|
. . .
DAY THIRTY-FIVE. Today is June 4, 2026. The GUARD Act cleared Senate Judiciary on April 30 by a recorded vote of twenty-two to zero. That makes today Day Thirty-Five post-markup, and the Congressional Budget Office has not scored the bill.
Senator Josh Hawley and Senator Richard Blumenthal moved S.3062 out of committee on a unanimous roll call. Seventeen bipartisan cosponsors signed on. The bill went to Senate Calendar No. 406 on May 11.
Majority Leader has not set a floor vote.
The Congressional Budget Office cost-estimate listing on Congress.gov reads zero. For complex private-sector mandate analyses CBO typically takes forty-five to seventy-five days. Today is Day Thirty-Five. The window opens next week.
. . .
The Unfunded Mandates Reform Act sets the FY2026 private-sector threshold at roughly $218 million per year. Title I of the GUARD Act builds an age-verification regime. It layers a criminal prohibition on top. It adds a civil-penalty regime of $250,000 per violation, per the EFF analysis of the reported-out text published May 8.
Enforcement runs through the U.S. Attorney General. State Attorneys General get parens patriae authority on top.
That stack of duties on covered companies very likely clears the UMRA threshold.
. . .
The reported-out bill text does not name a funding source. No fee mechanism. No appropriation. No tied revenue stream. The regulatory regime is created. The money to run it is not identified in the four corners of the bill.
That is the structural exposure.
. . .
UMRA Section 423 gives any senator a point of order on the floor. The point of order lies against a bill carrying a federal private-sector mandate above the UMRA threshold when the bill lacks a CBO mandate cost estimate or fails to identify funding sufficient to cover the mandate. Waiving the point of order takes sixty votes.
Twenty-two to zero in committee was easy. Seventeen cosponsors was easy. No senator had a fiscal number attached to their name.
CBO will attach one. When the score lands, the asymmetry shifts. A bill that protects children polls at ninety. A bill that protects children and quietly obligates the Treasury to cover the enforcement regime polls differently. A bill that protects children, obligates the Treasury, and arrives on the floor without a funding mechanism gives forty-one senators a clean procedural objection they can defend on camera.
The clock is the story. Day Thirty-Five today. The CBO window closes somewhere between Day Forty-Five and Day Seventy-Five. The floor calendar is silent until it isn't.
|
For Counsel: Read Section 423 of UMRA before the score lands. The point-of-order trigger is mechanical, not discretionary. A reported-out bill carrying mandates above the threshold and lacking a CBO estimate or identified funding is exposed on first call. Sixty votes to waive is a real number, not a formality. Track the CBO docket daily from Day Forty-Five forward.
For Builders: The $250,000-per-violation civil penalty in the reported-out text is the operative number, not the earlier $100,000 figure from the introduced version. Both the U.S. Attorney General and State Attorneys General can sue. Age-verification, prohibition, and penalty stack into a compliance regime your product team has to model now, not after passage. The funding gap inside the bill does not reduce your exposure. It only delays the floor vote.
For Legislators: A unanimous markup vote is not a unanimous floor vote. Section 423 hands any one of your colleagues a point of order the moment CBO confirms the mandate threshold is crossed without a funding source named in the text. Sixty votes to waive is the number that will decide whether GUARD reaches final passage in its current form. The cosponsor list does not insulate you from that math.
Source: Congress.gov S.3062 status page and Senate Calendar No. 406 listing, https://www.congress.gov/bill/119th-congress/senate-bill/3062
|
. . .
THE OTHER FEDERAL BILL YOU HAVEN'T HEARD OF. Senator Ted Cruz and Senator Brian Schatz introduced the CHATBOT Act in late April. The bill is S.4407 in the Senate. It moves through Commerce, not Judiciary.
Senator Cruz chairs Senate Commerce. He filed the bill with Senator Schatz of Hawaii, Senator John Curtis of Utah, and Senator Adam Schiff of California. The House companion is H.R.7985.
The full name is the Children's Health, Advancement, Trust, Boundaries, and Oversight in Technology Act. The acronym is CHATBOT. The bill targets companion chatbot platforms.
It does not ban them for minors.
It requires AI companies to build "family accounts." Parents open the account. Parents grant consent before a child can use the chatbot. Parents get controls to access and monitor the child's conversations.
. . .
The bill goes further on the commercial layer. It prohibits targeted advertising to children on chatbot platforms. It limits manipulative design features. It directs federal study of chatbot-related harms to children and of best practices for parents.
This is a disclosure and consent regime. Not a prohibition regime.
The Senate Commerce one-pager frames the design as parental oversight at the account level. Roll Call covered the introduction on April 29. The bill has not cleared committee. Senate Commerce has not held a markup.
. . .
The structural picture is now two federal committees moving on the same harm. Two chairmen. Two theories of who is responsible.
A parallel bill in another committee, with a different lead Republican, says verify ages and ban AI-companion access for minors. The CHATBOT Act says open a family account and let parents watch.
One theory locates the duty in the platform. The other locates the duty in the parent.
Both bills sit in introduced status. Neither has moved to a vote. The Senate calendar is crowded and the committees do not coordinate markups on overlapping subject matter.
That leaves three possible futures. The bills compete and one absorbs the other in conference. The bills complement and pass as a package on companion-chatbot harm. Or both stall and the states keep legislating in the gap.
|
For Counsel: The CHATBOT Act is a consent and disclosure statute, not a prohibition. Compliance turns on parental account architecture, advertising restrictions, and design limits. The "manipulative design features" clause is the open term. Watch the committee report for the operative definition. Preemption language is not in the introduced text.
For Builders: If S.4407 passes in its current form, the build is a family-account layer with parent-side controls, conversation access, and consent gating before a minor session opens. Targeted ads to minors are out. The design-features clause will require product review of engagement loops. The study mandate signals more rules later, not fewer.
For Legislators: Two federal committees are now moving on companion-chatbot harm to minors on different theories. Commerce takes the parental-controls path. Judiciary takes the age-verification and ban path. State bills will continue to fill the gap while both federal bills sit. The choice between the two frames, platform duty or parent duty, is the policy question your constituents will ask.
Source: Senate Commerce Committee press release on CHATBOT Act introduction, https://www.commerce.senate.gov/press/rep/release/cruz-schatz-curtis-schiff-introduce-new-bill-giving-parents-control-over-kids-ai-chatbot-use/
|
. . .
THE STATES ALREADY DECIDED. Governor Tina Kotek signed Oregon Senate Bill 1546 in March 2026. Governor Bob Ferguson signed Washington House Bill 2225 on March 24, 2026. California Senate Bill 243 took effect on January 1, 2026.
Three Pacific-coast states now have companion-chatbot laws on the books. All three contain explicit mental-health provisions. Oregon and Washington both take effect January 1, 2027.
The provisions are not symbolic.
Each law requires the system to detect user expressions of suicidal ideation or self-harm. Each requires the system to interrupt the conversation when necessary. Each requires referrals to crisis resources including the 988 Suicide and Crisis Lifeline. Oregon's statute also names Youthline, the state's youth peer-support service.
Oregon's SB 1546 goes one step further. It requires AI systems to be designed to avoid generating responses that could contribute to suicidal thoughts. That is a design mandate, not a disclosure mandate.
. . .
California's SB 243 set the floor. Developers must clearly notify users they are talking to a chatbot. For minors the law adds a reminder every three hours that the bot is not human and that the user should take a break.
Oregon and Washington then built on top of that floor. Mayer Brown and Morgan Lewis both flag the same pattern in their April analyses. The Pacific Northwest laws extend California's transparency baseline into active crisis-response duties.
. . .
The Oregon coalition that pushed SB 1546 was not a tech-policy coalition. It was suicide-prevention advocates. Mental-health advocates. Pediatricians. Youth-safety groups. They wrote the bill that named a hotline.
The Future of Privacy Forum tracks the rest of the country. Its 2026 Chatbot Legislation Tracker counts ninety-eight chatbot-specific bills introduced across thirty-four states this year. Plus three federal proposals. An alternate tally finds seventy-eight chatbot-safety bills alive across twenty-seven states.
FPF groups the state legislation into six core areas. Transparency. Age verification and access controls. Content safety and harm prevention. Professional licensure and regulated services. Data protection. Liability and enforcement.
. . .
The contrast with Washington, D.C. is the story.
The federal bills name a verification requirement. The state laws name a destination for a kid in crisis. The states wrote the only playbooks in the country with an explicit handoff to a hotline.
|
For Counsel: Compliance dates are fixed. January 1, 2027 for Oregon and Washington. California is already live. The Oregon design-duty language goes beyond disclosure and creates a plausible negligence hook tied to model behavior. Multi-state operators should map the six FPF buckets against current product flows now.
For Builders: The crisis-detection requirement is a product requirement, not a policy note. The system must detect, interrupt, and route. The 988 handoff is named in statute and Youthline is named in Oregon. Build the referral surface before the January 1, 2027 effective date, not after.
For Legislators: The Pacific coast has set the template. Three states. Three signatures. Two coalitions led by suicide-prevention groups and pediatricians. If your state is among the twenty-seven with live bills, the drafting work is already done. Oregon's SB 1546 and California's SB 243 are the cleanest models for a crisis-handoff statute.
Source: Future of Privacy Forum, 2026 Chatbot Legislation Tracker, https://fpf.org/2026-chatbot-legislation-tracker/
|
. . .
WHAT FDA IS QUIETLY BUILDING. Doctor Marty Makary resigned as FDA Commissioner on May 12, 2026. The risk-based AI framework he signaled in January is now without its patron. The lane keeps grinding.
On November 6, 2025, the FDA's Digital Health Advisory Committee met to weigh generative-AI-enabled digital mental health devices. The committee made recommendations on benefits, risks, and risk mitigations. It covered premarket evidence and postmarket monitoring.
The committee surfaced specific concerns. Human susceptibility to AI outputs. Risks around suicidal-ideation monitoring and reporting. Potential increased risk from long-term AI use.
FDA staff and the committee pressed one point hard. Physician oversight matters. Human intervention in mental-health generative AI tools is not optional.
. . .
Behind the committee meeting sits a longer queue. FDA has nine new guidance documents under construction at the Center for Devices and Radiological Health. One is aimed straight at this sector.
The title is "Clinical Evidence Considerations for Digital Mental Health Treatment Devices, including Computerized Behavioral Therapy Devices." That guidance will tell builders what counts as evidence. It will tell counsel what a submission must carry.
. . .
In January 2026, Doctor Makary signaled a new risk-based AI framework. The emphasis shifted to post-market monitoring over premarket approval.
Four months later, on May 12, 2026, Doctor Makary resigned after thirteen months in the job. NPR reported the final straw was White House pressure to approve flavored vapes. The President named Kyle Diamantas, the deputy commissioner for food, as acting head. Diamantas is not a physician.
The framework signal Doctor Makary gave in January now sits without its patron.
. . .
The lane keeps grinding anyway. The Center for Devices and Radiological Health is not the commissioner. The career staff producing the nine guidance documents are not the commissioner. The November advisory committee record is not the commissioner.
This is the administrative-state lane. It runs in parallel to Congress. And it survives the resignation of the person who put a political face on it.
A bill needs a floor vote. A guidance document does not. It lands when CDRH publishes it. Companies adjust submissions the next quarter.
The lane is quieter than legislation. It is also harder to defeat than a single commissioner.
|
For Counsel: Track the CDRH guidance docket, not just the bill tracker. The political face of the post-market-monitoring framework has now resigned. The framework itself still moves through career staff at the Center. Build a provenance and training-data disclosure record now. Acting Commissioner Diamantas comes from food, not devices, and is unlikely to make mental-health AI guidance a personal priority. He is also unlikely to halt a pipeline already in motion.
For Builders: The committee told you what FDA wants to see. Data quality, integrity, provenance. How the model was trained. How outputs are intended to inform care. Physician oversight is not a nice-to-have in this category. Build the post-market monitoring stack now. The guidance will land regardless of who sits in the commissioner's chair.
For Legislators: Federal bills are not the only federal action. FDA is writing nine guidance documents at CDRH right now. One targets digital mental health treatment devices directly. The political face of the framework resigned on May 12. The pipeline continues without him. Your state preemption analysis should assume CDRH guidance will land before any federal statute does.
Source: NPR coverage of Doctor Makary's resignation, https://www.npr.org/2026/05/13/nx-s1-5819861/fda-commissioner-marty-makary-resigns-after-tumultuous-tenure
|
. . .
THE HOUSE ALREADY PASSED THEIRS. House Resolution 7757, the Kids Internet and Digital Safety Act, cleared the House Energy and Commerce Committee in March 2026. The recorded vote was twenty-eight yeas to twenty-four nays. The bill now awaits a full House vote.
Representative Brett Guthrie (R-Kentucky-02), the committee chairman, sponsored the KIDS Act. The package folds in two bills authored by Representative Erin Houchin (R-Indiana-09). One is the AI Warnings and Resources for Education Act, known as the AWARE Act. The other is House Resolution 6489, the Safeguarding Adolescents From Exploitative BOTs Act, known as the SAFE BOTs Act.
The SAFE BOTs Act sets four rules for chatbot providers. Disclose to minors when they are talking to an artificial-intelligence system and not a real person. Prohibit chatbots from claiming to be licensed professionals such as doctors or therapists. Provide crisis-hotline information when a minor raises suicide or self-harm. Mandate break prompts after three continuous hours of interaction.
Enforcement runs through the Federal Trade Commission. State attorneys general get concurrent authority to sue for violations.
. . .
The committee vote split along party lines. Democrats balked on portions of the package.
The KIDS Act carries state-preemption provisions for some chatbot-related state laws. A child-safety carve-out, rooted in the broader executive moratorium framework, narrows the preemption scope. It does not eliminate the federal-state conflict.
. . .
The structural pattern matters. The higher-profile Senate companion sits in a different committee and still waits for floor action. The House version has already cleared committee. It could reach a floor vote before the Senate bill does.
|
For Counsel: Read the preemption clause against the child-safety carve-out before advising clients on state-law exposure. The carve-out narrows the federal sweep. It does not erase it. FTC enforcement with concurrent state-attorney-general authority means dual-track litigation risk. Track the floor schedule, not just the committee text.
For Builders: If you ship to minors, the four SAFE BOTs requirements are the floor: AI-identity disclosure, no licensed-professional impersonation, crisis-hotline surfacing on suicide or self-harm cues, and break prompts at three hours. Build them now. The House could vote before the Senate does. Retrofitting after enactment is more expensive than building against the bill text today.
For Legislators: The KIDS Act would preempt parts of your state chatbot-safety laws. The child-safety carve-out preserves some of your authority. The boundary between preempted and preserved is where the litigation will land. Read House Resolution 7757 against your own statute. Know which provisions survive and which fall.
Source: Congress.gov, H.R.7757 text, https://www.congress.gov/bill/119th-congress/house-bill/7757/text
|
. . .
THE COUNSELOR SIM. The Trevor Project has trained more than one thousand crisis counselors using an AI role-player named Riley. Riley never talks to a kid. Riley talks to the counselor who will.
The Trevor Project runs the world's largest suicide-prevention service for LGBTQ+ young people. It operates TrevorChat, TrevorText, and a twenty-four-hour crisis line. It is a partner in the 988 Suicide and Crisis Lifeline.
In March 2021, the organization launched the Crisis Contact Simulator. The tool role-plays a young person in crisis. The trainee is the counselor. The simulator is the kid.
The first persona is Riley. Riley emulates a teen in North Carolina who feels anxious and depressed. A second persona, Drew, was added later. Drew represents a person in their early twenties in California facing harassment and bullying.
. . .
The Trevor Project built the simulator on OpenAI's GPT-2. Staff trained it on mock transcripts of counselor sessions with at-risk teens. The Trevor Project owns the tool and runs it.
Google.org put up two-point-seven-million dollars. Nearly thirty Google.org Fellows built and scaled the system alongside Trevor Project engineers.
The model never speaks to a young person in crisis. It only role-plays one for the trainee.
. . .
Trainees complete digital role-plays with the simulator on their own time. Then they move to instructor-led role-plays with staff. Then they take live contacts.
More than one thousand counselors have completed training on the simulator since launch.
The Trevor Project served more than two hundred thirty-one thousand crisis contacts in 2024. The organization trained and supported nearly two hundred fifty crisis counselors and operational support staff that year to support the 988 Lifeline.
. . .
The design point is simple. The AI trains the human. The human takes the contact. The kid in crisis talks to a person.
It is the inverse of the consumer-chatbot pattern. No model sits between the young person and a counselor. The model sits behind the counselor, before the shift starts.
|
For Counsel: The Trevor Project owns the model, owns the training data, and controls the deployment surface. The simulator is a training artifact, not a clinical service. Liability lives in counselor training records, supervision logs, and the human handoff. Counsel reviewing AI deployments in crisis settings should note the bright line: the AI never contacts a young person in crisis.
For Builders: Architecture matters more than model choice. GPT-2 in 2021, fine-tuned on mock transcripts, training counselors. The constraint is the deployment shape. The model role-plays the vulnerable user so a trained human can serve the real one. Build the human in the loop, then pick the model.
For Legislators: A counselor-in-loop AI deployment in suicide prevention has been running since March 2021. It is federally relevant. It trains humans who answer 988 contacts. Bills aimed at banning companion chatbots for minors do not touch this pattern. The pattern is the policy answer hiding in plain sight.
Source: Google.org announcement of the Trevor Project Crisis Contact Simulator, https://blog.google/company-news/outreach-and-initiatives/google-org/trevor-project-crisis-contact-simulator/
|
. . .
THE ONE CONFIGURATION. Six bills, two committees, two chambers, one agency, three states. Stop and count what is actually moving.
. . .
The Senate bill everyone names sat for thirty-five days after a twenty-two to zero markup. The clock owns it now. It cannot reach a floor vote without a CBO number, and a CBO number triggers a point of order on the floor without a funding source named in the text.
In a different committee, a different Senate bill takes a different theory. Family accounts. Parental controls and account-level consent.
The House moved farther and quieter. Twenty-eight to twenty-four out of Energy and Commerce. A state-preemption clause inside the package. A child-safety carve-out narrowing it. Waiting on a floor vote that the lead Senate bill has not yet earned.
FDA's lane has nine guidance documents at the desk. The commissioner who put a political face on the framework resigned May 12. The pipeline keeps moving anyway. No floor vote needed. No senator can stop it.
The states are already done.
. . .
That is the architecture this morning. Federal lanes crowded with bills that name a verification or a family account. State lanes already carrying laws that name a hotline. An agency lane grinding toward published rules.
And one design, running today, tied into the 988 Lifeline network, that puts an AI on the inside of the training program and a human on the call. The bills argue about that human. The simulator is already training her.
|