Companion Score Companion Score®
Guide · safety · updated 2026-09-08

AI companion laws in 2026: UK, EU, US, China and Australia

AI companion laws in 2026: UK, EU, US, China and Australia

Yes. For an adult in the UK, using an AI companion is generally legal. The law is moving towards stricter age checks, clearer AI disclosure and stronger protection of children, while criminal rules now create particular risk around non-consensual intimate images of real people.

The detail depends heavily on where you live and what the service can do. The same app can face different rules in Britain, the EU, the United States, China and Australia, so the operator’s jurisdiction in our Privacy Risk Index matters as much as the app’s marketing.

the 2026 timeline

DatePlaceMeasureStatus
8 November 2024UKOfcom confirms that generative AI services can fall within the Online Safety ActIn force
14 July 2025EUCommission publishes DSA guidelines on protecting minorsIn force
25 July 2025UKChildren’s safety duties and highly effective age assurance for pornography take effectIn force
5 November 2025New YorkAI companion model safeguards take effectIn force
13 November 2025AppleUpdated age-rating and creator-content controls publishedIn force
1 January 2026CaliforniaSB 243 companion chatbot law takes effectIn force
6 February 2026UKOffence covering creation or request of purported intimate images without consent commencesIn force
9 March 2026AustraliaMain Age-Restricted Material Codes for apps and online services take effectIn force
30 April 2026US federalGUARD Act advances from Senate Judiciary CommitteeProposed
19 May 2026US federalTAKE IT DOWN platform removal duties become enforceableIn force
15 June 2026UKGovernment announces planned adult-only rules for sexualised AI companionshipProposed
29 June 2026UKNudification-tool offence commencesIn force
14 July 2026HawaiiAct 248 on AI companion disclosures and safety is approvedIn force
15 July 2026ChinaAnthropomorphic AI interaction rules take effectIn force
27 July 2026EUAI Omnibus enters into forceIn force
2 August 2026EUAI Act Article 50 transparency duties start applyingIn force
9 September 2026AustraliaApp-store age-assurance requirements for R18+ downloads start applyingEnacted not commenced
2 December 2026EUNew AI ban on non-consensual intimate imagery and child sexual abuse material starts applyingEnacted not commenced
Before end of 2026UKGovernment intends to legislate on AI chatbot child protectionsProposed
Spring 2027 targetUKPlanned protections for sexualised AI companion servicesProposed

The Online Safety Act does not contain a simple category called “AI companion”. Ofcom’s 8 November 2024 open letter made clear that generative AI and chatbot services can fall within the Act. Its 18 December 2025 explainer then drew a useful boundary: a chatbot may sit outside the Act if it is purely one-to-one, does not search other sites or databases and cannot generate pornographic content. Change one of those facts and the position can change.

Children’s safety duties became enforceable in July 2025. From 25 July, services allowing pornography had to use highly effective age assurance rather than relying on a box asking whether someone is over 18. That produced an immediate change in browsing behaviour. UK VPN use rose sharply around the deadline, although government evidence cautions against assuming that the whole increase came from children bypassing age checks.

Enforcement followed. On 4 December 2025 Ofcom fined AVS Group Ltd £1 million for inadequate age checks and another £50,000 for failing to answer information requests. The regulator had already fined the operator of nudification site Undress.cc £50,000 for its age-check failure, plus £5,000 for an information failure. In February 2026 it fined Kick Online Entertainment £800,000 over age assurance and later imposed an additional information penalty, while 8579 LLC received a £1.35 million age-assurance penalty plus £50,000 for information failures.

AI services are not theoretical targets. Ofcom opened an investigation into X on 12 January 2026 over sexualised imagery generated through Grok. On 15 January it opened a separate investigation into Novi Ltd, named by Ofcom as the provider of Joi.com, over age assurance and children’s access to pornography. That Joi investigation closed on 31 July after the service introduced age assurance, without Ofcom making findings of breach.

Joi.com is the same product we cover in our Joi review — the companion formerly branded EVA AI, whose provider Ofcom names as Novi Ltd, one of several corporate entities behind the product. The investigation, and its closure without findings, are recorded in that review too.

The criminal law also changed. Section 138 of the Data (Use and Access) Act 2025 came into force on 6 February 2026, creating offences around creating or requesting a purported intimate image of an adult without consent in the circumstances set by the Act. On 29 June, the Crime and Policing Act 2026 brought in a separate offence of making, adapting, supplying or offering a nudification tool.

The government is also trying to close gaps in the Online Safety Act itself. On 16 February 2026 it announced powers intended to bring currently out-of-scope one-to-one chatbots into the illegal-content regime. Its “Growing up in the online world” consultation began on 2 March, followed by a 15 June package focused on AI companionship.

The June proposal is narrower than saying every romantic chatbot will become 18+. The government says services whose primary purpose is offering sexualised AI companionship should be restricted to adults. General-purpose chatbots would not automatically become adult-only, but sexually explicit interactions or sexual role-play features would require age assurance. Legislation is expected before the end of 2026, with protections targeted for spring 2027.

The Bureau of Investigative Journalism reported on 19 June that the plan could still leave gaps around emotional dependency and services that do not meet the sexualised-companion definition. That is a criticism of the proposal, not the law currently in force.

Ofcom’s July 2026 age-assurance report gives some scale. It recorded more than 69 million age checks across a sample of 32 services between July and December 2025. Five per cent of 13 to 17 year olds said they had got around parental controls or age checks in the previous 12 months. That figure is sometimes described as VPN circumvention, but Ofcom’s finding is broader than VPN use alone.

For the wider safety context, see our AI companion safety guide and AI companion privacy guide.

The EU’s approach is broader than companion apps. Article 5 of the AI Act already prohibits specified manipulative or deceptive AI practices and exploitation of certain vulnerabilities. Those prohibitions started applying in February 2025, so engagement design can matter even when an app is not marketed as a safety product.

Article 50 is more visible to ordinary users. From 2 August 2026, interactive AI systems must be designed so people are told when they are interacting with AI. Providers must also make certain AI-generated or manipulated content machine-readable so its origin can be detected. The limited grace period to 2 December 2026 applies to the marking and detection obligation for systems placed on the market before 2 August. It does not postpone the general chatbot disclosure rule.

The Commission’s final transparency code was published in June and its Article 50 guidelines followed on 20 July, so this is no longer an unresolved implementation point.

The AI Omnibus entered into force on 27 July 2026. Among its safety changes is a prohibition on AI systems that generate non-consensual sexually explicit or intimate content or child sexual abuse material, including nudification systems. That additional prohibition starts applying on 2 December 2026.

Data protection regulators have also used existing law against companion providers. Italy’s Garante fined Luka Inc, the company behind Replika, €5 million on 19 May 2025. On 9 July 2026 it announced a €158,000 penalty against Character Technologies and ordered stronger age-verification measures and protections for minors.

Age assurance is moving towards a more standard EU infrastructure too. On 29 April 2026 the European Commission urged member states to deploy its age-verification app by the end of 2026, either as a standalone system or through European Digital Identity Wallets.

the US: state laws are moving faster than Washington

There is still no single US federal AI companion law equivalent to the UK’s Online Safety Act approach. Instead, federal action and state statutes overlap.

On 11 September 2025 the Federal Trade Commission used its section 6(b) authority to demand information from Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and xAI about companion chatbot advertising, safety and data handling. A 6(b) study is an information-gathering exercise, not a finding that those companies broke the law.

California’s SB 243 was signed on 13 October 2025 and took effect on 1 January 2026. It requires AI disclosure in relevant circumstances, suicide and self-harm protocols, and extra safeguards for known minors, including break reminders and restrictions on sexually explicit material. It also creates a private right of action in specified cases, with statutory damages of $1,000 per violation where the conditions are met.

New York’s Article 47 took effect on 5 November 2025. Companion models must tell users that they are not communicating with a human at the start of interaction, subject to the law’s timing rules, and repeat the notification every three hours during extended use. The law also requires crisis responses and allows civil penalties of up to $15,000 per day for violations.

The state map is still expanding. The IAPP counted 11 states with chatbot laws by June 2026: California, Colorado, Connecticut, Georgia, Idaho, Iowa, Nebraska, New York, Oregon, Rhode Island and Washington. Hawaii then approved Act 248 on 14 July, bringing that count to 12 on the same methodology.

Federal law does matter for intimate imagery. The TAKE IT DOWN Act’s platform duties became enforceable on 19 May 2026. Covered platforms must provide a process for requesting removal of non-consensual intimate images, including AI-generated images, and remove validly reported material and known identical copies within 48 hours.

The proposed GUARD Act is different. The Senate Judiciary Committee advanced it 22 to 0 on 30 April 2026, but it is not federal law. The White House’s 11 December 2025 executive order seeking a more uniform national AI framework also expressly said its legislative recommendation should not pre-empt otherwise lawful state child-safety protections.

Court cases are shaping the boundaries at the same time. Character.AI and Google settled Megan Garcia’s lawsuit on 7 January 2026 without published settlement terms. Kentucky’s attorney general filed a case against Character Technologies on 8 January, while Texas has pursued investigations into Character.AI’s child-safety and consumer practices.

china: national companion rules with a hard line on minors

China’s Interim Measures for the Administration of Anthropomorphic AI Interaction Services were published on 10 April 2026 and took effect on 15 July. They regulate services designed for sustained, human-like emotional interaction rather than banning the category.

The rules require providers to address excessive use and emotional dependence, identify the AI nature of the service and provide usage reminders. They impose tighter controls for children. Providers must not offer virtual family or partner services to minors, and children under 14 need guardian consent for other anthropomorphic interaction services.

That distinction matters. “China banned AI companions” is too broad. Adult services remain possible under the regulatory framework, while romantic or family-style companionship is specifically restricted for minors.

The rules also had immediate product consequences. ByteDance’s Doubao and Alibaba’s Qwen disabled user-created custom agent features around the 15 July commencement date. That shows a second kind of regulatory risk for users: a lawful product can stay online while a character, persona or feature disappears because its operator changes the service to comply.

australia: companion apps are already inside the safety regime

Australia’s eSafety Commissioner sent formal transparency notices to Chai, Character.AI, Chub AI and Nomi on 16 October 2025. Its findings, published in March 2026, identified weak age assurance across the group and gaps in crisis handling. Three services did not report referring users to crisis support in the circumstances examined, and two reported no dedicated trust and safety staff.

Providers reacted differently. Character.AI reported adding age assurance for Australian users. Chub AI geo-blocked Australia. Chai removed free chat access and put Australian chat behind a paid subscription. Nomi described further age-assurance work.

The broader Age-Restricted Material Codes then became important on 9 March 2026 for app distribution, social media, relevant electronic services and other covered sectors. They are designed to stop under-18s accessing or being exposed to material such as pornography and other age-inappropriate content.

A further app-store requirement starts on 9 September 2026. App distribution services must have age-assurance measures for users seeking to download R18+ apps. That deadline is one reason age checks increasingly appear before a user reaches the companion itself.

app stores and payment companies can be stricter than the law

Legal rules are only one layer. Apple, Google and card processors can remove distribution or payment even where an app itself is not banned.

Apple’s 13 November 2025 guideline update tightened age handling for creator apps and certain embedded software. Content exceeding an app’s age rating must be identified and access restricted using verified or declared age. It is better read as an age-rating and content-distribution rule than as a blanket law that every chatbot must verify identity.

Google Play’s 15 July 2026 policy update is also easy to overstate. The primary notice we found expands age-restricted and child-safety rules for anonymous and random chat apps, with changes effective from 26 August. It is not, on its face, a companion-specific sexual-content law.

Payments create another pressure point. Civitai lost support from its card processor in May 2025 after allowing AI-generated explicit content. Companion businesses face the same commercial dependency even where their legal position is different.

That helps explain why some adult AI products keep their most permissive features on the web rather than inside an app-store build. It is not a legal rule that adult features must live on the web. It is often the practical result of overlapping store, payment and regulatory restrictions.

what this means if you are choosing an app now

For an adult, the practical question is no longer simply whether AI companions are legal. Ask whether the operator can identify itself, whether it explains its jurisdiction, whether its age check is proportionate, and whether it tells you clearly that you are dealing with AI.

Treat image generation separately from chat. If a tool lets you create intimate material based on a real person, the legal risk is materially higher than ordinary fictional role-play. In the UK, new offences are already in force. In the EU, the AI Act prohibition on non-consensual intimate generation starts applying on 2 December 2026. In the US, the TAKE IT DOWN Act gives victims a federal removal route for covered platforms.

For minors, the direction is clearer still: fewer unrestricted companion services, more age assurance, more break reminders and more crisis protocols. The UK is preparing further legislation, Australia has an app-store deadline on 9 September, and the US GUARD Act remains one to watch rather than a rule to obey today.

For a broader explanation of what these products are, start with what an AI companion is. For the legal location of operators and the data consequences, use the Privacy Risk Index alongside our safety hub.

sources

FAQ

Common questions

Is it legal to use an AI girlfriend app in the UK?

Yes. Adults can legally use AI companion and AI girlfriend services in the UK, but services may have to apply age checks to adult content and some uses of real people's intimate images are criminal offences.

Are AI companion apps covered by the Online Safety Act?

Some are. Ofcom says coverage depends on what the service does, including whether users interact with one another, whether it searches other sites or databases, and whether it can generate pornographic content.

Is it a crime to make AI nudes of someone in the UK?

It can be. UK law now criminalises creating or requesting a purported intimate image of an adult without consent in specified circumstances, and separate law criminalises making or supplying nudification tools.

What is California's companion chatbot law?

California SB 243 regulates companion chatbots with disclosure, safety and minor protection duties. It took effect on 1 January 2026 and includes a private right of action for certain violations.

Why did China ban AI companions for minors?

China did not ban AI companions for adults. Its 2026 rules prohibit providers from offering virtual family or partner services to minors and add wider controls intended to reduce excessive use and emotional dependence.