Volume II · Episode 6 · 2026-08-07

AI Regulations and the Chatbot Laws Already in Force

Guest Michael Simon on what is actually in force: most of the attention went to the timelines that moved, while a set of chatbot obligations came into force on schedule across US states and beyond. Federal and nine states in detail, the EU AI Act and California around them, and what an operator does about it on Monday.

Host Sam Rogers · guest Michael Simon · 32 min

Also watch and listen

Watch the episodeYouTube — 32 minutes Read + listenSubstack — the episode, in your inbox PodcastApple Podcasts Podcast, the showSpotify ReadFull transcript

The signals

The subtractions

About this episode

The center of the episode is the rundown: the chatbot obligations already in force, state by state, stacked in one pass so the cumulative weight is visible. New York, reasonable measures against content promoting self-harm, up to $15,000 per incident from the Attorney General. California, the same plus preventing sexually explicit material reaching minors, an annual disclosure to a suicide-prevention agency, and a private right of action. Washington, no simulating distress, no dark-pattern pleas to stay or pay, no "don't tell your parents," private right of action. Oregon, the self-harm measures published openly plus a mandatory interrupt-and-refer when a user shows signs of suicidal ideation, private right of action again. Connecticut, no implying the bot is a mental health professional. Iowa, four duties: prevent creation of sexually explicit material, never claim to be human, do not create dependency on the chatbot, and provide privacy tools for minors and parents. Then healthcare on top: Illinois, Texas, Nevada, and claims-substantiation rules in California, Tennessee, and Colorado.

The jurisdictional hook is the part operators most often get wrong: if you have a website offering products or services to anyone in the US, these laws reach you. Most of the AI statutes skip the revenue thresholds privacy law uses; impacting consumers in the state is enough, and the internet goes everywhere.

The liability point lands through a hobby Mike picked up from a security-minded CEO: open any customer-help chatbot and treat it like ChatGPT. More often than not it behaves like a free frontier-model instance, set to do anything, like the dealership bot that offered a Chevy Suburban for $20. Contracting with a vendor does not move the liability; the laws put the deploying company on the hook for what the bot does. His standing advice: you do not want to be a test case, because the companies in those cases spend millions just to get back to where they were.

Mike is a lawyer, not your lawyer: nothing in the episode is legal advice. He practices at Law+Data and is part-time chief strategy officer at Bells Up AI.

This week's links:

This episode is sponsored by EveryAILaw, the free index of AI regulations cited on air as the episode's source. Disclosure: EveryAILaw is built and owned by Sam, the show's host.

Want to bring your own signal and subtraction? Find yours. Sponsored by EveryAILaw.

The newsletter

Read the newsletterThe Quilt and the Minefield

One signal, one subtraction, one analogy, in five minutes. It draws on this episode but stands on its own. Every issue.