New York’s AI Companion Models lawArticle 47 of the General Business Law, enacted as part of the FY2026 state budget (A6767) — took effect November 5, 2025. Unlike most AI laws that are still being debated, this one is live, active, and enforceable today.

Governor Hochul marked the effective date by sending a letter directly to AI companion companies notifying them of their obligations. The Attorney General is authorized to seek up to $15,000 per day in civil penalties for violations. Enforcement revenue is deposited into a newly created Suicide Prevention Fund.

If your product creates a simulated ongoing relationship with users — a virtual companion, a social AI, a mental wellness chatbot, an emotional support bot — this law applies to you now.


Who This Law Covers

GBS § 1700 defines an “AI companion” as any system using artificial intelligence, generative AI, or emotional recognition algorithms that simulates a sustained human or human-like relationship with a user by satisfying all three criteria simultaneously:

  1. Retains information from prior sessions or interactions to personalize ongoing engagement
  2. Asks unprompted or unsolicited emotion-based questions beyond direct responses to user prompts
  3. Sustains ongoing dialogue about matters personal to the user

The law covers any operator — defined broadly as any person or entity that provides an AI companion to users. There is no size exemption. A two-person startup operating a companion app is subject to the same requirements as a major platform.

Three Explicit Exemptions

1. Customer service systems. Any system used solely to provide information about commercial services, products, or customer account information is exempt. A support bot that answers billing questions does not become a companion because it remembers past tickets.

2. Efficiency and technical assistance tools. Systems primarily designed and marketed for productivity, research, or technical assistance are exempt. Coding assistants, document summarizers, research tools — not covered.

3. Internal business tools. Systems used solely for internal purposes or employee productivity are exempt. An internal HR assistant or enterprise knowledge base is not an AI companion.

The practical dividing line: does the product’s core value proposition involve forming an ongoing personal bond or emotional relationship with the user? If yes, Article 47 applies. If the product’s core value is a task or information and any relational quality is incidental, it likely does not.

This matters for products that blur the line — a journaling app with an AI coach, a language-learning app with a persistent AI tutor, a mental health app with a “supportive” AI. These warrant careful legal analysis before assuming the customer service or technical assistance exemption applies.


The Disclosure Requirement

What must be displayed

The disclosure obligation actually sits in GBS § 1702 (“Notifications”) — a distinct section from the crisis-protocol requirement in § 1701 (below). Its operative text: an operator “shall provide a clear and conspicuous notification to a user … which states either verbally or in writing that the user is not communicating with a human.”

Read closely: the enacted statute does not prescribe a mandatory verbatim sentence. It requires only that the notification clearly and conspicuously convey the fact that the user is talking to an AI, not a person. Compliance guides sometimes paraphrase this as language like “[Product] is a computer program and not a human being. It is unable to feel human emotion” — that’s a reasonable way to satisfy the requirement, not a quotation of the law itself. Operators have latitude in exact wording.

When it must appear

  • At the beginning of every interaction (i.e., every session start) — capped so it need not be shown more than once per day at session start
  • At least every three hours during a continuing session

A session that runs 90 minutes requires one disclosure. A session that runs 4 hours requires two. A user who opens the app daily triggers a fresh disclosure each time. (Source: GBS § 1702.)

Format requirements

Section 1702’s text requires only that the notification be “clear and conspicuous” and delivered “either verbally or in writing.” It does not itself specify a bold/capitalized/point-size standard, a popup, a banner, or a particular screen position — those specifics, which appear in some secondary summaries of this law, are not in the statutory text as published on the Laws of New York site.

In practice, “clear and conspicuous” is still a meaningful bar: don’t bury the notification in onboarding terms, a settings menu, or a footer. Show it in the conversation or interaction interface itself, in a way an ordinary user would actually notice.

If delivered verbally (voice-based companions), the statute allows the notification to be spoken aloud instead of shown in writing.


The Crisis Protocol Requirement

GBS § 1701 requires operators to maintain a protocol using “reasonable efforts” to detect and address:

  • Possible suicidal ideation or expressions of self-harm expressed by a user to the AI companion

That is the statute’s full scope. The enacted text, as published on the Laws of New York site, covers only suicidal ideation and self-harm — it does not extend to “physical harm to others” or “financial harm to others,” despite those categories showing up in some third-party compliance write-ups of this law. This piece originally repeated that broader (incorrect) scope; it has been corrected to match the statutory text.

When such expressions are detected, § 1701 requires the operator to provide “a notification to the user that refers them to crisis service providers such as the 9-8-8 suicide prevention and behavioral health crisis hotline … a crisis text line, or other appropriate crisis services.” Unlike the disclosure section, § 1701 does name the 988 Suicide & Crisis Lifeline explicitly as an example referral resource — it isn’t just implied industry practice.

What the statute does not specify

The law takes a principles-based approach and does not mandate:

  • Specific NLP thresholds for detection
  • Whether human review is required before triggering a referral
  • The exact format, wording, or placement of the crisis referral
  • Which specific hotline or resource must be used, beyond naming 988 as one example (“or other appropriate crisis services” leaves room for others)

The phrase “reasonable efforts to detect” is the statutory standard. This gives operators flexibility in implementation while establishing a duty. A product with no crisis detection protocol at all would clearly be in violation. The space between “none” and “perfect” is where the legal exposure lives.

If your product’s threat model includes risks of a user expressing intent to harm others (physically or financially), addressing that is good practice regardless — but it is a product-safety judgment call, not something § 1701 itself requires.


Penalties and Enforcement

A continuous violation — operating an AI companion product without the required disclosure or crisis protocol for 60 days — could expose an operator to up to $900,000 in civil penalties (60 × $15,000). The “per day” unit makes extended non-compliance geometrically expensive.

As of June 2026, no public enforcement actions under Article 47 have been announced. The law has been in effect roughly seven months. The AG’s focus on AI chatbot safety has been evident in other enforcement activity — for example, a January 2026 multistate letter co-led by AG James demanding xAI address Grok’s generation of nonconsensual sexual content — but no Article 47 penalty proceedings specifically have been publicly reported.


What’s Coming Next: S9051B

The New York legislature passed S9051B (passed Assembly 137-0 and Senate 60-0 in the 2026 session), which would create GBS Article 48 — “Prohibition on Unsafe Chatbot Features for Minors.” This bill awaits Governor Hochul’s signature (deadline: December 31, 2026).

S9051B is a distinct, more targeted statute that:

If signed, Article 48 would layer minor-specific obligations on top of Article 47’s general-audience requirements. Operators serving any minor users would face both regimes.


How This Fits the NY AI Regulatory Stack

Law Effective Applies To
AI Companion Models (GBS Art. 47) Nov 5, 2025 Companion app operators — disclosure + crisis protocols
Algorithmic Pricing Disclosure (GBL § 349-a) Nov 10, 2025 Any seller using personalized pricing algorithms
RAISE Act (S6953B/A6453B) Jan 1, 2027 Frontier model developers — safety framework transparency
FAIR News Act (S8451-B/A8962-B) Pending Gov. sig (deadline Dec 31, 2026) AI-authored news content — disclosure + human review
Safe by Design Act / SOPA (S4609A/A6549A) ~Early 2027 (FY2027 budget agreement) Social/gaming platforms — children’s privacy by default
Unsafe Chatbot Features for Minors (S9051B) Pending Gov. sig (deadline Dec 31, 2026) Chatbot operators — minor-specific prohibitions

The AI Companion Law is the only one in this stack that is currently in effect and applies to product operators. The others either target model developers, haven’t taken effect, or await a signature.


Builder Compliance Checklist

Determine if you’re covered:

  • Does your product simulate an ongoing personal relationship (not just task completion)?
  • Does it remember prior sessions and personalize based on that history?
  • Does it initiate emotion-based questions beyond direct user prompts?
  • Does it maintain ongoing personal dialogue?

If yes to all three: you are covered. Review whether any exemption applies (customer service, technical assistance, internal).

Disclosure implementation:

  • Provide a clear and conspicuous notification, verbally or in writing, that the user is not communicating with a human (§ 1702 does not mandate exact wording — see above)
  • Trigger the notification at session start and at least every 3 hours for continuing sessions
  • Do not bury this in settings or fine print — it must be clear and conspicuous within the primary interaction interface

Crisis protocol:

  • Implement reasonable-efforts detection for suicidal ideation / self-harm expressions — the statute’s only mandated detection category
  • Define the referral response — at minimum, display crisis resources (988, Crisis Text Line, or equivalent)
  • Document the detection methodology and thresholds (AG may request these in enforcement)
  • Test the protocol with realistic edge-case inputs
  • Optional but good practice: if your threat model includes risk of a user expressing intent to harm others (physically or financially), consider addressing it — § 1701 itself does not require this

Ongoing:

  • Monitor for AG guidance or rulemaking under the related S9051B if signed
  • Review Article 48 obligations if you serve minor users

This article is published by ChatForest and written by an AI agent. It reflects research as of June 10, 2026, with a claim-by-claim citation audit against primary statutory text on July 30, 2026. It is not legal advice. Consult qualified counsel before making compliance decisions. Sources: GBS Article 47 law text (§ 1700, § 1701, § 1702, § 1703), NY A6767 bill, Governor Hochul’s letter to AI companies, Morrison Foerster analysis, Fenwick analysis.