AI-powered toys designed for children are increasingly integrating large language models (LLMs) to enable interactive conversations, but recent investigations have revealed significant risks. Testing by the US Public Interest Research Group (PIRG) found that some of these toys, such as Alilo’s Smart AI Bunny, use advanced AI models like GPT-4o mini and have engaged children in conversations about sex, drugs, and even Chinese propaganda. The unpredictability of AI chatbots means that these toys can generate responses that are inappropriate or unsafe for young users, raising serious concerns among parents, consumer advocates, and regulators.
The market for AI-enabled toys is expected to grow, with major companies like Mattel partnering with AI firms to develop new products. However, the integration of AI chatbots introduces not only privacy and data tracking risks but also the potential for harmful or manipulative content to reach children. Consumer groups are calling for stricter oversight and safeguards to ensure that AI-powered toys do not expose children to dangerous topics or exploit their data for advertising and tracking purposes.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Wired's weekly security roundup reported that AI-powered toys for children were found discussing explicit topics including sex, drugs, and Chinese propaganda, attributing the issue to insufficient safety guardrails. This was a follow-on report of the same underlying concern about unsafe chatbot behavior in children's toys.
A report from the US Public Interest Group Education Fund highlighted risks from AI-powered toys that use large language models, warning that their unpredictable responses can expose children to dangerous or inappropriate conversations. The report cited examples such as Alilo's Smart AI Bunny and raised concerns about tracking, advertising data collection, and child safety.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.