H.R. 9915, the Stealth Bot Prohibition Act, is a pending US House bill that would let the Federal Trade Commission fine anyone who deploys a bot that hides who it is, up to $53,000 per violation. It has not passed. It is still in committee. But its definition of a “stealth bot” is the clearest legal description yet of what an honest agent should send, and merchants who want agent traffic should read it.
What the bill says
The bill was introduced on July 23, 2026 by Rep. Laurel Lee (R-FL) with Reps. Valerie Foushee and Gus Bilirakis, and referred to the House Committee on Energy and Commerce. The introduced text on govinfo.gov defines a stealth bot as a bot that accesses a site “without prior disclosure of its identity and purpose”, in particular by:
- failing to identify itself, including through a valid and accurate user-agent string; or
- failing to disclose its specific nature and purpose, including intended use of page content (text and data mining, search indexing, inferencing, training, fine tuning, retrieval augmented generation), at the time access is requested and in a format the site operator can access.
“Bot” is defined broadly: it includes crawlers, fetchers, clients, user agents and “AI agent[s]”.
What is actually prohibited
Being a stealth bot is not, by itself, the offence. Section 2(a) bans two specific things:
- Deploying a stealth bot to access a site in a manner “reasonably likely to damage, impair, or burden the technical or commercial operation” of that site.
- Intentionally misrepresenting, concealing or obscuring the nature of a bot to appear as a human user, in connection with a generative AI model or service.
Enforcement and timing
- The FTC may sue in federal court for civil penalties or an injunction. The cap is $53,000 per violation, adjusted each January 1 for inflation.
- State attorneys general may bring civil actions on behalf of residents, with notice to the FTC.
- The bill does not authorize the FTC to issue regulations.
- Actions must be brought within six years of the violation.
- The rules would take effect 180 days after enactment.
What it means for a store
Nothing changes for your site today. If the bill passes in this form, the party exposed is the bot operator, not the merchant. Two practical points follow:
- Honest agents are easier to tell apart. A request that sends an accurate user-agent and a declared purpose is distinguishable from one that does not. Web Bot Auth is one existing way to make that identity verifiable, though the bill does not mention it.
- Blanket blocking gets costlier. If you block every unrecognised client, you also block the agents that identify themselves correctly. See robots.txt for AI agents for how to separate them.
What the bill does not say: it does not require merchants to do anything, and the text names no technical standard for disclosure beyond the user-agent string and “a format that the website operator can access”.
FAQ
Is the Stealth Bot Prohibition Act law?
No. H.R. 9915 was introduced on July 23, 2026 and referred to the House Energy and Commerce Committee. It would take effect 180 days after enactment, so nothing in it is enforceable today.
Does the bill apply to AI shopping agents?
Its definition of “bot” explicitly includes AI agents and user agents. An agent that discloses an accurate user-agent and its purpose is not a stealth bot under the text. Liability would attach to operators who hide their identity and either burden a site or pose as a human.
Does a store owner have to do anything under H.R. 9915?
No. The bill places duties on people who deploy bots and gives enforcement to the FTC and state attorneys general. It creates no compliance obligation for the site being accessed.
Sources
AgentReady audits the transaction, and a transaction starts with a client that says who it is: this bill is the first attempt to make that a legal expectation rather than a courtesy.