Colorado's chatbot law puts the liability on the operator, not the model builder
HB26-1263, signed 29 May and effective 1 January 2027, makes Colorado the first US state to regulate AI companion chatbots for minors. The design choice that matters: compliance duty falls on whoever operates the product, not on whoever trained the model underneath it.
Two dozen states moved conversational-AI safety bills this session. Colorado's is the one worth reading closely, because it answers the question every AI statute has to answer and most have dodged: when a chatbot harms someone, who is the regulated party?
Colorado's answer is the operator. The obligations attach to whoever ships the product to a user — disclose that the product is not human, bar sexual content for under-18s, prohibit tactics engineered to create false emotional dependency, provide parental controls for under-13s, surface crisis resources on self-harm signals. A companion bill, HB26-1195, stops chatbots conducting psychotherapy or generating treatment plans without human review.
Putting duty on the operator is defensible and consequential. The operator chose the use case, set the system prompt, decided the age gate and owns the relationship with the user. It is also the party a state can actually reach, which the model developer — often in another jurisdiction — frequently is not.
The cost is fragmentation. Washington's HB 2225 and Georgia's SB 540 cover similar ground with different definitions, and an operator serving all fifty states now writes to the strictest. That is how a patchwork becomes a de facto national standard without anyone voting for one — and it is happening while the EU's comparable obligations slip to 2027.
Colorado Springs Gazette — Governor signs new regulations on AI chatbots for minors → · Available Law — Colorado's New AI Chatbot Law: What HB 26-1263 Means for Businesses → · Record of Record — Colorado enacts first-in-nation chatbot safety law →