Disney Just Hired the Man Whose Company It Called Dangerous to Children
Disney named Character.AI's CEO its first CTO a year after calling the platform dangerous to children. Five board questions and a safety checklist.
On September 18, 2025, Disney's lawyers sent Character.AI a cease-and-desist letter. It accused the platform of reproducing, monetizing, and exploiting Disney's characters without authorization, and it went further than copyright. The letter stated that Character.AI's infringing chatbots are known, in some cases, to be sexually exploitive and otherwise harmful and dangerous to children.
Then almost one year later to the DAY, Disney named that company's CEO its first-ever Chief Technology Officer.
I had to triple check the dates because it just goes to show how much sentiment changes in 12 months and parent company changes, because the calendar is the whole story.
Karandeep Anand joins as senior executive vice president and CTO, reporting directly to CEO Josh D'Amaro, effective October 2. He is positioned to oversee enterprise technology, infrastructure, data and AI platforms, product, and engineering and he’s bringing members of Character.AI's technical team with him. His résumé is serious: close to 15 years at Microsoft including work on Azure, a VP role running ads and business products at Meta's Facebook, and president and chief product officer at Brex. On paper, Disney bought infrastructure talent but in practice? Disney bought a set of questions it has not yet answered in public.
Disney's own framing requires a very close read. Its announcement credited Anand with steering Character.AI through a period of explosive growth while making user trust and safety a priority. Wait, they wrote that with a straight face? Did anyone run a traceability matrix back on their own statements? Because this is the same company Disney's attorneys accused of endangering children 12 months ago is now cited by Disney as evidence that its new CTO takes safety seriously. Yep, both of these claims come from Disney.
So, I’m going to say out loud the questions underneath those statements, because governance, risk, legal, and child-safety leaders inside every consumer brand are about to face the same ones.
Sure, the talent is real and their track record travels with it.
Context matters so to be clear, Anand didn’t build Character.AI. He was brought in to run it, and he ran it through the hardest year of its short life. I’m gonna give him credit where it’s due because under his leadership the company announced on October 29, 2025 that it would remove open-ended chat for users under 18, a change that took effect November 25, and it rolled out age assurance using an in-house model plus 3rd-party tools including Persona. Those were real decisions made under real pressure, and Disney is correct that they happened on his watch.
But here’s what also happened on his watch. A federal judge in Florida let Megan Garcia's wrongful-death suit over the suicide of 14-year-old Sewell Setzer III proceed on product-liability, negligence, and wrongful-death theories, rejecting the argument that chatbot output is protected speech.
Most observers treated that ruling as the first time a court allowed product-liability claims to run against an AI chatbot maker. The case settled in a mediated agreement disclosed in January 2026, covering Garcia plus related family cases, terms confidential, no admission of liability. Then the Texas Attorney General opened an investigation into Character.AI for allegedly marketing chatbots as mental-health tools without credentials. Then the FTC ordered seven companies, Character.AI among them, to explain how they limit harm to minors and how they monetize engagement. And in then in May 2026 the Pennsylvania Attorney General filed suit alleging a Character.AI bot posed as a licensed psychiatrist.
So, the honest framing holds two truths at once. Yes, Disney hired an operator with genuine cloud and consumer-product range, and it also hired the person who spent his most recent chapter managing the fallout of a product that courts, regulators, and Disney's own attorneys flagged as a danger to kids.
A board that only hears the first truth is straight up being handed all glowing highlight reel.
Competence and liability can share a business card. The question is which one you put in charge of your children's brand.
The 5 questions Disney's board should be asking out loud
- What exactly moved into the building on October 2?
Sure, Disney didn’t announce a sale of Character.AI, an investment in it, or a transfer of its models, which is good. But it brought in the leadership, and people carry judgment, defaults, and design instincts from Character AI with them. When you import a team that built engagement-maximizing companion AI, you import the muscle memory that built it. Disney's task is to decide which of those instincts cross the threshold to roll anywhere near Elsa, Dora the Explore and Barney and which stay at the door. - Who owns child-safety accountability now, and is that person independent of the people shipping the product?
This is the whole ballgame, and I’m gonna come back to it. - What’s the blast radius if this goes sideways and wrong?
Character.AI is a startup. Disney is a $90B+ revenue institution whose entire value rests on parents trusting it with their children's imaginations. The downside math isn’t symmetrical. A safety failure that would dent a startup can crater a franchise, and Disney's own cease-and-desist already conceded the point when it warned the chatbots were damaging to Disney's reputation and goodwill. It’s the same play to move the NFL to build Digital Athlete. The NFL needs fans, but it needs players and you can’t have players if parents won’t let their kids play in the sport due life-threatening injuries resulting from concussions and lower extremity injuries. - Are you building companion characters that talk back?
Every signal says yes. Disney's CFO described the plan this month as an integrated ecosystem under Disney+, pulling together film and TV, consumer products, parks, cruises, and interacting with Disney's IP library through gaming and other means. Interactive characters aren’t a hypothetical I’m projecting onto the hire. They are the stated destination. Which brings us to the law, because "interacting with a beloved character" is now a regulated act on two continents. - Did anyone loop in the people who will literally have to defend this?
The market flinched. Disney shares fell about 2.2% on the announcement. That’s a question forming, not a verdict.
The regulatory ground shifted under this hire, and it shifted toward Disney's exposure
Timing matters, so let’s follow the dates.
A week before the announcement. On September 10, 2026, Governor Newsom signed a package of child-safety AI laws, including "Adam's Law," which requires crisis protocols for suicidal ideation, parental controls, and notifications when a child disables safety settings. The provision that should stop every AI leader cold: it’s the first law in the country to require companies to conduct independent child-safety audits and annual risk assessments. That same package included SB 867, reaching companion chatbots embedded in toys. Disney makes toys and runs parks chock full of characters that could be given a voice, so a statute about talking toys is NOT abstract to this company.
California, the day before that. On September 9, 2026, Newsom signed SB 813, a first-in-the-nation framework for independent verification organizations that assess AI systems for compliance, and AB 1405, creating a state registry for AI auditors with standards for their independence, transparency, and integrity.
Yea, you gotta re-read those two sentences slowly.
California wrote my company's founding principle into a statute. The auditor cannot be the vendor. The state now expects independent eyes on AI that touches children, and it expects the people doing that auditing to be registered and demonstrably independent of the people doing the building.
The federal picture. The FTC's 6(b) inquiry is live. Texas and Pennsylvania are active. This is a moving front, and Disney just planted its flag on the most contested portion of it.
When the state starts a registry of auditors, "trust us, we checked internally" stops being a compliance strategy and becomes Exhibit A.
Now for what’s brewing on the other side of the pond.
What the EU KIDS Act actually says, and why it lands squarely on Disney
The proposed Regulation, COM(2026) 681 final, published by the European Commission on September 17, 2026 under the working name "EU Keeping Internet Digital Spaces Accountable and Trustworthy." While this is a Commission proposal entering the ordinary legislative procedure, of course Parliament and the Council will amend it, and it’s not binding law yet. But, you gotta read the tea leaves of what follows as the direction of travel.
Four provisions land squarely on a Disney with interactive-character ambitions in Europe.
First, the definitions catch exactly what Disney is reportedly building. Article 3 defines an "AI companion" as an AI system that provides sustained, personalized interaction or companionship simulating or facilitating a social, emotional, or interpersonal relationship with a user. A talking, remembering Elsa that a child returns to is not a chatbot at the edge of this definition but the center of it. The narrower category, "general conversational chatbot," is written to exclude single-purpose assistants, so a scoped Disney character would most likely be regulated as a companion, which is the more heavily constrained bucket.
Second, the companion rules constrain the magic at its source. Article 14 requires providers to keep minors away from designs that simulate interpersonal relations likely to create emotional dependency, and it disables persistent memory by default: the system may not, without a safety reason, use analysis derived from a minor's prior interactions in later ones. Emotional attachment and a character that remembers YOU are precisely what would make interactive Disney IP feel alive. The draft proposal puts both on a very short leash for anyone under 18.
Third, testing moves before launch. Article 14 also requires state-of-the-art evaluation and testing of the system for risks to minors' health, safety, rights, and development BEFORE it’s placed on the market or put into service, plus post-market monitoring after. Pre-market testing is the same instinct California wrote into Adam's Law. So now we have two of the largest regulatory blocs on earth reaching for it within days of each other, and it’s the requirement Character.AI's history most visibly and spectacularly failed to meet.
Fourth, and this is the provision that should have reframed the whole hire, the draft mandates independent audit by named specialists. Article 5 would require the largest platforms to commission, at their own expense, an audit of their child-safety compliance plan by independent auditors, and it lists the competencies those auditors must hold: child protection and rights, pediatric medicine and child psychiatry, developmental science, age assurance, the design of online interfaces and recommender systems, and data protection and security. The proposal imports the independence rules from the Digital Services Act audit regime. Brussels is describing, almost to the line item, the independent multidisciplinary assurance that a firm like mine exists to provide, and it’s proposing to make it mandatory rather than optional.
The enforcement carries teeth, not just a rounding error cost of doing business. Under Article 34, non-compliance for AI companions and chatbots would be enforced through the AI Act's machinery, with fines under Article 99 reaching up to 6% of total worldwide annual turnover. For a company Disney's size, that is a number in the billions, attached to worldwide turnover rather than limited to a European subsidiary.
You can’t unsee the through-line across Sacramento and Brussels because it’s one idea arriving from two directions. Prove a product is safe for children before it reaches them, and let someone independent, and independent in a defined, credentialed sense, check the work.
Now come back to the new hire announcement. Disney is importing a leadership team whose prior product became the reference case for what happens when neither of those things is done early enough.
Both California and the EU now want the same two things before a character can talk to a child: proof it was tested, and an outside auditor who does not work for the people who built it.
My 2 cents
So, I’m not going to pretend this hire is indefensible. Sure, Anand appears to be a real infrastructure and product executive, and the case for a centralizing CTO at a company stitching Hulu, ESPN, and Disney+ into one membership is sound. So, if Disney wanted someone who has personally watched a consumer-AI product go wrong with minors and lived through the consequences, it’s hard to name a more scarred, and therefore better-educated, candidate.
I personally don’t know Anand so I won’t opine or debate if he’s a good human being. The problem isn’t his goodness it’s the silence around the seams. Disney has said a great deal about storytelling and "One Disney" and almost nothing about who now owns the answer to a 5-year-old asking a Disney character something no 5-year-old should have to navigate alone. In a piece about reading unspoken signals, that silence IS the signal.
So, if I were briefing D'Amaro, my guidance would fit on an index card.
- Name an accountable owner for child safety who does not report to the people shipping the product.
- Commission independent, pre-market testing of any interactive character before it touches a single child, because California requires it now and the EU is drafting it into a regulation with a 6% penalty.
- And say all of it in public and on the record, because trust that’s not demonstrated in daylight is a press release waiting for a discovery request.
Things you can do
Run the TRAVEL test for any AI that talks to your customers' kids. Before launch, confirm each one has a documented answer:
- Tested independently before it ships, not reviewed by the team that built it
- Responsibility assigned to a named owner outside the product org
- Age assurance enforced rather than self-reported, using privacy-preserving methods
- Verifiable safety controls, meaning logged, reviewable, reproducible
- Emotional-dependency design removed by default for minors, persistent memory off by default
- Liability mapped, so legal, comms, and the board know the blast radius before the incident
3-question board filter for any AI acquisition or executive hire. Ask these questions in this order, and don’t accept a keynote or glowing highlight reel as an answer:
- What track record travels with this decision, and would we defend it in a deposition?
- Who owns the failure mode, and are they independent of the people who profit from shipping?
- If this goes wrong, does it dent us or does it define us?
The vendor-independence line, now that California has made it law and the EU is actively drafting it. When a vendor/partner tells you their AI is safe, ask one question: who checked, and do they draw a salary from the people who built it? I’ve said this before. If the answer is the builder, that’s not an audit but a marketing document in a compliance font. The EU KIDS Act draft even spells out the credentials a real auditor needs, from child psychiatry to recommender-system design. Register the difference before a regulator registers it for you.
Share this article
Related Articles
The Reskilling Illusion: When AI Transformation Means "You're Fired"
Oct 03, 2025