ITIF warns AI regulation risks repeating social media mistakes with broad rules and privacy concerns

A new report from the Information Technology and Innovation Foundation highlights the dangers of hastily regulated AI chatbots, calling for targeted and precise policies that distinguish between different AI products and prioritise user privacy.

A new Information Technology and Innovation Foundation report argues that the current rush to regulate AI chatbots is repeating the mistakes made with social media: broad age-verification rules that collect more personal data than necessary, while doing too little to address the harms they are meant to prevent. The report says state legislatures have moved quickly in response to child safety concerns, but in doing so have created a patchwork of rules that treat very different AI products as if they were the same.

ITIF, in its June and November policy papers on AI companions, has consistently warned that laws aimed at emotionally manipulative systems are often written so broadly that they also catch general-purpose assistants such as ChatGPT, Gemini and Claude. That matters because the risks are not identical. The most serious cases involve companion chatbots designed to simulate intimate relationships, not general tools used for homework, research or routine advice. The report says that distinction should be built into law, rather than ignored.

The central privacy concern is age verification. If a chatbot must confirm that a user is an adult, it generally has to collect identity documents, biometric images or other personal signals that it would not otherwise need. ITIF says that creates a permanent privacy burden for adults and shifts sensitive data to outside verification vendors. The foundation has also argued in earlier work that age assurance can be made less intrusive, but only if policymakers avoid building every safety rule around identity collection.

Instead, ITIF recommends a device-level “child flag” managed by operating systems. In that model, parents would set a minor status once on a device and apps would receive only an age-range signal, not the child’s name, birth date or ID. The report points to California’s Digital Age Assurance Act as an example of a signal-based architecture already moving into law, and says that approach is preferable to forcing every individual chatbot to build its own verification system.

The report also says the debate should not focus only on restriction. It notes that many children and young adults use chatbots for support, including mental health guidance, at a time when human services are often inaccessible. ITIF cites the shortage of mental health professionals in rural America and recent survey data showing that many young adults already turn to AI for advice. In that context, the report argues, laws that are too blunt could cut off useful support while failing to stop the most dangerous products.

Still, the foundation does not argue for leaving chatbots unregulated. It supports targeted crisis-response requirements, clearer parental controls and disclosure rules for paid or sponsored content. It also backs laws that identify self-harm and refer users to help. But it warns against measures such as blanket bans on minors, mandatory chat log access for parents in all cases and vague conduct rules that developers cannot reliably interpret. Its view is that child protection is strongest when regulation is narrow, technically precise and designed around how AI systems actually work.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.