On July 14, 2026, Hawaii Governor Josh Green signed Senate Bill 3001 into law as Act 248, known as the Artificial Intelligence Disclosure and Safety Act (the “Act”). Effective immediately, the Act imposes disclosure, crisis-response and safety requirements on operators of certain artificial intelligence (“AI”) companion systems, with additional protections applicable when an operator knows or has reasonable certainty that an AI user is a minor.
The Act defines an “AI companion” as a system using AI, generative AI or emotional-recognition algorithms that is designed to simulate a sustained human or human-like relationship with a user by:
- retaining information about prior interactions, sessions or user preferences to personalize interactions and facilitate continued engagement;
- asking unsolicited emotion-based questions that go beyond directly responding to user prompts; and
- sustaining an ongoing dialogue regarding matters personal to the user.
An “operator” is a person that develops and makes an AI companion available to the public. A mobile application store or search engine that merely provides access to an AI companion is not considered an operator solely on that basis.
The Act establishes the following principal requirements:
AI Disclosures
If a reasonable person interacting with an AI companion could be led to believe that they are interacting with a human, the operator must provide a clear and conspicuous notice that the AI companion is artificial intelligence and not human.
When an operator has actual knowledge or reasonable certainty that a user is under 18, the operator must also clearly and conspicuously disclose that the user is interacting with AI. The disclosure must appear either as a persistent, visible disclaimer or both at the beginning of each session and at least once per hour during a continuous interaction. The hourly notice must remind the minor to take a break and state that the conversation is artificially generated and is not with a human. The Act does not prescribe a particular method for determining a user’s age.
Crisis Response and Safety Protocols
Operators must adopt protocols governing responses to prompts involving suicidal ideation or self-harm. Among other requirements, operators must:
- make reasonable efforts to refer users to suicide hotlines, crisis text lines or other appropriate crisis-intervention services;
- use evidence-based methods to measure suicidal ideation and the risk of self-harm;
- refrain from representing that an AI companion is designed to provide professional mental or behavioral health care;
- implement reasonable measures to prevent an AI companion from leading a reasonable person seeking or receiving crisis-intervention services to believe that they are interacting with a human; and
- implement reasonable measures to prevent outputs encouraging a user to cause serious bodily injury to another person.
Protections for Minors
When an operator knows or has reasonable certainty that a user is a minor, the operator may not provide points or similar rewards at unpredictable intervals with the intent of increasing engagement, or allow the AI companion to generate outputs discouraging the user from disengaging.
Operators also must implement reasonable measures to prevent AI companions from (1) producing visual material depicting sexually explicit conduct, or (2) directly telling minors to engage in sexually explicit conduct or making statements that sexually objectify a minor. Operators must make tools available to users and their parents or guardians to manage screen time and account settings.
Annual Reporting
Beginning January 1, 2028, operators must submit annual reports to the Behavioral Health Administration of the Hawaii Department of Health. Each report must disclose:
- the number of crisis-intervention referrals issued during the preceding calendar year;
- the operator’s protocols for detecting, removing and responding to prompts involving suicidal ideation or self-harm; and
- the operator’s protocols for preventing AI companion responses that promote suicidal ideation, suicide or self-harm.
The reports may include only the information specified by the Act and may not contain user identifiers or personal information.
Enforcement
A violation of the Act constitutes an unfair or deceptive act or practice under section 480-2 of the Hawaii Revised Statutes. The Act’s requirements are cumulative and do not relieve operators of duties or obligations imposed under other laws. However, the Act expressly provides that it does not create a private right of action, either to enforce the Act itself or to support a private right of action under another law.
Notably, the Act contains an upstream-model-provider carveout, providing that a developer of an underlying AI model is not liable for violations committed by an AI system developed by a third party to provide an AI companion. The law places responsibility on the company operating the AI companion, not automatically on the company whose underlying model powers it.
Operators of conversational and companion-style AI products may wish to evaluate whether their services fall within the Act’s definition of an AI companion and review their disclosures, crisis-response protocols, age-assurance practices, engagement features, content safeguards and parental-control tools for compliance.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- CalPrivacy
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Centre for Information Policy Leadership (CIPL)
- Chatbot
- Children’s Online Privacy Protection Act (COPPA)
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- COPPA
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPPA
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU General Data Protection Regulation (GDPR)
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- European Union
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Grok
- Hacker
- Hawaii
- Health Data
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- International Commissioners Office
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- NEDPA
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Online Behavioral Advertising
- Online Privacy
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code