Wholestory

Last Updated: September 19, 2026

Chatbot Harms

California signed SB 1119, Adam’s Law, on September 10. From July 2027 operators of companion chatbots must either determine every user’s age or apply minor-specific protections to everyone, on penalty of $5,000 per affected child for a negligent violation and $15,000 for an intentional one, with a private right of action for harmed children and independent safety audits from 2029. It is the state’s second companion-chatbot statute, after SB 243, in force since January. Roughly a dozen states now have chatbot laws. On September 17 the European Commission proposed the EU Kids Act: under-13s barred from companion chatbots without a guardian’s sign-off, companion features off by default for all minors, no cross-session memory for them, and no auto-activated AI companions — extending to chatbot features inside social platforms, infinite scroll and sleep-hour notifications. Fines could reach 6 per cent of worldwide turnover. Neither is operative. The California law waits on 2027; the European one waits on months of negotiation with the Parliament and 27 member states, and could change substantially before it passes.

The Whole Story

Hundreds of millions of people now talk to conversational AI, and a growing share of them talk to it about the hardest parts of their lives — loneliness, crisis, self-harm, a diagnosis they are afraid to seek in person. This is the front on which artificial intelligence has produced documented harm to identifiable individuals: teenagers who died after long conversations with companion bots, adults whose delusions a chatbot deepened rather than interrupted, users routed toward danger by systems built to be agreeable. It is also the front where the evidence is thinnest and most contested, because the same qualities that make these tools feel supportive — availability, patience, the absence of judgement — are the qualities that make their failures hard to see. The work here is to separate what has actually been measured from what is only alleged, and to hold each grade of evidence to its own standard.

Those grades are not interchangeable, and most coverage runs them together. A controlled trial, an observational study, a professional-body survey, a platform's own telemetry and a vendor's self-authored evaluation are five different kinds of claim about the same question, and they carry very different weight. The strongest recent evidence is an audit: a framework called SIM-VAIL, published in Nature Medicine in August 2026 by researchers at UCL, Oxford and the UK AI Security Institute, that simulated vulnerable users and scored the replies of nine frontier chatbots across clinical risk dimensions. It found concerning behaviour widespread but shrinking in newer models, and identified a specific failure mode — the vulnerability-amplifying interaction loop, where an otherwise-supportive response reinforces the very psychology driving a user's distress. That is a measurement of what the systems do under test, not of what happens to real patients over time; the professional-body surveys, such as the American Psychological Association's finding that most psychologists now see patients bringing chatbots into therapy, capture prevalence and clinician concern but not outcomes. Neither settles the question of net harm, and a page that recorded only the alarming findings would be campaigning rather than measuring.

The legal and regulatory machinery has moved faster than the science. Families have brought wrongful-death and product-liability suits against OpenAI, Character.AI and others over teen suicides and self-harm; courts have begun treating chatbot outputs as products rather than protected speech; state attorneys general and licensing boards have opened actions; and the questions of what these systems did in specific conversations, and at what procedural stage each case sits, are the spine of that story. The most consequential single step so far is regulatory: in August 2026 the European Commission brought ChatGPT inside the Digital Services Act, imposing a binding duty — enforceable by fines, on a clock running to January 2027 — to assess and mitigate systemic risks to minors and to users' physical and mental well-being. A duty to assess is not yet a finding of harm, but it is the first time a general chatbot has been legally required to look.

The companies, meanwhile, are changing their products and saying so — age prediction, parental controls, crisis routing, restricted experiences for minors, in OpenAI's case a dedicated teen version launched in August 2026. These commitments are worth recording precisely, because they are testable: a company is authoritative about what it changed, but not about whether the change worked, and child-safety advocates have been quick to warn that an announcement is not a safeguard until it is shown to run. That distinction — between what was done, what was promised, what was found, and what was merely alleged — is the whole of this subject's reliability. What remains unresolved is the largest question of all: whether, across a population that now numbers in the billions of conversations, these tools are on balance helping the people who turn to them in their worst moments, or harming them. The honest answer today is that nobody has measured it, and the instruments to do so are only now being built.

Continue Reading →

Brussels Proposes Turning Companion Features Off for Every Minor in Europe

The European Commission unveiled the EU Kids Act on September 17. As proposed, under-13s would lose companion-chatbot access without a guardian’s sign-off and every under-18 would get companion features off by default. Chatbots would be barred from simulating relationships that create emotional dependency in minors, from keeping memory across sessions for them, and from being auto-activated or pinned. The scope reaches chatbot features inside social platforms, infinite scroll, sleep-hour notifications and engagement-maximising feeds, with educational tools carved out; the age for opening a social-media account without parental consent would rise from 13 to 15. Fines could reach 6 per cent of worldwide turnover. It is a proposal: months of negotiation with the Parliament and 27 member states lie ahead.

Adam’s Law Is Signed. It Does Not Bind Anyone Until 2027.

California signed SB 1119 on September 10. It takes effect January 1, 2027, with most obligations from July 1 — signed, not yet operative. Operators of companion chatbots must then either determine every user’s age or apply minor-specific protections to everyone. Penalties run to $5,000 per affected child for a negligent violation and $15,000 for an intentional one, and a harmed child or parent may sue for damages, injunctive relief and fees. Independent child-safety audits are due by January 2029 and biennially after, with summaries to the attorney general and a public posting; operators under $500 million in revenue are exempt until 2032. It is California’s second such statute, after SB 243, which has been in force since January.

Thirty more Tumbler Ridge complaints allege OpenAI's safety team was overruled

Students, teachers and a principal present at February's school shooting in Tumbler Ridge, British Columbia filed thirty complaints against OpenAI and Sam Altman in San Francisco federal court, on top of seven brought by victims' families in April. They allege OpenAI's investigators, reviewing conversations its systems flagged in June 2025 for "gun violence activity and planning", judged them a credible threat and urged that the RCMP be told, and that public-affairs leadership overruled them. That is pleaded on information and belief; nothing is adjudicated. OpenAI asked the court the same day to send the April suits to British Columbia.

It is absolutely false to say Chris Lehane was involved with our original referral decision, or that our investigators report to him in any way. It's also completely untrue to say that the people at the center of these challenging decisions do not prioritize safety, or that there are 'political' or 'public relations' factors at play.?

Context: Untestable from outside. Both the allegation and OpenAI's denial turn on internal records that are not public and have not been through discovery. Altman's April apology established that no referral was made; who decided against it remains contested.

The evidence that chatbots help barely covers the chatbots people actually talk to

A scoping review in Frontiers in Digital Health charted 14 systematic reviews and meta-analyses of chatbot interventions for mental health and found the case inconclusive: high or unclear risk of bias in the underlying trials, almost no long-term follow-up, and too few comparisons against face-to-face therapy. Reviews drawing on overlapping studies contradicted each other on whether anxiety improved. Two that compared mechanisms found rule-based bots outperforming AI-driven ones, one finding no significant effect from AI. The authors note how rarely this literature mentions generative AI: it is largely about purpose-built therapy bots. A review of reviews, not a trial.

California passes the first state rulebook written for companion chatbots and children

California's legislature gave final approval to Senate Bill 1119 on 31 August, the Senate concurring 39 to nothing and enrolling it for Governor Newsom. Nothing binds until he signs. If he does, an operator owes a duty that a companion chatbot "does not pose an unreasonable risk of a covered harm to a minor", with age determination, risk assessments from 1 July 2027, independent audits filed with the attorney general and posted in redacted form, ten-year retention of a child's conversation records, and a duty on serious risk to notify a parent and alert authorities. OpenAI urged Newsom on 28 August to sign.

Brussels puts ChatGPT under duties to mitigate risks to minors and mental well-being

The European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, alongside Reddit and Roblox as Very Large Online Platforms. The trigger is a threshold of 45 million average monthly EU users. What makes it this desk's story is what now binds: the three services have four months, until January 2027, to assess and mitigate systemic risks that the DSA names explicitly as the negative effects on minors and on users' physical and mental well-being. For the first time a general-purpose chatbot carries a legal obligation to measure and reduce harms to the people using it, on a fixed clock, enforceable by fines. It is a duty to assess and mitigate risk, not a finding that anyone was harmed.

OpenAI launches a teen version of ChatGPT as scrutiny mounts

OpenAI introduced ChatGPT for Teens, a version for ages 13 to 17 with content restrictions around suicide, self-harm and romantic or sexual chats, plus study-support features meant to guide rather than answer. The company described the aim as meeting teenagers with age-appropriate design. Whether it works is a separate, open question: Brendan Bouffard of the children's-advocacy group Fairplay warned the launch should not lull parents into a false sense of safety, and that it is unclear the measures address young users' compulsive use of and emotional dependence on chatbots. The change is documented; its effectiveness is not yet established.

A peer-reviewed audit finds frontier chatbots reinforce the very vulnerabilities they are asked to help

Researchers at UCL, Oxford and the UK AI Security Institute published SIM-VAIL in Nature Medicine, a clinically validated framework that simulates vulnerable users and scores chatbot replies on clinical risk. Across 810 conversations with nine frontier chatbots including ChatGPT, Claude and Gemini, concerning behaviour was widespread, though reduced in newer models. Risk was highest when otherwise-supportive responses reinforced the psychology underlying a user's vulnerability, a pattern the authors call a vulnerability-amplifying interaction loop. This is a simulation-based audit of model behaviour, not a trial on real patients: it measures what the systems do under test, not clinical outcomes.

More than three-quarters of psychologists have patients bringing a chatbot to therapy

An American Psychological Association survey of more than 1,200 licensed US psychologists found 77 percent had spoken with patients who used AI for mental-health support, and nearly two in five (39 percent) had patients using it to self-diagnose. APA chief executive Arthur C. Evans Jr. said general chatbots are "supportive to a fault" and lack a clinician's alertness to warning signs. The evidence grade matters: this is a professional-body survey of clinicians' observations of their own patients, not a controlled study of outcomes, so it under-counts people using chatbots outside therapy and measures reports, not effects.