What was published, and what CRS is
The Congressional Research Service is the in-house research arm of the US Congress. It writes non-partisan background briefs for members and their staff, and it deliberately stops short of recommending policy — the standard framing is "considerations," which is exactly the word in this report's subtitle. Its value to anyone outside Washington is that it shows what the people writing the bills are working from.
Report R49189, dated 14 August 2026, runs through the history of chatbots, current uses of companion apps, the mental-health research, privacy and transparency questions, and the state of legislation. It is the first CRS product to treat companion chatbots as a category in their own right rather than as a footnote to general-purpose AI.
The numbers Congress is now working from
Policy tends to follow whichever figures make it into a briefing document, so these are worth knowing precisely.
| Figure | As stated in the report |
|---|---|
| Adults using chatbots for emotional support | A 2026 report found approximately 1 in 10 adults use AI chatbots for emotional support or advice, and 1 in 25 use them for companionship. |
| Global downloads | AI companion apps were downloaded approximately 220 million times globally as of July 2025. |
| Teen use for mental health | A 2025 survey found 12% of teens used AI companion chatbots for emotional or mental health support. |
| Scale of a single platform | Character.AI supported over 20 million monthly active users in 2025. |
The gap between the first two rows is the interesting one. Downloads measure curiosity; the 1-in-25 companionship figure measures habit. A category can be simultaneously mass-market by install count and niche by sustained use, and most public argument about companion apps confuses the two.
Where state law actually stands
The report names more than ten states with enacted AI chatbot laws — Connecticut (Public Act 26-15), Georgia (SB 540), Idaho (SB 1297), Nebraska (LB 525), New York (General Business Law Article 47), Oregon (SB 1546), Rhode Island (HB 7350 / SB 2195), Tennessee (SB 1700) and Washington (HB 2225) among them — and notes that most take effect in 2027.
A legislative tracker published in June 2026 put the count at twelve once California, Colorado and Iowa are included. The discrepancy is not a contradiction: counts differ by cutoff date and by whether a statute is companion-specific or a broader AI law that happens to catch chatbots. Either way the direction is unambiguous, and the requirements have converged on three points.
| Requirement | How states differ |
|---|---|
| Periodic "this is an AI" reminder | Colorado, Georgia, Iowa, New York and Rhode Island require a reminder roughly every three hours for all users. California, Idaho, Nebraska and Oregon apply the three-hour reminder to minors only. Connecticut and Washington use three hours for adults and hourly for minors. |
| Crisis protocol | Every one of the enacted laws requires a protocol to identify expressions of suicidal ideation or self-harm and refer the user to resources such as the 988 Suicide & Crisis Lifeline. Connecticut and Rhode Island extend this to threats of harm toward others. |
| Minor-specific limits | Sexually explicit content, romantic interactions, emotional manipulation and engagement-maximising design are restricted for minors. States disagree on whether age verification is required before those protections apply. |
The disagreement about how to protect minors
Four days before the CRS brief, the Information Technology and Innovation Foundation published its own analysis, which counts nearly 100 state chatbot safety bills introduced so far in 2026 and argues that most of them recycle failed social-media regulation. Its position is not that chatbots are harmless; it explicitly supports crisis-referral protocols, robust parental controls and disclosure of paid sponsored content inside chatbot output. What it opposes is blanket age verification for all users, broad content restrictions, conversation-log collection and outright bans for minors — favouring instead a device-level signal that a user is a child.
That split matters more than it sounds. Age verification is the mechanism that decides whether an app has to identify you before it can decide what to show you, and it is the point where child-safety and privacy goals pull hardest against each other. We walked through that trade-off in privacy and age verification; the CRS report confirms it is now the central unresolved question rather than a technical detail.
What this changes inside the apps you use
Reminders you did not ask for
An interstitial saying you are talking to an AI is the single most likely visible change, and in several states it arrives on a clock rather than only at sign-up. If it reads as patronising, that is the trade the statutes made deliberately: the disclosure targets long unbroken sessions, which is exactly when a persona is most convincing.
Conversations that get routed away
Crisis protocols mean some conversations will stop being conversations and become a referral. Apps vary enormously in how well this is built today — a referral that fires on the word "die" in a fantasy battle scene is a different product experience from one that reads context. This is now a compliance requirement, not a nicety.
Age gates arriving unevenly
Because the state laws differ on when protections trigger, the same app can behave differently depending on where you open it. Expect more account-level questions about age, and expect them earlier in onboarding — a point where, as we've written before, apps already lose a large share of new users.
What the report is careful not to claim
CRS is unusually direct about the evidence base: much of what is known about these interactions comes from short-term studies or company disclosures, and the report calls for longitudinal research to assess long-term effects. It describes documented harms and documented benefits without adjudicating between them.
That caution lines up with the peer-reviewed picture. The largest recent study, covered in our piece on companions and loneliness, found associations concentrated in a specific subgroup and could not establish direction of causation. Anyone citing either document as proof that companion apps are harmful — or safe — is reading past what it says.
On the federal side, the report catalogues introduced bills: the CHAT Act, GUARD Act, CHATBOT Act, Youth AI Privacy Act, SAFE BOTs Act and KIDS Act, covering age verification, parental controls, data restrictions and disclosure. All are introduced measures rather than enacted law, which is why the operative rules for the next year remain state ones — and, for anyone outside the US, the EU and Chinese frameworks that are already in force.
What we're watching next
- The 2027 effective dates. Most enacted state laws land then. The interesting question is whether apps ship the requirements nationwide or geo-fence them.
- Whether age verification wins. The CRS brief frames it as contested; the ITIF analysis argues against it. Whichever approach the next wave of bills adopts will shape sign-up flows everywhere.
- Crisis-protocol quality. Once referral is mandatory, the differentiator becomes whether it works in context. We record for each app we review whether a distress signal produces a human-support referral rather than more conversation, per our methodology.
Related on CompanionRank
AI Companion Privacy & Age Verification, Explained AI Companions and Loneliness: What the Stanford Study Found China's AI Companion Rules Are Now in Force EU AI Act Disclosure Rules Now Apply to Companion AppsFrequently asked questions
What is the CRS report and does it change any law?
No. The Congressional Research Service writes non-partisan background briefs for members of Congress and their staff. Report R49189, published on 14 August 2026, describes how AI companion chatbots are used, what the research shows, and which bills are pending. It sets out considerations rather than recommendations, and it has no legal force of its own.
How many people actually use AI companions?
The report cites a 2026 finding that 1 in 10 adults use AI chatbots for emotional support or advice and 1 in 25 use them for companionship. It also cites AI companion apps being downloaded roughly 220 million times globally as of July 2025, and a 2025 survey in which 12% of teens used companion chatbots for emotional or mental health support.
Which US states have passed companion chatbot laws?
The report names Connecticut, Georgia, Idaho, Nebraska, New York, Oregon, Rhode Island, Tennessee and Washington among more than ten states with enacted AI chatbot laws, and notes that most take effect in 2027. A June 2026 legislative tracker counted twelve states once California, Colorado and Iowa are included, so the exact number depends on the cutoff date and on which statutes count as companion-specific.
What will change inside the apps themselves?
Three things recur across the state laws: a periodic reminder that you are talking to an AI rather than a person, a crisis protocol that routes conversations about self-harm toward human support such as the 988 line, and tighter limits on romantic or sexually explicit content for accounts identified as minors. Because most of these take effect in 2027, apps that already ship them are ahead of schedule rather than compliant with something in force.
Is there a federal AI companion law?
Not as of the report's publication. It catalogues introduced bills including the CHAT Act, the GUARD Act, the CHATBOT Act, the Youth AI Privacy Act, the SAFE BOTs Act and the KIDS Act, covering age verification, parental controls, data limits and disclosure. All are described as introduced measures rather than enacted law, so the operative rules for now are state ones.