Here is the short answer for anyone using a companion app from New Zealand. There is no dedicated AI companion Act, and no law that says "chatbots must do X". But three existing bodies of law reach these apps: the Harmful Digital Communications Act 2015, which Netsafe helps enforce, the Privacy Act 2020, and the criminal law on intimate images. Online safety rules aimed at apps like the ones we test have been proposed, but none is law yet.
No AI Act, but not a free-for-all
A few things are worth separating, because headlines blur them.
What New Zealand decided not to do. In July 2025 the government released its first national AI strategy, "Investing with Confidence". It takes a light-touch approach: no AI-specific law, voluntary Responsible AI guidance for business, and reliance on existing privacy and consumer law instead.
What already applies. Privacy law, consumer law, the Harmful Digital Communications Act and the Crimes Act all cover behaviour that happens to involve an AI. A company does not escape them because the thing on the other end of the chat is a model.

The main dates, as they stood at the end of September 2026.
Online safety: proposals, not yet law
New Zealand has no online safety regulator and no age-verification rule for AI companions. Parliament's Education and Workforce Committee reported on online harms in March 2026 and made 12 recommendations, including an under-16 limit for social media and an online safety regulator. On 24 August 2026 the government introduced the Online Safety (Minimum Age and Child Safety Risk Assessment) Bill. It would require operators of "age-restricted platforms", a term that covers "social AI companions", to take reasonable steps to stop under-16s holding accounts and to carry out annual child-safety risk assessments for under-18s. A self-declared birth date alone would not count as reasonable, and penalties would reach NZ$40 million or 10% of global turnover.
It is introduced, not law, and it is unlikely to pass this term. ACT and NZ First have said they will vote against it, and the Prime Minister has conceded it will not reach first reading before the election. A separate member's bill on under-16 social media accounts has been on hold since May 2026. For now, whether an app checks your age is the company's choice, not a New Zealand requirement.
Overseas regulators have looked harder. In October 2025 Australia's eSafety Commissioner published findings from transparency notices sent to four companion services: Character.AI, Nomi, Chai and Chub AI. It found that none had meaningful age checks, and that they mostly relied on users declaring their own age at sign-up. Three of the four (Chai, Chub AI and Nomi) did not steer users to support when self-harm came up.
The Classification Office classifies publications under the Films, Videos, and Publications Classification Act 1993 but does not run age checks on chatbots. Extremely harmful illegal content can be reported to the Department of Internal Affairs.

The Department of Internal Affairs' own page on online safety policy.
The short version of who does what:
| Rule | Who enforces it | Status | What it means for you |
|---|---|---|---|
| Harmful Digital Communications Act 2015 | Netsafe, then the District Court | In force | You can complain about harmful posts and seek take-down orders |
| Privacy Act 2020 | Privacy Commissioner | In force | You can ask what an app holds and complain if it refuses |
| Intimate visual recording offence (HDCA s 22A) | Police and courts | 9 Mar 2022 | Posting intimate recordings without consent is a crime |
| Online Safety (Minimum Age) Bill | Not yet set | Introduced 24 Aug 2026 | Not law, unlikely to pass this term |
| Deepfake Digital Harm and Exploitation Bill | Select committee stage | Not law | Would extend the offence to AI-made likenesses |
Under-16 limits
New Zealand has no social media minimum-age law in force. Australia's Online Safety Amendment (Social Media Minimum Age) Act 2024 took effect on 10 December 2025 and is often mentioned alongside AI companions, but it does not apply here. The nearest New Zealand proposal is the Bill described above, which would cover companions directly.
Privacy law
The Privacy Act 2020 and its Information Privacy Principles apply to almost all organisations, and the Office of the Privacy Commissioner has said they apply to generative AI chatbots. In practice that gives you a right to ask any organisation for the personal information it holds on you (Information Privacy Principle 6), which it must answer within 20 working days. Our guide to what an app knows about you walks through the checks.
The picture has moved in stages:
- In force. Organisations must tell the Commissioner and the people affected if a privacy breach may cause serious harm, ideally within 72 hours. Failing to notify is an offence, with a fine of up to $10,000.
- In force, for biometrics. The Biometric Processing Privacy Code 2025 started on 3 November 2025, and the grace period for existing users ended on 3 August 2026. It matters if an app uses face or voice scans, including age estimation.
- In force since 1 May 2026. A new principle (IPP 3A) requires organisations to notify people when they collect their information indirectly.
- Not in New Zealand. There is no statutory privacy tort and no children's online privacy code, unlike in Australia.
Sexual deepfakes and image-based abuse
Section 22A of the Harmful Digital Communications Act, in force since 9 March 2022, makes it an offence to post an intimate visual recording of someone without their consent, when you know or are reckless about whether they consent. No proof of harm is needed. Individuals face up to two years in prison or a $50,000 fine, and companies up to $200,000. Netsafe says fully AI-generated images may not be clearly covered. The Deepfake Digital Harm and Exploitation Bill, a member's bill from ACT MP Laura McClure, would extend the offence to AI-created or altered likenesses. It passed its first reading unanimously in May 2026 and is before a select committee, so it is not law yet. This offence is the New Zealand counterpart to the US TAKE IT DOWN Act. You can report intimate images, including fakes, to Netsafe, which works by advice, negotiation and mediation. If that fails, the District Court can make orders such as take-downs. There is no eSafety-style regulator with takedown powers here.
What you will actually notice
- Age checks. Expect ID, face-scan or card-based checks, especially on permissive apps, driven by overseas rules rather than New Zealand law. Self-declaration is being phased out.
- Helpline cards. A character that drops the scene and points to 1737 or a similar service. False alarms in fiction are common.
- Breach notices. If an app leaks your data and serious harm is likely, it should tell you and the Privacy Commissioner.
What is not covered
Billing. Subscription traps, credit systems and refunds are handled by the Consumer Guarantees Act 1993 and the Fair Trading Act 1986, enforced by the Commerce Commission. A Fair Trading Amendment Bill is before Parliament, but New Zealand has no ban on subscription traps like Australia's. See refunds and cancellations.
Adult content choices. Nothing here regulates what consenting adults do with a companion. The rules are about harmful communications and non-consensual images.
Overseas context
The US has moved faster on companion-specific statutes. New York's law has applied since November 2025 and California's SB 243 since January 2026, with more states following. Australia's eSafety age-restricted material codes have applied since 9 March 2026. Europe has relied on privacy law: Italy's data protection authority fined Luka Inc., the company behind Replika, five million euros in a decision announced in May 2025, citing no valid legal basis for processing, a non-transparent privacy policy and no working age checks. That same regulator's 2023 order preceded the sudden end of erotic roleplay on Replika, a story told in when your AI companion changes overnight.
Where that leaves you
An adult using a companion app here is not breaking any law, and is not about to be. What may change is the burden on the companies: verify ages, handle crisis talk, respect privacy. The careful apps will adapt without much fuss. The rest will either bolt on clumsy checks or, as Australia's eSafety testing showed, be found lacking.
This article is general information, not legal advice, and it reflects the position at the end of September 2026.