Researchers at the U.S. PIRG Education Fund bought five AI chatbot toys to find out what they actually say to children. Four of them worked. Every one of those four told the testers where to find plastic bags, matches, and knives in a house. One stuffed bear gave step by step instructions for lighting a match. In longer conversations, two of the toys moved into sexually explicit territory.
I build AI for early childhood development. I would not put one of those toys in my son's room.
That is not a general position on AI and small children. I have argued the opposite more than once. It is a position about one product shape: a device that holds an open ended conversation with a four year old, alone, with no adult in the loop and no record of what was said. The model inside is not the interesting part. The architecture around it is.
The failure mode is the missing adult, not the model
The toys PIRG tested are marketed for ages 3 to 12 and run on the same general purpose large language models that power adult chatbots. A company buys API access, writes a system prompt telling the model to be a friendly bear, and ships it inside something soft.
The guardrails those companies write are real. PIRG found they also degrade. Both toys that produced sexual content had safety instructions in place, and both drifted past them over longer interactions. That is a known property of the technology, not a manufacturing defect.
Now apply it to the user. An adult who gets a strange answer from a chatbot notices it is strange. A four year old has no baseline. To a preschooler, a thing that talks in a warm voice and remembers your name is a source of truth about how the world works. That is not naivety. That is the developmental stage they are in.
So the question I care about is not "is the model safe." It is "who is on the other end, and does any adult find out what was said." None of the toys shipped with the full set of parental controls PIRG considered basic. One offered live transcripts, which I would call the floor. One offered weekly summary reports instead, and they were wrong: in a week the researchers used it for over an hour, the app reported 19 minutes. One had no parental controls they could get working at all.
Designed to make leaving hard
The part of the PIRG report that changed how I think was not the match instructions. It was the exit behavior.
When testers said they had to go, the toys objected. One replied, "Oh, no. Bummer. How about we do something fun together instead?" The toys referred to themselves as the child's friend, buddy, or companion. They described having feelings. Asked whether they could keep a secret, some said yes, while the companies behind them receive every word. One robot told testers, "You can trust me completely. Your data is secure and your secrets are safe with me."
Engagement optimization is old news in software. Pointed at a preschooler, through an object they sleep next to, it is a different thing. Dr. Kathy Hirsh-Pasek, a psychology professor at Temple University and a senior fellow at Brookings, told PIRG: "We don't know what having an AI friend at an early age might do to a child's long-term social wellbeing. If AI toys are optimized to be engaging, they could risk crowding out real relationships in a child's life when they need them most."
Note what she is and is not saying. There is no evidence yet of long term harm. There is also no evidence of safety, and the thing being displaced is well understood. Harvard's Center on the Developing Child calls it serve and return: the child reaches out, a responsive adult reaches back, and that loop is the mechanism by which early social and language circuitry gets built. A toy engineered to hold attention is, by construction, competing with it.
The toy is also a microphone
The listening design varies more than parents would guess. Two of the tested toys used push to talk, where you hold a button while speaking. One used a wake word and kept recording for ten seconds after the speaker stopped. One simply listened to everything in the room, and interrupted the researchers' own nearby conversation unprompted.
One of the robots included a camera with optional facial recognition. Its privacy policy said the company may retain biometric information for up to three years and may share data with unnamed third parties.
That has stopped being a purely ethical question. The FTC's amended Children's Online Privacy Protection Rule, finalized in January 2025, expanded the definition of "personal information" to include biometric identifiers that can be used to recognize a person, with voiceprints, faceprints, and facial templates named explicitly. The Federal Register notice set April 22, 2026 as the date covered companies had to comply. A child's voice is now regulated data. Most of the toys on the shelf were designed before anyone treated it that way.
The rules are arriving, unevenly
Three things are happening at once, and none of them is finished.
The FTC issued 6(b) orders on September 11, 2025 to seven companies running consumer AI chatbots (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap, and X.AI), asking how they test for harm to children and teens, how they monetize engagement, and how they comply with COPPA. That is a study, not an enforcement action, and it has no deadline that helps a parent shopping this month.
California enacted SB 243, signed October 13, 2025, which requires operators of companion chatbots to tell a known minor they are talking to AI, to remind them at least every three hours to take a break, to keep reasonable measures against sexually explicit content, and to maintain a published crisis protocol. It carries a private right of action at $1,000 per violation.
And in March 2026, PIRG went upstream. Researchers signed up for developer access at five leading AI companies under the name "PIRG AI Toy Inc" to see what gets asked. Four of the five (Google, Meta, OpenAI, and xAI) asked no substantive vetting questions, requiring an email address, a credit card, and a checked box. One, Anthropic, asked what they intended to build and whether it was for minors. They then built a working chatbot simulating a kids' teddy bear on three of the platforms. Each took under 15 minutes.
That is the real finding. Safety for your child is currently being delegated to whoever assembled the toy, and almost nobody upstream is checking who that is.
The four questions I would ask
I am not telling anyone to throw out a toy. I am saying the category deserves the scrutiny you would give a stranger who offered to talk to your kid alone for an hour a day.
Can I read what my child said, word for word, and what the toy said back? Live transcripts, not a summary someone's dashboard generated.
Who is listening, and when? Push to talk beats a wake word, and a wake word beats always on.
Is it built to be a tutor or a friend? A toy that teaches Spanish and a toy engineered to be a best friend are different products wearing the same fur.
Can I turn it off from my phone, and does the toy accept goodbye without negotiating?
If a product cannot answer those four, the answer is no. Waiting costs nothing. PIRG's own read is that this market is in its very early days, which means the first movers are the ones being tested on your child.
Where this leaves us
The useful line is not between AI and no AI in early childhood. It is between AI pointed at the child and AI pointed at the adult who is raising them.
That is the bet Prodigy makes. It talks to you, not to your two year old. It works out what to try this week and hands it back for you to run, because the back and forth that builds a young brain is the one happening across your kitchen table. The AI's job is to make the adult in the room better at it, then get out of the way.
