Learning Center

The Stealth Bot Prohibition Act: What Publishers Need to Know

August 3, 2026

Show Editorial Policy

shield-icon-2

Editorial Policy

All of our content is generated by subject matter experts with years of ad tech experience and structured by writers and educators for ease of use and digestibility. Learn more about our rigorous interview, content production and review process here.

The Stealth Bot Prohibition Act: What Publishers Need to Know
Ready to be powered by Playwire?

Maximize your ad revenue today!

Apply Now

Key Points

  • Congressional action on AI crawlers: Three bipartisan House representatives introduced the Stealth Bot Prohibition Act (H.R.9915), which would require all bots to disclose their identity and purpose when crawling websites.
  • Bot traffic is a real operational problem: Researchers now report more bots than humans on the internet, and the majority act in harmful ways, hiding identities, overloading servers, and scraping content without authorization.
  • Major publishers are behind this: News Corp, Condé Nast, Hearst, and the Tampa Bay Times have all publicly supported the bill, signaling broad industry alignment.
  • State-level pressure is building: New York already passed its own version. Missouri, Nebraska, Tennessee, Texas, and Utah have all proposed similar legislation. Federal legislation would create one standard instead of a patchwork.
  • Traffic protection is step one: Knowing who's crawling your site is prerequisite to protecting the revenue that traffic generates.

What Happened

Three House representatives, Laurel Lee (FL-15), Valerie Foushee (NC-4), and Gus Bilirakis (FL-9), introduced the Stealth Bot Prohibition Act (H.R.9915), a bipartisan bill that would require AI crawlers and other bots to identify themselves and their purpose when accessing websites. The News/Media Alliance announced its support alongside major industry players including News Corp, Condé Nast, Hearst Magazines, and the Tampa Bay Times.

The bill targets what the legislation calls "stealth bots," crawlers that mask their identities, sometimes by hijacking residential devices to disguise their traffic as human activity. The practice is widespread. Researchers cited in the bill now say bots outnumber people on the internet, with a majority acting in ways that harm content providers.

This isn't the first attempt at this kind of legislation. New York's legislature already passed the "New York Stealth Crawler Prohibition Act." Five other states have proposed similar measures. The federal bill is designed to replace that growing patchwork with a single national standard.

See It In Action:

Why This Matters for Publishers

Publishers running standard traffic analysis tools can't reliably distinguish a well-disguised AI crawler from a human reader. That gap creates three distinct problems.

The performance problem is the most immediate. Bots consuming server resources degrade load times for actual human visitors. Slower pages hurt user experience, increase bounce rates, and compress the session value that drives ad revenue.

The content problem is the one generating most of the headlines. AI companies are training models on publisher content and deploying those models as direct competitors to the publishers whose work fed them. Condé Nast CEO Roger Lynch put it plainly: "AI companies are using disguised bots to scrape and steal original journalism with zero accountability."

The measurement problem is the one most publishers haven't fully reckoned with yet. If your analytics are counting bot traffic as human sessions, your CPM benchmarks, viewability rates, and engagement metrics are all contaminated. You're making monetization decisions on dirty data.

The Stealth Bot Prohibition Act addresses the first problem directly and creates the legal foundation for addressing the second. The measurement problem is yours to solve regardless of what Congress does.

Essential Background Reading:

What the Bill Aims to Do

The legislation takes a narrow, targeted approach. It doesn't ban AI crawling or require licensing agreements. It requires bots to identify themselves and state their purpose. That's it.

That disclosure requirement matters because enforcement follows identification. Right now, blocking AI crawlers via robots.txt works only for operators who choose to respect it. Many don't. Stealth crawlers actively impersonate browsers or hijack residential IP addresses to bypass controls entirely. A legal transparency mandate changes the accountability calculus for operators running those bots.

The bill also has a national security dimension the industry doesn't often emphasize. A significant share of malicious bot traffic originates from outside the United States. The legislation specifically calls out foreign bot operators as a competitiveness and national security concern, which broadens its political appeal beyond just the publishing industry.

Whether this bill passes is a separate question. Congressional timelines are unpredictable, and tech industry lobbying against disclosure requirements will be substantial. But the legislative momentum, state-level pressure, and bipartisan framing make this worth watching.

Related Content:

What Publishers Should Do Now

Don't wait for federal legislation to get your house in order. The bill, if passed, creates transparency obligations for bot operators. It doesn't automatically solve your traffic quality problem. That still requires active management on your end.

Here's where to start:

  • Audit your bot traffic: Use your server logs and analytics to assess what percentage of your traffic is non-human. Most publishers are surprised by the number.
  • Review your robots.txt configuration: Make sure you're explicitly disallowing the crawlers you don't want. Check our AI Crawler Protection Grader to see how your current setup holds up.
  • Separate bot sessions from human sessions in your reporting: Revenue per session metrics are meaningless if bot traffic is inflating your session counts.
  • Evaluate your blocking strategy: Blocking isn't right for every publisher. Some AI partnerships have legitimate value. The key is making the decision deliberately, with full visibility into who's crawling your site and what they're doing with it.

Our AI Crawler Resource Center has the technical detail on each of these steps if you want to go deeper.

Next Steps:

The Revenue Connection

The Stealth Bot Prohibition Act frames this as a content protection issue. It is. It's also a revenue protection issue.

Bot traffic doesn't generate ad revenue. It generates ad requests that get filtered out, inflate impression counts before IVT filtering, and distort the session-level data you use to make monetization decisions. Publishers optimizing their layouts, floor prices, and header bidding configurations based on contaminated traffic data are leaving real money on the table.

Knowing who's crawling your site is the prerequisite. Maximizing the revenue from your actual human audience is the goal. Those are two separate problems, and solving the first one creates space to focus on the second.

We work with publishers across gaming, education, sports, and news to do exactly that. If you want to talk through what better traffic quality and cleaner monetization data could mean for your RPS, we're here.

New call-to-action