[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 5051 Introduced in Senate (IS)]

<DOC>






119th CONGRESS
  2d Session
                                S. 5051

   To promote competition and reduce consumer switching costs in the 
         provision of online services, and for other purposes.


_______________________________________________________________________


                   IN THE SENATE OF THE UNITED STATES

                             July 21, 2026

  Mr. Warner introduced the following bill; which was read twice and 
   referred to the Committee on Commerce, Science, and Transportation

_______________________________________________________________________

                                 A BILL


 
   To promote competition and reduce consumer switching costs in the 
         provision of online services, and for other purposes.

    Be it enacted by the Senate and House of Representatives of the 
United States of America in Congress assembled,

SECTION 1. SHORT TITLE.

    This Act may be cited as the ``Artificial Intelligence Access, 
Gatekeeper Exchange, and Nondiscriminatory Transfer Act of 2026'' or 
the ``AI AGENT Act of 2026''.

SEC. 2. DEFINITIONS.

    In this Act:
            (1) Artificial intelligence; artificial intelligence 
        system.--The terms ``artificial intelligence'' and ``artificial 
        intelligence system'' have the meanings given those terms, 
        respectively, in section 5002 of the National Artificial 
        Intelligence Initiative Act of 2020 (15 U.S.C. 9401).
            (2) Commission.--The term ``Commission'' means the Federal 
        Trade Commission.
            (3) Custodial user agent.--The term ``custodial user 
        agent'' means a software-based agent that is expressly 
        authorized by a user to interact with a large online platform 
        provider on that user's behalf in a transparent, documented, 
        scope-limited, and revocable manner.
            (4) Custodial user agent provider.--The term ``custodial 
        user agent provider''--
                    (A) means any entity that operates or offers 1 or 
                more custodial user agents; and
                    (B) includes a user who operates a custodial user 
                agent on the user's own behalf and not on behalf of any 
                other user.
            (5) Electronic commerce.--The term ``electronic commerce'' 
        has the meaning given that term in section 2301 of title 41, 
        United States Code.
            (6) Interoperability interface.--The term 
        ``interoperability interface'' means an electronic interface 
        maintained by a large online platform for purposes of achieving 
        interoperability.
            (7) Large online platform.--The term ``large online 
        platform'' means a product, application, or service provided by 
        an online platform that has more than 50,000,000 customers or 
        subscribers in the United States in any calendar month during 
        the preceding 12-month period.
            (8) Large online platform provider.--The term ``large 
        online platform provider'' means an online provider that 
        provides, manages, or controls a large online platform.
            (9) Online provider.--The term ``online provider'' means a 
        consumer-facing communications, retail, or information services 
        provider, including a provider of social media, electronic 
        commerce, personal finance, or artificial intelligence 
        services.
            (10) Open protocol.--The term ``open protocol'' means a 
        publicly available technical standard that--
                    (A) enables interoperability and data exchange 
                between large online platforms;
                    (B) is free from--
                            (i) licensing fees; and
                            (ii) patent restrictions; and
                    (C) governs how large online platforms communicate 
                and exchange data with each other.
            (11) Social graph data.--The term ``social graph data'' 
        means data that represents a person's connections and 
        interactions within a social media service, including--
                    (A) content generated by the person;
                    (B) the person's responses to the content of other 
                users and entities, including comments, reactions, 
                mentions, reposts, shares, and other engagements in a 
                manner that excludes content of third-party users;
                    (C) the person's public profile;
                    (D) metadata associated with the content and 
                interactions under subparagraphs (A), (B), and (C); and
                    (E) relational references sufficient to maintain 
                the associations among data elements described in 
                subparagraphs (A) through (D).
            (12) Social media service.--The term ``social media 
        service'' means a website, online or mobile application, 
        operating system, digital assistant, or online service that 
        predominantly provides a community forum for user-generated 
        content, such as sharing videos, images, games, audio files, or 
        other content.
            (13) User data.--
                    (A) In general.--The term ``user data'' means 
                information that is--
                            (i) collected or otherwise processed, 
                        directly or indirectly, by an online provider; 
                        and
                            (ii) linked, or reasonably linkable, to a 
                        specific person.
                    (B) Exclusion.--The term ``user data'' does not 
                include information that is rendered wholly unusable or 
                unreadable.
                    (C) Social media services.--For large online 
                platforms that are social media services, the term 
                ``user data'' includes social graph data.

SEC. 3. DELEGATABILITY.

    (a) Individual's Right of Delegation.--Each end user of a large 
online platform shall have the right to designate 1 or more custodial 
user agents offered by a custodial user agent provider acting in 
compliance with subsection (d), as the user's authorized representative 
to manage the user's online interactions, electronic commerce 
decisions, user-generated content, and account settings on a large 
online platform on the same terms as a user, as rendered by that large 
online platform.
    (b) General Duty of Large Online Platform Providers.--A large 
online platform provider shall maintain a set of transparent third-
party-accessible interfaces by which a user may delegate a custodial 
user agent to manage the user's online interactions, electronic 
commerce decisions, user-generated content, and account settings on a 
large online platform on the same terms as a user.
    (c) Authentication.--Not later than 180 days after the date of 
enactment of this Act, the Commission shall establish rules and 
procedures to facilitate a custodial user agent's ability to obtain 
access pursuant to subsection (a) in a way that ensures that--
            (1) a request for access on behalf of a user is a 
        verifiable request; and
            (2) a user has a transparent, easily implementable method 
        to revoke a prior delegation, including a mechanism to promptly 
        communicate revocation requests to a large online platform 
        provider.
    (d) Registration With the Commission.--
            (1) In general.--A custodial user agent provider shall 
        register with the Commission as a condition of, and prior to, 
        any custodial user agent operated or offered by that provider 
        accessing an interface described in subsection (a). The 
        Commission may establish uniform terms and scope of service, by 
        which a custodial user agent provider may register through 
        self-attestation. Not later than 180 days after the date of 
        submission of a registration under this paragraph, the 
        Commission, or any recognized certification body described in 
        paragraph (4), shall evaluate the registration.
            (2) Commission authority.--The Commission may establish 
        specialized terms of service, including authorized scope of 
        delegated access, appropriate for custodial user agents in 
        specific commercial settings given the privacy, financial 
        security, and personal safety implications of such access.
            (3) Embedded agents.--The Commission may establish 
        specialized terms of service, including ensuring functional 
        equivalence for competing custodial user agents, for any 
        custodial user agent provided by a large online platform 
        provider that it determines to offer a service that is 
        competitive with the service of other custodial user agents.
            (4) Recognized certification bodies.--
                    (A) In general.--The Commission may recognize 1 or 
                more independent certification bodies that--
                            (i) maintain and publish standards of 
                        conduct, governance, and technical practices 
                        for custodial user agents that meet or exceed 
                        the duties established under subsection (g); 
                        and
                            (ii) conduct periodic assessments of 
                        conformity with those standards described in 
                        clause (i).
                    (B) Effect of certification.--Certification in good 
                standing by a recognized certification body shall 
                constitute a rebuttable presumption of compliance with 
                subsections (g) and shall be considered by the 
                Commission in any related proceeding.
                    (C) Independence.--The Commission shall not 
                recognize a certification body that is owned or 
                controlled by, or that derives a majority of its 
                revenue from, any single custodial user agent provider 
                or large online platform provider.
    (e) Deregistration by the Commission.--The Commission shall 
establish rules and procedures to deregister a custodial user agent 
provider that the Commission determines--
            (1) has violated the duties established under subsection 
        (g); or
            (2) operates or offers a custodial user agent that has 
        violated the duties established under subsection (g).
    (f) Revocation of Access Rights.--A large online platform provider 
may revoke or deny access for any custodial user agent--
            (1) the custodial user agent provider of which fails to 
        register with the Commission;
            (2) that repeatedly facilitates fraudulent or malicious 
        activity; or
            (3) for which a customer has revoked express written 
        consent, pursuant to a method established under subsection 
        (c)(2).
    (g) Duties of a Custodial User Agent.--
            (1) In general.--A custodial user agent--
                    (A) shall reasonably safeguard the privacy and 
                security of user data provided to it by a user, or 
                accessed on a user's behalf;
                    (B) shall not access or manage a user's online 
                interactions, electronic commerce decisions, financial 
                accounts, content, or account settings in any way 
                that--
                            (i) will benefit the custodial user agent 
                        to the detriment of the user;
                            (ii) will result in any reasonably 
                        foreseeable harm to the user; or
                            (iii) is inconsistent with the directions 
                        or reasonable expectations of the user;
                    (C) shall not collect, use, or share any user data 
                provided to it by a user, or accessed on a user's 
                behalf, except as reasonably necessary to provide the 
                services the user has delegated to the custodial user 
                agent, and shall not use, share, or retain such data 
                for advertising, behavioral profiling, sale, or any 
                other secondary commercial purpose;
                    (D) shall act with the care, skill, and diligence 
                that an ordinarily prudent person would reasonably be 
                expected to exercise in a like position and under 
                similar circumstances;
                    (E) shall maintain real-time records of actions 
                taken on the user's behalf and make such records 
                available to the user upon request, with the exception 
                of any records that a user has previously directed a 
                custodial user agent to delete; and
                    (F) shall not delegate, assign, or otherwise 
                transfer any authority granted by a user to any other 
                entity, agent, or artificial intelligence system 
                operated by another entity unless--
                            (i) such delegation, assignment, or 
                        transfer is pursuant to the express, specific, 
                        and revocable authorization of the user; and
                            (ii) any such permitted delegate, assignee, 
                        or transferree is subject to the duties 
                        established under this subsection to the same 
                        extent as the custodial user agent.
            (2) Responsibility of provider.--A custodial user agent 
        provider shall establish and maintain reasonable measures to 
        ensure that each custodial user agent it operates or offers 
        complies with the duties under this subsection, and a pattern 
        or practice of violations by any custodial user agent of a 
        provider shall be attributable to the custodial user agent 
        provider for purposes of deregistration under subsection (e) 
        and enforcement under section 4.
            (3) Non-waiver.--The duties established under this 
        subsection may not be waived, limited, or modified by contract, 
        by terms of service, or by any form of user consent, and a 
        user's reasonable expectations for purposes of paragraph 
        (1)(B)(iii) shall be determined without regard to any term of 
        service inconsistent with such duties.
    (h) Non-Discrimination.--
            (1) In general.--A large online platform provider shall 
        facilitate and maintain an interface accessible to custodial 
        user agents based on fair, reasonable, and nondiscriminatory 
        terms.
            (2) Reasonable thresholds, access standards, and fees.--
                    (A) In general.--A large online platform provider 
                may establish reasonable thresholds related to the 
                frequency, nature, and volume of requests by a 
                custodial user agent to access resources maintained by 
                the large online platform provider, beyond which the 
                large online platform provider may assess a reasonable 
                fee for such access.
                    (B) Usage expectations.--A large online platform 
                provider may establish fair, reasonable, and 
                nondiscriminatory usage expectations to govern access 
                by custodial user agents, including fees or usage 
                limitations for custodial user agent providers that 
                exceed those usage expectations.
                    (C) Limitation on fees and usage expectations.--
                            (i) In general.--Any fee, usage limitation, 
                        or usage expectation established under 
                        subparagraph (A) or (B) shall be reasonably 
                        proportional to the cost, complexity, and risk 
                        to the large online platform provider of 
                        providing such access.
                            (ii) Review.--A custodial user agent 
                        provider may petition the Commission to review 
                        the reasonableness of any fee, usage 
                        limitation, or usage expectation established 
                        under subparagraph (A) or (B).
                    (D) Notice.--A large online platform provider shall 
                provide public notice of any fees, usage limitation, or 
                usage expectations established under subparagraph (A) 
                or (B), including reasonable advance notice of any 
                changes.
                    (E) Security and privacy standards.--
                            (i) Reasonable access standards.--
                                    (I) In general.--A large online 
                                platform provider shall, consistent 
                                with industry best practices, set 
                                privacy and security standards for 
                                access by custodial user agents to the 
                                extent reasonably necessary to address 
                                a threat to the large online platform 
                                or user data, and shall report any 
                                suspected violations of those standards 
                                to the Commission.
                                    (II) Filing with commission; public 
                                accessibility.--A large online platform 
                                provider shall file the privacy and 
                                security standards developed under 
                                subclause (I) with the Commission, 
                                which the Commission shall make 
                                publicly available.
                            (ii) Report and appeal of denied access.--
                                    (I) Report to commission upon 
                                denial.--A large online platform 
                                provider that denies access to a 
                                custodial user agent under standards 
                                set pursuant to clause (i) shall submit 
                                to the Commission, in such form the 
                                Commission requires, a report 
                                describing the basis for the denial.
                                    (II) Notification of denial.--A 
                                large online platform provider that 
                                denies access to a custodial user agent 
                                under standards set pursuant to clause 
                                (i) shall provide the custodial user 
                                agent provider a notice containing 
                                rationale for why the custodial user 
                                agent failed to meet the privacy and 
                                security standards.
                                    (III) Period to cure.--A large 
                                online platform provider that denies 
                                access to a custodial user agent under 
                                the standards set pursuant to clause 
                                (i) shall allow the custodial user 
                                agent provider 14 calendar days to meet 
                                such standards, during which period the 
                                large online platform provider may deny 
                                the custodial user agent access until 
                                such time as the custodial user agent 
                                provider can demonstrate that the 
                                custodial user agent meets such 
                                standards.
                                    (IV) Appeal of denial.--A custodial 
                                user agent provider may appeal a denial 
                                under this subparagraph to the 
                                Commission and the Commission may grant 
                                access to the custodial user agent if 
                                the Commission finds that the denial by 
                                the large online platform provider was 
                                arbitrary, capricious, or not supported 
                                by the information submitted by the 
                                large online platform provider.
                                    (V) Publicly available reports.--
                                Each report submitted under this 
                                section shall be publicly available 
                                with personally identifiable 
                                information and business sensitive data 
                                removed.
            (3) Prohibited changes to interfaces.--A change to an 
        interface or terms of use made with the purpose, or substantial 
        effect, of unreasonably denying access or undermining access by 
        authorized custodial user agents shall be considered a 
        violation of the duty under paragraph (1) to facilitate and 
        maintain access based on fair, reasonable, and 
        nondiscriminatory terms.
            (4) Functional equivalence.--A large online platform 
        provider that maintains interoperability between its own large 
        online platform and other products, services, or affiliated 
        offerings of such provider that constitute a custodial user 
        service shall offer a functionally equivalent version of that 
        interface to competing custodial user agents.
            (5) Interface information.--
                    (A) In general.--Not later than 120 days after the 
                date of enactment of this Act, a large online platform 
                provider shall disclose to competing custodial user 
                agent providers complete and accurate documentation 
                describing access to the interoperability interface 
                required under this section.
                    (B) Contents.--The documentation required under 
                subparagraph (A)--
                            (i) is limited to interface documentation 
                        necessary to achieve development and operation 
                        of interoperable products and services; and
                            (ii) does not require the disclosure of the 
                        source code of a large online platform.
            (6) Notice of changes.--A large online platform provider 
        shall provide reasonable advance notice to any custodial user 
        agent provider, which may be provided through public notice, of 
        any change to an interface maintained by the large online 
        platform provider that will affect the interoperability of a 
        custodial user agent.
    (i) Fees.--A custodial user agent provider may charge users a fee 
for the provision of the products or services described in subsection 
(a).
    (j) Extent of Access Rights.--Nothing in this section shall be 
construed to confer greater rights of access for a custodial user agent 
to a large online platform than are accessible to a user.

SEC. 4. IMPLEMENTATION AND ENFORCEMENT.

    (a) Regulations.--Not later than 1 year after the date of enactment 
of this Act, the Commission, in coordination with the Consumer 
Financial Protection Bureau, the Federal Deposit Insurance Corporation, 
and the Office of the Comptroller of the Currency, shall promulgate 
regulations to implement this Act.
    (b) Authentication.--Not later than 180 days after the date of 
enactment of this Act, the Commission, in consultation with relevant 
industry stakeholders, shall establish rules and procedures to 
facilitate the verification of the validity of requests from custodial 
user agents to obtain user data on behalf of a user.
    (c) Technical Standards.--Not later than 180 days after the date of 
enactment of this Act, the Director of the National Institute of 
Standards and Technology shall identify open protocols, or develop and 
publish model technical standards if no such protocols exist, by which 
to make popular classes of online services more accessible to custodial 
user agents, including--
            (1) online messaging;
            (2) multimedia sharing and social media services;
            (3) electronic commerce;
            (4) personal finance;
            (5) artificial intelligence; and
            (6) verifiable delegation, including--
                    (A) open protocols and standards for scope-limited 
                and revocable delegation credentials;
                    (B) verification of custodial user agent identity 
                and registration status;
                    (C) real-time communication and effectuation of 
                revocation; and
                    (D) the creation of auditable records of actions 
                taken by custodial user agents on behalf of users.
    (d) Compliance Assessment.--The Commission shall regularly assess 
compliance by large online platform providers and custodial user agents 
with the provisions of this Act.
    (e) Complaints.--The Commission shall establish procedures under 
which a user, a large online platform provider, or a custodial user 
agent may file a complaint alleging that a large online platform 
provider or a custodial user agent has violated this Act.
    (f) Enforcement.--
            (1) Unfair or deceptive acts or practices.--A violation of 
        this Act, or regulations enacted pursuant to this Act, shall be 
        treated as a violation of a rule defining an unfair or 
        deceptive act or practice prescribed under section 18(a)(1)(B) 
        of the Federal Trade Commission Act (15 U.S.C. 57a(a)(1)(B)).
            (2) Powers of commission.--
                    (A) In general.--Except as provided in subparagraph 
                (C), the Commission shall enforce this Act in the same 
                manner, by the same means, and with the same 
                jurisdiction, powers, and duties as though all 
                applicable terms and provisions of the Federal Trade 
                Commission Act (15 U.S.C. 41 et seq.) were incorporated 
                into and made a part of this Act.
                    (B) Privileges and immunities.--Except as provided 
                in subparagraph (C), any person who violates section 3 
                shall be subject to the penalties and entitled to the 
                privileges and immunities provided in the Federal Trade 
                Commission Act (15 U.S.C. 41 et seq.).
                    (C) Nonprofit organizations and common carriers.--
                Notwithstanding section 4 or 5(a)(2) of the Federal 
                Trade Commission Act (15 U.S.C. 44, 45(a)(2)) or any 
                jurisdictional limitation of the Commission, the 
                Commission shall also enforce this Act, in the same 
                manner provided in subparagraphs (A) and (B) of this 
                paragraph, with respect to common carriers subject to 
                the Communications Act of 1934 (47 U.S.C. 151 et seq.).
                    (D) Fines.--In assessing any fine for a violation 
                of this Act, the Commission shall consider each 
                individual user affected by a violation of this Act as 
                an individual violation.
    (g) Interagency Coordination.--Not later than 180 days after the 
date of enactment of this Act, the Commission shall establish an 
interagency working group, consisting of the Commission, the Director 
of the Consumer Financial Protection Bureau, the Federal Deposit 
Insurance Corporation, the Comptroller of the Currency, the Secretary 
of the Treasury, the Secretary of Homeland Security, the Secretary of 
Commerce, the Attorney General, and the Chairman of the Securities and 
Exchange Commission, for the purpose of developing proposals to prevent 
harms to businesses and the Government resulting from custodial user 
agents undertaking actions on behalf of a principal as a result of 
fraud, misuse, or genuine mistake.
    (h) Preemption.--The provisions of this Act shall preempt any State 
law only to the extent that such State law is inconsistent with the 
provisions of this Act.
    (i) Effective Date.--This Act shall take effect on the earlier of--
            (1) date on which the Commission promulgates regulations 
        under subsection (a); or
            (2) 1 year after the date of enactment of this Act.

SEC. 5. RELATION TO OTHER LAWS.

    (a) Privacy and Security Laws.--Nothing in this Act shall be 
construed to modify, limit, or supersede the operation of any privacy 
or security provision in--
            (1) section 552a of title 5, United States Code (commonly 
        known as the ``Privacy Act of 1974'');
            (2) the Right to Financial Privacy Act of 1978 (12 U.S.C. 
        3401 et seq.);
            (3) the Fair Credit Reporting Act (15 U.S.C. 1681 et seq.);
            (4) the Fair Debt Collection Practices Act (15 U.S.C. 1692 
        et seq.);
            (5) the Children's Online Privacy Protection Act of 1998 
        (15 U.S.C. 6501 et seq.);
            (6) title V of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 
        et seq.);
            (7) chapters 119, 123, and 206 of title 18, United States 
        Code;
            (8) section 444 of the General Education Provisions Act (20 
        U.S.C. 1232g) (commonly referred to as the ``Family Educational 
        Rights and Privacy Act of 1974'');
            (9) section 445 of the General Education Provisions Act (20 
        U.S.C. 1232h);
            (10) the Privacy Protection Act of 1980 (42 U.S.C. 2000aa 
        et seq.);
            (11) the regulations promulgated under section 264(c) of 
        the Health Insurance Portability and Accountability Act of 1996 
        (42 U.S.C. 1320d-2 note), as those regulations relate to--
                    (A) a person described in section 1172(a) of the 
                Social Security Act (42 U.S.C. 1320d-1(a)); or
                    (B) transactions referred to in section 1173(a)(1) 
                of the Social Security Act (42 U.S.C. 1320d-2(a)(1));
            (12) the Communications Assistance for Law Enforcement Act 
        (47 U.S.C. 1001 et seq.);
            (13) sections 222 and 227 of the Communications Act of 1934 
        (47 U.S.C. 222, 227); or
            (14) any other privacy or security provision of Federal 
        law.
    (b) Antitrust Laws.--
            (1) In general.--Nothing in this Act shall be construed to 
        modify, impair, or supersede the operation of any of the 
        antitrust laws.
            (2) Antitrust laws defined.--The term ``antitrust laws''--
                    (A) has the meaning given that term in subsection 
                (a) of the first section of the Clayton Act (15 U.S.C. 
                12(a)); and
                    (B) includes section 5 of the Federal Trade 
                Commission Act (15 U.S.C. 45) to the extent that 
                section applies to unfair methods of competition.
                                 <all>