People-First Chatbot Act
United States119th CongressHR-9619House of Representatives
Updated: Jul 9, 2026
Summary
The People-First Chatbot Act establishes comprehensive data privacy, security, and transparency requirements for artificial intelligence chatbot providers. This legislation aims to protect user data, particularly chat logs and personal information, by imposing strict prohibitions on their collection, use, and retention. It also seeks to ensure user awareness and safety when interacting with AI chatbots, with a strong focus on protecting minors. A central provision prohibits AI chatbot providers from processing personal data beyond fulfilling explicit user requests without **affirmative consent**. Specifically, chat logs cannot be used for advertising purposes, such as determining ad display or customization. For users under 18, processing chat logs or personal data for any purpose, including training, requires **affirmative consent** from a parent or legal guardian. For adult users, training purposes also necessitate **affirmative consent**, and providers are barred from selling chat logs or retaining them for over five years without legal necessity. Users are granted significant rights, including the ability to request and receive their chat logs in a portable, readable format, and to demand the deletion of their chat logs and personal data. Providers are explicitly prohibited from discriminating or retaliating against users for refusing consent or exercising their right to access their data. Furthermore, government entities cannot compel the production or access of user data from providers without a court-issued warrant. The bill mandates that providers develop and maintain comprehensive data security programs, with summaries made publicly available on their websites. Transparency is also key, as providers must clearly notify users that they are interacting with an AI chatbot, both at the start of a conversation and periodically thereafter. They are also forbidden from making misleading claims about data confidentiality or implying that AI outputs are equivalent to advice from licensed professionals. To ensure user safety, AI chatbot providers must conduct monthly risk assessments for potential **covered harm**, **emotional dependence**, or **compulsive usage**, making this information publicly available quarterly. For minors, providers must disable design features that pose an unreasonable risk of such harms. Businesses using AI chatbots for customer service must disclose this fact and offer an immediate transfer to a human operator located in the United States upon request. The Federal Trade Commission (FTC) is tasked with promulgating detailed regulations to implement these provisions, including specific disclosure requirements and metrics for risk assessment. Violations of the Act or its regulations will be treated as unfair or deceptive acts or practices, enforceable by the FTC. States can also bring civil actions, and individuals have a private right of action to seek damages for violations, including statutory damages for specific harms and liability for injury caused by the AI chatbot.
Bill texts
All available records shown.
Timeline
Referred to the House Committee on Energy and Commerce.
House of Representatives
Introduced in House
All available records shown.