People-First Chatbot Act

Full Title:
People-First Chatbot Act

Summary#

This bill, the People-First Chatbot Act, sets rules for companies that make or run artificial intelligence chatbots. It defines an "artificial intelligence chatbot" and an "artificial intelligence chatbot provider." The bill limits how providers may collect, use, retain, and share user input, chat logs, and personal data. It generally bans using chat logs to target or customize advertisements and bans selling chat logs. Providers may not process personal data beyond the user’s input unless the user gives affirmative consent for a specific purpose. Special protections apply for users who the provider knows or should know are under 18: the bill generally bars using their chat logs or personal data for training, and requires disabling features that create unreasonable risks of serious harm, emotional dependence, or compulsive use. Providers must keep chat logs in a portable, readable format, give users access and deletion rights, and may not discriminate against users who refuse consent or who access their chat logs. Providers must create a written data security program within 12 months and perform monthly risk assessments for covered harms, emotional dependence, and compulsive usage, with quarterly public reporting. Providers must disclose clearly and accessibly that a user is interacting with an AI chatbot (before initial output, every hour, and when asked), and must not represent outputs as coming from licensed professionals (like doctors or lawyers). Businesses using AI chatbots for customer service must disclose that a nonhuman agent is being used and must allow an immediate transfer to a human operator located in the United States. The Federal Trade Commission (FTC) must write rules within 12 months to implement many requirements and metrics. The FTC enforces the Act; states may sue as parens patriae; and individuals have a private right of action with options to seek injunctions, actual damages, and statutory damages for certain violations. The bill also allows users injured by a chatbot to sue for actual damages even if the provider exercised reasonable care.

What it means for you#

  • If you use an AI chatbot, the provider must tell you you are talking to a chatbot in clear language and accessible format before the chatbot gives any output, every hour, and when you ask.
  • You can request and download your chat log in a portable, human- and machine-readable format.
  • You can ask a provider to delete your chat log or personal data they keep.
  • Providers cannot use your chat log to target or customize advertisements, or sell your chat log.
  • If you are likely under 18, the bill restricts use of your data for training and requires certain harmful features be disabled for you.
  • Companies using chatbots for customer service must say a nonhuman is being used and must let you ask for a U.S.-based human agent.

Expenses#

No publicly available information on estimated costs to the federal government or to private entities is included in the bill text. The bill does specify monetary remedies in private lawsuits: up to $10,000 per violation for some sections; up to $10,000 total for violations of disclosure rules; statutory minimums of $50,000, $100,000, or $250,000 for certain failures related to disabling harmful features for minors or harms that cause emotional dependence or covered harms; and courts may treble awards (up to 5 times) for willful violations. The FTC will carry out rulemaking and enforcement under its existing authority, but the bill text does not provide cost estimates for those agency actions.

Proponents' View#

No publicly available information.

Opponents' View#

No publicly available information.