A bill introduced in the House on July 23, 2026 would require automated web crawlers to say who they are and why they are visiting. Publishers back it, but the traffic it targets also runs through the analytics, attribution and content-licensing decisions that marketing teams own.
What the Stealth Bot Prohibition Act would do
Representatives Valerie Foushee (D-NC-04), Laurel Lee (R-FL-15) and Gus Bilirakis (R-FL-09) introduced the Stealth Bot Prohibition Act as bipartisan legislation to set transparency standards for automated web crawlers. It has two parts. Crawlers must accurately identify themselves and disclose their purpose when they access a website. And deceptive “stealth bots” that intentionally misrepresent their identity or impersonate human users in connection with generative AI services are prohibited.
The Federal Trade Commission would enforce the requirements through civil penalties. Foushee’s statement says the bill would also authorize state attorneys general to pursue civil penalties against violators. The sponsors’ release gives no penalty amounts and no effective date.
The sponsors describe the problem in traffic terms. Their release says automated bots now account for more than half of all global web traffic, and that many AI-powered web crawlers “ignore existing industry standards, disguise themselves as human users, or conceal their identities altogether.”
Who is backing it
The release lists these supporters: ASCRL, Bria, Condé Nast, the News/Media Alliance, News Corp, Advance Local, Axel Springer US, Hearst Magazines, McClatchy Media Company, Newsmax, Tampa Bay Times, The New York Times, USA TODAY Co, Vox Media and Reddit. Nearly all of them own content. One builds AI. Vered Horesh, Chief AI Strategy Officer at Bria, said: “Any bot crawling the web should say who it is and what it wants with the content it takes. Bria is an AI developer, and we are asking for that rule to apply to us.”
Danielle Coffey, President and CEO of the News/Media Alliance, put the publisher case this way: “We are drowning in bot traffic that is hurting our ability to serve our readers, and existing technical tools simply aren’t enough to protect our content from malicious foreign actors that can disguise their identity.”
Why a marketing team should care about a publisher’s bill
Most marketing dashboards count sessions, and a session count is only as clean as the filter in front of it. The sponsors say stealth crawling makes it “more difficult to distinguish legitimate automated activity from malicious actors.” The bill does not mention analytics or advertising. What follows is our reading of where marketing teams are exposed, not something the text says.
Analytics and attribution
Conversion rate, cost per visit and engagement per session all use human visits as the denominator. A crawler that passes as a person inflates that denominator and pulls down every rate computed from it. A disclosure rule would give analytics vendors a declared identity to filter on, for the crawlers that comply.
AI visibility and referral reporting
Teams now report on how AI systems read and cite their pages, and the tracking questions are moving into advertising too, as we covered in AI Chat Ads Inherit the Web’s Old Tracking Fight. Those reports depend on knowing which automated visits come from AI systems and which come from people. A declared purpose on each crawler would let a team separate the two in its logs.
Content access policy
A declared crawler can be allowed, blocked or licensed by name. An undeclared one cannot. Whoever owns the site’s content policy, often a marketing or web team, needs the crawler’s identity before any of those choices exist.
What is still unsettled
The bill is introduced, not passed. The release names House sponsors only, and Coffey says the alliance looks forward to working with colleagues “in both the House and the Senate.”
Compliance is the harder question. A disclosure rule binds the crawlers that follow rules, and the sponsors’ own description of the problem is bots that already ignore existing standards. Enforcement therefore rests on the FTC and state attorneys general, and the release does not say how a crawler’s “purpose” would be categorized.
The supporter list also shows who is absent. It contains publishers, creators and one AI developer. It contains no analytics provider, ad verification vendor or advertiser, the parties that would build the filters and act on the cleaner numbers. The marketing-side cost and benefit of the bill has not yet been argued by the people who would carry it. For a related argument on governing AI agents, see our opinion piece The MCP Rush Has a Governance Gap Nobody Is Naming.
What it means for the marketing leader
Five checks apply whether or not the bill moves.
First, ask your analytics and ad verification vendors how they classify automated traffic today, and whether they filter on a crawler’s declared identity or only on lists of known bad actors.
Second, compare server-log request counts with analytics sessions for the same pages over one week. A persistent gap is your first estimate of the automated share of traffic.
Third, write down a crawler policy. Name which declared AI crawlers you allow, which you block and which you would license, and who approves a change.
Fourth, keep AI-related traffic out of human-session reporting before you set next quarter’s traffic and conversion targets, so that targets rest on people and not on crawlers.
Fifth, brief your legal and privacy counsel on the bill’s two obligations, disclosure of identity and purpose, so that any change to how you treat crawlers is reviewed against them before enforcement rules arrive.
The log comparison needs no bill to pass. Start there.
Source: Office of Rep. Valerie Foushee