There's a sentence in California law that should make every AI product team pause, and almost none of them have read it.
Since January, California's SB 243 — the first companion chatbot law in the country — has regulated any AI with a natural-language interface that is "capable of meeting a user's social needs" and sustaining a relationship across interactions. It requires disclosures, break reminders for minors, crisis protocols, annual reporting. And it carries a private right of action: $1,000 minimum per violation, plus attorneys' fees, enforceable by individual users.
"But we're not a companion app," says every product team reading this. "We're a shopping assistant. A support bot. A productivity tool."
Here's the part almost nobody has read closely. The law does exempt bots "used only for customer service, a business's operational purposes, productivity, internal research, or technical assistance."
Used. Only. For.
That exemption is not a category. It's a behavior. And behaviors change with every product update.
Legal analysts have already spelled out what pulls a bot back into scope: recalling prior conversations. Remembering user preferences. Tailoring recommendations to a specific person. Adapting tone to the user. Checking in. Building anything that feels like a relationship.
Now look at your roadmap. Memory across sessions is on it. Personalization is on it. A warmer, more human tone is on it — your metrics team asked for it, because it lifts retention. A re-engagement notification is probably on it too.
Every one of those features is good product practice by the industry's defaults. And every one of them is a step out of the exemption and into a statute with a private right of action.
This is what I call the migration problem, and it's the blind spot in how we all think about AI products. We classify them by function — support bot, shopping assistant, tutor. But the law, and more importantly the user, experiences them by relationship. A support bot that remembers you, contacts you first, and asks how you've been is not functionally different from a companion. It is one — one that never decided to be, never designed for it, and never built the safeguards that deliberate companion products are now legally required to have.
I think about this in terms of behavioral permissions — the set of capabilities an AI product holds that shape the relationship, regardless of what the product calls itself: memory across sessions; the ability to initiate contact; re-engagement mechanics like streaks and reminders; elicitation of emotional disclosure; persuasion; a persistent persona users can bond with.
Here's what makes permissions useful where categories fail: you can't audit "are we a companion?" — that's vibes and marketing. But every permission is a design artifact. Memory is a fact of your data architecture. Initiation is a fact of your notification code. Streaks are visible in your interface. Each one can be inventoried, dated, and checked — including against the specific behaviors regulators have flagged.
Most teams have never done that inventory. When they do, there's almost always a surprise — a permission the product holds that nobody remembers deciding to take. It got added feature by reasonable feature, each one lifting a metric, none of them examined as what they collectively are: a relationship being assembled without a designer.
The teams that will handle this era well aren't the ones that lawyer up after a demand letter. They're the ones that can answer two questions before a regulator, a journalist, or a plaintiff's attorney asks: What relationship is our product inviting? And what have we licensed it to take?
If you can't answer those today, that's not a character flaw — it's the industry default. But it's now a default with a statute attached.