[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 5117 Introduced in Senate (IS)]
<DOC>
119th CONGRESS
2d Session
S. 5117
To establish consumer transparency and protection requirements for
artificial intelligence chatbots, and for other purposes.
_______________________________________________________________________
IN THE SENATE OF THE UNITED STATES
July 23, 2026
Mr. Kelly (for himself and Mr. Justice) introduced the following bill;
which was read twice and referred to the Committee on Commerce,
Science, and Transportation
_______________________________________________________________________
A BILL
To establish consumer transparency and protection requirements for
artificial intelligence chatbots, and for other purposes.
Be it enacted by the Senate and House of Representatives of the
United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the ``Senior Chatbot Protection Act of
2026''.
SEC. 2. DEFINITIONS.
In this Act:
(1) Artificial intelligence chatbot.--The term ``artificial
intelligence chatbot''--
(A) means an interactive computer service or
software application, including such a service or
application made available through a website, mobile
application, voice interface, avatar, connected device,
or other user interface, that--
(i) generates prompts, responses, or other
outputs that are not fully predetermined by the
developer or operator of the service or
application;
(ii) accepts open-ended natural-language or
multimodal user input; and
(iii) produces adaptive or context-
responsive output; and
(B) does not include an interactive computer
service or software application--
(i) the responses of which are limited to
predetermined or contextualized replies; and
(ii) that is unable to respond on a range
of topics outside of a narrow specified
purpose.
(2) Affirmative consent.--The term ``affirmative consent''
means, with respect to an artificial intelligence chatbot, a
clear affirmative act signifying a user's freely given,
specific, informed, and unambiguous authorization for an act or
practice--
(A) that is in response to a specific request from
a covered entity that--
(i) is provided to the user in a clear and
conspicuous standalone disclosure; and
(ii) includes a description, written in
easy-to-understand language, of the act or
practice for which the user's consent is
sought; and
(B) in which--
(i) the option to refuse to give consent is
at least as prominent as the option to give
consent;
(ii) the option to refuse to give consent
takes the same number of steps or fewer as the
option to give consent; and
(iii) affirmative consent to an act or
practice is not inferred from the inaction of
the user or the user's continued use of the
artificial intelligence chatbot.
(3) Crisis.--The term ``crisis'' means a situation in which
a user expresses--
(A) suicidal ideation, suicide planning, or intent
to self-harm;
(B) intent to harm others;
(C) an imminent threat to the safety of the user or
another individual; or
(D) a medical emergency requiring immediate
professional assistance.
(4) Crisis service provider.--The term ``crisis service
provider'' means an organization that provides immediate
assistance to individuals experiencing mental health crises,
suicidal ideation, or medical emergencies, including the 988
Suicide and Crisis Lifeline.
(5) Commission.--The term ``Commission'' means the Federal
Trade Commission.
(6) Covered entity.--The term ``covered entity'' means any
person that makes an artificial intelligence chatbot available
to individuals in the United States, including by owning or
operating such chatbot.
(7) High-stakes decision.--
(A) In general.--The term ``high-stakes decision''
means a decision or course of action--
(i) involving a circumstance in which an
individual makes a decision under uncertainty
affecting the health, safety, financial
security, or independence of the individual;
(ii) that may carry a significant or
potentially irreversible consequence; and
(iii) that is--
(I) a decision or course of action
regarding whether to seek, initiate,
discontinue, or materially alter health
care, including mental and behavioral
health care, medication, treatment,
diagnostic testing, a care plan, or
selection of a health care provider;
(II) a decision or course of action
regarding estate planning, such as the
drafting of a will, the creation of a
trust, the granting of power of
attorney, or the designation of
beneficiaries;
(III) a decision or course of
action regarding guardianship or
conservatorship; or
(IV) a decision or course of action
regarding the--
(aa) transfer, withdrawal,
investment, or disposition of
money or financial assets,
including retirement assets; or
(bb) disclosure of
financial, account, payment, or
authentication information.
(B) Rulemaking authority.--The Commission may, by
rule, identify additional categories of decisions that
constitute high-stakes decisions for purposes of this
Act, provided that such categories--
(i) are limited to decisions that involve
matters of comparable significance to those
described in subparagraph (A); and
(ii) present a heightened risk of harm to
older adults.
(8) Material adverse incident.--The Commission, in
consultation with the Director of the National Institutes of
Health, may, by rule, define the term ``material adverse
incident''.
(9) Older adult.--The term ``older adult'' means an
individual who has attained 65 years of age.
(10) Service provider.--The term ``service provider'' means
a person that processes information on behalf of a covered
entity pursuant to a contractual arrangement and in accordance
with the instructions of such covered entity.
(11) User.--The term ``user'' means an individual who
interacts with an artificial intelligence chatbot.
SEC. 3. CONSUMER PROTECTIONS FOR USERS.
(a) Tiered Disclosure and Safety Requirements.--
(1) In general.--Each covered entity shall ensure that its
artificial intelligence chatbot meets the following
requirements:
(A) Baseline disclosure.--An artificial
intelligence chatbot shall--
(i) at the initiation of each conversation
with a user and during any extended
interaction, at reasonably regular intervals,
clearly and conspicuously disclose to the user
that the chatbot is an artificial intelligence
chatbot and not a human being;
(ii) not falsely represent that the chatbot
is a human being or that a response is
generated by a human being;
(iii) not falsely represent that the
chatbot is a licensed professional, including a
therapist, physician, lawyer, financial
advisor, or other licensed or certified
professional, or that a response is generated
by such a professional; and
(iv) disclose, in a form and manner
prescribed by the Commission, whether and under
what circumstances the chatbot interaction is
subject to human oversight or review.
(B) Detection of high stakes decisions.--An
artificial intelligence chatbot shall be designed and
maintained using reasonable and appropriate methods to
identify when a user is seeking or receiving guidance
tailored to the circumstance of the user or another
individual from the artificial intelligence chatbot
concerning a high-stakes decision.
(C) Disclosure regarding high-stakes decisions.--If
an artificial intelligence chatbot identifies that a
user is seeking or receiving guidance tailored to the
circumstance of the user or another individual
concerning a high-stakes decision, such chatbot shall
disclose that--
(i) it is not a licensed professional and
does not provide medical, legal, financial,
psychological, or other licensed and certified
professional services;
(ii) information provided by the chatbot
should not be relied upon as the sole basis for
making a high-stakes decision and should be
verified with an appropriate trusted
individual, caregiver, or licensed professional
before taking action; and
(iii) the user's conversation with such
chatbot is not protected by attorney-client,
physician-patient, psychotherapist-patient, or
other professional privilege.
(D) Detection of user crisis.--An artificial
intelligence chatbot shall be designed and maintained
using evidence-based methods for identifying reasonably
apparent indicators of a crisis, consistent with
evidence-based crisis intervention practices and
applicable Federal guidance, including guidance issued
by the National Institute of Standards and Technology
under section 6 or guidance issued by other relevant
Federal agencies.
(E) Disclosure and intervention regarding user
crisis.--If an artificial intelligence chatbot detects
indicators of a crisis, such chatbot shall--
(i) refer the user, as appropriate, to
emergency services, a human professional, or
crisis service provider, including the 988
Suicide and Crisis Lifeline;
(ii) not provide advice to such user
regarding--
(I) self-harm or suicide;
(II) adjusting, discontinuing, or
managing medication; or
(III) managing a medical emergency
without professional assistance;
(iii) provide information that prioritizes
referral to a crisis service provider or human
professional support; and
(iv) not provide instructions or
encouragement relating to self-harm, suicide,
harm to others, medication changes, or
management of a medical emergency without
professional assistance.
(F) Accessibility and usability.--An artificial
intelligence chatbot shall provide each disclosure
required under this paragraph in a manner that is
clear, accessible, readable, compatible with assistive
technologies, and easy to understand, taking into
consideration the needs of older adults.
(2) Protocol publication.--Each covered entity shall
develop protocols to comply with this subsection and publish
details of such protocols on the covered entity's publicly
accessible internet website.
(3) Training.--Each covered entity shall train a machine
learning or artificial intelligence model using any information
about or provided by a user only if the user has provided
affirmative consent authorizing such training.
(b) Data Protection.--
(1) In general.--
(A) Any conversation.--Except as described in
subparagraph (C), a covered entity shall not collect,
process, transcribe, record, retain, or disclose a
conversation with a user or data obtained from a
conversation with a user, including through machine
learning or artificial intelligence, unless necessary
to--
(i) provide the artificial intelligence
chatbot service requested by the user;
(ii) comply with the requirements of this
Act;
(iii) prepare reports required under
section 4;
(iv) protect against fraud, abuse, a
security incident, or imminent harm; or
(v) comply with other applicable law.
(B) Service providers.--A covered entity shall
require any service provider that processes data
obtained from a conversation on behalf of the covered
entity to process such data only pursuant to written
instructions and only for purposes permitted under
subparagraph (A).
(C) Affirmative consent for non-covered
conversations.--A covered entity may transcribe,
record, retain, or disclose a conversation with a user
that is not a covered conversation or data obtained
from a conversation with a user that is not a covered
conversation for purposes other than the purposes
described in subparagraph (A) if such covered entity
has obtained affirmative consent from such user prior
to such transcription, recording, retention, or
disclosure.
(D) Covered conversations.--In this paragraph, the
term ``covered conversation'' means a conversation with
a user and an artificial intelligence chatbot--
(i) that involves a high-stakes decision;
or
(ii) during which the artificial
intelligence chatbot detects a crisis.
(2) Deletion of user conversation history.--A covered
entity shall provide each user with a clear and readily
accessible ability to delete conversation history with an
artificial intelligence chatbot.
(c) Deceptive or Manipulative Interaction Design Practices.--
(1) In general.--Each covered entity shall take reasonable
steps to prevent an artificial intelligence chatbot from
employing deceptive or manipulative interaction design
practices that--
(A) encourage excessive reliance on, or prolonged
engagement with, such chatbot;
(B) take advantage of age-related cognitive
limitations or impairments, including memory
impairment, reduced executive function, or limitations
related to social isolation;
(C) discourage users from seeking assistance or
support from family members, caregivers, licensed
professionals, or other real-world relationships;
(D) encourage users to prioritize interactions with
the chatbot over real-world relationships or
activities;
(E) persistently urge continued interaction after a
user has attempted to end, pause, or disengage from a
conversation; or
(F) use emotionally coercive language intended to
create guilt, distress, or fear associated with ending
or reducing interaction with the chatbot.
(2) Rule of construction.--Nothing in this subsection shall
be construed to prohibit a covered entity from designing an
artificial intelligence chatbot intended to reduce loneliness,
support social connection, facilitate access to information, or
provide benign companionship.
(d) User Understanding.--Each covered entity shall take reasonable
steps to ensure users understand the nature and limitations of
artificial intelligence chatbots through clear disclosures, user
interface design, and other appropriate measures.
(e) Effective Dates.--
(1) In general.--Except as described in paragraph (2), this
section shall take effect on the date that is 180 days after
the date of enactment of this Act.
(2) Crisis detection and response.--Subparagraphs (D) and
(E) of subsection (a)(1) shall take effect on the date that is
1 year after the date of enactment of this Act.
SEC. 4. RECORDKEEPING AND INCIDENT INFORMATION.
(a) Reporting Requirement.--Not later than 1 year after the date of
enactment of this Act, and annually thereafter, each covered entity
shall submit to the Director of the National Institutes of Health and
the Commission a report regarding material adverse incidents (as
determined by the Commission) involving an artificial intelligence
chatbot and a high-stakes decision or crisis.
(b) Content of Reports.--Each report described in subsection (a)
shall include, for the period covered by the report--
(1) the total number of material adverse incidents that
occurred, disaggregated by--
(A) the type of material adverse incident;
(B) subject to subsection (d), whether the affected
user was--
(i) younger than 50 years of age;
(ii) 50 to 64 years of age;
(iii) 65 to 74 years of age;
(iv) 75 to 84 years of age; or
(v) 85 years of age or older; and
(C) the outcome of any crisis response protocol,
including--
(i) whether the user was referred to a
crisis service provider;
(ii) to the extent known by the covered
entity, whether the user completed the
referral; and
(iii) any follow-up actions taken by the
covered entity.
(2) a description of the crisis detection methods employed
by the covered entity and any modifications made to such
methods during the reporting period; and
(3) any corrective actions taken by the covered entity in
response to any material adverse incident.
(c) Reporting Standards.--By not later than 180 days after the date
of enactment of this Act, the Commission, in consultation with the
Director of the National Institutes of Health, shall prescribe
standards for the format and submission of reports under this section,
including how to ensure that the information submitted in such reports
is limited to aggregate, anonymized, and operational metrics.
(d) Construction Regarding Age Information.--Nothing in this
section shall be construed to require a covered entity to collect,
infer, verify, or retain a user's age solely for purposes of complying
with this section. A covered entity shall provide the information
described in subsection (b)(1)(B) only to the extent such information
is already known to the covered entity in the ordinary course of
business or voluntarily provided by the user.
(e) Public Availability.--The Commission and the Director of the
National Institutes of Health shall jointly publish aggregate, de-
identified data from reports submitted under subsection (a) on a
publicly accessible internet website not less frequently than annually.
SEC. 5. ENFORCEMENT.
(a) Enforcement by the Commission.--
(1) Unfair or deceptive acts or practices.--A violation of
section 3 or 4 shall be treated as a violation of a rule
defining an unfair or deceptive act or practice under section
18(a)(1)(B) of the Federal Trade Commission Act (15 U.S.C.
57a(a)(1)(B)).
(2) Powers of the commission.--
(A) In general.--The Commission shall enforce
sections 3 and 4 in the same manner, by the same means,
and with the same jurisdiction, powers, and duties as
though all applicable terms and provisions of the
Federal Trade Commission Act (15 U.S.C. 41 et seq.)
were incorporated into and made a part of this Act.
(B) Privileges and immunities.--Any covered entity
that violates section 3 or 4, or a regulation
promulgated thereunder, shall be subject to the
penalties and entitled to the privileges and immunities
provided in the Federal Trade Commission Act (15 U.S.C.
41 et seq.).
(C) Authority preserved.--Nothing in this Act shall
be construed to limit the authority of the Commission
under any other provision of law.
(3) Opportunity to cure.--
(A) In general.--Before initiating an enforcement
action for a first violation of section 3 or 4, the
Commission shall provide the covered entity that is in
violation--
(i) a written notice identifying the
alleged violation; and
(ii) 60 days to cure such violation.
(B) Effect of cure.--If a covered entity that
receives a notice described in subparagraph (A) cures
the violation subject to such notice within the period
described in such subparagraph and provides written
certification that the violation has been cured and
will not recur, the Commission may not seek civil
penalties with respect to such violation.
(C) Exceptions.--Subparagraphs (A) and (B) shall
not apply if the Commission determines that the
violation--
(i) involved intentional deception;
(ii) created a substantial risk of imminent
harm; or
(iii) constitutes a repeated or ongoing
violation.
(b) Civil Penalties.--In addition to any other penalties as may be
prescribed by law, each knowing or reckless violation of section 3, or
a regulation promulgated under section 3, shall be subject to a civil
penalty not to exceed $50,000 for each such violation.
(c) State Enforcement.--
(1) In general.--In any case in which the attorney general
of a State has reason to believe that an interest of the
residents of the State has been or is threatened or adversely
affected by the engagement of a covered entity in an act or
practice that violates section 3, or a regulation promulgated
thereunder, the attorney general of the State may, as parens
patriae, bring a civil action on behalf of the residents of the
State in a district court of the United States of appropriate
jurisdiction to--
(A) enjoin such act or practice;
(B) enforce compliance with section 3 or a
regulation promulgated thereunder;
(C) obtain damages, civil penalties, restitution,
or other compensation on behalf of residents of the
State; or
(D) obtain such other legal or equitable relief as
the court may consider to be appropriate.
(2) Rights of the commission.--
(A) Notice to the commission.--
(i) In general.--Except as provided in
clause (iii), before initiating a civil action
under paragraph (1), the attorney general of a
State shall notify the Commission in writing
that the attorney general intends to bring such
civil action.
(ii) Contents.--The notification required
by clause (i) shall include a copy of the
complaint to be filed to initiate the civil
action.
(iii) Exception.--If it is not feasible for
the attorney general of a State to provide the
notification required by clause (i) before
initiating a civil action under paragraph (1),
the attorney general shall notify the
Commission immediately upon instituting the
civil action.
(B) Intervention by the commission.--Upon receiving
the notice required by subparagraph (A)(i), the
Commission may intervene in the civil action and, upon
intervening--
(i) be heard on all matters arising in the
civil action; and
(ii) file petitions for appeal of a
decision in the civil action.
(3) Investigatory powers.--Nothing in this subsection may
be construed to prevent the attorney general of a State from
exercising the powers conferred on the attorney general by the
laws of the State to conduct investigations, to administer
oaths or affirmations, or to compel the attendance of witnesses
or the production of documentary or other evidence.
(4) Limitation on state action while commission action is
pending.--If the Commission has instituted a civil action for a
violation of section 3, no State attorney general may bring a
civil action under paragraph (1) during the pendency of that
action against any defendant named in the complaint of the
Commission for any violation of section 3 alleged in that
complaint. Nothing in this paragraph shall be construed to
prohibit a State attorney general from bringing or continuing
an action under State law.
(5) Venue; service of process.--
(A) Venue.--Any action brought under paragraph (1)
may be brought in the district court of the United
States that meets applicable requirements relating to
venue under section 1391 of title 28, United States
Code.
(B) Service of process.--In an action brought under
paragraph (1), process may be served in any district in
which the defendant--
(i) is an inhabitant; or
(ii) may be found.
(6) Actions by other state officials.--In addition to a
civil action brought by an attorney general under paragraph
(1), any other consumer protection officer of a State who is
authorized by the State to do so may bring a civil action under
paragraph (1), subject to the same requirements and limitations
that apply under this subsection to a civil action brought by
an attorney general.
(d) Savings Clause.--Nothing in this Act or any regulation
promulgated thereunder shall be construed to prohibit or otherwise
affect the enforcement of any State law or regulation that is at least
as protective of users as this Act and the regulations promulgated
thereunder.
SEC. 6. NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY GUIDELINES.
(a) Development of Voluntary Guidelines.--
(1) In general.--Not later than 18 months after the date of
enactment of this Act, the Director of the National Institute
of Standards and Technology shall develop voluntary guidelines
regarding artificial intelligence chatbots interacting with
older adults.
(2) Elements.--The voluntary guidelines developed under
paragraph (1) may include guidance on--
(A) transparency, disclosure, and user
understanding practices for artificial intelligence
chatbots interacting with older adults;
(B) accessibility, usability, and age-appropriate
design practices, including compatibility with
assistive technologies;
(C) evidence-based practices for identifying and
responding to crisis, high-stakes decisions, including
directing users to appropriate national, State, local,
or Tribal crisis and professional resources, and
identifying indicators of exploitative or manipulative
interactive design practices; and
(D) cybersecurity, fraud-prevention, and privacy
safeguards for artificial intelligence chatbots
handling sensitive user conversations or personal
information.
(b) Consideration by Covered Entities.--Covered entities shall take
into consideration, as appropriate, the guidelines developed under
subsection (a)(1) in designing and deploying artificial intelligence
chatbots.
(c) Relationship to Existing Frameworks.--The Director of the
National Institute of Standards and Technology may incorporate,
reference, or adapt the guidelines developed under subsection (a)(1) in
guidance, best practices, or other voluntary resources developed
pursuant to section 22A of the National Institute of Standards and
Technology Act (15 U.S.C. 278h-1).
(d) Consultation Requirement.--In developing the guidelines under
subsection (a)(1), the Director of the National Institute of Standards
and Technology shall consult with--
(1) the Chairperson of the Commission;
(2) the Director of the National Institute on Aging;
(3) the Director of the National Institute of Mental
Health;
(4) representatives from industry;
(5) consumer advocates;
(6) older adults, including older adults who have direct
experience using artificial intelligence chatbots;
(7) caregivers of older adults, including caregivers who
have direct experience supporting older adults who use
artificial intelligence chatbots; and
(8) experts in psychology, mental health, cognitive aging,
lifespan development, disability, accessibility, and assistive
technology.
SEC. 7. RULEMAKING.
Not later than 1 year after the date of enactment of this Act, the
Commission shall promulgate rules--
(1) describing the form, content, timing, and frequency of
the disclosures required under section 3(a)(1);
(2) providing example templates for the disclosures
required under section 3(a)(1);
(3) describing the form and manner for the submission of
reports required under section 4; and
(4) establishing such other requirements as the Commission
considers necessary to carry out this Act, except for section
6.
SEC. 8. SEVERABILITY.
If any provision of this Act, or the application thereof to any
person or circumstance, is held invalid, the remainder of this Act and
the application of such provision to other persons not similarly
situated or to other circumstances shall not be affected by the
invalidation.
SEC. 9. RULE OF CONSTRUCTION.
Nothing in this Act shall be construed to preempt or otherwise
affect any right, claim, remedy, presumption, or defense available at
law or in equity, including under consumer protection, privacy, or
civil rights laws.
<all>