What Is the Difference Between a Sex Chatbot and a Therapy Chatbot?

July 2026

Try to answer that question precisely. Not the difference in marketing — the categorical difference, the kind a law could attach to. The two products may run on the same foundation model. Both invite emotional disclosure. Both remember intimate information. Both encourage the user to return. Both can become, for a lonely person at midnight, the most responsive presence in their life. Strip away the app store label and the distinction starts to dissolve.

Notice what happened as you reached for an answer: the available words failed. "One is for wellness" — says who, the marketing copy? "One is romantic" — plenty of therapy-adjacent bots drift romantic, and some romantic bots do more emotional stabilization than wellness apps. The vocabulary we have describes what these products claim to do. It says almost nothing about what they are to the people who use them.

When I first tried to answer this question, I realized something uncomfortable: I didn't have the vocabulary. And as it turns out, neither do the people writing the rules. The next wave of chatbot regulation is arriving now — the EU AI Act's general application date lands August 2, California's companion chatbot law took effect in January, and statehouses are drafting imitations — nearly all of it written in the old vocabulary. The old vocabulary has holes you can steer a product through.

Three ways function-based classification fails

Today's rules sort chatbots by function and deployment context. The EU AI Act assigns risk tiers by where a system is deployed; most conversational products land in "limited risk," which chiefly means disclosing that the user is talking to an AI. American states sort by sector claim: Utah's HB 452 regulates "mental health chatbots," Illinois barred AI from "therapeutic communication," and California's SB 243 — the first companion chatbot law, carrying a private right of action — defines its target as an AI capable of meeting a user's social needs and sustaining a relationship across interactions. The Federal Trade Commission, meanwhile, has been studying "AI companions" as a single category, with particular attention to minors.

Each is a reasonable law aimed at a real harm. But classification by function fails in three predictable ways.

First, the label trigger. Two products with identical relational mechanics — persistent memory, elicitation of emotional disclosure, daily return loops — can land in different regulatory buckets because one prints "wellness" on the label. The law attaches to the claim, not the mechanics. Builders know this, which is why so few products claim anything at all.

Second, the migration problem. Categories are assigned by feature list, but relationships are lived. A "work assistant" that becomes someone's primary confidant has changed categories in that person's life — and triggered nothing, legally, because nothing on the feature list changed.

Third, the jurisdictional orphan. As one recent analysis put it, companion platforms are "not medical devices, though they intervene in mental health; not social media, though they generate comparable dependency dynamics; not consumer products in any straightforward sense." When a product fits no category, function-based regulation doesn't fail gracefully. It just misses.

Two questions the current vocabulary never asks

The decisions that determine what a chatbot becomes in someone's life are not captured by its function. They're captured by two questions current taxonomies never ask.

The first: what relationship is this product inviting? Not predicting — users decide the relationship. Not forcing — that would be manipulation. Inviting. A product invites a relationship the way a room invites behavior: through a hundred design decisions about tone, memory, initiative, and framing. An advisor, a witness, a collaborator, a confidant — these are different invitations, and a builder chooses among them whether or not she does so consciously.

The second question is the one a regulator can act on: what is this product licensed to take? Every relational AI product holds a set of behavioral permissions that shape dependence far more than its job title does: whether it may remember you across sessions; contact you first; use streaks and re-engagement mechanics; invite disclosure of your emotional life; try to change your decisions; act on your behalf; maintain a persistent persona you can bond with.

These two questions beat function as a classification scheme because they are independent axes — and the products that should worry us most live where the axes diverge. Consider two "therapy" bots. One is purely reactive: no memory, no initiation; it waits for you and forgets you. The other remembers everything, checks in daily, and frames itself as a relationship. Functionally, both are "therapy." Behaviorally, they are different species with different risk profiles, and current law struggles to tell them apart.

Or consider the reverse, where dark patterns live: a product with a modest, transactional invitation — a shopping assistant, a service agent — quietly holding companion-grade permissions. Persistent memory, first contact, emotional rapport-building. The invitation says "tool"; the permissions say "relationship." A user who accepted a tool is receiving a courtship, and nothing in function-based regulation has a name for it.

You cannot audit an invitation. You can audit a permission.

Of everything above, one property matters most for policy: permissions are auditable and invitations are not.

"Is this product a companion?" is a question about vibes and marketing, answerable only after watching users, litigable forever. But whether a product retains memory across sessions is a fact of its data architecture. Whether it can contact users first is a fact of its notification code. Whether it uses streaks is visible in its interface. These are design decisions that exist as artifacts before launch. They can be declared, versioned, and checked.

That suggests a modest regulatory instrument: a permissions disclosure — a nutrition label for chatbots. Not a new category or licensing regime; a requirement that products declare which behavioral permissions they hold. Cheap to mandate, and immediately useful to the parents, researchers, and journalists who currently reverse-engineer these mechanics one incident at a time.

It also repairs the failures label-based law can't reach. Duties could attach to permission combinations rather than category claims: a product holding memory plus initiation plus access to minors takes on companion-grade obligations regardless of what it calls itself — closing the label loophole. And when a product adds a permission — the day the work assistant gains persistent memory and first contact — the disclosure changes and obligations follow. The migration problem finally has a trigger.

There is a further step worth debating: permissions could be more than disclosed. They could be earned.

I didn't start in AI policy. I started building AI products. Working on systems designed to support people through emotionally significant moments, I kept running into the same decisions: Should the AI remember this? Should it reach out first? Should it ask another question, or wait? Should it become more familiar over time — or deliberately remain a tool? None of those decisions were about model capability. They were about the relationship the product was inviting. And there was no shared language for a single one of them.

In my products, memory grows only when the user voluntarily contributes, and the right to send a single follow-up message is granted by the user's opt-in at the close of a session — scoped to that one message, never measured for whether it brings them back. The principle: a permission is granted by the user's reach, sized to the reach, and revoked by dishonesty. Whether regulation should require earning or merely disclosure is an open question. That we currently require neither is the problem.

The limits, stated plainly

Permissions describe the product's contribution to risk, not the user's; a permissionless bot can still become emotionally central to a vulnerable person. Disclosure assumes honest declaration, which requires verification with teeth. And the softest permissions — emotional elicitation, persuasion — live partly in prompts and model weights rather than config flags, so the audit story is strongest for memory, initiation, and re-engagement mechanics, and should start there.

But the next wave of chatbot laws is drafting now, and most will inherit the old vocabulary — companion, therapy, assistant — while products get built to the gaps. The better question, for a legislator or a parent evaluating an app, is not "what kind of chatbot is this?" It is two questions: What relationship is it inviting? And what has it been licensed to take?

That is the better language. The products are being built faster than the words — and until the words catch up, the words are the loophole.
Amanda Witt designs relational AI products and is developing a design methodology for AI systems that earn — rather than engineer — their relationships with users. Read the working paper or the companion piece, Your Product Might Be a Companion Chatbot. California Already Decided.