Status: Enacted — Included in New York FY2027 Enacted Budget (signed by Governor Hochul, May/June 2026); effective 180 days after the New York Attorney General promulgates implementing regulations (estimated early 2027)
Citation: New York State FY2027 Enacted Budget (2026); Stop Online Predators Act (SOPA) / Safe by Design Act; sponsored by Sen. Andrew Gounardes
Jurisdiction: New York
Category: Children's Online Safety, AI Regulation, Platform Safety, Privacy, Age Verification
Industries: Technology and Social Media Platforms, AI Product Development, Education Technology, Consumer Apps, Any Platform with Minor Users
Enacted Date: May/June 2026 (signed as part of NY FY2027 State Budget by Governor Hochul)
Effective Date: 180 days after the New York Attorney General issues implementing regulations; estimated early 2027. AG rulemaking had not been finalized as of June 2026.
Summary: New York's Safe by Design Act (commonly called SOPA — the Stop Online Predators Act) was enacted as part of the state's FY2027 budget in 2026. It establishes one of the most detailed children's online safety frameworks in the United States, requiring consumer platforms to treat minors as the default case and build privacy-by-default protections and parental control architecture into product design itself — not as an opt-in feature. The law is specifically designed to prevent platforms from using AI companion features, personalization algorithms, and engagement-maximizing tools that expose minors to harm. Governor Hochul cited the law as evidence of New York's leadership in children's technology protection, with the state receiving a top national ranking for technology laws keeping kids safe online following the law's enactment.
Key Requirements:
- Privacy by Default: Platforms must configure minor users' accounts to the highest available privacy setting by default; no opt-in required for the most protective setting.
- Parental Controls: Platforms must implement verified parental approval tiers, giving parents meaningful access controls over their child's account configuration and connectivity.
- Open Chat Restrictions: Platforms must disable open or unsolicited messaging to minors; direct messaging to a minor must require an existing approved connection or explicit parental authorization.
- AI Companion Restrictions: Platforms may not include AI companion features (chatbots, virtual companions, or relationship-style AI interactions) as a default setting for minor users.
- Age Verification: Platforms must implement reasonable age verification processes to enable meaningful enforcement of minor-specific protections.
- Safe by Design Standard: Compliance must be built into product architecture — protective features must be the default state, not settings a minor must discover and enable. This is a design mandate, not a disclosure requirement.
Affected Entities: Consumer technology platforms, social media platforms, gaming platforms, AI chatbot and companion application providers, and any platform that knowingly has or is likely to have minor users in New York. Platforms operating nationally will face pressure to implement changes applicable to all accounts identified as minors — not just New York users — due to enforcement practicalities.
IntelliSee Relevance: Moderate — IntelliSee's AI platform (behavioral detection, weapons detection, access control analytics) does not operate as a consumer-facing chatbot or social platform and is not directly regulated by SOPA. Two dimensions create relevance:
- School and education sector context: IntelliSee customers in the K-12 sector operate under the same increasingly regulated AI and technology environment as platforms subject to SOPA. When school administrators evaluate AI tools, SOPA's framework helps draw a clear distinction between consumer platforms with interactive AI features (regulated) and facility security AI like IntelliSee's that analyzes physical environments rather than engaging digitally with students (not regulated under SOPA).
- Precedent for AI safety architecture: SOPA's "safe by design" framework — requiring privacy and safety protections to be the default in AI product architecture — signals a growing legislative expectation that AI systems serving vulnerable populations must proactively build in protective guardrails. Physical security AI vendors serving school markets should monitor how this framework evolves and shapes procurement expectations.
Compliance Timeline
- May/June 2026 — Enacted in NY FY2027 Budget; signed by Governor Hochul.
- TBD (estimated late 2026) — New York Attorney General issues implementing regulations; 180-day clock starts.
- Estimated Early 2027 — Law takes effect; platforms must be in compliance with all Safe by Design requirements.
Related Legislation
- New York Kids Chatbot Safety Act — Protecting Minors from Unsafe AI (S9051B, 2026)
- New York FY2027 Enacted Budget — Public Safety Package (2026)
- New York RAISE Act — Frontier AI Safety (S6953B / A6453B, 2026)
- Colorado AI Companion Chatbot Safety Act (HB 26-1263, 2026)
- Vermont AI Therapy Chatbot Ban (H.816 / Act 156, 2026)
Sources: NY Senate — Sen. Gounardes Announcement | Governor Hochul Announcement | SOPA Compliance Builder Guide | Common Sense Media Coverage