AI Regulation Guide · Multi-state (US)
US Conversational AI (Multi-State): who's covered, what it requires
US Conversational AI (Multi-State) carries 8 tracked obligations for companies in scope. This guide lists who is covered, the duty tiers, and every obligation with its deadline and statutory citation — all from Shieldra's versioned regulation pack, verified 2026-09-08.
Who does US Conversational AI (Multi-State) apply to?
Out of scope only if: No consumer-facing conversational AI reaching a covered state reported. This pack covers the 2025-26 state chatbot/companion/AI-therapy cluster, which attaches to conversational AI interacting with consumers in Maine, New York, the therapy-ban states (NV, IL, UT, RI, TN, VT, ME, CO, MO), Hawaii (in force since 14 July 2026), or the 2027-wave states (CO, WA, OR, RI, NE, ID, GA, IA). Internal-only and authenticated-B2B-only tools sit outside the cluster — re-screen on any consumer-facing launch or persona, memory, or wellness feature.
Cross-references: California SB 243 companion duties (in force, with a private right of action) live in the california_ai pack; Connecticut PA 26-15 §§4-6 companion duties (from 1 January 2027) live in the connecticut_cart pack; Utah HB 452's mental-health chatbot regime (Utah Code §13-72a) lives in the utah_aipa pack.
- What is your role for the conversational AI product?
- Do you operate, provide, or supply a conversational AI — chatbot, voice assistant, in-product AI persona, companion app, or wellness/coaching feature — that communicates with individual consumers, rather than exclusively with authenticated business users in internal or B2B tooling?
- Could a reasonable consumer be misled into believing they are communicating with a human — e.g., a human name, photo-realistic avatar, or human-simulating conversation without a clear upfront AI label?
- Is any bot designed to sustain an ongoing relationship or emotional engagement with the user across interactions — adaptive, human-like or emotional responses, memory or a persistent persona, or marketing as a companion, friend, romantic partner, or emotional support?
- Does any marketing copy, product name, persona, avatar, system prompt, or output state or imply — explicitly or implicitly — that the AI can provide therapy, counseling, psychotherapy, or mental or behavioral health care, or use titles such as 'therapist', 'counselor', 'psychologist', or 'psychiatrist'?
- Is the system specifically programmed to provide a service or experience that would constitute the practice of professional mental or behavioral health care if provided by a natural person — diagnosis, treatment, or prevention of mental illness or emotional or behavioral disorders — or does it independently conduct therapy sessions, make therapeutic decisions, or generate treatment plans?
- If a therapy flag could apply: is every such feature limited to self-help materials or advice that do not purport to offer professional care, OR administrative support for licensed providers (scheduling, records, billing, session notes) with independent accuracy review of AI output, OR otherwise delivered under a licensed professional's oversight within the relevant state carve-out?
- Can minors (under 18) access or use the bot — is it open to the general public without age assurance, directed at minors, or known to have minor users?
- Can consumers in Maine use the product?
- Can users in Hawaii use the product?
- Can users in New York use the product?
- Can users in any of Nevada, Illinois, Utah, Rhode Island, Tennessee, Vermont, Maine, Colorado, or Missouri use the product?
- Can users in any of Colorado, Washington, Oregon, Rhode Island, Nebraska, Idaho, Georgia, or Iowa use the product?
What are the duty tiers under US Conversational AI (Multi-State)?
AI-therapy flag — remediate now (Nev. AB 406 (2025), NRS ch. 433 new sections (anchor of the multi-state AI-therapy cluster))
Citation: Nev. AB 406 (2025), NRS ch. 433 new sections (anchor of the multi-state AI-therapy cluster) — https://archive.leg.state.nv.us/Session/83rd2025/Bills/AB/AB406_EN.pdf
Fires on a representation flag (which no safe harbor cures — Nevada bans explicit AND implicit representations; Tennessee bans the marketing itself) or on a specifically-programmed therapy function without a documented safe-harbor fit. Nevada's 'specifically programmed' element means incidental capability of a general-purpose bot does not trigger the function ban, but emotional- or mental-wellness marketing undermines that position. Companion and disclosure duties below still apply alongside remediation. Flag for legal review, never auto-concluded.
Companion-bot operator duties (N.Y. Gen. Bus. Law art. 47, §§1700–1704 (anchor; in force since 5 November 2025))
Citation: N.Y. Gen. Bus. Law art. 47, §§1700–1704 (anchor; in force since 5 November 2025) — https://www.nysenate.gov/legislation/laws/GBS/A47
The statutory companion definitions (sustained human-relationship simulation with adaptive or emotional responses) and the business-bot carve-outs decide coverage — a labeled support bot on narrow product topics is generally outside every companion law in this pack. Private rights of action are the sharp edge: Washington and Oregon from 1 January 2027 (Oregon at $1,000 statutory damages per violation), plus California SB 243 (in force — california_ai pack) and Connecticut PA 26-15 §§4-6 from 1 January 2027 (connecticut_cart pack).
In scope — disclosure hygiene and documented carve-out fit (10 M.R.S. §1500-DD (enacted as §1500-Y by P.L. 2025, c. 294; reallocated by RR 2025, c. 1) (Me. P.L. 2025, ch. 294; LD 1727))
Citation: 10 M.R.S. §1500-DD (enacted as §1500-Y by P.L. 2025, c. 294; reallocated by RR 2025, c. 1) (Me. P.L. 2025, ch. 294; LD 1727) — https://www.mainelegislature.org/legis/bills/display_ps.asp?LD=1727&snum=132
The dominant outcome for a labeled customer-support bot with no companion elements and no therapy claims: maintain non-human labeling (Maine's duty is in force with UTPA exposure) and keep a documented record of carve-out fit per state, re-screened on product changes.
What are the obligations and deadlines under US Conversational AI (Multi-State)?
| Obligation | Who | Deadline | Citation |
|---|---|---|---|
| Stop or restructure AI-therapy representations and functions | developer, deployer | in force in stages — UT since 7 May 2025, NV since 1 July 2025, IL since 1 August 2025, VT since 17 June 2026, RI since 22 June 2026, TN since 1 July 2026, ME since 29 July 2026, CO since 12 August 2026, MO since 28 August 2026 | Nev. AB 406 (NRS chs. 433/629 new sections); Ill. P.A. 104-0054; R.I. S 2197; Me. LD 2082; Tenn. SB 1580; Vt. Act 156; Colo. HB 26-1195; Utah Code §13-72a; Mo. SB 1019 (§407.3007) — https://archive.leg.state.nv.us/Session/83rd2025/Bills/AB/AB406_EN.pdf |
| Maine: disclose that the consumer is talking to AI, not a human | developer, deployer | in force since 24 September 2025 | 10 M.R.S. §1500-DD (enacted as §1500-Y by P.L. 2025, c. 294; reallocated by RR 2025, c. 1) (Me. P.L. 2025, ch. 294; LD 1727) — https://legislature.maine.gov/statutes/10/title10sec1500-DD.html |
| New York: AI-companion disclosure cadence and crisis protocol | developer, deployer | in force since 5 November 2025 | N.Y. Gen. Bus. Law art. 47, §§1700–1704 — https://www.nysenate.gov/legislation/laws/GBS/A47 |
| Hawaii: conversational-AI disclosure, minor safeguards, crisis protocol, and no professional-care representation | developer, deployer | in force since 14 July 2026 (Act 248); annual report to the Department of Health from 1 January 2028 | Haw. Act 248 (2026) (SB 3001 CD1) — https://data.capitol.hawaii.gov/sessions/session2026/bills/SB3001_CD1_.HTM |
| 2027 wave: general conversational-AI duties (CO, NE, ID, IA) — crisis protocol and no-therapy-representation | developer, deployer | applies from 1 January 2027 (CO HB 26-1263) and from 1 July 2027 (NE LB 525, ID S 1297, IA SF 2417) | Idaho Code 48-2103(2)–(3) (S 1297); Neb. LB 525 secs. 16–17; Colo. HB 26-1263; Iowa SF 2417 (Iowa Code ch. 554J) — https://legislature.idaho.gov/wp-content/uploads/sessioninfo/2026/legislation/S1297E1.pdf |
| Get ready for the 2027 conversational-AI wave (CO, WA, OR, RI, NE, ID, GA, IA) | developer, deployer | applies from 1 January 2027 (CO HB 26-1263, WA HB 2225, OR SB 1546, RI S 2195) and from 1 July 2027 (NE LB 525, ID S 1297, GA SB 540, IA SF 2417) | Colo. HB 26-1263; Wash. HB 2225; Or. SB 1546; R.I. S 2195; Neb. LB 525; Idaho S 1297; Ga. SB 540; Iowa SF 2417 — https://leg.colorado.gov/bills/HB26-1263 |
| Maintain persistent non-human labeling on every consumer surface | developer, deployer | earliest binding duty (Maine) in force since 24 September 2025 | 10 M.R.S. §1500-DD (enacted as §1500-Y by P.L. 2025, c. 294; reallocated by RR 2025, c. 1) (anchor); N.Y. GBL art. 47; Utah Code §13-2-12/13-72; Cal. B&P Code §22601 et seq. — https://legislature.maine.gov/statutes/10/title10sec1500-DD.html |
| Document per-state carve-out and safe-harbor fit; re-screen on product changes | developer, deployer | in-force layer (Maine, New York, Hawaii, therapy bans) — document current fit; earliest duty in force since 24 September 2025; re-verify before the first 2027-wave duties apply from 1 January 2027 | Neb. LB 525 (business-entity/narrow-topic exclusions); Ga. SB 540; Wash. HB 2225; N.Y. GBL art. 47; Nev. AB 406 safe harbors — https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB525.pdf |
What should you do about each obligation?
Stop or restructure AI-therapy representations and functions (Nev. AB 406 (NRS chs. 433/629 new sections); Ill. P.A. 104-0054; R.I. S 2197; Me. LD 2082; Tenn. SB 1580; Vt. Act 156; Colo. HB 26-1195; Utah Code §13-72a; Mo. SB 1019 (§407.3007))
Stop, redesign, or geo-restrict before exposure: Nevada prohibits making an AI system available that is specifically programmed to provide services constituting professional mental or behavioral health care AND any explicit or implicit representation of such capability (including therapist-type titles or avatars) — Division of Public and Behavioral Health enforcement, civil penalties up to $15,000 per violation, no cure period, no private right of action. Illinois bars AI from independently providing therapy or making therapeutic decisions, permitting only administrative or supplementary roles under a licensed professional's oversight (IDFPR, penalties up to $10,000 per violation); Rhode Island bars independent AI therapeutic decisions, requires written consent before AI use in recorded sessions, and limits internet-based AI therapy to licensed professionals; Maine requires a licensed professional for any therapy or psychotherapy service, including AI-delivered; Tennessee bans marketing an AI system as a qualified mental health professional. Colorado HB 26-1195 (in force since 12 August 2026) makes providing or advertising psychotherapy through AI by anyone other than a regulated professional a deceptive trade practice — with carve-outs for education, IRB research, and self-help tools carrying a disclaimer — and restricts how licensed providers may use AI (no therapeutic communication except synchronously with the provider present, provider review of AI recommendations, written consent for recording); enforcement runs through DORA board discipline with administrative fines up to $5,000 and Colorado Consumer Protection Act civil penalties up to $20,000. Remediation paths: scrub therapy claims, titles, and personas from marketing, avatars, system prompts, and outputs, and either restructure into a state safe harbor (self-help content not purporting to offer professional care, or licensed-provider administrative support with independent accuracy review) or geo-restrict — noting that Nevada separately bars even licensed providers from using AI to provide care directly to patients. Vermont Act 156 (signed 17 June 2026) took effect immediately on passage — the AI-only-therapy ban has been in force since 17 June 2026, enforced through Vermont's Consumer Protection Act (9 V.S.A. ch. 63) including private civil actions. Missouri SB 1019 has applied since 28 August 2026: AI-therapy representations become unlawful practices under the Missouri Merchandising Practices Act ($10,000 first / $20,000 subsequent offenses). Tennessee SB 1580 violations are unfair/deceptive acts under the Tennessee Consumer Protection Act with civil penalties up to $5,000 per violation PLUS a private right of action for affected individuals.
Maine: disclose that the consumer is talking to AI, not a human (10 M.R.S. §1500-DD (enacted as §1500-Y by P.L. 2025, c. 294; reallocated by RR 2025, c. 1) (Me. P.L. 2025, ch. 294; LD 1727))
Give a clear and conspicuous disclosure, at the outset of the interaction, that the consumer is communicating with an AI system and not a human, wherever the technology may mislead or deceive a reasonable consumer into believing they are engaging with a human being. The duty reaches any person using such technology in trade and commerce with Maine consumers — no companion element, no size threshold, and no customer-service carve-out. A violation is an unfair trade practice under the Maine UTPA — Attorney General enforcement with civil penalties up to $10,000 per intentional violation (5 M.R.S. §209), plus private UTPA actions for consumers who lost money or property (5 M.R.S. §213). A persistent, prominent AI label at the start of every session satisfies the trigger and is the cheapest fix in this pack.
New York: AI-companion disclosure cadence and crisis protocol (N.Y. Gen. Bus. Law art. 47, §§1700–1704)
Disclose the non-human status of the AI companion at the start of each session and at least every three hours of continued interaction, and implement a protocol for detecting expressions of suicidal ideation or self-harm that refers users to crisis services such as the 988 lifeline. The Attorney General enforces with civil penalties up to $15,000 per day, and the Governor's office wrote directly to companion operators when the law took effect in November 2025 — enforcement attention is real. The duties bind operators of 'AI companions' (systems sustaining personalized conversations that simulate a human relationship); an ordinary customer-support or productivity bot falls outside the definition, and that determination should be documented.
Hawaii: conversational-AI disclosure, minor safeguards, crisis protocol, and no professional-care representation (Haw. Act 248 (2026) (SB 3001 CD1))
Disclose that the user is interacting with AI wherever a reasonable person could otherwise be misled, apply the minor-user protections, maintain a suicide and self-harm crisis protocol with referral to crisis services, and do not represent the service as providing licensed psychology or behavioral-health services. Enforced as an unfair or deceptive practice under HRS §480-2 by the Attorney General and the Office of Consumer Protection, with no private right of action; the duties sit on the operator, not the upstream model developer. The annual report to the Department of Health's Behavioral Health Administration is due from 1 January 2028.
2027 wave: general conversational-AI duties (CO, NE, ID, IA) — crisis protocol and no-therapy-representation (Idaho Code 48-2103(2)–(3) (S 1297); Neb. LB 525 secs. 16–17; Colo. HB 26-1263; Iowa SF 2417 (Iowa Code ch. 554J))
These four states reach ALL in-scope consumer conversational AI services — companion elements, human-mimicry, or minor access are NOT required. Idaho (from 1 July 2027, Idaho Code 48-2103(2)–(3)) and Nebraska (from 1 July 2027, LB 525 secs. 16–17) require a suicidal-ideation crisis-referral protocol and prohibit explicitly representing the service as providing professional mental or behavioral health care; Colorado HB 26-1263 (from 1 January 2027) adds a disclosure cadence (start of the first interaction each day and every three hours, or a persistent indicator, plus on request), a false-representation ban covering licensed health-care, legal, mental-health, and dietitian services, and annual protocol reporting to the Attorney General. Iowa SF 2417 (Iowa Code ch. 554J, from 1 July 2027) reaches all public conversational AI services with reasonable-person disclosure (persistent or at least every three hours), minor protections, a crisis protocol, and a ban on representations that a reasonable person would read as licensed psychology or behavioral-health services — Attorney General only, $1,000 per violation up to $500,000 per operator or actual damages, no private right of action. Build the crisis-referral protocol once (detection, referral to the 988 Suicide & Crisis Lifeline, documentation) and keep marketing/system prompts free of professional-care representations. Developer shields: ID 48-2105(3), NE sec. 18(4), IA ch. 554J, and GA (m)(5) place these duties on the operator, not the upstream model developer.
Get ready for the 2027 conversational-AI wave (CO, WA, OR, RI, NE, ID, GA, IA) (Colo. HB 26-1263; Wash. HB 2225; Or. SB 1546; R.I. S 2195; Neb. LB 525; Idaho S 1297; Ga. SB 540; Iowa SF 2417)
Build once for the strictest requirements and you cover the wave: non-human disclosure at the outset with a redisplay cadence (Washington every 3 hours, hourly for minors; Georgia at the beginning of each interaction or session and every 3 hours, dropping to hourly for known-minor users or minor-directed bots; Rhode Island at initiation and every 3 hours), suicide/self-harm detection with crisis referral (Washington requires a detection protocol (expressly including eating-disorder expressions), crisis-resource referral (suicide hotline / crisis text line), prevention of content encouraging or describing self-harm methods, and public disclosure of the protocol plus the yearly count of crisis referrals), minor safeguards (Georgia: commercially reasonable age assurance before access to any sexually-explicit-capable feature (24-hour data-retention cap), plus screen-time/privacy/safety tools for known minor accounts; Colorado commercially reasonable age estimation plus, for known minors, bans on engagement-maximizing incentive features, sexually explicit content, and emotional-dependency mechanics; Nebraska always-disclose-to-minors plus a sexually-explicit prohibition), and annual transparency duties — Oregon: public website report by 31 December each year (referral counts + protocol details, nothing is filed with the state); Rhode Island: annual AG reports beginning 1 July 2027; Colorado: annual protocol reports to the AG; Washington and Georgia: public disclosure of protocol details and yearly crisis-referral counts. Enforcement sharp edges: private rights of action in Washington and Oregon (Oregon at $1,000 statutory damages per violation), Rhode Island penalties up to $15,000 per day, Georgia AG penalties up to $10,000 per knowing violation, Nebraska (civil penalties of at least $1,000 per violation capped at $500,000 per operator, plus actual damages) and Idaho and Iowa Attorney-General-only; Georgia counts each day per affected user as a separate violation and allows a discretionary 30-day cure for first-time non-knowing violations. The carve-outs are the screen: Nebraska excludes applications primarily designed and marketed for commercial use by business entities and bots limited to narrow and discrete topics; Georgia excludes internal business tools, customer service chatbots, and educational tools; Washington excludes business-oriented and gaming bots, general virtual assistants, and narrowly tailored educational tools; Idaho follows the Nebraska model, with nine enrolled exclusions including customer-service, internal, and enterprise-contract bots; note that Colorado HB 26-1263 covers conversational AI services offered to Colorado users generally, not only companions. Hawaii Act 248 (SB 3001, signed 14 July 2026) already imposes comparable duties — in force on approval, with the annual Department of Health report starting 1 January 2028 — and is screened separately through the Hawaii reach question; parallel companion duties under California SB 243 (in force, private right of action) and Connecticut PA 26-15 §§4-6 (from 1 January 2027) live in the california_ai and connecticut_cart packs.
Maintain persistent non-human labeling on every consumer surface (10 M.R.S. §1500-DD (enacted as §1500-Y by P.L. 2025, c. 294; reallocated by RR 2025, c. 1) (anchor); N.Y. GBL art. 47; Utah Code §13-2-12/13-72; Cal. B&P Code §22601 et seq.)
Label every consumer-facing conversational surface as AI — a persistent, conspicuous non-human indicator at session start, and in the persona name where practical — and treat removing or weakening the label as a regulated product change. This single control satisfies the in-force Maine trigger, provides the baseline for the New York and 2027-wave cadence duties, and defuses the 'could a reasonable person be misled' element that most of the cluster hooks on; Utah's generative-AI disclosure duties (utah_aipa pack) and California SB 243's reasonable-person trigger (california_ai pack) point the same way. Keep screenshots and change logs of the labeling as compliance evidence.
Document per-state carve-out and safe-harbor fit; re-screen on product changes (Neb. LB 525 (business-entity/narrow-topic exclusions); Ga. SB 540; Wash. HB 2225; N.Y. GBL art. 47; Nev. AB 406 safe harbors)
Record a per-state determination of why each statute does not reach the product: which carve-out or definitional element applies (Nebraska's business-entity and narrow-and-discrete-topic exclusions; Colorado HB 26-1263's commerce/customer-service, narrow-topic, business-entity, virtual-assistant, internal, HIPAA-entity, and educational exclusions; Georgia's customer-service, internal-tool, and educational exclusions; Washington's business-oriented, gaming, and virtual-assistant exclusions; New York's human-relationship companion definition; the Nevada/Illinois therapy safe harbors — self-help not purporting to offer professional care, or licensed-provider administrative support with independent accuracy review). Re-run the screen on any consumer-facing launch, persona or memory feature, wellness or emotional-support feature, or marketing change — the carve-outs are behaviour- and marketing-dependent, and a single feature release can silently move you into the companion or therapy tiers. This file is your first response to an AG inquiry and your evidence of good faith.
Disclaimer
Compliance guidance, not legal advice. Confirm obligations with counsel. Content version 2026.09.08-1, verified 2026-09-08.
Frequently asked questions
Who does US Conversational AI (Multi-State) apply to?
No consumer-facing conversational AI reaching a covered state reported. This pack covers the 2025-26 state chatbot/companion/AI-therapy cluster, which attaches to conversational AI interacting with consumers in Maine, New York, the therapy-ban states (NV, IL, UT, RI, TN, VT, ME, CO, MO), Hawaii (in force since 14 July 2026), or the 2027-wave states (CO, WA, OR, RI, NE, ID, GA, IA). Internal-only and authenticated-B2B-only tools sit outside the cluster — re-screen on any consumer-facing launch or persona, memory, or wellness feature. Coverage turns on the screening questions listed on this page — each obligation then applies its own statutory gate.
When does US Conversational AI (Multi-State) take effect?
in force in stages — UT since 7 May 2025, NV since 1 July 2025, IL since 1 August 2025, VT since 17 June 2026, RI since 22 June 2026, TN since 1 July 2026, ME since 29 July 2026, CO since 12 August 2026, MO since 28 August 2026. in force since 24 September 2025. in force since 5 November 2025. in force since 14 July 2026 (Act 248); annual report to the Department of Health from 1 January 2028. applies from 1 January 2027 (CO HB 26-1263) and from 1 July 2027 (NE LB 525, ID S 1297, IA SF 2417). applies from 1 January 2027 (CO HB 26-1263, WA HB 2225, OR SB 1546, RI S 2195) and from 1 July 2027 (NE LB 525, ID S 1297, GA SB 540, IA SF 2417). earliest binding duty (Maine) in force since 24 September 2025. in-force layer (Maine, New York, Hawaii, therapy bans) — document current fit; earliest duty in force since 24 September 2025. re-verify before the first 2027-wave duties apply from 1 January 2027
What are the obligations under US Conversational AI (Multi-State)?
Stop or restructure AI-therapy representations and functions; Maine: disclose that the consumer is talking to AI, not a human; New York: AI-companion disclosure cadence and crisis protocol; Hawaii: conversational-AI disclosure, minor safeguards, crisis protocol, and no professional-care representation; 2027 wave: general conversational-AI duties (CO, NE, ID, IA) — crisis protocol and no-therapy-representation; Get ready for the 2027 conversational-AI wave (CO, WA, OR, RI, NE, ID, GA, IA); Maintain persistent non-human labeling on every consumer surface; Document per-state carve-out and safe-harbor fit; re-screen on product changes.