[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[H.R. 9619 Introduced in House (IH)]
<DOC>
119th CONGRESS
2d Session
H. R. 9619
To require artificial intelligence chatbot providers to provide data
privacy and security, and for other purposes.
_______________________________________________________________________
IN THE HOUSE OF REPRESENTATIVES
July 9, 2026
Mrs. Foushee (for herself and Mr. Casar) introduced the following bill;
which was referred to the Committee on Energy and Commerce
_______________________________________________________________________
A BILL
To require artificial intelligence chatbot providers to provide data
privacy and security, and for other purposes.
Be it enacted by the Senate and House of Representatives of the
United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the ``People-First Chatbot Act''.
SEC. 2. PROHIBITIONS AND REQUIREMENTS.
(a) Data Privacy and Security.--
(1) Prohibitions.--An artificial intelligence chatbot
provider may not do the following:
(A) Process personal data other than input data to
inform chatbot outputs unless the processing of
personal data is necessary to fulfill an express
request made by a user and that user has provided
affirmative consent.
(B) Process the chat log of a user as follows:
(i) To determine whether to display an
advertisement for a product or service to the
user.
(ii) To determine a product, service, or
category of product or service to advertise to
the user.
(iii) To customize an advertisement or how
an advertisement is presented to the user.
(C) Process the chat log or personal data of a user
(unless the personal data is the age of the user, but
only to implement the policies of the artificial
intelligence chatbot provider, regarding harmful design
features for minors) as follows:
(i) If the artificial intelligence chatbot
provider knows or should know, based on
knowledge fairly implied on the basis of
objective circumstances, that the user is under
the age of 18, without the affirmative consent
of the parent or legal guardian of that user.
(ii) For training purposes, if the
artificial intelligence chatbot provider knows
or should know, based on knowledge fairly
implied on the basis of objective
circumstances, that a user is under 18 years of
age.
(iii) For training purposes, of a user over
18 years of age, unless the artificial
intelligence chatbot provider first obtains
affirmative consent.
(D) Use any classification or designation of the
personality or behavioral characteristic of a user
created through profiling beyond what is necessary to
fulfill an express request made by a user.
(E) Sell the chat log of a user.
(F) Retain the chat log of a user for longer than 5
years, unless retention is necessary to comply with
this Act or otherwise required by law.
(G) Discriminate or retaliate against any user,
including by denying products or services, charging
different prices or rates for products or services, or
providing lower quality products or services to the
user, for refusing to consent to the use of chat logs
or personal data for training purposes.
(2) Right of access.--
(A) Access to chat log.--An artificial intelligence
chatbot provider that retains the chatlog of a user
shall retain such chat log in a portable, readily
usable, downloadable, and human and machine-readable
format, and shall provide such chat log to the user
upon request by the user.
(B) Deletion of chat logs and personal data.--An
artificial intelligence chatbot provider that retains
the chat log or personal data of a user shall delete
such chat log or personal data upon request by the
user.
(C) Discrimination and retaliation prohibited.--An
artificial intelligence chatbot provider may not
discriminate or retaliate against any user, including
by denying products or services, charging different
prices or rates for products or services, or providing
lower quality products or services to the user, for
accessing the chat log of the user.
(3) Data security program.--Not later than 12 months after
the date of the enactment of this Act, an artificial
intelligence chatbot provider shall develop, implement, and
maintain a comprehensive, written, data security program that
contains administrative, technical, and physical safeguards
that are proportionate to the volume and nature of the personal
data and chat logs maintained by the artificial intelligence
chatbot provider, a summary of which shall be made publicly
available on the website of the artificial intelligence chatbot
provider.
(4) Prohibited production and access.--A Government entity
may not compel the production of or access to input data or
chat logs from an artificial intelligence chatbot provider,
except as provided by a warrant issued by a court under section
2518 of title 18, United States Code.
(b) Transparency for Users.--
(1) Prohibition against misleading information.--An
artificial intelligence chatbot provider may not--
(A) represent that the input data or chat log of a
user is confidential; or
(B) use any term, letter, or phrase in the
advertising, interface, or output of an artificial
intelligence chatbot that indicates or implies that any
output data is being provided by, endorsed by, or
equivalent to those provided by the following:
(i) A licensed healthcare professional or a
licensed therapist.
(ii) A licensed legal professional.
(iii) A licensed accounting professional.
(iv) A certified financial fiduciary or
planner.
(2) AI chatbot notice required.--An artificial intelligence
chatbot provider shall provide a clear, conspicuous, and
explicit notice to a user that the user is interacting with an
artificial intelligence chatbot rather than a human before the
artificial intelligence chatbot generates any output, every
hour thereafter, and each time a user prompts the artificial
intelligence chatbot about whether the artificial intelligence
chatbot is a real person as follows:
(A) The disclosure of the notice shall be in the
same language as the one in which the user interacts
with the artificial intelligence chatbot, in a font
size easily readable by an average user, and not
smaller than the largest font size of other text
appearing on the interface on which the artificial
intelligence chatbot is provided.
(B) The notice shall be accessible to users with
disabilities.
(C) The notice shall comply with regulations
promulgated by the Commission.
(c) Safety by Design: Assessments and Transparency Requirements.--
(1) Monthly risk assessment of ai chatbot required.--Not
less frequently than monthly, an artificial intelligence
chatbot provider shall assess the artificial intelligence
chatbot for the risk of any covered harm, emotional dependence,
or compulsive usage, according to metrics set forth in rules
promulgated by the Commission.
(2) Public availability of ai chatbot information.--Not
less frequently than quarterly, an artificial intelligence
chatbot provider shall make information concerning the risk
assessment required under paragraph (1) publicly available on
the website of the provider, in accordance with rules
promulgated by the Commission.
(3) Prohibition of harmful design features for minors.--If
an artificial intelligence chatbot provider knows or should
know, based on knowledge fairly implied on the basis of
objective circumstances, that a user is under the age of 18,
the artificial intelligence chatbot provider shall disable for
that user any feature or setting that creates an unreasonable
risk of the user suffering a covered harm, emotional
dependence, or compulsive usage, in accordance with rules
promulgated by the Commission.
(d) Required Disclosure by Business Entities Engaged in Customer
Service Communications of Use of an Artificial Intelligence Chatbot for
Customer Service.--A business entity that initiates or receives a
customer service communication and uses an artificial intelligence
chatbot for customer service communication shall, at the beginning of
each customer service communication so initiated or received, disclose,
in accordance with rules promulgated by the Commission--
(1) that a nonhuman, artificial intelligence, or machine is
being used for customer service; and
(2) that the consumer may request, and upon such request,
be immediately transferred to a human operator who is
physically located in the United States, including, if
possible, by voice command (such as by saying the word
``agent'').
SEC. 3. RULEMAKING.
(a) Regulations Required.--Not later than 12 months after the date
of the enactment of this Act, the Commission shall promulgate
regulations that include the following:
(1) A description of the form and content of the
disclosures required under section 2(b).
(2) An example template for the disclosures required under
section 2(b).
(3) A description of the metrics that each artificial
intelligence chatbot provider is required to use to assess and
publish any risk of a covered harm, emotional dependence, or
compulsive usage under section 2(c)(3).
(4) Rules that prohibit the use of artificial intelligence
chatbot design features or settings that create an unreasonable
risk of causing a covered harm, emotional dependence, or
compulsive usage for users under the age of 18, as described
under section 2(c)(3).
(5) An identification and description of categories of
information that each artificial intelligence chatbot provider
is required to make publicly available about the artificial
intelligence chatbots of the provider under section 2(b).
(6) A description and example of the disclosure required by
each business entity that initiates or receives a customer
service communication and uses an artificial intelligence
chatbot for customer service communication, as described under
section 2(d).
(b) General Rulemaking Authority.--The Commission may promulgate
any other regulation necessary to implement this Act.
SEC. 4. ENFORCEMENT.
(a) Enforcement by Federal Trade Commission.--
(1) Unfair or deceptive acts or practices.--A violation of
section 2 or a regulation promulgated under such section shall
be treated as a violation of a regulation under section
18(a)(1)(B) of the Federal Trade Commission Act (15 U.S.C.
57a(a)(1)(B)) regarding unfair or deceptive acts or practices.
(2) Powers of commission.--The Federal Trade Commission
shall enforce section 2 and any regulation promulgated under
such section in the same manner, by the same means, and with
the same jurisdiction, powers, and duties as though all
applicable terms and provisions of the Federal Trade Commission
Act (15 U.S.C. 41 et seq.) were incorporated into and made a
part of this section. Any person who violates such section or
regulation shall be subject to the penalties and entitled to
the privileges and immunities provided in the Federal Trade
Commission Act.
(b) Actions by States.--
(1) In general.--In any case in which the attorney general
of a State, or an official or agency of a State, has reason to
believe that an interest of the residents of such State has
been or is threatened or adversely affected by an act or
practice in violation of section 2 or a regulation promulgated
under such section, the State, as parens patriae, may bring a
civil action on behalf of the residents of the State in an
appropriate State court or appropriate district court of the
United States to--
(A) enjoin such act or practice;
(B) enforce compliance with such section or
regulation;
(C) obtain damages, restitution, or other
compensation on behalf of residents of the State;
(D) obtain reasonable attorney's fees and other
litigation costs reasonably incurred; or
(E) obtain such other legal and equitable relief as
the court may consider to be appropriate.
(2) Notice.--Before filing an action under this subsection,
the attorney general, official, or agency of the State involved
shall provide to the Federal Trade Commission a written notice
of such action and a copy of the complaint for such action. If
the attorney general, official, or agency determines that it is
not feasible to provide the notice described in this paragraph
before the filing of the action, the attorney general,
official, or agency shall provide written notice of the action
and a copy of the complaint to the Federal Trade Commission
immediately upon the filing of the action.
(3) Authority of federal trade commission.--
(A) In general.--On receiving notice under
paragraph (2) of an action under this subsection, the
Federal Trade Commission shall have the right--
(i) to intervene in the action;
(ii) upon so intervening, to be heard on
all matters arising therein; and
(iii) to file petitions for appeal.
(B) Limitation on state action while federal action
is pending.--If the Federal Trade Commission or the
Attorney General of the United States has instituted a
civil action for violation of section 2 or a regulation
promulgated under such section (referred to in this
subparagraph as the ``Federal action''), no State
attorney general, official, or agency may bring an
action under this subsection during the pendency of the
Federal action against any defendant named in the
complaint in the Federal action for any violation of
such section or regulation alleged in such complaint.
(4) Rule of construction.--For purposes of bringing a civil
action under this subsection, nothing in this Act shall be
construed to prevent an attorney general, official, or agency
of a State from exercising the powers conferred on the attorney
general, official, or agency by the laws of such State to
conduct investigations, administer oaths and affirmations, or
compel the attendance of witnesses or the production of
documentary and other evidence.
(c) Private Right of Action.--
(1) In general.--A person injured by an act or practice in
violation of section 2 or a regulation promulgated under such
section may bring in an appropriate State court or an
appropriate district court of the United States any of the
following:
(A) An action to enjoin the violation.
(B) An action to recover actual damages resulting
from the violation, or to receive--
(i) up to $10,000 per violation, for a
violation of subsections (a), (c)(1), and
(c)(2) of section 2, whichever is greater; and
(ii) up to $10,000 in total for all
violations of section 2(b), whichever is
greater.
(iii) for a violation of--
(I) section 2(c)(3), actual damages
and statutory damages of not less than
$50,000.
(II) section 2(c)(3) that results
in a covered harm, actual damages and
statutory damages of not less than
$250,000.
(III) section 2(c)(3) that results
in emotional dependence or compulsive
usage, actual damages and statutory
damages of not less than $100,000.
(2) Willful or knowing violations.--If the court finds that
the defendant acted willfully or knowingly in committing a
violation described in paragraph (1), the court may, in its
discretion, increase the amount of the award to an amount equal
to not more than 5 times the amount available under paragraph
(1)(B).
(3) Costs and attorney's fees.--The court shall award to a
prevailing plaintiff in an action under this subsection the
costs of such action and reasonable attorney's fees, as
determined by the court.
(4) Limitation.--An action may be commenced under this
subsection not later than 2 years after the date on which the
person first discovered or had a reasonable opportunity to
discover the violation.
(5) Nonexclusive remedy.--The remedy provided by this
subsection shall be in addition to any other remedies available
to the person.
(d) Liability for Injury.--A user of an artificial intelligence
chatbot who suffers an injury in fact caused through the use of the
artificial intelligence chatbot may bring an action against the
artificial intelligence chatbot provider in an appropriate State court
or an appropriate district court of the United States to recover actual
damages from the artificial intelligence chatbot provider, even if--
(1) the artificial intelligence chatbot provider exercised
all reasonable care in the design and distribution of the
artificial intelligence chatbot; or
(2) the artificial intelligence chatbot provider did not
directly distribute the artificial intelligence chatbot to the
user or otherwise enter into a contractual relationship with
the user.
SEC. 5. DEFINITIONS.
In this Act:
(1) Advertisement.--The term ``advertisement'' means any
written or oral statement, illustration, or depiction that
promotes the sale or use of a good or service or is designed to
increase interest in a brand, good, or service in which the
statement, illustration, or depiction is displayed in exchange
for monetary or other valuable consideration, including access
to data, between the artificial intelligence chatbot provider
and the brand, good, or service.
(2) Affirmative consent.--
(A) Requirements.--The term ``affirmative consent''
means a clear affirmative act that signifies the freely
given, specific, informed, and unambiguous
authorization of a user for an act or practice in
response to a specific request from an artificial
intelligence chatbot provider if each of the following
conditions are met:
(i) The request is provided to the user in
a clear and conspicuous standalone disclosure.
(ii) The request includes a written
description, in easy-to-understand language, of
the act or practice for which the consent of
the user is sought.
(iii) The request is made in a manner
reasonably accessible to and usable by a user
with a disability (as defined in section 3 of
the Americans with Disabilities Act of 1990 (42
U.S.C. 12102)).
(iv) The request is made available to the
user in each language in which the artificial
intelligence chatbot provider provides an
artificial intelligence chatbot.
(v) The option to refuse to give consent is
at least as prominent as the option to give
consent, and the option to refuse to give
consent takes the same number of steps or fewer
as the option to give consent.
(B) Exclusions.--The term ``affirmative consent''
does not include any of the following:
(i) Inference of consent from the inaction
of the user or the continued use of an
artificial intelligence chatbot by the user.
(ii) Acceptance of a general or broad terms
of use or similar document.
(iii) Hovering over, muting, pausing, or
closing a given piece of content.
(iv) Agreement obtained through the use of
a false, fraudulent, or materially misleading
statement or representation.
(v) Agreement obtained through the use of
other dark patterns.
(3) Artificial intelligence chatbot.--
(A) In general.--The term ``artificial intelligence
chatbot''--
(i) means any interactive computer service
or software application that--
(I) generates responses that are
not fully predetermined; and
(II) accepts open-ended natural-
language or multimodal user input and
produces adaptive or context-responsive
output; and
(ii) does not include an interactive
computer service or software application--
(I) the responses of which are
limited to contextualized replies; and
(II) that is unable to respond on a
range of topics outside of a narrow
specified purpose.
(B) Inclusions.--The term ``artificial intelligence
chatbot'' includes a service or application described
in subparagraph (A) that, in a manner that simulates a
sustained interpersonal relationship or emotional
interaction with the user--
(i) exhibits persistent responses that
suggest affection or attachment directed toward
the user, or engages in interactions involving
emotional disclosures from the user; or
(ii) presents at least one persistent
identity, persona, or character or holds itself
out as a sentient being, fictional character,
or social entity.
(4) Artificial intelligence chatbot provider.--The term
``artificial intelligence chatbot provider'' means any person
who creates, distributes (including to a third party), or
otherwise makes publicly available an artificial intelligence
chatbot.
(5) Chat log.--The term ``chat log'' means any input data,
output generated by an artificial intelligence chatbot, or
record of the input data or output from user interaction with
an artificial intelligence chatbot.
(6) Collect.--The term ``collect'' means to create, buy,
rent, gather, obtain, receive, access, or otherwise acquire
personal data or input data by any means through the use of an
artificial intelligence chatbot by an individual.
(7) Commission.--The term ``Commission'' means the Federal
Trade Commission.
(8) Compulsive usage.--The term ``compulsive usage'' means
a persistent and repetitive use of an AI chatbot that
significantly impacts one or more major life activities of a
user, including socializing, sleeping, eating, learning,
reading, concentrating, communicating, or working.
(9) Covered harm.--The term ``covered harm'' means death, a
suicide attempt, or a psychiatric emergency that results in
urgent medical treatment.
(10) Dark pattern.--The term ``dark pattern'' means a user
interface designed or manipulated with the substantial effect
of subverting or impairing user autonomy, decision-making or
choice, and includes any practice the Commission refers to as a
``dark pattern''.
(11) De-identified data.--The term ``de-identified data''
means--
(A) information that cannot reasonably be used to
infer or derive the identity of an individual;
(B) information that does not identify and is not
linked or reasonably linkable to an individual; or
(C) a device that identifies or is linked or
reasonably linkable to an individual, regardless of
whether the information is aggregated, if the
artificial intelligence chatbot provider--
(i) takes such physical, administrative,
and technical measures as are necessary to
ensure that the information cannot, at any
point, be used to re-identify any individual or
device that identifies or is linked or
reasonably linkable to an individual;
(ii) publicly commits in a clear and
conspicuous manner to--
(I) process, retain, or transfer
the information solely in a de-
identified form without any reasonable
means for re-identification; and
(II) not attempt to re-identify the
information with any individual or
device that identifies or is linked or
reasonably linkable to an individual;
and
(iii) contractually obligates any entity
that receives the information from the
artificial intelligence chatbot provider to--
(I) comply with all of the
provisions of this subparagraph with
respect to the information; and
(II) require that such contractual
obligation is included in any
subsequent instance for which the data
may be received.
(12) Emotional dependence.--``emotional dependence'' means
a behavioral or spoken pattern of the user that indicates the
user relies on an artificial intelligence chatbot as a primary
source of emotional support or social connection, such as--
(A) a user expressing that the artificial
intelligence chatbot is the primary source of emotional
support for the user;
(B) a user expressing distress at the prospect of
losing access to the artificial intelligence chatbot;
or
(C) any pattern of use that suggests the user is
substituting the artificial intelligence chatbot for
human relationships.
(13) Input data.--The term ``input data'' means
information, including text, photo, audio, video, or file
provided to an artificial intelligence chatbot by a user.
(14) Model.--The term ``model'' means an engineered or
machine-based system underlying an artificial intelligence
chatbot that can, for explicit or implicit objectives, infer
from the input it receives how to generate outputs that can
influence physical or virtual environments.
(15) Personal data.--The term ``personal data''--
(A) means any information, including derived data,
inferences, or unique identifiers, that is linked or
reasonably linkable, alone or in combination with other
information, to an identified or identifiable
individual or a device that identifies or is linked or
reasonably linkable to an individual; and
(B) does not include de-identified data or publicly
available information.
(16) Publicly available information.--The term ``publicly
available information'' means information that has been
lawfully made available to the general public from--
(A) Federal, State or municipal government records,
if the person collects, processes, and transfers such
information in accordance with any restrictions or
terms of use placed on the information by the relevant
government entity;
(B) widely distributed media; or
(C) a disclosure to the general public as required
by Federal, State, or local law.
(17) Publicly available information.--The term ``publicly
available information'' does not include the following:
(A) Any obscene visual depiction (as defined in
section 1460 of title 18, United States Code).
(B) Biometric data.
(C) Personal data that is created through the
combination of personal data with publicly available
information.
(D) Information that is collated and combined to
create user profiles on publicly available or
subscription-based websites and inferences generated
from such information.
(E) Genetic data, unless otherwise made publicly
available by the individual to whom the information
pertains.
(F) Information made available by a user on a
website or online service made available to all members
of the public, for free or for a fee, where the user
has restricted the information to a specific audience.
(G) Intimate images, authentic or computer-
generated, known to be nonconsensual.
(18) Process; processing.--The terms ``process'' and
``processing'' mean any operation or set of operations
performed, whether by manual or automated means, on personal
data or input data or on sets of personal data or input data,
such as the use, storage, disclosure, analysis, deletion, or
modification of such data.
(19) Profiling.--The term ``profiling''--
(A) means any form of processing performed on input
data or personal data to infer, detect, classify, or
designate emotional vulnerability or distinct
behavioral characteristics of an individual; and
(B) does not include processing of a chat log for
purposes of user safety or to otherwise comply with
this Act.
(20) Sell.--The term ``sell''--
(A) means the exchange of personal data or input
data for monetary or other valuable consideration, or
making available such data or use of such data, by the
AI chatbot provider to a third party; and
(B) does not include--
(i) the disclosure of personal data or
input data to a third party that processes the
data on behalf of the artificial intelligence
chatbot provider;
(ii) with the affirmative consent of the
user, the disclosure of personal data or input
data in which the user affirmatively directs
the artificial intelligence chatbot provider to
disclose the data or intentionally uses the
artificial intelligence chatbot provider to
interact with a third party; or
(iii) the disclosure of personal data that
the user--
(I) intentionally made available to
the general public through a channel of
mass media; and
(II) did not restrict to a specific
audience.
(21) Training.--The term ``training''--
(A) means the use of input data to adjust or modify
a model; and
(B) does not include--
(i) testing to identify risks of harm to a
user;
(ii) any adjustment or modification to
address any such identified risks of harm; or
(iii) any action necessary to comply with
this Act or otherwise required by law.
(22) User.--The term ``user'' means an individual,
regardless of age.
(23) Widely distributed media.--The term ``widely
distributed media''--
(A) means information that is available to the
public, including information from a telephone book or
online directory, a television, internet, or radio
program, the news media, or an internet site that is
available to the public on an unrestricted basis; and
(B) does not include an obscene visual depiction
(as defined in section 1460 of title 18, United States
Code).
SEC. 6. RULE OF CONSTRUCTION.
Nothing in this Act or any regulation promulgated under this Act
may be construed to affect any right, cause of action, remedy,
presumption, liability, or defense available at law or in equity,
including any anti-discrimination, consumer protection, labor, tort, or
civil rights law.
SEC. 7. RELATIONSHIP TO STATE LAWS.
Nothing in this Act or any regulation promulgated under this Act
preempts or otherwise affects any State law, rule, requirement, or
regulation, including any right, cause of action, remedy, presumption,
liability, or defense available at law or in equity, that is at least
as protective of users of artificial intelligence chatbots as provided
for in this Act or any regulation promulgated under this Act.
<all>