Gloss Key Takeaways
  1. 78 bills regulating chatbots and conversational AI are actively moving through 27 states early in the 2026 legislative season, turning the “patchwork” from a warning into reality.
  2. Washington has already enacted two laws focused on AI disclosure and chatbot safety requirements for interactions with minors, showing states are moving from proposals to enforceable rules.
  3. Oregon’s chatbot safety law adds a private right of action with statutory damages, lowering the bar for lawsuits by making violations themselves actionable harm.
  4. Colorado is advancing healthcare-specific AI chatbot rules, signaling that sector-based overlays will stack on top of general chatbot requirements.
  5. Common themes across bills include disclosure mandates, age-gating/minor protections, and varying enforcement models, creating a large and fast-moving compliance gap for companies shipping nationally.

78 chatbot bills in 27 states and most AI companies haven't read a single one

Hero image

Six weeks into the 2026 state legislative season, 78 bills regulating chatbots and conversational AI are alive across 27 states. Not proposed. Not rumored. Alive, moving through committees, getting amended, passing chambers.

Washington already passed two: HB 1170 requiring disclosure when users interact with AI, and HB 2225 imposing safety requirements for chatbots interacting with minors. Oregon passed a chatbot safety bill that includes a private right of action and statutory damages, meaning individual users can sue. Colorado is advancing multiple bills targeting AI in healthcare settings.

At the federal level, the FTC was required to issue an AI policy statement by March 11. An AI litigation task force has been established specifically to challenge state laws that the tech industry considers overreach. The battle lines are drawn, the legislation is moving, and the compliance gap is enormous.

The patchwork is already here

The phrase "patchwork of state laws" has been a warning for years. It's not a warning anymore. It's a description.

Washington's two bills illustrate how different states are approaching the same problem from different angles. HB 1170 is a transparency play: if a user is talking to a chatbot, they need to know it. HB 2225 goes further, establishing specific safety requirements when the chatbot's counterpart is a child. These aren't theoretical bills sitting in committee. They passed.

Oregon's approach is more aggressive. Its chatbot safety bill doesn't just set rules, it gives people standing to sue when those rules are broken. Private right of action with statutory damages means a plaintiff's lawyer doesn't need to prove specific financial harm. The violation itself is the harm. That's a fundamentally different enforcement model than anything at the federal level.

Colorado is carving out healthcare as a specific domain requiring additional AI regulation. If you're building a chatbot that triages symptoms, answers insurance questions, or interacts with patients in any capacity, Colorado wants separate rules for that.

US map showing states with active AI chatbot legislation

What the bills actually require

The requirements across these 78 bills aren't uniform, but patterns are emerging.

Disclosure mandates are the most common. Users must be told they're interacting with AI. This sounds simple until you consider the implementation details: when does disclosure happen, how prominent must it be, does it need to be repeated, what happens in voice interfaces where there's no screen to display a label.

Age-gating and minor safety provisions appear in roughly a third of the bills. Washington's HB 2225 is the model here, but states are defining "safety" differently. Some focus on content filtering. Others require parental consent mechanisms. A few mandate data handling restrictions specific to minors that go beyond COPPA.

Private right of action appears in a smaller but significant subset, with Oregon leading. This is the provision that should keep general counsels awake. Federal enforcement means waiting for an agency to act. Private right of action means any user, anywhere, can file a lawsuit the moment they believe a violation occurred.

Healthcare-specific provisions, like Colorado's bills, layer domain requirements on top of general chatbot rules. If your AI product touches healthcare, you're potentially subject to both general chatbot laws and sector-specific AI laws in the same state.

The compliance math nobody wants to do

Here's what 78 bills across 27 states means in practice for a company shipping a chatbot product nationally.

You need legal analysis of each bill. Not just the text, but the committee amendments, the regulatory rulemaking authority granted, the enforcement mechanisms, the effective dates. Some of these bills take effect 90 days after signing. Others give companies a year. A few are retroactive to products already in market.

Then you need to map your product's functionality against each state's requirements. Does your chatbot interact with minors? Does it operate in healthcare? Does it generate content that could be considered deceptive? Each question triggers a different subset of applicable laws.

Then you need to build the compliance infrastructure. Disclosure mechanisms. Age verification. Data handling pipelines. Audit trails. Reporting requirements. Each state's version is slightly different, which means either you build to the strictest standard everywhere, or you build a system that adapts by jurisdiction.

Most companies building AI products right now have done none of this. Not because they're irresponsible, but because they're focused on shipping features, raising rounds, and growing users. Compliance is a cost center that doesn't show up until it shows up as a lawsuit.

The federal layer adds complexity, not clarity

The FTC's March 11 deadline for an AI policy statement was supposed to provide some federal framework. But federal policy statements aren't preemptive. They don't override state laws. At best, they signal enforcement priorities. At worst, they create a parallel set of expectations that companies must satisfy alongside state requirements.

The AI litigation task force, established to challenge state laws the industry considers burdensome, is a long game. Constitutional challenges to state regulation take years. Companies need compliance strategies that work today, not ones that depend on a favorable court ruling in 2028.

Lawyer's desk with compliance materials

The practical result is that federal activity is additive. It's another layer to monitor, another set of requirements to track, another enforcement body with its own priorities. It doesn't simplify the state-level picture.

What companies should actually be doing right now

The first step is inventory. Map every state where your chatbot is accessible to users. Not where your company is headquartered, where your users are. If your product is available nationally, you're potentially subject to all 27 states with active bills, plus whatever passes in the remaining 23 over the next six months.

The second step is categorization. Which bills apply to your specific product? A customer service chatbot faces different requirements than a healthcare triage bot or an AI companion app. The bills aren't one-size-fits-all, and your compliance strategy shouldn't be either.

The third step is architecture. Build disclosure, consent, and data handling as infrastructure, not afterthoughts. If you're bolting on a "this is an AI" label as a frontend patch, you're going to rebuild it when the next state passes a bill with different disclosure requirements.

The fourth step is monitoring. These 78 bills will become 100+ by summer. New states will introduce new bills. Existing bills will be amended. Some will die in committee. Others will pass with significant changes from their introduced versions. You need a system for tracking this, whether that's a legal team, a compliance service, or a regulatory intelligence tool.

The window is closing

Oregon's private right of action provision is the canary. When individual users can sue for statutory damages without proving specific financial harm, the risk calculus changes completely. One motivated plaintiff's attorney in Portland can create more compliance pressure than the entire FTC.

Companies building AI products have maybe six months before the first wave of these laws takes effect. That's not a lot of time to build compliance infrastructure from scratch, especially when the requirements are still being finalized in many states.

The companies that treat this as a 2027 problem are going to discover it's a 2026 problem with 2025 deadlines they already missed. The legislation is moving faster than the industry's awareness of it, and the gap between what's required and what's been built is growing every week.

Seventy-eight bills. Twenty-seven states. Six weeks into the session. The patchwork is being stitched whether the industry is watching or not.


Marco Kotrotsos writes about practical AI implementation at gloss.run and acdigest.substack.com.

Gloss What This Means For You

If you build or deploy chatbots, assume state-by-state compliance is now a near-term requirement, not a future risk. Start by inventorying where your chatbot is used (including healthcare contexts and minors), then map those use cases to emerging themes like disclosure timing, age-gating, and data handling. Pay special attention to states adding private rights of action and short effective dates, and set up a process to track amendments and rulemaking so your implementation doesn’t lag behind the laws.