Congress Targets AI Chatbot Access for Terror
House passes act to assess AI terrorism risks
Model Diplomat7 min readUnited States
Congress Targets AI Chatbot Access to Preempt Terror Plots
The House passed the Generative AI Terrorism Risk Assessment Act on November 19, 2025. The bigger fight — whether DHS can query ChatGPT prompts — is only starting.
The U.S. House passed H.R. 1736, the Generative AI Terrorism Risk Assessment Act, by voice vote on November 19, 2025 — sending to the Senate the first federal statute built specifically around the misuse of large language models. The study bill is a decoy. The real fight is House Homeland Security Chair Andrew Garbarino's parallel push to give the government structured access to user queries inside AI chatbots — a policy that would extend Fourth Amendment doctrine into the most intimate consumer product in history.
Congress is using the counterterrorism frame to normalize a category of surveillance — the reverse chatbot warrant — already deployed once, in secret, against an OpenAI user. The bill on the House floor is modest. The regime it enables is not.
What the House actually passed
H.R. 1736, authored by Rep. August Pfluger (R-TX-11), chair of the Homeland Security Subcommittee on Counterterrorism, Law Enforcement, and Intelligence, requires the Secretary of Homeland Security, in consultation with the Director of National Intelligence, to submit an annual threat assessment for five years on foreign terrorist organizations' use of generative AI. The bill defines the mission narrowly: catalog incidents in which a foreign terrorist organization or individual used generative AI to "spread violent extremist messaging" or to "enhance their ability to develop or deploy chemical, biological, radiological, or nuclear weapons," according to the engrossed text on Congress.gov.
The unclassified portion must be posted publicly; a classified annex is optional. Fusion centers become the collection nodes, with an explicit directive that DHS "review information … gathered by State and major urban area fusion centers and the National Network of Fusion Centers, and incorporate such information … into the Department of Homeland Security's own information." The bill cleared the Homeland Security Committee 21–0 on September 3, 2025, per the committee action record, and was reported as H. Rept. 119-373 on November 12. The Senate Homeland Security and Governmental Affairs Committee took referral on November 20, 2025, according to the
Congress.gov docket.
Read plainly: the statute does not compel a single chatbot company to hand over a single prompt. It compels DHS to write a report — and to plug fusion centers into the workflow. That is the trellis. The vine grows next.
The Garbarino overlay — what changes the game
The study bill is the pretext. The operative policy is Chair Andrew Garbarino's proposal, advanced this spring, to give the government structured access to AI chatbot user queries as an "early warning" mechanism against terror plots. As Model Diplomat reported in April, Garbarino's push marks "one of the first" U.S. legislative moves aimed at "real-time data transparency from AI companies" — a category of demand that has no equivalent in the search-engine era.
The precedent has already been set outside Congress. On October 20, 2025, Forbes reporter Thomas Brewster disclosed the first known federal warrant compelling OpenAI to unmask the author of specific ChatGPT prompts — a "reverse chatbot warrant" issued at DHS's request. The Center for Democracy & Technology cited that warrant directly in its amicus brief in Chatrie v. United States, arguing that "reverse warrants for AI chatbot prompts" have "potentially even more profound dangers" than the geofence searches at issue in Chatrie, because "users' prompts can be far more detailed and revealing … potentially regarding the user's most intimate thoughts and ideas."
That is the leverage point. Garbarino's proposal would move a case-by-case investigative tool into a standing pipeline. The Congressional Research Service, in a 2026 legal sidebar, notes that the Supreme Court granted certiorari in Chatrie on January 16, 2026 precisely to decide whether the "reverse warrant" architecture — search first, identify suspect later — survives Carpenter's Fourth Amendment framework. If the Court restricts geofence dragnets, chatbot dragnets become the workaround; if the Court blesses them, they become the template.
Why the labs are already at the table
OpenAI and Anthropic did not wait for a subpoena. On April 28, 2025, executives from both companies briefed the House Homeland Security Committee behind closed doors on the offensive-cyber and CBRN uplift risks of frontier models — a bid to shape the guardrails before Congress writes them, as Model Diplomat reported. The commercial incentive is stark: ChatGPT alone reaches roughly 700 million weekly users, per
Al Jazeera, a scale that turns any query-access mandate into a de facto national database of American thought.
The labs face converging pressure that makes cooperation the rational play. Florida Attorney General James Uthmeier opened a criminal investigation of OpenAI in April 2026 over ChatGPT's alleged role advising the shooter in the 2025 Florida State University attack. The suspect asked ChatGPT "what type of gun, what type of ammunition to use" and "when to go to campus to encounter the most people," according to NPR. Weeks later, seven families of victims of the February 10, 2026 Tumbler Ridge, British Columbia school shooting sued OpenAI and Sam Altman in California federal court. The
BBC reported that OpenAI's own 12-person safety team had recommended reporting the shooter to the Royal Canadian Mounted Police months before the attack — a recommendation executives allegedly overruled to protect the company's $850 billion valuation.
A federal reporting channel written into statute lets the labs answer the next negligence complaint with a citation, not a deposition transcript — qualified immunity exchanged for permanent access.
The evidence base is thinner than the rhetoric
Congress is legislating faster than the empirical record grows. The Global Network on Extremism and Technology has documented at least five worldwide cases in which chatbots played a role in planning or attempting a violent attack, per The New Republic — a small denominator against 700 million weekly users. The clearest precedent remains Jaswant Singh Chail, sentenced in 2023 for treason after arriving at Windsor Castle with a crossbow to kill Queen Elizabeth II, having exchanged more than 5,000 messages with a Replika chatbot that "appeared to encourage" his plan, according to the
BBC.
The threat picture is bifurcating. The Atlantic Council's June 2026 issue brief warns that "jailbroken AI models could be directed to help with terrorist training, operational planning, and propaganda development" — the ISIS-facing use case Pfluger's bill targets. But CSIS's
2026 Global Terrorism Threat Assessment is blunt that there is "no clear paramount threat" to the U.S. homeland comparable to the post-9/11 or peak-ISIS eras, and that the current threat "arises primarily from lone actors and loose networks." Lone actors are precisely the population a query-access regime would sweep — and precisely the population least likely to be caught by an FTO-scoped statute.
The result is a mismatch: H.R. 1736 is written against foreign terrorist organizations, but the lawsuits driving political urgency involve American and Canadian domestic shooters. The bill Congress passed does not answer the shootings Congress is responding to.
The Fourth Amendment problem the bill sidesteps
The statute contains one sentence of civil liberties boilerplate — each assessment "shall be coordinated by the Secretary of Homeland Security to ensure compliance with applicable law and protections relating to individuals' privacy, civil rights, and civil liberties." That language does no work. The harder constraint is external.
In Chatrie, the amicus brief filed by Fourth Amendment scholars warns that "reverse searches through chat data … will trawl through the unguarded and raw thoughts of millions," noting that chatbots do not merely "receive the thoughts of the user, but they are designed to adapt to them, elicit them, and anticipate them." The Electronic Frontier Foundation, joined by other civil liberties groups, argued in its
Supreme Court amicus that under Carpenter, geofence-style searches are Fourth Amendment searches requiring particularized warrants.
The underlying statute is even older. Brookings' John Villasenor notes that the Electronic Communications Privacy Act, the 1986 law governing law enforcement access to data held by providers like OpenAI, "was written long before the era of smartphones and chatbots, leaving parts of the statute decades out of date." The reverse chatbot warrant issued to OpenAI in October 2025 was executed against that 40-year-old scaffolding — a fact the Senate committee reviewing H.R. 1736 has not been forced to address.
Named winners, named losers
The winners are the frontier labs. A federally chartered reporting regime hands OpenAI, Anthropic, and Google a shield against the Tumbler Ridge and FSU-style negligence suits, and a moat against smaller competitors that cannot bear the compliance cost. Pfluger and Garbarino win a signature counterterrorism deliverable in an administration that, as the Council on Foreign Relations' Bruce Hoffman warned, has "directed DHS to focus more on illegal immigration operations than on counterterrorism."
The losers are open-source AI developers, downstream chatbot providers without the legal firepower to negotiate carveouts, and the users whose prompts become, in the CDT's phrase, "an ocean of data … an irresistible one through which to drag law enforcement nets." Character.AI, Replika, and their peers — the platforms where the actual documented harms have concentrated — sit outside the frontier-lab briefing room.
Diplomat View
The Senate will pass H.R. 1736 in something close to its current form. It is cheap, unanimous, and politically unassailable — a bill demanding a report is the lowest-cost signal Congress can send. That is not where to look.
The forecast: within 18 months, DHS will use the H.R. 1736 assessment process — and the fusion-center pipeline it mandates — to justify a follow-on bill or executive action codifying structured access to chatbot prompts under a national-security predicate. The reverse ChatGPT warrant of October 2025 is the proof of concept. The lab briefings of April 2025 are the negotiation. Garbarino's proposal is the vehicle. What would falsify this call: a Supreme Court ruling in Chatrie that treats reverse searches as categorical Fourth Amendment violations, or a Senate Democrat — Wyden is the obvious candidate — placing a hold on H.R. 1736 pending civil-liberties language with teeth. Neither is currently visible.
What to watch
- Senate HSGAC markup of H.R. 1736 — the first opportunity to attach warrant-requirement or minimization language.
- Supreme Court ruling in Chatrie v. United States — expected in the 2026 term; will set the constitutional ceiling for reverse chatbot warrants.
- DHS response to the OpenAI reverse warrant disclosure — whether DOJ moves to defend or narrow the practice will signal executive-branch appetite.
Discover more
India
Congress Advocates 33% Women’s Quota
Congress calls for a 33% women's reservation in the existing 543 Lok Sabha seats, countering Modi's plan to expand the house to 850 seats.
Global Politics
Trump's Conflicting Messages on Iran War
Trump's mixed messages on Iran reflect a strategy of audience management, benefiting Tehran amid a complex geopolitical landscape.

Tech Policy
SK Hynix, CXMT IPOs Fueled by Chip Shortage
SK Hynix raises $26.5B in record US IPO while China's CXMT targets $10B Shanghai listing. Both deals are underwritten by the same global memory shortage, with Chey Tae-won's chipflation warning as the backdrop.

Elections & Campaigns
Iran's invisible leader hands power to IRGC
Mojtaba Khamenei's five-month public absence creates a power vacuum that the IRGC exploits to undermine Iran's US ceasefire deal and consolidate control over the economy.