California Puts Age Checks on Companion Chatbots (09/24/2026)
- › California's Adam's Law, SB 1119, requires companion chatbot operators to verify age, run documented risk assessments, and keep crisis protocols.
- › Operators must also tell users they are talking to AI and give parents controls and a public incident reporting path.
- › Ofcom will investigate whether Aylo's reliance on operating system age checks meets the Online Safety Act's highly effective standard.
- › Steam now requires Australian users to pass credit card age inference, which excludes adults without a card.
- › YouTube will pair voice detection with facial likeness detection to catch AI impersonation of creators.
Age assurance moved on three fronts today, and they share a pattern that deserves attention. Each one takes a question the law wants answered, whether this person is a child, and hands it to whatever signal is easiest to collect, a credit card in one case, the phone’s operating system in another, and a chatbot operator’s own verification in a third. California’s new companion chatbot law is the most substantial of the three, because it pairs the age check with obligations about what the product does once it knows who it is talking to.
Top 5 Critical Privacy Alerts
1. California’s Adam’s Law Regulates Companion Chatbots
California has enacted several laws on minors’ privacy and safety, including Adam’s Law, SB 1119, which requires companion chatbot operators to verify user age under the Digital Age Assurance Act, conduct and document risk assessments, document safety mitigations, publish a minor safety policy, and establish crisis response protocols, per PogoWasRight. Operators must also add usage reminders and safeguards for minors, set parent-controlled defaults, disclose that users are talking to AI, prevent specified harmful chatbot behaviors, and provide parental controls and public incident reporting.
Operator Note: The crisis protocol requirement is the part to take seriously, because it assumes the product will sometimes be the first to hear that a young person is in danger. That is a human judgment problem, and it needs a human path behind it.
2. Ofcom Examines Aylo’s Operating System Age Checks
Ofcom will investigate whether the age assurance Pornhub’s parent Aylo adopted for its return to the UK complies with the Online Safety Act, focusing on whether operating system level checks meet the highly effective standard the law requires, per Biometric Update. This follows yesterday’s report that the regulator was questioning the company’s diligence, and it is now a formal inquiry.
3. Steam Requires Credit Cards for Age Inference in Australia
Steam introduced mandatory credit card age inference for Australian users in response to the Age-Restricted Material Codes for app distribution services, which took effect September 9, per Biometric Update. A credit card proves somebody over 18 approved a payment, and it excludes every adult who does not carry one, which tends to fall hardest on people with the least financial stability.
Operator Note: Each age signal leaves out a different group of adults, whether that is a card, an ID document, or a face scan. Pick one and you have also picked who gets locked out, so the choice deserves an explicit decision rather than a default.
4. YouTube Adds Voice to Its Likeness Detection
YouTube will integrate speaking voice detection with its existing facial likeness system later this year, combining two biometric signals to improve accuracy and extend protection against AI-generated impersonation, per Biometric Update. Protecting creators from impersonation requires holding a detailed biometric reference of each creator, which is a trade people should make knowingly.
5. The EUDI Wallet Deadline Nears With an Uneven Rollout
Every EU member state is supposed to offer the EU Digital Identity Wallet by the end of this year, and the rollout picture remains uneven across countries, per Biometric Update. A wallet designed around selective disclosure could answer the age question without handing over the whole identity, if it arrives and people actually use it.
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.