Seven States Now Restrict AI Therapy: What Small Behavioral Health Practices Can Still Automate

Executive Summary

  • Seven states now restrict artificial intelligence in mental and behavioral health care. Illinois and Nevada acted in 2025. Colorado, Maine, Rhode Island, Tennessee and Vermont followed in 2026, and five of those seven took effect between June and August 2026.
  • They converge on one principle and diverge on almost everything else. Illinois fines up to $10,000 per violation and Nevada up to $15,000. Tennessee is far narrower than the rest and reaches only advertising and representations, at $5,000 per violation. Maine and Vermont created no flat fine at all and instead made a violation an unfair trade practice, which opens the door to private plaintiffs.
  • None of these laws bans AI from a behavioral health practice. All of them permit scheduling, billing, records and referral work. Several permit documentation support, though the consent, clinician review and data handling conditions differ materially by state.
  • Marketing language is the easiest violation for a regulator to find. Nevada, Tennessee, Maine, Vermont and California all reach the words on your website and intake screens, and California treats each separate use of a prohibited term as a separate violation.
  • The American Psychological Association surveyed more than 1,200 licensed psychologists in June 2026 and found that 77 percent had spoken with patients who used AI, and 35 percent had patients treating AI as an additional mental health professional. The compliance question is no longer hypothetical for any practice.

1. Seven states now restrict AI in therapy, and the rules are not identical

Seven states have enacted laws restricting artificial intelligence in mental and behavioral health care, and five of those laws took effect between June and August 2026. State AI therapy laws prohibit artificial intelligence from delivering mental health treatment unless a licensed professional provides it. Illinois and Nevada acted first in 2025. Colorado, Maine, Rhode Island, Tennessee and Vermont followed in 2026. Every one of them permits licensed clinicians to keep using AI for administrative work, and several permit documentation support subject to written patient consent.

A note on scope before going further. This article covers the seven states that restrict AI from delivering therapy or behavioral health services. Utah is a separate and important regime that regulates mental health chatbots through disclosure, data handling, advertising and filed policies rather than a licensure line, and section 9 covers it. California also regulates AI that implies licensed clinical care, but it does so as a health care impersonation rule rather than a therapy restriction. Neither is counted among the seven.

That last sentence is the part small practices keep missing. The headlines said “AI therapy ban,” so a large number of solo counselors, two clinician group practices and small community behavioral health agencies concluded that the safe move was to stop using AI altogether. That is not what any of these statutes say. Each one draws a line between clinical work, which must stay with a licensed human, and everything else, which a practice may automate under conditions the statute spells out.

The volume of state activity is the real signal. The Transparency Coalition counted 14 new state laws across 11 states regulating AI in health care in 2026 alone as of July 27, 2026. Seven addressed insurer use of AI in prior authorization and five addressed therapy chatbots. That is a legislature by legislature consensus forming inside a single session, which almost never happens in health care regulation.

The clinical reality moved faster than the statutes. In June 2026 the American Psychological Association published a survey of more than 1,200 licensed psychologists. Seventy seven percent had spoken with patients who had used AI. Thirty five percent said patients were using AI as an additional mental health professional, and 39 percent had patients who used AI to self diagnose. Ninety four percent were concerned that chatbots cannot treat conditions with appropriate nuance, and 89 percent that chatbots may encourage self harm. Legislators read those numbers too.

2. The licensure line: what all seven laws actually prohibit

Most of the seven prohibit the same core act: offering therapy to the public through artificial intelligence without a licensed human providing it. Tennessee is the exception and is materially narrower, reaching only representations that an AI system is or can act as a qualified mental health professional. The rest get there through two different mechanisms, and the difference matters for who is exposed.

The first mechanism regulates the market. Maine’s Public Law Chapter 687, enacted as LD 2082 on April 13, 2026, states that a person may not provide, advertise or otherwise offer therapy or psychotherapy services, including through internet based artificial intelligence, unless a licensed professional provides them. Vermont’s Act 156, signed June 17, 2026, uses nearly the same sentence for a corporation or entity, and Rhode Island’s Oversight of Artificial Intelligence Technology in Mental Health Care Act, enacted as S 2197 Substitute A and effective on passage June 22, 2026, uses the same structure. Nevada’s AB 406 goes further and prohibits an AI provider from making available in Nevada any system specifically programmed to provide an experience that would constitute the practice of professional mental or behavioral health care if a person provided it.

The second mechanism regulates the clinician. Illinois takes this approach in the Wellness and Oversight for Psychological Resources Act, signed as Public Act 104-0054 on August 1, 2025. Under Section 20 a licensed professional may not permit AI to make independent therapeutic decisions, communicate directly with clients in a therapeutic capacity, generate treatment plans without professional review, or detect emotions and mental states. Colorado’s HB 26-1195, signed June 3, 2026 and effective August 12, 2026, adds a requirement no other state has. Subsection (5)(a) of the enacted act bars a licensee from allowing an AI system to interact with clients in any form of therapeutic communication without synchronous, real time interaction among the licensee, the AI system and the client. The act defines synchronous as interactions occurring simultaneously with active participation by both client and clinician, and expressly says it does not mean reviewing an interaction after it has happened.

Most of the seven do both. Maine’s chaptered law enacted a general market prohibition in Title 10 and then added parallel clinician facing sections to seven separate professional licensing chapters in Title 32, so each profession has its own statutory section saying the same thing. Vermont amended its unprofessional conduct statute so that prohibited AI use is itself grounds for board discipline.

GOVERNANCE INSIGHT

The statute your practice violates first is usually the market one, not the clinical one.

A solo clinician who uses an AI scribe correctly can still violate the law through a website page describing an “AI intake counselor.” The market provisions in Maine, Vermont, Nevada and Tennessee do not require a patient to be harmed or even to exist. They regulate what you offer and how you describe it.

3. What your practice can still legally automate

You can automate scheduling, billing, insurance claims, records management, operational data analysis and referral organization in all seven states. Four of them, Illinois, Colorado, Maine and Rhode Island, use a common three tier vocabulary as defined statutory terms, and it is worth learning because it decides which of your tools are in scope. Nevada uses the first tier only. Tennessee and Vermont do not use these labels at all, so in those two states the practical question is simply whether the tool communicates therapeutically, exercises clinical judgment or independently influences treatment.

Administrative support means work that assists in delivering therapy but involves no therapeutic communication. Rhode Island, Maine and Colorado all use nearly identical enumerations: appointment scheduling and reminders, billing and insurance claims, and drafting general communications about logistics that carry no therapeutic advice. Nevada’s AB 406 adds analyzing data for operational purposes and organizing session notes. Administrative support carries the lightest conditions in every state.

Supplementary support is the middle tier and the one practices misjudge. It also involves no therapeutic communication, but it touches clinical material. Rhode Island and Maine both define it to include preparing and maintaining client records including therapy notes, analyzing data to track client progress subject to review by a licensed professional, and organizing external resources or referrals. This is where your AI scribe lives. It is permitted, and it carries the consent conditions described in the next section.

Therapeutic communication is the prohibited tier. Every one of these statutes defines it expansively. Vermont’s definition in 18 V.S.A. § 7115 covers direct interactions to understand or reflect a patient’s mental health condition, clinical guidance or intervention, offering reassurance or empathy in response to emotional distress, collaborating on treatment plans, and delivering feedback intended to promote growth. Rhode Island, Maine and Colorado use materially the same list. Read that list against any chatbot you have on your website and the answer usually becomes obvious.

Task Tier Permitted? Conditions that attach
Appointment scheduling and reminders Administrative Yes, all seven states Clinician retains responsibility for outputs
Billing and insurance claims Administrative Yes, all seven states Nevada requires independent accuracy review of output
AI scribe drafting session notes Supplementary Often, state by state Turns on recording or transcription, written consent, clinician review, HIPAA arrangement and vendor data use. Check the specific statute
Progress trend analysis across a caseload Supplementary Yes, with conditions Licensed professional review required; Maine requires anonymized data
Drafting a treatment plan for clinician review High risk Read your statute first Illinois, Colorado, Maine and Rhode Island all bar unreviewed plan generation. Do not assume clinician review cures it everywhere
Chatbot answering a client’s emotional message Therapeutic communication No Prohibited in all seven states
AI inferring a client’s emotional state Therapeutic communication No in Illinois Illinois Section 20 names emotion and mental state detection specifically

Three carve outs can rescue a tool you already use, though none of them is a general shield. Rhode Island’s chapter does not apply to an AI tool reviewed and cleared by the Food and Drug Administration or another federal agency that approves AI for health care. Vermont’s Act 156 preserves a professional’s use of AI tools that comply with the Health Insurance Portability and Accountability Act, provided the professional reviews and approves any mental health services, and it names FDA authorized software as a medical device and digital therapeutics when a professional prescribes or recommends them. Colorado excludes non diagnostic wellness tools that clearly disclose they are not a substitute for clinical care, and FDA authorized behavioral health tools on the same disclosure condition. Note the limit: FDA status can matter to a state exemption, but it does not by itself resolve consent, confidentiality, advertising or professional practice duties.

4. The consent rule most practices are getting wrong

Where Maine or Rhode Island requires consent for a covered AI use, a broad click through terms of use acceptance is unlikely to satisfy it. Both statutes define consent to exclude an agreement obtained through acceptance of a broad terms of use document that mentions artificial intelligence alongside unrelated information, or through a user hovering over, muting, pausing or closing content. That definition defeats exactly the workflow most practices adopted, which was to add an AI paragraph to the existing intake packet and treat the signature at the bottom as coverage.

The trigger is narrower than practices assume, and that is good news. In Rhode Island, Maine and Colorado, the written consent obligation attaches when the therapeutic session is recorded or transcribed. If your AI tool never touches the session itself, and only handles scheduling or claims, the specific consent requirement in those states is not triggered. If you run an ambient scribe, it is. Note also that these state consent duties are separate from HIPAA. A business associate agreement is not a substitute for statutory consent, and statutory consent is not a substitute for a business associate agreement.

Maine’s chaptered law is the most demanding on content. Before using AI for supplementary support in a recorded or transcribed session, the client must be informed in writing that AI will be used, of the specific purpose of the tool, and of how session data will be stored, retained, used for training and deleted when services end. That third element is a vendor question, not a clinician question, and most practices cannot currently answer it from their own records.

Two Maine provisions deserve a place in your policy. A licensee may not deny or refuse services to a client solely because the client declined consent to AI assisted supplementary support. And any client waiver of the section is contrary to public policy and void, so a broad release in your intake paperwork does not travel. Colorado reaches the same result from the other direction: a client’s refusal to give consent, or a later decision to revoke it, may not be used as a basis to deny psychotherapy services.

Colorado is also the most workable of the three on cadence. Its consent for recording or transcription is required only for the initial use of the AI system on or after the effective date, not for every subsequent session, unless the purpose or manner of use materially changes. Separately, Colorado requires written information about the AI prohibitions to be given to the client at initial contact, which is a disclosure duty independent of the recording consent.

5. Where the seven states actually differ

The seven states differ most on enforcement route and penalty size, which changes who can sue you and for how much. Illinois and Nevada set flat administrative penalties. Tennessee, Maine and Vermont route violations through consumer protection statutes, which in Tennessee and Vermont carries a private right of action. Rhode Island routes penalties through its existing health care confidentiality statute. Colorado works primarily through professional licensure.

State Law Effective Enforcement and penalty Distinctive feature
Illinois HB 1806, Public Act 104-0054 August 1, 2025 IDFPR investigates; civil penalty up to $10,000 per violation Bans AI detection of emotions or mental states
Nevada AB 406 July 1, 2025 Civil penalty up to $15,000 per violation; provider misuse is unprofessional conduct Also bars public schools from using AI for counselor mental health duties
Tennessee SB 1580, Tenn. Code Ann. 33-1-205 July 1, 2026 Consumer Protection Act violation; $5,000 per violation notwithstanding normal limits Narrowest of the seven; reaches advertising and representations only
Maine LD 2082, Public Law Chapter 687 July 29, 2026 Unfair Trade Practices Act violation; board discipline for licensees Consent may not be waived; services may not be denied for refusing consent
Vermont H.816, Act 156, 18 V.S.A. § 7115 June 17, 2026 Consumer Protection Act; Attorney General authority plus private remedies Express savings clause preserving HIPAA compliant and FDA authorized tools under clinician review
Rhode Island S 2197 Substitute A, R.I. Gen. Laws ch. 40.1-5.5 June 22, 2026 (on passage) Executive Office of Health and Human Services investigates; health care confidentiality penalties apply Express exemption for FDA cleared tools
Colorado HB 26-1195 August 12, 2026 Professional licensure and discipline, plus a Consumer Protection Act provision at C.R.S. 6-1-1705.2 Synchronous real time clinician, AI and client interaction required for any AI therapeutic communication

Three practical takeaways fall out of that table. First, Tennessee is the cheapest state to comply with and the easiest to violate, because Tenn. Code Ann. 33-1-205 only prohibits advertising or representing that an AI system is or can act as a qualified mental health professional. A single website sentence is the whole exposure. Second, Maine and Vermont look permissive because they carry no headline fine, but a consumer protection violation invites private plaintiffs and fee shifting, which usually costs more than a $10,000 administrative penalty. Third, Colorado’s synchronous requirement is the hardest operational constraint in the country, and it applies to every regulated psychotherapy professional in the state as of August 12, 2026.

These laws do not preempt one another and they do not follow the provider. A Vermont licensed counselor seeing a Colorado resident by telehealth should assume both states have something to say. This is the same multi state exposure problem we mapped in our analysis of patient intake chatbot compliance, and it has only gotten more layered since.

6. Your marketing language is the easiest violation to find

Marketing language is the easiest violation for a regulator to find because it is public, permanent and requires no patient complaint to discover. An investigator can open your website and confirm a violation in under a minute. That asymmetry is why the market facing provisions, not the clinical ones, are where small practices should look first.

Nevada is the most specific. AB 406 prohibits an AI provider from making, or knowingly programming a system to make, any representation that explicitly or implicitly indicates that the system can provide professional mental or behavioral health care, or that any component, feature, avatar or embodiment of the system is a therapist, counselor, psychiatrist, doctor or any similar term. Separately, it bars an unlicensed person from using the titles therapist, psychotherapist or counselor. Civil penalties reach $15,000 per violation.

California reaches the same conduct from the consumer protection side. AB 489, chaptered October 11, 2025 and effective January 1, 2026, added Chapter 15.5 to Division 2 of the Business and Professions Code. It prohibits a term, letter or phrase in the advertising or functionality of an AI system that indicates or implies the care, advice, reports or assessments are being provided by a natural person holding the appropriate license. The statute states that each use of a prohibited term is a separate violation, and the relevant healing arts licensing boards enforce it and may seek injunctive relief.

Colorado joined this group too, and it is easy to miss because it sits in the consumer protection code rather than the practice act. C.R.S. 6-1-1705.2 prohibits using any term, letter or phrase in the advertising, interface or outputs of an AI system that implies the output is provided by or equivalent to services from a licensed psychotherapy professional, or that represents the system provides psychotherapy services. It also bars representing that a user’s data is confidential in a way that would lead a reasonable user to believe it carries something comparable to therapist client privilege. That third prohibition is unusual and worth reading against your privacy page.

Practical translation for a small practice. The test is the overall impression of implied licensure, not any single word, so review your website, intake screens, chatbot personas, app store listings and paid search copy as a whole. Remove uses of therapist, counselor, clinician, psychotherapist or doctor to describe a software feature, and credential letters attached to a bot name. Look hard at imagery and interface design, such as a clinical avatar or a white coat, which can contribute to an implied licensure problem even though no single design choice is automatically unlawful. Replace “AI therapy assistant” with a plain description of the actual function, such as “appointment scheduling assistant” or “documentation assistant.”

GOVERNANCE INSIGHT

California is the one that expressly multiplies.

Business and Professions Code section 4999.9 states that each use of a prohibited term is a separate violation, so a single word repeated across a homepage, a services page, three blog posts and an intake screen is not one problem in California. Nevada, Illinois and Tennessee price their penalties per violation, but none of them defines a violation as each instance of a word, so do not assume the same arithmetic. Run the site wide text search either way.

7. Enforcement: who investigates and what it costs

Enforcement sits with four different kinds of body depending on the state, and only one of them is a professional licensing board. In Illinois, the Department of Financial and Professional Regulation has authority to investigate all suspected violations, and the department’s own announcement of the law states that confirmed violations result in a fine of up to $10,000 payable to IDFPR. In Rhode Island, the Executive Office of Health and Human Services has authority to investigate any actual, alleged or suspected violation and may promulgate implementing rules. In Utah, a state we return to below, the Division of Consumer Protection administers enforcement. In Vermont and Tennessee, the Attorney General and private plaintiffs both have standing.

The penalty numbers understate the real cost for a small practice. A $10,000 administrative penalty is survivable. A consumer protection claim with fee shifting, a licensure complaint disclosed on every credentialing application for the next decade, and a malpractice carrier that reprices at renewal are not comparable line items. Vermont made the linkage explicit by amending its unprofessional conduct statute at 3 V.S.A. § 129a, so the same facts generate a consumer protection exposure and a board exposure at once.

There is no meaningful enforcement record yet. The oldest of these laws is barely a year old and five took effect within the last three months. As of September 2026 we are not aware of any publicly announced agency action interpreting the boundary between supplementary support and therapeutic communication under these statutes. That uncertainty argues for documenting your reasoning now, while you can do it calmly, rather than reconstructing it later under an investigator’s timeline.

Two rulemakings are worth tracking. Maine’s chaptered law directs each affected licensing board to adopt implementing rules and designates them major substantive rules, which in Maine means legislative review. Vermont directed its Artificial Intelligence Advisory Council to report to four legislative committees by January 15, 2027 with recommendations for further legislative action. Both will move the line, and both are open to comment from practitioners.

Getting your AI governance in order

Dynamic Comply helps small and medium sized businesses build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001.

Start the free AI maturity self assessment

8. Your AI scribe contract is now a compliance document

Your AI scribe contract now has to answer questions the statutes ask of you, which means the vendor agreement has become part of your compliance file rather than a procurement artifact. Maine’s consent requirement obliges you to tell the client how session data is stored, retained, used for training and deleted when services end. You cannot make that disclosure truthfully unless the contract says it.

Ask for six things in writing before your next renewal. First, a plain statement of whether client session content is used to train models, including de identified or aggregated training use, since that is the term Maine requires you to disclose. Second, retention and deletion terms tied to termination of services, with a defined deletion window. Third, a signed business associate agreement, because an ambient scribe processing protected health information on your behalf is a HIPAA business associate regardless of what any state AI law says. Fourth, confirmation of whether any component holds FDA clearance or authorization, which may be relevant to the Rhode Island exclusion, the Vermont savings clause and the Colorado carve out, without resolving your other obligations.

Fifth, a written description of what the tool does with emotional or affective signals. Illinois specifically prohibits allowing AI to detect emotions or mental states, so a sentiment scoring feature that a vendor markets as a clinical insight is a compliance problem in Illinois even when the clinician never acts on it. Sixth, an accuracy review workflow, because Nevada requires a provider to independently review the accuracy of any report, data or information an AI system compiled, summarized, analyzed or generated for billing and session note purposes.

One contractual point deserves emphasis. Rhode Island’s statute says the licensed professional retains responsibility for clinical judgment and reasonable therapeutic oversight of the patient’s use of the system, but not for vendor controlled system design, algorithms or outputs. Colorado goes further and states that nothing in its section imposes liability on a licensee for defects or failures attributable to the developer or deployer. Neither provision eliminates your exposure, but both give you language to point at during negotiation.

9. The federal layer: FDA, the FTC, and the companion chatbot laws

The federal government has not enacted an AI therapy statute, but two agencies have moved in ways that shape what your vendors can offer. On November 6, 2025 the FDA convened its Digital Health Advisory Committee on generative AI enabled digital mental health medical devices, using a hypothetical prescription large language model therapy chatbot for adults with major depressive disorder as the worked example. Orrick’s analysis of the meeting reported that the committee signaled a risk based life cycle approach, with premarket clinical evidence using validated depression endpoints, controls for hallucination and model drift, human escalation pathways, and postmarket surveillance. Read that for what it is. An advisory committee meeting is not a rule, a final guidance, a clearance or an authorization, and it did not establish a pathway for any particular therapy chatbot.

The Federal Trade Commission moved earlier. On September 11, 2025 it issued 6(b) orders to seven companies operating consumer facing AI chatbots, seeking information on how they measure, test and monitor negative impacts on children and teens. A 6(b) order is an information gathering tool, not an enforcement action. It can feed a report, a rulemaking, consumer education or enforcement priorities, and it does not necessarily lead to a case against anyone.

Alongside the therapy statutes, a separate wave of companion chatbot laws now governs consumer facing emotional support tools. New York’s Artificial Intelligence Companion Models law took effect November 5, 2025 and requires operators to disclose that the user is engaging with AI rather than a human, with daily notifications or notification every three hours during continuing interactions, and to maintain a protocol that detects expressions of suicidal ideation or self harm and refers the user to crisis resources. Fenwick reports penalties of up to $15,000 per day, enforced by the Attorney General. Rhode Island passed a parallel Artificial Intelligence Companion Models Act as S 2195, which Nixon Peabody reports takes effect January 1, 2027 with civil penalties of up to $15,000 per day and annual attorney general reporting beginning July 1, 2027.

Utah is the separate regime flagged in section 1, and it is the model other states may copy. HB 452, effective May 7, 2025, regulates mental health chatbots without banning them. It requires clear and conspicuous disclosure that the chatbot is AI and not human before a user may access its features, again at the start of any interaction after seven days of non use, and any time the user asks. It restricts in conversation advertising and the sharing of individually identifiable health information, requires suppliers to file a written policy with the Division of Consumer Protection, and gives compliant suppliers a documented defense. The division director may impose an administrative fine of up to $2,500 per violation. Epstein Becker Green walks through the code sections at Utah Code 13-72a-101 through 13-72a-301 and 58-60-118.

The states are also converging on disclosure duties for health care AI generally, which is a separate obligation from the therapy line. Texas enacted a health care disclosure duty inside its broader AI statute, which we covered in our analysis of the Texas AI complaint portal, and Rhode Island’s S 2570 requires providers to notify patients when AI technology documents an in person or telehealth visit.

10. A 30 day compliance plan for a practice with no compliance staff

A practice with no compliance staff can close the highest risk gaps in about 30 days by working in three stages: inventory, language, then consent. This is a baseline that makes you defensible, not a full governance program, and it assumes a practice of roughly two to twenty clinicians in one or two states.

Days 1 to 10, build the inventory. List every tool that touches a client, including the ones you did not buy. That means your electronic health record’s newly enabled AI features, your ambient scribe, your website chat widget, your appointment reminder system, your intake form vendor and any general purpose assistant a clinician uses on their own account. For each one, write down what it does, whether it touches session content, whether it is recorded or transcribed, and which of the three statutory tiers it falls into. Practices routinely find between six and twelve tools when they expect four.

Days 11 to 18, fix the language. Run a text search across your website, intake documents, app listings, email templates and paid search copy for therapist, counselor, clinician, psychotherapist, doctor, diagnosis and treatment used to describe software. Rewrite each instance to describe the actual function. Check avatars and icons for implied clinical authority. This is the cheapest work in the plan and it closes the Tennessee, Nevada, California and Maine market facing exposure almost entirely.

Days 19 to 26, rebuild consent where it is actually required. This step applies to the tools your inventory flagged as touching a recorded or transcribed session, not to every tool you own. Scheduling and billing systems generally do not trigger these specific consent provisions. For the ones that do, pull the AI language out of your general intake packet and create a standalone, separately signed AI consent covering that AI will be used, the specific purpose of each tool, and how session data is stored, retained, used for training and deleted. Make it revocable in writing. Add a line to your scheduling workflow confirming that a client who declines is still seen, since both Maine and Colorado prohibit denial of services on that basis alone.

Days 27 to 30, close the vendor and documentation loop. Send the six question list from section 8 to every vendor on your inventory and file the answers. Write one page recording which tier you assigned each tool to and why, and have the clinical lead sign it. That page is the single most useful artifact you can hold if a board or an attorney general ever asks how you reached your conclusions, because none of these statutes has an enforcement record to reason from yet.

Where this goes next is predictable. The 2026 session produced five of these laws in states with little in common politically, and the same NIST AI RMF and ISO/IEC 42001 concepts of documented risk assessment, human oversight and vendor management sit underneath all of them. Build those habits once and the next three states are absorbable. Treat each statute as a separate fire drill and they will not be.

Talk to Ross about your AI governance needs

Every business has different AI governance requirements. Let us talk about yours.

Contact Dynamic Comply

Frequently Asked Questions

Which states ban AI therapy?

Seven states restrict artificial intelligence in mental and behavioral health care: Illinois, Nevada, Colorado, Maine, Rhode Island, Tennessee and Vermont. Illinois and Nevada acted in 2025 and the other five in 2026. Tennessee is the narrowest, reaching only advertising and representations that an AI system is or can act as a qualified mental health professional. Utah and California regulate related conduct through disclosure and impersonation rules rather than a licensure line.

Can my practice still use an AI scribe for session notes?

In many of these states, yes, but the conditions are state specific rather than uniform. Session note drafting falls into the supplementary support tier that Illinois, Colorado, Maine and Rhode Island define and permit. Where the session is recorded or transcribed, Colorado, Maine and Rhode Island require separate written consent identifying the tool and its purpose, and Maine also requires disclosure of how session data is stored, retained, used for training and deleted. In every case the clinician must review and approve the output, and a HIPAA business associate agreement is required on top of the state analysis.

What are the penalties for violating these AI therapy laws?

Illinois allows civil penalties up to $10,000 per violation enforced by IDFPR, and Nevada up to $15,000 per violation. Tennessee sets $5,000 per violation through its Consumer Protection Act. Maine and Vermont created no flat fine and instead made violations unfair trade practices, which allows private plaintiffs. Utah’s separate mental health chatbot law allows administrative fines up to $2,500 per violation.

Does a signed intake packet count as consent for AI use?

No. Rhode Island and Maine both define consent to exclude agreement obtained through acceptance of a general or broad terms of use document that describes artificial intelligence alongside unrelated information. Consent must be a specific, informed, voluntary written agreement that the client can revoke. Maine also voids any client waiver of the provision as contrary to public policy.

Do these laws apply if my practice is in a state that has not passed one?

Possibly. Maine, Vermont, Rhode Island and Nevada write their prohibitions around offering services to the public in the state rather than around where the provider sits, so a telehealth practice serving residents of those states should assume exposure. Colorado’s requirements attach to professionals regulated in Colorado. Review every state where you hold a license or see a client.

What should a small practice do first?

Fix the language on your website and intake screens. Marketing violations are public, require no patient complaint to discover, and are priced per instance in California, Nevada, Illinois and Tennessee. Removing therapist, counselor and similar terms from software descriptions closes the largest exposure in a few hours, before you touch consent forms or vendor contracts.

About the author

Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm based in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.

This article is provided for general informational purposes and reflects the state of the law as of September 2026. It is not legal advice. Regulations in this area are changing quickly. Confirm current requirements and consult qualified counsel before making decisions for your organization.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *