The People-First Chatbot Act imposes strict privacy and safety regulations on companies that create or distribute AI chatbots, requiring them to obtain explicit user consent before using personal data for training or advertising purposes. The bill mandates that providers clearly disclose when users are interacting with an AI rather than a human, prohibit the sale of chat logs, and limit data retention to five years unless required by law. Additionally, companies must conduct monthly risk assessments for potential harms such as emotional dependence or compulsive usage, with specific safeguards required to protect minors from features that could cause significant injury. Enforcement is handled by the Federal Trade Commission, while state attorneys general and private individuals are granted the right to file lawsuits against providers who violate these provisions.
The Protecting Americans from Doxing and Political Violence Act requires government agencies to remove the personal contact details, home addresses, and financial information of Members of Congress, their family members, and designated staff from public records within 72 hours of a written request. The bill also prohibits data brokers from knowingly selling or trading this private information for any individual in the United States and mandates that other online platforms take down such data if the affected person submits a takedown notice. While these protections apply broadly to prevent doxing, the law includes exceptions that allow the continued publication of information related to news stories, matters of public concern, or records required by federal election laws.
The Cybersecurity for Small Businesses Act of 2026 directs the Small Business Administration, in partnership with federal cybersecurity agencies, to create and distribute resources that help small businesses improve their digital security practices. The bill specifically requires the administration to provide guidance on federal cybersecurity compliance standards to small companies seeking government contracts or subcontracting opportunities. This information must be made available through small business development centers, district offices, and the agency's website. Additionally, the Office of Advocacy is required to submit an annual report to Congress detailing how many small businesses have contacted them regarding cybersecurity issues.
The Smart Meter Data Privacy Protection Act prohibits state-regulated electric utilities that are not wholly owned by U.S. persons from selling or commercially monetizing personal consumption data collected via smart meters, restricting such use to specific operational needs like billing and grid reliability. The bill requires these utilities to submit annual reports to the Federal Trade Commission detailing what data was collected, how it was used, and with whom it was shared. If a utility violates these privacy rules, the FTC can order the company to credit affected customers an amount equal to three times the revenue generated from that unauthorized use. State attorneys general are also granted the authority to sue on behalf of residents to enforce compliance or seek damages, while the FTC is tasked with establishing security standards for data retention.
The Halt Abusive Internet Lawsuits Act of 2026 prohibits federal and state legal claims related to wiretapping or eavesdropping when information is collected for commercial digital activities. This applies to practices such as using cookies, pixels, chatbots, and analytics tools to facilitate sales, marketing, or customer interactions. The bill directly affects businesses and service providers that use these standard digital commerce tools by shielding them from specific privacy-related lawsuits. Additionally, any existing legal actions based on these grounds would be required to stop once the law is enacted.
The Open-Source AI Leadership Act directs the Secretary of Commerce to promote the adoption of U.S.-developed open-source artificial intelligence models by coordinating with private sector entities, state governments, and foreign partners. The bill requires the Department of Commerce to identify barriers to using these domestic models and to enter into agreements that facilitate their use in interstate and foreign commerce. Additionally, it mandates an annual public report assessing the risks associated with AI models developed by foreign adversary nations, including concerns about data security, national safety, and model performance. A specific provision ensures that the Secretary of Commerce cannot use this authority to ban or restrict any open-source AI model from being available in the market.
The Flock-Off Act prohibits federal agencies, state and local governments, and other recipients of federal funds from using federal money to purchase, operate, or maintain automated camera systems that capture biometric data or license plate information. The bill requires these entities to remove any existing covered camera systems within 180 days of enactment, with violations resulting in the withholding of further federal funding until reimbursed. Specific exceptions allow for the continued use of such systems within one mile of the U.S. borders for security purposes and on toll roads strictly for toll collection and enforcement.
The GUARDIAN Act requires social media platforms to obtain verifiable parental consent before collecting or processing the personal data of users under the age of 16. It defines "covered platforms" as internet services that use design features like infinite scrolling, push notifications, and personalized recommendation algorithms to promote user engagement. The bill mandates that these platforms delete a minor's data when they turn 16 unless a parent explicitly requests retention, and it grants parents the right to withdraw consent at any time, which forces the platform to terminate the account within ten days. Enforcement is handled by the Federal Trade Commission, with state attorneys general also permitted to bring civil actions for violations, while the law preempts conflicting state regulations but allows states to enact stricter protections for minors.
The RECOVER PII Act expands identity protection coverage for individuals affected by federal agency data breaches, extending the duration of protection for the remainder of their lives and increasing the minimum insurance amount to $5 million. Additionally, the bill allows federal agencies to use appropriated funds to reimburse employees or their contractors for up to 100 percent of the costs associated with privacy-enhancing services, such as software or hardware designed to mitigate data risks. These provisions aim to provide long-term financial support and resources to victims of data breaches while ensuring that reimbursement claims are supported by necessary documentation.
The STRATA Act of 2026 establishes a new program within the Department of State to foster international partnerships focused on advancing critical minerals technologies, aiming to strengthen U.S. supply chains and national security. This initiative allows the Secretary of State to form alliances with allied and partner nations, universities, and private companies while explicitly prohibiting collaborations with designated countries of concern such as China and Russia. Key provisions include the creation of International Centers of Excellence for research and training, the development of a digital platform to connect stakeholders with funding opportunities, and the establishment of clear guidelines for intellectual property and data security within these partnerships. The program authorizes the use of specific funding sources to support joint projects in extraction, recycling, and manufacturing, with a requirement that all activities conclude within ten years of the bill's enactment.