The fastest-moving corner of US health-AI law has nothing to do with the FDA. It is the state-by-state regulation of AI in mental and behavioral health — where chatbots reached vulnerable users years ahead of any statute, and where legislatures are now writing the rules in two distinct waves. This tracker maps the enacted laws and the 2026 pipeline, with each row tied to a statute text or a primary tracker. It is a status page for orientation, and state law changes quarterly; confirm the live position with counsel before building or deploying. As of August 2026.
Why are states regulating AI therapy now?
Because usage ran ahead of oversight. Conversational systems built on the modern clinical LLM stack are being used for emotional support at scale, a pattern we examined in our guide to AI in psychiatry and mental-health chatbots — along with the safety incidents, from hallucinated advice to missed crisis language, that made legislators move; the deployment scale behind the urgency is visible in our AI in healthcare statistics. The Future of Privacy Forum's mapping of the 2026 session counts 98 chatbot-specific bills across 34 states, plus three federal proposals, and notes the interest is bipartisan — 53 percent of bills introduced by Democrats, 46 percent by Republicans 1. MultiState's read of the same landscape is that lawmakers are shifting from broad AI acts toward "narrower, use-case-driven regulation, with chatbots at the center of that transition" 6.
Which states restrict AI from delivering therapy?
Illinois moved first with the Wellness and Oversight for Psychological Resources Act — Public Act 104-0054, enacted in August 2025 — the first US statute to explicitly define and regulate AI in psychotherapy services 2. Its structure is a three-tier permission model: AI may perform administrative support (scheduling, billing, general communications) and, with explicit patient consent, supplementary support (records, drafting notes from transcripts) — but AI may make no independent therapeutic decisions, engage in no direct therapeutic communication, and perform no emotion detection 2. "Therapeutic communication" is defined broadly, reaching any interaction intended to diagnose, treat, or address mental, emotional or behavioral health concerns 2. The state licensing regulator enforces, with civil penalties up to $10,000 per violation 24.
Nevada's AB 406, passed in June 2025, prohibits offering AI systems designed to provide services that would constitute the practice of professional mental or behavioral healthcare — and prohibits representing that an AI system can provide such care. Licensed providers may still use AI for administrative functions, with penalties up to $15,000 per violation, and public schools may put no AI in the role of counselor or school psychologist 41.
The 2026 wave broadened the map. The Transparency Coalition's July 2026 count of the year's enacted health-AI laws records five more states — Colorado, Maine, Rhode Island, Tennessee and Vermont — prohibiting AI chatbots from providing therapy services independently 5. The same count finds seven states (Alabama, Colorado, Georgia, Illinois, Iowa, Utah and Washington) restricting AI in insurers' authorization decisions with human-clinician-review requirements — the state-level echo of the fight over AI prior authorization in Medicare — and Iowa requiring patient consent before appointments are recorded for AI transcription, a duty familiar from our consent-by-jurisdiction guide 5.
Which states regulate rather than restrict?
Utah's HB 452, from March 2025, is the template for the disclosure lane: mental-health chatbot suppliers must clearly disclose that the user is talking to AI, may make no sale or sharing of individually identifiable health data, and face marketing restrictions — with a documented-compliance pathway that functions as an affirmative defense 41.
California's SB 243 — Chapter 677, approved 13 October 2025 — regulates companion chatbots rather than therapy as such 3. Where a reasonable person could be misled into believing they are talking to a human, the operator must issue "a clear and conspicuous notification" that the chatbot is artificial; known minors get AI disclosure and additional safeguards; operators must maintain and publish a protocol preventing the production of suicidal-ideation, suicide or self-harm content; and from 1 July 2027 operators report annually to the state Office of Suicide Prevention 3.
New York, New Hampshire, Maine and Utah enacted the rest of the 2025 chatbot-safety statutes — New York's S-3008C and New Hampshire's HB 143 with disclosure-and-safety cores, Maine's LD 1727 on chatbot transparency 1. The recurring pattern across all of them: tell users it is AI, protect minors, route crisis language to human help, and restrict data use 16.
| State | Law | Enacted | Approach |
|---|---|---|---|
| Illinois | PA 104-0054 (WOPR Act) | Aug 2025 | Therapy restricted to licensed professionals; AI limited to administrative/supplementary roles; $10k penalties 2 |
| Nevada | AB 406 | Jun 2025 | AI-provided mental healthcare prohibited; admin use allowed; $15k penalties 4 |
| Utah | HB 452 | Mar 2025 | Mental-health chatbots permitted with AI disclosure, data-sale ban, marketing limits 4 |
| California | SB 243 (Ch. 677) | Oct 2025 | Companion chatbots: disclosure, minor safeguards, self-harm protocol, annual reporting 3 |
| New York; New Hampshire; Maine | S-3008C; HB 143; LD 1727 | 2025 | Chatbot disclosure and safety statutes 1 |
| Colorado, Maine, Rhode Island, Tennessee, Vermont | 2026 statutes | 2026 | AI chatbots restricted from independently providing therapy 5 |
What does the 2026 session signal?
Three themes dominate the pending-bill pile: transparency and non-human disclosure, age verification and minors' access controls, and professional licensure restrictions — with content safety, data protection and liability mechanisms close behind 1. For health systems, the direction of travel is clear enough to act on: assume disclosure duties everywhere, assume therapy-delivery restrictions in a growing minority of states, and assume the utilization-review restrictions will keep spreading alongside the federal fight we track in our global regulation tracker.
What do these laws mean for builders and health systems?
For product teams, scope is destiny: a wellness product that drifts into therapeutic claims crosses, in at least seven states, from consumer software into unlicensed practice. Marketing copy is part of the regulated surface — Nevada reaches representations about capability, and Utah reaches advertising 4. Disclosure design, crisis routing and audit trails are now statutory features, and the underlying engineering disciplines — instructing and evaluating the model against harmful-content production — look like the evaluation practices and red-flag reviews the field already knows from clinical AI.
For health systems, the restriction states still permit plenty: triage and intake tools compared in our patient triage chatbot guide, documentation support and patient-communication drafting, and clinician-reviewed drafting under HIPAA's rules for LLMs — provided a licensed professional stays between AI output and the patient, the human-in-the-loop structure these statutes effectively mandate. Liability when the structure fails is the unsettled frontier we map in liability when clinical AI errs; governance ownership belongs with your AI committee, exactly as for the scribe state laws this tracker parallels.
Sources and method
State-law claims are tied to the statute text where we could open it — the chaptered text of California SB 243 on the Legislature's site 3 — and otherwise to a peer-reviewed legal analysis of the Illinois Act 2, the Future of Privacy Forum's 2026 legislative mapping 1, the Transparency Coalition's July 2026 enacted-law count 5, MultiState's chatbot-regulation tracking 6, and Blueprint's compliance summaries of the Illinois, Nevada and Utah statutes 4. Where sources characterize a law rather than quote it, we say so, and bill-by-bill status changes faster than any page — verify current state law with counsel before relying on a row. We revisit this tracker every ninety days and sooner when a statute is enacted. Current as of 1 August 2026.