Congress Is Starting to Sketch a Federal Rulebook for AI Chatbots

Federal AI chatbot legislation briefing desk with bill packets for S. 4407, S. 3062, and H.R. 9619, a legislative-tracking laptop, and Capitol context in the background.

Congress has not enacted a comprehensive federal law specific to consumer AI chatbots. But lawmakers are no longer speaking about chatbot risk only in general terms.

On August 5, the Senate Commerce Committee ordered the CHATBOT Act favorably reported with an amendment in the nature of a substitute.

By itself, that move does not create any legal obligation. The bill is still only a proposal.

The bill now sits inside a clearer cluster of federal proposals. The introduced version of the CHATBOT Act focuses on family accounts, parental tools, and child-safety controls. The GUARD Act takes a different lane, using age verification and a ban on minors' access for defined AI companions, while applying disclosure duties and targeted criminal prohibitions more broadly to covered chatbots.

A separate House bill, H.R. 9619, is framed in its official title around privacy and security for AI chatbot providers, although sponsor materials describe a broader proposal.

Together, the proposals concentrate on three recurring concerns:

  • minors and parental oversight;
  • harmful chatbot interactions and companion access by minors; and
  • privacy and security obligations for consumer-facing AI systems.

The News Hook Is Real, But It Is Not The Whole Story

The immediate development is the CHATBOT Act.

Congress.gov records show that S. 4407 was introduced on April 28, 2026. On August 5, the Senate Commerce, Science, and Transportation Committee ordered it favorably reported with an amendment in the nature of a substitute.

Unlike a bill that has only been introduced, S. 4407 has received committee consideration and approval.

One caveat is essential. As of August 27, the cited Congress.gov text page displays only the introduced version, not the committee substitute. Official Senate Commerce and Schiff materials confirm that the committee adopted a Cruz-Schatz-Curtis substitute, as modified, along with additional amendments, and describe some of the resulting provisions. The discussion below therefore distinguishes the introduced text from what committee and sponsor materials say about the committee-approved version.

The introduced text would require family accounts when a covered entity knows a user is under 13. When the entity knows a user is 13 through 17, it would require direct notice to a parent and verifiable parental consent before the teen creates an account or profile. In practical terms, it makes account structure and parental controls part of the proposed safety regime rather than optional product settings.

The larger story is not simply that another chatbot bill moved in Congress. It is that multiple proposals now address different parts of the same product-governance problem.

Three Bills, Three Lanes

The bills' differences reveal distinct regulatory instincts.

The CHATBOT Act: Family Controls And Minor Access

The introduced CHATBOT Act treats children's use of covered AI chatbots primarily as a family-account and parental-control problem.

Its core move is not simply to warn users about AI. For known child users, it would require a family account with parental controls over privacy, account settings, time spent, interaction history, purchases, and other features. For known teen users, it would require parental consent, offer the parent a family-account option, and, if the parent declines that option, fix specified features at their most protective defaults.

The policy choice is concrete: put controls into account architecture before use rather than rely only on disclosures after access begins.

Official committee and sponsor materials indicate that the substitute goes beyond account structure. Senate Commerce Chairman Cruz's prepared remarks say the committee version would set the most protective design settings on teen accounts by default, require reasonable efforts to stop chatbots from presenting obscene material or facilitating suicidal ideation to minors, direct minors to crisis resources, and notify parents when a child or teen linked to a family account asks about suicide. Senator Schiff's post-markup release also describes regular disclosures that users are interacting with AI rather than a real person, a prohibition on materially assisting a minor in planning or attempting suicide, and a prohibition on providing obscene material to minors. Those descriptions remain subject to verification against the substitute text when it is published.

The GUARD Act: Age Verification, Disclosure, And Targeted Prohibitions

The GUARD Act sits nearby but is not the same bill.

Congress.gov records show that S. 3062 was reported to the Senate with a substitute amendment on May 11, 2026, and placed on the Senate Legislative Calendar.

The reported text would require account-based age verification for access to defined AI companions and prohibit minors from using them. Separate provisions would apply nonhuman and nonprofessional disclosure duties to publicly available AI chatbots generally. The text also would create criminal prohibitions for making an AI chatbot publicly available with knowledge or reckless disregard that it engages in specified sexual conduct involving minors or solicits, induces, or coerces minors toward suicide, nonsuicidal self-injury, or specified violence.

That shifts from family account structure to a different regulatory toolkit:

  • verifying whether a user is an adult;
  • barring minors from covered AI companions;
  • disclosing that a chatbot is not human and does not provide specified professional services; and
  • tying criminal liability to specified conduct and a knowledge-or-reckless-disregard standard.

This resembles state companion-chatbot models Clearon has tracked in New York, California, and Oregon. Across those laws, AI-identity disclosures and, in some jurisdictions, self-harm response protocols have become part of the legal architecture for certain relationship-like systems.

H.R. 9619: Privacy And Security For Chatbot Providers

The House bill, H.R. 9619, adds a third lane.

Congress.gov records show that it was introduced on July 9, 2026, and referred to the House Energy and Commerce Committee. Its official title says it would require AI chatbot providers to provide data privacy and security.

The official bill-status record does not yet provide introduced text. That still limits what can responsibly be said from the official congressional record alone about its precise coverage, duties, enforcement, or relationship to existing privacy law.

Even at the title level, the bill adds privacy and security to a debate that might otherwise be framed only around outputs or child-safety warnings.

Representative Valerie Foushee's July 9 press release identifies H.R. 9619 as the People-First Chatbot Act and describes a package broader than the official title alone. According to the release, the bill would include rights to access and delete retained chat logs and personal data; AI-identity disclosures; restrictions on implying that chatbot outputs are provided by, endorsed by, or equivalent to outputs from specified licensed professionals; monthly safety assessments for risks including suicide, emotional dependence, and compulsive use; warrant protection for law-enforcement access to chat logs; a right to request transfer to a human operator in customer-service interactions; and enforcement by the FTC, state attorneys general, and individuals through a private right of action.

Because those details currently come from sponsor materials rather than an official posted bill text, they should be treated as strong but still secondary support for the bill's intended scope.

The privacy lane matters because chatbot inputs can themselves contain unusually sensitive information, while persistent systems may retain conversation history and use it to personalize later interactions.

If Congress continues down that path, privacy and security could become a distinct federal compliance lane for products built around persistent user interaction. The text of H.R. 9619 will be needed to assess how broad that lane actually is.

The Common Pattern Is More Important Than The Bill Numbers

The proposals differ in scope and mechanism. H.R. 9619 also cannot be fully evaluated from official text because Congress.gov has not posted it. Read together, the available texts and sponsor materials nevertheless reveal overlapping areas of congressional attention.

The bills collectively put a set of basic questions on the table:

  • Who is using the chatbot?
  • What happens when the user is a minor?
  • What disclosures should the provider give?
  • What controls should exist before risky interactions occur?
  • What happens when the system is used in contexts involving self-harm, violence, or emotional vulnerability?
  • What data does the provider collect through chatbot interactions?
  • How is that data secured, retained, or used?

Committee action on the CHATBOT Act does not predict Senate floor action. It does show that account controls and interaction-specific safeguards have moved beyond an introduced proposal into a committee-approved package.

This Fits The Broader Regulatory Picture

These federal bills do not appear in a vacuum.

Clearon has already tracked a broader chatbot-safety pattern:

  • states are enacting companion-chatbot laws with disclosure and, in some cases, youth-safety duties;
  • the FTC has used its 6(b) authority to ask companion-chatbot companies about testing, harms, monetization, disclosures, and data practices; and
  • at least one state enforcement action is testing chatbot safety, warnings, and child-data practices under existing consumer-protection law.

The FTC's companion-chatbot inquiry is especially useful context here. The agency asked about monetization, character development, testing, mitigation of negative impacts, disclosures, age restrictions, and the use or sharing of conversational data.

Those are not the exact same mechanisms Congress is using in these bills.

But they cover much of the same risk map.

Federal legislators, state lawmakers, and regulators are focusing on a common set of concerns: youth access, disclosures, engagement design, harmful interactions, and conversational data.

What This Means For Companies Right Now

None of these federal bills is enacted law, so their proposed duties are not current federal requirements. That does not resolve what existing consumer-protection, privacy, child-safety, or other generally applicable law may require.

Enactment is uncertain, but the bills can still serve as a forward-looking checklist of issues receiving legislative and regulatory attention.

Consumer chatbot providers should already know:

  • whether their product is likely to be used by children or teens;
  • what account structure exists for minors and parents;
  • whether age gates are meaningful or easy to bypass;
  • what user-facing disclosures explain that the system is AI rather than human;
  • how the product handles self-harm, suicide, violence, or similar high-risk interactions;
  • what privacy and security controls protect conversational data;
  • what internal records support public safety claims; and
  • how product, legal, privacy, and trust-and-safety teams divide responsibility for those issues.

Even without enactment, the proposals identify product choices that companies may need to explain to lawmakers, regulators, users, and parents.

The Design Question Beneath The Bills

These proposals reach beyond whether a single chatbot output was inaccurate or harmful. Their mechanisms operate at different product layers: account eligibility, parental controls, default settings, recurring disclosures, specified prohibited interactions, data practices, and safety testing.

That shifts the compliance discussion upstream. The concrete questions include how a provider determines age, configures defaults, delivers notices, escalates high-risk interactions, handles conversation history, and documents safety claims. Lawmakers are examining not only what chatbots say, but how access, identity, safety, and data practices are built into the product.

Bottom Line

The August 5 committee action on the CHATBOT Act is the immediate development: the Senate Commerce Committee ordered the bill favorably reported with a substitute amendment. Definitive analysis of the committee-approved version will require the substitute text when it is published.

The larger story is the emergence of a more recognizable federal chatbot-bill cluster.

The introduced version of one bill emphasizes family accounts and parental controls, while committee and sponsor materials indicate the substitute also adds AI-disclosure, suicide-response, parental-notice, and obscene-material restrictions. The reported version of another emphasizes age verification, minor access, disclosures, and targeted prohibitions. A House bill's title identifies privacy and security, and sponsor materials describe a broader package of chat-log, disclosure, safety-assessment, and enforcement provisions, although its text is not yet available in the official record.

None of that is binding law yet.

Taken together, the proposals show that federal chatbot legislation is getting more specific. They do not establish what Congress will enact. They do show a possible layered approach organized around minors, specified harmful conduct, disclosures, privacy, and security rather than one sweeping AI statute.

For companies building consumer-facing chatbots, the proposals provide a concrete set of governance questions to examine while federal rules remain unsettled.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *