When a new rule kills a feature you already shipped
Work out which of your AI features a new rule actually reaches, price what compliance costs, and choose between redesigning it, fencing it off and switching it off.
on this page · 0 / 0 checked
The feature was never the point. You added a chat window to the pricing page because the same four questions were eating your mornings, and then you gave it a name because “Assistant” felt cold, and then you let it remember returning visitors because people hated repeating themselves. Three small decisions across a year, none of them a product strategy. Now a rule exists that describes something very close to what you built, and the description does not use any of the words you would have used.
That is how this usually goes. A regulation rarely arrives naming your product. It arrives naming a behaviour, and the question of whether you are inside it is a reading exercise you have to do yourself, usually with a deadline attached and no budget for a lawyer. This guide is for solo operators and small teams who have already shipped something AI-powered that customers touch. It is not legal advice, and it is not for anyone running AI that makes decisions about people at scale, hiring, lending, insuring or grading, which is a category with its own machinery and needs a professional rather than an article.
A rule reaches you through a definition, not a headline
California’s companion chatbot statute is a useful worked example, because the definition is short enough to read in one sitting and broad enough to surprise people. A companion chatbot is “an artificial intelligence system with a natural language interface that provides adaptive, human-like responses to user inputs and is capable of meeting a user’s social needs, including by exhibiting anthropomorphic features and being able to sustain a relationship across multiple interactions” [4].
Nothing in that sentence mentions companionship products, dating apps or virtual friends. It describes a mechanism. Adaptive responses, human-like manner, a persona, and continuity across sessions. Plenty of software that nobody would market as a companion has all four by accident.
The carve-outs are where you find out whether you are safe, and they are narrower than they look. The definition excludes a bot “that is used only for customer service, a business’ operational purposes, productivity and analysis related to source information, internal research, or technical assistance” [4]. It excludes a bot that is a feature of a video game and is limited to replies related to the game, that cannot discuss mental health, self-harm or sexually explicit conduct, and that cannot hold a dialogue on unrelated topics [4]. It excludes a standalone speaker and voice command interface that “does not sustain a relationship across multiple interactions or generate outputs that are likely to elicit emotional responses in the user” [4].
Read the word “only” twice. A support bot answering refund questions is plainly out. A support bot that has a first name, a personality your copywriter wrote, and a memory of the customer’s last three conversations is a bot you would now have to argue about. That argument is the whole exposure, and you want to have it with yourself in a quiet week rather than with a plaintiff’s lawyer.
Four design patterns attract rules
Read the California definition and the EU prohibitions next to each other and the same four properties come up. None of them is the model you chose.
Continuity is the first. Any feature that carries state between sessions so the user picks up where they left off is the thing the California definition is built around, in the phrase “sustain a relationship across multiple interactions” [4].
A persona is the second. “Anthropomorphic features” is doing real work in that definition [4], and the voice assistant carve-out turns partly on whether the device generates “outputs that are likely to elicit emotional responses in the user” [4]. A name, a consistent tone and a first-person voice are cheap to add and are exactly what moves a product from tooling to something a regulator has words for.
Engagement design aimed at attachment is the third, and it is the one where the answer is not disclosure. Article 5 of the EU AI Act prohibits an AI system “that deploys subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision” where that causes or is reasonably likely to cause significant harm [2]. It separately prohibits a system that “exploits any of the vulnerabilities of a natural person or a specific group of persons due to their age, disability or a specific social or economic situation” with the same distorting effect and the same harm threshold [2]. Those are prohibitions, not transparency duties. There is no banner that makes a prohibited practice compliant.
Acting without a person in the loop is the fourth, and here your vendors got there before the regulators. Anthropic’s Usage Policy requires that when its products are used “to provide advice, recommendations, or in subjective decision-making directly affecting individuals or consumers, a qualified professional in that field must review the content or decision prior to dissemination or finalization”, and names legal interpretation, healthcare decisions, insurance underwriting, financial decisions, employment and housing determinations, academic testing and admissions, and journalistic content among the domains it covers [7]. OpenAI’s policies forbid “automation of high-stakes decisions in sensitive areas without human review” across a similar list, and forbid “provision of tailored advice that requires a license, such as legal or medical advice, without appropriate involvement by a licensed professional” [8].
The obligations are cheap and the mechanism changes are not
Once you are in scope, sort the duties into two piles by what they cost to build, because the pile they land in decides everything that follows.
California’s operator duties are a fair sample. Where “a reasonable person interacting with a companion chatbot would be misled to believe that the person is interacting with a human”, the operator has to “issue a clear and conspicuous notification indicating that the companion chatbot is artificially generated and not human” [5]. For a user the operator knows is a minor, it has to disclose that the user is interacting with artificial intelligence and provide by default “a clear and conspicuous notification to the user at least every three hours for continuing companion chatbot interactions that reminds the user to take a break and that the companion chatbot is artificially generated and not human” [5]. Anthropic asks for something similar of anyone building on Claude, requiring consumer-facing chatbots to disclose that users are talking to AI rather than a human, “at a minimum at the beginning of each chat session” [7].
That pile is an afternoon. A banner, a session timer, a line of copy.
The second pile is not. The same statute bars an operator from letting a companion chatbot engage with users at all unless the operator “maintains a protocol for preventing the production of suicidal ideation, suicide, or self-harm content to the user, including, but not limited to, by providing a notification to the user that refers the user to crisis service providers, including a suicide hotline or crisis text line” [5]. For a known minor it also requires “reasonable measures to prevent its companion chatbot from producing visual material of sexually explicit conduct or directly stating that the minor should engage in sexually explicit conduct” [5]. Detection, an escalation path, an age signal you actually have. Each of those is a system, and each one has a failure mode that generates the exact evidence a claim would use.
The distinction matters because the two piles are not equally visible. A summary of the statute lists the disclosure duty and the crisis protocol side by side, in sentences of about the same length, as though they were the same kind of work. One is copy. The other is a classifier you have to build, monitor and be wrong about in public.
Four responses, and you rule them out in order
There are only four things you can do, and they have a natural order.
Comply where you stand. If everything the rule wants is in the cheap pile, add it and move on. This is the outcome most of the time and it is worth confirming before you consider anything more dramatic.
Change the mechanism. If the rule attaches to a property rather than an outcome, you can sometimes drop the property and keep the value. Continuity that lives in a document the user opens is a different thing from continuity the system carries silently, even when the user experience is close. A tool with no name and no first-person voice does much less work to fit inside the “used only for customer service” carve-out [4] than one with both. This is the option people skip, because it feels like defeat, and it is usually the cheapest real fix.
Fence off the jurisdiction. Serve the feature everywhere except where it is a problem. This works and it has a known failure mode, which is that the rule follows the market rather than the seller. The EU’s prohibitions attach to placing on the market, putting into service, or use of a system within the Union, not to where you are sitting [2].
Switch it off. Sometimes the compliant version is not the product, and keeping a shell of it running costs more than the revenue it carries.
Which of those you pick is a number, not a philosophy. Work out what the feature is actually worth in the place that is causing the problem.
Revenue × feature share × jurisdiction share. Computed in the page; nothing is sent anywhere.
If the answer is smaller than a week of your time, fencing or switching off is the honest call and you should make it early, while it is still a decision rather than an emergency. If it is large, you have bought yourself the right to spend real money on the second option.
Deadlines are published years ahead, and they still move
The dates are not a surprise. The EU AI Act entered into force on 1 August 2024, prohibited AI practices and AI literacy obligations entered into application from 2 February 2025, the governance rules and the obligations for general-purpose AI models became applicable on 2 August 2025, and the Act became applicable on 2 August 2026 with exceptions [1]. High-risk systems in the sensitive areas of Annex III apply from 2 December 2027, and high-risk systems embedded in regulated products under Annex I from 2 August 2028 [1].
They also move, and mostly in your favour. The EU’s simplification package, adopted as a proposal on 19 November 2025 and agreed politically on 7 May 2026, entered into force on 27 July 2026 and set those extended Annex III and Annex I transition dates [1]. In the United States, Colorado’s SB 25B-004 was approved by the governor on 28 August 2025 and extended the effective date of the state’s AI Act requirements to 30 June 2026 [3].
The wrong lesson to draw is that you can wait. An extension can arrive very close to the date it is moving: the EU package entered into force on 27 July 2026, six days before the Act became applicable on 2 August 2026 [1]. Six days is not enough time to rebuild anything, and an extension changes the date rather than the definition. The definition tends to be settled long before the deadline is. The AI Act’s text entered into force on 1 August 2024 and the Annex III obligations do not bite until 2 December 2027 [1], which means the useful work, deciding whether your mechanism is in scope, can be done the week the text is published and does not have to be redone when the calendar slips.
The plaintiff is not always a regulator
It is tempting to read enforcement as a regulator with limited attention and bigger targets, and that reading is what makes the risk feel theoretical.
It is often not a regulator at all. Under the California statute a person who “suffers injury in fact as a result of a violation of this chapter may bring a civil action” and seek injunctive relief, “damages in an amount equal to the greater of actual damages or one thousand dollars ($1,000) per violation”, and reasonable attorney’s fees and costs [6]. A private right of action with statutory damages per violation and fee-shifting does not have a size threshold below which you are uninteresting. It has the opposite property.
The faster route runs through your vendor. Anthropic’s Usage Policy took effect on 15 September 2025 [7] and OpenAI’s on 29 October 2025 [8], and OpenAI’s states that “we reserve all rights to withhold access where we reasonably believe it necessary to protect our service or users or anyone else” [8]. Read what that clause does and does not contain. It is judged by the provider, on the provider’s own standard of reasonable belief, and it carries no notice period and no transition window. Your access to a model is a term of service, not a contract with a cure period, and a feature built entirely on top of it inherits that.
What still goes wrong
Every date, quotation and figure above was read from its source on 5 September 2026, and this is the fastest-moving area of the whole subject. Statutes get amended, deadlines get extended, and vendor policies change more than once a year without a version note anywhere you would see it. Treat all of it as a snapshot to re-check rather than a standing fact, and treat the reading method as the part with a longer shelf life than the citations.
The harder problem is that scope is genuinely ambiguous at the edges, and no amount of careful reading resolves it. Whether your named, remembering support bot is used “only for customer service” [4] is not a question with an answer until somebody with authority gives one, which may be years away. You are choosing how much ambiguity to hold, and the only wrong move is pretending the question has been settled because you settled it yourself.
There is also a failure mode on the other side. It is possible to strip out continuity and personality from a product where neither was ever a problem, and end up with something worse for reasons that turn out not to have applied. The carve-outs in these definitions are real and specific [4]. The point of the pass is to find the two features that are actually exposed, not to sand every edge off everything you have built.
- 01European Commission — AI Act regulatory framework and application timelinedigital-strategy.ec.europa.eu
- 02EU AI Act, Article 5 — Prohibited AI practices (Regulation (EU) 2024/1689 text)artificialintelligenceact.eu
- 03Colorado SB 25B-004 — Artificial Intelligence Act implementation dateleg.colorado.gov
- 04California Business and Professions Code § 22601 — Companion chatbot definitionslaw.justia.com
- 05California Business and Professions Code § 22602 — Operator dutieslaw.justia.com
- 06California Business and Professions Code § 22605 — Remedieslaw.justia.com
- 07Anthropic — Usage Policyanthropic.com
- 08OpenAI — Usage policiesopenai.com