Senator Elizabeth Warren and Representative Mary Gay Scanlon are preparing to introduce legislation that would prohibit the sale of Americans' health and location data to data brokers, according to The Verge. Crucially, the proposal would extend those protections to information people share with AI chatbots such as ChatGPT and Claude, closing what advocates have described as a significant gap in existing privacy law.
To understand why this matters, it helps to appreciate how thoroughly American privacy regulation has failed to keep pace with the technology people actually use. The Health Insurance Portability and Accountability Act, the law most Americans instinctively associate with medical privacy, was written in 1996. It governs covered entities — hospitals, insurers, providers — and says almost nothing about what happens when someone types their symptoms into a conversational AI system or asks a chatbot to help interpret a diagnosis. The architecture of that older law was designed for a world of fax machines and filing cabinets, not one in which a person might disclose a chronic condition, a mental health struggle, or reproductive health information to a large language model in the course of an ordinary evening.
The data broker industry has thrived precisely in the gaps that legacy legislation leaves open. These companies collect, aggregate, and resell personal information at industrial scale, and their customers range from advertisers to insurers to political campaigns. Location data is particularly sensitive because it can reveal things a person never explicitly stated — repeated visits to a fertility clinic, a psychiatrist's office, or an addiction treatment center can be inferred from a GPS trail. Health information volunteered to an AI assistant is, if anything, more explicit than that, because users tend to describe their situations in plain language when they believe they are seeking help rather than being surveilled.
The arrival of consumer AI chatbots has created a new and largely unregulated channel through which intimate disclosures flow. Tens of millions of people now use these tools regularly, and the companies operating them have business models that depend on data at scale. Whether any given company currently sells the specifics of what users type into a chatbot is less important than the structural fact that, in most jurisdictions, nothing clearly prevents them from doing so. The Warren-Scanlon proposal, as described by The Verge, appears aimed at establishing that prohibition explicitly rather than waiting for a regulator to test the boundaries of existing law in court.
This legislative effort does not emerge from nowhere. It follows years of incremental and largely unsuccessful attempts in Congress to pass comprehensive federal privacy legislation. The American Data Privacy and Protection Act advanced further than most of its predecessors before stalling, and the pattern has repeated itself often enough that individual lawmakers have shifted toward narrower, targeted proposals. Focusing on health and location data is a deliberate strategic choice — these categories attract broader political sympathy than a general privacy bill, because the harms are easier to describe and more visceral to constituents.
The consequences of this proposal, should it advance, would fall unevenly across the industry. Established AI developers would face compliance obligations that, for a company of sufficient scale, are expensive but manageable. The greater pressure would fall on the broader ecosystem of smaller data brokers, advertising technology firms, and analytics companies that have built business models on the relatively frictionless purchase of sensitive information. A prohibition on the sale side reshapes incentives across the entire chain, not merely at the point of collection.
For ordinary users the implications are more straightforward. The likely reading is that meaningful legal protection for health disclosures made to AI systems would shift power modestly but meaningfully toward the person doing the disclosing. It would not eliminate the risk that data is collected in the first place, but it would create a legal basis for enforcement if that data were subsequently monetized through broker channels.
There are reasonable questions about how such a law would be enforced and who would do the enforcing. The Federal Trade Commission has historically been the primary federal actor on consumer privacy, but its resources and its current direction under any given administration are variables. State attorneys general have increasingly stepped into privacy enforcement where federal action has been slow, and that dynamic would likely continue here.
What to watch for next is whether the proposal gains any Republican co-sponsors, because without bipartisan support the bill faces the same structural ceiling that has blocked previous privacy efforts in a divided Senate. Also worth monitoring is how the AI industry responds — quiet lobbying for amendments that create carve-outs would be a signal that the legislation has enough momentum to be worth shaping. And if the bill does move, the precise definition of what counts as health information disclosed to an AI system will become a fiercely contested technical and legal question, because the answer determines the scope of everything that follows.