

AI Chatbot Laws Hit OnlyFans Chatting 2026
Companion chatbot statutes describe paid fan chat far more closely than they describe customer service, and at least one of them lets the fan sue directly. A practical read of California SB 243, New York's AI companion law, Maine's disclosure rule and the 2026 state wave, aimed at an owner deciding how much of the chat stack to automate.

Yasmin Khalil
Head of Compliance & Legal
17 min read

TL;DR. If you run fully automated AI chat with fans in the United States, several state AI chatbot disclosure laws now require you to tell the fan it is not human, and California's version lets him sue you directly. California SB 243 took effect 1 January 2026, defines a "companion chatbot" as an AI system giving adaptive, human-like responses that is "capable of meeting a user's social needs," and gives any injured person a private right of action for the greater of actual damages or 1,000 dollars per violation plus fees. New York's AI companion law has been live since 5 November 2025 and forces a repeat disclosure at least every three hours. Maine has barred misleading a consumer into thinking they are talking to a human since September 2025. Their exclusions were all drafted for customer service bots, and paid fan chat is the opposite: relationship simulation that happens to sell. A human on the send button keeps you outside most of them, and lying to a fan who asks whether he is talking to a bot turns a compliance question into a documented deception case. Educational, not legal advice.
Most owners moved part of chat onto AI without writing down what that meant legally. The debate was about conversion and margin, and it ran while legislatures in more than two dozen states drafted statutes describing what you are doing with unnerving precision.
What a Companion Chatbot Statute Actually Covers
"AI chatbot law" covers three statutory species.
The first is the commercial bot disclosure law. California's is the original: Business and Professions Code sections 17940 to 17943, enacted as SB 1001 and operative since 1 July 2019. It bans using a bot to communicate with a person in California online with intent to mislead them about its artificial identity, to deceive them about the content and incentivize a purchase or sale. Disclose that it is a bot and the section does not reach you. Section 17940 defines a bot as "an automated online account where all or substantially all of the actions or posts of that account are not the result of a person," a phrase that matters later.
The second is the general consumer transparency statute, exemplified by Maine's Title 10 section 1500-DD, "Required disclosure of use of artificial intelligence chatbot to engage in trade and commerce." It came in as LD 1727, was signed 12 June 2025 as Public Law 2025 chapter 294, and took effect that September on Maine's standard ninety-day clock. Utah is lighter: its Artificial Intelligence Policy Act, narrowed by SB 226 in 2025, requires disclosure of generative AI use in a consumer transaction when the consumer asks.
The third species is the one that should worry you: the companion chatbot statute. It does not turn on deception. Its duties attach to a category of system whether or not anyone was fooled. A commercial bot law asks whether you lied. A companion chatbot law asks whether the system simulates a sustained, personalized, emotionally responsive relationship, and paid fan chat answers yes by design.
California SB 243 and the Private Right of Action
SB 243, authored by Senator Padilla, was approved on 13 October 2025, the same day Newsom vetoed the broader AB 1064. It added Chapter 22.6, sections 22601 to 22606, to Division 8 of the Business and Professions Code, and took effect 1 January 2026, the standard date for a non-urgency California statute.
The definition is the whole ballgame. A companion chatbot is an artificial intelligence system with a natural language interface that provides adaptive, human-like responses to user inputs and is capable of meeting a user's social needs, including by exhibiting anthropomorphic features and sustaining a relationship across multiple interactions. Three carve-outs follow: bots used only for customer service, business operations or research; video game bots; and standalone voice assistants that do not sustain a relationship. Nothing on that list mentions entertainment, adult content or paid conversation.
Section 22602 is the operative duty. Where a reasonable person would be misled into believing they are interacting with a human, the operator must issue a clear and conspicuous notification that the chatbot is artificially generated and not human. For a user the operator knows is a minor, duties stack: disclose the AI nature, push a default break reminder at least every three hours, and prevent sexually explicit content. Operators must also maintain and publish a protocol for preventing production of suicidal ideation, suicide or self-harm content, and under section 22603, "beginning July 1, 2027, an operator shall annually report" to the Office of Suicide Prevention.
Then section 22605. A person who suffers injury in fact from a violation may bring a civil action for injunctive relief, damages equal to the greater of actual damages or one thousand dollars per violation, and reasonable attorney's fees and costs.
Most state AI statutes reserve enforcement to the Attorney General, a remote risk for a small private agency. A private right of action with statutory damages and fee-shifting needs no regulator to care, only one motivated fan and one plaintiff's lawyer who can do arithmetic. SB 243 never defines a single violation, so the obvious plaintiff-side unit is the message.
New York, Maine and the 2026 State Chatbot Law Wave
New York got there first: its AI companion provisions, enacted in the FY2026 budget and codified at General Business Law Article 47, took effect 5 November 2025. Section 1700's definition is behavioral rather than capability-based: a system that simulates a sustained human-like relationship by retaining prior interactions to personalize engagement, asking unprompted emotion-based questions, and sustaining an ongoing dialogue on matters personal to the user. No accident of drafting: it describes what every chatting SOP in this industry trains for, because it is what makes a fan spend.
Section 1702 is the rule: "An operator shall provide a clear and conspicuous notification to a user at the beginning of any AI companion interaction which need not exceed once per day and at least every three hours for continuing AI companion interactions which states either verbally or in writing that the user is not communicating with a human." Section 1701 requires a self-harm detection protocol with referral to crisis services such as the 988 line. Section 1703 gives enforcement to the Attorney General alone, with civil penalties up to 15,000 dollars per day. No private right of action, which makes New York less dangerous than California but no less binding.
Maine catches everybody, because it does not care whether your system is a companion. Section 1500-DD bars using an AI chatbot in trade and commerce in a manner that may mislead a reasonable consumer into believing they are engaging with a human being, absent clear and conspicuous notice, and a breach is a violation of the Maine Unfair Trade Practices Act.
The 2027 arrival to diary now is Washington. Engrossed Substitute HB 2225, "Regulating artificial intelligence companion chatbots," was requested by Governor Ferguson, signed 24 March 2026 as chapter 168 of the 2026 laws, and takes effect 1 January 2027. Its operator definition is pure deployer language: "any person, partnership, corporation, or entity that makes available or controls access to an AI companion chatbot." Disclosure is required at the beginning of the interaction and at least every three hours of continued interaction for adults, at least every hour for minors. Enforcement runs through chapter 19.86 RCW, the Consumer Protection Act, and RCW 19.86.090 lets any person injured in business or property sue for damages, costs, fees and treble damages, the trebled portion capped at 25,000 dollars. That is a second private route into the same conduct, on a stricter cadence than California's.
Treat none of this as a complete list. The Transparency Coalition counted 78 chatbot bills across 27 states in February 2026, and its 21 July 2026 mid-year report counted 84 new AI laws enacted across 27 states in the first half of the year, with chatbot disclosure, self-harm response protocols and parental controls among the recurring themes. Connecticut alone enacted a 74 page artificial intelligence and online safety law covering chatbot safeguards. Re-pull the list every quarter: the states your fans live in change faster than your chat stack does. Our piece on the operating rules for AI chatting inside an OnlyFans agency covers the contractual layer underneath this, and the European equivalent is in our breakdown of the EU AI Act's chatbot disclosure obligation.
Does AI Assisted Fan Chat Meet the Definition
It turns on how much autonomy the system has. Three configurations, three risk profiles.
AI drafts, a human sends every message. The chatter reads the thread, the tool proposes a reply, the chatter edits or accepts, a human presses send. This is the strongest position by a wide margin. California's bot law does not reach it: section 17940 requires that all or substantially all actions not be the result of a person, and here every outbound is a person's judgment. Untested against the companion statutes, but defensible, and defensible is what you are buying.
AI runs the queue, humans supervise and escalate. The AI sends autonomously for stretches while a human reviews flagged threads and takes over on high-value fans. This is where most agencies that have adopted AI sit, and it is the genuine grey zone: during the unattended stretches you are running exactly what the statutes describe, and reading the transcript afterwards does not change what the fan experienced.
Fully autonomous persona. The system holds the persona, remembers the fan, asks how his day went and upsells, with nobody on the send. Under SB 243 that is a companion chatbot on any straightforward reading, under New York's test it hits all three prongs by design, and under Maine it will mislead a reasonable consumer unless you say otherwise. The question is not whether the statutes apply but what your disclosure looks like.
Now the trap. Every owner reaches for the customer service exclusion: "we are just answering messages about the subscription." Those carve-outs describe systems whose function is informational. A fan chat system's function is emotional: it builds a parasocial bond and monetizes it. Worse, your own chatting SOP almost certainly tells operators to build rapport, remember personal details and sustain the relationship, so your internal documents argue against you. Our comparison of AI versus human chatters on an OnlyFans roster sets out what each configuration costs and earns.
Who Carries the Liability, Agency, Creator or Vendor
The duty runs to the operator, and the operator is usually you. California defines an operator as a person who makes a companion chatbot platform available to a user in the state. Washington's HB 2225 reaches "any person, partnership, corporation, or entity that makes available or controls access to an AI companion chatbot," and treats operators as a separate category from developers. The consistent drafting choice is deployer liability, so if you license a chat AI, configure the persona, point it at fans and take a cut of what it earns, you are the operator in every sense the statutes care about, whoever trained the model.
Vendor contracts push the same way. In the AI chat vendor terms we have seen, legal compliance is the customer's obligation and indemnity runs from customer to vendor. Get four answers in writing before you sign or renew. What disclosure does the system render to the fan, and can we configure it? What does it do when a user expresses suicidal ideation or self-harm? Can it be disabled per jurisdiction? Will you indemnify us for claims arising from its outputs?
The creator is exposed differently, not less. The message goes out under her name, so reputational and platform-terms fallout lands on her account while the operator analysis lands on you. Your management agreement should say who is the operator, who indemnifies whom, and who holds the logs.
Jurisdiction follows the fan, not you. SB 243 speaks of a user in the state, so an agency operating from Manila, Dubai or Melbourne with a paying fan in Sacramento is inside California's stated scope. The litigation backdrop matters too: a putative class action in California alleged that agency chatters impersonated creators, and trade reporting in late 2025 described a federal judge dismissing most claims with leave to amend while sanctioning plaintiffs' counsel over AI-generated briefs with false citations. That is reporting, not settled precedent, and the lesson is not that the claims failed but that the theory exists, which we cover in our piece on ghost chatting lawsuits and where the legal risk actually sits.
The Disclosure Question Nobody Wants to Answer
The objection every owner raises: disclosure kills conversion. A fan who knows he is texting software spends less than one who believes he is texting a person. Three real options.
Do not automate the persona. Keep humans on the send and use AI for drafting, translation, summarization and queue triage. You lose some labor saving, keep almost all of the conversion, and your duties collapse to two: do not deceive, and answer honestly if asked. Most agencies should land here.
Automate and disclose. Put the disclosure where the statutes want it, in the profile and in-conversation, and accept the hit. Any conversion figure you hear is a practitioner claim, not measured evidence, because nobody has published a clean test. Measure it with your own holdout.
Automate and hide. This converts a business risk into a statutory damages claim a plaintiff will try to price per message. Washington adds a second private route from January 2027 through a Consumer Protection Act that already trebles damages and shifts fees. Fee-shifting is why a private right of action is a different order of risk from Attorney General enforcement.
Whatever you choose, one rule has no exceptions. Never lie to a fan who directly asks whether he is talking to a bot or an AI. Utah makes an on-request disclosure duty explicit, California's bot law turns on intent to mislead about artificial identity to incentivize a purchase, and Maine turns on misleading a reasonable consumer. A denial satisfies the mental-state element of all three at once, in writing, in a log you do not control.
A Defensible Policy for an AI Assisted Chat Team
You do not need a legal opinion to sit ahead of most competitors, just a written, dated, enforced policy.
Declare the operating mode per creator, in writing. Human-only, AI-assisted with human send, AI-first with human escalation, or fully autonomous. One dated line per creator, changed before the mode changes. In any dispute the opening question is what your system was doing.
Know where the fan is, or assume the strictest rule. Every statute here keys to the consumer's state, so if your stack cannot attribute a fan to a jurisdiction, apply the strictest live rule to everyone.
Build disclosure in two places. A profile-level statement covers the reasonable-person test; an in-conversation disclosure covers the statutes demanding it at the start and on a recurring cadence. If you run autonomously and touch New York now, or Washington from 2027, build the recurring reminder early.
Write the never-lie rule into the chatter handbook and audit it in QA. One sentence, no exceptions, plus a scripted honest response so operators do not improvise under pressure.
Adopt a self-harm protocol even where you are not yet covered. Detect suicidal ideation, stop selling, refer to crisis services such as the 988 line, hand the thread to a named human. California and New York already require one; California requires it published.
Treat minors as a hard stop. Platform age verification is your first line, but you need a documented rule for the moment a chatter or classifier suspects a minor: freeze, escalate, report, never resume.
Log what generated each message. Timestamp, thread, sender, and whether the outbound was human-composed, human-approved or autonomous. In a damages case that log is the difference between a defense and a shrug.
Fix the contract and diary a re-read every six months. Name the operator, allocate indemnity, assign log ownership. Washington lands 1 January 2027 and California's annual reporting duty starts 1 July 2027, so a policy written in July 2026 is stale by January.
Why the arithmetic matters. If four hundred of your paying fans sit in California, chat is fully autonomous with no disclosure, and a plaintiff argues per-message violations, the floor is 1,000 dollars a violation before fees. That asymmetry, not the odds of getting caught, is the reason to fix this. If a human-on-send model is where you land, our guide to redesigning a chat team around an AI and human handoff covers the staffing and shift mechanics.
FAQ on State AI Chatbot Laws and Fan Chat
Do I have to tell fans they are talking to an AI chatter?
If the chat is fully automated and the fan is in a state with a live statute, generally yes. California SB 243 requires a clear and conspicuous notification that the chatbot is artificially generated and not human where a reasonable person would be misled, New York requires it at the start and at least every three hours after, and Maine prohibits misleading a consumer into believing they are dealing with a human. If a human approves every outbound you sit on much stronger ground, but never deny it when a fan asks directly.
Does California SB 243 apply to my OnlyFans agency?
It applies if you are an operator making a companion chatbot available to a user in California, and the definition is capability-based, not industry-specific: an AI system giving adaptive, human-like responses that is capable of meeting a user's social needs across multiple interactions. Fully autonomous fan chat fits that far better than it fits the customer service exclusion, and scope follows the fan's location, so operating offshore does not remove it.
Can a fan sue my agency directly over an AI chatter?
Under California SB 243, yes. Section 22605 lets a person who suffers injury in fact recover injunctive relief plus the greater of actual damages or 1,000 dollars per violation, along with attorney's fees and costs. From 1 January 2027, Washington HB 2225 makes a violation an unfair or deceptive act under chapter 19.86 RCW, and RCW 19.86.090 lets an injured person sue for damages, costs, fees and treble damages capped at 25,000 dollars. New York's Article 47 is Attorney General enforcement only, with civil penalties up to 15,000 dollars per day.
Does a human chatter using AI to draft messages count as a chatbot?
Probably not, though it is untested. California's bot law defines a bot as an account where all or substantially all actions are not the result of a person, and a workflow where a human reads, edits and sends every message fails that test comfortably. The companion statutes attach to systems rather than accounts, leaving more room for argument, but their duties are framed around a user interacting with the chatbot, not with a person using software.
Which states have AI chatbot disclosure laws right now?
As of late July 2026, the ones most relevant to paid chat are California, with the 2019 bot disclosure law at Business and Professions Code 17940 and SB 243 since 1 January 2026; New York's General Business Law Article 47 since 5 November 2025; Maine's Title 10 section 1500-DD since September 2025; and Utah's disclosure-on-request rule. Washington HB 2225 arrives 1 January 2027. More are moving: the Transparency Coalition counted 78 chatbot bills across 27 states in February 2026 and 84 enacted AI laws across 27 states in its 21 July 2026 mid-year report. Verify before relying on any summary, including this one.
Is this legal advice, and how does WhaleFinders fit in?
No. This is educational information about United States state chatbot statutes and how they intersect with AI-assisted fan chat, not legal advice, and several questions above are unsettled because no court has applied these statutes to paid adult chat. Have a qualified lawyer review your configuration, contracts and disclosures. WhaleFinders works white-label as the marketing direction arm inside OnlyFans agencies and does not chat with fans or post content, so this is policy design we help owners think through rather than execute. We are on Telegram at t.me/whalefindersupport.
Put a full marketing department behind your agency
WhaleFinders runs the niche strategy, daily content direction, and platform playbooks for OnlyFans agencies, white-label under your brand.
Join the newsletter
Be the first to read our articles.