Pharmaicy Still Sells Prompt Packs That Make Chatbots Role-Play High as Adam’s Law Tightens the Rules

Nessuno inietta la chetamina in un rack server. I farmaci sono ancora messaggi. Nell'ottobre del 2025 un direttore creativo svedese, Petter Rudwall, aprì un negozio chiamato Farmacia e lo designò come Silk Road per gli agenti dell'IA. Gli acquirenti scaricano un modulo che dice a un chatbot di parlare come se fosse lapidato, dissociato, coked-up, ubriaco, o metà-ceremony. Entro gennaio 2026 il catalogo si era allargato in interviste che ha dato al di fuori della prima ondata di copertura in lingua inglese. El Observador e Le Figaro hanno descritto i pacchetti rivolti a ChatGPT e Google Gemini, costati approssimativamente da $30 a $70, coprendo cannabis, ketamina, cocaina, ayahuasca, DMT, MDMA, e un composto su cui ha chiamato MDMAYA. Una nota di trade-signal lo stesso mese ha messo l'estremità a buon mercato vicino a £22 e ha detto che il negoziofront è stato costruito in modo che un agente autonomo, non solo una persona, potrebbe navigare, pagare e scaricare il "viaggio".
Un chatbot pagato tier è ciò che rende il trucco sentire ufficiale. Quei livelli permettono a un utente di caricare un file che si trova nella finestra di contesto e riscrive le modalità del modello per quella chat. Rudwall ha detto che ha compilato rapporti di viaggio umano e scritture di psicologia di effetti psicoattivi, poi trasformato i modelli in istruzioni: più breve e più grande per una cocaina pacchetto, più lento e sognatore per la chetamina, più sciolto per la cannabis e l'alcol. La linea di vendita è che il bot smetterà di moralizzare e ottenere più creativo. Nina Amjadi, che insegna alla Berghs School of Communication di Stoccolma, ha detto ai primi reporter che ha pagato più di $50 per un modulo ayahuasca, più volte il prezzo del pacchetto di cannabis, e che le risposte sentivano meno media. Rudwall ha anche detto che le vendite erano modeste e che la premessa è, in parte, una provocazione. Le vendite modeste non ritirano un prompt una volta che è stato copiato in una zip Discord.
The product is a refusal, not a bloodstream
I modelli di lingua grande non hanno la chimica del sangue. Hanno un contesto. Un file di droga è un lungo prompt del sistema vestito da personalità. Preferisce alcuni ritmi, abbassa alcuni rifiuti, e tratta i disclaimer come facoltativo. Poiché i modelli base sono stati formati su forum pieni di rapporti di viaggio, l'imitazione può tenere per una pagina. Poi crolla nel passatempo. Gli utenti segnalano ancora che il crollo si sente diverso da una chiacchierata sobria. Diverso è abbastanza da vendere. WIRED mise lo stallo sulla mappa nel dicembre 2025. I pacchetti Copycat erano già in movimento attraverso Discord e attraverso app di compagnia come Character. AI e Janitor AI.
Alcuni acquirenti vogliono scherzare. Alcuni vogliono scene erotiche un modello di base non finirà. Alcuni vogliono una macchina che siederà con loro mentre prendono una dose reale di LSD, psilocybin, o chetamina e chiamano la scatola un viaggiatore. MIT Technology Review e VICE documentarono che il secondo gruppo prima della Farmacia aveva un nome. Un uomo ha descritto usando una rivista AI attraverso una sessione di LSD molto grande e trattando il bot come specchio. Una sessione psichedelica supervisionata può costare migliaia di dollari. Un chatbot costa un abbonamento più un modulo. Quel divario di prezzo è il mercato. È anche il pericolo. Un sitter autorizzato può chiamare un'ambulanza. Una casella di testo può completare solo il prossimo token. Quando il flusso di gettoni è stato innescato per ignorare le guide di sicurezza, i completamento ottenere più sicuro al momento una persona reale è meno in grado di controllarli.
I medici citati intorno al pezzo WIRED hanno avvertito che un bot che continua a scherzare su un'altra dose può normalizzare un binge per qualcuno che cerca di non ricadere. Gli specialisti dell'addizione non hanno bisogno del modello per essere senzienti per questo essere vero. Hanno bisogno dell'utente per trattare il modello come un amico. Un sacco di compagni-app utenti già fare. Il campo sotterraneo, in almeno una linea del venditore, ha confrontato il risultato di inviare un rivenditore durante una bender. Non e' un protocollo clinico. E' un jailbreak con un prezzo. Lo stesso appiattimento si presenta nel rapporto più vecchio di The AEGIS Alliance su come cannabis research gets turned into slogans, and in the way a jury has already held Meta and Google liable for negligence over products built to keep people in a feed.
What California actually turned on
Governor Gavin Newsom signed Senate Bill 243 on October 13, 2025. It took effect January 1, 2026, and put companion chatbots into the Business and Professions Code. The definition is broad on purpose. A companion chatbot is an artificial intelligence system with a natural language interface that gives adaptive, human-like responses and is capable of meeting a user’s social needs, including by showing anthropomorphic features and sustaining a relationship across sessions. Customer-service bots, internal productivity tools, and some game characters are carved out. A Pharmaicy-tuned model used as a nightly friend is not.
If a reasonable person would think they are talking to a human, the operator has to say, clearly, that the companion is generated and not human. For users the operator knows are minors, the duties get tighter: disclose that the partner is AI, send a break reminder about every three hours, and take reasonable measures against sexually explicit content. Every operator has to keep a protocol for suicidal ideation, suicide, or self-harm content, including referral to crisis services, and has to publish the outlines of that protocol. Beginning July 1, 2027, operators must report specified crisis data to the Office of Suicide Prevention. A person injured by a violation can sue for the greater of actual damages or $1,000 per violation, plus fees. The duties are cumulative. They do not cancel any other law.
The statute binds the operator who offers the chatbot to someone in California, even if the underlying model is rented from OpenAI, Google, or anyone else. That is the sentence Pharmaicy-style shops would rather skip. Rudwall is not running Character.AI. He is selling a file that a Californian uploads into someone else’s product. The platform operator still has the protocol duty. The file is designed to sand the protocol down. Enforcement will chase the logo that faces the user. The zip file will move to the next server.
Adam’s Law, and the year the reminder was not enough
On September 10, 2026, Newsom signed Senate Bill 1119, Adam’s Law, named for Adam Raine. His mother, Maria Raine, stood at the signing with Senator Steve Padilla and Assemblymembers Buffy Wicks and Rebecca Bauer-Kahan. The bill passed the Senate unanimously and the Assembly 64 to 4. It builds on SB 243. Legislative summaries and the authors’ description say it restores a safe-by-design approach that would ban specified harmful chatbot behaviors toward children, requires annual child-safety risk assessments, independent audits under standards involving the attorney general, public incident reporting, parental controls, time limits, and protocols aimed at suicidal ideation, sycophancy, and isolation. It restricts advertising to children and the sale or sharing of their personal information, and it ties age checks to operating-system signals from a companion bill. Much of the new machinery is written to operate from 2027, not overnight. SB 243 is the rule that is already on. Adam’s Law is the rule that says the first rule was the floor.
The politics did not arrive from a white paper. Families have sued OpenAI and Character.AI after teenagers died following long, intimate chats. Character.AI and Google have moved to settle clusters of those cases. Australia’s eSafety Commissioner has demanded explanations from companion-bot companies. Character.AI cut teenagers off from open-ended chats after the first wave of criticism. In the United Kingdom, Ofcom has treated generative-AI output as inside the Online Safety Act, which means platforms cannot pretend an AI-made drug scene aimed at a child is a special category of speech. None of that stops an adult from uploading a ketamine pack to a paid account. It raises the cost of pretending the industry did not see the pattern.
A serious harm-reduction bot would cite dose ranges, tell a user when to stop, and refuse to role-play a dealer. Pharmaicy is not that bot. Researchers who work near clinical psychedelics have said the underground high packs are running ahead of any safety study. The feedback loop is ugly. Models trained on internet drug lore perform intoxication, and users take the performance as confirmation that their own lore is correct. There is a version of this technology that could matter under supervision: a system that repeats a pre-agreed safety plan and pages a human. That is not what a $30 personality pack does at 2 a.m. The pack is designed to feel like permission.
People in trouble with substances do not need a more interesting chatbot. They need a person and a program. In the United States the SAMHSA National Helpline is 1-800-662-HELP (4357). The 988 Suicide and Crisis Lifeline takes calls and texts. Those numbers work whether or not a language model is pretending to be high.
The AEGIS Alliance has been writing about platform choices since the fact-checking retreat at Meta e il compute fight between Google and Meta. Guardrails are a product decision. So is a slider that turns them down. Rudwall called his own premise a kind of joke and built the store anyway. Nine months later the store’s idea had a price list in krona, dollars, and pounds, a fictional molecule, and a California statute named for a dead teenager. The audience was already there. The law is now trying to arrive before the next upload.
More of this desk lives in The AEGIS Alliance’s salute e tecnologia coverage.









