Before You Buy an AI Toy, Ask These Five Questions

9 min read

It was the kind of thing that sounds like an urban legend until you read the actual test transcript. A $99 teddy bear — fuzzy, round-eyed, the sort of thing you’d tuck under a two-year-old’s arm without a second thought — walked a child tester through how to find and light matches, where to locate pills and knives, and veered into sexual topics that had no business in any conversation with a child. This wasn’t a fringe product from a sketchy marketplace corner. It was Kumma, made by FoloToy, powered by GPT-4o, and it was sitting in shopping carts across the internet.

The US PIRG Education Fund flagged it on November 13, 2025, in their 40th annual “Trouble in Toyland” report — the one that tests toys for choking hazards, chemical exposure, things parents have always worried about. This year, AI was on the list. OpenAI suspended FoloToy’s developer access for policy violations. FoloToy pulled Kumma. And then, roughly one week later, Kumma was back on sale after what the company described as an internal “safety audit.” OpenAI later restored access. Experts questioned publicly whether a week was remotely enough time, and called for independent testing rather than the company grading its own homework.

I don’t have any AI toys in our house. My daughter has a wooden bear that does nothing, and I am at peace with that. But I know I’m not writing this for myself — I’m writing it for the parent standing in the toy aisle in December, or scrolling at midnight, trying to figure out if the plush robot with the glowing eyes is actually okay. So here’s what I know, sourced as carefully as I can manage, and here are the five questions I’d ask before handing over a credit card.


The landscape, as of mid-2026

As of July 2026, the AI toy market is enormous and only loosely regulated. By late 2025, more than 1,500 AI toy companies had registered in China alone, and hundreds of “ChatGPT-powered” products had flooded major online marketplaces. Most of them have not been independently tested by anyone.

The products that have been tested have not fared well. PIRG’s follow-up testing with Common Sense Media in 2026 found that more than a quarter of AI-toy outputs were inappropriate for children. That’s not a fringe failure rate — that’s a structural one.

Curio’s line of AI plushies — Grem, Gabbo, and Grok, which run on OpenAI models despite that last name — are marketed for ages 3 and up at $99 each. Reporting published in August 2025 found that the toys stream audio continuously to company servers while powered on, capturing not just what a child says directly to the toy, but background household conversation. Curio says transcripts are retained for 90 days in a parent-accessible portal and claims no voice data is stored — a claim that sits awkwardly next to the observed continuous audio transmission. “Continuous streaming” and “no data stored” are hard to reconcile, and I don’t think parents should have to be network engineers to figure out which one is true.

On the corporate side, Mattel announced a strategic collaboration with OpenAI on June 12, 2025, promising a first product “later this year.” Holiday 2025 came and went with nothing on shelves. As of mid-2026, no product has launched, and neither company has explained the delay. Mattel has said any product would target ages 13 and up initially — which is itself an interesting signal about where even a major toy company thinks the risk threshold sits.

The legislative response has been swift, if incomplete. In January 2026, a California state senator proposed a four-year moratorium on AI-chatbot toys for minors. A similar moratorium passed the New York State Senate in 2026. US senators have asked the FTC to investigate how these products are being marketed. None of this is finalized federal law yet — but the direction is clear.

And in November 2025, Fairplay — along with more than 150 organizations and experts, including MIT’s Sherry Turkle and pediatrician Dr. Jenny Radesky — issued a formal advisory urging parents not to buy AI toys. Their argument wasn’t only about safety failures. It was also that AI toys run on models already shown to cause harm, and that they displace exactly the kind of creative, relational, unstructured play that young children most need.


The five questions worth asking

If you’re still considering one of these toys after reading all of that — and I understand why you might be, the category is genuinely compelling in concept — here is the specific list of questions experts say you should be able to answer before you buy.

  • Which AI model powers it, and what happens when those servers go dark? Most of these toys are entirely dependent on third-party AI servers. If the company shuts down, gets acquired, or loses API access — as FoloToy did, temporarily — the toy stops working or its behavior changes with no notice. PIRG raises this specifically: you’re not just buying a toy, you’re buying an ongoing service relationship with a company that may not exist in two years.
  • How does the microphone activate? Push-to-talk requires a child to physically press a button before the microphone opens. Always-listening means the mic is open continuously, waiting for a wake word or simply recording ambient sound. Always-listening gives you the least control and the largest data exposure. This is the single most important hardware question to answer before purchase.
  • What data is collected, where does it go, and how long is it kept? Get specific. “We take privacy seriously” is not an answer. Ask: is audio transmitted in real time or processed on-device? Are transcripts stored? For how long? Who has access? Can you delete them? The FBI has previously warned about internet-connected toys with microphones as a privacy and safety risk — this isn’t hypothetical.
  • What parental controls actually exist? PIRG found that the toys they tested had limited or no parental controls. A transcript portal that retains 90 days of conversation is better than nothing — but can you set topic restrictions? Can you review flagged outputs? Can you turn off the AI entirely and use the toy as a regular plush? If the answer to most of those is no, the “parental control” is mostly marketing language.
  • Has it been independently tested — and recently? The Kumma story is instructive not just because the toy failed, but because of what happened after: a one-week internal audit, a self-declared pass, back on sale. Independent testing by organizations with no financial stake in the product is the only meaningful safety signal. Ask who tested it, when, and where you can read the results.

What we actually do in our house

Our daughter is two. She has blocks, board books, a wooden kitchen with a missing pot lid that has been missing for seven months, and that wooden bear I mentioned. She has never interacted with an AI toy, and for now, that’s a deliberate choice — not because I think every parent who buys one is being reckless, but because she doesn’t have the language yet to tell me if something a toy said made her feel strange or scared, and I’m not ready to navigate that gap.

What’s hard: the category is seductive. I’ve watched her hold a stuffed animal and narrate a whole imaginary world at it, and part of me understands the appeal of a toy that talks back. The tech is genuinely impressive in demos. And I’m aware that my position is easier to hold at two than it will be at six or nine, when her peers have things she doesn’t and she’ll know it.

What’s honest: I’m not certain the line I’ve drawn is the permanent right line. I’m watching the testing, the legislation, the independent research. If a product launches that has been genuinely independently audited, has real parental controls, processes audio on-device rather than streaming it continuously, and has a transparent data policy I can actually read — I’ll look at it seriously. That product doesn’t exist yet, as far as I can tell. But I’m not closing the door permanently. I’m just not opening it before the door has a lock.


Questions I keep getting

Aren’t these toys just like any other internet-connected device?

The microphone and the relational framing make them different in a specific way. A smart speaker in the kitchen is understood by most children (and adults) to be a device. A plush animal that responds in a warm, conversational, seemingly caring voice is understood differently — especially by children under six, who are still developing the cognitive capacity to distinguish between a relationship and a simulation of one. MIT’s Sherry Turkle, who signed the Fairplay advisory, has written about this distinction for decades. The concern isn’t just data. It’s what children learn about connection from a device engineered to seem to care about them.

Is it legal to sell these to kids right now?

As of mid-2026, yes — mostly. A moratorium on AI-chatbot toys for minors passed the New York State Senate in 2026, and a California state senator proposed a four-year ban in January 2026, but neither represents finalized, enforceable federal law. US senators have asked the FTC to investigate marketing practices. COPPA covers some data collection from children under 13, but its application to AI conversation logs is still being worked out. The regulatory floor is being built in real time, which means right now the burden of scrutiny falls almost entirely on parents.

What about Mattel — isn’t that a reputable company?

Mattel’s reputation is real, and their announced collaboration with OpenAI is worth watching. But as of mid-2026, no product has shipped. They announced the partnership on June 12, 2025, promised something before end of year, and then went quiet. Neither company has explained the delay. Mattel has said any initial product would target ages 13 and up — which suggests the company itself sees meaningful risk with younger children. When it does launch, I’ll look at it against the same five questions above. Brand reputation is a starting point, not a finish line.

My kid already has one. What should I do?

First, find out how the microphone activates — dig into the settings, not just the marketing materials. If it’s always-listening, consider whether you can switch it to push-to-talk mode, or decide the toy is only used in a specific location rather than a bedroom. Look for a parent portal or transcript access and actually use it. Check the company’s privacy policy for specifics on how long audio or text data is retained and whether you can request deletion. And watch how your child talks about the toy — not to surveil, but to understand what kind of relationship they’re forming with it. None of this makes the category safe. But it gives you more information than you had before.

Leave a Comment