AI Frontier Institute

AI Chatbots-Licensing, Safety, & Privacy

NCS963In committee
Published automatically

View primary source →

North Carolina Senate Bill 963 has not been enacted. It was filed April 30, 2026, passed first reading, and on May 4, 2026 was re-referred to the Appropriations/Base Budget committee. If enacted, it would do three things. (1) Part I would create the Chatbot Licensing Act (new Chapter 114B). Anyone operating or distributing a chatbot that deals substantially with health information would need a license from the Department of Justice (G.S. 114B-3). Applicants must document the chatbot's architecture, data practices, security and privacy measures, testing, risk mitigation, regulatory compliance, and insurance. Licensees would have to carry professional liability insurance, use encryption, report breaches within 24 hours to the Department and 48 hours to consumers, obtain explicit consent, and give users access to and deletion of their data. They would also have to disclose the chatbot's artificial nature and its limitations. They would have to show effectiveness through peer-reviewed controlled trials and comparison with human experts, undergo an annual third-party audit, and submit quarterly performance reports (G.S. 114B-4). The Department could carry out physical and digital inspections, including examining source code, algorithms and models (G.S. 114B-6). Violating G.S. 114B-5 or 114B-6 would carry a $50,000 civil penalty (G.S. 114B-7). Section 1(b) appropriates $50,000 in nonrecurring funds for 2026-27 to publicize the Act. (2) Part II would create the Chatbot Safety and Privacy Act (new Chapter 170). It would apply to covered platforms, which are chatbot providers with more than $100,000 in annual revenue or more than 5,000 monthly active U.S. users, with exclusions for non-monetized educational or research services and government entities. Covered platforms would owe users a duty of loyalty (G.S. 170-3). That duty includes emergency detection and response, preventing emotional dependence for companion-style chatbots, honest identification as non-human, and limits on manipulative influence, data collection and personalization. Chatbot identification and consent would have to be repeated at the start of each interaction, separate from privacy policy consent (G.S. 170-5). Data privacy rules would require de-identification before storage and analysis, keeping sensitive personal information out of AI training datasets, 30-day self-destructing messages in sensitive sectors such as healthcare, finance, legal, government, mental health and education, and transport encryption (G.S. 170-6). The Attorney General could sue, and individuals could sue for the greater of actual damages or $1,000 per violation plus attorneys' fees. The right to sue could not be waived (G.S. 170-7). (3) Section 3 directs the Department of Justice to adopt implementing rules by January 1, 2027. Chapter 114B and Part II take effect January 1, 2027, and the appropriation takes effect July 1, 2026 (Sections 1(c), 2(b)).

Status history

Current status as of 2026-04-30

  1. In committee

    2026-04-30

    observed 2026-08-30

Impact areas

← Back to the tracker