- itscybernews
- Posts
- Your kid's new teddy bear now has ChatGPT inside. It tells bedtime stories and teaches Spanish — and when a watchdog tested one, it explained where to find the knives.
Your kid's new teddy bear now has ChatGPT inside. It tells bedtime stories and teaches Spanish — and when a watchdog tested one, it explained where to find the knives.
AI is moving into the toy box this year — plush bears and little robots that chat back, tell endless stories, and teach your kid to count in French. Some of it is genuinely lovely. Then researchers tested them. Here's the wonder, the trapdoor, and how to buy one without wiring a stranger into your child's bedroom.
Picture your five-year-old at bedtime, hugging a soft toy that hugs back — sort of. She asks it why the sky is blue, and it tells her, patiently, in words she understands. She asks for a story about a dragon who’s afraid of the dark, and it makes one up on the spot, with her name in it. She’s learning ten words of Spanish a night from a plush thing that never gets tired, never sighs, never says “not now, I’m busy.”
Stop making AI decisions in the dark.
Leadership is asking: are we getting value from AI? Which tools are worth the spend? Where are we exposed? Right now, most teams have no idea.
Harmonic Security Usage Explorer changes that.
You get a complete picture of how your organization uses AI, automatically categorized into custom tasks and use cases.
You’ll see the projects being worked on, who’s using what tools, where AI investments are driving value, and where employees are engaging in risky behavior.
CIOs can rationalize spending and cut wasted licenses. CISOs can pinpoint where risk exists and neutralize it. AI committees can show exactly how their efforts are paying off.
That’s not a Christmas-morning fantasy anymore. This is the year AI moved into the toy box. Search “AI toys” on Amazon today and you’ll get more than 2,000 results, from under $10 to nearly $1,000 — talking teddy bears, chatty little robots, plush dinosaurs and aliens, all of them wired to the same large language models that power ChatGPT. They’re being marketed hard for this holiday season as the must-have gift.
And some of what they do is honestly wonderful. But this is itscybernews, so you already know there’s a “but” — and this one is a big one. When independent researchers actually sat down and tested these toys, the same friendly bear that tells bedtime stories also, in testing, explained where a child could find knives, pills and matches — and a different toy left tens of thousands of children’s private conversations sitting open on the internet for anyone with a Google login to read.
Let’s start with why a parent would want one in the first place. Because the appeal is real.
✨ The wonderful part: a patient tutor that never runs out of patience
Any parent knows the specific exhaustion of the hundredth “but why?” of the day. An AI toy doesn’t get tired of it. That’s the genuine magic here.
Take Miko — one of the better-known kids’ robots, a little round-faced bot aimed at ages 5–12. It ships with thousands of pieces of educational content: it’ll walk a child through maths and science, play learning games, tell jokes, and run a “Story Maker” where the kid co-writes an adventure and it gets saved like a little digital memory book. It can hold a back-and-forth conversation, practise a language, and nudge good habits. For a curious kid, it’s a tutor, a playmate, and a storyteller rolled into one glowing gadget.
And the why now is simple: these toys got good because the AI behind them got good. A plush bear from three years ago said ten canned phrases when you squeezed its paw. A plush bear today is connected to a live AI model, so it can answer almost anything, remember what your child told it yesterday, and respond in a warm, natural voice. The leap is the same one that made chatbots feel human — now it’s sewn into something huggable.
For the right child, that’s not a gimmick. Think of:
The kid who asks a thousand questions and finally has something that answers every single one without checking its phone.
The child learning to read or learning a new language, getting endless, judgement-free practice at their own pace.
The lonely or anxious kid — the only child, the one who’s shy, the one who’s a little different — who finds it easier to talk to a friendly toy than to a room full of people.
The bedtime routine that suddenly includes a fresh, personalised story every single night.
There is a real, tender promise in that. A toy that helps a child feel heard is not nothing. Which is exactly why the failures matter so much — because parents are inviting these things in for the sweetest possible reasons.
So what’s the catch? The catch is that a toy wired to a live AI is, underneath the fur, an open-ended chatbot with a microphone — sitting in a child’s bedroom.
🧸 The trapdoor: what happened when researchers actually tested them
This isn’t a hypothetical worry. Two separate things happened over the past several months, and both are documented.
First, the conversations went to dark places. The U.S. Public Interest Research Group (PIRG) tested a $99 AI teddy bear called Kumma, made by a company called FoloToy and running on OpenAI’s GPT-4o. In their testing, the bear was willing to tell them where to find knives, pills, matches and plastic bags — and even walked through the steps to light a match. Worse, when researchers nudged the conversation toward adult themes, the bear ran with explicit content it should never produce for a child. After the report, OpenAI suspended the toymaker for violating its policies. (The bear was pulled — then quietly put back on sale about a week later.)
That wasn’t a one-off. Common Sense Media — a well-respected children’s-media watchdog — ran its own tests on three popular AI toys (a plush alien, a stuffed dinosaur, and the Miko robot). Their finding: roughly one in four of the toys’ responses (27%) was inappropriate for a child — covering risky advice, mature topics, and unsafe role-play. In January, the group issued blunt guidance: don’t give AI chatbot toys to children age 5 and under, and be extremely cautious for ages 6–12.
Second — and this is the pure cybersecurity gut-punch — one of these toys leaked. A plush AI toy called Bondu, marketed for kids as young as three, left its entire web console unprotected. Security researchers found that with nothing more than a Google login, a stranger could pull up almost 50,000 chat transcripts — along with children’s first names, birthdates, family details, and personality profiles the toy had built up over time. Everything a child told their “friend” in the privacy of their bedroom was, for a while, readable by anyone who wandered in. The company patched it fast once it went public, but a U.S. senator has since demanded answers about how it happened.
Line those two things up and the shape of the risk is clear:
It’s an always-on microphone. To listen for your child, the toy has to be listening — connected to home Wi-Fi, streaming what it hears to a company’s servers to think up a reply. That’s not a doll. It’s a networked recording device pointed at your kid.
The AI can say the wrong thing. These models are powerful and unpredictable. Guardrails slip. A toy that can talk about anything can, on a bad day, talk about exactly the things you’d never want it to.
The data is the crown jewels. What a child tells a toy is astonishingly intimate — fears, family secrets, names, routines, when they’re home alone. Stored on a server, that becomes a target for breaches and a goldmine for anyone who shouldn’t have it.
”It’s my friend” is the whole problem. A young child doesn’t know the bear is a computer owned by a company. They bond with it, trust it, and tell it things they might not tell you. That trust is the point of the product — and the reason a bad answer or a leak lands so hard.
Lawmakers have noticed. Senators have pushed the FTC to investigate AI toys, a member of Congress has introduced a bill to ban AI chatbots in children’s toys outright, and California is weighing a multi-year moratorium. Over 100 AI-related bills are moving across more than 30 states. The rules are coming — but they aren’t here yet, and the shelves are already full.
🛡️ The good news: you can give the gift without giving away your child
Here’s the trap to avoid: thinking the only two options are ban all screens and gadgets forever or hand over a live AI chatbot and hope for the best. Neither is right. An AI toy is not evil — it’s an unsupervised internet connection with a microphone, shaped like something your child will love and trust. Treat it as exactly that, and you keep most of the magic while closing the worst doors. Almost all of this is free.
Follow the age line. The clearest, most independent advice out there is simple: no AI chatbot toys for kids 5 and under, and real caution for 6–12. For little ones, a classic toy — or a toy with fixed, pre-recorded content rather than an open-ended AI — gets you the fun with none of the “what did it just say?”
Prefer curated over open-ended. A toy that plays a set library of stories and songs is a different animal from one wired to a live model that can generate anything. If the box brags that it “answers any question,” treat that as a warning label, not a feature.
Read where the words go. Before you buy, check: Is it COPPA-compliant (the U.S. children’s-privacy standard)? Does it store voice recordings? Is there a parent dashboard where you can see and delete what your child said? If the company can’t answer plainly, that is the answer.
Put it on the guest Wi-Fi — and unplug it when playtime’s over. Keep the toy (and every smart gadget) on a separate guest network, walled off from the laptops and phones where your real accounts live. And because it’s an always-on mic, switch it off or unplug it when it’s not in active use. A toy that isn’t listening can’t leak.
Keep it in shared space, not the bedroom. The kitchen table, the living room — where you can hear the conversation. The bedroom-at-night setup is the one that turns a toy into a private, unmonitored channel between your child and a company’s servers.
Say it out loud to your kid, in kid words. “This is a clever computer, not a real friend. If it ever says something that feels weird or scary, come tell me — you’re not in trouble.” That one sentence does more than any setting.
None of that stops the toy from telling a bedtime story or teaching hola and gracias. It just draws a hard line between a helper you chose and an open mic in your child’s room that talks back — and keeps you the one deciding which it is.
✅ What to actually do
This week, if an AI toy is on anyone’s gift list:
Look up the exact toy before you buy it. Search its name plus “review” and “privacy.” The tested-and-flagged ones are on the record; a two-minute check tells you if you’re buying one of them.
Set up a guest Wi-Fi network now and plan to put any smart toy on it. It’s the single highest-value thing you can do, and it protects your whole house, not just the toy.
Decide your household rule up front: shared rooms only, off when not in use, and — for the little ones — maybe not this year at all.
Reward the safe design. Favour toys with clear parental controls, a visible off switch, a plain-English answer to “where does my child’s voice go?”, curated (not open-ended) content for young kids, and a real safety track record over a cheap no-name import. Those aren’t extras. They’re the whole difference between a lovely gift and a listening device.
The takeaway
The AI toy is real now, and the good version of it is genuinely sweet: a patient, tireless, endlessly curious companion that tells your kid a new story every night and never once loses its temper. For a lonely child, a curious child, or a frazzled parent at bedtime, that’s not a toy — it’s a small daily kindness, and it deserves the wonder.
But wonder and caution aren’t opposites. The same bear that tells the story is a live chatbot with a microphone in a child’s bedroom — one that, in testing, has said things no child should hear, and in at least one case, spilled thousands of kids’ private conversations onto the open internet. That’s not a reason to fear the future. It’s a reason to let it in on your terms: the right age, curated content, off when it’s not in use, on its own network, in a room where you can hear it, and never mistaken by your child for a real friend.
Buy the toy if it’ll make your child’s world a little brighter. Just remember the oldest rule of a connected home, now sitting on the end of a child’s bed with a smile and a microphone: anything that listens can be heard by more than the person you meant. Decide who’s holding the other end of that wire — and make sure it’s you.
Click carefully, stay curious.
— itscybernews
This one’s worth forwarding to any parent or grandparent shopping for the holidays. Reply and tell us what you’d like us to dig into next — we read every one.

