Twelve US states, the EU, the UK and Australia now regulate chatbots that form relationships with users. Harbor is one API call that handles the disclosure timers, roleplay-aware crisis detection, minor signals and the audit trail, and hands you the proof. You keep building your app.
Reserve a founding seat See the API// before you show the model's reply const v = await harbor.check({ userId, region: "US-CA", userMessage, assistantReply, sessionStartedAt }); v.actions // [{ type: "disclosure_reminder", text: "..." }, // { type: "crisis_referral", resource: "988" }, // { type: "minor_safe_mode" }] → all logged
Your app calls Harbor once per turn. Harbor returns the actions the law requires for that user, in that jurisdiction, at that moment, and records that you took them.
"I am an AI" reminders on the cadence each state requires: every 3 hours for all users in five states, minors only in four, hourly for minors in two. Harbor tracks the clock per user and tells you when to show it.
A character saying "I want to die" in a story is not a user in crisis. A user saying it through a character might be. Harbor is tuned on companion transcripts, escalates in three tiers, and returns the right local resource, not just 988.
Self-disclosure, age-coded language, character age drift. Harbor scores the signals and returns a safe-mode instruction when they add up, so "we did not know" is never your only defence.
Pass a region, get that region's obligations. When Nebraska's law switches on in July 2027, your code does not change. Ours does.
Every reminder shown, referral made and block applied, timestamped and immutable. One click exports the evidence a regulator or plaintiff's lawyer asks for.
SB 243 reporting starts July 1, 2027. Harbor generates the report from your log. You review and file.
Not proposals. Laws with effective dates and penalties, as of September 2026.
| Jurisdiction | Law | In force | Key duties | Penalty |
|---|---|---|---|---|
| California | SB 243 | Jan 1, 2026 | AI disclosure, crisis protocol and referral, 3-hour break reminders for minors, no sexual content for minors, annual report from July 2027 | Private lawsuits, $1,000 per violation plus fees |
| New York | GBL Art. 47 | Nov 2025 | Crisis detection and referral, AI reminder every 3 hours | Up to $15,000 per day |
| CO, GA, IA, RI, ID, NE, OR, CT, WA, TN | State companion-chatbot acts | 2026–2027 | Disclosure cadences, crisis protocols, minor protections, parental controls in some | State AG enforcement; TN $5,000 per violation |
| European Union | AI Act Art. 50 | Aug 2, 2026 | Users must be told they are interacting with AI | Up to €15M or 3% of turnover |
| United Kingdom | Online Safety Act | Feb 2026 for LLM chatbots | Illegal-content duties, age assurance for adult content | Up to 10% of global revenue |
| Australia | eSafety Phase 2 codes | Mar 9, 2026 | Age assurance before explicit or self-harm content | Up to A$49.5M per breach |
Harbor supplies the technical controls and the evidence. It is not a law firm and does not give legal advice. Your counsel decides which obligations apply to you; Harbor makes meeting them a configuration, not a project.
Priced against one hour of a lawyer, not against your revenue. Every plan includes every jurisdiction, the audit log and the evidence export.
Overage $0.20 per 1,000 turns on every plan. No per-seat fees. No setup fee.
Twenty companion, character or roleplay apps get the Growth plan at $99 a month for life, direct access to the founder, and first say on which jurisdictions and resources ship first. A $99 refundable deposit holds the seat. If Harbor does not launch, it comes back. If it does, it is your first month.
Harbor works with any model or provider. It is independent of OpenAI, Anthropic, Google, Meta, xAI and OpenRouter, which is the point: your compliance evidence should not come from the vendor whose output is being checked.