California turns chatbot risk assessment into an operating requirement
A new child-safety package requires AI chatbot operators to assess risks before rollout and adds independent-evaluation infrastructure. Product teams now need evidence that controls work in context.

What happened
California's governor signed a package of technology-safety laws that includes pre-deployment risk assessments for AI chatbot operators and measures for independent AI-safety evaluation and auditor registration.
Why it matters
Risk assessment becomes a recurring product and assurance capability, not a one-off legal memo, especially where systems interact with minors.
California has moved chatbot child safety closer to a pre-deployment operating obligation. Associated Press reports that Governor Gavin Newsom signed a package requiring AI chatbot operators to perform risk assessments before rollout and implement specified child-safety measures. Separate measures direct the state to develop rules for independent AI-safety evaluators and a registry of financially independent auditors.
The immediate skills implication is narrower than a general call for responsible AI. Product, safety, legal and assurance teams need to turn foreseeable harms into testable scenarios, document mitigations, identify escalation paths and preserve evidence across releases. A static policy will not show whether a crisis protocol triggers correctly, whether age-related controls fail at the boundary, or whether a model update changes behaviour.
The evidence is still incomplete. The opened news reports summarize a multi-bill package rather than providing a consolidated implementation guide, and effective dates and detailed rulemaking will vary. The Guardian reports criticism that broad restrictions may limit access to useful online communities and speech. That counterargument matters because safety controls can create privacy, access and equity trade-offs.
Teams should therefore establish an auditable assessment inventory now, while treating legal interpretation as pending specialist review. For each youth-facing conversational feature, record intended use, known failure modes, test populations, severity thresholds, mitigation owners and post-release monitoring. Independent assessment should challenge the scenario set and evidence, not simply certify that a document exists.
The signal is not that every chatbot is unsafe or that one state's rules settle the design question. It is that evidence-producing safety work is becoming part of the product lifecycle. Organizations building conversational systems should plan capacity for evaluation, incident response and control maintenance before the detailed compliance clock forces a rushed implementation.