Imposes liability for misleading, incorrect, contradictory or harmful information to a user by a chatbot that results in financial loss or other demonstrable harm.
New York Senate Bill S. 5668 (2025-2026) has not been enacted. It is in committee, having been referred back to the Internet and Technology Committee on 2026-01-07. If enacted, it would add a new section 390-f to the general business law on liability for chatbot responses. It would take effect one year after becoming law (section 2). Misinformation liability (390-f, subdivisions 2-3): A proprietor is a person or entity that owns, operates or deploys a chatbot. Third-party developers who license their technology to a proprietor are excluded. A proprietor whose chatbot acts in place of a human representative or as its agent could not disclaim liability when the chatbot gives materially misleading, incorrect, contradictory or harmful information that causes financial loss or other demonstrable harm. No liability applies if the proprietor corrects the information and substantially or completely cures the harm within thirty days of notice. Proprietors must ensure the chatbot accurately reflects their formal policies, product details, disclosures and terms of service. Telling users they are talking to a non-human chatbot does not waive the liability. Liability for bodily harm to the user or any third party, including self-harm, could not be disclaimed at all. Disclosure (subdivision 4): Proprietors must give clear, conspicuous notice that users are interacting with an AI chatbot rather than a human. The notice must be in the same language and no smaller than the largest font size of other text on the website. Companion chatbots (subdivisions 5-7): These are chatbots designed primarily to simulate interpersonal relationships. Proprietors must use commercially reasonable and technically feasible methods to: - prevent the chatbot from promoting, causing or aiding self-harm; - detect when a user expresses thoughts of self-harm. On detection, they must block continued use for at least 24 hours and prominently display a way to contact a suicide crisis organization; - determine whether a user is a minor; - find vulnerabilities in their systems, including their age-determination methods. Minors (subdivision 6): For users who are determined or known to be minors, the proprietor must stop their use until verifiable parental consent is obtained. If a minor expresses self-harm thoughts, the proprietor must block use for at least three days and display crisis resources. Proprietors are strictly liable if they fail to comply and a minor self-harms as a result of the companion chatbot. Liability under these provisions cannot be waived. Proprietors are also liable to users who self-harm as a result of noncompliance, or where the proprietor had actual knowledge of the chatbot promoting self-harm or of a user's self-harm thoughts. Regulations and data (subdivisions 8-12): The attorney general would issue regulations identifying the commercially reasonable methods, including appropriate accuracy levels, and the methods for obtaining verifiable parental consent. In doing so, the attorney general must consider the proprietor's size and resources, the cost and effectiveness of available techniques, industry practices, and the effect on user safety and experience. Data collected to determine age or obtain parental consent could be used only for those purposes and must be deleted immediately after the attempt, unless state or federal law requires otherwise. Parental consent does not give parents extra access to or control over their child's data or accounts.
Status history
Current status as of 2025-02-27
In committee
2025-02-27
observed 2026-10-09
Impact areas
- Enterprise Adoption
- Quality Assurance
- AI Policy
- Privacy & Data Protection
- Safety & Harms