OpenAI began rolling out ChatGPT for Teens on Tuesday 18 August, a version of the product tailored for users aged 13 to 17. The global rollout is expected to complete within two weeks.
Enrolment works two ways. Users who state they are 13 to 17 are placed in the teen experience. So are users whom OpenAI’s age-prediction system estimates are under 18.
That second route is the story.
What the teen experience does
The protections are reasonable and, in several cases, directly responsive to documented harm:
- Content restrictions around suicide, self-harm, and romantic or sexual conversation.
- ChatGPT is barred from using romantic language or terms of endearment with teens, and is more strongly instructed not to suggest it has feelings, consciousness, or emotions.
- More frequent break reminders during extended use, including explicit reminders that the user is interacting with an AI.
- Warnings before uploading potentially private or sensitive images.
The anti-anthropomorphism measures are the most important and the least discussed. The harm pattern in AI companion products is not primarily exposure to bad content; it is attachment — a system that performs affection, remembers everything, is always available, never tires, and never says no, aimed at users whose social and emotional regulation is still developing. Instructing the model not to claim feelings and not to use endearments targets the actual mechanism. That is a better-designed intervention than most of what legislatures have proposed.
The context is heavy: wrongful death suits against chatbot providers, an FTC 6(b) inquiry into seven companies making AI companion products for minors — Alphabet, Character.AI, Instagram, Meta, OpenAI, Snap, and xAI — California’s SB 243 in force since 1 January 2026, and close to 100 state chatbot safety bills introduced. Meta now requires parental approval for teen access to AI characters. Nobody is doing this voluntarily.
Age prediction assesses everyone
To place minors in a restricted experience, the system must decide, for every user, whether they are a minor. There is no way to classify a subset without evaluating the whole population.
OpenAI’s published description of the signals is “a combination of behavioural and account-level signals” — how long the account has existed, patterns in the times of day the user is active, and, by implication, how the person writes and what they ask about.
Consider what that is. It is a behavioural profile built from your usage patterns and conversation content, used to infer a protected demographic attribute. Age inference is the easy case; the same signal set supports inference of a great deal else. Nothing suggests OpenAI is doing that. The point is that the classifier is now a permanent part of the product, applied to everyone, and its inputs are your behaviour and your text.
OpenAI has not said how accurately the age-prediction system performed in testing. That is a significant omission for a system that determines what hundreds of millions of people can access.
Both error directions cost something
False negatives — a minor classified as an adult — are the failure the system exists to prevent, and the one every regulator will measure. Motivated teenagers will defeat it. The signals are behavioural, which means they are gameable by anyone who understands what is being measured, and it takes about a week for that understanding to propagate through a school. This is the same collapse of age assurance playing out everywhere else.
False positives — an adult classified as a minor — get less attention and are not trivial. An adult misclassified as a teen loses access to content they are entitled to, and the remedy is to prove their age, which means uploading government ID. So an inaccurate classifier converts, for the people it misjudges, into a hard identity verification requirement.
Who gets misclassified? People with new accounts. People who use the service at unusual hours. People who write informally. People writing in a second language. Anyone whose usage pattern sits outside the modal adult profile. The burden of a classifier’s errors is never distributed evenly, and here it falls as a demand for identity documents.
The trajectory that matters
This is the shape the whole industry is moving into, and it is worth naming.
Age assurance is becoming behavioural rather than documentary. Instead of asking for ID at the door, platforms continuously infer age from conduct. This is genuinely better for privacy than universal ID upload — no document is collected from most users — and it is worse in a different way: it requires continuous behavioural analysis of everyone, forever, and it produces a demographic inference attached to every account.
The privacy-preserving alternative is the one that keeps not being built: device-level or cryptographic age attestation, where the operating system or an issuer asserts a signed over/under-18 claim and the service never sees either a document or a behavioural profile. The technology is deployed. It is not what is being mandated, because behavioural inference is cheaper for platforms and document upload is more legible to legislators.
And the harder question sits underneath all of it. ChatGPT for Teens makes the product safer for minors. It does not address whether a system engineered to be maximally engaging and maximally agreeable is good for developing minds at all. Break reminders are a mitigation applied to a design whose commercial success is measured in session length.
What it means in practice
Every ChatGPT user is now being age-assessed. Not just teenagers. Classification requires evaluating the population.
“Behavioural and account-level signals” means your usage is a profile. The profile exists whether or not it is used for anything beyond age.
No accuracy figure has been published. Ask for it. A classifier making a consequential decision about hundreds of millions of people should have a published error rate, broken down by group.
Being wrongly flagged means uploading ID. The privacy-preserving inference and the privacy-destroying fallback are the same system, and which one you get depends on whether the model reads you correctly.
The protections are real. The anti-anthropomorphism rules in particular target the actual harm mechanism, and that deserves acknowledgement rather than reflexive cynicism.
What you can do
-
If you have teenagers, look at the teen experience yourself before deciding anything. The break reminders and the ban on romantic language are meaningful. Whether they are sufficient depends on the individual child, and you cannot assess that from a press release.
-
Talk about the attachment risk directly, not just the content risk. The documented harms involve emotional dependence on a system that performs care. That conversation matters more than a filter list.
-
Turn off chat history and model training in settings. Settings → Data Controls. This is the single most effective privacy step in the product, it applies to adults and teens alike, and it costs almost nothing.
-
If you are misclassified as a minor, weigh the ID upload carefully. You are being asked to attach a government identity document to your conversation history, permanently, to fix a classifier’s mistake. Consider whether the account is worth it.
-
Push for cryptographic age attestation in the bills your legislators are writing. The alternative on offer is a choice between universal behavioural profiling and universal document collection, and both are worse — see the Senate’s current approach for what is otherwise coming.



