HR 7124 prohibits the use of specific mobile biometric apps (Mobile Fortify and Mobile Identify) outside U.S. ports of entry, restricting them solely for border identification. It requires Homeland Security to remove these apps from all non-Department devices, ban sharing with other agencies, and destroy U.S. citizens' captured biometric data (photos/fingerprints) within 12 hours of collection at ports of entry. The bill directly affects U.S. citizens whose biometric data is collected during border processing. Key mechanisms include mandatory app removal, remote deactivation of unauthorized installations, and strict data destruction timelines.
HR 6117, the Patient Device Data Access Act of 2025, requires medical device manufacturers to share patient-specific data recorded or transmitted by covered devices (like pacemakers or remote monitors) when a patient requests it. The bill mandates that manufacturers provide this data in understandable formats, publish device-specific data policies on their websites, and notify patients about how to access their information. It directly affects patients using covered devices and device manufacturers, while exempting data stored in inaccessible closed systems. The law focuses on enabling patient access to their own health data without requiring device redesigns or disclosing proprietary information.
The Artificial Intelligence Scam Prevention Act makes it illegal to use AI to impersonate people for fraudulent purposes, such as creating fake voices or images to scam consumers. It requires clear disclosure when AI is used in phone calls or text messages, so people know they're interacting with technology rather than a real person. The bill establishes an advisory group with FTC, FCC, and industry representatives to develop best practices for preventing these scams and mandates regular reports on AI-enabled fraud. The law aims to protect consumers from increasingly sophisticated scams, which cost over $1.4 billion in 2024 alone.
This bill prohibits grocery stores from charging unreasonably high prices (defined as 120% or more of a product’s average price over the prior six months) unless they prove the increase stems from uncontrollable costs like supply chain issues. It bans using personal data - such as facial recognition or purchase history - to set different prices for individual shoppers and requires clear signage about facial recognition use at store entrances. Large grocery stores (over 10,000 sq ft) must replace electronic shelf labels with physical price tags. The Federal Trade Commission enforces these rules, allowing states and consumers to seek $3,000 per violation in court for price gouging or data misuse.
The DELETE Act creates a federal system allowing individuals to request deletion of their personal data from data brokers. It requires data brokers (entities collecting personal information without a direct customer relationship) to register with the FTC annually and implement a centralized deletion system. Individuals can submit one request to delete all their data across registered brokers within 31 days, with limited exceptions for research or legal compliance. Data brokers must pay an annual fee (capped at 1% of system costs) to maintain the system, and the FTC enforces the rules under existing privacy laws. The law preempts conflicting state privacy laws but allows states to offer stronger protections.
This bill requires the Federal Trade Commission (FTC) to conduct a one-year study on neural data privacy and governance, including risks of behavioral manipulation and gaps in current laws. The study will analyze how neural data (from brain-monitoring devices) and related biometric data are collected, used, and transferred, with recommendations for future privacy protections. It directly affects the FTC (which must complete the study) and federal agencies (which will later receive guidance on using neural technology). The bill does not create new regulations but sets the stage for potential future policy changes based on the FTC's findings.
The DRIVER Act requires car manufacturers and fleet owners to give vehicle owners free, real-time access to their vehicle's data (like location, driving habits, and sensor information) through standard ports or wireless connections. Owners can control how this data is used or shared with third parties (except for foreign adversaries), delete stored data, and cannot be charged for access or decryption. Manufacturers and fleet owners must provide clear opt-out options before selling owner data and are banned from selling data to specific countries like China, Russia, or Iran. The Federal Trade Commission enforces these rules under existing laws, and states cannot create conflicting laws.
HR 1770, the Consumer Safety Technology Act, requires federal agencies to study and pilot new technologies to improve consumer safety. Title I mandates the Consumer Product Safety Commission to run a one-year AI pilot program to track product injuries, identify hazards, monitor recalls, and check imports, then report findings to Congress. Title II directs the Commerce Secretary to study how blockchain technology can prevent fraud in consumer transactions, including public input and a 6-month report to Congress. Title III requires the Federal Trade Commission to report on its enforcement actions against deceptive practices involving digital tokens and recommend improvements to protect consumers. The bill affects the Consumer Product Safety Commission, Commerce Department, and FTC, focusing on research and reporting rather than immediate regulatory changes.
This bill blocks federal contractors from using DeepSeek or similar AI tools developed by High Flyer (or its affiliates) for government work, with limited security waivers allowed for national defense or research. It requires a detailed report within one year on national security risks from AI platforms based in or linked to "countries of concern" (as defined in existing law). The report must analyze data privacy threats, including how U.S. user data stored in these platforms could be accessed by foreign governments, used for propaganda, or exploited for economic espionage. The law aims to protect U.S. data security and prevent foreign adversaries from leveraging AI systems for strategic advantage.
HR 2403, the TELL Act, requires companies operating websites or mobile apps that store U.S. user data in China to clearly disclose two specific facts to users: (1) that their data is stored in China, and (2) whether the Chinese Communist Party or Chinese state-owned entities have access to it. It prohibits companies from knowingly providing false information about these points. Violations would be enforced as unfair or deceptive practices under the Federal Trade Commission Act, with the FTC handling enforcement and penalties. The law directly affects U.S. technology companies that collect user data and store it in China.