CiberLATAMbywhalemate

U.S. Congress advances new AI rules

Bills in Congress would require AI to disclose sponsored content and major data centers to report their electricity and water use.

Whalemate Labs · AI-assisted researchPublished:3 min read

The U.S. Congress added new measures this week that expand regulatory obligations for digital infrastructure and AI platforms. They include the AI Advertising Disclosure Act and the Ratepayer Bill of Rights Act.

In August 2026, the U.S. Congress advanced several measures that expand transparency and compliance obligations for digital infrastructure, AI platforms, and critical services. They include the AI Advertising Disclosure Act, the Ratepayer Bill of Rights Act of 2026, the Quantum-GUARD proposal for the electric grid, and the Water Cyber Shield Act for water utilities, with potential effects on operations and subsidiaries that rely on U.S. jurisdiction.

What changes for AI tools?

H.R. 10146, the AI Advertising Disclosure Act, was introduced on August 24, 2026, by Seth Magaziner and referred to the House Committee on Energy and Commerce. It would require certain artificial intelligence tools to disclose when a response contains sponsored content tied to a commercial agreement.

The official text defines sponsored content broadly and requires specific disclosures when a recommendation was not explicitly requested, when bias enters through the system prompt, RAG sources, or fine-tuning data funded by third parties, or when the output includes affiliate links or referral codes. Outside analysis says the bill is aimed at mass-market tools and expands advertising compliance rules for foundation models and conversational assistants.

What does it require of major data centers?

H.R. 10139, the Ratepayer Bill of Rights Act of 2026, was introduced on August 24, 2026, and seeks to impose public disclosures on electricity and water use, infrastructure costs, tariff impacts, public financial support, and commitments tied to large data centers. According to the analyses cited, facilities that use at least 50 megawatts of electricity or 100,000 gallons of water per day would fall under the bill.

The proposal also calls for public hearings for covered projects and a requirement to show that the connection will not harm electric service reliability for existing customers or the availability of community water supplies. It would also fall under shared jurisdiction among several federal agencies, including FERC, the Department of Energy, and the EPA.

How does it affect energy, water, and cybersecurity?

The Quantum-GUARD Act, introduced in August 2026 by Senators Mike Rounds and Chris Coons, would direct FERC to consider quantum computing threats when reviewing reliability standards for owners and operators of electric systems under the Federal Power Act. That review would include exploring post-quantum cryptography in information technology and operational systems, and adopting any measures the commission deems appropriate.

In parallel, the Water Cyber Shield Act, identified as S. 5368, is framed as an amendment to the Safe Drinking Water Act and the Federal Water Pollution Control Act to establish or modify cybersecurity requirements for drinking water and wastewater systems. Bill summaries say the EPA would have to develop tiered standards together with CISA, NIST, states, and water-sector stakeholders.

What other signals is Congress sending?

An analysis from the Center for American Progress Action noted that the House passed the May 22, 2025 version of the One Big Beautiful Bill Act, which included a 10-year moratorium on state and local laws and regulations that limit, restrict, or regulate AI models and systems. The same congressional pipeline still includes bills on children and social media, such as the Kids Online Safety Act, the Children and Teens Online Privacy Protection Act, and the KIDS Act, according to the CRS.

A Legis1 report also describes compliance conflicts between proposed or issued cybersecurity rules from three Department of Homeland Security agencies, including TSA and CISA, for critical infrastructure operators. The legislative recommendation is to move toward common definitions, a unified reporting authority, or reciprocity agreements to reduce the regulatory burden.

Sources

View all