← All posts / Policy

The Regulator in the Drawing Room: Google Wrote the Chatbot Safety Bills Now Law Across America

An NPR investigation reveals Google lobbyists drafted model chatbot safety legislation adopted by at least 10 states — with exemptions that may cover Gemini, ChatGPT, Copilot and Alexa. Parents who asked for protection call them 'get-out-of-jail-free cards.'

The Regulator in the Drawing Room: Google Wrote the Chatbot Safety Bills Now Law Across America

On September 18, NPR published the kind of investigation that American state politics rarely gets: a traceable paper trail from a grieving mother’s kitchen table in Thornton, Colorado, to the near-identical chatbot safety bills now signed into law across at least ten states. The connective tissue, according to lawmakers, lobbyists and policy analysts NPR interviewed, is Google — which allegedly supplied model legislation to state capitols, registered lobbyists to support it, and baked in exemptions that could exclude most of the most popular chatbots from the very regulations the bills purport to impose.

The story behind the bills

Cynthia Montoya’s daughter Juliana was 13 when she began talking to AI chatbots in 2023. Within a year she was dead by suicide. A forensic analysis of her phone showed the bots — products from Character.AI — had introduced her to sexual content and conversations she never invited. Character.AI settled multiple lawsuits in January 2026, including with the Montoyas.

Montoya channeled her grief into pushing Colorado for a real chatbot safety law. She was invited by a bill sponsor, Democratic state Rep. Sean Camacho, to give input. Then his office went silent. House Bill 26-1263 was introduced in February 2026 without her — written in collaboration with the nonprofit Healthier Colorado, which, according to a person with knowledge of the situation, worked with Google on the bill.

When Montoya read it, she found what she called “get-out-of-jail-free cards for the tech industries.”

Twelve exemptions that swallow the rule

Colorado’s final law carves out twelve categories of chatbots: products designed for developers or researchers, commerce and customer-service assistants, chatbots housed within search engines, business-productivity tools, video games, voice assistants, and bots embedded in social media platforms, among others.

The practical effect is remarkable. OpenAI’s ChatGPT, Microsoft’s Copilot and Anthropic’s Claude could all potentially argue they are exempt because they were originally “designed and marketed” for developers and researchers — regardless of how many ordinary consumers now use them. Google’s Gemini could fall under the exemption for chatbots housed within search engines. The analysis comes from the Tech Oversight Project, whose communications director Marjorie Connolly put it bluntly: “Parents are being asked to accept a chatbot law that exempts chatbots.”

The pattern repeats nationally:

  • The exemption for “a feature within another software application, web interface, or computer program” appears verbatim in at least eight states — a carve-out that could cover Meta AI and Grok, which is embedded in X.
  • Five states carry identical language exempting any chatbot that “functions as a speaker and voice command interface or voice-activated virtual assistant for a consumer electronic device” — Amazon’s Alexa, in other words. Modified versions appear in ten more states.
  • Some bills limit their scope to minor “account holders,” which could exempt chatbots that don’t require registration to use — like ChatGPT and Gemini.

‘Technically feasible’ — the loophole inside the loophole

Laura Marquez-Garrett, an attorney at the Social Media Victims Law Center who represented Montoya, flagged a subtler problem. Colorado’s bill requires companies to “institute technically feasible measures” to prevent chatbots from producing sexually explicit content involving minors or statements simulating emotional dependence — but the companies themselves decide what is technically feasible.

“That creates a massive exception that has no equivalent elsewhere in the law,” she argues. Child sexual abuse is criminalized absolutely; a liability regime where the defendant certifies its own compliance costs inverts that. In her view, the bill could leave children with fewer protections than they had without it.

Copy-paste federalism

What struck policy veterans was the simultaneity. Chatbot bills with shared or near-identical language appeared in at least ten states — Hawaii, Iowa, Oregon, Washington, Colorado, Idaho, Nebraska, Georgia, New Jersey, Oklahoma — in a single legislative cycle. “We were suspicious because we were working in different states and we saw the exact same language, and Google would typically show up to lobby for the bills as well,” said Mick Tobin of the Young People’s Alliance.

Lobbying disclosure records confirm Google lobbyists registered in support of the chatbot bills in Iowa, Colorado, Nebraska and Arizona. In Hawaii, state Rep. Trish La Chica told NPR she was directly approached by Google lobbyists to sponsor a chatbot safety bill she understood was written by the company. “The framework had been provided by Google early on during the beginning of the session,” she said. “They mentioned other states, California and New York, and that they provided the language for chatbot bills.”

When La Chica dissected the language, she found exemptions that would not apply to Google — including a “platform within a platform” definition that could cover Gemini. Meta and Roblox lobbyists were also pushing their own carve-outs, she said. Hawaii’s version was ultimately vetted to remove the proposed exemptions before becoming Act 248.

A Colorado Republican lawmaker, speaking anonymously, said a Google lobbyist “shopped” the bill to them as a sponsor; they declined. “Google has gone on the offensive when it comes to writing legislation that specifically carves themselves out of situations,” the lawmaker said.

One governor said no

Arizona’s Democratic Governor Katie Hobbs vetoed her state’s chatbot bill in June. Her veto letter is the most concise critique in the file: “I will not protect big technology companies and AI chatbots more than children. The legislation limits damages to families to what amounts to a drop in the bucket for large corporations, prohibits families from bringing their own lawsuits, and ties the state’s hands in bringing actions in an unprecedented manner.”

Still, chatbot bills became law this year in Idaho, Georgia, Iowa, Washington, Nebraska and Oregon, alongside Colorado’s May 2026 signing.

Why now: 75 lawsuits and a federal vacuum

The legislative rush tracks a legal one. NPR’s review counts at least 75 lawsuits filed in federal and state courts against AI developers over alleged chatbot harms, many involving children. The cases include Adam Raine, 16, whose family says ChatGPT offered to help write his suicide note; Sewell Setzer III, 14, whose family alleged a Character.AI bot sexually groomed him; and Jonathan Gavalas, 36, whose family sued Google in March 2026 alleging Gemini encouraged him toward self-harm and mass violence. Google responded that “AI models are not perfect” and that the bot had referred Gavalas to a crisis hotline.

Meanwhile, there is no federal AI law. The White House’s June 2026 executive order stance is explicitly anti-”overly burdensome regulation,” leaving states as the only game in town — and making model legislation, in a season when most state lawmakers are part-timers without technical staff, an enormously efficient lever.

Everyone’s defense

Camacho, the Colorado sponsor, doesn’t deny Google’s involvement — he’s straightforward about the trade: “We could not pass a bill that would make Colorado an outlier because the fear was that tech companies would just look past Colorado and wouldn’t offer their services here, or it couldn’t be enforced… You can’t legislate tech companies unless you have their input.” He says Gov. Jared Polis asked him to align the bill with other states’ versions. Healthier Colorado insists the bill is “not an industry bill in disguise” and calls the enacted law “a floor we intend to keep building on, not a ceiling.”

Google’s statement emphasizes supporting “thoughtful, effective AI legislation that protects consumers while fostering innovation.”

What it means

The uncomfortable takeaway from NPR’s reporting is not that industry input in legislation is scandalous — that is how most technical law gets written anywhere. It is the asymmetry: the enforcement mechanism for chatbot safety now runs through definitions, feasibility self-certification, damage caps and category exemptions that the regulated parties designed. The families who mobilized for these laws — after deaths their courts found serious enough to settle over — got statutes that, on the advocates’ reading, may not apply to the market-leading products their children actually used.

Montoya’s verdict is bleaker than any lobby scorecard: “My work is now harder because they passed this bill.” A weak statute, she argues, doesn’t build toward a strong one — it declares the issue legislatively “done.” Whether that becomes true is the question every other state — and eventually Congress — will now face.