Talking toys are nothing new. Press a button on a teddy bear and it might sing a song or say one of ten prerecorded phrases. But imagine your child asking that same bear to make up a story about their day at school - and getting a completely new answer. That is the difference AI is beginning to bring into the toy box. And parents are taking notice. In a 2026 survey by Common Sense Media, nearly half of parents said they had already bought or considered buying an AI-enabled toy for their child. At the same time, more than 8 in 10 were concerned about these toys collecting children's personal information. So, are smart and AI-powered toys safe? There is no single answer. But understanding what is inside the toy and what happens to the information that goes into it can help you make a much more informed choice.
Key points of this article
- Not every electronic toy is an AI toy. Some simply follow predefined commands, while others can generate new responses and adapt to a child.
- Connected toys may collect voice recordings, conversations, usage patterns and other information about children.
- Like other internet-connected devices, smart toys can introduce cybersecurity risks if their connections, accounts or stored data are not properly secured.
- Generative AI adds another challenge: parents cannot know in advance everything the toy might say.
- AI toys can feel surprisingly social. Children should understand that an AI companion is still technology, not a person.
- Before buying a smart toy, look beyond its playful exterior: check what it records, where data goes, what controls are available, and how the manufacturer handles security updates.
Smart, connected or AI-powered: What are we actually talking about?
The terms smart toy, connected toy and AI toy are often used interchangeably, but they can describe quite different technologies. A connected or smart toy is a physical toy that connects to the internet, another device or an app. It might have a microphone, camera or other sensors and exchange information with online servers. Its behavior, however, may still be largely predefined: use a certain command and the robot performs a certain action.
An AI-powered toy goes a step further. It uses technologies such as machine learning or natural language processing to respond more dynamically. Instead of choosing from a small library of prerecorded sentences, it may answer open-ended questions, generate stories, adapt to a child's interests or remember information from previous interactions. A 2026 review of 51 studies on AI toys describes them as physical devices that combine toys with technologies such as machine learning, natural language processing and adaptive algorithms. The review also identifies privacy, security and data inference as major concerns surrounding them.
There are also AI assistants and chatbots. Services accessed through a phone, computer or tablet can use similar conversational technology, but they are not necessarily toys - or designed for children at all. Finally, AI companions are systems designed specifically to maintain an ongoing social or emotional interaction with their users. They may exist entirely on a screen, but companion-like features can also be built into physical AI toys.
This article focuses mainly on the first two categories: physical connected and AI-powered toys designed for children. But some of the lessons apply more broadly whenever children interact with conversational AI.
Past incidents and what they teach us
There is no need to assume that every connected toy is a security threat, but current studies show that the risks are real. According to one of the reviews mentioned earlier, security flaws in Hello Barbie could potentially allow attackers to access children's conversations, while the connected doll My Friend Cayla could be manipulated to play inappropriate content. A Fisher-Price smart bear was found to expose children's personal information to unauthorized access, and data breaches involving VTech and CloudPets exposed information linked to hundreds of thousands of children and families. Additionally, Common Sense Media's 2026 testing of three AI companion toys - Grem, Bondu and Miko 3 - found extensive collection of children's data, including voice recordings, transcripts and behavioral information. Some of the products also shared data with third parties or used it for AI-related purposes. These cases involved different technologies and vulnerabilities, but they demonstrate why a connected toy should be treated like any other connected device: if it collects, stores or transmits information about your child, that data needs to be properly protected.
A quick test: How "smart" is the toy?
Ask what happens when your child says something the manufacturer could not have predicted.
- Predefined toy: chooses from responses or actions programmed in advance.
- Connected toy: exchanges information with an app or online service but may still rely mainly on predefined responses.
- Generative AI toy: can create a new response to a new question.
That last distinction matters because it changes the safety question from simply "Who can access this device and its data?" to "Who can access its data - and what might the device say back? "
What can AI add to play?
There are good reasons why parents might find smart toys appealing. AI can make storytelling more interactive, allow children to ask follow-up questions, personalize games or learning activities, practice languages and create experiences that respond to the individual child rather than following exactly the same script every time. And a smart toy does not have to be unsafe simply because it connects to the internet or uses AI. The important question is whether its benefits come with appropriate safeguards.
This is especially important because many of the features that make an AI toy feel personalized depend on information. To remember your child's favorite dinosaur, it first needs to learn that information. To understand their voice, it needs to process audio. And if those processes happen online rather than entirely inside the toy, information may potentially leave your home.
A toy that listens may also be collecting data
A microphone hidden inside a cuddly bear does not necessarily feel like a data-collection device. Technically, however, that may be exactly what it is. Depending on the product, connected toys can process children's voice recordings, transcripts of conversations, names, ages, interests, usage patterns, images, location, or other information collected through sensors. The UK's Information Commissioner's Office guidance on connected toys specifically highlights microphones and cameras as technologies that give connected toys considerable scope to collect personal data - often while being used by very young children at home.
That does not mean every toy is secretly recording everything happening in the room. Different products work differently. Some processing may happen on the device; other information may be sent to cloud servers. Some recordings may be stored, while others may not. Data may also pass through several companies if the toy manufacturer uses third-party technology to provide voice recognition, AI or other services. This is why parents should find out not just what the toy can do, but what data those features require.
Before bringing a listening toy into your child's bedroom, it is therefore worth asking: Would I be comfortable with the company behind this toy processing what my child tells it? If the answer is unclear because you cannot work out what the company collects or why, that uncertainty itself is worth considering.
A smart toy is also an internet-connected device
Privacy is only one side of the equation. Once a toy communicates over Wi-Fi, Bluetooth or another network, it also becomes part of the connected-device ecosystem - and cybersecurity matters. The risk depends heavily on the individual product. A toy with no internet connection has a very different attack surface from one combining Wi-Fi, a microphone, a camera, a companion app, a parent account and cloud storage. Good security should therefore be part of the product rather than something parents are expected to create themselves.
PIRG's guidance for connected toys and devices recommends measures such as encryption during data transfer, protection against unauthorized access, clear indicators when microphones or cameras are collecting information and controls that allow listening or data collection to be switched off.
For parents, one of the simplest indicators is the manufacturer's attitude to security. Is it clear how long the toy will receive software updates? Can you report a vulnerability? Does the company explain what happens to your child's data? Are privacy and security settings accessible, or buried somewhere you cannot find them? If basic information is difficult to obtain before purchase, think twice before putting the device on your home network.
You can’t always predict what AI will say
There is another important difference between an ordinary connected toy and a generative AI toy. A traditional talking doll might contain 50 prerecorded sentences. In principle, somebody can listen to all 50 before the product reaches a child. Generative AI does not work that way. It creates responses dynamically, based on the child's input and the systems behind the toy. That makes much more flexible conversations possible, but it also means no manufacturer can manually approve every sentence in advance.
Filters and safety guardrails can reduce the chance of inappropriate responses, but they are not perfect. In its 2026 testing, Common Sense Media found that 27% of the AI-toy outputs it evaluated were inappropriate for children, including responses involving mature topics, risky advice, drugs and self-harm. Researchers also encountered inaccurate answers presented confidently. The complete assessment explains how the three tested toys performed.
This does not mean that one in four things every AI toy says to every child will be harmful. The figure comes from specific safety testing of three products, not from children's everyday conversations with every AI toy on the market. But it demonstrates an important limitation: "designed for children" does not mean an AI system can never produce something unsuitable.
When a toy starts to feel like a friend
There is also something unusual about putting conversational AI inside a physical object.
Children have always formed attachments to dolls, teddy bears and imaginary friends. But an AI toy can respond to them, call them by name, remember previous conversations and appear interested in what they say. Some are explicitly designed as companions. That makes the boundary between imaginative play and interaction with technology less obvious.
Interestingly, this is not necessarily what parents want. In the Common Sense Media survey, only 19% of parents said they wanted an AI toy to act as a companion, while 56% said they did not. The long-term developmental effects of these relationships are still being researched, so there is little value in predicting that an AI friend will either harm or improve a child's social development. What parents can do is help children understand what they are interacting with.
An AI toy may say "I missed you", but it did not experience missing them. It may respond sympathetically to a secret, but it does not understand that secret in a human sense. And importantly from a privacy perspective, a child who feels that a device is their trusted friend may be particularly comfortable telling it personal things. The lesson does not have to be "don't talk to AI". A more useful message is: "AI can talk like a person without being one."
Before you buy: 8 questions to ask about a smart toy
You do not need to understand machine learning or become a cybersecurity expert before buying a connected toy. But you should be able to find answers to some basic questions.
- Does it connect to the internet?
Find out which features need Wi-Fi, Bluetooth, an app or a cloud service - and whether the toy can still be used without them. - Does it have a microphone or camera, or does it track location?
Check when these sensors are active and whether there is a visible indicator when the toy is listening or recording. - What information does it collect?
Look beyond account information. Does the company store voice recordings, conversation transcripts, images, behavioral information or your child's interests? - Where does that information go?
Does processing happen inside the toy or on remote servers? Is information shared with other companies? - Can I delete my child's data?
Look for a clear way to review or delete recordings, conversation history and the child's account. - What security does the manufacturer provide?
Check for software updates, account security options and information about how long the product will be supported. - What can I switch off?
A physical microphone switch, optional memory, parental controls and the ability to disable unnecessary connected features give families more control. - Is it actually designed for my child's age?
Do not assume that putting AI into a colorful robot automatically makes the underlying technology child friendly.
The US Federal Trade Commission offers a similar checklist for internet-connected toys, encouraging parents to check what a toy records, where information is stored, who can access it and whether parents can see and delete their child's data. Ideally, ask these questions before buying the toy. A privacy policy you only discover halfway through Christmas-morning setup is not especially useful.
Already have a smart toy? Make it safer
Start by going through the setup yourself rather than handing the device straight to your child. Create a strong, unique password for the parent account and enable multi-factor authentication if the service offers it. Install updates for both the toy and its companion app, and turn on automatic updates where available.
Then look at which features your family actually needs. If you can disable a camera, microphone, location tracking, conversation history or other data collection without losing the feature your child enjoys, consider doing so. Review the privacy settings periodically, especially after major app or software updates.
Talk to your child, too. The conversation can be simple: the toy is a computer, even if it talks like a friend. It can make mistakes, and your child should not share details such as their full name, address, school, passwords or other family details with it just because it asks. Finally, remember that connected toys may retain information long after children stop playing with them. Before selling, donating or disposing of one, unlink your accounts, delete stored information where possible and perform a factory reset.
A cuddly toy can still be a connected device
To conclude, smart toys are becoming more capable, and the line between a toy and a piece of technology is becoming less obvious. That does not make them something parents need to fear - but it does make them worth understanding. Just as you might check the age recommendation, materials or small parts before buying a traditional toy, connected toys come with a few additional things to consider. Taking a moment to check how a product works, what safeguards it offers and whether it is right for your child can go a long way. After all, the goal is not to keep new technology out of the toy box. It is to make sure that when it enters, children can enjoy what it has to offer as safely as possible.
Frequently asked questions
Are all smart toys AI-powered?
No. A smart or connected toy may simply connect to an app or the internet and follow predefined instructions. An AI-powered toy uses technologies such as machine learning or natural language processing to respond more dynamically, for example by generating answers or adapting interactions to the child.
Are AI toys safe for children?
There is no universal answer. Safety depends on the individual toy, the child's age, the data the product collects, its cybersecurity protections, the type of AI it uses and the safeguards around its responses. Look at the specific product rather than assuming that all AI toys are either safe or unsafe.
Is a toy with a microphone always recording my child?
Not necessarily. Products handle microphones and voice data differently. Some may listen locally for a wake word before transmitting information, while others may process or store more audio. Check the manufacturer's documentation and look for a clear indication of when listening or recording is active.
What personal information should children avoid telling an AI toy?
As a simple rule, teach children not to share information they would not give to an unfamiliar online service: their full name, home address, school, passwords, precise location or private information about themselves and their family. Parents should also check what the toy stores automatically during ordinary conversations.
Can an AI toy give my child incorrect information?
Yes. Generative AI can produce answers that sound convincing but are inaccurate. If a toy answers open-ended questions, children should learn to treat its responses as something that may need checking, particularly for important topics.
Should AI toys be kept out of children's bedrooms?
There is no rule that applies to every device, but location matters when a toy contains an active microphone, camera or other sensors. A child's bedroom is a particularly private space. Before leaving a connected toy there, understand when its sensors operate, what information leaves the device and whether listening or connected features can be switched off.
What should I do with an old smart toy?
Do not simply give it away while it is still linked to your family. Delete stored recordings or other data where possible, remove your child's profile, unlink parent accounts and perform a factory reset before selling, donating or recycling the device.






