PolicyBrief
H.R. 9915
119th CongressJul 23rd 2026
Stealth Bot Prohibition Act
IN COMMITTEE

The Stealth Bot Prohibition Act bans the use of deceptive or harmful automated bots that scrape websites or impersonate human users, establishing federal and state enforcement mechanisms to protect digital platforms.

Laurel Lee
R

Laurel Lee

Representative

FL-15

LEGISLATION

New 'Stealth Bot' Ban Sets $53,000 Fines for Deceptive AI and Website Scraping

The Stealth Bot Prohibition Act targets the digital 'ghosts' in the machine by making it illegal to deploy bots that hide their identity while interacting with websites or users. Specifically, the bill bans the use of automated software that accesses a site in a way that is reasonably likely to damage its technical operations or burden its commercial business. It also takes a direct swing at AI deception, making it illegal to intentionally disguise a bot as a human when it’s connected to a generative AI service. If you’ve ever felt like you were being tricked by a customer service chat that seemed a little too 'human,' or if you run a small website that keeps getting crashed by mysterious data-scrapers, this bill is designed to put a name—and a price tag—on those activities.

Digital ID Cards for Bots

Under this bill, bots would essentially be required to show their ID at the door. A 'stealth bot' is defined as any software (like a crawler or AI agent) that fails to disclose its identity and purpose—such as search indexing or data mining—in a format the website operator can see. For a local independent bookstore trying to keep its inventory online, this means protection against aggressive bots that scrape their data and slow down their site for real customers. Section 2 requires these bots to use valid 'user-agent strings,' which are basically digital signatures that tell a server who is visiting and why. By forcing bots out of the shadows, the bill aims to give site owners more control over who is accessing their data and resources.

The Cost of Deception

The financial stakes for breaking these rules are high. The Federal Trade Commission (FTC) is empowered to hit violators with civil penalties of up to $53,000 per violation, a number that will be adjusted for inflation every January. This isn't just a federal matter, either; state attorneys general are given the green light to sue on behalf of their residents. For example, if a company uses a fleet of bots to pose as real people on a social platform to spread AI-generated misinformation, they could face massive lawsuits from both the FTC and individual states. This dual-enforcement layer ensures that even if federal priorities shift, state officials can still step in to protect their local digital economy.

Enforcement and the Six-Year Clock

While the bill provides clear definitions for 'Generative AI' and 'Bots,' there is some middle-of-the-road vagueness regarding what exactly constitutes a 'burden' on a website’s commercial operation. This could lead to some legal gray areas for developers of new AI tools who are trying to train their models on public data. However, the bill includes a six-year statute of limitations for filing actions, giving regulators plenty of time to track down sophisticated bad actors. Once enacted, the tech industry and bot operators will have a 180-day grace period to update their code and disclosure practices before the $53,000 fines start kicking in.