Vermont · House Bill · 2026 Regular Session
HB784
Vermont H.784 — An act relating to the regulation of chatbots

Status ● Introduced Effective Jul 1, 2026 Passage Likelihood M

WHAT THIS BILL REGULATES · 6 REQUIREMENT TYPES

How Is This Bill Enforced

Enforcement Authority
Attorney General or State's Attorney enforcement via civil action. Private right of action for users injured by violations of § 4193b (data privacy and security) or § 4193c(a)–(b) (licensed professional misrepresentation and AI identity disclosure). A violation of those sections constitutes an injury in fact to a user, establishing standing without proof of additional harm.
Private Right of Action
Private right of action for users injured by violations of § 4193b (data privacy and security) or § 4193c(a)–(b) (licensed professional misrepresentation and AI identity disclosure).
Penalties
Private action: liquidated damages of $5,000 per violation for data privacy violations (§ 4193b), or actual damages, whichever is greater; $5,000 in total for all transparency violations (§ 4193c(a)–(b)), or actual damages, whichever is greater. Punitive damages available for reckless and knowing violations. Injunctive relief, declaratory relief, and reasonable attorney's fees and litigation costs also available. AG/State's Attorney may obtain damages, civil penalties, restitution, injunctive relief, and reasonable attorney's fees.

What This Bill Requires

Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.

Statutory Text
Analysis & Obligations
9 V.S.A. § 4193a
Definitions

(1)–(18) As used in this subchapter: (1) "AdvertisementAdvertisement"Advertisement" means any written or oral statement, illustration, or depiction that promotes the sale or use of a good or service or is designed to increase interest in a brand, good, or service where such statement, illustration, or depiction is displayed in exchange for monetary or other valuable consideration, including access to data between the chatbot provider and the brand, good, or service.9 V.S.A. § 4193a(1)" means any written or oral statement, illustration, or depiction that promotes the sale or use of a good or service or is designed to increase interest in a brand, good, or service where such statement, illustration, or depiction is displayed in exchange for monetary or other valuable consideration, including access to data between the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) and the brand, good, or service. (2)(A) "Affirmative consentAffirmative consent"Affirmative consent" means a clear, affirmative act signifying a user's freely given, specific, informed, and unambiguous authorization for an act or practice in response to a specific request from a chatbot provider, provided: (i) the request is provided to the user in a clear and conspicuous standalone disclosure; (ii) the request includes a description, written in easy-to-understand language, of the act or practice for which the user's consent is sought; (iii) the request is made in a manner reasonably accessible to and usable by users with disabilities; (iv) the request is made available to the user in each language in which the chatbot provider provides a chatbot; (v) the option to refuse to give consent is at least as prominent as the option to give consent, and the option to refuse to give consent takes the same number of steps as or fewer than the option to give consent; and (vi) affirmative consent to an act or practice is not inferred from the inaction of the user or the user's continued use of a chatbot provided by the chatbot provider. "Affirmative consent" does not include: (i) acceptance of general or broad terms of use or a similar document; (ii) hovering over, muting, pausing, or closing a given piece of content; (iii) agreement obtained through the use of a false, fraudulent, or materially misleading statement or representation; or (iv) agreement obtained through the use of other dark patterns.9 V.S.A. § 4193a(2)" means a clear, affirmative act signifying a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s freely given, specific, informed, and unambiguous authorization for an act or practice in response to a specific request from a chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5), provided: (i) the request is provided to the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) in a clear and conspicuous standalone disclosure; (ii) the request includes a description, written in easy-to-understand language, of the act or practice for which the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s consent is sought; (iii) the request is made in a manner reasonably accessible to and usable by usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) with disabilities; (iv) the request is made available to the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) in each language in which the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) provides a chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4); (v) the option to refuse to give consent is at least as prominent as the option to give consent, and the option to refuse to give consent takes the same number of steps as or fewer than the option to give consent; and (vi) affirmative consentAffirmative consent"Affirmative consent" means a clear, affirmative act signifying a user's freely given, specific, informed, and unambiguous authorization for an act or practice in response to a specific request from a chatbot provider, provided: (i) the request is provided to the user in a clear and conspicuous standalone disclosure; (ii) the request includes a description, written in easy-to-understand language, of the act or practice for which the user's consent is sought; (iii) the request is made in a manner reasonably accessible to and usable by users with disabilities; (iv) the request is made available to the user in each language in which the chatbot provider provides a chatbot; (v) the option to refuse to give consent is at least as prominent as the option to give consent, and the option to refuse to give consent takes the same number of steps as or fewer than the option to give consent; and (vi) affirmative consent to an act or practice is not inferred from the inaction of the user or the user's continued use of a chatbot provided by the chatbot provider. "Affirmative consent" does not include: (i) acceptance of general or broad terms of use or a similar document; (ii) hovering over, muting, pausing, or closing a given piece of content; (iii) agreement obtained through the use of a false, fraudulent, or materially misleading statement or representation; or (iv) agreement obtained through the use of other dark patterns.9 V.S.A. § 4193a(2) to an act or practice is not inferred from the inaction of the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) or the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s continued use of a chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) provided by the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5). (B) "Affirmative consentAffirmative consent"Affirmative consent" means a clear, affirmative act signifying a user's freely given, specific, informed, and unambiguous authorization for an act or practice in response to a specific request from a chatbot provider, provided: (i) the request is provided to the user in a clear and conspicuous standalone disclosure; (ii) the request includes a description, written in easy-to-understand language, of the act or practice for which the user's consent is sought; (iii) the request is made in a manner reasonably accessible to and usable by users with disabilities; (iv) the request is made available to the user in each language in which the chatbot provider provides a chatbot; (v) the option to refuse to give consent is at least as prominent as the option to give consent, and the option to refuse to give consent takes the same number of steps as or fewer than the option to give consent; and (vi) affirmative consent to an act or practice is not inferred from the inaction of the user or the user's continued use of a chatbot provided by the chatbot provider. "Affirmative consent" does not include: (i) acceptance of general or broad terms of use or a similar document; (ii) hovering over, muting, pausing, or closing a given piece of content; (iii) agreement obtained through the use of a false, fraudulent, or materially misleading statement or representation; or (iv) agreement obtained through the use of other dark patterns.9 V.S.A. § 4193a(2)" does not include: (i) acceptance of general or broad terms of use or a similar document; (ii) hovering over, muting, pausing, or closing a given piece of content; (iii) agreement obtained through the use of a false, fraudulent, or materially misleading statement or representation; or (iv) agreement obtained through the use of other dark patternsDark pattern"Dark pattern" means a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision making, or choice, and includes any practice the Federal Trade Commission refers to as a dark pattern.9 V.S.A. § 4193a(7). (3) "Chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3)" means any input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9), outputs generated by a chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4), or record of the input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) or outputs from userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) interactions with a chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4). (4) "ChatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4)" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation. (5) "Chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5)" means any person creating, distributing, or otherwise making available a chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4). (6) "CollectCollect"Collect" or "collecting" means creating, buying, renting, gathering, obtaining, receiving, accessing, or otherwise acquiring personal data or input data by any means through individuals' use of chatbots.9 V.S.A. § 4193a(6)" or "collecting" means creating, buying, renting, gathering, obtaining, receiving, accessing, or otherwise acquiring personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) or input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) by any means through individuals' use of chatbotsChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4). (7) "Dark patternDark pattern"Dark pattern" means a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision making, or choice, and includes any practice the Federal Trade Commission refers to as a dark pattern.9 V.S.A. § 4193a(7)" means a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) interface designed or manipulated with the substantial effect of subverting or impairing userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) autonomy, decision making, or choice, and includes any practice the Federal Trade Commission refers to as a dark patternDark pattern"Dark pattern" means a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision making, or choice, and includes any practice the Federal Trade Commission refers to as a dark pattern.9 V.S.A. § 4193a(7). (8) "Deidentified dataDeidentified data"Deidentified data" means information that cannot reasonably be used to infer or derive the identity of an individual or does not identify and is not linked or reasonably linkable to an individual or a device that identifies or is linked or reasonably linkable to such individual, regardless of whether the information is aggregated, provided that the chatbot provider: (A) takes such physical, administrative, and technical measures as are necessary to ensure that the information cannot, at any point, be used to reidentify any individual or device that identifies or is linked or reasonably linkable to one or more individuals; (B) publicly commits in a clear and conspicuous manner to: (i) process, retain, or transfer the information solely in a deidentified form without any reasonable means for reidentification; and (ii) not attempt to reidentify the information with any individual or device that identifies or is linked or reasonably linkable to an individual; and (C) contractually obligates any entity that receives the information from the chatbot provider to: (i) comply with all of the provisions of this subdivision (8) with respect to the information; and (ii) require that such contractual obligations be included in all subsequent instances in which the data may be received.9 V.S.A. § 4193a(8)" means information that cannot reasonably be used to infer or derive the identity of an individual or does not identify and is not linked or reasonably linkable to an individual or a device that identifies or is linked or reasonably linkable to such individual, regardless of whether the information is aggregated, provided that the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5): (A) takes such physical, administrative, and technical measures as are necessary to ensure that the information cannot, at any point, be used to reidentify any individual or device that identifies or is linked or reasonably linkable to one or more individuals; (B) publicly commits in a clear and conspicuous manner to: (i) processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12), retain, or transfer the information solely in a deidentified form without any reasonable means for reidentification; and (ii) not attempt to reidentify the information with any individual or device that identifies or is linked or reasonably linkable to an individual; and (C) contractually obligates any entity that receives the information from the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) to: (i) comply with all of the provisions of this subdivision (8) with respect to the information; and (ii) require that such contractual obligations be included in all subsequent instances in which the data may be received. (9) "Input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9)" means information, including text, photos, audio, video, or files, provided to a chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) by a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17). (10) "ModelModel"Model" means an engineered or machine-based system underlying a chatbot that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.9 V.S.A. § 4193a(10)" means an engineered or machine-based system underlying a chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments. (11)(A) "Personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11)" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. (B) "Personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11)" does not include deidentified dataDeidentified data"Deidentified data" means information that cannot reasonably be used to infer or derive the identity of an individual or does not identify and is not linked or reasonably linkable to an individual or a device that identifies or is linked or reasonably linkable to such individual, regardless of whether the information is aggregated, provided that the chatbot provider: (A) takes such physical, administrative, and technical measures as are necessary to ensure that the information cannot, at any point, be used to reidentify any individual or device that identifies or is linked or reasonably linkable to one or more individuals; (B) publicly commits in a clear and conspicuous manner to: (i) process, retain, or transfer the information solely in a deidentified form without any reasonable means for reidentification; and (ii) not attempt to reidentify the information with any individual or device that identifies or is linked or reasonably linkable to an individual; and (C) contractually obligates any entity that receives the information from the chatbot provider to: (i) comply with all of the provisions of this subdivision (8) with respect to the information; and (ii) require that such contractual obligations be included in all subsequent instances in which the data may be received.9 V.S.A. § 4193a(8) or publicly available informationPublicly available information"Publicly available information" means information that has been lawfully made available to the general public from: (i) federal, state, or municipal government records, provided the information is collected, processed, and transferred in accordance with restrictions or terms of use placed on the information by the relevant government entity; (ii) widely distributed media; or (iii) a disclosure to the general public as required by federal, state, or local law. "Publicly available information" does not include: (i) any obscene visual depiction, as defined in 18 U.S.C. § 1460; (ii) biometric data; (iii) personal data that is created through the combination of personal data with publicly available information; (iv) information that is collated and combined to create user profiles on publicly available or subscription-based websites and inferences generated from such information; (v) genetic data, unless otherwise made publicly available by the individual to whom the information pertains; (vi) information made available by a user on a website or online service made available to all members of the public, for free or for a fee, where the user has restricted the information to a specific audience; or (vii) intimate images, authentic or computer generated, known to be nonconsensual.9 V.S.A. § 4193a(14). (12) "ProcessProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12)" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) or input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) or on sets of personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) or input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9), such as the use, storage, disclosure, analysis, deletion, or modification of such data. (13)(A) "ProfilingProfiling"Profiling" means any form of processing performed on input data or personal data to detect and classify or designate personality and behavioral characteristics of an individual. "Profiling" does not include processing of chat logs for purposes of user safety or to otherwise comply with this subchapter.9 V.S.A. § 4193a(13)" means any form of processing performed on input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) or personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) to detect and classify or designate personality and behavioral characteristics of an individual. (B) "ProfilingProfiling"Profiling" means any form of processing performed on input data or personal data to detect and classify or designate personality and behavioral characteristics of an individual. "Profiling" does not include processing of chat logs for purposes of user safety or to otherwise comply with this subchapter.9 V.S.A. § 4193a(13)" does not include processing of chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) for purposes of userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) safety or to otherwise comply with this subchapter. (14)(A) "Publicly available informationPublicly available information"Publicly available information" means information that has been lawfully made available to the general public from: (i) federal, state, or municipal government records, provided the information is collected, processed, and transferred in accordance with restrictions or terms of use placed on the information by the relevant government entity; (ii) widely distributed media; or (iii) a disclosure to the general public as required by federal, state, or local law. "Publicly available information" does not include: (i) any obscene visual depiction, as defined in 18 U.S.C. § 1460; (ii) biometric data; (iii) personal data that is created through the combination of personal data with publicly available information; (iv) information that is collated and combined to create user profiles on publicly available or subscription-based websites and inferences generated from such information; (v) genetic data, unless otherwise made publicly available by the individual to whom the information pertains; (vi) information made available by a user on a website or online service made available to all members of the public, for free or for a fee, where the user has restricted the information to a specific audience; or (vii) intimate images, authentic or computer generated, known to be nonconsensual.9 V.S.A. § 4193a(14)" means information that has been lawfully made available to the general public from: (i) federal, state, or municipal government records, provided the information is collected, processed, and transferred in accordance with restrictions or terms of use placed on the information by the relevant government entity; (ii) widely distributed media; or (iii) a disclosure to the general public as required by federal, state, or local law. (B) "Publicly available informationPublicly available information"Publicly available information" means information that has been lawfully made available to the general public from: (i) federal, state, or municipal government records, provided the information is collected, processed, and transferred in accordance with restrictions or terms of use placed on the information by the relevant government entity; (ii) widely distributed media; or (iii) a disclosure to the general public as required by federal, state, or local law. "Publicly available information" does not include: (i) any obscene visual depiction, as defined in 18 U.S.C. § 1460; (ii) biometric data; (iii) personal data that is created through the combination of personal data with publicly available information; (iv) information that is collated and combined to create user profiles on publicly available or subscription-based websites and inferences generated from such information; (v) genetic data, unless otherwise made publicly available by the individual to whom the information pertains; (vi) information made available by a user on a website or online service made available to all members of the public, for free or for a fee, where the user has restricted the information to a specific audience; or (vii) intimate images, authentic or computer generated, known to be nonconsensual.9 V.S.A. § 4193a(14)" does not include: (i) any obscene visual depiction, as defined in 18 U.S.C. § 1460; (ii) biometric data; (iii) personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) that is created through the combination of personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) with publicly available informationPublicly available information"Publicly available information" means information that has been lawfully made available to the general public from: (i) federal, state, or municipal government records, provided the information is collected, processed, and transferred in accordance with restrictions or terms of use placed on the information by the relevant government entity; (ii) widely distributed media; or (iii) a disclosure to the general public as required by federal, state, or local law. "Publicly available information" does not include: (i) any obscene visual depiction, as defined in 18 U.S.C. § 1460; (ii) biometric data; (iii) personal data that is created through the combination of personal data with publicly available information; (iv) information that is collated and combined to create user profiles on publicly available or subscription-based websites and inferences generated from such information; (v) genetic data, unless otherwise made publicly available by the individual to whom the information pertains; (vi) information made available by a user on a website or online service made available to all members of the public, for free or for a fee, where the user has restricted the information to a specific audience; or (vii) intimate images, authentic or computer generated, known to be nonconsensual.9 V.S.A. § 4193a(14); (iv) information that is collated and combined to create userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) profiles on publicly available or subscription-based websites and inferences generated from such information; (v) genetic data, unless otherwise made publicly available by the individual to whom the information pertains; (vi) information made available by a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) on a website or online service made available to all members of the public, for free or for a fee, where the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) has restricted the information to a specific audience; or (vii) intimate images, authentic or computer generated, known to be nonconsensual. (15)(A) "SellSell"Sell" means exchanging personal data or input data for monetary or other valuable consideration or making available such data or use of such data by the chatbot provider to a third party. "Sell" does not include: (i) the disclosure of personal data or input data to a third party that processes the data on behalf of the chatbot provider; (ii) with the user's affirmative consent, the disclosure of personal data or input data where the user affirmatively directs the chatbot provider to disclose the data or intentionally uses the chatbot provider to interact with a third party; or (iii) the disclosure of personal data that the user: (I) intentionally made available to the general public via a channel of mass media; and (II) did not restrict to a specific audience.9 V.S.A. § 4193a(15)" means exchanging personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) or input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) for monetary or other valuable consideration or making available such data or use of such data by the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) to a third party. (B) "SellSell"Sell" means exchanging personal data or input data for monetary or other valuable consideration or making available such data or use of such data by the chatbot provider to a third party. "Sell" does not include: (i) the disclosure of personal data or input data to a third party that processes the data on behalf of the chatbot provider; (ii) with the user's affirmative consent, the disclosure of personal data or input data where the user affirmatively directs the chatbot provider to disclose the data or intentionally uses the chatbot provider to interact with a third party; or (iii) the disclosure of personal data that the user: (I) intentionally made available to the general public via a channel of mass media; and (II) did not restrict to a specific audience.9 V.S.A. § 4193a(15)" does not include: (i) the disclosure of personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) or input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) to a third party that processesProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) the data on behalf of the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5); (ii) with the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s affirmative consentAffirmative consent"Affirmative consent" means a clear, affirmative act signifying a user's freely given, specific, informed, and unambiguous authorization for an act or practice in response to a specific request from a chatbot provider, provided: (i) the request is provided to the user in a clear and conspicuous standalone disclosure; (ii) the request includes a description, written in easy-to-understand language, of the act or practice for which the user's consent is sought; (iii) the request is made in a manner reasonably accessible to and usable by users with disabilities; (iv) the request is made available to the user in each language in which the chatbot provider provides a chatbot; (v) the option to refuse to give consent is at least as prominent as the option to give consent, and the option to refuse to give consent takes the same number of steps as or fewer than the option to give consent; and (vi) affirmative consent to an act or practice is not inferred from the inaction of the user or the user's continued use of a chatbot provided by the chatbot provider. "Affirmative consent" does not include: (i) acceptance of general or broad terms of use or a similar document; (ii) hovering over, muting, pausing, or closing a given piece of content; (iii) agreement obtained through the use of a false, fraudulent, or materially misleading statement or representation; or (iv) agreement obtained through the use of other dark patterns.9 V.S.A. § 4193a(2), the disclosure of personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) or input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) where the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) affirmatively directs the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) to disclose the data or intentionally uses the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) to interact with a third party; or (iii) the disclosure of personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) that the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17): (I) intentionally made available to the general public via a channel of mass media; and (II) did not restrict to a specific audience. (16) "TrainingTraining"Training" means the use of input data to adjust or modify a model. "Training" does not include: (A) testing to identify risks of harm to users; (B) adjustments or modifications to address identified risks of harm to users; or (C) any actions necessary to comply with this subchapter or otherwise required by law.9 V.S.A. § 4193a(16)" means the use of input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) to adjust or modify a modelModel"Model" means an engineered or machine-based system underlying a chatbot that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.9 V.S.A. § 4193a(10). "TrainingTraining"Training" means the use of input data to adjust or modify a model. "Training" does not include: (A) testing to identify risks of harm to users; (B) adjustments or modifications to address identified risks of harm to users; or (C) any actions necessary to comply with this subchapter or otherwise required by law.9 V.S.A. § 4193a(16)" does not include: (A) testing to identify risks of harm to usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17); (B) adjustments or modifications to address identified risks of harm to usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17); or (C) any actions necessary to comply with this subchapter or otherwise required by law. (17) "UserUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)" means any individual, regardless of age. (18)(A) "Widely distributed media" means information that is available to the general public, including information from a telephone book or online directory; a television, internet, or radio program; the news media; or an internet site that is available to the general public on an unrestricted basis. (B) "Widely distributed media" does not include an obscene visual depiction, as defined in 18 U.S.C. § 1460.

Section 4193a establishes 18 defined terms used throughout the chatbot subchapter. Key definitions include the broadly scoped chatbot (any AI, algorithmic, or automated system generating information that simulates interpersonal interactions), chatbot provider (any person creating, distributing, or making available a chatbot), and affirmative consent (a rigorous opt-in standard that explicitly excludes blanket terms of use, inaction, and dark patterns). The definition of training carves out safety testing and compliance adjustments, creating a safe harbor for providers who process data solely for those purposes.

9 V.S.A. § 4193b
Data privacy and security
Deployer

(a)(1) 1 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) other than input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) to inform chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) outputs unless the processing of personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) is necessary to fulfill an express request made by a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) and that userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) has provided affirmative consentAffirmative consent"Affirmative consent" means a clear, affirmative act signifying a user's freely given, specific, informed, and unambiguous authorization for an act or practice in response to a specific request from a chatbot provider, provided: (i) the request is provided to the user in a clear and conspicuous standalone disclosure; (ii) the request includes a description, written in easy-to-understand language, of the act or practice for which the user's consent is sought; (iii) the request is made in a manner reasonably accessible to and usable by users with disabilities; (iv) the request is made available to the user in each language in which the chatbot provider provides a chatbot; (v) the option to refuse to give consent is at least as prominent as the option to give consent, and the option to refuse to give consent takes the same number of steps as or fewer than the option to give consent; and (vi) affirmative consent to an act or practice is not inferred from the inaction of the user or the user's continued use of a chatbot provided by the chatbot provider. "Affirmative consent" does not include: (i) acceptance of general or broad terms of use or a similar document; (ii) hovering over, muting, pausing, or closing a given piece of content; (iii) agreement obtained through the use of a false, fraudulent, or materially misleading statement or representation; or (iv) agreement obtained through the use of other dark patterns.9 V.S.A. § 4193a(2);

(a)(2) 2 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) to: (A) determine whether to display an advertisementAdvertisement"Advertisement" means any written or oral statement, illustration, or depiction that promotes the sale or use of a good or service or is designed to increase interest in a brand, good, or service where such statement, illustration, or depiction is displayed in exchange for monetary or other valuable consideration, including access to data between the chatbot provider and the brand, good, or service.9 V.S.A. § 4193a(1) for a product or service to the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17); (B) determine a product, service, or category of product or service to advertise to the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17); or (C) customize an advertisementAdvertisement"Advertisement" means any written or oral statement, illustration, or depiction that promotes the sale or use of a good or service or is designed to increase interest in a brand, good, or service where such statement, illustration, or depiction is displayed in exchange for monetary or other valuable consideration, including access to data between the chatbot provider and the brand, good, or service.9 V.S.A. § 4193a(1) or how an advertisementAdvertisement"Advertisement" means any written or oral statement, illustration, or depiction that promotes the sale or use of a good or service or is designed to increase interest in a brand, good, or service where such statement, illustration, or depiction is displayed in exchange for monetary or other valuable consideration, including access to data between the chatbot provider and the brand, good, or service.9 V.S.A. § 4193a(1) is presented to the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17);

(a)(3)(A)–(B) 3 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) or personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11): (A) if the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) knows or should have known, based on knowledge fairly implied on the basis of objective circumstances, that the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) is under 18 years of age without the affirmative consent of that userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s parent or legal guardian; (B) for trainingTraining"Training" means the use of input data to adjust or modify a model. "Training" does not include: (A) testing to identify risks of harm to users; (B) adjustments or modifications to address identified risks of harm to users; or (C) any actions necessary to comply with this subchapter or otherwise required by law.9 V.S.A. § 4193a(16) purposes, if the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) knows or should have known, based on knowledge fairly implied on the basis of objective circumstances, that a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) is under 18 years of age;

(a)(3)(C) 4 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) or personal data of a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) over 18 years of age for trainingTraining"Training" means the use of input data to adjust or modify a model. "Training" does not include: (A) testing to identify risks of harm to users; (B) adjustments or modifications to address identified risks of harm to users; or (C) any actions necessary to comply with this subchapter or otherwise required by law.9 V.S.A. § 4193a(16) purposes, unless the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) first obtains affirmative consentAffirmative consent"Affirmative consent" means a clear, affirmative act signifying a user's freely given, specific, informed, and unambiguous authorization for an act or practice in response to a specific request from a chatbot provider, provided: (i) the request is provided to the user in a clear and conspicuous standalone disclosure; (ii) the request includes a description, written in easy-to-understand language, of the act or practice for which the user's consent is sought; (iii) the request is made in a manner reasonably accessible to and usable by users with disabilities; (iv) the request is made available to the user in each language in which the chatbot provider provides a chatbot; (v) the option to refuse to give consent is at least as prominent as the option to give consent, and the option to refuse to give consent takes the same number of steps as or fewer than the option to give consent; and (vi) affirmative consent to an act or practice is not inferred from the inaction of the user or the user's continued use of a chatbot provided by the chatbot provider. "Affirmative consent" does not include: (i) acceptance of general or broad terms of use or a similar document; (ii) hovering over, muting, pausing, or closing a given piece of content; (iii) agreement obtained through the use of a false, fraudulent, or materially misleading statement or representation; or (iv) agreement obtained through the use of other dark patterns.9 V.S.A. § 4193a(2);

(a)(3)(D) 5 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) or personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) to engage in profilingProfiling"Profiling" means any form of processing performed on input data or personal data to detect and classify or designate personality and behavioral characteristics of an individual. "Profiling" does not include processing of chat logs for purposes of user safety or to otherwise comply with this subchapter.9 V.S.A. § 4193a(13) beyond what is necessary to fulfill an express request from the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17);

(a)(4) 5 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not use any classification or designation of a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s personality or behavioral characteristics created through profilingProfiling"Profiling" means any form of processing performed on input data or personal data to detect and classify or designate personality and behavioral characteristics of an individual. "Profiling" does not include processing of chat logs for purposes of user safety or to otherwise comply with this subchapter.9 V.S.A. § 4193a(13) beyond what is necessary to fulfill an express request made by the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17);

(a)(5) 6 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not sellSell"Sell" means exchanging personal data or input data for monetary or other valuable consideration or making available such data or use of such data by the chatbot provider to a third party. "Sell" does not include: (i) the disclosure of personal data or input data to a third party that processes the data on behalf of the chatbot provider; (ii) with the user's affirmative consent, the disclosure of personal data or input data where the user affirmatively directs the chatbot provider to disclose the data or intentionally uses the chatbot provider to interact with a third party; or (iii) the disclosure of personal data that the user: (I) intentionally made available to the general public via a channel of mass media; and (II) did not restrict to a specific audience.9 V.S.A. § 4193a(15) a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3);

(a)(6) 7 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not retain a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) for longer than 10 years, unless retention is necessary to comply with this subchapter or otherwise required by law;

(a)(7) 8 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not discriminate or retaliate against any userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17), including by denying products or services, charging different prices or rates for products or services, or providing lower-quality products or services to the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17), for refusing to consent to the use of chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) or personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) for trainingTraining"Training" means the use of input data to adjust or modify a model. "Training" does not include: (A) testing to identify risks of harm to users; (B) adjustments or modifications to address identified risks of harm to users; or (C) any actions necessary to comply with this subchapter or otherwise required by law.9 V.S.A. § 4193a(16) purposes;

(a)(8) 9 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not represent to a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) that the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) or chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) is confidential.

(b) 10 A userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) has the right to access, in a portable and readily usable format and at any time, any of the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s own chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) that a chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) has retained. (1) Chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) must be made available to usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) in a downloadable and human- and machine-readable format. (2) A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not discriminate or retaliate against any userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17), including by denying products or services, charging different prices or rates for products or services, or providing lower-quality products or services to the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17), for accessing their own chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3).

(c) A public agency, as that term is defined in 1 V.S.A. § 317, shall not compel the production of or access to input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) or chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) from a chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) without a duly issued wiretap warrant pursuant to 13 V.S.A. chapter 232 (Vermont Electronic Communication Privacy Act).

(d) 11 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall develop, implement, and maintain a comprehensive data security program that contains administrative, technical, and physical safeguards that are proportionate to the volume and nature of the personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) and chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) maintained by the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5). The program shall be written and made publicly available on the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5)'s website.

Section 4193b is the bill's data governance core. Subsection (a) imposes eight enumerated prohibitions on chatbot providers, covering personal data processing restrictions, a ban on chat-log-based targeted advertising, minor-specific protections requiring parental consent, an affirmative-consent requirement for adult training-data use, profiling limits, a chat-log sale prohibition, a 10-year retention cap, an anti-retaliation rule, and a ban on representing user data as confidential.

Subsection (b) creates a user right of access to retained chat logs in portable, downloadable, human- and machine-readable format, with an accompanying anti-retaliation clause. Subsection (c) restricts government compulsion of chat-log production to wiretap warrants. Subsection (d) requires a written, publicly available comprehensive data security program.

Compliance actions 11 items
1
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) other than input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) to inform chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) outputs unless the processing is necessary to fulfill an express userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) request and the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) has provided affirmative consentAffirmative consent"Affirmative consent" means a clear, affirmative act signifying a user's freely given, specific, informed, and unambiguous authorization for an act or practice in response to a specific request from a chatbot provider, provided: (i) the request is provided to the user in a clear and conspicuous standalone disclosure; (ii) the request includes a description, written in easy-to-understand language, of the act or practice for which the user's consent is sought; (iii) the request is made in a manner reasonably accessible to and usable by users with disabilities; (iv) the request is made available to the user in each language in which the chatbot provider provides a chatbot; (v) the option to refuse to give consent is at least as prominent as the option to give consent, and the option to refuse to give consent takes the same number of steps as or fewer than the option to give consent; and (vi) affirmative consent to an act or practice is not inferred from the inaction of the user or the user's continued use of a chatbot provided by the chatbot provider. "Affirmative consent" does not include: (i) acceptance of general or broad terms of use or a similar document; (ii) hovering over, muting, pausing, or closing a given piece of content; (iii) agreement obtained through the use of a false, fraudulent, or materially misleading statement or representation; or (iv) agreement obtained through the use of other dark patterns.9 V.S.A. § 4193a(2).
D-01.4
2
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) to determine whether to display an advertisementAdvertisement"Advertisement" means any written or oral statement, illustration, or depiction that promotes the sale or use of a good or service or is designed to increase interest in a brand, good, or service where such statement, illustration, or depiction is displayed in exchange for monetary or other valuable consideration, including access to data between the chatbot provider and the brand, good, or service.9 V.S.A. § 4193a(1), to select a product or service to advertise, or to customize an advertisementAdvertisement"Advertisement" means any written or oral statement, illustration, or depiction that promotes the sale or use of a good or service or is designed to increase interest in a brand, good, or service where such statement, illustration, or depiction is displayed in exchange for monetary or other valuable consideration, including access to data between the chatbot provider and the brand, good, or service.9 V.S.A. § 4193a(1) or its presentation to the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17).
D-01.10
3
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) a known or reasonably known minor userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) or personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) without the affirmative consent of that userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s parent or legal guardian. Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) a known or reasonably known minor userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) or personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) for trainingTraining"Training" means the use of input data to adjust or modify a model. "Training" does not include: (A) testing to identify risks of harm to users; (B) adjustments or modifications to address identified risks of harm to users; or (C) any actions necessary to comply with this subchapter or otherwise required by law.9 V.S.A. § 4193a(16) purposes under any circumstances — parental consent does not override this prohibition.
D-01.4
4
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) an adult userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) or personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) for trainingTraining"Training" means the use of input data to adjust or modify a model. "Training" does not include: (A) testing to identify risks of harm to users; (B) adjustments or modifications to address identified risks of harm to users; or (C) any actions necessary to comply with this subchapter or otherwise required by law.9 V.S.A. § 4193a(16) purposes unless the provider first obtains the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s affirmative consentAffirmative consent"Affirmative consent" means a clear, affirmative act signifying a user's freely given, specific, informed, and unambiguous authorization for an act or practice in response to a specific request from a chatbot provider, provided: (i) the request is provided to the user in a clear and conspicuous standalone disclosure; (ii) the request includes a description, written in easy-to-understand language, of the act or practice for which the user's consent is sought; (iii) the request is made in a manner reasonably accessible to and usable by users with disabilities; (iv) the request is made available to the user in each language in which the chatbot provider provides a chatbot; (v) the option to refuse to give consent is at least as prominent as the option to give consent, and the option to refuse to give consent takes the same number of steps as or fewer than the option to give consent; and (vi) affirmative consent to an act or practice is not inferred from the inaction of the user or the user's continued use of a chatbot provided by the chatbot provider. "Affirmative consent" does not include: (i) acceptance of general or broad terms of use or a similar document; (ii) hovering over, muting, pausing, or closing a given piece of content; (iii) agreement obtained through the use of a false, fraudulent, or materially misleading statement or representation; or (iv) agreement obtained through the use of other dark patterns.9 V.S.A. § 4193a(2).
D-01.4
5
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not processProcess"Process" or "processing" means any operation or set of operations performed, whether by manual or automated means, on personal data or input data or on sets of personal data or input data, such as the use, storage, disclosure, analysis, deletion, or modification of such data.9 V.S.A. § 4193a(12) a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) or personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) for profilingProfiling"Profiling" means any form of processing performed on input data or personal data to detect and classify or designate personality and behavioral characteristics of an individual. "Profiling" does not include processing of chat logs for purposes of user safety or to otherwise comply with this subchapter.9 V.S.A. § 4193a(13), nor use any personality or behavioral classification derived from profilingProfiling"Profiling" means any form of processing performed on input data or personal data to detect and classify or designate personality and behavioral characteristics of an individual. "Profiling" does not include processing of chat logs for purposes of user safety or to otherwise comply with this subchapter.9 V.S.A. § 4193a(13), beyond what is necessary to fulfill an express userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) request.
D-01.4
6
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not sellSell"Sell" means exchanging personal data or input data for monetary or other valuable consideration or making available such data or use of such data by the chatbot provider to a third party. "Sell" does not include: (i) the disclosure of personal data or input data to a third party that processes the data on behalf of the chatbot provider; (ii) with the user's affirmative consent, the disclosure of personal data or input data where the user affirmatively directs the chatbot provider to disclose the data or intentionally uses the chatbot provider to interact with a third party; or (iii) the disclosure of personal data that the user: (I) intentionally made available to the general public via a channel of mass media; and (II) did not restrict to a specific audience.9 V.S.A. § 4193a(15) a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3).
D-01.10
7
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not retain a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) for longer than 10 years, unless retention is necessary to comply with this subchapter or otherwise required by law.
D-01.9
8
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not discriminate or retaliate against any userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) — including by denying products or services, charging different prices, or providing lower-quality services — for refusing to consent to the use of chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) or personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) for trainingTraining"Training" means the use of input data to adjust or modify a model. "Training" does not include: (A) testing to identify risks of harm to users; (B) adjustments or modifications to address identified risks of harm to users; or (C) any actions necessary to comply with this subchapter or otherwise required by law.9 V.S.A. § 4193a(16) purposes.
D-01.3
9
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not represent to a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) that the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s input dataInput data"Input data" means information, including text, photos, audio, video, or files, provided to a chatbot by a user.9 V.S.A. § 4193a(9) or chat logChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) is confidential.
CP-01.5
10
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must provide usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) with access to any of their own retained chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) at any time, in a portable, downloadable, human- and machine-readable format. Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not discriminate or retaliate against any userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) for exercising this access right.
D-01.1
11
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must develop, implement, and maintain a comprehensive written data security program containing administrative, technical, and physical safeguards proportionate to the volume and nature of the personal dataPersonal data"Personal data" means any information, including derived data, inferences, or unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include deidentified data or publicly available information.9 V.S.A. § 4193a(11) and chat logsChat log"Chat log" means any input data, outputs generated by a chatbot, or record of the input data or outputs from user interactions with a chatbot.9 V.S.A. § 4193a(3) maintained. The program must be made publicly available on the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5)'s website.
G-01.1
9 V.S.A. § 4193c
Transparency
Deployer

(a)(1)–(2) 12 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall not use any term, letter, or phrase in the advertising, interface, or outputs of a chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) that indicates or implies that any output data is being provided by or endorsed by or is equivalent to that provided by: (A) a licensed health care professional; (B) a licensed legal professional; (C) a licensed accounting professional; (D) a certified financial fiduciary or planner; or (E) any licensed or certified professional regulated by the Office of Professional Regulation. (2) A violation of subdivision (1) of this subsection is an unfair and deceptive and act in commerce, subject to enforcement and penalties as provided in this subchapter.

(b) 13 Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall provide clear, conspicuous, and explicit notice to usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) that usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) are interacting with a chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) rather than a human prior to the chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) generating any outputs, every hour thereafter, and each time a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) prompts the chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) about whether it is a real person subject to the following: (1) The text of this notice must appear in the same language as the one in which the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) is interacting with the chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4), in a font size easily readable by an average userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17), and no smaller than the largest font size of other text appearing on the interface on which the chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) is provided. (2) This notice must be accessible to usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) with disabilities. (3) This notice must comply with rules adopted by the Attorney General pursuant to this subchapter.

(c) 14 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall on a monthly basis, according to metrics as set forth in rules adopted by the Attorney General pursuant to this subchapter, assess its chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) for risks of harm to usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) and actively mitigate any risks of harm.

(d) 15 A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall make information about its chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) publicly available on its website on a monthly basis as set forth in rules adopted by the Attorney General pursuant to this subchapter.

Section 4193c imposes four transparency obligations. Subsection (a) prohibits chatbot providers from using terms or phrases that indicate or imply chatbot output is provided by, endorsed by, or equivalent to that provided by a licensed professional — covering health care, legal, accounting, financial, and all professionals regulated by Vermont's Office of Professional Regulation. A violation constitutes an unfair and deceptive act in commerce.

Subsection (b) requires AI identity disclosure before any output, with hourly re-disclosure and on-demand disclosure when a user asks if the chatbot is a real person. The notice must be multilingual, accessible, and in a font at least as large as the largest text on the interface. Subsection (c) mandates monthly risk assessments using Attorney General-prescribed metrics. Subsection (d) requires monthly public posting of chatbot information as prescribed by AG rules.

Compliance actions 4 items
12
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must not use any term, letter, or phrase in the advertising, interface, or outputs of a chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) that indicates or implies that output data is being provided by, endorsed by, or equivalent to that provided by a licensed health care professional, licensed legal professional, licensed accounting professional, certified financial fiduciary or planner, or any licensed or certified professional regulated by the Office of Professional Regulation. A violation constitutes an unfair and deceptive act in commerce.
CP-01.9
13
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must provide clear, conspicuous, and explicit notice to usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) that usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) are interacting with a chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) rather than a human (1) prior to the chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) generating any outputs, (2) every hour thereafter, and (3) each time a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) prompts the chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) about whether it is a real person. The notice must appear in the same language as the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17)'s interaction, in a font size easily readable by an average userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) and no smaller than the largest font size of other text on the interface, must be accessible to usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) with disabilities, and must comply with rules adopted by the Attorney General.
T-01.1
14
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must, on a monthly basis, assess their chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) for risks of harm to usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) using metrics prescribed by Attorney General rules, and must actively mitigate any identified risks of harm.
S-01.4
15
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must make information about their chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) publicly available on their website on a monthly basis, covering categories of information as prescribed by Attorney General rules.
G-02.1
9 V.S.A. § 4193d
Rulemaking

(a)–(b) The Attorney General shall adopt rules: (1) describing the form and content of the disclosures and providing an example template for the disclosures required pursuant to subsection 4193c(b) of this subchapter; (2) describing risks of harm to usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) and the metrics that each chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) shall use to assess its chatbotsChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) for these risks of harm to usersUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) pursuant to subsection 4193c(c) of this subchapter; and (3) identifying and describing categories of information that each chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) must make publicly available about its chatbotsChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) pursuant to subsection 4193c(d) of this subchapter. (b) The Attorney General may adopt other rules as necessary to implement the provisions of this subchapter.

Section 4193d delegates rulemaking authority to the Attorney General to implement three mandatory areas: disclosure form and content (including a template), risk assessment metrics, and categories of public chatbot information. The AG also has general supplementary rulemaking authority. This section creates no independent compliance obligation on chatbot providers but will shape the content of obligations under § 4193c(b)–(d).

9 V.S.A. § 4193e
Liability
Deployer

(a)–(c) 16 A chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) is a product for the purposes of product liability actions. (b) A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) has a duty to ensure that the use of its chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) does not cause injury to a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17). (c) A chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) is liable for any injury it caused a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) through the use of its chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4), even if: (1) the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) exercised all reasonable care in the design and distribution of the chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4); or (2) the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) did not directly distribute the chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) to the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) or otherwise enter into a contractual relationship with the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17).

(d) Nothing in this subchapter preempts or otherwise affects any right, claim, remedy, presumption, or defense available at law or in equity, including antidiscrimination, consumer protection, labor, and civil rights laws.

Section 4193e establishes a strict product liability regime for chatbots. Subsection (a) classifies chatbots as products for product liability purposes — a significant legal designation that brings chatbots within existing Vermont products liability law. Subsection (b) establishes an affirmative duty of safety. Subsection (c) imposes strict liability: providers are liable for user injuries even if they exercised all reasonable care or did not directly distribute the chatbot to the user. Subsection (d) is a savings clause preserving existing legal rights and remedies.

Compliance actions 1 item
16
Chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) have a duty to ensure that the use of their chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) does not cause injury to a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17). ChatbotsChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4) are classified as products for product liability purposes, and chatbot providersChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) are strictly liable for any injury caused to a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) through use of the chatbotChatbot"Chatbot" means any artificial intelligence, algorithmic, or automated system that generates information via text, audio, image, or video in a manner that simulates interpersonal interactions or conversation.9 V.S.A. § 4193a(4), regardless of whether the provider exercised all reasonable care or had a direct contractual relationship with the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17).
9 V.S.A. § 4193f
Enforcement and penalty

(a)–(c) The Attorney General or a State's Attorney may bring a civil action against a chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5) that violates this subchapter to: (1) enjoin an act or practice that is in violation; (2) enforce compliance with this subchapter or a rule adopted pursuant to this subchapter; (3) obtain damages, civil penalties, restitution, or other remedies on behalf of the residents of the State; and (4) obtain reasonable attorney's fees and other litigation costs reasonably incurred. (b) A violation of section 4193b of this subchapter or subsection 4193c(a) or 4193c(b) of this subchapter constitutes an injury in fact to a userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17). (c) A userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) injured pursuant to subsection (b) of this section may bring an action in Superior Court against the chatbot providerChatbot provider"Chatbot provider" means any person creating, distributing, or otherwise making available a chatbot.9 V.S.A. § 4193a(5), in which the court may issue an award to the userUser"User" means any individual, regardless of age.9 V.S.A. § 4193a(17) for: (1) liquidated damages of: (A) $5,000.00 per violation for any violation of section 4193b of this subchapter, or actual damages, whichever is greater; and (B) $5,000.00 in total for all violations of subsection 4193c(a) or 4193c(b) of this subchapter, or actual damages, whichever is greater; (2) punitive damages, for reckless and knowing violations; (3) injunctive relief; (4) declaratory relief; and (5) reasonable attorney's fees and litigation costs.

Section 4193f establishes a dual enforcement framework. Subsection (a) empowers the Attorney General or a State's Attorney to bring civil actions for injunctive relief, compliance enforcement, damages, civil penalties, restitution, and attorney's fees. Subsection (b) creates a statutory injury-in-fact for users affected by data privacy violations (§ 4193b) or transparency violations (§ 4193c(a)–(b)), eliminating standing barriers. Subsection (c) creates a private right of action with two tiers of liquidated damages: $5,000 per violation for data privacy violations or $5,000 total for all transparency violations, plus punitive damages for reckless and knowing violations, injunctive and declaratory relief, and attorney's fees.

Sec. 2
Effective date

This act shall take effect on July 1, 2026.

Section 2 establishes July 1, 2026 as the effective date for the entire act.

Passage Likelihood

Medium
Status Introduced
Chamber No passage
Committee No action
Majority party Yes
Bipartisan Yes
Prior session None

Legislative History

2026-01-27 Read first time and referred to the Committee on Commerce and Economic Development

Entry Last Reviewed

2026-05-20
AI generated