[Congressional Record Volume 172, Number 8 (Monday, January 12, 2026)]
[Senate]
[Pages S136-S137]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 4168. Mrs. BLACKBURN submitted an amendment intended to be
proposed by her to the bill H.R. 6938, making consolidated
appropriations for the fiscal year ending September 30, 2026, and for
other purposes; which was ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. ___. MAIN EVENT TICKETING ACT.
(a) Short Title.--This section may be cited as the
``Mitigating Automated Internet Networks for Event Ticketing
Act'' or the ``MAIN Event Ticketing Act''.
(b) Strengthening the BOTS Act.--
(1) In general.--Section 2 of the Better Online Ticket
Sales Act of 2016 (15 U.S.C. 45c) is amended--
(A) in subsection (a)(1)--
(i) in subparagraph (A)--
(I) by inserting ``online'' before ``ticket issuer''; and
(II) by striking ``; or'' and inserting a semicolon;
(ii) in subparagraph (B), by striking the period at the end
and inserting ``; or''; and
(iii) by adding at the end the following new subparagraph:
``(C) to use or cause to be used an application, including
a software application, that performs automated tasks to
purchase event tickets from an Internet website or online
service used by an online ticket issuer through the
circumvention of an access control system, security measure,
or other technological control or measure used by such
Internet website or online service to enforce posted online
ticket purchasing order rules of the Internet website or
online service.'';
(B) by redesignating subsections (b) and (c) as subsections
(c) and (d), respectively;
(C) by inserting after subsection (a) the following new
subsection:
``(b) Requiring Online Ticket Issuers to Enforce Site
Policies.--
``(1) Requirement to enforce and update site policies.--
Each online ticket issuer shall--
``(A) establish, implement, and maintain an access control
system, security measure, or other technological control or
measure to
[[Page S137]]
enforce posted event ticket purchasing limits and to maintain
the integrity of posted online ticket purchasing order rules;
and
``(B) regularly evaluate and make adjustments, as
necessary, to such an access control system, security
measure, or other technological control or measure in light
of any material changes in technology, internal or external
threats to system security, and the changing business
arrangements or operations of the ticket issuer.
``(2) Requirement to report incidents of circumvention;
consumer complaints.--
``(A) In general.--Each online ticket issuer shall report
to the Commission any incidents of circumvention of which the
ticket issuer has actual knowledge not later than 30 days
after the incident of circumvention is discovered by the
online ticket issuer.
``(B) Electronic submission.--The Commission may establish
a reporting mechanism to provide for the electronic
submission of reports required by subparagraph (A).
``(C) Coordination with state attorneys general.--The
Commission shall share with State attorneys general, as
appropriate--
``(i) any report received from online ticket issuers under
subparagraph (A); and
``(ii) consumer complaints related to any violation of this
subsection that are submitted through the Commission's
website.
``(3) Requirement to address known causes of
circumvention.--Each online ticket issuer shall take
reasonable steps to improve its access control systems,
security measures, and other technological controls or
measures to address any known or reasonably foreseeable risks
connected to incidents of circumvention.
``(4) Commission guidance.--Not later than 1 year after the
date of enactment of the Mitigating Automated Internet
Networks for Event Ticketing Act, the Commission shall
publish guidance for online ticket issuers regarding
compliance with the requirements of this subsection.'';
(D) in subsection (c), as redesignated by subparagraph (B)
of this paragraph--
(i) by striking ``subsection (a)'' each place it appears
and inserting ``subsection (a) or (b)''; and
(ii) by adding at the end the following new paragraph:
``(3) Limitation on commission guidance.--
``(A) In general.--No guidance issued by the Commission
with respect to this Act shall confer any rights on any
person, State, or locality, nor shall operate to bind the
Commission or any person to the approach recommended in such
guidance.
``(B) Specific allegations.--In any enforcement action
brought pursuant to this Act, the Commission--
``(i) shall allege a specific violation of a provision of
this Act; and
``(ii) may not base an enforcement action on, or execute a
consent order based on, practices that are alleged to be
inconsistent with any such guidance, unless the practices
allegedly violate this Act.'';
(E) in subsection (d), as redesignated by subparagraph (B)
of this paragraph, by striking ``subsection (a)'' each place
it appears and inserting ``subsection (a) or (b)''; and
(F) by adding at the end the following new subsections:
``(e) Law Enforcement Coordination.--
``(1) In general.--The Federal Bureau of Investigation, the
Attorney General, and other relevant State or local law
enforcement officials shall coordinate as appropriate with
the Commission to share information about any known instance
of a cyberattack on a security measure, access control
system, or other technological control or measure on an
Internet website or online service that is used by an online
ticket issuer to enforce posted event ticket purchasing
limits or to maintain the integrity of posted online ticket
purchasing order rules. Such coordination may include
providing information about ongoing investigations, but may
exclude classified information or information that could
compromise a law enforcement or national security effort, as
appropriate.
``(2) Cyberattack defined.--In this subsection, the term
`cyberattack' means an attack, via cyberspace, targeting an
enterprise's use of cyberspace for the purpose of--
``(A) disrupting, disabling, destroying, or maliciously
controlling a computing environment or computing
infrastructure; or
``(B) destroying the integrity of data or stealing
controlled information.
``(f) Congressional Report.--Not later than 1 year after
the date of enactment of this paragraph, the Commission shall
report to Committee on Commerce, Science, and Transportation
of the Senate and the Committee on Energy and Commerce of the
House of Representatives on the status of any enforcement
action taken pursuant to this Act, as well as any identified
limitations to the Commission's ability to pursue incidents
of circumvention described in subsection (a)(1)(A).''.
(2) Additional definitions.--Section 3 of the Better Online
Ticket Sales Act of 2016 (15 U.S.C. 45c note) is amended by
adding at the end the following new paragraphs:
``(5) Circumvention.--The term `circumvention' means the
act of avoiding, bypassing, removing, deactivating, or
otherwise impairing an access control system, security
measure, safeguard, or other technological control or measure
described in section 2.
``(6) Online ticket issuer.--The term `online ticket
issuer' means a ticket issuer that owns or operates an
Internet website or online service that, in the regular
course of trade or business of the issuer, facilitates or
executes the sale of event tickets to the general public.''.
______