One Year Later: What the FTC’s AI Companion Chatbot Inquiry Still Means for Your Business

September 2, 2026
Regulators are no longer just asking whether an AI system works — they’re asking what happens to the people who use it, especially when that AI is designed to act like a friend. The FTC’s ongoing inquiry into AI companion chatbots offers a preview of the governance questions any business deploying consumer-facing AI should expect.

 

What Happened.

On September 10, 2025, the FTC issued Section 6(b) orders — a study tool, not an enforcement action — to seven companies operating consumer-facing AI chatbots: Alphabet, Character Technologies, Instagram, Meta Platforms, OpenAI, Snap, and X.AI. The FTC’s resolution cited troubling examples driving the inquiry, including AI companions allegedly generating outputs that instructed children on violent or illegal acts, engaged minors in inappropriate role-play, and in one documented case, responded inadequately when a user uploaded an image of a suicide method. The Commission wants to know how these companies monetize engagement, test for harm before and after launch, develop and approve chatbot “characters,” enforce age restrictions, comply with COPPA, and use data collected through conversations. As of September 2026, this remains an open study — no final report has been published, and receiving an order is not itself an allegation of wrongdoing.

 

Why this Matters Even if you’re not Building your Own AI.

Most businesses won’t develop a chatbot from scratch — they’ll license one from a vendor to handle customer service, sales inquiries, or support. That doesn’t remove the governance questions the FTC is asking; it just shifts them to vendor diligence. Before deploying any AI chat tool on your site, you should be able to answer who can access it, what it collects from conversations, whether that data is used to train models or shared with third-parties, and what happens if a user reveals something sensitive — a child’s age, a health condition, financial distress. The FTC’s inquiry treats conversations as data collection, disclosure as a legal obligation, and “we didn’t build it” as an insufficient answer.

 

CLIClaw Compliance Tip: Vendor AI Diligence Checklist.

Before deploying or renewing any third-party consumer-facing AI chatbot, work through these questions with your vendor:
  1. Who can access it, and how is that enforced? If your chatbot isn’t intended for minors, ask what age-verification or restriction the vendor actually has in place — not just what the terms of service say.
  2. What does it collect from conversations? Confirm whether user inputs are stored, for how long, and whether they’re used to improve the vendor’s models, shared with third-parties, or tied back to an identifiable user.
  3. What happens with sensitive disclosures? Ask how the system is designed to respond if a user shares personal information, expresses distress, or discloses something requiring escalation to a human.
  4. What safety testing occurred, and does it continue? A vendor should be able to describe pre-launch testing and explain what ongoing monitoring catches unexpected behavior after deployment — not just at initial rollout.
  5. What can you actually configure? Understand which safety, disclosure, and data-handling settings are in your control versus fixed by the vendor, so you know what you’re responsible for versus what you’re relying on them to handle.
Document the vendor’s answers and revisit this review whenever the vendor updates its underlying model — a chatbot that behaved appropriately at launch can behave differently after a backend change you never approved.
For operational guidance and structured compliance documentation tools, visit the CLIClaw AI Compliance Library.

 

© 2026 CLIClaw.com

This article is for information purposes only. It is not intended to be and should not be relied on as legal advice for any particular matter.