The CHATBOT Act would create a federal framework governing artificial intelligence chatbots used by children and teens. For children under 13, covered chatbot providers would have to require a family account; for teens, providers would have to give parents direct notice and obtain verifiable parental consent before an account or profile can be created. The bill also requires providers to offer family-account tools that let parents control privacy and account settings, limit time and incentives, disable notifications and certain transactions, view conversation histories, receive alerts about bypass attempts, and set how long a chatbot may retain a child’s or teen’s personal data in memory.
The bill further prohibits covered entities from using a child’s or teen’s personal data for targeted advertising, requires transparency labels disclosing that the chatbot is AI and not a human, and directs providers to delete personal data when a child or teen account is terminated, subject to limited retention for compliance. It also directs the National Science Foundation to study the effects of chatbots on children’s and teens’ relationships and social needs, and requires the Government Accountability Office to report on the law’s effectiveness and best practices. Enforcement would be handled by the Federal Trade Commission and state attorneys general, and the bill would generally preempt conflicting state law while preserving stronger state protections and existing student-privacy and COPPA rules.
Impact
If enacted, the bill would impose new federal duties on public-facing AI chatbot services that are the primary function of a website, app, or online service when those services know they are dealing with children or teens. It would effectively extend child-privacy and parental-consent concepts into the chatbot context, require new parental-control features and disclosures, restrict targeted advertising, and create data-deletion and access obligations tied to account termination. The bill would be enforced as an FTC unfair-or-deceptive-practices rule, with parallel state enforcement authority, and it would take effect one year after enactment.
Sentiment
Based on the bill’s bipartisan sponsorship by Senators Cruz, Schatz, Curtis, and Schiff, the measure appears to have been introduced with cross-party interest in child online safety rather than partisan opposition. There are no recorded committee transcripts or votes in the provided material, so there is no formal evidence of support or resistance beyond the bill’s structure. The overall tone of the legislation is precautionary and protective, emphasizing parental oversight, transparency, and limits on data use.
Contention
The main policy tensions in the bill are between child safety and product functionality, and between privacy protection and age-assurance requirements. The bill tries to avoid mandatory age verification or government ID collection, but it still depends on whether a provider “knows” a user is a child or teen, which could be difficult to operationalize. Another likely point of contention is the breadth of parental access to conversation records and monitoring tools, which may raise privacy concerns for teens and implementation concerns for providers. The targeted-advertising ban and default protective settings may also be debated by industry stakeholders who argue they could reduce service utility or increase compliance burdens, while child-safety advocates are likely to favor the stronger restrictions.