Youth AI Privacy Act

Full Title:
Youth AI Privacy Act

Summary#

This bill, the Youth AI Privacy Act, aims to limit how AI chatbots interact with and use data from people under 18. Its main changes require clear disclosures to minors, restrict how companies can use minors’ data, ban certain design features that encourage heavy use, and bar advertising and profiling of minors through chatbots. The overall goal is to reduce privacy harms, manipulative design, and covert advertising aimed at children and teens.

  • Required disclosures: Chatbots that a deployer (the company that makes a chatbot available) knows a user is a minor must clearly say the user is talking to AI, not a human, at the start of a session and at least every 30 minutes.
  • Limits on data use: The Federal Trade Commission (FTC or “the Commission”) must set rules that generally stop companies that know a user is a minor from processing that minor’s personal data to shape outputs, except for recent input during the current session (FTC will set how long that can be).
  • Bans on addictive features: Within one year the FTC must ban features for known-minor users that reward frequent use, send push notifications (except the required disclosure), show social-typing indicators, or produce unsolicited messages.
  • No advertising or profiling: Companies that know a user is a minor may not advertise to them via a chatbot, promote products where a financial tie affects credibility, or profile minors (classify personality/behavior) using their data.
  • Limits on training data: Companies that know a user is a minor generally may not use that minor’s personal data to train AI models, except to test or fix risks of harm.
  • Enforcement and remedies: The FTC enforces the law as an unfair or deceptive practice; states’ attorneys general may sue; parents or guardians can sue companies for violations and seek damages and other relief.
  • Research and surveys: The bill authorizes $50 million per year (2027–2030) for research on AI chatbots’ health effects on youth and requires CDC/NIH to add chatbot questions to national surveys.

What it means for you#

  • Minors and parents

    • Chatbots that a company knows a user is under 18 must tell the user they are interacting with AI, not a person, at the start of a session and every 30 minutes.
    • Companies should not be using a minor’s past data to personalize responses beyond a FTC-set recent time frame.
    • Parents or legal guardians may sue companies for violations of the safe-design and data privacy rules.
  • Companies that run chatbots (deployers)

    • Must add clear, age-appropriate disclosures and remove or stop certain engagement features when they know a user is a minor.
    • Must stop advertising to or profiling known-minor users and generally may not use minors’ data to train models.
    • Face FTC enforcement, possible state lawsuits, and private suits by parents, including possible damages and legal fees.
  • Developers (those who build or substantially modify chatbot algorithms)

    • Prohibited from building, for known-minor users, features that encourage compulsive use as defined by the FTC rules.
    • May be subject to enforcement where their design choices enable violations.
  • Researchers and public health agencies

    • Will receive funding for research ($50 million per year, 2027–2030).
    • CDC and NIH must include questions about chatbot use in national surveys to track prevalence and effects.
  • State attorneys general

    • May sue on behalf of residents for violations and coordinate with the FTC; states can adopt stronger protections than this law allows.

Expenses#

Estimated public cost: $50 million per year authorized for research from 2027 through 2030; no other cost estimate is provided.

  • Authorized research funding: $50,000,000 per year for fiscal years 2027–2030 for studying health and developmental effects of AI chatbots on minors.
  • FTC rulemaking and enforcement costs: not estimated in the bill text; the FTC will need to write rules and guidance and carry out enforcement.
  • Business compliance costs: companies will likely have costs to change designs, data practices, and recordkeeping to comply; no dollar estimates are provided.
  • Litigation and enforcement: private suits and state enforcement could create additional public and private legal costs; no estimate available.
  • If no fiscal note or budget estimate beyond the research authorization is provided: No publicly available information.

Proponents' View#

  • The bill appears intended to protect minors from privacy harms and manipulative design in AI chatbots by requiring transparency and limiting data-driven personalization and training.
  • Supporters may argue this reduces the risk that minors form emotional dependence on chatbots or disclose sensitive information used for personalization or model training.
  • This could be seen as preventing covert advertising and profiling of minors inside conversational AI.
  • The bill funds research and better data collection to understand how chatbots affect youth mental health and behavior.
  • The private right of action and state enforcement give multiple ways to hold companies accountable.

Opponents' View#

  • One concern is that the bill leaves key details to FTC rulemaking (for example, how the agency will define a “session” and the “maximum permitted period of use”), creating near-term uncertainty for companies and regulators.
  • The standard that a deployer “has knowledge fairly implied on the basis of objective circumstances” that a user is a minor may be hard to apply in practice. The bill says companies are not required to collect age or add age verification, which could make compliance ambiguous.
  • The broad bans on using input data and on training with minors’ data could limit legitimate uses (for safety, personalization needed for care, or accessibility) unless covered by narrow exceptions; how those exceptions will work is not fully detailed.
  • The private right to sue with possible punitive damages could raise litigation risks and costs for firms, especially smaller companies.
  • It is unclear how the law will interact with existing privacy laws and industry practices, and whether enforcement resources will be sufficient.
  • The bill does not specify exact definitions for “advertise,” “promote,” or when a financial connection “materially affects” credibility, which may create disputes over enforcement.