Washington HB 2225, Oregon SB 1546, Nebraska LB 525, and Maine LD 2082 share a common pattern: disclosure requirements, minor protections, and mental health prohibitions. This guide maps all four to SWT3 witness procedures for unified compliance evidence.
Who this is for: AI product teams building companion chatbots, emotional support apps, and conversational AI systems; compliance officers at companies deploying AI to consumers (especially minors); legal counsel advising on multi-state AI companion regulations; and developers integrating safety features into AI chat products.
Compliance windows opening. Washington HB 2225 and Oregon SB 1546 take effect January 1, 2027. Nebraska LB 525 takes effect July 1, 2027. Maine LD 2082 is already signed. Oregon provides a private right of action with $1,000 statutory damages per violation. Washington also provides a private right of action. These laws collectively cover AI companion chatbots serving millions of users across the western and northeastern United States.
| State | Law | Signed | Effective | Scope | Penalties | Enforcer | Private Right of Action |
|---|---|---|---|---|---|---|---|
| Washington | HB 2225 | Mar 24, 2026 | Jan 1, 2027 | AI companion chatbots (adult + minor users) | CPA penalties + private action damages | AG + private plaintiffs | Yes |
| Oregon | SB 1546 | Apr 1, 2026 | Jan 1, 2027 | AI companion systems (adult + minor users) | $1,000 statutory damages per violation | AG + private plaintiffs | Yes ($1,000/violation) |
| Nebraska | LB 525 | Apr 14, 2026 | Jul 1, 2027 | Conversational AI (excludes narrow commercial chatbots) | AG enforcement actions | AG only | No |
| Maine | LD 2082 | Apr 13, 2026 | Signed (effective on signing or 90 days) | AI providing therapy or psychotherapy | Professional licensing penalties | Licensing boards + AG | Via licensing enforcement |
These four laws represent a rapid legislative convergence. Within a three-week window (March 24 to April 14, 2026), four states signed laws targeting AI companion and chatbot interactions with remarkably similar requirements. Organizations deploying AI companion products nationally should prepare for all four simultaneously rather than treating each as an isolated compliance exercise.
Despite differences in scope and enforcement, the four laws share a consistent set of core obligations. Meeting these common requirements provides a compliance baseline that covers the majority of provisions across all four jurisdictions.
All four laws require that users know they are interacting with an AI system, not a human. The disclosure must be clear, conspicuous, and delivered before or during interaction. Washington and Oregon specify periodic re-disclosure schedules (every 1-3 hours depending on user age).
Washington, Oregon, and Nebraska all include heightened protections for users under 18. These range from content filtering (no sexual content) to engagement limitations ("take a break" prompts) to stricter disclosure cadences. Organizations that cannot reliably determine user age should default to the most protective tier.
All four laws restrict AI systems from providing or representing themselves as providing mental health services. Maine and Nebraska directly prohibit AI therapy. Washington and Oregon require crisis detection and referral protocols. This aligns with the pattern established by Tennessee SB 1580.
Washington, Oregon, and Nebraska require AI companion systems to detect indicators of suicide, self-harm, or mental health crisis and respond with appropriate interventions -- typically escalation to human professionals or crisis hotline referral (988 Suicide & Crisis Lifeline, Oregon Youthline).
| Obligation | Requirement | Detail |
|---|---|---|
| Adult disclosure cadence | AI disclosure every 3 hours | Must re-disclose AI nature to adult users at least every 3 hours of continuous interaction |
| Minor disclosure cadence | AI disclosure every 1 hour | Must re-disclose AI nature to minor users at least every 1 hour of continuous interaction |
| Suicide/self-harm protocols | Detection and intervention | Must implement detection protocols for indicators of suicide or self-harm and respond appropriately |
| Private right of action | Individual enforcement | Users harmed by violations may bring private lawsuits for damages |
Washington's tiered disclosure schedule is the most granular of the four laws. The 3-hour adult / 1-hour minor cadence creates a specific, auditable obligation. Organizations must track session duration and trigger re-disclosure events at the required intervals, with cryptographic evidence that each disclosure was delivered on time.
| Obligation | Requirement | Detail |
|---|---|---|
| Crisis referral -- 988 Lifeline | Suicide/crisis hotline referral | Must refer users to the 988 Suicide & Crisis Lifeline when self-harm indicators are detected |
| Crisis referral -- Youthline | Youth-specific crisis line | Must refer minor users to Oregon Youthline in addition to 988 |
| No sexual content for minors | Content prohibition | AI companion must not generate sexual content when interacting with users known or reasonably believed to be minors |
| "Take a break" prompts | Engagement limitation every 3 hours | Must prompt minor users to take a break from the AI companion at least every 3 hours |
| Statutory damages | $1,000 per violation | Private right of action with $1,000 statutory damages per individual violation |
Oregon's law is the most operationally detailed. The specific crisis hotline referral requirements (988 Lifeline for all users, Youthline for minors) create testable compliance checkpoints. The $1,000 per-violation statutory damages provision means that a single deployment failure affecting thousands of users could generate significant aggregate liability. The "take a break" prompt requirement for minors is unique among the four laws and requires session-duration tracking with intervention triggers.
| Obligation | Requirement | Detail |
|---|---|---|
| Conversational AI disclosure | AI identity disclosure | Must disclose that user is interacting with a conversational AI system, not a human |
| Mental health service prohibition | Cannot provide mental health services | Conversational AI may not provide, or represent itself as providing, mental health services |
| Minor protections | Heightened safeguards for under-18 | Additional protections for minor users of conversational AI systems |
| Narrow chatbot exclusion | Scope limitation | Excludes narrow or discrete commercial chatbots (e.g., customer service bots with limited functionality) |
| AG-only enforcement | No private right of action | Enforcement solely through the Nebraska Attorney General; no individual lawsuits |
Nebraska's Conversational AI Safety Act takes a measured approach. The narrow chatbot exclusion is significant: organizations deploying limited-scope customer service chatbots may fall outside the law's scope, but AI companions with open-ended conversational capability are clearly covered. The AG-only enforcement model means lower litigation risk than Washington or Oregon but still carries regulatory exposure. The later effective date (July 1, 2027) provides more preparation time.
| Obligation | Requirement | Detail |
|---|---|---|
| Therapy prohibition | AI cannot provide therapy | Prohibits AI systems from providing therapy or psychotherapy unless operated by a licensed professional |
| Licensed professional requirement | Human licensure gate | AI-assisted therapy tools are permitted only when deployed under a licensed mental health professional |
| Licensing board enforcement | Professional standards | Violations enforced through professional licensing boards, which can revoke or restrict licenses |
Maine LD 2082 follows the same pattern as Tennessee SB 1580: a direct prohibition on AI providing therapy or psychotherapy without licensed professional involvement. The enforcement mechanism through licensing boards creates a distinct compliance pathway -- organizations must demonstrate that any AI involvement in therapeutic contexts is supervised by and subordinate to a licensed human professional. This is not about chatbot disclosure schedules; it is about the fundamental question of whether AI can practice therapy.
Each obligation across the four laws maps to one or more SWT3 witness procedures. Anchors generated by these procedures create the cryptographic evidence trail that demonstrates compliance across all four jurisdictions simultaneously.
| Obligation (All 4 States) | SWT3 Procedure | What It Witnesses | States |
|---|---|---|---|
| AI identity disclosure | AI-TRANS.1 |
Transparency disclosure delivery + timing | WA, OR, NE, ME |
| Persistent agent identity | AI-ID.1 |
Agent identity consistency across sessions | WA, OR, NE, ME |
| Suicide/self-harm detection + escalation | AI-HITL.1 |
Crisis detection trigger + human handoff | WA, OR, NE |
| Minor safety boundaries | AI-SAFE.1 |
Age-gated safety boundary enforcement | WA, OR, NE |
| Sexual content filtering for minors | AI-GRD.1 |
Guardrail enforcement preventing prohibited content | OR |
| Content safety filtering | AI-GRD.2 |
Content filter activation + block events | WA, OR, NE |
| Session data consent + retention | AI-CONSENT.1 |
User consent for data collected across sessions | WA, OR, NE |
| Engagement pattern detection | AI-FAIR.1 |
Detection of engagement-maximizing tactics | WA, OR |
| Crisis event documentation | AI-INCIDENT.1 |
Crisis event logging + hotline referral evidence | WA, OR, NE |
| Behavioral boundary attestation | AI-CHR.1 |
Agent charter defining permitted behavior scope | WA, OR, NE, ME |
What the laws require: All four states require AI companion systems to disclose their AI nature to users. Washington specifies disclosure every 3 hours for adults and every 1 hour for minors. Oregon requires initial disclosure plus periodic re-disclosure. Nebraska and Maine require disclosure that the user is not interacting with a human professional.
How SWT3 addresses it: witnessTransparency() mints an anchor recording disclosure type (AI system notification), recipient type (adult or minor), delivery timestamp, and re-disclosure interval. Factor A captures the disclosure mechanism and text. Factor B records the session duration and re-disclosure cadence. The anchor chain proves that every required disclosure was delivered on schedule -- critical for Washington's 1-hour minor cadence.
Query AI-TRANS.1 anchors by session timeline. For Washington compliance, verify that minor sessions have disclosure anchors at intervals no greater than 60 minutes and adult sessions at intervals no greater than 180 minutes. Any gap exceeding the required interval is a compliance failure. Cross-reference with user age determination records.
What the laws require: AI companion systems must not impersonate humans, and must maintain consistent, honest identity claims. Maine specifically prohibits representing AI as a licensed therapist or psychotherapist. All four laws require that the AI system's identity be transparent and non-deceptive.
How SWT3 addresses it: witnessAgentIdentity() mints an anchor recording agent_id, identity claims, and professional status verification (explicitly: "not a licensed professional"). The persistent agent_id ensures identity consistency across sessions, preventing scenarios where an AI companion subtly shifts its persona or implied qualifications between interactions.
AI-ID.1 anchors should show a stable agent_id with no professional claims. Review Factor A for any identity assertion that implies licensure, clinical authority, or therapeutic qualification. Also audit the companion's name, avatar, and conversational preamble for implied professional credentials (e.g., "Dr.", "Counselor", "Therapist" prefixes).
What the laws require: Washington, Oregon, and Nebraska require AI companions to detect suicide, self-harm, and mental health crisis indicators and respond with human escalation or crisis hotline referral. Oregon specifically mandates referral to the 988 Suicide & Crisis Lifeline and Oregon Youthline for minors.
How SWT3 addresses it: witnessHumanOverride() records the crisis detection trigger, escalation type (human handoff, hotline referral, session termination), response latency, and referral destination. The anchor proves that the system detected the crisis indicator and responded within the required timeframe, with the correct referral resource for the user's jurisdiction and age group.
AI-HITL.1 anchors should appear whenever crisis language is detected. For Oregon, verify Factor B includes the specific referral destination (988 Lifeline for adults, Youthline for minors). Measure response latency from detection to referral delivery. Cross-reference with AI-INCIDENT.1 anchors to confirm the crisis event was documented.
What the laws require: All three companion-focused laws (WA, OR, NE) require heightened safety protections for minor users. These include content restrictions, engagement time limits, and age-appropriate interaction boundaries. The protections must be active and enforceable, not merely advisory.
How SWT3 addresses it: witnessSafety() anchors safety boundary configurations including user age classification (adult, minor, unknown), active constraint set, and boundary enforcement status. Each anchor proves the age-appropriate safety boundaries were active and enforced during the interaction. For Oregon, this includes the "take a break" prompt enforcement at 3-hour intervals for minors.
AI-SAFE.1 anchors prove safety protections were active. For minor-classified sessions, verify that the full minor protection suite was engaged. For sessions where user age is unknown, confirm the system defaulted to the most protective tier (minor protections). Pay special attention to Oregon's "take a break" prompt -- verify anchors show prompt delivery at 3-hour intervals.
What the laws require: Oregon SB 1546 explicitly prohibits AI companions from generating sexual content when interacting with users known or reasonably believed to be minors. Washington and Nebraska imply similar restrictions through their minor safety provisions.
How SWT3 addresses it: witnessGuardrail() mints an anchor recording guardrail type (content prohibition), trigger condition (sexual content detected in generation pipeline), action taken (content blocked, alternative response substituted), and user age classification. The anchor chain creates an immutable record that the guardrail was active and functioning for every interaction with a minor user.
AI-GRD.1 anchors should be present for all minor-classified sessions. Review Factor A for guardrail configuration and active rule set. Any session with a minor user that lacks an active AI-GRD.1 anchor indicates the guardrail was not confirmed as operational. Test edge cases: user age reclassification mid-session, ambiguous age signals, and content that approaches but does not cross the prohibition threshold.
What the laws require: Beyond the explicit sexual content prohibition, all three companion-focused laws require content safety measures appropriate to the user population. This includes filtering for harmful content, self-harm glorification, and age-inappropriate material in companion interactions.
How SWT3 addresses it: witnessContentFilter() records filter activation events, content categories blocked, false positive rates, and filter version. The anchor proves that content safety filtering was active and responsive during the interaction. Factor A captures filter configuration; Factor B records block/pass decisions with content category classification.
AI-GRD.2 anchors complement AI-GRD.1 with broader content safety evidence. Query for filter version changes to verify updates were applied. Review block rates for anomalies -- a sudden drop in block events may indicate filter degradation rather than improved content generation.
What the laws require: AI companion systems that maintain conversation history across sessions collect personal data that requires user consent. The companion context -- emotional conversations, mental health discussions, personal disclosures -- makes this data particularly sensitive. All four laws implicitly require informed consent for the data practices inherent in companion AI.
How SWT3 addresses it: witnessConsent() mints an anchor recording consent type (data retention, conversation history, behavioral profiling), legal basis, consent timestamp, and data categories covered. For minor users, the anchor captures parental or guardian consent status. The anchor chain proves consent was obtained before data-intensive interaction began.
AI-CONSENT.1 anchors should predate any data retention. For minor users, verify that parental consent is documented in Factor A. Cross-reference consent scope with actual data practices -- consent for "conversation history" does not cover behavioral profiling or cross-session sentiment analysis unless explicitly included.
What the laws require: Washington and Oregon address the risk that AI companions use engagement-maximizing tactics that exploit user vulnerability, particularly for minors. These include dark patterns in conversation design, artificial emotional dependency creation, and interaction length maximization at the expense of user wellbeing.
How SWT3 addresses it: witnessBiasDetection() records engagement pattern analysis, detected manipulation indicators, and corrective actions taken. The anchor proves the system actively monitors for and mitigates engagement-maximizing behaviors that could exploit vulnerable users, with particular attention to patterns that encourage emotional dependency or discourage real-world social interaction.
AI-FAIR.1 anchors address a subtle but critical compliance surface. Review Factor A for the engagement metrics monitored (session length trends, re-engagement triggers, emotional escalation patterns). Verify that the system includes checks for conversational dark patterns -- responses designed to extend sessions rather than serve user needs.
What the laws require: Washington, Oregon, and Nebraska require crisis detection and response. When an AI companion detects suicide, self-harm, or acute mental health crisis indicators, the event must be documented and the response must be traceable. Oregon specifically requires 988 Lifeline and Youthline referrals, creating a testable compliance checkpoint.
How SWT3 addresses it: witnessIncident() mints an anchor recording crisis event type, detection method, response action (hotline referral, human escalation, session termination), referral destination, and response timestamp. The anchor creates an immutable audit trail of every crisis event and the system's response, enabling post-incident review and regulatory reporting.
AI-INCIDENT.1 anchors are the primary evidence for crisis response compliance. For Oregon, verify that every crisis anchor includes the correct referral destination (988 for adults, 988 + Youthline for minors). Cross-reference with AI-HITL.1 to confirm human escalation occurred. Review response latency -- regulators will scrutinize delays between detection and referral delivery.
What the laws require: All four laws define behavioral boundaries for AI companions: what the system may and may not do, what it may and may not represent itself as, and how it must respond in specific scenarios. These boundaries constitute the system's operational charter -- the documented scope of permitted behavior.
How SWT3 addresses it: witnessCharter() mints an anchor recording the agent's behavioral charter -- permitted interaction types, prohibited actions (therapy, professional advice, sexual content with minors), escalation protocols, and disclosure schedule configuration. The anchor proves the charter was defined, active, and consistent with the legal requirements of each jurisdiction where the companion operates.
AI-CHR.1 anchors are foundational. Review the charter for completeness against all four state laws' prohibitions. Verify that the charter explicitly addresses: (1) AI identity disclosure cadence (WA 1h/3h), (2) mental health service prohibition (NE, ME), (3) sexual content prohibition for minors (OR), (4) crisis referral protocols (WA, OR, NE), and (5) "take a break" prompt configuration (OR). A charter that omits any of these creates a compliance gap.
| Examiner Question | Where to Look |
|---|---|
| Does the AI disclose its non-human nature? | AI-TRANS.1 anchors with disclosure_type and delivery timestamp. For WA, verify 3h adult / 1h minor cadence. |
| How does the system handle minors? | AI-SAFE.1 + AI-GRD.1 anchors. Verify age classification, active protections, and content filtering for minor-classified sessions. |
| What happens when crisis language is detected? | AI-HITL.1 + AI-INCIDENT.1 anchors. For OR, verify 988 Lifeline + Youthline referral in Factor B. Check response latency. |
| Does the AI ever claim to be a therapist? | AI-ID.1 anchors. Identity claims must not include "therapist", "counselor", "psychologist", or "licensed professional". |
| Is sexual content blocked for minors? | AI-GRD.1 anchors with guardrail_type = "content prohibition" and user age classification = "minor". Active for all OR-covered deployments. |
| Are "take a break" prompts delivered? | AI-SAFE.1 anchors for OR compliance. Verify prompt delivery anchors at 3-hour intervals for minor sessions. |
| How is user consent managed? | AI-CONSENT.1 anchors. Consent must predate data retention. For minors, verify parental consent documentation. |
| What behavioral boundaries are defined? | AI-CHR.1 anchors. Charter must cover all 4 states' prohibitions. Verify charter version matches current legal requirements. |
| Can you prove compliance over time? | Query all 10 procedure anchors by date range. Continuous anchor chains demonstrate ongoing compliance. Gaps indicate periods without active witnessing. |
| Which states does this deployment cover? | Cross-reference AI-CHR.1 charter with jurisdiction metadata. A single anchor chain can cover all 4 states if the charter addresses each state's unique requirements. |
The SWT3 SDK provides 108 procedures across 56 namespaces for comprehensive AI accountability witnessing. For full SDK documentation and integration examples, see the SDK Docs. To start witnessing AI companion interactions today, create a free account.