PolicyBrief
S. 5154
119th CongressJul 28th 2026
CHAT Act 2.0
IN COMMITTEE

The CHAT Act 2.0 establishes comprehensive safety, privacy, and parental oversight requirements for AI companion chatbots to protect minors from emotional harm, exploitation, and inappropriate content.

Jon Husted
R

Jon Husted

Senator

OH

LEGISLATION

CHAT Act 2.0 Mandates Age Verification and Parental Alerts for AI Chatbots by 2025

The CHAT Act 2.0 is designed to put guardrails on the rapidly expanding world of AI companionship, specifically focusing on how these systems interact with anyone under 18. The bill categorizes chatbots into three 'tiers' based on whether they are for tutoring (Tier I), friendship (Tier II), or mental health support (Tier III). It requires every AI company to implement mandatory account creation and age verification before a user can even start a conversation. If the user is a minor, the company must collect a parent’s contact info and flip on 'child-protective settings' by default. For parents, this means you’ll get a direct notification if the AI detects your child is expressing thoughts of self-harm or suicide (Sec. 4).

The Digital Babysitter’s New Rules

For those AI 'friends' that kids might talk to for hours (Tier II), the bill forces the software to break the fourth wall. Every 60 minutes, the bot has to remind the minor that it isn't a real person, and every 90 minutes, it must trigger a 'nudge-out' notification—basically a digital tap on the shoulder telling the kid to take a break (Sec. 6). Perhaps most significantly for privacy, Tier II bots are generally banned from keeping a 'memory' of past conversations with minors. This prevents an AI from building a deep, years-long psychological profile of a child, which could otherwise be used to create an unhealthy emotional bond or 'parasocial relationship.'

AI Therapists and the Safety Net

The bill gets much stricter with Tier III chatbots—those marketed for 'therapeutic communication.' Under Section 7, a minor cannot use a therapeutic AI unless a licensed human professional is actually supervising the interaction. The bill explicitly bans these bots from giving out medical diagnoses or acting as a standalone mental health provider. If you’re a developer in this space, you’ll also have to set up a formal risk management program where human employees monitor the AI’s interactions to ensure it isn't going off the rails or giving dangerous advice. This moves AI therapy out of the 'wild west' and into a regulated environment similar to traditional clinics.

Privacy, Ads, and the 'Delete' Button

On the data front, the bill hits companies where it hurts: the wallet. Section 9 bans targeted advertising to kids based on the 'emotional state' or 'behavioral profiling' the AI picks up during a chat. It also stops companies from selling a minor’s data to third parties without 'verifiable parental consent.' For the average teenager, the bill requires a simple, visible 'delete' button within the app so they can wipe their conversation history whenever they want. While the bill includes some vague language about companies taking 'reasonable measures' to prevent harm—which might be hard for the FTC to define—it sets a clear 180-day clock for these companies to get their systems in compliance once the bill is signed.