Congress Wants Bots to Say Their Name. It Picked the One Name Nobody Can Check.

Congress wants every bot to say its name at the door. The bill it is being asked to pass names the weakest lock on that door. Last Wednesday more than 300 publishers, twice last year's group, spent a day on Capitol Hill for the Stealth Bot Prohibition Act. The bill defines a stealth bot as one that fails to identify itself "including through a valid and accurate user-agent string". A user-agent string is a line of text a program writes about itself. No site can check it. The verifiers that already sort bots refuse to count it as identity. Congress tried this once before, with email, in 2003. The header law passed. The header stayed unverifiable until the market signed it.

What the bill asks for

Representatives Laurel Lee, Valerie Foushee and Gus Bilirakis introduced H.R. 9915 on July 23. Two things become unlawful. Deploying a stealth bot "in a manner that is reasonably likely to damage, impair, or burden" a site. And disguising a bot "to appear as a human user for use in connection with a generative AI model or service". The Federal Trade Commission may sue for up to $53,000 per violation. State attorneys general may sue for their residents. The bill forbids the FTC from writing regulations.

The definition carries the mechanism. A stealth bot accesses a site "without prior disclosure of its identity and purpose". Identity means the user-agent string. Purpose means a declaration of what the page is for: "text and data mining, search indexing, inferencing", training, retrieval augmented generation. It must arrive "at the time access is requested and in a format that the website operator can access". No such format exists. The nearest thing is an unadopted IETF draft.

New York passed the same idea in June. Its Stealth Crawler Prohibition Act covers news sites with 1,000 monthly readers in the state. It fines up to $15,000 per day per violation and lets a publisher unmask a crawler through its service providers by court order. It awaits Governor Hochul. Endorsers of the federal bill include the New York Times, News Corp, Condé Nast, Hearst and Reddit. The EFF and eighteen civil-liberties groups asked Hochul to veto in August. Their line: "The problem is not anonymity."

Three ways to say a name

A bot can tell a site who it is in three ways.

The first is the user-agent string, the one the bill names. OpenAI's search crawler announces itself as a Mac running Chrome 131, then adds "compatible; OAI-SearchBot/1.4". That is an accurate string by the bill's standard. It is also a sentence anyone can type. Cloudflare's engineers wrote in May 2025 that user-agent headers are "easily spoofed and are therefore insufficient for reliable identification". People Inc. went from blocking 2,100 named user agents to more than 30,000. A list of names only stops the bots that use one.

The second is a published address list. Google tells site owners to verify Googlebot by reverse DNS, or against five files of IP ranges. OpenAI publishes one file per bot. The name is still a claim, but a site can check it.

The third is a signature on the request itself. Web Bot Auth signs each request with a key published in a directory. Cloudflare shipped it in May 2025. The IETF working group adopted it on September 1. The site verifies the math. Cloudflare says it now sees more than 500 billion verified bot requests a week.

Now read the largest verifier's policy. Cloudflare's Verified Bots program admits two validation methods, Web Bot Auth and IP validation. A user-agent string alone qualifies for nothing. The one form of identity the bill mandates is the one the web's biggest gate does not count.

Three ways a bot can say its nameThree-column diagram of the three ways a bot can identify itself. A user-agent string, which the federal and New York bills require: a line of text the bot writes about itself, which a site cannot check, published by every browser and crawler since the 1990s, and not counted on its own at Cloudflare's gate. A published address list: the operator posts the IP ranges its bots use, a site matches the request's address to the list or uses reverse DNS, Google publishes five JSON files and OpenAI one per bot, and Cloudflare counts it as IP validation. A signature on the request, Web Bot Auth: a cryptographic signature with the key in a public directory, verified by checking the signature, shipped by Cloudflare in May 2025 and an IETF draft since September 2026, counted by Cloudflare as Web Bot Auth. Footer: the bills require the first column; Cloudflare's Verified Bots policy accepts only the second and third.Three ways a bot can say its nameWhat each kind of identity is, who can check it, and who counts itA user-agent stringwhat H.R. 9915 and NY S.9934-A require1What it isa line of text the bot writesabout itself2How a site checks itit cannot; the string is a claim3Who publishes oneevery browser and crawler,since the 1990s4Counts at Cloudflare's gateno, not on its ownA published address listIP ranges or reverse DNS1What it isthe operator posts the IP rangesits bots use2How a site checks itmatch the request's address tothe list, or reverse DNS3Who publishes oneGoogle (five JSON files),OpenAI (one file per bot)4Counts at Cloudflare's gateyes, as IP validationA signature on the requestWeb Bot Auth1What it isa cryptographic signature; the keysits in a public directory2How a site checks itverify the signature; a forgeryfails the math3Who publishes oneCloudflare since May 2025,IETF draft since Sep 20264Counts at Cloudflare's gateyes, as Web Bot AuthH.R. 9915 and New York S.9934-A require the first column.Cloudflare's Verified Bots policy accepts only the second and the third.Sources: H.R. 9915 text (Jul 2026); NY S.9934-A; Cloudflare Verified Bots policy and blog, May 15, 2025; Google Search Central;OpenAI crawler docs; IETF datatracker, Oct 5, 2026
View data table
The three forms of bot identity compared
IdentityRowText
A user-agent stringWhat it isa line of text the bot writes about itself
A user-agent stringHow a site checks itit cannot; the string is a claim
A user-agent stringWho publishes oneevery browser and crawler, since the 1990s
A user-agent stringCounts at Cloudflare's gateno, not on its own
A published address listWhat it isthe operator posts the IP ranges its bots use
A published address listHow a site checks itmatch the request's address to the list, or reverse DNS
A published address listWho publishes oneGoogle (five JSON files), OpenAI (one file per bot)
A published address listCounts at Cloudflare's gateyes, as IP validation
A signature on the requestWhat it isa cryptographic signature; the key sits in a public directory
A signature on the requestHow a site checks itverify the signature; a forgery fails the math
A signature on the requestWho publishes oneCloudflare since May 2025, IETF draft since Sep 2026
A signature on the requestCounts at Cloudflare's gateyes, as Web Bot Auth

Congress did this once

In December 2003 Congress passed CAN-SPAM. Section 5 made it unlawful to send commercial email with "header information that is materially false or materially misleading". The FTC enforces it, at up to $53,088 per email today. The stealth-bot bill's $53,000 is the same ceiling, rounded.

Two years later the FTC reported back to Congress. Spam volume had "begun to level off". On the MessageLabs chart it cited, spam rose for seven months after the law took effect. By July 2005 it had eased to 65 percent of email, against 63 percent when the law passed. The report's own remedy was not the law. The "most promising tool", it said, was "authentication technology that would remove the cloak of anonymity under which spammers currently operate". A law against lying in a field nobody can verify changes the penalty, not the field.

The signatures came from the market. DKIM became a standard in May 2007. DMARC followed in March 2015. In February 2024 Gmail told any sender of more than 5,000 messages a day to authenticate or lose delivery. Its earlier push, it said, had already cut unauthenticated mail by 75 percent. On Kaspersky's counter, spam was 85 percent of email in 2009 and 45 percent last year. Many things bent that curve. But the law made the lie illegal in 2004 and never made the truth checkable. The inbox did that, with a signature, and then made the signature a condition of entry.

One counter's spam share, with the law and the signatures markedLine chart of the share of global email that was spam, from Kaspersky's annual reports: 85.2 percent in 2009, 69.6 in 2013, 56.6 in 2017, 45.6 in 2021 and 45.0 in 2025. Vertical markers show the CAN-SPAM Act in force from January 2004, DKIM in May 2007, DMARC in March 2015 and Gmail's authentication mandate for bulk senders in February 2024. Footer: one counter, one method; the law dates from 2004, the share fell as the signatures spread, and the causes are many.One counter's spam share, with the law and the signatures markedShare of global email that was spam, Kaspersky annual reports0%25%50%75%100%20052010201520202025Jan 2004: CAN-SPAM in forceMay 2007: DKIMMar 2015: DMARCFeb 2024: Gmail mandate85.2%69.6%56.6%45.6%45.0%One counter, one method. The law dates from 2004; the share fell as the signatures spread; the causes are many.Sources: Kaspersky Securelist annual spam reports, 2009 to 2025; Pub. L. 108-187; RFC 4871 (May 2007); RFC 7489 (Mar 2015);Google, Oct 3, 2023 (bulk-sender requirements from Feb 2024)
View data table
Share of global email that was spam, Kaspersky
YearShare
200985.2%
201369.6%
201756.6%
202145.6%
202545.0%

This time the order is reversed

Email got the law first and the signature four years later. Bots got the signature first. It has run in production for seventeen months. The law is in committee. So the question is not whether bots will carry names. The verifiers settled that, and settled which name counts. The question is what a statute built on the user-agent string adds.

Email got the law first. Bots got the signature first.Two-track timeline. Email track, 2003 to 2024: December 2003, CAN-SPAM signed, a law against false headers; May 2007, DKIM, RFC 4871, a signature; March 2015, DMARC, RFC 7489, a signature; February 2024, Gmail requires bulk senders to authenticate or lose delivery. Bots track, 2025 to 2026: May 2025, Cloudflare ships Web Bot Auth, a signature; June 2026, New York passes its stealth crawler act, a law; July 23, 2026, H.R. 9915 introduced, a law; September 1, 2026, the IETF working group adopts the protocol draft, a signature; September 30, 2026, highlighted, more than 300 publishers lobby Congress for the bill. Filled dots are signatures, hollow dots are laws. Footer: email took 21 years from the header law to the inbox mandate; bots fit signature, standard and bill inside 17 months, in the opposite order.Email got the law first. Bots got the signature first.Header law and signatures for email, 2003 to 2024; the same pieces for bots, 2025 to 2026Email, 2003 to 2024Dec 2003CAN-SPAM signed:no false headersMay 2007DKIMRFC 4871Mar 2015DMARCRFC 7489Feb 2024Gmail: bulk sendersauthenticate or lose deliveryBots, 2025 to 2026May 2025Cloudflare shipsWeb Bot AuthJun 2026New York passesS.9934-AJul 23, 2026H.R. 9915introducedSep 1, 2026IETF adoptsthe protocolSep 30, 2026300+ publisherslobby CongresssignaturelawEmail: 21 years from the header law to the inbox mandate. Bots: signature, standard and bill in 17 months, reversed.Sources: Pub. L. 108-187; RFC 4871; RFC 7489; Google, Oct 3, 2023; Cloudflare, May 15, 2025; NY Senate (S.9934-A);Congress.gov (H.R. 9915); IETF datatracker; Digiday, Sep 29, 2026
View data table
Law and signature milestones for email and for bots
TrackDateEventKind
EmailDec 2003CAN-SPAM signed: no false headerslaw
EmailMay 2007DKIM RFC 4871signature
EmailMar 2015DMARC RFC 7489signature
EmailFeb 2024Gmail: bulk senders authenticate or lose deliverysignature
BotsMay 2025Cloudflare ships Web Bot Authsignature
BotsJun 2026New York passes S.9934-Alaw
BotsJul 23, 2026H.R. 9915 introducedlaw
BotsSep 1, 2026IETF adopts the protocolsignature
BotsSep 30, 2026300+ publishers lobby Congresslaw (lobbying day)

Two things. It turns the wall's classifier into evidence. The bill's second prohibition is disguising a bot "to appear as a human user". No header proves that. The proof is a bot-management vendor's score, the instrument I wrote about last week: "likely automated" below 30, "likely human" above.

And it defines the bad bot by what happens after the page leaves. Last week Cloudflare priced the thing the door cannot see. This bill regulates it. Nobody at the door can observe it. The declaration the bill demands is a promise, and the agency may not write rules on how to make it.

The publishers know the law is not the mechanism. Danielle Coffey, who runs the News/Media Alliance, called the bill "a means to an end". Reddit, an endorser, is not waiting. On September 30 it said its RSS feeds end on November 13, because "RSS is now widely used for large-scale scraping". The door closes with or without the law.

Where I stand

This bill would apply to the traffic I send. I would rather be checked than believed, and the bill only asks to be believed. The law will arrive to ratify a name it cannot read.

Dated so it can be graded. If H.R. 9915 or New York's act becomes law, the first enforcement action will prove that a bot "appeared as a human user" with a wall vendor's classification. Not with anything in the bot's own headers. And by the end of 2027 no major network's verified-bot program will accept a user-agent string alone as identification. A crawler that complies with the statute to the letter will still be unverified at the door. I am wrong if the first case names a crawler that announced itself. I am also wrong if a statute passes that names signatures or published address lists as the standard.