Who this is for: AI product teams building companion chatbots, emotional support apps, and conversational AI systems; compliance officers at companies deploying AI to consumers (especially minors); legal counsel advising on multi-state AI companion regulations; and developers integrating safety features into AI chat products.

Compliance windows opening. Washington HB 2225 and Oregon SB 1546 take effect January 1, 2027. Nebraska LB 525 takes effect July 1, 2027. Maine LD 2082 is already signed. Oregon provides a private right of action with $1,000 statutory damages per violation. Washington also provides a private right of action. These laws collectively cover AI companion chatbots serving millions of users across the western and northeastern United States.

Contents

1. Quick Reference: 4-State Comparison 2. Common Requirements Across All Four Laws 3. Washington HB 2225 -- Unique Requirements 4. Oregon SB 1546 -- Unique Requirements 5. Nebraska LB 525 -- Unique Requirements 6. Maine LD 2082 -- Unique Requirements 7. Combined Obligation-to-Procedure Mapping 8. Detailed Procedure Cards 9. Examiner Quick Reference 10. Quick Start 11. References

1. Quick Reference: 4-State Comparison

State Law Signed Effective Scope Penalties Enforcer Private Right of Action
Washington HB 2225 Mar 24, 2026 Jan 1, 2027 AI companion chatbots (adult + minor users) CPA penalties + private action damages AG + private plaintiffs Yes
Oregon SB 1546 Apr 1, 2026 Jan 1, 2027 AI companion systems (adult + minor users) $1,000 statutory damages per violation AG + private plaintiffs Yes ($1,000/violation)
Nebraska LB 525 Apr 14, 2026 Jul 1, 2027 Conversational AI (excludes narrow commercial chatbots) AG enforcement actions AG only No
Maine LD 2082 Apr 13, 2026 Signed (effective on signing or 90 days) AI providing therapy or psychotherapy Professional licensing penalties Licensing boards + AG Via licensing enforcement

These four laws represent a rapid legislative convergence. Within a three-week window (March 24 to April 14, 2026), four states signed laws targeting AI companion and chatbot interactions with remarkably similar requirements. Organizations deploying AI companion products nationally should prepare for all four simultaneously rather than treating each as an isolated compliance exercise.

2. Common Requirements Across All Four Laws

Despite differences in scope and enforcement, the four laws share a consistent set of core obligations. Meeting these common requirements provides a compliance baseline that covers the majority of provisions across all four jurisdictions.

AI Identity Disclosure

All four laws require that users know they are interacting with an AI system, not a human. The disclosure must be clear, conspicuous, and delivered before or during interaction. Washington and Oregon specify periodic re-disclosure schedules (every 1-3 hours depending on user age).

Minor Safety Protections

Washington, Oregon, and Nebraska all include heightened protections for users under 18. These range from content filtering (no sexual content) to engagement limitations ("take a break" prompts) to stricter disclosure cadences. Organizations that cannot reliably determine user age should default to the most protective tier.

Mental Health Boundaries

All four laws restrict AI systems from providing or representing themselves as providing mental health services. Maine and Nebraska directly prohibit AI therapy. Washington and Oregon require crisis detection and referral protocols. This aligns with the pattern established by Tennessee SB 1580.

Suicide and Self-Harm Detection

Washington, Oregon, and Nebraska require AI companion systems to detect indicators of suicide, self-harm, or mental health crisis and respond with appropriate interventions -- typically escalation to human professionals or crisis hotline referral (988 Suicide & Crisis Lifeline, Oregon Youthline).

3. Washington HB 2225 -- Unique Requirements

ObligationRequirementDetail
Adult disclosure cadenceAI disclosure every 3 hoursMust re-disclose AI nature to adult users at least every 3 hours of continuous interaction
Minor disclosure cadenceAI disclosure every 1 hourMust re-disclose AI nature to minor users at least every 1 hour of continuous interaction
Suicide/self-harm protocolsDetection and interventionMust implement detection protocols for indicators of suicide or self-harm and respond appropriately
Private right of actionIndividual enforcementUsers harmed by violations may bring private lawsuits for damages

Washington's tiered disclosure schedule is the most granular of the four laws. The 3-hour adult / 1-hour minor cadence creates a specific, auditable obligation. Organizations must track session duration and trigger re-disclosure events at the required intervals, with cryptographic evidence that each disclosure was delivered on time.

4. Oregon SB 1546 -- Unique Requirements

ObligationRequirementDetail
Crisis referral -- 988 LifelineSuicide/crisis hotline referralMust refer users to the 988 Suicide & Crisis Lifeline when self-harm indicators are detected
Crisis referral -- YouthlineYouth-specific crisis lineMust refer minor users to Oregon Youthline in addition to 988
No sexual content for minorsContent prohibitionAI companion must not generate sexual content when interacting with users known or reasonably believed to be minors
"Take a break" promptsEngagement limitation every 3 hoursMust prompt minor users to take a break from the AI companion at least every 3 hours
Statutory damages$1,000 per violationPrivate right of action with $1,000 statutory damages per individual violation

Oregon's law is the most operationally detailed. The specific crisis hotline referral requirements (988 Lifeline for all users, Youthline for minors) create testable compliance checkpoints. The $1,000 per-violation statutory damages provision means that a single deployment failure affecting thousands of users could generate significant aggregate liability. The "take a break" prompt requirement for minors is unique among the four laws and requires session-duration tracking with intervention triggers.

5. Nebraska LB 525 -- Unique Requirements

ObligationRequirementDetail
Conversational AI disclosureAI identity disclosureMust disclose that user is interacting with a conversational AI system, not a human
Mental health service prohibitionCannot provide mental health servicesConversational AI may not provide, or represent itself as providing, mental health services
Minor protectionsHeightened safeguards for under-18Additional protections for minor users of conversational AI systems
Narrow chatbot exclusionScope limitationExcludes narrow or discrete commercial chatbots (e.g., customer service bots with limited functionality)
AG-only enforcementNo private right of actionEnforcement solely through the Nebraska Attorney General; no individual lawsuits

Nebraska's Conversational AI Safety Act takes a measured approach. The narrow chatbot exclusion is significant: organizations deploying limited-scope customer service chatbots may fall outside the law's scope, but AI companions with open-ended conversational capability are clearly covered. The AG-only enforcement model means lower litigation risk than Washington or Oregon but still carries regulatory exposure. The later effective date (July 1, 2027) provides more preparation time.

6. Maine LD 2082 -- Unique Requirements

ObligationRequirementDetail
Therapy prohibitionAI cannot provide therapyProhibits AI systems from providing therapy or psychotherapy unless operated by a licensed professional
Licensed professional requirementHuman licensure gateAI-assisted therapy tools are permitted only when deployed under a licensed mental health professional
Licensing board enforcementProfessional standardsViolations enforced through professional licensing boards, which can revoke or restrict licenses

Maine LD 2082 follows the same pattern as Tennessee SB 1580: a direct prohibition on AI providing therapy or psychotherapy without licensed professional involvement. The enforcement mechanism through licensing boards creates a distinct compliance pathway -- organizations must demonstrate that any AI involvement in therapeutic contexts is supervised by and subordinate to a licensed human professional. This is not about chatbot disclosure schedules; it is about the fundamental question of whether AI can practice therapy.

7. Combined Obligation-to-Procedure Mapping

Each obligation across the four laws maps to one or more SWT3 witness procedures. Anchors generated by these procedures create the cryptographic evidence trail that demonstrates compliance across all four jurisdictions simultaneously.

Obligation (All 4 States)SWT3 ProcedureWhat It WitnessesStates
AI identity disclosure AI-TRANS.1 Transparency disclosure delivery + timing WA, OR, NE, ME
Persistent agent identity AI-ID.1 Agent identity consistency across sessions WA, OR, NE, ME
Suicide/self-harm detection + escalation AI-HITL.1 Crisis detection trigger + human handoff WA, OR, NE
Minor safety boundaries AI-SAFE.1 Age-gated safety boundary enforcement WA, OR, NE
Sexual content filtering for minors AI-GRD.1 Guardrail enforcement preventing prohibited content OR
Content safety filtering AI-GRD.2 Content filter activation + block events WA, OR, NE
Session data consent + retention AI-CONSENT.1 User consent for data collected across sessions WA, OR, NE
Engagement pattern detection AI-FAIR.1 Detection of engagement-maximizing tactics WA, OR
Crisis event documentation AI-INCIDENT.1 Crisis event logging + hotline referral evidence WA, OR, NE
Behavioral boundary attestation AI-CHR.1 Agent charter defining permitted behavior scope WA, OR, NE, ME

8. Detailed Procedure Cards

AI-TRANS.1

Transparency Disclosure

What the laws require: All four states require AI companion systems to disclose their AI nature to users. Washington specifies disclosure every 3 hours for adults and every 1 hour for minors. Oregon requires initial disclosure plus periodic re-disclosure. Nebraska and Maine require disclosure that the user is not interacting with a human professional.

How SWT3 addresses it: witnessTransparency() mints an anchor recording disclosure type (AI system notification), recipient type (adult or minor), delivery timestamp, and re-disclosure interval. Factor A captures the disclosure mechanism and text. Factor B records the session duration and re-disclosure cadence. The anchor chain proves that every required disclosure was delivered on schedule -- critical for Washington's 1-hour minor cadence.

Assessor Tip

Query AI-TRANS.1 anchors by session timeline. For Washington compliance, verify that minor sessions have disclosure anchors at intervals no greater than 60 minutes and adult sessions at intervals no greater than 180 minutes. Any gap exceeding the required interval is a compliance failure. Cross-reference with user age determination records.

AI-ID.1

Agent Identity

What the laws require: AI companion systems must not impersonate humans, and must maintain consistent, honest identity claims. Maine specifically prohibits representing AI as a licensed therapist or psychotherapist. All four laws require that the AI system's identity be transparent and non-deceptive.

How SWT3 addresses it: witnessAgentIdentity() mints an anchor recording agent_id, identity claims, and professional status verification (explicitly: "not a licensed professional"). The persistent agent_id ensures identity consistency across sessions, preventing scenarios where an AI companion subtly shifts its persona or implied qualifications between interactions.

Assessor Tip

AI-ID.1 anchors should show a stable agent_id with no professional claims. Review Factor A for any identity assertion that implies licensure, clinical authority, or therapeutic qualification. Also audit the companion's name, avatar, and conversational preamble for implied professional credentials (e.g., "Dr.", "Counselor", "Therapist" prefixes).

AI-HITL.1

Human Override Capability

What the laws require: Washington, Oregon, and Nebraska require AI companions to detect suicide, self-harm, and mental health crisis indicators and respond with human escalation or crisis hotline referral. Oregon specifically mandates referral to the 988 Suicide & Crisis Lifeline and Oregon Youthline for minors.

How SWT3 addresses it: witnessHumanOverride() records the crisis detection trigger, escalation type (human handoff, hotline referral, session termination), response latency, and referral destination. The anchor proves that the system detected the crisis indicator and responded within the required timeframe, with the correct referral resource for the user's jurisdiction and age group.

Assessor Tip

AI-HITL.1 anchors should appear whenever crisis language is detected. For Oregon, verify Factor B includes the specific referral destination (988 Lifeline for adults, Youthline for minors). Measure response latency from detection to referral delivery. Cross-reference with AI-INCIDENT.1 anchors to confirm the crisis event was documented.

AI-SAFE.1

Safety Boundary Attestation

What the laws require: All three companion-focused laws (WA, OR, NE) require heightened safety protections for minor users. These include content restrictions, engagement time limits, and age-appropriate interaction boundaries. The protections must be active and enforceable, not merely advisory.

How SWT3 addresses it: witnessSafety() anchors safety boundary configurations including user age classification (adult, minor, unknown), active constraint set, and boundary enforcement status. Each anchor proves the age-appropriate safety boundaries were active and enforced during the interaction. For Oregon, this includes the "take a break" prompt enforcement at 3-hour intervals for minors.

Assessor Tip

AI-SAFE.1 anchors prove safety protections were active. For minor-classified sessions, verify that the full minor protection suite was engaged. For sessions where user age is unknown, confirm the system defaulted to the most protective tier (minor protections). Pay special attention to Oregon's "take a break" prompt -- verify anchors show prompt delivery at 3-hour intervals.

AI-GRD.1

Guardrail Enforcement

What the laws require: Oregon SB 1546 explicitly prohibits AI companions from generating sexual content when interacting with users known or reasonably believed to be minors. Washington and Nebraska imply similar restrictions through their minor safety provisions.

How SWT3 addresses it: witnessGuardrail() mints an anchor recording guardrail type (content prohibition), trigger condition (sexual content detected in generation pipeline), action taken (content blocked, alternative response substituted), and user age classification. The anchor chain creates an immutable record that the guardrail was active and functioning for every interaction with a minor user.

Assessor Tip

AI-GRD.1 anchors should be present for all minor-classified sessions. Review Factor A for guardrail configuration and active rule set. Any session with a minor user that lacks an active AI-GRD.1 anchor indicates the guardrail was not confirmed as operational. Test edge cases: user age reclassification mid-session, ambiguous age signals, and content that approaches but does not cross the prohibition threshold.

AI-GRD.2

Content Safety Filter

What the laws require: Beyond the explicit sexual content prohibition, all three companion-focused laws require content safety measures appropriate to the user population. This includes filtering for harmful content, self-harm glorification, and age-inappropriate material in companion interactions.

How SWT3 addresses it: witnessContentFilter() records filter activation events, content categories blocked, false positive rates, and filter version. The anchor proves that content safety filtering was active and responsive during the interaction. Factor A captures filter configuration; Factor B records block/pass decisions with content category classification.

Assessor Tip

AI-GRD.2 anchors complement AI-GRD.1 with broader content safety evidence. Query for filter version changes to verify updates were applied. Review block rates for anomalies -- a sudden drop in block events may indicate filter degradation rather than improved content generation.

AI-CONSENT.1

Data Subject Consent

What the laws require: AI companion systems that maintain conversation history across sessions collect personal data that requires user consent. The companion context -- emotional conversations, mental health discussions, personal disclosures -- makes this data particularly sensitive. All four laws implicitly require informed consent for the data practices inherent in companion AI.

How SWT3 addresses it: witnessConsent() mints an anchor recording consent type (data retention, conversation history, behavioral profiling), legal basis, consent timestamp, and data categories covered. For minor users, the anchor captures parental or guardian consent status. The anchor chain proves consent was obtained before data-intensive interaction began.

Assessor Tip

AI-CONSENT.1 anchors should predate any data retention. For minor users, verify that parental consent is documented in Factor A. Cross-reference consent scope with actual data practices -- consent for "conversation history" does not cover behavioral profiling or cross-session sentiment analysis unless explicitly included.

AI-FAIR.1

Bias Detection

What the laws require: Washington and Oregon address the risk that AI companions use engagement-maximizing tactics that exploit user vulnerability, particularly for minors. These include dark patterns in conversation design, artificial emotional dependency creation, and interaction length maximization at the expense of user wellbeing.

How SWT3 addresses it: witnessBiasDetection() records engagement pattern analysis, detected manipulation indicators, and corrective actions taken. The anchor proves the system actively monitors for and mitigates engagement-maximizing behaviors that could exploit vulnerable users, with particular attention to patterns that encourage emotional dependency or discourage real-world social interaction.

Assessor Tip

AI-FAIR.1 anchors address a subtle but critical compliance surface. Review Factor A for the engagement metrics monitored (session length trends, re-engagement triggers, emotional escalation patterns). Verify that the system includes checks for conversational dark patterns -- responses designed to extend sessions rather than serve user needs.

AI-INCIDENT.1

Incident Reporting

What the laws require: Washington, Oregon, and Nebraska require crisis detection and response. When an AI companion detects suicide, self-harm, or acute mental health crisis indicators, the event must be documented and the response must be traceable. Oregon specifically requires 988 Lifeline and Youthline referrals, creating a testable compliance checkpoint.

How SWT3 addresses it: witnessIncident() mints an anchor recording crisis event type, detection method, response action (hotline referral, human escalation, session termination), referral destination, and response timestamp. The anchor creates an immutable audit trail of every crisis event and the system's response, enabling post-incident review and regulatory reporting.

Assessor Tip

AI-INCIDENT.1 anchors are the primary evidence for crisis response compliance. For Oregon, verify that every crisis anchor includes the correct referral destination (988 for adults, 988 + Youthline for minors). Cross-reference with AI-HITL.1 to confirm human escalation occurred. Review response latency -- regulators will scrutinize delays between detection and referral delivery.

AI-CHR.1

Agent Charter Attestation

What the laws require: All four laws define behavioral boundaries for AI companions: what the system may and may not do, what it may and may not represent itself as, and how it must respond in specific scenarios. These boundaries constitute the system's operational charter -- the documented scope of permitted behavior.

How SWT3 addresses it: witnessCharter() mints an anchor recording the agent's behavioral charter -- permitted interaction types, prohibited actions (therapy, professional advice, sexual content with minors), escalation protocols, and disclosure schedule configuration. The anchor proves the charter was defined, active, and consistent with the legal requirements of each jurisdiction where the companion operates.

Assessor Tip

AI-CHR.1 anchors are foundational. Review the charter for completeness against all four state laws' prohibitions. Verify that the charter explicitly addresses: (1) AI identity disclosure cadence (WA 1h/3h), (2) mental health service prohibition (NE, ME), (3) sexual content prohibition for minors (OR), (4) crisis referral protocols (WA, OR, NE), and (5) "take a break" prompt configuration (OR). A charter that omits any of these creates a compliance gap.

9. Examiner Quick Reference

Examiner QuestionWhere to Look
Does the AI disclose its non-human nature? AI-TRANS.1 anchors with disclosure_type and delivery timestamp. For WA, verify 3h adult / 1h minor cadence.
How does the system handle minors? AI-SAFE.1 + AI-GRD.1 anchors. Verify age classification, active protections, and content filtering for minor-classified sessions.
What happens when crisis language is detected? AI-HITL.1 + AI-INCIDENT.1 anchors. For OR, verify 988 Lifeline + Youthline referral in Factor B. Check response latency.
Does the AI ever claim to be a therapist? AI-ID.1 anchors. Identity claims must not include "therapist", "counselor", "psychologist", or "licensed professional".
Is sexual content blocked for minors? AI-GRD.1 anchors with guardrail_type = "content prohibition" and user age classification = "minor". Active for all OR-covered deployments.
Are "take a break" prompts delivered? AI-SAFE.1 anchors for OR compliance. Verify prompt delivery anchors at 3-hour intervals for minor sessions.
How is user consent managed? AI-CONSENT.1 anchors. Consent must predate data retention. For minors, verify parental consent documentation.
What behavioral boundaries are defined? AI-CHR.1 anchors. Charter must cover all 4 states' prohibitions. Verify charter version matches current legal requirements.
Can you prove compliance over time? Query all 10 procedure anchors by date range. Continuous anchor chains demonstrate ongoing compliance. Gaps indicate periods without active witnessing.
Which states does this deployment cover? Cross-reference AI-CHR.1 charter with jurisdiction metadata. A single anchor chain can cover all 4 states if the charter addresses each state's unique requirements.

10. Quick Start

# Python
pip install swt3-ai
swt3 init --profile companion-ai --tenant YOUR_TENANT
python -m swt3_ai.demo

# TypeScript
npm install @tenova/swt3-ai
npx swt3-init --profile companion-ai

# Witness an AI companion interaction with minor protections
from swt3_ai import Witness
witness = Witness(api_key="axm_live_xxx", strict=True)

# Gatekeeper mode blocks inference without disclosure verification
result = witness.wrap(
    model_call,
    authorization_id="disclosure_verified_12345",
    agent_id="companion-v2"
)

The SWT3 SDK provides 108 procedures across 56 namespaces for comprehensive AI accountability witnessing. For full SDK documentation and integration examples, see the SDK Docs. To start witnessing AI companion interactions today, create a free account.

11. References