Accessibility Laws

Is your AI chatbot covered by the ADA Title II web rule?

David LoPresti By David LoPresti August 5, 2026

The widget your procurement file calls a subscription

If the assistant arrived as a script tag, a monthly fee and a vendor dashboard, it probably sits in a software subscription file rather than a web project file, and the accessibility answer on record probably came from the vendor.

Two rules decide whether that matters to you. Subpart H of 28 CFR part 35 binds public entities under Title II of the ADA, and subpart I of 45 CFR part 84 binds recipients of federal financial assistance from HHS. If you are neither, neither rule sets you a conformance target: answering commenters at 89 FR 31370, DOJ wrote that subpart H “does not alter the responsibilities title III entities have with regard to the goods, services, privileges, or activities offered by public accommodations on the web.”

For the entities they do bind, neither rule asks who wrote the code or who owns the service. Each asks whether the entity provides or makes the content available, in a sentence that reaches contracts and licenses on its face. Once the answer is yes, none of the five exceptions pulls the assistant back out.

This article stays on one question: whether the assistant is in scope and what the contract therefore has to say. The compliance dates and the litigation over the 2026 extensions belong to a separate post on the deadline extensions. One boundary up front. Drafting and negotiating the terms below is legal work and belongs to your counsel and your procurement office. What sits on the accessibility side of the line is the technical specification the clause points at, and the evidence that shows whether it was met.

What the rule counts as web content

Start with the definition, because it is wider than the word “page” suggests. 28 CFR 35.104 says:

Web content means the information and sensory experience to be communicated to the user by means of a user agent, including code or markup that defines the content’s structure, presentation, and interactions. Examples of web content include text, images, sounds, videos, controls, animations, and conventional electronic documents.

The same section defines a user agent as “any software that retrieves and presents web content for users.” A chat panel drawn by a browser is presented by a user agent, and its controls, markup and interactions are named in the definition. Nothing in that sentence turns on authorship or hosting. The identical text sits at 45 CFR 84.10 for recipients of HHS financial assistance.

So the interface is web content on a plain reading. Whether the assistant’s generated answers are separately covered content is harder, and the open questions section below explains why nobody has answered it.

AI chatbot compliance under Title II starts at 28 CFR 35.200(a)(1)

The operative sentence is short. 28 CFR 35.200(a) requires a public entity to ensure that the following are readily accessible to and usable by individuals with disabilities:

(1) Web content that a public entity provides or makes available, directly or through contractual, licensing, or other arrangements; and (2) Mobile apps that a public entity provides or makes available, directly or through contractual, licensing, or other arrangements.

Both limbs matter to a chatbot. An assistant embedded in your website is caught by paragraph (a)(1). The same assistant shipped inside your native app is caught by paragraph (a)(2), on the same “provides or makes available” test, so a clause written only about the website leaves the app uncovered.

The phrase “directly or through contractual, licensing, or other arrangements” carries the coverage question. At 89 FR 31345 of the 2024 final rule, DOJ wrote that the phrase “is not intended to mean that Sec. 35.200 only applies when the public entity creates or owns the web content or mobile app.” The plain meaning of the words make available, the Department continued, “includes situations where a public entity relies on a third party to operate or furnish content.”

Its worked example on the same page is a parking app the city did not build: “even when a city does not design, create, or own a mobile app … when a contractual, licensing, or other arrangement exists between the city and the mobile app enabling the public to use the mobile app to pay for parking in the city, the mobile app is covered under Sec. 35.200.” Substitute a hosted assistant that answers questions about permits and the structure does not change.

At 89 FR 31367 the Department gave five examples of the same shape, covered third-party content “such as calendars, scheduling tools, maps, reservations systems, and payment systems that were developed by an outside technology company,” and then set the consequence:

To the extent a public entity chooses to rely on third-party content on its website in these ways, it must select third-party content that meets the requirements of Sec. 35.200. This is because a public entity may not delegate away its obligations under the ADA.

That is a procurement instruction with a citation on it: the duty to select a conforming product sits with the entity before signing, and does not move to the vendor after signing.

The boundary in the other direction runs on the same page: content “truly unaffiliated with the public entity and not provided on behalf of the public entity due to contractual, licensing, or other arrangements” falls outside 35.200. A licensed widget embedded in your own page is not that.

The coverage chain at 28 CFR 35.200(a)(1) in four steps. Step one, a contract or licence: you rely on a third party to furnish it. Step two, content you make available: 35.200(a)(1) reaches it either way. Step three, the duty attaches to you: not to whoever creates or owns it. Step four, select a conforming product: you may not delegate the obligation.
Each step turns on the arrangement rather than on who wrote the code, which is why a vendor’s own accessibility answer settles nothing.
View the data as a list
  1. A contract or licence: You rely on a third party to furnish it
  2. Content you make available: 35.200(a)(1) reaches it either way
  3. The duty attaches to you: Not to whoever creates or owns it
  4. Select a conforming product: You may not delegate the obligation

The five exceptions, and why none of them applies

28 CFR 35.201 lists five exceptions, and four dispose of themselves. Paragraphs (b) and (d), on preexisting and individualized secured documents, reach only conventional electronic documents, which 35.104 limits to four file formats: portable document formats, word processor files, presentation files and spreadsheet files. Paragraph (a) reaches archived web content, whose definition requires, among four conditions, that the content be “retained exclusively for reference, research, or recordkeeping” and “not altered or updated after the date of archiving,” and paragraph (e) reaches preexisting social media posts. A live chat interface is none of those things.

That leaves paragraph (c), the third-party exception, which is where the vendor conversation starts and where it should not end:

(c) Content posted by a third party. Content posted by a third party, unless the third party is posting due to contractual, licensing, or other arrangements with the public entity.

Two paragraphs of preamble close this off. At 89 FR 31367 DOJ said the exception “only applies where the third-party posted content is independent from the actions of the public entity,” and added: “If such an arrangement exists, the third-party content is not covered by the exception and must be made accessible in accordance with subpart H of this part.” At 89 FR 31368 it named the machinery rather than the posting, writing that “the exception does not apply to the authoring tools and embedded content provided by the public entity, directly or through contractual, licensing, or other arrangements.”

There is a cleaner analysis, though. Paragraph (c) is written around a third party who is posting, and a widget that generates a response at runtime is an awkward fit for that verb in either direction. You do not need the fit. If the assistant is content the entity provides or makes available under a contractual or licensing arrangement, it is covered by 35.200(a)(1), and paragraph (c) then fails to pull it back out, because the carve-out fires on exactly that arrangement. The 35.200(a)(1) analysis is the lead. Paragraph (c) is the backstop that does not hold.

The five exceptions at 28 CFR 35.201, none of which reaches a live vendor chat assistant. Paragraph (a), archived content, is for reference, research and recordkeeping. Paragraph (b), preexisting documents, covers four document formats only. Paragraph (c), third-party posts, fails on a licensed arrangement. Paragraph (d), secured documents, covers four document formats only. Paragraph (e), social media posts, covers posts, not a live chat panel.
Four of the five dispose of themselves on their own wording; the third-party carve-out is the only one worth arguing about, and it fires on the arrangement itself.
View the data as a list

28 CFR 35.201: five exceptions: None of them reaches a live vendor chat assistant

  • (a) Archived content: Reference, research, recordkeeping
  • (b) Preexisting documents: Four document formats only
  • (c) Third-party posts: Fails on a licensed arrangement
  • (d) Secured documents: Four document formats only
  • (e) Social media posts: Posts, not a live chat panel

Section 504 asks the same question in the same words

If you take HHS financial assistance, run the identical analysis in a different part of the CFR. 45 CFR 84.84(a)(1) covers “Web content that a recipient provides or makes available, directly or through contractual, licensing, or other arrangements,” which is 35.200(a)(1) with one noun changed, and 45 CFR 84.85(c) carries the same third-party exception with the same carve-out. The HHS final rule repeats DOJ’s chat sentence word for word at 89 FR 40161, against its own minimal-impact provision at 84.89(b).

QuestionTitle IISection 504
What is web content28 CFR 35.10445 CFR 84.10
The duty over content provided through arrangements28 CFR 35.200(a)(1)45 CFR 84.84(a)(1)
Exceptions, including the third-party carve-out28 CFR 35.201(c)45 CFR 84.85(c)
Conforming alternate versions, and the gate on them28 CFR 35.202(a)45 CFR 84.86
Equivalent facilitation28 CFR 35.20345 CFR 84.87
Fundamental alteration and undue burdens, decided by “the head of a public entity or their designee” and “the head of a recipient or their designee”28 CFR 35.20445 CFR 84.88
Noncompliance with minimal impact on access28 CFR 35.20545 CFR 84.89
Effective communication, which survives conformance28 CFR 35.16045 CFR 84.77

The dates and the cohort tests differ, and both rules had their compliance dates pushed back a year in 2026. For this article the relevant sentence is DOJ’s own, at 91 FR 20906: “No matter the deadline, the rule’s substantive requirements bind covered entities.”

What neither rule says, and what nobody has decided

This part cuts both ways.

Neither web rule uses the word chatbot. Counted over the full text of the DOJ final rule at 89 FR 31320 to 31396, the strings chatbot, chat bot, artificial intelligence, virtual assistant and conversational appear zero times. The HHS final rule uses the phrase artificial intelligence only in its discussion of medical treatment, value assessment and child welfare, at 89 FR 40101 to 40107, which is more than twenty pages ahead of where the subpart I web discussion begins at 89 FR 40126. There is no AI discussion inside the web part of either rule.

What the rules do name is chat. Discussing the minimal-impact provision at 89 FR 31388, DOJ wrote that “Sec. 35.205(b) would not be satisfied if people with disabilities could not interact with all of the different components of the web content or mobile app, such as chat functionality, messaging, calculators, calendars, and search functions.”

The nearest thing to an agency statement that AI output is covered content sits in the April 2026 interim final rule that delayed the compliance dates. Listing its reasons at 91 FR 20906 and 20907, DOJ wrote: “Third, covered entities have been generating substantial amounts of content that would be covered by the 2024 final rule using generative AI that is potentially inaccessible.” Read it for what it is. The sentence treats generative output as content the rule reaches, and it appears in a passage justifying a delay rather than in regulatory text. No provision in either rule addresses runtime generation.

Three more limits, stated plainly.

  1. No decision applying either web rule to an AI assistant turned up in the research for this article. No published court decision, no DOJ settlement and no HHS resolution agreement addressing a chatbot under 28 CFR 35.200 or 45 CFR 84.84 was found, and neither preamble cites one. Treat the mechanics here as text on the page rather than as construed law. The only AI guidance published on ada.gov, on algorithms, artificial intelligence, and disability discrimination in hiring, is dated 12 May 2022 and addresses employment.
  2. W3C has no Recommendation on the accessibility of conversational interfaces. The closest document, Natural Language Interface Accessibility User Requirements, lists “Chat bots in Web applications” among its typical examples of natural language interfaces, but it is a W3C Group Draft Note of 3 September 2022 whose status section says such notes “are not endorsed by W3C nor its Members.” Useful for thinking. Not a standard, and a requirement that cites it has specified nothing.
  3. Whether a text-only or human fallback discharges the duty is unresolved. 28 CFR 35.202(a) permits conforming alternate versions “only where it is not possible to make web content directly accessible due to technical or legal limitations,” and whether a vendor’s inability to fix its own widget sits inside that phrase has not been construed.

The two words that decide your contract

Read the requirement clause at 35.200(b)(1) slowly. Content must “comply with Level A and Level AA success criteria and conformance requirements specified in WCAG 2.1.” Success criteria and conformance requirements are two different things in WCAG, and the second phrase is the one an embedded widget can fail while its own demo passes.

WCAG 2.1, in the 5 June 2018 edition that 35.104 incorporates by reference, states five conformance requirements in section 5.2, and two of them decide how an embedded assistant is judged. Full pages, at 5.2.2, says conformance “is for full Web page(s) only, and cannot be achieved if part of a Web page is excluded.” Non-Interference, at 5.2.5, says technologies used in a non-conforming way “do not block the ability of users to access the rest of the page.”

So a vendor report showing the widget passing in isolation does not answer the question the rule asks. If the assistant traps keyboard focus, if its status messages are not exposed through role or properties as success criterion 4.1.3 requires, or if its panel covers the page’s own controls, the page has not conformed, and the page is what 35.200(b)(1) is about. Note which edition the rule pins: 35.104 names the Recommendation of 5 June 2018 at a dated address, while the undated WCAG 2.1 address now serves a later 2025 text. Write the dated edition into the clause.

WCAG’s own statement of partial conformance lets an author say a page “does not conform, but would conform to WCAG 2.1 at level X if the following parts from uncontrolled sources were removed.” Section 5.4 attaches a precondition: the excluded content “is not content that is under the author’s control.” A widget the entity licenses, configures and embeds is arguably under its control, so the statement may not even be available. Either way it governs what a conformance claim may say, not what 35.200 requires you to fix, and a vendor that answers a remediation request with one has answered a different question.

What to accept and refuse when judging an embedded assistant against WCAG 2.1. Do: measure the result on the full page, because conformance is for full web pages only and cannot be achieved if part of a page is excluded; write the dated 5 June 2018 edition of WCAG 2.1 into the clause; check that status messages are exposed through role or properties, and that the panel does not block access to the rest of the page. Don't: accept a vendor report showing the widget passing in isolation; treat a partial-conformance statement as an answer to a remediation request; point the clause at the undated WCAG 2.1 address, which now serves a later 2025 text.
Both columns follow from one line in section 5.2 of WCAG 2.1: the unit of conformance is the page, not the widget sitting on it.
View the data as a table
DoDon’t
Measure the result on the full page, since conformance cannot be achieved if part of a page is excludedAccept a vendor report showing the widget passing in isolation
Write the dated 5 June 2018 edition of WCAG 2.1 into the clauseTreat a partial-conformance statement as an answer to a remediation request
Check that status messages are exposed through role or properties, and that the panel does not block the rest of the pagePoint the clause at the undated WCAG 2.1 address, which now serves a later 2025 text

Four clauses, keyed to the paragraph each one enforces

DOJ pointed at procurement as the answer. At 89 FR 31346 it wrote that public entities “can choose to work with providers who can ensure accessibility, and public entities can also include contract stipulations that ensure accessibility in third-party services.” Each clause below is marked as stated in the rule or derived from it, so that nobody presents a drafting device as regulatory text.

One thing to be clear-eyed about before drafting. The coverage analysis above settles the interface. It does not settle whether the answers the model generates at runtime are separately covered content, and no provision addresses that. A clause that warrants conformance for the whole assistant, output included, is a contractual allocation of an unresolved legal question, which is a reasonable thing for a buyer to do and is not a restatement of the rule.

One, the conformance clause. Name WCAG 2.1 Level A and Level AA, the W3C Recommendation of 5 June 2018, and say “success criteria and conformance requirements” rather than “success criteria” alone, because that is what 35.200(b) and 84.84(b) say. Acceptance is measured on the host page, and on the native app if the assistant ships there too, not on a demo page. WCAG 2.2 is a W3C Recommendation of 12 December 2024 and is not incorporated by either rule, but if 2.2 Level AA is what you want, say so in the clause: DOJ accepted at 89 FR 31348 that public entities “could choose to comply with subpart H by conforming their web content to WCAG 2.2 Level AA” through equivalent facilitation at 35.203. The standard and the 2.2 route are stated in the rule and its preamble; the acceptance venue is derived.

Two, the not-a-third-party acknowledgement. The vendor states in writing that it supplies the assistant under a contractual or licensing arrangement with the entity, and that it will not assert the exceptions at 35.201(c) or 84.85(c) in a dispute. This is a derived drafting device, and its reach is limited: it settles the argument between you and the vendor, and it cannot bind a regulator’s or a plaintiff’s reading of the carve-out.

Three, the alternate-version gate. A separate accessible chat surface, a text-only mode or a telephone fallback is not acceptance. Under 35.202(a) and 84.86 an alternate version is available “only where it is not possible to make web content directly accessible due to technical or legal limitations.” Write the clause so the vendor fixes the primary assistant and may propose an alternate version only on a written limitation the entity accepts. The gate is stated in the rule; the acceptance mechanics are derived.

Four, who decides and on what record. A fundamental alteration or undue burdens decision is not the vendor’s to make. Under 35.204 it “must be made by the head of a public entity or their designee after considering all resources available for use in the funding and operation of the service, program, or activity, and must be accompanied by a written statement of the reasons for reaching that conclusion,” and the entity carries the burden of proving it. 45 CFR 84.88 says the same for recipients, reading “the head of a recipient or their designee.” So the clause obliges the vendor to supply the technical and cost information the entity needs to make and document that decision itself, and writes acceptance criteria as the four limbs of 35.205. That is also the answer when no accessible product is on the market: DOJ acknowledged at 89 FR 31346 that some commenters “face limited existing options in procurement for accessible third-party services,” and replied that “where such circumstances warrant, public entities can rely on the undue burdens provision when they can satisfy its requirements.” The decision-maker rule and the four limbs are stated in the rule; the flow-down of the information duty is derived.

One clause to leave out: anything that buys a process instead of a result. Answering a comment about overlays at 89 FR 31396, DOJ wrote that “Subpart H does not address the internal policies or procedures that public entities might implement to conform to the technical standard under subpart H.” A remediation program, a roadmap or an accessibility statement satisfies nothing in the rule by itself.

Four contract clauses for a vendor AI assistant, each with the paragraph it enforces and how much of it is regulatory text. Clause one, the standard: names WCAG 2.1 Level A and AA of 5 June 2018; enforces 28 CFR 35.200(b) and 45 CFR 84.84(b); the standard is stated in the rule and the acceptance venue is derived. Clause two, not a third party: the vendor will not assert the third-party carve-out; keyed to 28 CFR 35.201(c) and 45 CFR 84.85(c); a derived drafting device. Clause three, alternate version: the vendor fixes the primary assistant first; keyed to 28 CFR 35.202(a) and 45 CFR 84.86; the gate is stated in the rule and the mechanics are derived. Clause four, who decides: the vendor hands you the cost and technical record; keyed to 28 CFR 35.204 and 45 CFR 84.88; the rule is stated and the flow-down is derived.
The last row is the point: two of these clauses restate the rule, and two are drafting devices a buyer chooses to add.
View the data as a table
1. Standard2. Not a third party3. Alternate version4. Who decides
What the clause doesNames WCAG 2.1 Level A and AA of 5 June 2018Vendor will not assert the third-party carve-outVendor fixes the primary assistant firstVendor hands you the cost and technical record
Paragraph it enforces, 28 CFR then 45 CFR35.200(b) and 84.84(b)35.201(c) and 84.85(c)35.202(a) and 84.8635.204 and 84.88
Stated in the rule, or derivedStandard stated; venue derivedDerived drafting deviceGate stated; mechanics derivedRule stated; flow-down derived

Where conformance stops and effective communication starts

Conformance is the standard and it is not the end of the analysis. At 89 FR 31390 DOJ wrote that subpart H “adds certainty by establishing that conformance to WCAG 2.1 Level AA is generally sufficient for a public entity to meet its obligations to ensure accessibility of web content and mobile apps.” Five pages earlier, at 89 FR 31385, it told public entities to “refer to Sec. 35.160 (effective communication) to determine its obligations” for the person who still cannot use content that conforms. Effective communication is a separate duty that survives conformance, and its 504 counterpart sits at 45 CFR 84.77. What is owed to a person who cannot use a fully conforming assistant is left to case-by-case determination, and nothing found in the research for this article resolves it.

35.205 is the other half, and it is narrower than a vendor may read it. It excuses noncompliance only where the entity can demonstrate the impact is so minimal that people with disabilities can still access the same information, engage in the same interactions and conduct the same transactions “in a manner that provides substantially equivalent timeliness, privacy, independence, and ease of use.” DOJ’s example of failing that test names chat functionality. Its example of passing it is small: 35.205(b) “might be satisfied if the time limit for an interaction, such as a chat response, expires at exactly 20 hours, even though Success Criterion 2.2.1 … has an exception that only applies if the time limit is longer than 20 hours.” At exactly 20 hours the exception does not reach the page, so the page has failed the criterion and 35.205 forgives it. That is the scale of defect on offer.

Your next step

Three things, in this order, and none of them needs a decision from counsel.

  1. Find the arrangement. Pull the assistant’s contract, order form or license and locate the clause naming the accessibility standard the product meets. If the answer is a marketing page or nothing at all, you have found the gap: 35.200(a)(1) attaches on the existence of the arrangement, not on its contents.
  2. Test the assistant on your own page, not the vendor’s demo. Keyboard only, from page load to a completed answer, then again with a screen reader listening for the status message when a response streams in. Full pages conformance is measured on the whole page, so the result you need is a page result.
  3. Fix the clause at the renewal, not after the date. Under the April 2026 interim final rule, public entities with a total population of 50,000 or more comply from 26 April 2027, and smaller entities and special district governments from 26 April 2028, with the deadline post covering how those dates moved. The renewal is where the entity has leverage and a natural place to add the four terms above.

If you want the assistant and the page it sits on tested against WCAG 2.1 Level A and AA, with a defect register your vendor can act on, that is what a WCAG audit and retest engagement delivers. If the wider question is whether the site meets ADA website compliance obligations before your cohort’s date, our government accessibility practice scopes that work against the rule rather than against a scanner score.