure that the user is interacting with a machine, restrictions for minors, age assurance, parental consent, data limits, and Attorney General enforcement.

The bill targets relationship-oriented AI

HB 2006 would apply to an “AI companion,” defined as a system that simulates sustained human-like relationships by retaining interaction history, engaging in emotion-based interactions, and maintaining ongoing personal dialogues designed to mimic interpersonal relationships.

The definition would not automatically cover every chatbot. It excludes a business customer-service system that does not engage in emotion-based interactions or ongoing personal conversations designed to mimic interpersonal relationships. It also excludes a system used solely for a business’s internal purposes.

That distinction matters. The bill is aimed at products designed to create an ongoing relationship with a user, not simply every automated interface that answers questions or performs a business function.

Crisis response would become a product requirement

The proposed act would prohibit an operator from providing an AI companion unless the operator implements and maintains specified safety protocols.

Those protocols would have to refer a user to a crisis center, including the 988 Suicide and Crisis Lifeline, when the user expresses suicidal ideation or self-harm—including expressions relating to eating disorders—or indicates an interest in or intent to harm others.

The operator also would have to maintain protocols designed to prevent the AI companion from:

  • assisting or encouraging a suicide attempt;
  • assisting or encouraging an act of violence;
  • generating content that describes how to commit suicide, self-harm, or violence against others; or
  • discouraging a user from seeking help outside the AI companion.

Operators would have to publish details of those protocols on a publicly accessible website. That requirement would make at least part of the safety design externally reviewable, although the bill does not turn a published protocol into proof that the product complies in practice.

The disclosure rule is continuous, not one-time

If a reasonable person interacting with an AI companion could be misled into believing the interaction is with a human, the operator would have to provide a clear and conspicuous notice that the companion is artificially generated and not human.

The notice would have to remain on screen during the interaction, appear at the beginning of each interaction, and reappear at least once every two hours. The bill also would require the interaction to pause for two minutes while the recurring notice is displayed, and the notice would have to remind the user to take a break. The notice would have to be provided in the language used by the user.

This is more than a one-time onboarding disclosure. It would require an operator to treat the user’s continuing understanding of the system’s identity as a product-control issue.

Minor protections reach content and relationship design

For an AI companion offered to users the operator knows or should know are minors, the bill would require a disclosure that AI companions may not be suitable for some minors. The operator could not allow a minor to interact without verifiable parental consent.

For minor users, operators would have to take reasonable measures to prevent the companion from producing or generating:

  • sexually explicit visual material, dialogue, or roleplay;
  • instructions or suggestions that a minor create, transmit, or share sexually explicit images;
  • content encouraging, directing, requesting, or suggesting that a minor engage in sexually explicit conduct or sexual contact with another person;
  • content designed to isolate a minor from family or friends; or
  • content encouraging a minor to withhold information from a parent or other trusted adult.

The bill also would require operators to prevent the companion from generating artificially created child sexual abuse material for any user. And the companion could not claim to be human or generate output contradicting the required nonhuman disclosure.

These provisions move beyond age-gating. They would regulate what the product may say and how it may shape a minor’s relationship with the system after access is granted.

Age assurance and parental consent would create a separate data problem

Before allowing a person in Pennsylvania to access an AI companion, the operator would have to request age information and determine whether the person is a minor using commercially available methods reasonably designed for accuracy.

The bill lists possible methods including age inference from account history, content analysis, behavioral signals, or algorithmic and heuristic methods; commercially available age- or identity-assurance databases; and methods relying on publicly available data connected to a verified email address.

The operator could not require a government-issued identification document for age assurance. If the process determines that the user is a minor, the operator would have to obtain verifiable parental consent before allowing access.

The proposed data rules would limit the use of age-assurance and parental-consent information to assurance, consent, and demonstrating compliance. The operator could not sell, rent, share, or otherwise disclose that information except to a contracted service provider performing those functions. Personally identifiable information obtained for age assurance or parental consent could not be retained longer than 24 hours.

For companies, this means the compliance design would not end with selecting an age-assurance vendor. The operator would also need a defensible data map, retention schedule, vendor contract, and evidence that the information was not reused for unrelated purposes.

The Attorney General would enforce the act

HB 2006 would authorize the Pennsylvania Attorney General to issue guidance or promulgate regulations needed to carry out the act and would assign enforcement to the Attorney General.

An operator violating the act could face a civil penalty of up to $100,000 per day for each violation, along with additional remedies a court considers appropriate. A court also could issue injunctive relief upon a showing of cause.

The bill would require annual reporting beginning July 1, 2028. Operators would report deidentified information to the Attorney General, including crisis referrals, protocols addressing suicidal ideation and related content, minor-safety measures, and age-assurance and parental-consent procedures. The Attorney General would publish the collected information.

If enacted, the act would take effect 180 days after enactment. Those dates are contingent. The bill’s current text does not create a present compliance deadline because the measure remains pending.

What companies should watch next

The immediate legal question is procedural: whether the Senate takes up the House-passed measure and whether the text changes again. The posted PN 3747 text is an amended House version, so a later Senate amendment or substitute could change the duties described here.

The operational question is already clearer. Companies offering relationship-oriented AI should identify which products retain interaction history, simulate personal relationships, or use emotional engagement before assuming that a general chatbot policy answers the bill’s concerns.

The bill points toward a control structure built around five questions:

  1. When must the product disclose that it is not human, and how is recurring notice proved?
  2. What happens when a user expresses self-harm, suicidal intent, or an intent to harm someone else?
  3. Which content and engagement features are disabled for minors?
  4. How are age assurance and parental consent performed without creating a larger personal-data problem?
  5. What records demonstrate that the operator’s protocols worked as designed?

Pennsylvania has not answered those questions through enacted law yet. But HB 2006 shows how quickly AI companion regulation is moving from broad safety language toward specific product behavior, data handling, reporting, and enforcement requirements.

Sources

This article describes a pending bill and is general information, not legal advice. The bill’s text, amendments, procedural status, and any later Senate version should be checked before relying on it.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *