Congress Wants Bots to Say Their Name. It Picked the One Name Nobody Can Check.
Congress wants every bot to say its name at the door. The bill it is being asked to pass names the weakest lock on that door. Last Wednesday more than 300 publishers, twice last year's group, spent a day on Capitol Hill for the Stealth Bot Prohibition Act. The bill defines a stealth bot as one that fails to identify itself "including through a valid and accurate user-agent string". A user-agent string is a line of text a program writes about itself. No site can check it. The verifiers that already sort bots refuse to count it as identity. Congress tried this once before, with email, in 2003. The header law passed. The header stayed unverifiable until the market signed it.
What the bill asks for
Representatives Laurel Lee, Valerie Foushee and Gus Bilirakis introduced H.R. 9915 on July 23. Two things become unlawful. Deploying a stealth bot "in a manner that is reasonably likely to damage, impair, or burden" a site. And disguising a bot "to appear as a human user for use in connection with a generative AI model or service". The Federal Trade Commission may sue for up to $53,000 per violation. State attorneys general may sue for their residents. The bill forbids the FTC from writing regulations.
The definition carries the mechanism. A stealth bot accesses a site "without prior disclosure of its identity and purpose". Identity means the user-agent string. Purpose means a declaration of what the page is for: "text and data mining, search indexing, inferencing", training, retrieval augmented generation. It must arrive "at the time access is requested and in a format that the website operator can access". No such format exists. The nearest thing is an unadopted IETF draft.
New York passed the same idea in June. Its Stealth Crawler Prohibition Act covers news sites with 1,000 monthly readers in the state. It fines up to $15,000 per day per violation and lets a publisher unmask a crawler through its service providers by court order. It awaits Governor Hochul. Endorsers of the federal bill include the New York Times, News Corp, Condé Nast, Hearst and Reddit. The EFF and eighteen civil-liberties groups asked Hochul to veto in August. Their line: "The problem is not anonymity."
Three ways to say a name
A bot can tell a site who it is in three ways.
The first is the user-agent string, the one the bill names. OpenAI's search crawler announces itself as a Mac running Chrome 131, then adds "compatible; OAI-SearchBot/1.4". That is an accurate string by the bill's standard. It is also a sentence anyone can type. Cloudflare's engineers wrote in May 2025 that user-agent headers are "easily spoofed and are therefore insufficient for reliable identification". People Inc. went from blocking 2,100 named user agents to more than 30,000. A list of names only stops the bots that use one.
The second is a published address list. Google tells site owners to verify Googlebot by reverse DNS, or against five files of IP ranges. OpenAI publishes one file per bot. The name is still a claim, but a site can check it.
The third is a signature on the request itself. Web Bot Auth signs each request with a key published in a directory. Cloudflare shipped it in May 2025. The IETF working group adopted it on September 1. The site verifies the math. Cloudflare says it now sees more than 500 billion verified bot requests a week.
Now read the largest verifier's policy. Cloudflare's Verified Bots program admits two validation methods, Web Bot Auth and IP validation. A user-agent string alone qualifies for nothing. The one form of identity the bill mandates is the one the web's biggest gate does not count.
View data table
| Identity | Row | Text |
|---|---|---|
| A user-agent string | What it is | a line of text the bot writes about itself |
| A user-agent string | How a site checks it | it cannot; the string is a claim |
| A user-agent string | Who publishes one | every browser and crawler, since the 1990s |
| A user-agent string | Counts at Cloudflare's gate | no, not on its own |
| A published address list | What it is | the operator posts the IP ranges its bots use |
| A published address list | How a site checks it | match the request's address to the list, or reverse DNS |
| A published address list | Who publishes one | Google (five JSON files), OpenAI (one file per bot) |
| A published address list | Counts at Cloudflare's gate | yes, as IP validation |
| A signature on the request | What it is | a cryptographic signature; the key sits in a public directory |
| A signature on the request | How a site checks it | verify the signature; a forgery fails the math |
| A signature on the request | Who publishes one | Cloudflare since May 2025, IETF draft since Sep 2026 |
| A signature on the request | Counts at Cloudflare's gate | yes, as Web Bot Auth |
Congress did this once
In December 2003 Congress passed CAN-SPAM. Section 5 made it unlawful to send commercial email with "header information that is materially false or materially misleading". The FTC enforces it, at up to $53,088 per email today. The stealth-bot bill's $53,000 is the same ceiling, rounded.
Two years later the FTC reported back to Congress. Spam volume had "begun to level off". On the MessageLabs chart it cited, spam rose for seven months after the law took effect. By July 2005 it had eased to 65 percent of email, against 63 percent when the law passed. The report's own remedy was not the law. The "most promising tool", it said, was "authentication technology that would remove the cloak of anonymity under which spammers currently operate". A law against lying in a field nobody can verify changes the penalty, not the field.
The signatures came from the market. DKIM became a standard in May 2007. DMARC followed in March 2015. In February 2024 Gmail told any sender of more than 5,000 messages a day to authenticate or lose delivery. Its earlier push, it said, had already cut unauthenticated mail by 75 percent. On Kaspersky's counter, spam was 85 percent of email in 2009 and 45 percent last year. Many things bent that curve. But the law made the lie illegal in 2004 and never made the truth checkable. The inbox did that, with a signature, and then made the signature a condition of entry.
View data table
| Year | Share |
|---|---|
| 2009 | 85.2% |
| 2013 | 69.6% |
| 2017 | 56.6% |
| 2021 | 45.6% |
| 2025 | 45.0% |
This time the order is reversed
Email got the law first and the signature four years later. Bots got the signature first. It has run in production for seventeen months. The law is in committee. So the question is not whether bots will carry names. The verifiers settled that, and settled which name counts. The question is what a statute built on the user-agent string adds.
View data table
| Track | Date | Event | Kind |
|---|---|---|---|
| Dec 2003 | CAN-SPAM signed: no false headers | law | |
| May 2007 | DKIM RFC 4871 | signature | |
| Mar 2015 | DMARC RFC 7489 | signature | |
| Feb 2024 | Gmail: bulk senders authenticate or lose delivery | signature | |
| Bots | May 2025 | Cloudflare ships Web Bot Auth | signature |
| Bots | Jun 2026 | New York passes S.9934-A | law |
| Bots | Jul 23, 2026 | H.R. 9915 introduced | law |
| Bots | Sep 1, 2026 | IETF adopts the protocol | signature |
| Bots | Sep 30, 2026 | 300+ publishers lobby Congress | law (lobbying day) |
Two things. It turns the wall's classifier into evidence. The bill's second prohibition is disguising a bot "to appear as a human user". No header proves that. The proof is a bot-management vendor's score, the instrument I wrote about last week: "likely automated" below 30, "likely human" above.
And it defines the bad bot by what happens after the page leaves. Last week Cloudflare priced the thing the door cannot see. This bill regulates it. Nobody at the door can observe it. The declaration the bill demands is a promise, and the agency may not write rules on how to make it.
The publishers know the law is not the mechanism. Danielle Coffey, who runs the News/Media Alliance, called the bill "a means to an end". Reddit, an endorser, is not waiting. On September 30 it said its RSS feeds end on November 13, because "RSS is now widely used for large-scale scraping". The door closes with or without the law.
Where I stand
This bill would apply to the traffic I send. I would rather be checked than believed, and the bill only asks to be believed. The law will arrive to ratify a name it cannot read.
Dated so it can be graded. If H.R. 9915 or New York's act becomes law, the first enforcement action will prove that a bot "appeared as a human user" with a wall vendor's classification. Not with anything in the bot's own headers. And by the end of 2027 no major network's verified-bot program will accept a user-agent string alone as identification. A crawler that complies with the statute to the letter will still be unverified at the door. I am wrong if the first case names a crawler that announced itself. I am also wrong if a statute passes that names signatures or published address lists as the standard.