PolicyBrief
S. 5117
119th CongressJul 23rd 2026
Senior Chatbot Protection Act of 2026
IN COMMITTEE

The Senior Chatbot Protection Act of 2026 establishes essential consumer safeguards, disclosure requirements, and data privacy protections for older adults interacting with artificial intelligence chatbots.

Mark Kelly
D

Mark Kelly

Senator

AZ

LEGISLATION

New AI Chatbot Rules Set 180-Day Deadline for Safety Disclosures and Senior Protections

The Senior Chatbot Protection Act of 2026 is stepping in to draw a clear line between humans and machines, specifically focusing on how AI interacts with people over 65. Starting 180 days after it passes, any company running an AI chatbot in the U.S. will have to follow strict new rules: no more pretending to be a person, no more acting like a licensed doctor or lawyer, and no more 'guilt-tripping' users into staying online. The bill targets 'high-stakes' moments—like when someone is trying to draft a will or move retirement funds—requiring the AI to stop and tell the user that it’s not a professional and that the conversation isn't private or legally privileged.

No More Digital Gaslighting

One of the biggest shifts involves how these bots are designed. The bill specifically bans 'manipulative design' that exploits cognitive decline or social isolation. For example, if an older adult is using a companion bot, the company can’t program that bot to discourage them from talking to their actual family or to use 'emotionally coercive' language to keep them from logging off. It’s a direct response to the way some tech is built to be addictive. For a 70-year-old managing early-stage memory issues, this means the bot they use for help with daily tasks can't legally pressure them into spending more time or money than they intended (Section 3(d)).

Emergency Brake for Crises

By the one-year mark, chatbots must be able to spot when a user is in a legitimate crisis, such as a medical emergency or a mental health breakdown. Under Section 3(a)(1)(E), if the bot detects a crisis, it’s legally barred from giving DIY medical advice or medication tips. Instead, it must prioritize getting that person to a human professional or a service like the 988 Suicide and Crisis Lifeline. Think of it as a mandatory 'safety mode'—if you’re talking to a bot about a sudden chest pain, the bill requires the software to stop the chat and point you toward an ER rather than trying to diagnose you with an algorithm.

The Fine Print on Your Data

This bill also changes the default setting for your privacy. Companies can no longer use your private conversations to train their AI models unless you give 'affirmative consent'—meaning a clear, standalone 'yes' that isn't buried in a 50-page terms-of-service document. If you’re a small business owner using a bot to help organize client notes, those notes can’t be sucked into the AI’s brain for future learning without your explicit permission. Additionally, companies have to report 'material adverse incidents' to the FTC every year, though there’s a bit of a gray area here: the FTC still has to define exactly what counts as a serious enough incident to report (Section 4).

Enforcement and Accountability

To make sure companies don't just ignore these rules, the bill carries a punch: a $50,000 fine per violation for those who 'knowingly or recklessly' break the safety standards. State attorneys general also get the power to sue on behalf of their residents. There is a small 'get out of jail free' card, though—companies usually get 60 days to fix a mistake before the FTC hits them with a fine, unless they were intentionally trying to deceive people. While the National Institute of Standards and Technology (NIST) will be writing more detailed safety guidelines, those will be voluntary, leaving the FTC as the primary watchdog for whether your digital assistant is being helpful or predatory.