|
119th CONGRESS
2d Session |
To require artificial intelligence chatbot providers to provide data privacy and security, and for other purposes.
Mrs. Foushee (for herself and Mr. Casar) introduced the following bill; which was referred to the Committee on Energy and Commerce
To require artificial intelligence chatbot providers to provide data privacy and security, and for other purposes.
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,
This Act may be cited as the “People-First Chatbot Act”.
SEC. 2. Prohibitions and requirements.
(a) Data privacy and security.—
(1) PROHIBITIONS.—An artificial intelligence chatbot provider may not do the following:
(A) Process personal data other than input data to inform chatbot outputs unless the processing of personal data is necessary to fulfill an express request made by a user and that user has provided affirmative consent.
(B) Process the chat log of a user as follows:
(i) To determine whether to display an advertisement for a product or service to the user.
(ii) To determine a product, service, or category of product or service to advertise to the user.
(iii) To customize an advertisement or how an advertisement is presented to the user.
(C) Process the chat log or personal data of a user (unless the personal data is the age of the user, but only to implement the policies of the artificial intelligence chatbot provider, regarding harmful design features for minors) as follows:
(i) If the artificial intelligence chatbot provider knows or should know, based on knowledge fairly implied on the basis of objective circumstances, that the user is under the age of 18, without the affirmative consent of the parent or legal guardian of that user.
(ii) For training purposes, if the artificial intelligence chatbot provider knows or should know, based on knowledge fairly implied on the basis of objective circumstances, that a user is under 18 years of age.
(iii) For training purposes, of a user over 18 years of age, unless the artificial intelligence chatbot provider first obtains affirmative consent.
(D) Use any classification or designation of the personality or behavioral characteristic of a user created through profiling beyond what is necessary to fulfill an express request made by a user.
(E) Sell the chat log of a user.
(F) Retain the chat log of a user for longer than 5 years, unless retention is necessary to comply with this Act or otherwise required by law.
(G) Discriminate or retaliate against any user, including by denying products or services, charging different prices or rates for products or services, or providing lower quality products or services to the user, for refusing to consent to the use of chat logs or personal data for training purposes.
(A) ACCESS TO CHAT LOG.—An artificial intelligence chatbot provider that retains the chatlog of a user shall retain such chat log in a portable, readily usable, downloadable, and human and machine-readable format, and shall provide such chat log to the user upon request by the user.
(B) DELETION OF CHAT LOGS AND PERSONAL DATA.—An artificial intelligence chatbot provider that retains the chat log or personal data of a user shall delete such chat log or personal data upon request by the user.
(C) DISCRIMINATION AND RETALIATION PROHIBITED.—An artificial intelligence chatbot provider may not discriminate or retaliate against any user, including by denying products or services, charging different prices or rates for products or services, or providing lower quality products or services to the user, for accessing the chat log of the user.
(3) DATA SECURITY PROGRAM.—Not later than 12 months after the date of the enactment of this Act, an artificial intelligence chatbot provider shall develop, implement, and maintain a comprehensive, written, data security program that contains administrative, technical, and physical safeguards that are proportionate to the volume and nature of the personal data and chat logs maintained by the artificial intelligence chatbot provider, a summary of which shall be made publicly available on the website of the artificial intelligence chatbot provider.
(4) PROHIBITED PRODUCTION AND ACCESS.—A Government entity may not compel the production of or access to input data or chat logs from an artificial intelligence chatbot provider, except as provided by a warrant issued by a court under section 2518 of title 18, United States Code.
(1) PROHIBITION AGAINST MISLEADING INFORMATION.—An artificial intelligence chatbot provider may not—
(A) represent that the input data or chat log of a user is confidential; or
(B) use any term, letter, or phrase in the advertising, interface, or output of an artificial intelligence chatbot that indicates or implies that any output data is being provided by, endorsed by, or equivalent to those provided by the following:
(i) A licensed healthcare professional or a licensed therapist.
(ii) A licensed legal professional.
(iii) A licensed accounting professional.
(iv) A certified financial fiduciary or planner.
(2) AI CHATBOT NOTICE REQUIRED.—An artificial intelligence chatbot provider shall provide a clear, conspicuous, and explicit notice to a user that the user is interacting with an artificial intelligence chatbot rather than a human before the artificial intelligence chatbot generates any output, every hour thereafter, and each time a user prompts the artificial intelligence chatbot about whether the artificial intelligence chatbot is a real person as follows:
(A) The disclosure of the notice shall be in the same language as the one in which the user interacts with the artificial intelligence chatbot, in a font size easily readable by an average user, and not smaller than the largest font size of other text appearing on the interface on which the artificial intelligence chatbot is provided.
(B) The notice shall be accessible to users with disabilities.
(C) The notice shall comply with regulations promulgated by the Commission.
(c) Safety by design: assessments and transparency requirements.—
(1) MONTHLY RISK ASSESSMENT OF AI CHATBOT REQUIRED.—Not less frequently than monthly, an artificial intelligence chatbot provider shall assess the artificial intelligence chatbot for the risk of any covered harm, emotional dependence, or compulsive usage, according to metrics set forth in rules promulgated by the Commission.
(2) PUBLIC AVAILABILITY OF AI CHATBOT INFORMATION.—Not less frequently than quarterly, an artificial intelligence chatbot provider shall make information concerning the risk assessment required under paragraph (1) publicly available on the website of the provider, in accordance with rules promulgated by the Commission.
(3) PROHIBITION OF HARMFUL DESIGN FEATURES FOR MINORS.—If an artificial intelligence chatbot provider knows or should know, based on knowledge fairly implied on the basis of objective circumstances, that a user is under the age of 18, the artificial intelligence chatbot provider shall disable for that user any feature or setting that creates an unreasonable risk of the user suffering a covered harm, emotional dependence, or compulsive usage, in accordance with rules promulgated by the Commission.
(d) Required disclosure by business entities engaged in customer service communications of use of an artificial intelligence chatbot for customer service.—A business entity that initiates or receives a customer service communication and uses an artificial intelligence chatbot for customer service communication shall, at the beginning of each customer service communication so initiated or received, disclose, in accordance with rules promulgated by the Commission—
(1) that a nonhuman, artificial intelligence, or machine is being used for customer service; and
(2) that the consumer may request, and upon such request, be immediately transferred to a human operator who is physically located in the United States, including, if possible, by voice command (such as by saying the word “agent”).
(a) Regulations required.—Not later than 12 months after the date of the enactment of this Act, the Commission shall promulgate regulations that include the following:
(1) A description of the form and content of the disclosures required under section 2(b).
(2) An example template for the disclosures required under section 2(b).
(3) A description of the metrics that each artificial intelligence chatbot provider is required to use to assess and publish any risk of a covered harm, emotional dependence, or compulsive usage under section 2(c)(3).
(4) Rules that prohibit the use of artificial intelligence chatbot design features or settings that create an unreasonable risk of causing a covered harm, emotional dependence, or compulsive usage for users under the age of 18, as described under section 2(c)(3).
(5) An identification and description of categories of information that each artificial intelligence chatbot provider is required to make publicly available about the artificial intelligence chatbots of the provider under section 2(b).
(6) A description and example of the disclosure required by each business entity that initiates or receives a customer service communication and uses an artificial intelligence chatbot for customer service communication, as described under section 2(d).
(b) General rulemaking authority.—The Commission may promulgate any other regulation necessary to implement this Act.
(a) Enforcement by Federal Trade Commission.—
(1) UNFAIR OR DECEPTIVE ACTS OR PRACTICES.—A violation of section 2 or a regulation promulgated under such section shall be treated as a violation of a regulation under section 18(a)(1)(B) of the Federal Trade Commission Act (15 U.S.C. 57a(a)(1)(B)) regarding unfair or deceptive acts or practices.
(2) POWERS OF COMMISSION.—The Federal Trade Commission shall enforce section 2 and any regulation promulgated under such section in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (15 U.S.C. 41 et seq.) were incorporated into and made a part of this section. Any person who violates such section or regulation shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act.
(1) IN GENERAL.—In any case in which the attorney general of a State, or an official or agency of a State, has reason to believe that an interest of the residents of such State has been or is threatened or adversely affected by an act or practice in violation of section 2 or a regulation promulgated under such section, the State, as parens patriae, may bring a civil action on behalf of the residents of the State in an appropriate State court or appropriate district court of the United States to—
(A) enjoin such act or practice;
(B) enforce compliance with such section or regulation;
(C) obtain damages, restitution, or other compensation on behalf of residents of the State;
(D) obtain reasonable attorney’s fees and other litigation costs reasonably incurred; or
(E) obtain such other legal and equitable relief as the court may consider to be appropriate.
(2) NOTICE.—Before filing an action under this subsection, the attorney general, official, or agency of the State involved shall provide to the Federal Trade Commission a written notice of such action and a copy of the complaint for such action. If the attorney general, official, or agency determines that it is not feasible to provide the notice described in this paragraph before the filing of the action, the attorney general, official, or agency shall provide written notice of the action and a copy of the complaint to the Federal Trade Commission immediately upon the filing of the action.
(3) AUTHORITY OF FEDERAL TRADE COMMISSION.—
(A) IN GENERAL.—On receiving notice under paragraph (2) of an action under this subsection, the Federal Trade Commission shall have the right—
(i) to intervene in the action;
(ii) upon so intervening, to be heard on all matters arising therein; and
(iii) to file petitions for appeal.
(B) LIMITATION ON STATE ACTION WHILE FEDERAL ACTION IS PENDING.—If the Federal Trade Commission or the Attorney General of the United States has instituted a civil action for violation of section 2 or a regulation promulgated under such section (referred to in this subparagraph as the “Federal action”), no State attorney general, official, or agency may bring an action under this subsection during the pendency of the Federal action against any defendant named in the complaint in the Federal action for any violation of such section or regulation alleged in such complaint.
(4) RULE OF CONSTRUCTION.—For purposes of bringing a civil action under this subsection, nothing in this Act shall be construed to prevent an attorney general, official, or agency of a State from exercising the powers conferred on the attorney general, official, or agency by the laws of such State to conduct investigations, administer oaths and affirmations, or compel the attendance of witnesses or the production of documentary and other evidence.
(1) IN GENERAL.—A person injured by an act or practice in violation of section 2 or a regulation promulgated under such section may bring in an appropriate State court or an appropriate district court of the United States any of the following:
(A) An action to enjoin the violation.
(B) An action to recover actual damages resulting from the violation, or to receive—
(i) up to $10,000 per violation, for a violation of subsections (a), (c)(1), and (c)(2) of section 2, whichever is greater; and
(ii) up to $10,000 in total for all violations of section 2(b), whichever is greater.
(I) section 2(c)(3), actual damages and statutory damages of not less than $50,000.
(II) section 2(c)(3) that results in a covered harm, actual damages and statutory damages of not less than $250,000.
(III) section 2(c)(3) that results in emotional dependence or compulsive usage, actual damages and statutory damages of not less than $100,000.
(2) WILLFUL OR KNOWING VIOLATIONS.—If the court finds that the defendant acted willfully or knowingly in committing a violation described in paragraph (1), the court may, in its discretion, increase the amount of the award to an amount equal to not more than 5 times the amount available under paragraph (1)(B).
(3) COSTS AND ATTORNEY’S FEES.—The court shall award to a prevailing plaintiff in an action under this subsection the costs of such action and reasonable attorney’s fees, as determined by the court.
(4) LIMITATION.—An action may be commenced under this subsection not later than 2 years after the date on which the person first discovered or had a reasonable opportunity to discover the violation.
(5) NONEXCLUSIVE REMEDY.—The remedy provided by this subsection shall be in addition to any other remedies available to the person.
(d) Liability for injury.—A user of an artificial intelligence chatbot who suffers an injury in fact caused through the use of the artificial intelligence chatbot may bring an action against the artificial intelligence chatbot provider in an appropriate State court or an appropriate district court of the United States to recover actual damages from the artificial intelligence chatbot provider, even if—
(1) the artificial intelligence chatbot provider exercised all reasonable care in the design and distribution of the artificial intelligence chatbot; or
(2) the artificial intelligence chatbot provider did not directly distribute the artificial intelligence chatbot to the user or otherwise enter into a contractual relationship with the user.
In this Act:
(1) ADVERTISEMENT.—The term “advertisement” means any written or oral statement, illustration, or depiction that promotes the sale or use of a good or service or is designed to increase interest in a brand, good, or service in which the statement, illustration, or depiction is displayed in exchange for monetary or other valuable consideration, including access to data, between the artificial intelligence chatbot provider and the brand, good, or service.
(A) REQUIREMENTS.—The term “affirmative consent” means a clear affirmative act that signifies the freely given, specific, informed, and unambiguous authorization of a user for an act or practice in response to a specific request from an artificial intelligence chatbot provider if each of the following conditions are met:
(i) The request is provided to the user in a clear and conspicuous standalone disclosure.
(ii) The request includes a written description, in easy-to-understand language, of the act or practice for which the consent of the user is sought.
(iii) The request is made in a manner reasonably accessible to and usable by a user with a disability (as defined in section 3 of the Americans with Disabilities Act of 1990 (42 U.S.C. 12102)).
(iv) The request is made available to the user in each language in which the artificial intelligence chatbot provider provides an artificial intelligence chatbot.
(v) The option to refuse to give consent is at least as prominent as the option to give consent, and the option to refuse to give consent takes the same number of steps or fewer as the option to give consent.
(B) EXCLUSIONS.—The term “affirmative consent” does not include any of the following:
(i) Inference of consent from the inaction of the user or the continued use of an artificial intelligence chatbot by the user.
(ii) Acceptance of a general or broad terms of use or similar document.
(iii) Hovering over, muting, pausing, or closing a given piece of content.
(iv) Agreement obtained through the use of a false, fraudulent, or materially misleading statement or representation.
(v) Agreement obtained through the use of other dark patterns.
(3) ARTIFICIAL INTELLIGENCE CHATBOT.—
(A) IN GENERAL.—The term “artificial intelligence chatbot”—
(i) means any interactive computer service or software application that—
(I) generates responses that are not fully predetermined; and
(II) accepts open-ended natural-language or multimodal user input and produces adaptive or context-responsive output; and
(ii) does not include an interactive computer service or software application—
(I) the responses of which are limited to contextualized replies; and
(II) that is unable to respond on a range of topics outside of a narrow specified purpose.
(B) INCLUSIONS.—The term “artificial intelligence chatbot” includes a service or application described in subparagraph (A) that, in a manner that simulates a sustained interpersonal relationship or emotional interaction with the user—
(i) exhibits persistent responses that suggest affection or attachment directed toward the user, or engages in interactions involving emotional disclosures from the user; or
(ii) presents at least one persistent identity, persona, or character or holds itself out as a sentient being, fictional character, or social entity.
(4) ARTIFICIAL INTELLIGENCE CHATBOT PROVIDER.—The term “artificial intelligence chatbot provider” means any person who creates, distributes (including to a third party), or otherwise makes publicly available an artificial intelligence chatbot.
(5) CHAT LOG.—The term “chat log” means any input data, output generated by an artificial intelligence chatbot, or record of the input data or output from user interaction with an artificial intelligence chatbot.
(6) COLLECT.—The term “collect” means to create, buy, rent, gather, obtain, receive, access, or otherwise acquire personal data or input data by any means through the use of an artificial intelligence chatbot by an individual.
(7) COMMISSION.—The term “Commission” means the Federal Trade Commission.
(8) COMPULSIVE USAGE.—The term “compulsive usage” means a persistent and repetitive use of an AI chatbot that significantly impacts one or more major life activities of a user, including socializing, sleeping, eating, learning, reading, concentrating, communicating, or working.
(9) COVERED HARM.—The term “covered harm” means death, a suicide attempt, or a psychiatric emergency that results in urgent medical treatment.
(10) DARK PATTERN.—The term “dark pattern” means a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making or choice, and includes any practice the Commission refers to as a “dark pattern”.
(11) DE-IDENTIFIED DATA.—The term “de-identified data” means—
(A) information that cannot reasonably be used to infer or derive the identity of an individual;
(B) information that does not identify and is not linked or reasonably linkable to an individual; or
(C) a device that identifies or is linked or reasonably linkable to an individual, regardless of whether the information is aggregated, if the artificial intelligence chatbot provider—
(i) takes such physical, administrative, and technical measures as are necessary to ensure that the information cannot, at any point, be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual;
(ii) publicly commits in a clear and conspicuous manner to—
(I) process, retain, or transfer the information solely in a de-identified form without any reasonable means for re-identification; and
(II) not attempt to re-identify the information with any individual or device that identifies or is linked or reasonably linkable to an individual; and
(iii) contractually obligates any entity that receives the information from the artificial intelligence chatbot provider to—
(I) comply with all of the provisions of this subparagraph with respect to the information; and
(II) require that such contractual obligation is included in any subsequent instance for which the data may be received.
(12) EMOTIONAL DEPENDENCE.—“emotional dependence” means a behavioral or spoken pattern of the user that indicates the user relies on an artificial intelligence chatbot as a primary source of emotional support or social connection, such as—
(A) a user expressing that the artificial intelligence chatbot is the primary source of emotional support for the user;
(B) a user expressing distress at the prospect of losing access to the artificial intelligence chatbot; or
(C) any pattern of use that suggests the user is substituting the artificial intelligence chatbot for human relationships.
(13) INPUT DATA.—The term “input data” means information, including text, photo, audio, video, or file provided to an artificial intelligence chatbot by a user.
(14) MODEL.—The term “model” means an engineered or machine-based system underlying an artificial intelligence chatbot that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.
(15) PERSONAL DATA.—The term “personal data”—
(A) means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual; and
(B) does not include de-identified data or publicly available information.
(16) PUBLICLY AVAILABLE INFORMATION.—The term “publicly available information” means information that has been lawfully made available to the general public from—
(A) Federal, State or municipal government records, if the person collects, processes, and transfers such information in accordance with any restrictions or terms of use placed on the information by the relevant government entity;
(B) widely distributed media; or
(C) a disclosure to the general public as required by Federal, State, or local law.
(17) PUBLICLY AVAILABLE INFORMATION.—The term “publicly available information” does not include the following:
(A) Any obscene visual depiction (as defined in section 1460 of title 18, United States Code).
(B) Biometric data.
(C) Personal data that is created through the combination of personal data with publicly available information.
(D) Information that is collated and combined to create user profiles on publicly available or subscription-based websites and inferences generated from such information.
(E) Genetic data, unless otherwise made publicly available by the individual to whom the information pertains.
(F) Information made available by a user on a website or online service made available to all members of the public, for free or for a fee, where the user has restricted the information to a specific audience.
(G) Intimate images, authentic or computer-generated, known to be nonconsensual.
(18) PROCESS; PROCESSING.—The terms “process” and “processing” mean any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.
(19) PROFILING.—The term “profiling”—
(A) means any form of processing performed on input data or personal data to infer, detect, classify, or designate emotional vulnerability or distinct behavioral characteristics of an individual; and
(B) does not include processing of a chat log for purposes of user safety or to otherwise comply with this Act.
(A) means the exchange of personal data or input data for monetary or other valuable consideration, or making available such data or use of such data, by the AI chatbot provider to a third party; and
(i) the disclosure of personal data or input data to a third party that processes the data on behalf of the artificial intelligence chatbot provider;
(ii) with the affirmative consent of the user, the disclosure of personal data or input data in which the user affirmatively directs the artificial intelligence chatbot provider to disclose the data or intentionally uses the artificial intelligence chatbot provider to interact with a third party; or
(iii) the disclosure of personal data that the user—
(I) intentionally made available to the general public through a channel of mass media; and
(II) did not restrict to a specific audience.
(21) TRAINING.—The term “training”—
(A) means the use of input data to adjust or modify a model; and
(i) testing to identify risks of harm to a user;
(ii) any adjustment or modification to address any such identified risks of harm; or
(iii) any action necessary to comply with this Act or otherwise required by law.
(22) USER.—The term “user” means an individual, regardless of age.
(23) WIDELY DISTRIBUTED MEDIA.—The term “widely distributed media”—
(A) means information that is available to the public, including information from a telephone book or online directory, a television, internet, or radio program, the news media, or an internet site that is available to the public on an unrestricted basis; and
(B) does not include an obscene visual depiction (as defined in section 1460 of title 18, United States Code).
Nothing in this Act or any regulation promulgated under this Act may be construed to affect any right, cause of action, remedy, presumption, liability, or defense available at law or in equity, including any anti-discrimination, consumer protection, labor, tort, or civil rights law.
SEC. 7. Relationship to state laws.
Nothing in this Act or any regulation promulgated under this Act preempts or otherwise affects any State law, rule, requirement, or regulation, including any right, cause of action, remedy, presumption, liability, or defense available at law or in equity, that is at least as protective of users of artificial intelligence chatbots as provided for in this Act or any regulation promulgated under this Act.