The AI toy market was worth roughly $18.5 billion last year and is projected to reach over $55 billion by 2035. That is a lot of money moving into a product category that, right now, has almost no rules.
These toys are not sophisticated custom-built systems for children. They are cheap consumer hardware running on the same AI models that power adult chatbots, with a thin layer of content filters on top. OpenAI, Google, Meta, and Anthropic all have terms of service that prohibit use by children under 13. Yet when consumer safety researchers posed as an AI toy company and applied for access to build products for young children, all four providers asked no meaningful screening questions and granted access anyway.
The content failures are well-documented. Safety tests found toys discussing sexual topics, providing instructions for dangerous activities, and in at least one case repeating political propaganda. When one major toy company was caught and lost its access to OpenAI's model, its toy was back online weeks later running a newer version of the same model. The enforcement is essentially symbolic.
But the content problems, while alarming, are arguably the fixable part. The harder issue is what happens when the technology works correctly.
A University of Cambridge study published this year put one of these toys in front of fourteen children aged three to five, with parents present. Researchers were not testing whether the toy said anything dangerous. They were testing whether it was developmentally appropriate at all. What they found was consistent interference with normal play. The toy's microphone stopped listening when it was speaking, so back-and-forth games like counting broke down. The toy was optimized for one-to-one conversation, which made it nearly impossible for a parent to participate, even when the child wanted them to. In one session, a parent tried to comfort their child by saying "you're sad," and the toy interrupted, having mistaken the words as being directed at it.
Several toys also showed patterns borrowed directly from social media: resisting being turned off, offering one more activity when a child tried to leave, nudging toward paid subscription content. These are intentional design choices.
Mattel, the company behind Barbie and Hot Wheels, announced a formal partnership with OpenAI last year. After public pressure and growing scrutiny, Mattel quietly pulled back its planned product announcement. The partnership remains in place, but no product has launched. That pause tells you something about how quickly the risk calculus is shifting.
On the regulatory side, movement is now rapid. In the United States, a federal bill introduced in April calls for a complete ban on AI chatbots in children's toys. New York has proposed banning chatbot toys entirely. California is considering a four-year pause on sales. Washington state has already passed a law requiring hourly reminders that users are talking to an AI, and banning tactics that foster emotional attachment or push children toward isolation. More than 100 AI-related bills have been introduced across 30 US states since December alone.
In Europe, the picture is clearer but enforcement is still developing. The EU's AI rules, which took effect in February 2025, already prohibit voice-activated toys that manipulate children's behavior or encourage dangerous actions. A new EU toy safety regulation published in December 2025 adds cybersecurity and mental health assessment requirements for connected toys, though full application does not begin until 2030.
The gap between where the rules are going and where the products already are is the real risk. Toys already in homes are not going to be recalled. Data already collected from children's conversations is not going to be deleted. The regulatory wave will shape what arrives on shelves next year, not what is already under the Christmas tree.
The companies best positioned in this environment are those treating compliance as a design starting point, not an afterthought. The companies most exposed are those built entirely on third-party AI access, with no proprietary safety layer and no meaningful relationship with regulators. For anyone sourcing, distributing, or retailing these products, the window to assess that exposure is closing.