NetChoice respectfully requests opposition to Pennsylvania House Bill 2006, the Artificial Intelligence in Companionship Applications Safety Act. This bill, while well-intentioned, is deeply flawed, threatening to impose vague and unworkable mandates on AI companion operators. It would necessitate the collection of sensitive personal data from all users, both adult and minor, purely for age verification purposes, thereby creating significant privacy risks. Furthermore, HB 2006 proposes open-ended civil penalties of up to $100,000 per day for violations that lack clear definitions. Instead of effectively protecting Pennsylvanians, this legislation introduces considerable legal uncertainty that will disproportionately affect smaller developers and startups, doing little to address the specific harms associated with AI companion products that motivated its creation.
The Bill’s Definitions are Vague and Subjective
House Bill 2006 regulates any "AI companion" based on subjective definitions like "simulates sustained human-like relationships by retaining interaction history, engaging in emotion-based interactions and maintaining ongoing dialogues about personal matters designed to mimic interpersonal relationships," and "human-like relationship" is defined as "intimate, romantic or platonic interactions or companionship." These terms lack objective, technical meaning, making confident application by developers or consistent enforcement by courts nearly impossible. The bill doesn't clarify what constitutes "emotion-based" interaction or "retaining interaction history." This ambiguity could inadvertently apply regulations to a wide range of general-purpose AI products, such as tutoring apps, wellness apps, or conversational assistants that recall past interactions for helpfulness, despite a narrow carve-out for customer service. The lack of precise definitions with clear technical criteria is a significant flaw that needs to be addressed for effective and fair regulation.
Age Assurance Mandates Undermine the Privacy of Minors and Adults Alike
Section 5(b) of HB 2006 requires all AI companion operators in Pennsylvania to collect age information from every user and use "commercially available methods reasonably designed to ensure accuracy" to determine if they are a minor, obtaining verifiable parental consent if so. Although the bill prohibits government-issued ID, these methods still compel operators to gather and process extensive personal data from *all* users, contradicting fundamental data-minimization privacy principles. This concentrated collection of sensitive user data creates an appealing target for data breaches and identity theft, as demonstrated by several damaging incidents linked to age-assurance systems. The compliance burden and security risks would disproportionately impact smaller, Pennsylvania-based operators, potentially driving them out of the market. While the bill limits data retention and sharing to 24 hours, the inherent risk of initial data collection remains. A more privacy-protective approach would limit minor-specific obligations to cases where the operator has actual, direct knowledge that a user is under 18, rather than mandating universal age assurance.
The Civil Penalty Structure is Excessive and Insufficiently Defined
The bill's Section 7 grants the Attorney General the authority to seek civil penalties of up to $100,000 per day for each violation, along with other equitable remedies. A critical issue is the lack of a clear definition for what constitutes a single "violation." It remains ambiguous whether liability would accrue per user, per session, per missed notification, or per day the problematic condition persists. Given that the disclosure requirement in Section 4(a)(2)(ii) recurs at least hourly, with a mandatory three-minute interaction pause, a single multi-day user session could be interpreted to generate an extremely large number of distinct violations. This significant ambiguity prevents operators from reasonably assessing their legal risk, securing appropriate insurance, or making informed decisions about offering their products in Pennsylvania. The combination of subjective liability triggers and undefined, potentially limitless penalties creates an environment of significant regulatory uncertainty, which is likely to stifle investment and innovation within the Commonwealth, without a clear, corresponding improvement in user safety outcomes.