How Does the Government Regulate the Internet? Speech, Privacy, and AI

The federal government regulates the internet through a patchwork of laws and agency rules rather than any single statute. Understanding how the government regulates the internet means looking at several distinct areas: speech and platform liability, copyright, broadband access, privacy, consumer protection, cybercrime, and, most recently, artificial intelligence. Congress and federal agencies have layered these rules over three decades, each responding to specific problems as online activity expanded into commerce, communication, and critical infrastructure.

Speech and Platform Liability

Congress’s first major attempt to regulate online content was the Communications Decency Act (CDA) of 1996, part of the Telecommunications Act. It made it a crime to transmit “obscene or indecent” messages to anyone under 18. In Reno v. American Civil Liberties Union (1997), the Supreme Court struck down those provisions, holding that the law’s broad language swept in constitutionally protected adult speech and that online speech receives the same First Amendment protection as print or broadcast.1The First Amendment Encyclopedia. Communications Decency Act and Section 230 (1996)

One provision of the CDA survived and became arguably the most consequential internet law in the country. Section 230 provides that no operator of an interactive computer service can be treated as the publisher or speaker of content posted by someone else.2Office of the Law Revision Counsel. 47 USC 230 – Protection for Private Blocking and Screening of Offensive Material If a user posts something defamatory or fraudulent on a platform, the platform generally cannot be sued as if it had published that content itself. Section 230 also protects platforms that choose to moderate, allowing them to remove posts they consider obscene, violent, or harassing without losing immunity.

That immunity has limits. Section 230(e) preserves federal criminal law, intellectual property claims, and the Electronic Communications Privacy Act. In 2018, Congress added another exception through the Allow States and Victims to Fight Online Sex Trafficking Act (FOSTA-SESTA). Under 18 U.S.C. § 2421A, anyone who owns or operates an interactive computer service with the intent to promote or facilitate prostitution faces up to 10 years in prison, rising to 25 years if the conduct involves five or more people or reckless disregard of sex trafficking on the platform.3Office of the Law Revision Counsel. 18 USC 2421A – Promotion or Facilitation of Prostitution and Reckless Disregard of Sex Trafficking

Copyright Online

The Digital Millennium Copyright Act (DMCA) of 1998 gave copyright holders tools built for the digital era. It made it illegal to produce or distribute technology designed to bypass digital copyright protections such as encryption or software access controls.

Its most practically significant feature is the safe harbor system under 17 U.S.C. § 512. Platforms that host user-uploaded content can avoid liability for user infringement if they meet specific conditions: they must adopt and communicate a policy for terminating repeat infringers, lack actual knowledge of infringing material, promptly remove flagged content upon receiving a valid takedown notice, and designate an agent registered with the U.S. Copyright Office to receive those notices.4Office of the Law Revision Counsel. 17 USC 512 – Limitations on Liability Relating to Material Online This notice-and-takedown process is the backbone of how copyright disputes play out online. Uploaders can file a counter-notice if they believe a removal was mistaken.

Broadband and Internet Access

The Federal Communications Commission (FCC) is the primary federal agency overseeing how Americans access the internet.5Federal Communications Commission. What We Do The central debate for over a decade has been net neutrality, or whether internet service providers must treat all traffic equally.

The technical question is one of classification. Under Title II of the Communications Act of 1934, ISPs are regulated like telephone companies, giving the FCC authority to impose strict rules against discriminatory practices. Under Title I, they are “information services” with a lighter regulatory touch. The classification has swung repeatedly.

  • 2015: The FCC’s Open Internet Order reclassified broadband as a Title II telecommunications service and banned blocking, throttling, and paid prioritization.6Federal Register. Protecting and Promoting the Open Internet
  • 2017: The Restoring Internet Freedom Order reversed course, moving broadband back to Title I and eliminating the net neutrality rules.7Federal Register. Restoring Internet Freedom
  • 2024: The FCC again restored net neutrality on April 25, 2024, with an effective date of July 22, 2024. The order faced immediate legal challenges, and its long-term status remains uncertain.8Federal Communications Commission. FCC Announces Effective Date of Net Neutrality Order

Beyond net neutrality, the FCC has pushed transparency into how ISPs market their plans. Since 2024, providers must display standardized broadband consumer labels, modeled on nutrition labels, at the point of sale and in each customer’s online account. Labels must show the actual price, typical download and upload speeds, data caps, early termination fees, and throttling practices.9Federal Communications Commission. Broadband Consumer Labels

Access itself is also a regulatory concern. The Broadband Equity, Access, and Deployment (BEAD) Program, funded through the 2021 Infrastructure Investment and Jobs Act, allocated $42.45 billion to expand high-speed internet to underserved communities. States and territories submit deployment plans to the National Telecommunications and Information Administration (NTIA) for approval before receiving funds. As of March 2026, 53 of the 56 eligible states and territories have had final proposals approved, and 38 have signed grant agreements.10NTIA. BEAD Progress Dashboard The other major federal broadband subsidy, the Affordable Connectivity Program, which helped roughly 23 million low-income households pay for service, expired on May 31, 2024, after Congress declined to approve additional funding.11Federal Communications Commission. Affordable Connectivity Program No federal replacement has been enacted as of early 2026.

Privacy and Children’s Data

Federal online privacy regulation is largely sector-specific. There is no single comprehensive federal law covering all consumer data online. The most significant online privacy statute remains the Children’s Online Privacy Protection Act (COPPA) of 1998, which applies to websites and online services that collect personal information from children under 13. Operators must obtain verifiable parental consent before collecting, using, or sharing a child’s data, post clear privacy policies, and let parents review and delete their child’s information.12eCFR. 16 CFR Part 312 – Children’s Online Privacy Protection Rule

The Federal Trade Commission finalized major COPPA amendments in January 2025. Operators now need separate parental consent before sharing a child’s data with third parties for targeted advertising. Companies can only keep children’s information for as long as reasonably necessary, and indefinite retention is prohibited. The definition of personal information now includes biometric identifiers and government-issued identifiers. FTC-approved self-regulatory safe harbor programs must publicly disclose their membership lists and report additional information to the agency. Covered entities have one year from Federal Register publication to comply.13Federal Trade Commission. FTC Finalizes Changes to Childrens Privacy Rule Limiting Companies Ability to Monetize Kids Data

For adults, states have moved in where federal law hasn’t. As of 2026, approximately 20 states have enacted comprehensive consumer data privacy laws, generally granting residents rights to access, delete, and opt out of the sale of their personal information. The result is a fragmented landscape that national businesses must navigate.

Consumer Protection in Digital Marketplaces

The FTC has been the most active federal agency in extending traditional consumer protection principles to online commerce.

Fake Reviews

The FTC’s Consumer Review Rule prohibits several forms of deception that had become common online. Businesses cannot post or commission reviews that misrepresent the reviewer’s experience, pay for reviews conditioned on positive sentiment, or publish reviews from company insiders without disclosing the relationship. The rule also covers misuse of social media engagement metrics like follower counts. Violations can lead to civil penalties of up to $53,088 per violation.14Federal Trade Commission. FTC Warns 10 Companies About Possible Violations of the Agencys New Consumer Review Rule

Click-to-Cancel

The FTC’s amended Negative Option Rule, commonly known as “click-to-cancel,” requires businesses to make canceling a subscription at least as easy as signing up. If a customer enrolled online, the business must offer an online cancellation option and cannot force the customer to call or visit in person. All material terms, including price, billing frequency, free trial end dates, and cancellation procedures, must be clearly disclosed at the point of enrollment. Businesses must retain proof of consent for at least three years.15Federal Trade Commission. Click to Cancel: The FTCs Amended Negative Option Rule and What It Means for Your Business

Online Marketplace Sellers

The INFORM Consumers Act, codified at 15 U.S.C. § 45f, targets fraud and counterfeiting on marketplaces like Amazon and eBay by requiring transparency about who is actually selling. It applies to “high-volume third-party sellers,” meaning anyone with 200 or more sales and at least $5,000 in gross revenue on a platform within any 12-month period. Marketplaces must collect and verify each qualifying seller’s bank account, tax ID, contact information, phone number, and email. For sellers earning $20,000 or more annually, the marketplace must disclose the seller’s name, physical address, and contact information to consumers on the product listing or in order confirmations.16Office of the Law Revision Counsel. 15 USC 45f – Collection, Verification, and Disclosure of Information by Online Marketplaces

Cybercrime and Critical Infrastructure

The Computer Fraud and Abuse Act (CFAA), enacted in 1984 and substantially amended in 1986, is the primary federal law used to prosecute hacking. It covers accessing a computer without authorization, exceeding authorized access, transmitting malicious code that damages systems, and trafficking in stolen passwords. Penalties scale with severity, and intentionally damaging a protected computer or stealing sensitive information such as financial or national security data carries the heaviest sentences.17Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers

Two federal agencies lead cybercrime investigations. The FBI operates specialized cyber squads in each of its 56 field offices and coordinates the National Cyber Investigative Joint Task Force with more than 30 partner agencies.18Federal Bureau of Investigation. Cyber The U.S. Secret Service focuses on cybercrime affecting financial systems and critical infrastructure through its Cyber Fraud Task Forces.19United States Secret Service. Cyber Investigations

When personal information is exposed in a breach, notification obligations kick in. Every state has a data breach notification law, though specifics vary. Notification deadlines typically range from 30 to 60 days after discovery, and notices must describe what information was compromised and how affected individuals can protect themselves.

For attacks on critical infrastructure, the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), signed in 2022, will require owners and operators to report significant cyberattacks to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours and ransomware payments within 24 hours. CISA has not yet finalized the implementing rule; the agency targeted May 2026, but that deadline is expected to slip as it continues gathering stakeholder input.

Artificial Intelligence

Federal AI oversight is still in its earliest stages, and the regulatory picture has already shifted dramatically. In October 2023, President Biden signed Executive Order 14110, which imposed mandatory reporting requirements on companies developing the most powerful AI models, including disclosures about training activities, red-team safety testing, and the location of large-scale computing clusters.20Federal Register. Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

In January 2025, President Trump signed a new executive order titled “Removing Barriers to American Leadership in Artificial Intelligence,” directing agencies to review and potentially suspend, revise, or rescind actions taken under EO 14110.21The White House. Removing Barriers to American Leadership in Artificial Intelligence The order prioritized reducing regulatory burdens on AI development and called for a new AI action plan within 180 days.

Alongside executive action, the National Institute of Standards and Technology (NIST) developed the AI Risk Management Framework, a voluntary set of guidelines for identifying and managing risks related to bias, security, and trustworthiness.22National Institute of Standards and Technology. AI Risk Management Framework Because it is voluntary, it functions as a best-practices reference rather than binding regulation. Bills like the Algorithmic Accountability Act, which would require impact assessments of automated decision-making systems, and the Kids Online Safety Act have been introduced but not enacted as of mid-2026.23U.S. Congress. S.1748 – 119th Congress (2025-2026) – Kids Online Safety Act Federal AI regulation for now remains a mix of shifting executive priorities, voluntary frameworks, and stalled legislation.