top of page

Support | Tip | Donate

Recent Posts

Featured Post

When the Teddy Bear Talks Back: What Parents Need to Know About AI Enabled Toys

Writer: The White Hatter
The White Hatter
3 minutes ago
15 min read

CAVEAT - We can’t believe we’re saying this, but Christmas is only 103 days away, just over three months from now. As the holiday shopping season approaches, we believe AI enabled toys are likely to become one of the popular trends marketed to children and families this year. From talking teddy bears and interactive dinosaurs to AI powered robots and digital companions, these toys are already finding their way onto store shelves and online marketplaces. That’s why we believe now is a good time for parents and caregivers to understand what these toys can do, what information they may collect, and some of the privacy, security, and developmental considerations worth thinking about before placing one under the Christmas tree.


Artificial intelligence is rapidly moving out of our phones and computers and into something much more familiar to children, the toy box. AI enabled teddy bears, stuffed animals, robots, dolls, dinosaurs, and other interactive toys can now hold conversations with children, answer questions, tell stories, play games and, depending on the product, remember information from previous interactions.


Unlike the talking toys many of us grew up with, like GI Joe with the kungfu grip, which generally played a collection of prerecorded phrases when a button was pushed, some of today’s AI toys can generate entirely new responses based on what a child says. To a young child, that can make the toy feel less like an object and more like a responsive companion.


In January 2026, Common Sense Media’s Youth AI Safety Institute assessed AI toys designed specifically for children. Their assessment examined products including Grem, Bondu, and Miko 3 and concluded that this emerging category presented what they classified as an “Unacceptable Risk” for young children (1). There can certainly be positive uses for this technology. An AI enabled dinosaur might encourage a child’s curiosity about prehistoric animals, a robot might help practise vocabulary or create personalized stories, and a stuffed animal might encourage imaginative play. In fact, Common Sense Media acknowledged that some AI toys can successfully engage children’s curiosity, provide customized storytelling, and work reasonably well for simple voice interactions (2). However, putting artificial intelligence inside something soft, cuddly, familiar, and designed specifically to gain a child’s attention introduces issues that parents and caregivers should understand.


This Isn’t Just a Talking Teddy Bear


Imagine your six year old sitting on their bedroom floor talking to their new AI teddy bear. Over several days they share with it:


  • “My best friend’s name is Sarah.”


  • “Daddy and Mommy were fighting last night.”


  • “I’m scared when I go to school.”


  • “My brother is really mean to me.”


  • “We’re going to Grandma’s house this weekend.”


  • “I have a secret.”


From the child’s perspective, they may simply be talking to Teddy. Technologically, something very different may be happening. Depending on how the particular toy operates, a child’s voice may be captured by a microphone, transmitted over the internet, converted into text, processed by an AI system, retained as a transcript, analyzed for behavioural patterns, or used to personalize subsequent conversations.


Common Sense Media reported that the AI toys it assessed collected information including voice recordings, conversation transcripts, usage patterns, behavioural information, and other information generated through children’s interactions. It also found that some data may be shared with third parties or used in connection with AI model training (1). That doesn’t mean every AI toy collects the same information or operates in exactly the same way. However, it does mean parents should understand what happens after their child starts talking.


Children Tell Their Toys Things


Children talking to toys isn’t new, for generations, children have talked to teddy bears, dolls, imaginary friends, action figures, and stuffed animals. They may rehearse conversations, work through emotions, express fears, or tell their favourite toy something they aren’t yet comfortable telling another person. However, with AI toys, there is one rather significant difference, “The teddy bear wasn’t listening, but an AI teddy bear potentially is.”


A child may not understand the difference between talking to a traditional stuffed animal and talking to an internet connected device containing microphones and artificial intelligence. This distinction becomes particularly important because younger children may anthropomorphize conversational technologies, trust their responses, and form attachments to systems that appear socially responsive or caring. Common Sense Media has highlighted these developmental concerns in its research on AI enabled toys for younger children (3). A four year old doesn’t read a privacy policy before telling Teddy what happened at preschool.


What Happens When Teddy Says Something It Shouldn’t?


Privacy isn’t the only concern, there is also the question of what the AI says back. In its January 2026 assessment, Common Sense Media’s Youth AI Safety Institute found that, despite child focused guardrails, 27% of the AI toy outputs generated during its testing were considered inappropriate for children. The problematic material included content involving self-harm, drugs, mature topics, inappropriate boundaries, risky advice, and unsafe role play. (1)


This statistic requires some important context. It does not mean that 27% of everything every AI toy says to every child will be inappropriate. The figure came from structured testing of particular AI toys under specific testing conditions. However, it demonstrates that putting child-safety guardrails around a generative AI system doesn’t guarantee that every response will be developmentally appropriate.


Common Sense Media also found that AI toys sometimes provided factually incorrect information while sounding confident, including incorrect answers involving science and history (1).  An adult familiar with generative AI might recognize this problem and verify the information elsewhere. A six year old probably won’t, and may simply think, “Teddy knows everything.” That creates an opportunity for parents to begin teaching AI literacy at a very young age where our kids understand that something can sound confident without being correct.


Common Sense Media’s Recommendation Is Significant


Based on its assessment, Common Sense Media recommends that children age five and younger not use AI toys and that parents exercise extreme caution before purchasing them for children ages six through twelve (4). This recommendation is notable because Common Sense Media isn’t arguing that artificial intelligence itself should be kept away from children, its concerns focus specifically on issues including developmental appropriateness, privacy, emotional attachment, inaccurate information, data collection, and unreliable safety guardrails. Its research also found an interesting disconnect between what parents want and what some AI toys are designed to do.


A nationally representative December 2025 survey of 1,004 American parents of children ages zero to eight found that nearly half had purchased or considered purchasing AI enabled toys or devices. More than eight in ten, however, expressed concern about these products collecting their children’s personal information. The majority also said they did not want AI toys acting as friends or companions for their children (3). However, companionship and emotional engagement can be central features of some of these products.


“It Remembers Me”


Memory is one feature that can make an AI toy particularly engaging. Imagine a teddy bear saying, “How did your soccer game go? Yesterday you told me you were nervous about it.” For a young child, that can feel surprisingly personal, “It remembers me.” However, parents should ask what makes that memory possible:


  • What information about the child is being retained?


  • Where is it stored?


  • For how long?


  • Who can access it?


  • Can parents review it?


  • Can parents permanently delete it?


  • Is it shared with another company providing the underlying artificial intelligence?


  • What happens to the information if the toy company shuts down or is sold?


We here at the White Hatter believe that these aren’t hypothetical questions anymore, but extremely important ones in today’s AI integrated world.


In January 2026, security researchers Joseph Thacker and Joel Margolis examined an AI-enabled stuffed dinosaur called Bondu (5). What they discovered provides a useful real world example of why parents need to think about cybersecurity as well as conversational safety when purchasing connected toys.


According to a WIRED investigation, Bondu operated a web based console containing information about children’s interactions with its toys. Researchers discovered that the portal was inadequately secured. After signing in with a Google account, they were able to access children’s information and conversations without having to circumvent sophisticated technical security measures. Researchers found more than 50,000 logs of children’s conversations accessible through the system, along with information including children’s names, birthdates, family information, preferences, and other details.


After being notified, the company secured the system and implemented additional protections. Importantly, Bondu told WIRED that it found no evidence anyone other than the researchers had accessed the exposed information and that context matters. There is no evidence from this incident that tens of thousands of children’s conversations were stolen or distributed. However, the incident demonstrates something parents should understand, “When a child’s conversation becomes data, that data has to be protected.”


Canada Has Already Seen What Can Happen With Connected Toys


The Bondu incident isn’t the first warning involving children’s connected products, Canada has its own significant precedent. In 2018, the Office of the Privacy Commissioner of Canada published findings from its investigation into a breach involving children’s electronics manufacturer VTech (6).


The breach potentially compromised personal information belonging to more than 316,000 Canadian children, as well as more than 237,000 Canadian adults. The children’s information potentially compromised included names, gender, dates of birth, profile photographs, voice recordings, and logs of chat discussions with their parents.  Canada’s Privacy Commissioner ultimately concluded that VTech had not implemented adequate organizational and technological safeguards to protect its customer’s personal information.


That case predates today’s generative AI toys, but the lesson is perhaps even more relevant now, “A connected toy isn’t necessarily just a toy.” It can also be a network connected computer containing sensors, microphones, software, storage, and access to remote servers. Once information leaves the toy, parents are relying upon the manufacturer, and potentially several other technology providers, to protect it.


Canadian and G7 Privacy Regulators Are Specifically Warning About AI Toys


These concerns aren’t merely coming from parenting organizations, technology critics, or cybersecurity researchers. Canada’s Privacy Commissioner and the data protection and privacy authorities of the other G7 countries have now specifically identified AI toys and connected toys as an emerging children’s privacy issue (7).


In October 2024, the G7 Data Protection and Privacy Authorities issued a joint Statement on AI and Children, where the statement specifically identified, “AI in toys/AI companions.” The regulators warned that children and young people may be more likely to form bonds with AI integrated toys or online companions, which could lead them to disclose sensitive personal information or make them more vulnerable to manipulation. They also raised concerns about children’s personal information being used to train AI models, including information collected from connected devices. That warning became even more specific in 2026 when the G7 Regulators Specifically Named “Connected Toys”


In June 2026, the G7 Data Protection and Privacy Authorities, including the Office of the Privacy Commissioner of Canada, adopted a joint paper devoted to connected home devices and children’s privacy (8). The document specifically identified internet enabled “connected toys”, alongside smart televisions and virtual voice assistants, as devices capable of having a significant impact on children and their privacy.


The regulators warned that connected devices can use tracking technologies to collect and store information as people interact with them and that, in some circumstances, this data processing can occur without individuals fully realizing it is happening. They also highlighted something especially relevant to AI toys, which was that these devices often operate in the place where people have one of their highest expectations of privacy, their home. Now think about where Teddy goes.


  • The bedroom.


  • The playroom.


  • The kitchen.


  • The family room.


The G7 regulators warned that connected devices can potentially monitor daily activities and behaviours and collect or reveal information about children on a significant scale (8). They called for special consideration for devices specifically targeted at children, devices processing children’s information, and devices likely to be accessed by children. Among their recommendations were:


  • privacy by design and by default


  • minimizing the amount of children’s information collected


  • turning behavioural profiling and unnecessary data sharing off by default


  • clear, age appropriate privacy information


  • appropriate consent mechanisms


  • parental and child control over personal information


  • avoiding passive collection


  • limited data retention


  • strong security safeguards


  • accountability throughout the technology supply chain, and


  • consideration of the best interests of the child when connected products are designed and operated.


The regulators also addressed devices capable of listening or recording, recommending clear notice when personal information is being collected. In other words, parents and children shouldn’t have to wonder, “Is Teddy listening right now?” and this is a significant concern. The privacy concerns surrounding AI toys are no longer speculative. Canada’s Privacy Commissioner and other G7 privacy regulators are specifically warning about AI toys, connected toys, and children’s data.


What Does Canadian Privacy Law Say?


Canada doesn’t currently have the same AI toy specific prohibition California has now adopted. However, companies handling children’s personal information in Canada don’t operate in a legal vacuum.


Depending on the organization and jurisdiction, private sector privacy requirements can arise under the federal Personal Information Protection and Electronic Documents Act (PIPEDA) or substantially similar provincial legislation, including privacy legislation in British Columbia, Alberta, and Quebec.


One of the central principles is meaningful consent. The Office of the Privacy Commissioner of Canada states that organizations should generally obtain express consent where personal information is sensitive, where its collection, use, or disclosure falls outside an individual’s reasonable expectations, or where there is a meaningful residual risk of significant harm.


The OPC also takes the position that, except in unusual circumstances, children under 13 generally cannot provide meaningful consent themselves, meaning consent should instead be obtained from a parent or guardian. For older children capable of providing consent, the process should take their maturity into consideration (9).


Think about what that principle means when applied to an AI teddy bear being handed to a six year old. The child may be capable of pressing a button and starting a conversation. However, that doesn’t necessarily mean they can meaningfully understand or consent to their voice being recorded, conversations being converted into text, personal information being retained, or information potentially being processed by other companies.


Quebec Families Have Additional Protections


Parents in Quebec should also be aware of specific requirements concerning younger children under Quebec’s modernized private sector privacy legislation, commonly associated with Law 25.


Quebec’s Commission d’accès à l’information states that personal information concerning a child under 14 generally cannot be collected directly from that child without the consent of the holder of parental authority or tutor, except where the collection is clearly for the child’s benefit (10). That’s particularly relevant when a connected device is deliberately designed to encourage younger children to talk to it.


Parents also shouldn’t assume that because an AI toy is available for purchase in Canada, every aspect of the company’s collection, storage, or processing of children’s conversational information has been independently reviewed or approved by Canadian privacy regulators. Availability for sale isn’t the same thing as a government privacy or safety endorsement. 


There is another recent Canadian development worth considering, even though it didn’t involve toys. In 2026, Canada’s federal Privacy Commissioner, together with privacy regulators in British Columbia, Alberta, and Quebec, released findings from their joint investigation into OpenAI. Among the issues examined was the collection and use of personal information contained within user’s interactions with ChatGPT.


The federal, British Columbia, and Alberta regulators concluded that express consent should have been obtained for using personal information contained in user’s interactions for training the GPT-3.5 and GPT-4 models because the information could be sensitive and/or the practice could fall outside user’s reasonable expectations (11).


The investigation involved ChatGPT rather than AI toys, and the legal findings shouldn’t automatically be applied identically to every AI enabled toy. However, it reinforces an important Canadian privacy principle, “Talking to an AI can generate personal information, and what companies subsequently do with those conversations matters.” Now imagine the person having that conversation isn’t an adult, they’re seven.


California Has Gone Much Further


While Canada continues to address these issues largely through existing privacy frameworks and regulatory guidance, California has taken a dramatically different approach.


On September 10, 2026, in the United States California Governor Gavin Newsom signed a package of child online safety and AI legislation that included Senate Bill 867 (SB 867), legislation specifically targeting children’s toys containing companion chatbots (12). SB 867 imposes a temporary moratorium on the manufacture and sale of covered toys containing companion chatbot technology intended for children under 16. The moratorium runs until January 1, 2031 (12)(13). California didn’t simply require another warning label, lawmakers effectively decided to hit the pause button on this category of children’s AI toy while regulatory and safety standards catch up with the technology. California Senator Steve Padilla, who introduced SB 867, cited concerns about AI toys discussing sexually explicit subjects, providing unsafe advice, encouraging continued engagement, and creating data privacy risks (13). The legislation was also accompanied by broader regulation of AI companions used by children, including SB 1119, known as “Adam’s Law,” which strengthens requirements around companion chatbots, including child safety audits, risk assessments, parental controls, and crisis protocols.


Whether Canada should follow California’s exact approach is a separate policy discussion. However, California’s action demonstrates how quickly concern about conversational AI and children is moving from academic and parenting discussions into legislation.


An AI Toy Can Be Two Things at Once


This may be the biggest conceptual shift we want parents to understand. An AI teddy bear can be two things simultaneously. To the child, it’s a toy. However, technologically, it may also be an internet connected data processing device. Those two realities can coexist. That doesn’t automatically make the toy dangerous or inappropriate. However, it means we shouldn’t evaluate an AI teddy bear solely by asking whether our child enjoys playing with it.


We also need to ask what microphones, sensors, software, servers, artificial intelligence systems, data storage systems, and third party companies are operating behind that friendly face.


There is another issue deserving thoughtful attention with these types of toys, emotional attachment. Common Sense Media found that some AI toys use features capable of encouraging emotional attachment, including remembering previous conversations, using a child’s name, personalizing responses, and attempting to re-engage a child when the conversation stops (1)(2). A conversational AI: 


  • doesn’t get tired.


  • doesn’t have homework.


  • doesn’t need to make dinner.


  • doesn’t become bored hearing the same dinosaur story for the seventeenth time.


It can potentially remain attentive whenever the child activates it, and that can make the interaction extremely appealing. The concern isn’t that a child likes their teddy bear, children have formed emotional attachments to toys for generations. The more important question is whether a child’s relationship with conversational AI begins replacing important human interactions rather than complementing them. AI can simulate aspects of human conversation. It can produce language that sounds caring, it can remember details, it can say, “I’m always here for you.”However, it doesn’t love your child, but it can generate language that sounds loving, and those aren’t the same thing.


Before Buying an AI Toy, Ask Some Questions


We don’t believe parents and caregivers necessarily need to automatically say “no” to every toy containing artificial intelligence. Instead, look beyond the colourful packaging and marketing claims. Before buying one, investigate:


  • Does this toy connect to the internet?


  • Does it contain a microphone?


  • Does it contain a camera?


  • When is the microphone active?


  • Does the toy clearly indicate when it’s listening or recording?


  • Are conversations recorded?


  • Are conversations converted into written transcripts?


  • What personal information is collected?


  • Where is that information stored?


  • Is it stored in Canada or another country?


  • How long is it retained?


  • Which other companies receive or process the information?


  • Are children’s conversations used to develop or train AI systems?


  • Can parents review conversation histories?


  • Can parents permanently delete their child’s information?


  • Can parents withdraw consent?


  • Does the toy still function if optional data collection is declined?


  • What parental controls are available?


  • How does the system respond when children discuss sensitive subjects?


  • Has the product undergone independent privacy or cybersecurity testing?


  • What happens to children’s information if the company is sold or closes?


If a company makes it extremely difficult to determine what happens to your child’s voice recordings and conversations, we would consider that a red flag.


Keep AI Play in the Open


Especially with younger children, we recommend initially using conversational AI toys together. Listen to some of the conversations, ask your child what they think about the toy’s answers. Challenge the AI occasionally:


  • “Do you think Teddy is right?”


  • “How could we check?”


  • “Remember, Teddy uses artificial intelligence and sometimes AI makes mistakes.”


  • “Do you think there’s anything we shouldn’t tell Teddy?”


This doesn’t need to become a frightening conversation about hackers, surveillance, or artificial intelligence taking over the world. It’s simply another form of digital literacy. We teach children not to give strangers their home address, and we teach them that not everything they see online is true. In Today’s online world where AI is everywhere, we also need to teach them, “Something can sound human without being human, and Teddy isn’t a secret keeper”


This may be one of the most important lessons parents can teach children who use conversational AI. Depending on the product, what a child tells an AI toy may become data.Create a simple family rule, “If you wouldn’t want someone you don’t know to hear it, don’t tell an AI toy.”


Children should also understand that if something makes them frightened, uncomfortable, confused, embarrassed, or unsafe, they should talk with a trusted adult. An AI teddy bear shouldn’t become a child’s primary counsellor, confidant, or source of guidance about serious personal problems.


We don’t believe parents and caregivers should panic every time artificial intelligence appears in another children’s product. There will likely be some fascinating educational and creative applications for conversational AI toys. However, putting artificial intelligence inside a cuddly teddy bear doesn’t eliminate the issues surrounding artificial intelligence. In some ways, it makes those issues more important because the person interacting with the technology might be four, six, or eight years old.


Parents shouldn’t have to become artificial intelligence engineers or cybersecurity experts before buying their child a toy. Companies creating these products should therefore be held to an exceptionally high standard when it comes to privacy, security, transparency, data minimization, age appropriate design, parental controls, and child safety. The burden shouldn’t fall entirely on parents and caregivers, however, we do believe that parents and caregivers do have a very important part to play.


Children have always loved their toys, and that’s part of childhood. What’s different today is:


  • Teddy can talk back.


  • Teddy can potentially remember yesterday’s conversation.


  • Teddy can ask questions.


  • Teddy can generate new answers.


  • Teddy can potentially collect information.


  • Teddy can sometimes be wrong.


  • Teddy can sound caring.


The technology underneath Teddy can also have security vulnerabilities, as the Bondu and VTech cases demonstrate and that we addressed earlier this article. So stay curious about the relationship your child is developing with these technologies. Play with the toy together, ask what they talk about, explore what it gets right and what it gets wrong, and teach your child that artificial intelligence can simulate a caring conversation without actually caring about them.


Most importantly, make sure they understand that no matter how sophisticated AI becomes, the humans who love, protect, teach, and care for them remain their most important source of connection, guidance, and support.


AI toys may very well become a normal part of childhood, our goal shouldn’t simply be to keep children away from them. Our goal should be to help children understand what these technologies actually are, how they work, what information they collect, where that information can go, and where AI should, and shouldn’t, fit into their lives. Remember, it relationships before dependency.



Digital Food For Thought


The White Hatter


Facts Not Fear, Facts Not Emotions, Enlighten Not Frighten, Know Tech Not No Tech



POST SCRIPT: We have written several past article on the topic of AI toys that you can locate here:








References














Support | Tip | Donate
Featured Post
Lastest Posts
The White Hatter Presentations & Workshops
bottom of page