In a significant escalation of AI oversight efforts, Senator Elizabeth Warren (D-MA) and Representative Mary Gay Scanlon (D-PA) are planning to introduce sweeping legislation that would ban the sale of Americans' health and location data to third-party data brokers. The proposal, expected to debut in the coming weeks, specifically targets the growing practice of AI companies monetizing sensitive personal information revealed during interactions with chatbots and other AI systems. This move represents the first major federal attempt to restrict how AI companies can commercialize health data—information that has become increasingly valuable as companies build behavioral profiles for advertising and other commercial purposes. The bill would apply comprehensive restrictions to chatbot platforms like ChatGPT and Claude, which millions of Americans now use for health-related inquiries despite no explicit medical training.
The legislation arrives at a critical juncture as AI companies have largely operated in a regulatory gray zone regarding health data. Unlike healthcare providers bound by HIPAA, AI platforms accepting health queries have faced minimal constraints on data monetization. Warren and Scanlon's proposal addresses this gap directly, establishing that voluntary disclosures to AI systems carry the same protections as institutionally-gathered health information. The timing reflects growing public concern about AI companies' data practices following investigations into how chatbots retain and potentially repurpose sensitive user information. Industry observers expect significant pushback from tech companies and data brokers who have built business models around health data sales, though consumer advocacy groups have welcomed the intervention.
This proposal signals that AI regulation is shifting from abstract principles toward concrete restrictions on specific practices. Unlike earlier proposals focusing on AI safety or bias, the Warren-Scanlon bill targets a tangible harm: unauthorized commercialization of medical information. If successful, it could establish a precedent for treating AI platforms similarly to traditional healthcare entities regarding data stewardship. The bill's success remains uncertain—tech industry lobbying is expected to intensify—but its introduction demonstrates that Congress is moving beyond rhetoric toward legislative action on AI accountability, particularly where vulnerable health information is involved.