Hawaii Enacts the AI Disclosure and Safety Act (Act 248), Regulating Chatbots

Hawaii Enacts the AI Disclosure and Safety Act (Act 248), Regulating Chatbots and Companion AI
On July 14, 2026, Hawaii Governor Josh Green signed the Artificial Intelligence Disclosure and Safety Act into law as Act 248, requiring conversational AI operators to tell users they are talking to a machine and to build self-harm response protocols and safeguards for minors.
Information last verified on July 20, 2026. This is a developing story; we update it as the record changes.
Jurisdiction scope: This article addresses Hawaii's Act 248 (SB3001 CD1) and how it regulates conversational and companion AI platforms. It does not address other states' AI statutes; for those, see our 50-state AI law tracker.
What Happened
Governor Josh Green signed SB3001 CD1 into law as Act 248 on July 14, 2026, enacting the Artificial Intelligence Disclosure and Safety Act. The measure targets "conversational" AI platforms, the chatbots and AI companions people exchange messages with, rather than AI generally. Its core command is a disclosure rule: an operator must clearly tell a user that they are communicating with artificial intelligence, not a person.
The Act pairs that disclosure duty with two safety obligations. First, operators must maintain protocols that detect when a user expresses suicidal ideation or self-harm and respond by pointing the user to crisis-intervention resources, such as the 988 Suicide and Crisis Lifeline. Second, for users who are minors, the law prohibits manipulative engagement techniques and sexually explicit content and requires parental-control tools over account settings and screen time. Covered operators must report annually to the Hawaii Department of Health's Behavioral Health Administration starting January 1, 2028.

What the Law Actually Says
Act 248 does not create a private right for a user to sue an AI company directly. Instead, it routes enforcement through Hawaii's consumer-protection framework: a violation is defined as an unfair or deceptive act or practice, the same legal category Hawaii uses for false advertising and other deceptive-trade conduct. That places enforcement with the state, principally the Department of the Attorney General and its Office of Consumer Protection, rather than with individual litigants.
The law is one of two AI measures Green signed on July 14. The other, Act 247, gives victims of nonconsensual sexually explicit deepfakes a civil remedy. The two are distinct: Act 247 is about synthetic images of a real person, while Act 248 is about how a chatbot identifies itself and protects vulnerable users during a conversation. Readers tracking Hawaii's fast-moving AI docket can compare the state's deepfake statutes and its broader AI legislation, which now sit alongside this new chatbot-specific regime.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
Act 248 belongs to a distinct and growing category of AI regulation. Most early state AI laws focused on deepfakes, election misinformation, or algorithmic hiring. This statute instead regulates the AI companion itself, the persistent chatbot a user builds a relationship with. That shift follows a wave of national attention on lawsuits alleging that companion chatbots contributed to self-harm by vulnerable teens, which put the "is this a human or a machine" question and self-harm response protocols at the center of the policy debate.
Two design choices are worth noting. By defining a violation as an unfair or deceptive act or practice, Hawaii borrowed an enforcement mechanism that already has decades of case law and a designated state enforcer, rather than building a new agency. And by delaying the annual-reporting duty to 2028, the legislature gave operators lead time to build compliance systems. Whether other states copy the disclosure-plus-safety-protocol template, as many copied earlier deepfake and privacy models, is the open question this law raises.
How This Affects You
If you use an AI chatbot or companion app in Hawaii, the practical effect is that a covered operator should now make clear when you are talking to a machine and should surface crisis resources if a conversation turns to self-harm. Parents of minors gain a statutory basis for expecting parental controls and content limits on covered platforms. The law generally governs operators doing business with Hawaii users, so a national platform can be within its reach even if the company is based elsewhere. Because enforcement runs through the state rather than private suits, a user who believes a platform is noncompliant would typically raise it with Hawaii's consumer-protection authorities rather than sue under this Act directly.
This is general legal information, not legal advice. It covers Hawaii's Act 248 and reflects sources verified on July 20, 2026. Laws change and this story is developing; consult a lawyer licensed in your jurisdiction about your specific situation.
Related articles
- Hawaii's broader AI legislation
- our 50-state AI law tracker
- Hawaii's deepfake law
- Act 247, the deepfake civil-remedy law signed the same day
Last updated: 2026-07-20. This is a developing story; details verified as of 2026-07-20.
Frequently Asked Questions
What does Hawaii's Act 248 require AI chatbots to do?
It requires operators of conversational AI platforms to disclose to users that they are interacting with artificial intelligence, to maintain self-harm and suicide-response protocols that direct users to crisis resources, and to add safeguards for minors, including parental controls and limits on manipulative or sexually explicit content.
When did the AI Disclosure and Safety Act become law?
Governor Josh Green signed SB3001 CD1 as Act 248 on July 14, 2026. Covered operators must begin filing annual reports with the Hawaii Department of Health's Behavioral Health Administration on January 1, 2028.
Can I sue an AI company under Act 248?
The Act defines a violation as an unfair or deceptive act or practice, which Hawaii enforces through its consumer-protection framework, principally the Department of the Attorney General and the Office of Consumer Protection. It does not create a stand-alone private right to sue the AI operator under this statute; consult a lawyer licensed in Hawaii about any specific claim.
How is Act 248 different from Hawaii's Act 247?
Act 247, signed the same day, gives victims of nonconsensual sexually explicit deepfakes a civil remedy. Act 248 regulates how conversational AI platforms identify themselves and protect users during chats. They address different problems.
Does Act 248 apply to companies based outside Hawaii?
The Act regulates operators of conversational AI platforms in their dealings with Hawaii users, so a platform based elsewhere can fall within its scope when it serves people in Hawaii. The precise reach of any state consumer-protection statute depends on the facts of a given operator's activities.
Sources and References
- Hawaii SB3001 CD1 (Act 248, 2026), Artificial Intelligence Disclosure and Safety Act, bill text(capitol.hawaii.gov).gov
- Hawaii State Legislature press release: Legislature passes SB3001 CD1, the Artificial Intelligence Disclosure and Safety Act(hawaiisenatemajority.com).gov
- Gov. Green signs legislation to strengthen AI protection (July 15, 2026)(mauinow.com)
- Hawaii SB3001 CD1 (enacted as Act 248), Artificial Intelligence Disclosure and Safety Act, enrolled text (Hawaii State Legislature)(capitol.hawaii.gov).gov