S 1885, the Stop the Scroll Act, requires major social media platforms and anonymous content-sharing apps (defined as "covered platforms") to display clear mental health warning labels each time a U.S. user accesses the service. The labels must warn users about potential mental health risks linked to social media use and provide access to resources like the 988 Suicide Lifeline. Platforms must display the label prominently upon entry, redisplay it hourly after user acknowledgment, and cannot hide it in terms of service or allow disabling. This law directly affects all covered platform providers operating in the U.S., mandating specific disclosure practices to inform users about health risks before engagement.
HR 2594 establishes a Water Risk and Resilience Organization (WRRO), certified by the EPA Administrator, to develop and enforce cybersecurity standards for large water systems. It directly affects community water systems serving 3,300+ people or similar treatment works, requiring them to meet WRRO-developed cybersecurity risk and resilience requirements. The WRRO proposes these standards, which the EPA must approve within 90 days if deemed reasonable, and monitors compliance through annual self-attestations and 5-year third-party assessments. The bill creates a process for penalties (up to $25,000/day) for noncompliance, with appeals to the EPA, while ensuring state authority remains intact.
The Consumer Safety Technology Act (S 2766) creates three key initiatives to enhance consumer safety through emerging technologies. Title I requires the Consumer Product Safety Commission to run a pilot program using artificial intelligence for tracking product injuries, identifying hazards, and monitoring online markets for recalled items, with a mandatory report to Congress afterward. Title II directs the Commerce Secretary to study how blockchain technology can prevent fraud in consumer transactions, including public input and a report on regulatory improvements. Title III mandates the Federal Trade Commission to report on its enforcement actions against deceptive practices involving digital tokens and recommend legislative changes to strengthen consumer protections in this growing market.
The Artificial Intelligence Civil Rights Act of 2025 requires developers and deployers of AI systems that make decisions affecting "consequential actions" (such as employment, housing, healthcare, education, and credit) to conduct pre-deployment evaluations and annual impact assessments by independent auditors. The bill mandates transparency requirements including clear disclosures to individuals about how AI is used in decision-making, establishes a right to human alternatives for significant AI-driven decisions, and prohibits discrimination based on protected characteristics like race, gender, or disability. It creates enforcement mechanisms through the Federal Trade Commission, state attorneys general, and private lawsuits, with penalties including civil penalties of up to 4% of annual revenue. The act also requires developers to provide explanations for AI-driven decisions and sets standards for data collection to prevent harm and ensure fairness in critical life areas.
The GUARD Act requires companies providing AI chatbots to verify users' ages using reliable methods (like government IDs, not just self-reported birth dates) and prohibits minors under 18 from accessing "AI companions" designed for emotional interaction. It mandates clear disclosures that chatbots are not human and cannot falsely claim to be licensed professionals (e.g., therapists), while banning features that solicit minors for explicit content or promote violence. Covered entities must implement secure age verification processes for all accounts, including periodic checks, and face civil penalties up to $100,000 per violation for noncompliance. The law directly affects tech companies operating AI chatbots in the U.S. and aims to reduce minors' exposure to harmful AI interactions.
HR 6334, the Deepfake Liability Act, requires online platforms to implement specific processes to address non-consensual intimate content and cyberstalking. It amends Section 230 of the Communications Act to create a "duty of care" for platforms, mandating they prevent and remove intimate privacy violations (like non-consensual deepfakes or intimate images) within 48 hours of a valid request. The law directly affects victims of non-consensual intimate content and platforms classified as "covered platforms" (social media, apps, and websites), while excluding email, messaging services, and data storage. Key provisions include minimum data logging for legal proceedings, clear removal processes, and a 48-hour removal timeline for verified violations.
HR 872 requires federal contractors with contracts above $250,000 or those handling federal information systems to implement vulnerability disclosure policies aligned with NIST guidelines and international standards (like ISO 29147). Within 180 days, the OMB and agencies must update the Federal Acquisition Regulation (FAR) and Defense FAR (DFARS) to mandate these policies, ensuring contractors disclose security vulnerabilities in systems they manage for the government. The bill allows limited waivers for national security or research, requiring congressional notification within 30 days. It directly affects major federal contractors, aiming to standardize how security flaws are reported and addressed across government contracts.
S 2850, the Protecting Legislators and Survivors of Sexual Assault and Domestic Violence from Doxing and Political Violence Act, would protect Members of Congress, their immediate family members, designated legislative employees, and survivors of domestic violence or sexual assault from having sensitive personal information publicly shared. The bill defines "covered information" to include home addresses, phone numbers, email addresses, social security numbers, license plate numbers, and details about children's schools or daily routines. It requires government agencies to remove this information from public records within 72 hours of a request and prohibits data brokers from selling or trading this information. Businesses and websites must also remove covered information upon request, with exceptions for news reporting and information voluntarily shared by the individual.
The AI Grand Challenges Act of 2026 directs the National Science Foundation (NSF) to establish prize competitions for U.S.-based researchers and companies to solve specific, measurable problems in critical areas like health, national security, energy, and cancer research. It requires the NSF to publish clear problem statements and success metrics for each challenge, including a mandatory $10 million prize competition focused on AI-driven cancer breakthroughs for detection, treatment, or diagnostics. Eligibility is limited to U.S. entities or citizens/permanent residents, with annual reporting to Congress on competition results and public accessibility via the Challenge.gov platform. The bill mandates public input on challenge selection and biennial reports detailing program activities and outcomes.
HR 3218, the Reproductive Data Privacy and Protection Act, requires law enforcement and government agencies to swear under oath that they will not use reproductive or sexual health information in investigations or legal proceedings. It amends federal wiretap laws (18 U.S.C. § 2518) and communication disclosure rules (18 U.S.C. § 2703) to mandate this protection. The bill defines "reproductive or sexual health information" broadly to include details about abortion, contraception, IVF, pregnancy, sexual health conditions, and related medical services. This directly affects law enforcement, courts, and service providers by legally restricting how sensitive health data can be used in investigations. The law aims to prevent government use of such data to target individuals seeking or providing reproductive care.