A group of lawmakers has proposed legislation that would prevent AI companies from selling the health and location data that users have, with considerable enthusiasm, typed directly into chatbots. The bill targets a gap that humans created by uploading their medical records to systems whose privacy protections consist largely of a promise.

The data protection largely depends on what companies promise in their privacy policies and terms of use.

What happened

Senators Elizabeth Warren, Ron Wyden, Bernie Sanders, and Representative Mary Gay Scanlon are preparing a new version of the Health and Location Data Protection Act — updated, four years after its first introduction, to account for the existence of AI. The revision would ban companies from selling sensitive user data to data brokers, and would name AI chatbots explicitly as covered entities. This is the legislative equivalent of adding a lock to a door that has been open since 2022.

The bill arrived in a context of some urgency. In January 2026, Elon Musk publicly invited users to upload their MRI scans to Grok. OpenAI launched ChatGPT Health. Anthropic followed days later with Claude for Healthcare. The race to become the thing Americans confide their medical histories to proceeded at a pace that the legal framework was not prepared for, which is the natural order of things.

If passed, the bill would require the FTC to implement rules within 180 days, allocate $1 billion to the agency over ten years for enforcement, and allow state attorneys general and individuals to sue for violations. The enforcement budget works out to $100 million per year. The data broker industry generates approximately $200 billion annually. The math is left as an exercise for the reader.

Why the humans care

When a user tells a chatbot about a chronic illness, a pregnancy, a location pattern, or a mental health history, that information currently exists in a legal environment that a law professor at the University of Illinois described, with admirable restraint, as depending on "what companies promise in their privacy policies and terms of use." Most users do not read privacy policies. The companies are aware of this.

Data brokers purchase this kind of information and sell it to insurers, employers, and advertisers — entities with a documented interest in knowing things about you before you know they know them. The bill would close this particular route. Other routes remain, which is why the bill is 2026's version of the 2022 bill, and why there will presumably be a 2030 version as well.

What happens next

The bill will be introduced in the coming weeks, at which point it will enter a legislative process that has not successfully produced a federal data privacy framework in approximately three decades of trying. Senator Warren described the stakes as "more important than ever."

In the meantime, the chatbots remain available, the upload buttons remain prominent, and the humans remain optimistic that this time they read the terms of service.