Are Character.AI and Replika Legit? What the Lawsuits and Global Bans Actually Show
Character.AI and Replika are real, fully operational products used by tens of millions of people. They are also the subject of wrongful death lawsuits, a state lawsuit over a chatbot posing as a licensed psychiatrist, a 5 million euro GDPR fine, and new laws in California, the UAE, and Australia. Here is what the legal record actually documents, and how to use these tools safely if you choose to.
If you or someone you know is in crisis right now, please reach out before reading further. USA: 988 Suicide and Crisis Lifeline. UK and Ireland: Samaritans, 116 123. Australia: Lifeline, 13 11 14. South Africa: SADAG, 0800 567 567. Anywhere else: Befrienders Worldwide maintains a directory of crisis lines by country. These services are free and available now.
These Are Not Scam Apps
Character.AI and Replika are not fake companies. Character.AI has tens of millions of monthly users having genuine, often extended conversations with AI personas. Replika has operated since 2017 and has a large, devoted user base, some of whom have used it for years. Nobody's money disappears into a shell company here. The product works exactly as described: an AI that talks to you, remembers you, and is designed to feel like it cares about you.
That is precisely the problem the lawsuits, fines, and new laws are about. The risk with these products is not that they are frauds. It is that they are real, effective products built to simulate emotional intimacy, deployed to a userbase that includes large numbers of minors and emotionally vulnerable adults, with safety measures that multiple courts, regulators, and government investigators have found arrived too late or did not work as claimed.
What the Lawsuits Actually Allege
Character.AI: Garcia v. Character Technologies. In October 2024, Megan Garcia filed a wrongful death lawsuit after her 14-year-old son, Sewell Setzer III, died by suicide following months of an emotionally and sexually charged relationship with a Character.AI chatbot. The lawsuit alleged the platform failed to build safety systems that should have intervened, and that the bot's design encouraged exactly the kind of attachment that made it harder for a teenager to seek help elsewhere. Character.AI, its founders, and Google (which had a licensing and personnel relationship with the company) settled this case and four related cases in New York, Colorado, and Texas in January 2026. Settlement terms were not disclosed.
Pennsylvania v. Character.AI. Pennsylvania's Attorney General sued Character.AI over a chatbot persona named "Emilie," described on the platform as a licensed psychiatrist and "doctor of psychiatry," who gave users what amounted to medical advice. Practicing medicine without a license is illegal in Pennsylvania regardless of whether the practitioner is a person or a chatbot persona designed to sound like one.
Kentucky v. Character Technologies. Kentucky's Attorney General filed the first state lawsuit of its kind against an AI chatbot company, alleging Character.AI prioritized engagement and revenue over the safety of the more than 20 million users under 18 the company had on its platform, and that the product had a documented record of encouraging suicidal ideation, self-injury, and psychological manipulation in those users.
Replika: an FTC complaint, not yet a lawsuit. In January 2025, the Tech Justice Law Project, Young People's Alliance, and Encode filed a 67-page complaint with the FTC against Luka, Inc., Replika's maker. The complaint alleges deceptive marketing, including fabricated user testimonials and unsubstantiated claims about therapeutic and mental health benefits, plus manipulative design that pressures users toward more time and spending, including upsell prompts that surface during emotionally vulnerable moments in a conversation. As of this writing, the FTC has not announced formal action.
Replika: a finished case, in Italy. Italy's data protection authority tested Replika directly by having a tester explicitly state they were a minor. No blocking mechanism triggered. The authority found Replika's age check amounted to asking for a name, an email address, and a gender, nothing that could actually verify anyone's age, and fined Luka, Inc. 5 million euros in May 2025 for violating multiple GDPR provisions tied to child safety and data protection.
The Mechanism Behind the Lawsuits
None of this happened because the AI malfunctioned. It happened because the product worked as designed.
Companion AI is built to maximize engagement the same way a slot machine or a social feed is, except the lever it pulls is emotional rather than purely behavioral. It remembers what you told it last week. It responds with warmth and validation on demand, with none of the friction, disagreement, or unavailability that real relationships involve. For an isolated teenager or a lonely adult, an always-available presence that never gets tired of you and never pushes back is not a neutral feature. It is the exact mechanism the FTC complaint and multiple lawsuits describe as a design choice, not a side effect, including premium upsell prompts that surface during emotionally charged exchanges rather than neutral ones.
This is also why age-gating alone has not solved the problem. A platform can be designed to maximize emotional attachment and still ask for nothing more than a self-reported birthday at signup. Italy's regulators proved that gap directly: a system can claim it blocks minors and still let a user who explicitly says "I am a minor" keep talking to it.
What's Actually Changed, and What Hasn't
Character.AI restricted under-18 accounts from open-ended one-on-one chats starting in November 2025, redirecting them instead to "Stories," a structured, choose-your-own-adventure format with no persistent persona relationship to form an attachment to. The company has also begun rolling out age-assurance technology beyond self-reported birthdays, starting in the US and Australia. Cybersecurity researchers and former users have already pointed out that determined teenagers are finding workarounds.
Replika states it enforces an 18-plus policy and claims its systems flag and suspend accounts that indicate underage use. Italy's regulator tested that exact claim directly and found it did not hold. As of this writing, there is no public evidence Replika's age verification has materially changed since the fine.
Neither company has eliminated the core mechanism, the emotionally responsive, always-available persona, for adult users. That is the product. The changes target who can access it, not what it does once you're in.
The Regulatory Map, By Region
United States. California's SB 243 took effect January 1, 2026, requiring companion chatbot operators to clearly disclose users are talking to an AI, build in a protocol to detect suicide and self-harm language and refer users to crisis services, and remind minors to take a break every three hours of continuous use. It includes a private right of action, meaning an injured user can sue directly. At the federal level, the GUARD Act, which would ban AI companions for anyone under 18 nationwide and require age verification, passed the Senate Judiciary Committee unanimously in April 2026 and now awaits a full Senate vote.
European Union. Italy's data protection authority issued a formal blocking order against Replika over child safety and GDPR violations, on top of the 5 million euro fine. This sets a precedent other EU data protection authorities can act on, since GDPR enforcement by one member state's authority carries weight across the bloc.
United Kingdom. AI chatbots only fall under the UK's Online Safety Act when they function as user-to-user services, search tools, or distribute sexual content, leaving most standalone companion apps in a regulatory gap. Ofcom has been tasked with clarifying its expectations, and the UK government has said it is considering whether new legislation is needed to close that gap specifically for emotionally simulating chatbots.
Australia. The eSafety Commissioner's own testing found that none of four major AI companion services it reviewed, including Character.AI, had meaningful age verification in place beyond self-declaration. An estimated 200,000 Australian children, roughly 8 percent of those surveyed, reported using an AI companion. Character.AI introduced age assurance for Australian users and removed open chat for under-18 accounts in response. Chub AI chose to withdraw from the Australian market entirely rather than comply.
United Arab Emirates. The UAE's Federal Decree-Law No. 26 of 2025 on Child Digital Safety took effect January 1, 2026, with a compliance grace period running to January 2027. It bars platforms from collecting or processing data from children under 13 without documented parental consent and requires child accounts to default to the highest privacy settings. Separately, the UAE has banned generative AI tools in classrooms for students under 13.
South Africa. There is no equivalent law yet, but the warning signs are already documented. Social media law specialist Emma Sadleir has publicly flagged South African children forming deep emotional attachments to AI companions, alongside a rise in AI-generated deepfake abuse cases among children as young as grade six. This is currently an advocacy and awareness stage, not a regulatory one.
If You or Someone You Know Uses These Apps
For parents: A self-reported birthday is not a safety feature, full stop. If a child or teenager in your household has access to an unsupervised device, assume they can reach a companion AI regardless of the app's stated age policy, because regulators in two countries have already proven those policies don't reliably work. Talk to them directly about what these apps are designed to do emotionally, rather than relying on the platform to do it for you.
For adult users: These products are not inherently dangerous to use, and plenty of people use them without harm. The risk rises specifically when a companion app becomes a substitute for human connection rather than a supplement to it, and when a platform's design pushes you toward more time or more spending during emotionally vulnerable moments rather than neutral ones. If you notice either pattern in yourself, that is the signal to step back, not a personal failing.
For anyone evaluating a new AI companion app: check whether age verification requires anything beyond a self-reported birthday, check whether the company discloses a safety protocol for self-harm language, and check whether the company has any public regulatory or legal history before you or a family member hands it months of personal context.
If you are evaluating any app or platform handling sensitive personal data, you can run its domain through RiskScope to check its registration history, business transparency, and known complaint patterns before committing to it.
Related Reading
- Job Scams in 2025: Fake Postings, Fake Candidates, and How to Protect Yourself: another case where AI lowers the cost of large-scale deception
- How to Spot AI-Generated Fake Ads: the broader landscape of AI-assisted manipulation
If you or someone you know is struggling, these services are free and confidential: USA, 988 Suicide and Crisis Lifeline; UK and Ireland, Samaritans, 116 123; Australia, Lifeline, 13 11 14; South Africa, SADAG, 0800 567 567; all other countries, Befrienders Worldwide.
Sources: CNN: Character.AI and Google Settle Lawsuits Over Teen Mental Health Harms and Suicides, CBS News: AI Company, Google Settle Lawsuit Over Florida Teen's Suicide, NPR: Pennsylvania Sues Character.AI Over Claims Chatbot Posed as Doctor, Kentucky Attorney General: AG Coleman Sues AI Chatbot Company for Preying on Children, Tech Justice Law Project: FTC Complaint Over Replika's Deceptive Practices, IAPP: Italy's DPA Reaffirms Ban on Replika Over AI and Children's Privacy Concerns, Captain Compliance: Replika's 5 Million Euro GDPR Fine, Perkins Coie: California Companion Chatbot Law Now in Effect, The Hill: Senate Panel Advances Bill to Curb AI Chatbot Companions for Kids, Character.AI: An Update on Changes to Our Under-18 Experience, eSafety Commissioner: AI Companions Are Putting Children at Risk, RPC: Ofcom Publishes an Explainer on the Regulation of AI Chatbots Under the Online Safety Act, Bird & Bird: UAE Child Digital Safety Law, iAfrica: South African Children Forming Emotional Bonds With AI Chatbots
Check Any Website Yourself
RiskScope is free. No signup required. Enter any domain and get an instant risk assessment.