AI Therapy Chatbot Laws 2026: State Bans on AI Mental Health Services
Most AI regulation so far has demanded disclosure, documentation, or an audit. The new state mental-health statutes do something different: they prohibit the conduct outright. An AI system cannot provide therapy in Illinois, and a product that drifted from "wellness companion" into assessment and treatment may already be over the line.
A Different Kind of AI Law: Prohibition, Not Paperwork
The dominant pattern in AI regulation is procedural. The EU AI Act asks for risk management systems and technical documentation. Bias audit laws ask for an audit and a published summary. Privacy statutes ask for notice and opt-outs. In each case, a company that does the work can keep shipping the product.
The state AI mental-health statutes enacted through 2025 and taking effect into 2026 are structurally different. Illinois' framework prohibits AI systems from providing therapy or psychotherapy services and from making independent therapeutic decisions, while allowing AI in administrative and supplementary roles under a licensed professional's supervision. Nevada restricted AI systems from holding themselves out as capable of providing professional mental or behavioral health care. Utah took a lighter approach, focused on disclosure that the user is interacting with AI and on limits around the use of conversation data for advertising. There is no compliance filing that unlocks the prohibited conduct in the strictest states — the conduct itself is off the table.
Where Products Cross the Line Without Meaning To
Risk: Naming and marketing that claims a clinical role
RISKCalling a product an AI therapist, counselor, or psychologist, or describing it as treatment for anxiety or depression, is the fastest route into a statute's coverage. Regulators read the marketing page and the app store listing, and those pages are usually written by people who never saw the licensing analysis.
Risk: Symptom assessment flows that produce a label
RISKA conversational flow that walks a user through screening questions and reports back that they appear to have a condition is performing an assessment. It does not stop being an assessment because the output is phrased as a suggestion or hedged with a disclaimer.
Risk: Adaptive therapeutic interventions with no human in the loop
RISKDelivering a structured intervention — a CBT-style protocol, exposure exercises, a treatment plan — and adjusting it based on the user's reported progress is the core of what these statutes describe as an independent therapeutic decision.
Risk: No crisis escalation path
RISKWhen a user discloses self-harm intent, a product without reliable detection, immediate routing to human crisis resources, and a durable log of the exchange has both a regulatory exposure and a liability exposure it cannot reconstruct after the fact.
Mitigant: Licensed-professional supervision for clinical features
MITIGATESWhere the statutes leave room, it is for AI operating in a supporting role under a licensed human — drafting notes, handling scheduling, surfacing information for a clinician's judgment. Designing clinical features so a licensed professional owns the decision keeps the product inside that carve-out.
Mitigant: State-level availability controls
MITIGATESBecause licensing law follows the user's location, restricting clinical-adjacent features by state is a legitimate and effective control. It requires knowing where users are, which means the geolocation and account-state logic becomes a compliance dependency, not just a product setting.
The Wellness Boundary Is a Product Decision, Not a Disclaimer
Teams frequently assume a terms-of-service line stating the product is "not a substitute for professional care" resolves the question. It does not. Licensing analysis looks at what the system actually does with a user: whether it evaluates them against clinical criteria, whether it applies a therapeutic technique, and whether it modifies that technique in response to their answers. A disclaimer sitting under a flow that does all three describes the product inaccurately rather than protecting it.
The safer architecture keeps the AI on the education-and-referral side of the line: psychoeducational content, mood and journaling tools that reflect data back without interpreting it clinically, structured prompts that do not adapt into an intervention, and prominent routing to human providers and crisis lines. That product is still useful, and it is materially easier to launch in all fifty states.
Pre-Launch Checklist for Mental Health AI Features
Audit the naming and marketing copy first
Review the app store listing, landing page, and in-product labels for any claim of therapy, counseling, treatment, or clinical competence. This is the cheapest fix and the most commonly cited evidence.
Map each conversational flow to diagnose / treat / neither
Walk every scripted flow and system prompt and classify what it does. Flows that assess against clinical criteria or deliver an adaptive intervention need either removal, licensed supervision, or state-level gating.
Build and test a crisis escalation path
Detection of self-harm or crisis language should immediately surface human crisis resources and stop therapeutic-style engagement. Test it against real phrasings, not keyword lists, and log every trigger.
Add a persistent AI disclosure
Disclose that the user is interacting with an AI system at the start of the session and keep it visible, satisfying the disclosure-oriented statutes and reducing the risk a user believes they are talking to a clinician.
Know where your users are
State-by-state availability controls only work if account state or geolocation is reliable. Treat that data as a compliance dependency with the same rigor as billing address verification.
Constrain conversation data use
Mental health conversation content should be excluded from advertising, third-party sharing, and — unless separately and clearly consented to — model training. Several statutes speak directly to this, and it is a foreseeable enforcement target.
Frequently Asked Questions
Which states restrict AI from providing therapy?
Illinois enacted the most restrictive framework, barring AI from providing therapy or psychotherapy services and from making independent therapeutic decisions while permitting administrative and supplementary use under a licensed professional. Nevada restricted AI systems from holding themselves out as providing professional mental or behavioral health care, and Utah imposed disclosure and data-use requirements on mental health chatbots. A nationally available product has to meet the strictest applicable standard.
Does a general-purpose AI assistant fall under these laws?
These statutes target systems held out as providing mental or behavioral health services, not every model capable of discussing emotions. Positioning and configuration are what pull a general-purpose model inside the definition: a clinical name, treatment marketing, or a flow that assesses symptoms and delivers an intervention.
Where exactly is the line between wellness and therapy?
Diagnosis and treatment. Journaling, mood tracking, breathing exercises, psychoeducation, and referrals are wellness. Evaluating a user against diagnostic criteria, assigning a condition, delivering a structured therapeutic protocol, or adapting that protocol to their responses is regulated conduct no matter what the product calls itself.
Does a disclaimer that we are not a substitute for professional care protect us?
Not on its own. Regulators and courts look at what the system does in the conversation, not what the terms of service assert. A disclaimer sitting above an assessment-and-intervention flow is evidence that the company understood the risk, not evidence that it avoided it.
We are not headquartered in a restricting state — are we exposed?
Very likely, yes. Professional licensing generally follows the location of the person receiving services. If a resident of a restricting state can use the product, the state's law is in play regardless of where the company sits, which is why state-level feature gating is a practical compliance measure.
Can we use AI at all in a licensed clinical practice?
Yes, and that is the space the statutes deliberately preserve. Documentation drafting, intake scheduling, administrative workflows, and surfacing information for a clinician to evaluate remain available. The requirement is that a licensed human, not the model, owns the therapeutic decision.
Find AI Compliance and Governance Tools on RatedWithAI
RatedWithAI reviews AI compliance and governance platforms — including tools for logging model conversations, enforcing guardrails and escalation paths, and documenting the human-in-the-loop controls these statutes expect.
Explore AI Legal & Compliance Guides