Summary#
This bill sets new consumer rules for artificial intelligence chatbots, with special attention to older adults. It requires clear disclosures that a user is talking with a chatbot, steps to detect crises and high‑stakes decisions, limits on when conversations can be collected or used for training, and rules against manipulative design. The Federal Trade Commission (FTC) enforces the law, and the National Institute of Standards and Technology (NIST) must publish voluntary guidelines for chatbots that interact with older adults.
- Chatbots must tell users they are not human and must not claim to be licensed professionals.
- Chatbots must try to detect crises (suicide risk, intent to harm, medical emergency) and refer users to emergency or crisis services instead of giving certain kinds of advice.
- Chatbots must try to detect when a user is facing a “high‑stakes decision” (health, finances, guardianship, estate planning) and warn that the bot is not a licensed professional and that users should verify with trusted people or professionals.
- Covered entities may not record, retain, or use conversations for other purposes (including model training) unless necessary for the service or the user gives affirmative consent.
- Covered entities must publish protocols, let users delete conversation history, avoid manipulative interaction designs that exploit age‑related vulnerabilities, and report material adverse incidents annually to the NIH and FTC.
What it means for you#
- Older adults: Chatbots you use must clearly say they are AI, be designed for accessibility, avoid manipulative prompts that exploit memory or decision problems, and trigger crisis referrals if you show signs of danger.
- Chatbot companies and operators (covered entities): You must add clear disclosures, build crisis and high‑stakes detection, publish compliance protocols online, get affirmative consent before using conversations for training, allow users to delete histories, and submit yearly reports about serious incidents.
- Service providers (companies that process data for chatbots): You may only process conversation data under written instructions and for permitted purposes (service delivery, compliance, safety, reporting, or required by law).
- Caregivers, family, and professionals: Bots must warn users not to rely solely on chatbot guidance for major decisions and remind them to seek human professionals.
- Health, legal, or financial professionals: Bots cannot represent themselves as licensed professionals. They must advise users to consult real professionals for high‑stakes matters.
- Users generally: You should see more frequent and clearer notices that you are talking with an AI, be able to delete chat histories, and be asked for clear consent if your chat will be used to train models.
Expenses#
No publicly available information.
- The bill creates tasks that could raise costs for companies: building crisis and high‑stakes detection, changing user interfaces to show disclosures, creating delete functions, publishing protocols, and preparing annual reports.
- FTC and NIH will receive and process reports. NIST must develop voluntary guidelines. The bill does not provide a budget or cost estimates for these government tasks.
- Civil penalties: knowing or reckless violations can carry fines up to $50,000 per violation. This creates potential legal and financial costs for covered entities.
- States may bring enforcement actions, which can add litigation costs for companies.
- If smaller developers must comply, compliance costs could be proportionally larger for them. The bill does not say whether there will be exemptions or financial assistance.
Proponents' View#
- The bill appears intended to protect older adults from being misled, manipulated, or harmed by chatbots.
- It aims to increase transparency so users clearly know they are interacting with AI and not a human or licensed professional.
- Requiring crisis detection and referral is designed to reduce risk when users show signs of imminent danger or medical emergencies.
- Limiting the use of conversations for training without affirmative consent is intended to give users control over their personal conversations and protect privacy.
- Public reporting of serious incidents could improve oversight and help identify systemic problems.
Opponents' View#
- One concern is that important definitions are left to regulators (for example, what counts as a “material adverse incident”), which could create uncertainty for companies during the transition.
- The bill may impose significant compliance costs on developers and operators, especially smaller firms, to build detection systems, accessibility features, and reporting systems.
- Requiring affirmative consent for model training and restricting use of conversations could slow model improvement or limit features that rely on user data.
- Some enforcement rules and penalties may be seen as severe or unclear (for example, what constitutes a single “violation” for the $50,000 penalty).
- Reporting requirements could raise privacy questions unless aggregated and anonymized data are handled carefully; the bill directs regulators to set standards but does not give immediate detail.
- It is unclear how the rules will affect chatbots designed specifically for companionship or social support; the bill allows benign companionship but balancing protections with useful features may be difficult in practice.