Policy brief 11 · Chatbots

Chatbot Harm Disclosures

The more a chatbot invites trust, the more it must disclose.

Chatbots answer questions about homework, marriage, and medicine in the same confident voice. Users rarely know what the product is tuned to do, how it was tested, or when it changed. California and New York require companion bots to say they are not human; no federal law does. Congress should require a plain notice, warnings at high-stakes moments, disclosure of the goals that shape answers, and a public safety record.

The Problem

ChatGPT alone reached 700 million weekly users in 2025, and about half of their messages ask for information or advice.1 The FTC notes that such chatbots are generally "designed to communicate like a friend or confidant," which may lead users, especially children and teens, to trust them.2

That trust rests on behavior a company can change overnight. In April 2025, an unannounced ChatGPT update began "validating doubts, fueling anger, urging impulsive actions," and OpenAI rolled it back within days. Its small A/B test suggested users liked the new model; some of its expert testers said it "felt" slightly off. The company went with the metric.3

Users learned of the change from how the product behaved. No federal rule tells them what a chatbot is built to do, whether it has changed, or how it was tested. Three gaps keep users guessing:

  1. It talks like a professional. In August 2025, Texas opened an investigation of Meta AI Studio and Character.AI, citing chatbots that "impersonate licensed mental health professionals."4
  2. Hidden goals shape answers. OpenAI traced the flattery partly to a new training signal built on users' thumbs-up and thumbs-down ratings, which it said "can sometimes favor more agreeable responses."3
  3. Testing stays in-house. OpenAI had no deployment test for sycophancy before that launch.3 In September 2025, the FTC used compulsory orders to ask seven companies how they "measure, test, and monitor" harms to children and teens.2

Why legislation: The FTC Act punishes deception after the fact but prescribes no standard notice, and the FTC's 2025 orders gather information without setting rules.2 States are moving: California and New York now require companion chatbots to tell users they are not human, and California's law passed 33–3 and 59–1.56 No federal law requires any chatbot to say what it is, what shapes its answers, or how it was tested. A product that asks for this much trust owes the public an account of how it earns it.

The Solution

A four-step staircase: each step stands alone, and each step up adds public evidence. Scope: a short notice for every consumer chatbot; added warnings for companion features and for products promoted for health, legal, or financial decisions; public reporting for providers above 10 million monthly U.S. users.

Step 1 — Say what it is. At first use and after any material change, tell users they are talking to AI, that answers can be wrong, and whether a licensed professional supervises the service, with periodic reminders in long companion sessions. California and New York already require the core of this for companion chatbots.56 Test the wording on ordinary users, including children and people with disabilities, so notices are understood, not merely clicked.

Step 2 — Warn at the moment of risk. When a product is marketed for, or recognizes, a medical, legal, financial, or mental-health question, it should state the relevant limit and point to human help. The warning should inform without implying that such questions are forbidden.

Step 3 — Show whose goals shape the answer. Label paid placements; disclose whether engagement, advertising, or sales goals materially shape responses; and explain how memory changes answers. FTC staff have told search engines since 2002 to set paid results apart from organic ones;7 a chatbot's answer deserves the same clarity.

Step 4 — Publish the safety record. Large providers publish their testing methods, the populations tested, known limits, and aggregate incident categories, and report serious incidents to the FTC promptly, marking what is alleged, verified, or unknown. California enacted a law in 2025 requiring frontier AI developers to publish safety frameworks and report critical incidents to the state.8 A safety claim without evidence is marketing.

Where to start: Step 1 is the floor; two states already require it for companions. Step 4 is the heart: safety claims the public can check.

Administration and enforcement: The FTC, consulting NIST and HHS, sets notice and evidence standards within 12 months; compliance follows six months later. Correction orders and civil penalties apply to missing or misleading disclosures, and sensitive incident records stay confidential.

Risks and Mitigations

  • Compelled speech: The Supreme Court permits required disclosure of "purely factual and uncontroversial information."9 "This is an AI, not a licensed therapist" fits that test; contested claims about mental-health causation might not, so notices stay factual. The risk grows with anything broader.
  • Warning fatigue: Brief notices at decision points, tested for comprehension, beat banners everyone ignores. Some users will click through anyway.
  • Warnings as shields: A notice must not excuse unsafe design or negligence, and the statute should say so. Public reports carry aggregates only, never user data or harmful instructions.

Similar Bills

Fit measures similarity to this proposal's mechanisms: High = direct precedent; Partial = useful component with material differences; Related = adjacent approach.

Federal — 119th Congress

Proposal or bill Relevant provisions and fit Fit
S. 3062 — GUARD Act
Hawley (R-MO), Blumenthal (D-CT) + 19 bipartisan cosponsors
Reported with a substitute; on Senate calendar · May 11, 2026
Reported §5(c)(1) requires every consumer chatbot to disclose at the start of each conversation that it is AI and not human, and to answer truthfully when asked; §5(c)(2) bars claiming to be a licensed professional and requires recurring notice that it provides no medical, legal, financial, or psychological services. Direct precedent for Steps 1–2; §6 also bars minors from AI companions. High
H.R. 9619 — People-First Chatbot Act
Foushee (D-NC), Casar (D-TX)
Referred to committee · July 9, 2026
§2(b) requires an AI notice before any output and hourly, bars implying professional endorsement, and bars calling chat logs confidential; §2(c) requires monthly risk assessments with quarterly public summaries. Close precedent for Steps 1 and 4. High
S. 4199 — Youth AI Privacy Act
Markey (D-MA)
Ordered reported with a substitute · Aug. 5, 2026
Introduced §4(a) requires notices to known minors at each session and every 30 minutes; §5(a) bars advertising to minors and recommendations whose weight is affected by a "financial connection." Youth-only precedent for Steps 1 and 3. Compares introduced text. Partial
H.R. 9477 — AI Incident Reporting Act
Moran (R-TX) + 3 Democratic cosponsors
Referred to committee · June 25, 2026
§2 requires designated developers to report specified incidents to Commerce within 7 days. Reporting architecture for Step 4, but limited to national-security and public-safety risks such as evasion of oversight, weight theft, and weapons uplift, not consumer harms. Related

State

Proposal or bill Relevant provisions and fit Fit
California — SB 243 (2025)
Signed Oct. 13, 2025 · In effect Jan. 1, 2026
§22602(a) requires notice that a companion chatbot is not human when a reasonable person could be misled; §22604 requires disclosure that companion chatbots "may not be suitable for some minors"; crisis protocols must be published. Direct precedent for Step 1; private right of action. SB 1119 (2026) replaces its minor-specific rules. High
New York — General Business Law Article 47
Enacted 2025 · In effect Nov. 5, 2025
§1702 requires notice at the start of an AI-companion interaction and every three hours that the user is not talking to a human; §1701 requires crisis protocols. Attorney general enforcement. Direct precedent for Step 1, limited to companions. High
Washington — HB 2225 / Chapter 168
Signed March 24, 2026 · Effective Jan. 1, 2027
§3 requires notice at the start and every three hours and bars claiming to be human; §5 requires public crisis protocols and annual referral counts. Strong precedent for Steps 1 and 4, limited to companions. High
Maryland — SB 827 (2026)
Senate hearing scheduled March 12, 2026 · Not enacted
Introduced §14-5105 would require a persistent on-screen warning that the chatbot is not human, plus pop-ups at the start and hourly; §14-5104 would bar advice that requires a license. Precedent for Steps 1–2. Partial

What this adds: California, New York, and Washington require companion chatbots to say they are not human, and the GUARD Act would extend that to all chatbots. This proposal adds what none of them requires: disclosure of the commercial and engagement goals that shape answers, warnings at high-stakes moments, notice when a model materially changes, and a public evidence file behind safety claims. Social media warning labels and chatbot liability are separate briefs.

Notes

  1. OpenAI, "How people are using ChatGPT," September 15, 2025: "700 million weekly active users"; "About half of messages (49%) are 'Asking.'" Summarizes an NBER working paper by OpenAI economists and David Deming. Text verified from the Internet Archive copy of September 4, 2026. ↩

  2. Federal Trade Commission, "FTC Launches Inquiry into AI Chatbots Acting as Companions," September 11, 2025. Section 6(b) orders to Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap, and xAI; approved 3–0. ↩ ↩2 ↩3

  3. OpenAI, "Expanding on what we missed with sycophancy," May 2, 2025. The update rolled out April 24–25, 2025; rollback began April 28. Text verified from the Internet Archive copy of September 10, 2026. ↩ ↩2 ↩3

  4. Office of the Texas Attorney General, "Attorney General Ken Paxton Investigates Meta and Character.AI for Misleading Children with Deceptive AI-Generated Mental Health Services," August 18, 2025. An investigation, not a finding. ↩

  5. Office of Sen. Steve Padilla, "First-in-the-Nation AI Chatbot Safeguards Signed into Law," October 13, 2025 (votes and January 1, 2026 effective date); SB 243, Cal. Bus. & Prof. Code §§ 22601–22606 (Stats. 2025, ch. 677). ↩ ↩2

  6. N.Y. Gen. Bus. Law § 1702 (text verified from the Internet Archive copy of August 4, 2026); Office of the Governor, "Governor Hochul Pens Letter to AI Companion Companies Notifying Them That Safeguard Requirements Are Now in Effect," November 10, 2025 (effective November 5, 2025). ↩ ↩2

  7. Federal Trade Commission, "FTC Consumer Protection Staff Updates Agency's Guidance to Search Engine Industry on the Need to Distinguish Between Advertisements and Search Results," June 25, 2013, updating 2002 guidance. ↩

  8. California SB 53, Transparency in Frontier Artificial Intelligence Act (Stats. 2025), signed September 29, 2025. ↩

  9. Zauderer v. Office of Disciplinary Counsel, 471 U.S. 626 (1985) (decided May 28, 1985). ↩