Law / United States / New York / New York City
Chatbot Data Privacy, Security, and TransparencyNew, proposed
In committee, dated , as of .
An AI transparency rule binding private bodies.
- What it reaches
- duty
As of .
Where it has got to
The text described here is Bill text as posted on the Council's legislation record, with no amendment letter, published .
Locally, this stage is introduced by the Council on and in the Committee of the Whole, which heard it as a pre-considered (P-C) item and laid it over on .
The stage above is recorded at legistar.council.nyc.gov.
The Committee of the Whole heard the item as a pre-considered item and laid it over on . The Council formally introduced it on as Int. No. 1118 of 2026, and the record shows it in the Committee of the Whole. The record carries no amendment letter and does not date the publication of the text, so the version date shown is that of the first recorded action.
What it requires
- This measure is proposed and binds nobody yet; what follows is what it would require if enacted in this form.
- It would require a chatbot provider to notify each user, before the chatbot generates any output, every hour afterward and each time the user asks whether it is a real person, that the user is interacting with a chatbot rather than a human, in a form accessible to users with disabilities, in the language the user is using and in a font no smaller than the largest other text on the interface.
- It would require a chatbot provider to maintain a comprehensive data security program, with administrative, technical and physical safeguards proportionate to the personal data and chat logs it holds, and to make the program publicly available on its website.
- It would give each user a right to access, at any time, the user's own retained chat logs in a downloadable, human- and machine-readable format.
- It would require a chatbot provider to assess its chatbot for risks of harm to users every month, mitigate those risks, and publish information about identified safety risks and their mitigation on its website.
- It would restrict a chatbot provider's processing: personal data beyond input data only where necessary for an express user request and with the user's affirmative consent; the chat logs and personal data of a user it knows or has reason to know is under 18 only with a parent's or guardian's affirmative consent and never for training; and an adult user's chat logs and personal data for training only with that user's affirmative consent.
- It would bar a chatbot provider, beyond what an express user request needs, from using chat logs to choose, target or customize advertisements, from profiling users, and from using a classification of a user's personality or behavior created through profiling.
- It would bar a chatbot provider from selling a user's chat logs without the user's affirmative consent, and from retaining a chat log for longer than 10 years unless retention is necessary to comply with the subchapter or is otherwise required by law.
- It would bar a chatbot provider from discriminating or retaliating against a user for refusing to consent to training use of chat logs or personal data or for accessing the user's own chat logs, and from indicating or implying that outputs are provided by, endorsed by or equivalent to those of a licensed healthcare, legal or accounting professional, a certified financial fiduciary or planner, or any other licensed or certified professional.
- It would make a chatbot provider liable for any injury it causes a user through the chatbot, including where it exercised all reasonable care and does not directly distribute the chatbot to the user, and would treat chatbots as products for product liability actions.
What this law does
This measure is proposed and binds nobody yet.
Sponsored by Council Member Frank Morano, it would put duties on a chatbot provider, meaning any person creating, distributing or otherwise making available an artificial intelligence model that generates text, audio, image or video simulating conversation: notify each user that they are talking to a chatbot rather than a human, publish a data security program, give users access to their own retained chat logs, assess the chatbot for risks of harm to users every month, and not imply that its outputs come from or equal those of a licensed or certified professional.
It would also restrict the processing of personal data and chat logs: that of a user the provider knows or has reason to know is under 18 could never be used for training and could be processed otherwise only with a parent's or guardian's affirmative consent, and an adult's could be used for training only with that user's consent.
It would limit advertising use, profiling, sale and retention of chat logs, bar retaliation against users who refuse consent to training or access their own chat logs, and make a provider liable for any injury its chatbot causes a user, with chatbots treated as products for product liability actions.
A civil penalty of not more than $25,000 per violation would apply, the corporation counsel could bring an action to correct violations, a person alleging a violation could sue for compensatory, injunctive and declaratory relief, and the bill would take effect 180 days after it becomes law.
When LexLint raises it
When your app profile says your app deploys a chatbot, generates content with AI, trains models, serves under-18s or processes voice recordings.