Governor Gavin Newsom signed a package of child online safety bills on 10 September 2026, calling them the strongest in the country. Two drew the headlines: AB 1709, which bars social media platforms from giving users under 16 addictive features, and SB 1119, known as Adam's Law after Adam Raine, which puts time limits and crisis rules on companion chatbots used by children.

The coverage described what the laws require. The bill texts show what they depend on, and it is the same thing in both cases.

Neither law asks the app to guess anyone's age

AB 1709 says a platform may not give an addictive feature to a user under 16. Before providing one, section 22684 says the platform "shall verify the age of a user pursuant to the Digital Age Assurance Act."

SB 1119 does the same for chatbots: operators determine a child's age under that same title of the Civil Code, or rely on the determination made under it.

That act is California's Digital Age Assurance Act, signed in October 2025 and revised this session by AB 1856. It moves age checking off websites and apps and onto the device.

The age lives in the operating system

Under AB 1856, any operating system with an account setup feature must ask the account holder, at setup, for the birth date, age, or both of the device's primary user. The account holder can be a parent or guardian entering a child's age.

The operating system then produces a signal, defined as "age bracket data that pertains to the primary user of a device", in four brackets: under 13, 13 to 15, 16 to 17, and 18 or older. App stores pass it along. Developers "shall treat a signal received pursuant to this title as the primary indicator of a user's age range," and may not request more information than the minimum necessary.

The 13-to-15 bracket is exactly the line AB 1709 needs. The bills were built to fit together.

The obligations begin before 1 January 2027 for new devices and before 1 July 2027 for devices already set up. The Attorney General enforces them, with penalties of up to 2,500 dollars per affected child for negligent violations and 7,500 dollars for intentional ones.

What that design gets right, and what it hands to the setup screen

There is a real case for it. Making every app verify age means handing identity documents or face scans to thousands of companies. Asking once, on the device, and passing only a bracket collects far less.

But it concentrates the whole regime on one moment: whoever sets up the phone, and what they type. Some of the consequences are written into the text:

  • It follows the device's primary user. AB 1856 says it "does not impose liability that arises from the use of a shared device" by someone who is not that user.
  • Software distributed under licences that let recipients copy, modify and redistribute it is excluded from the definition of an operating system provider. Reporting on the change says open-source distributions such as Debian and Fedora fall outside the rule while the major commercial platforms stay in.
  • An app is told to treat the bracket as the primary indicator, not to second-guess it.

What AB 1709 actually prohibits

The operative definition is narrower than the coverage suggested. An addictive feature under section 22682 is an addictive feed or autoplay. An addictive feed is one where content is recommended, selected or prioritised using information about the user, with seven exceptions, including private messages and content a user specifically asked for.

Infinite scroll and notifications appear in the bill's findings, not in the prohibition.

Platforms may still let under-16 users have accounts without those features. The text reviewed contains no route for a parent to consent to them. Penalties reach 25,000 dollars per affected minor for negligent violations and 50,000 dollars for knowing ones, and the bill creates an e-Safety Advisory Commission inside the state Department of Justice.

What SB 1119 requires of chatbots, precisely

  • A child may use an operator's companion chatbots for at most two hours a day, and one hour in a single session.
  • Operators need a documented crisis response protocol for suicidal ideation and self-harm content.
  • On a "credible and imminent threat," the operator must either notify a parent "as soon as practicable if that notification does not risk a threat of serious harm to the child," or give the child streamlined access to the 988 crisis line.

That last clause is where the headlines ran ahead of the text. It is not a guaranteed alert to parents. It is a choice, with an explicit exception for the children for whom telling a parent is itself the danger.

Operators must also complete a risk assessment before deployment and commission independent audits every two years. The main obligations take effect on 1 July 2027. Public prosecutors can seek 5,000 dollars per affected child for negligent violations and 15,000 dollars for intentional ones, and families get a private right of action for actual damages under specified sections.

OpenAI has said the law "pairs strong protections with continued access to useful AI tools."

What to watch

  • How the Attorney General's regulations define verification under AB 1709.
  • How operating system vendors build the signal before January.
  • Legal challenges. State laws restricting minors' access to online features have drawn First Amendment suits before.

What is not established

  • A start date for AB 1709's prohibition separate from the age-assurance timeline. The text reviewed does not state one.
  • How accurate setup-screen ages will be in practice.
  • Whether the open-source exclusion becomes a route around the rules.
  • How operators will judge "credible and imminent", and how often they will choose the crisis line over a parent.