[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 5051 Introduced in Senate (IS)]
<DOC>
119th CONGRESS
2d Session
S. 5051
To promote competition and reduce consumer switching costs in the
provision of online services, and for other purposes.
_______________________________________________________________________
IN THE SENATE OF THE UNITED STATES
July 21, 2026
Mr. Warner introduced the following bill; which was read twice and
referred to the Committee on Commerce, Science, and Transportation
_______________________________________________________________________
A BILL
To promote competition and reduce consumer switching costs in the
provision of online services, and for other purposes.
Be it enacted by the Senate and House of Representatives of the
United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the ``Artificial Intelligence Access,
Gatekeeper Exchange, and Nondiscriminatory Transfer Act of 2026'' or
the ``AI AGENT Act of 2026''.
SEC. 2. DEFINITIONS.
In this Act:
(1) Artificial intelligence; artificial intelligence
system.--The terms ``artificial intelligence'' and ``artificial
intelligence system'' have the meanings given those terms,
respectively, in section 5002 of the National Artificial
Intelligence Initiative Act of 2020 (15 U.S.C. 9401).
(2) Commission.--The term ``Commission'' means the Federal
Trade Commission.
(3) Custodial user agent.--The term ``custodial user
agent'' means a software-based agent that is expressly
authorized by a user to interact with a large online platform
provider on that user's behalf in a transparent, documented,
scope-limited, and revocable manner.
(4) Custodial user agent provider.--The term ``custodial
user agent provider''--
(A) means any entity that operates or offers 1 or
more custodial user agents; and
(B) includes a user who operates a custodial user
agent on the user's own behalf and not on behalf of any
other user.
(5) Electronic commerce.--The term ``electronic commerce''
has the meaning given that term in section 2301 of title 41,
United States Code.
(6) Interoperability interface.--The term
``interoperability interface'' means an electronic interface
maintained by a large online platform for purposes of achieving
interoperability.
(7) Large online platform.--The term ``large online
platform'' means a product, application, or service provided by
an online platform that has more than 50,000,000 customers or
subscribers in the United States in any calendar month during
the preceding 12-month period.
(8) Large online platform provider.--The term ``large
online platform provider'' means an online provider that
provides, manages, or controls a large online platform.
(9) Online provider.--The term ``online provider'' means a
consumer-facing communications, retail, or information services
provider, including a provider of social media, electronic
commerce, personal finance, or artificial intelligence
services.
(10) Open protocol.--The term ``open protocol'' means a
publicly available technical standard that--
(A) enables interoperability and data exchange
between large online platforms;
(B) is free from--
(i) licensing fees; and
(ii) patent restrictions; and
(C) governs how large online platforms communicate
and exchange data with each other.
(11) Social graph data.--The term ``social graph data''
means data that represents a person's connections and
interactions within a social media service, including--
(A) content generated by the person;
(B) the person's responses to the content of other
users and entities, including comments, reactions,
mentions, reposts, shares, and other engagements in a
manner that excludes content of third-party users;
(C) the person's public profile;
(D) metadata associated with the content and
interactions under subparagraphs (A), (B), and (C); and
(E) relational references sufficient to maintain
the associations among data elements described in
subparagraphs (A) through (D).
(12) Social media service.--The term ``social media
service'' means a website, online or mobile application,
operating system, digital assistant, or online service that
predominantly provides a community forum for user-generated
content, such as sharing videos, images, games, audio files, or
other content.
(13) User data.--
(A) In general.--The term ``user data'' means
information that is--
(i) collected or otherwise processed,
directly or indirectly, by an online provider;
and
(ii) linked, or reasonably linkable, to a
specific person.
(B) Exclusion.--The term ``user data'' does not
include information that is rendered wholly unusable or
unreadable.
(C) Social media services.--For large online
platforms that are social media services, the term
``user data'' includes social graph data.
SEC. 3. DELEGATABILITY.
(a) Individual's Right of Delegation.--Each end user of a large
online platform shall have the right to designate 1 or more custodial
user agents offered by a custodial user agent provider acting in
compliance with subsection (d), as the user's authorized representative
to manage the user's online interactions, electronic commerce
decisions, user-generated content, and account settings on a large
online platform on the same terms as a user, as rendered by that large
online platform.
(b) General Duty of Large Online Platform Providers.--A large
online platform provider shall maintain a set of transparent third-
party-accessible interfaces by which a user may delegate a custodial
user agent to manage the user's online interactions, electronic
commerce decisions, user-generated content, and account settings on a
large online platform on the same terms as a user.
(c) Authentication.--Not later than 180 days after the date of
enactment of this Act, the Commission shall establish rules and
procedures to facilitate a custodial user agent's ability to obtain
access pursuant to subsection (a) in a way that ensures that--
(1) a request for access on behalf of a user is a
verifiable request; and
(2) a user has a transparent, easily implementable method
to revoke a prior delegation, including a mechanism to promptly
communicate revocation requests to a large online platform
provider.
(d) Registration With the Commission.--
(1) In general.--A custodial user agent provider shall
register with the Commission as a condition of, and prior to,
any custodial user agent operated or offered by that provider
accessing an interface described in subsection (a). The
Commission may establish uniform terms and scope of service, by
which a custodial user agent provider may register through
self-attestation. Not later than 180 days after the date of
submission of a registration under this paragraph, the
Commission, or any recognized certification body described in
paragraph (4), shall evaluate the registration.
(2) Commission authority.--The Commission may establish
specialized terms of service, including authorized scope of
delegated access, appropriate for custodial user agents in
specific commercial settings given the privacy, financial
security, and personal safety implications of such access.
(3) Embedded agents.--The Commission may establish
specialized terms of service, including ensuring functional
equivalence for competing custodial user agents, for any
custodial user agent provided by a large online platform
provider that it determines to offer a service that is
competitive with the service of other custodial user agents.
(4) Recognized certification bodies.--
(A) In general.--The Commission may recognize 1 or
more independent certification bodies that--
(i) maintain and publish standards of
conduct, governance, and technical practices
for custodial user agents that meet or exceed
the duties established under subsection (g);
and
(ii) conduct periodic assessments of
conformity with those standards described in
clause (i).
(B) Effect of certification.--Certification in good
standing by a recognized certification body shall
constitute a rebuttable presumption of compliance with
subsections (g) and shall be considered by the
Commission in any related proceeding.
(C) Independence.--The Commission shall not
recognize a certification body that is owned or
controlled by, or that derives a majority of its
revenue from, any single custodial user agent provider
or large online platform provider.
(e) Deregistration by the Commission.--The Commission shall
establish rules and procedures to deregister a custodial user agent
provider that the Commission determines--
(1) has violated the duties established under subsection
(g); or
(2) operates or offers a custodial user agent that has
violated the duties established under subsection (g).
(f) Revocation of Access Rights.--A large online platform provider
may revoke or deny access for any custodial user agent--
(1) the custodial user agent provider of which fails to
register with the Commission;
(2) that repeatedly facilitates fraudulent or malicious
activity; or
(3) for which a customer has revoked express written
consent, pursuant to a method established under subsection
(c)(2).
(g) Duties of a Custodial User Agent.--
(1) In general.--A custodial user agent--
(A) shall reasonably safeguard the privacy and
security of user data provided to it by a user, or
accessed on a user's behalf;
(B) shall not access or manage a user's online
interactions, electronic commerce decisions, financial
accounts, content, or account settings in any way
that--
(i) will benefit the custodial user agent
to the detriment of the user;
(ii) will result in any reasonably
foreseeable harm to the user; or
(iii) is inconsistent with the directions
or reasonable expectations of the user;
(C) shall not collect, use, or share any user data
provided to it by a user, or accessed on a user's
behalf, except as reasonably necessary to provide the
services the user has delegated to the custodial user
agent, and shall not use, share, or retain such data
for advertising, behavioral profiling, sale, or any
other secondary commercial purpose;
(D) shall act with the care, skill, and diligence
that an ordinarily prudent person would reasonably be
expected to exercise in a like position and under
similar circumstances;
(E) shall maintain real-time records of actions
taken on the user's behalf and make such records
available to the user upon request, with the exception
of any records that a user has previously directed a
custodial user agent to delete; and
(F) shall not delegate, assign, or otherwise
transfer any authority granted by a user to any other
entity, agent, or artificial intelligence system
operated by another entity unless--
(i) such delegation, assignment, or
transfer is pursuant to the express, specific,
and revocable authorization of the user; and
(ii) any such permitted delegate, assignee,
or transferree is subject to the duties
established under this subsection to the same
extent as the custodial user agent.
(2) Responsibility of provider.--A custodial user agent
provider shall establish and maintain reasonable measures to
ensure that each custodial user agent it operates or offers
complies with the duties under this subsection, and a pattern
or practice of violations by any custodial user agent of a
provider shall be attributable to the custodial user agent
provider for purposes of deregistration under subsection (e)
and enforcement under section 4.
(3) Non-waiver.--The duties established under this
subsection may not be waived, limited, or modified by contract,
by terms of service, or by any form of user consent, and a
user's reasonable expectations for purposes of paragraph
(1)(B)(iii) shall be determined without regard to any term of
service inconsistent with such duties.
(h) Non-Discrimination.--
(1) In general.--A large online platform provider shall
facilitate and maintain an interface accessible to custodial
user agents based on fair, reasonable, and nondiscriminatory
terms.
(2) Reasonable thresholds, access standards, and fees.--
(A) In general.--A large online platform provider
may establish reasonable thresholds related to the
frequency, nature, and volume of requests by a
custodial user agent to access resources maintained by
the large online platform provider, beyond which the
large online platform provider may assess a reasonable
fee for such access.
(B) Usage expectations.--A large online platform
provider may establish fair, reasonable, and
nondiscriminatory usage expectations to govern access
by custodial user agents, including fees or usage
limitations for custodial user agent providers that
exceed those usage expectations.
(C) Limitation on fees and usage expectations.--
(i) In general.--Any fee, usage limitation,
or usage expectation established under
subparagraph (A) or (B) shall be reasonably
proportional to the cost, complexity, and risk
to the large online platform provider of
providing such access.
(ii) Review.--A custodial user agent
provider may petition the Commission to review
the reasonableness of any fee, usage
limitation, or usage expectation established
under subparagraph (A) or (B).
(D) Notice.--A large online platform provider shall
provide public notice of any fees, usage limitation, or
usage expectations established under subparagraph (A)
or (B), including reasonable advance notice of any
changes.
(E) Security and privacy standards.--
(i) Reasonable access standards.--
(I) In general.--A large online
platform provider shall, consistent
with industry best practices, set
privacy and security standards for
access by custodial user agents to the
extent reasonably necessary to address
a threat to the large online platform
or user data, and shall report any
suspected violations of those standards
to the Commission.
(II) Filing with commission; public
accessibility.--A large online platform
provider shall file the privacy and
security standards developed under
subclause (I) with the Commission,
which the Commission shall make
publicly available.
(ii) Report and appeal of denied access.--
(I) Report to commission upon
denial.--A large online platform
provider that denies access to a
custodial user agent under standards
set pursuant to clause (i) shall submit
to the Commission, in such form the
Commission requires, a report
describing the basis for the denial.
(II) Notification of denial.--A
large online platform provider that
denies access to a custodial user agent
under standards set pursuant to clause
(i) shall provide the custodial user
agent provider a notice containing
rationale for why the custodial user
agent failed to meet the privacy and
security standards.
(III) Period to cure.--A large
online platform provider that denies
access to a custodial user agent under
the standards set pursuant to clause
(i) shall allow the custodial user
agent provider 14 calendar days to meet
such standards, during which period the
large online platform provider may deny
the custodial user agent access until
such time as the custodial user agent
provider can demonstrate that the
custodial user agent meets such
standards.
(IV) Appeal of denial.--A custodial
user agent provider may appeal a denial
under this subparagraph to the
Commission and the Commission may grant
access to the custodial user agent if
the Commission finds that the denial by
the large online platform provider was
arbitrary, capricious, or not supported
by the information submitted by the
large online platform provider.
(V) Publicly available reports.--
Each report submitted under this
section shall be publicly available
with personally identifiable
information and business sensitive data
removed.
(3) Prohibited changes to interfaces.--A change to an
interface or terms of use made with the purpose, or substantial
effect, of unreasonably denying access or undermining access by
authorized custodial user agents shall be considered a
violation of the duty under paragraph (1) to facilitate and
maintain access based on fair, reasonable, and
nondiscriminatory terms.
(4) Functional equivalence.--A large online platform
provider that maintains interoperability between its own large
online platform and other products, services, or affiliated
offerings of such provider that constitute a custodial user
service shall offer a functionally equivalent version of that
interface to competing custodial user agents.
(5) Interface information.--
(A) In general.--Not later than 120 days after the
date of enactment of this Act, a large online platform
provider shall disclose to competing custodial user
agent providers complete and accurate documentation
describing access to the interoperability interface
required under this section.
(B) Contents.--The documentation required under
subparagraph (A)--
(i) is limited to interface documentation
necessary to achieve development and operation
of interoperable products and services; and
(ii) does not require the disclosure of the
source code of a large online platform.
(6) Notice of changes.--A large online platform provider
shall provide reasonable advance notice to any custodial user
agent provider, which may be provided through public notice, of
any change to an interface maintained by the large online
platform provider that will affect the interoperability of a
custodial user agent.
(i) Fees.--A custodial user agent provider may charge users a fee
for the provision of the products or services described in subsection
(a).
(j) Extent of Access Rights.--Nothing in this section shall be
construed to confer greater rights of access for a custodial user agent
to a large online platform than are accessible to a user.
SEC. 4. IMPLEMENTATION AND ENFORCEMENT.
(a) Regulations.--Not later than 1 year after the date of enactment
of this Act, the Commission, in coordination with the Consumer
Financial Protection Bureau, the Federal Deposit Insurance Corporation,
and the Office of the Comptroller of the Currency, shall promulgate
regulations to implement this Act.
(b) Authentication.--Not later than 180 days after the date of
enactment of this Act, the Commission, in consultation with relevant
industry stakeholders, shall establish rules and procedures to
facilitate the verification of the validity of requests from custodial
user agents to obtain user data on behalf of a user.
(c) Technical Standards.--Not later than 180 days after the date of
enactment of this Act, the Director of the National Institute of
Standards and Technology shall identify open protocols, or develop and
publish model technical standards if no such protocols exist, by which
to make popular classes of online services more accessible to custodial
user agents, including--
(1) online messaging;
(2) multimedia sharing and social media services;
(3) electronic commerce;
(4) personal finance;
(5) artificial intelligence; and
(6) verifiable delegation, including--
(A) open protocols and standards for scope-limited
and revocable delegation credentials;
(B) verification of custodial user agent identity
and registration status;
(C) real-time communication and effectuation of
revocation; and
(D) the creation of auditable records of actions
taken by custodial user agents on behalf of users.
(d) Compliance Assessment.--The Commission shall regularly assess
compliance by large online platform providers and custodial user agents
with the provisions of this Act.
(e) Complaints.--The Commission shall establish procedures under
which a user, a large online platform provider, or a custodial user
agent may file a complaint alleging that a large online platform
provider or a custodial user agent has violated this Act.
(f) Enforcement.--
(1) Unfair or deceptive acts or practices.--A violation of
this Act, or regulations enacted pursuant to this Act, shall be
treated as a violation of a rule defining an unfair or
deceptive act or practice prescribed under section 18(a)(1)(B)
of the Federal Trade Commission Act (15 U.S.C. 57a(a)(1)(B)).
(2) Powers of commission.--
(A) In general.--Except as provided in subparagraph
(C), the Commission shall enforce this Act in the same
manner, by the same means, and with the same
jurisdiction, powers, and duties as though all
applicable terms and provisions of the Federal Trade
Commission Act (15 U.S.C. 41 et seq.) were incorporated
into and made a part of this Act.
(B) Privileges and immunities.--Except as provided
in subparagraph (C), any person who violates section 3
shall be subject to the penalties and entitled to the
privileges and immunities provided in the Federal Trade
Commission Act (15 U.S.C. 41 et seq.).
(C) Nonprofit organizations and common carriers.--
Notwithstanding section 4 or 5(a)(2) of the Federal
Trade Commission Act (15 U.S.C. 44, 45(a)(2)) or any
jurisdictional limitation of the Commission, the
Commission shall also enforce this Act, in the same
manner provided in subparagraphs (A) and (B) of this
paragraph, with respect to common carriers subject to
the Communications Act of 1934 (47 U.S.C. 151 et seq.).
(D) Fines.--In assessing any fine for a violation
of this Act, the Commission shall consider each
individual user affected by a violation of this Act as
an individual violation.
(g) Interagency Coordination.--Not later than 180 days after the
date of enactment of this Act, the Commission shall establish an
interagency working group, consisting of the Commission, the Director
of the Consumer Financial Protection Bureau, the Federal Deposit
Insurance Corporation, the Comptroller of the Currency, the Secretary
of the Treasury, the Secretary of Homeland Security, the Secretary of
Commerce, the Attorney General, and the Chairman of the Securities and
Exchange Commission, for the purpose of developing proposals to prevent
harms to businesses and the Government resulting from custodial user
agents undertaking actions on behalf of a principal as a result of
fraud, misuse, or genuine mistake.
(h) Preemption.--The provisions of this Act shall preempt any State
law only to the extent that such State law is inconsistent with the
provisions of this Act.
(i) Effective Date.--This Act shall take effect on the earlier of--
(1) date on which the Commission promulgates regulations
under subsection (a); or
(2) 1 year after the date of enactment of this Act.
SEC. 5. RELATION TO OTHER LAWS.
(a) Privacy and Security Laws.--Nothing in this Act shall be
construed to modify, limit, or supersede the operation of any privacy
or security provision in--
(1) section 552a of title 5, United States Code (commonly
known as the ``Privacy Act of 1974'');
(2) the Right to Financial Privacy Act of 1978 (12 U.S.C.
3401 et seq.);
(3) the Fair Credit Reporting Act (15 U.S.C. 1681 et seq.);
(4) the Fair Debt Collection Practices Act (15 U.S.C. 1692
et seq.);
(5) the Children's Online Privacy Protection Act of 1998
(15 U.S.C. 6501 et seq.);
(6) title V of the Gramm-Leach-Bliley Act (15 U.S.C. 6801
et seq.);
(7) chapters 119, 123, and 206 of title 18, United States
Code;
(8) section 444 of the General Education Provisions Act (20
U.S.C. 1232g) (commonly referred to as the ``Family Educational
Rights and Privacy Act of 1974'');
(9) section 445 of the General Education Provisions Act (20
U.S.C. 1232h);
(10) the Privacy Protection Act of 1980 (42 U.S.C. 2000aa
et seq.);
(11) the regulations promulgated under section 264(c) of
the Health Insurance Portability and Accountability Act of 1996
(42 U.S.C. 1320d-2 note), as those regulations relate to--
(A) a person described in section 1172(a) of the
Social Security Act (42 U.S.C. 1320d-1(a)); or
(B) transactions referred to in section 1173(a)(1)
of the Social Security Act (42 U.S.C. 1320d-2(a)(1));
(12) the Communications Assistance for Law Enforcement Act
(47 U.S.C. 1001 et seq.);
(13) sections 222 and 227 of the Communications Act of 1934
(47 U.S.C. 222, 227); or
(14) any other privacy or security provision of Federal
law.
(b) Antitrust Laws.--
(1) In general.--Nothing in this Act shall be construed to
modify, impair, or supersede the operation of any of the
antitrust laws.
(2) Antitrust laws defined.--The term ``antitrust laws''--
(A) has the meaning given that term in subsection
(a) of the first section of the Clayton Act (15 U.S.C.
12(a)); and
(B) includes section 5 of the Federal Trade
Commission Act (15 U.S.C. 45) to the extent that
section applies to unfair methods of competition.
<all>