Stealth Bot Prohibition

Full Title:
Stealth Bot Prohibition Act

Summary#

This bill, the Stealth Bot Prohibition Act, would ban certain hidden or deceptive automated programs (bots) that access websites. Its main change is to make it illegal to run a “stealth bot” that either harms a site’s operation or pretends to be a human for use with generative AI. The bill gives the Federal Trade Commission (FTC) authority to sue for penalties and lets states bring their own civil cases in many situations.

Key points:

  • Prohibits bots that (a) access sites in ways likely to damage or burden their technical or commercial operation, or (b) intentionally hide that they are bots and pretend to be human when used with generative AI.
  • Defines “stealth bot” to include bots that do not identify themselves (for example, via a valid user-agent) or do not disclose the specific nature and purpose of their access, including planned uses like AI training or fine-tuning.
  • The FTC may sue to stop violations or seek civil penalties up to $53,000 per violation, adjusted yearly for inflation.
  • State attorneys general and other state officials may bring civil suits on behalf of residents, with notice rules and limits when the federal government is already suing.
  • The law would start 180 days after it is enacted and allows civil actions for violations that happened within the prior six years.

What it means for you#

  • Website owners and operators

    • May get clearer grounds to sue or get FTC help if hidden bots harm their servers, content, or business.
    • Could see fewer undisclosed data-scraping bots if enforcement is active.
  • Companies that run web crawlers, scrapers, or data-collection bots

    • Must disclose a bot’s identity and the specific purpose of access before the bot interacts with a site, in a format the site operator can access.
    • Could face civil penalties for noncompliance, especially if access is likely to harm a site or the bot disguises itself as a human.
  • Developers and providers of generative AI

    • If their services use data collected by bots that were concealed or misrepresented as human, those bots could be illegal under this bill.
    • May need to change how they acquire training or indexing data and document provenance.
  • Researchers, news organizations, and academics

    • Practical effects depend on how “prior disclosure” and “format the website operator can access” are interpreted; some research or journalistic scraping practices may need to change or obtain permission.
  • Consumers

    • No direct new consumer benefits or changes described in the bill text beyond the general aim of protecting website operations and transparency about automated actors.
  • State governments

    • Can bring civil suits on behalf of residents but must notify the FTC and may be limited if the FTC or U.S. Department of Justice already brought a federal action.

Expenses#

No publicly available information.

  • The bill sets civil penalties (up to $53,000 per violation, adjusted yearly) but provides no fiscal note estimating enforcement or compliance costs.
  • Possible costs that follow from the bill (not estimated in the text):
    • FTC may need extra staff or resources to enforce the law.
    • Businesses and researchers may incur compliance costs to disclose bot identity and purpose or to obtain permission for data collection.
    • States bringing litigation could incur legal costs; businesses defending suits could face legal expenses and possible penalties.

Proponents' View#

  • The bill appears intended to make automated access more transparent and to stop hidden bots that can harm websites or be used to misrepresent human behavior to AI systems.
  • Supporters may argue that requiring disclosure protects website operators’ servers and commercial interests.
  • Making deceptive bot activity a civil violation could give site owners and regulators a clearer tool to stop and penalize harmful scraping or impersonation.
  • Allowing both FTC and state civil actions provides multiple enforcement paths.

Opponents' View#

  • One concern is that key terms are vague. The bill does not clearly define what counts as adequate “prior disclosure,” what technical format is required, or how to measure when access is “reasonably likely” to damage or burden a site.
  • The rule could chill legitimate uses such as academic research, news-gathering, search engine indexing, or benign crawling unless those actors change practices or obtain permission.
  • Compliance and litigation costs for businesses and nonprofits could be substantial, but the bill provides no cost estimates or guidance on low-risk uses.
  • The bill bars the FTC from issuing regulations under this section, which may leave technical standards and enforcement to case-by-case court decisions rather than clear rules.
  • It is unclear how the limitation on FTC rulemaking interacts with the grant of FTC enforcement powers; this could create inconsistent enforcement or uncertainty about expectations.