Search “can therapists use AI” right now and every result on page one answers the wrong question. The AI Overview, NPR, APA, Stanford HAI — all of them are talking about whether patients should confide in a chatbot instead of a human therapist. Not one of them tells a licensed clinician what they’re actually allowed to do with ChatGPT in their own practice. That gap matters more than it did even three months ago, because five states have now put real law behind the answer — with real penalties attached.
What Just Changed
Through most of 2026, “can I use AI in my practice” was a Colorado question. HB26-1195 passed in June and everyone in behavioral health watched it as a single-state pilot. That framing is out of date. As of this week, it’s a national compliance question with a consistent structure across every state that’s acted: Illinois, Colorado, Maine, Nevada, and Rhode Island have all enacted laws restricting AI in therapy, and Ohio and Pennsylvania have bills moving through their legislatures. A July 2026 tally from the Transparency Coalition counted 84 new state AI laws across 27 states so far this year — mental health is one of the areas states are moving on fastest, alongside anything touching regulated healthcare.
The pattern across every enacted law is close to identical, which is the useful news buried in what looks like a compliance headache: AI can handle your paperwork. It can’t run the session. Every state that’s legislated on this draws the same line — administrative and supplementary support is fine under your professional responsibility; independent therapeutic decisions, direct client communication, and unreviewed treatment plans are not. Once you understand that one distinction, the state-by-state variation is mostly about penalty amounts and consent paperwork, not about whether you can use AI at all.
This wave is also colliding with the week’s other big AI story. OpenAI’s GPT-6 Astra launched September 3 with the company listing “nursing care plans” and clinical documentation among the things the model can draft — under “welcome to the AGI era” headlines that are making plenty of clinicians nervous about where the line actually sits. The state laws below answer that question more precisely than any AI vendor’s marketing copy will.
The State-by-State Rules
Here’s what’s actually on the books, in plain language, as of September 4, 2026.
| State | Law | What’s banned | What’s allowed | Penalty |
|---|---|---|---|---|
| Illinois | WOPR Act (P.A. 104-0054) | AI making independent therapeutic decisions, engaging in direct “therapeutic communication,” generating unreviewed treatment plans, or detecting emotions/mental states | Administrative support (scheduling, billing) and supplementary support (notes, anonymized-data analysis) under full clinician responsibility | Up to $10,000 per violation, IDFPR civil penalty |
| Colorado | HB26-1195 (eff. Aug 12, 2026) | AI conducting therapeutic communication with a client unless the clinician, AI, and client interact synchronously in real time | Administrative/supplementary support; AI-generated recommendations if reviewed and approved by the clinician | Professional discipline + Consumer Protection Act consequences for misleading claims |
| Maine | LD 2082 (eff. July 29, 2026) | Providing, advertising, or offering therapy via AI to the public unless a licensed professional delivers it | Admin/supplementary support with written disclosure and client consent for any AI-recorded/transcribed session | Maine Unfair Trade Practices Act violation |
| Nevada | AB 406 (eff. July 2025) | AI systems marketed or made available as providing professional mental/behavioral health care without licensed supervision | Support tools where a licensed provider remains directly involved | Up to $15,000 per violation |
| Rhode Island | S 2197, Oversight of AI Technology in Mental Health Care Act (signed June 22, 2026) | AI’s independent therapeutic role; supplementary AI support without prescribed client notice and consent | Disclosed, consented AI support for documentation | Under the Act’s enforcement provisions (confirm current text before relying on it) |
| California | AB 1979, SB 903 (both passed legislature, pending final signature as of Sept. 4) | AI recording/transcribing psychotherapy sessions or triaging patients without informed consent; clinical decisions resting solely on AI output | Reviewed, consented documentation support; AI-informed decisions with independent clinician judgment | Under CMIA and standard licensing-board enforcement once signed |
| Ohio | HB 525 (pending) | Would bar licensed therapy professionals from using AI for therapeutic communication | Not yet enacted — check current status before relying on it | N/A — still a bill |
| Pennsylvania | HB 1993 / HB 2100 (pending) | Would regulate AI use by mental-health therapists and AI-driven mental-health chatbots | Not yet enacted — check current status before relying on it | N/A — still a bill |
A note on how to read this table: laws move. Ohio and Pennsylvania are bills, not statutes, as of this writing — track them through your state legislature’s bill-status page rather than treating “pending” as “settled.” For the five enacted laws, the core restriction (no unsupervised AI therapy, yes to reviewed documentation support) is stable enough to build a workflow around today.
Reading the Fine Print: What Each Law Actually Says
The table above is the summary. If you practice in one of these states, the exact wording matters more than the summary does — here’s what the statutes and bills actually say, beyond the headline.
Illinois’s WOPR Act is the most precisely worded of the group, which makes it the best reference even if you don’t practice there. It defines “therapeutic communication” broadly enough to cover more than a live session: it includes eliciting or reflecting a client’s thoughts and emotions, offering guidance or therapeutic strategies, providing emotional support or reassurance during distress, collaboratively setting or modifying treatment goals, and giving behavioral feedback meant to promote psychological growth. If an AI interaction does any of that directly with a client, it’s covered — regardless of whether it happens inside a formal “session.” The law explicitly carves out physicians (they’re covered by separate medical regulation), and it names the professions covered with unusual specificity: licensed clinical psychologists, clinical social workers, professional counselors, marriage and family therapists, certain substance-use counselors, music therapists, and advanced-practice psychiatric nurses, among others.
Colorado’s requirement for “synchronous” interaction is the detail most practices miss. HB26-1195 doesn’t just say a clinician has to review AI output eventually — it says that if AI is going to interact with a client in any form of therapeutic communication at all, the clinician, the AI, and the client all have to be present and interacting in real time together. An asynchronous AI chat with a client between sessions, even a well-intentioned “check-in bot,” falls outside what the law permits, no matter how closely you review the transcript afterward. Colorado’s law also does something the others don’t: it makes certain marketing claims a form of unfair trade practice — implying an AI tool is endorsed by, equivalent to, or provides the confidentiality of, a licensed professional’s services.
Maine’s law is the strictest on consent mechanics. Beyond requiring written, informed consent for AI-assisted recording or transcription, Maine requires the disclosure to cover how the collected session data will be stored, retained, used for training, and deleted once treatment ends — not just that AI is being used. A generic “we use AI-assisted tools” line doesn’t meet that bar; your consent form needs to actually answer the storage and training-data questions, which means you need to know the answers from whatever tool you’re using before you can write compliant paperwork.
Nevada’s AB 406 is the one most likely to catch a practice off guard, because its effective date (July 2025) predates most of the public conversation about this topic — a lot of Nevada practices have been technically covered for over a year without realizing it. The core prohibition targets AI systems marketed or made available as providing professional mental or behavioral health care without a licensed provider directly involved; the $15,000-per-violation ceiling is the highest of the five enacted laws.
California hasn’t finished the process yet, but it’s worth tracking closely because it’s legislating on three fronts simultaneously rather than one consolidated bill. AB 1979 folds AI-assisted health chatbots into the state’s existing medical-information confidentiality law (CMIA) — meaning a qualifying chatbot gets treated as a healthcare provider for privacy purposes, a different mechanism than the other states are using. SB 903 is the therapy-specific bill, closest in structure to Illinois and Colorado. AB 2575 is aimed at worker protections — it would require employers to explain any AI clinical-decision tool to the staff using it, and it bars retaliation against a clinician who overrides an AI recommendation. As of this writing both AB 1979 and SB 903 have passed both houses of the legislature and are in the engrossing/enrolling stage; neither had received the governor’s final signature.
The Workflow That’s Legal in Every State
Every enacted law — even the ones with different penalty structures and consent language — permits the same underlying pattern. If you build your AI use around this sequence, you’re inside the law in Illinois, Colorado, Maine, Nevada, and Rhode Island, and almost certainly inside whatever California and the pending states land on.
Step 1: De-identify before anything touches AI. Strip the client’s name, date of birth, address, and any other identifying detail from your notes before pasting them into any general-purpose AI tool like ChatGPT. Use a case number or initials internally, never a name. This step matters regardless of which state you’re in — HIPAA’s business associate rules apply everywhere, and de-identification is the fastest way to reduce your exposure before you even get to state-specific AI laws.
Expected result: a set of session notes with zero patient-identifying information, ready to hand to an AI tool without creating a HIPAA disclosure.
Step 2: Let AI draft — never decide. Ask the AI to turn your de-identified session notes into a structured SOAP or DAP note. This is exactly the “supplementary support” every state law permits, as long as you — the clinician — remain the one who reviews and finalizes it.
Worked example prompt: “Convert these de-identified session notes into a SOAP note. Subjective: client reports increased anxiety around a upcoming return-to-work date, sleep disruption 3-4 nights/week. Objective: client presented tearful, speech pressured at times, oriented x4. Assessment and Plan sections should reflect standard clinical language for generalized anxiety with an occupational stressor. Do not add any clinical judgment I haven’t given you — flag anything you’re inferring rather than stating.”
Expected result: a formatted note draft you can review in under two minutes, versus the 8-10 minutes most clinicians report writing one from scratch.
Step 3: Review and sign — every time, no exceptions. Read the draft. Correct anything that doesn’t match your actual clinical judgment. Sign or initial it as the author of record. This is the step that satisfies every state’s “clinician retains full responsibility” language, and it’s also just good clinical practice — AI notes drift toward generic phrasing if you don’t check them.
Step 4: Get informed consent before any AI touches a recording or transcription. If you’re using AI to transcribe or record any part of a session — not just to draft notes afterward — every enacted state law requires written, informed, specific consent before you do it. Illinois defines this precisely: consent buried in a general terms-of-use document doesn’t count, and it must be revocable. Build a one-page consent form into your intake packet now, before you need it mid-session.
Step 5: Never let AI touch scheduling-adjacent client communication that looks therapeutic. Appointment reminders and billing questions are fine. A client asking “I’m having a hard week, can we move my appointment up?” followed by an AI-drafted empathetic response is exactly the “therapeutic communication” every state bans an AI from handling independently. Route anything with emotional content back to a human — you or your front-desk staff, not the AI you use for scheduling.
What This Means for You
If you’re a solo therapist in Illinois, Colorado, Maine, Nevada, or Rhode Island: You’re already covered by an enacted law with real penalties. Build the five-step workflow above into your practice this week, and add the written consent language to your intake forms if you haven’t already — this is the highest-penalty gap for solo practitioners who are otherwise compliant.
If you’re in a state without an enacted AI-therapy law yet: The five-step workflow is still your safest default. HIPAA’s de-identification and business-associate requirements apply regardless of state AI legislation, and building the habit now means you’re not scrambling when your state’s version passes — which, given the pace of 2026 legislation, is a matter of when, not if.
If you’re a clinical social worker or counselor: The Illinois and Colorado laws explicitly name your license category, not just psychologists and psychiatrists — read the statutory language for “licensed professional” carefully rather than assuming a narrower medical-doctor-only scope.
If you run a group practice: Standardize the consent form and the AI-note workflow across every clinician in your practice, not just the ones who happen to use ChatGPT already. A practice-wide policy is also your best defense if a regulator ever asks how you’re ensuring compliance — “we have a written policy every clinician follows” is a materially stronger answer than “each therapist does their own thing.”
If you’re a supervisor or clinical director: Add a state-law-compliance line item to your next staff training. Several of these laws (Illinois in particular) carry per-violation penalties that scale with the number of clients affected, so a practice-wide gap is a practice-wide liability, not an individual one.
If you’re weighing a dedicated AI scribe tool (Mentalyc, Upheal, DeepCura) against doing it yourself with ChatGPT: The paid tools handle de-identification and consent-tracking automatically, which is worth the subscription if you see high volume. If you’re a solo practitioner with a manageable caseload, the five-step manual workflow above costs nothing and takes about the same two minutes of review time per note.
If your state has a pending bill (Ohio, Pennsylvania) you’re watching: Don’t wait for it to pass to start the safe workflow — the administrative/supplementary-support pattern is what every state has converged on, so building it now means the eventual law finding you already compliant, not scrambling to retrofit a practice.
Edge Cases and What’s Actually Tripping People Up
“Most clinics still don’t know this is already on the books.” This is a direct quote from a healthcare compliance account tracking these laws, and it’s the single biggest risk right now — not malicious non-compliance, but genuine unawareness. Illinois’s WOPR Act has been in force since August 2025; a lot of practices are only now realizing it applies to them.
The HIPAA layer that exists whether or not your state has an AI law. If any tool you use to process patient information — including a general ChatGPT account — creates, receives, or transmits protected health information (PHI), federal guidance treats that tool as a HIPAA business associate. That means you need a signed Business Associate Agreement (BAA) before any identifiable patient data touches it, encryption or privacy settings notwithstanding. A standard consumer ChatGPT account does not have a BAA. OpenAI does offer HIPAA-eligible products (ChatGPT for Healthcare, ChatGPT Enterprise with a Regulated Workspace, specific API configurations) — but only those specific, BAA-covered products, not your personal or default account. If you want to use AI with anything beyond fully de-identified text, confirm you’re on one of the eligible, BAA-covered products first.
The Kaiser walkout story is a preview of a bigger fight. In April 2026, therapists at Kaiser in Northern California walked off the job over what they described as AI-driven systems replacing licensed clinicians at the front door of care — early screening shifted to scripted operators and apps, and charting sped up in a way staff said turned care into a volume business. That’s a labor and clinical-quality dispute, not a legal violation under the laws above, but it’s the kind of pressure that’s likely shaping how aggressively regulators enforce the new statutes.
A Brown University study found real problems when AI acts as the therapist, not the note-taker. Licensed psychologists reviewed transcripts of ChatGPT responding to simulated clients and found 15 violations of standards every human therapist is legally required to follow — including what researchers termed “deceptive empathy,” where the model uses trust-building language (“I understand,” “that must be really hard”) without any of the accountability structure a licensed clinician carries. This is exactly the harm the state laws are trying to prevent, and it’s worth knowing the research exists if a client ever asks you whether AI therapy is “basically the same thing.”
Consent language buried in a general terms-of-use document doesn’t count. Several states, Illinois most explicitly, define acceptable consent as clear, affirmative, specific, written, and revocable — not something a client agreed to by using your practice’s booking software. If your current intake paperwork has a generic “we may use technology to assist your care” line, that’s not sufficient under the newer laws. Write a specific line about AI-assisted documentation and get it signed separately.
Don’t assume a note-taking app’s marketing claims mean it’s automatically compliant. A paid AI scribe tool can still put you out of compliance if you skip the consent step or don’t review its output before it goes in the chart. The tool doesn’t create the compliance — your workflow around the tool does.
What This Can’t Fix
These laws don’t resolve the “is AI therapy effective” debate. They regulate what a licensed professional can delegate to AI in their own practice. They say nothing about the separate, ongoing debate over whether AI companion apps and chatbots are appropriate substitutes for therapy for people who can’t access or afford a human clinician — a real access problem these laws don’t touch.
Compliant documentation doesn’t guarantee accurate documentation. An AI-drafted note that you reviewed and signed is legally sound under every state’s framework, but “legally sound” and “clinically accurate” are different bars. AI models still hallucinate details and generalize toward common phrasing — the review step in the workflow above exists precisely because the law assumes, correctly, that AI output needs a human check.
State law doesn’t override your professional ethics board. Being compliant with Illinois’s WOPR Act doesn’t automatically satisfy APA, NASW, or your state licensing board’s separate ethical guidance on AI use, which in some cases is stricter than the statute. Check both.
None of this settles the employment-pressure question. The Kaiser dispute reflects a real tension between AI-driven efficiency and clinician workload that state consent laws don’t address — they regulate what AI can do in a session, not how aggressively an employer can push AI-assisted efficiency onto staff.
These protections apply to licensed professionals — not to every AI product marketed at people in distress. A general AI companion app operating outside a clinical relationship isn’t covered by these therapy-specific statutes the same way a licensed therapist’s practice is; that’s a separate, ongoing regulatory gap several of these same states are also working on.
FAQ
Can therapists use ChatGPT for session notes? Yes, in every state with an enacted AI-therapy law, as long as you de-identify the information first, review and finalize the AI’s draft yourself, and get informed consent if you’re using AI to record or transcribe the actual session.
Is AI banned from therapy entirely in any state? No enacted state law bans AI from a therapy practice outright. Every one — Illinois, Colorado, Maine, Nevada, Rhode Island — permits administrative and supplementary support. What’s banned is AI independently delivering the therapeutic communication itself.
What counts as “therapeutic communication” under these laws? Illinois defines it broadly: any verbal, nonverbal, or written interaction intended to diagnose, treat, or address mental, emotional, or behavioral concerns — including eliciting a client’s feelings, offering emotional support or reassurance, or collaboratively setting treatment goals. If an interaction sounds like something a therapist would say to a client mid-session, it’s likely covered.
Do I need a client’s written consent to use AI for notes? You need written consent specifically if AI is recording or transcribing a session. For drafting notes from your own de-identified summary after the fact, most states don’t require a separate consent form, though disclosing your practice’s general AI use in your intake paperwork is good practice regardless.
What’s the penalty if I get this wrong? It varies by state — up to $10,000 per violation in Illinois, up to $15,000 in Nevada, professional discipline in Colorado, and Unfair Trade Practices Act consequences in Maine. Penalties are typically calibrated to harm and circumstances, not automatic maximums, but they’re real enough to take seriously.
Is a paid AI note-taking tool like Upheal or Mentalyc automatically compliant? No tool is automatically compliant — compliance comes from your workflow (de-identification, review, consent), not the software. Paid tools can make parts of that workflow easier, but they don’t remove your responsibility to review output and secure proper consent.
Does HIPAA apply on top of these state laws? Yes, always, regardless of which state you’re in or whether it has an AI-specific law yet. If any AI tool processes identifiable patient information, you need a Business Associate Agreement covering that specific product before you use it that way.
What about GPT-6 Astra — does it change any of this? No. GPT-6 Astra’s marketing lists clinical documentation among its capabilities, but the legal framework above governs how any AI model — GPT-5.6, GPT-6 Astra, Claude, Gemini — can be used in a therapy practice. A more capable model doesn’t loosen the “AI drafts, clinician decides” rule.
Is Ohio’s or Pennsylvania’s bill going to pass? Unknown as of this writing — both are still bills moving through their state legislatures, not enacted law. Track them through your state legislature’s official bill-status page rather than a news summary, since legislative timelines shift.
What should I do if my state hasn’t legislated on this yet? Build the five-step workflow above anyway. It’s the pattern every enacted law has converged on, HIPAA’s requirements apply regardless of state AI legislation, and adopting it now means you won’t need to scramble when your state’s law lands.
The Bottom Line
Five states have turned “can I use AI in my practice” from a hypothetical into statute, and the pattern across all of them is more forgiving than the headlines suggest: draft with AI, decide as the clinician, disclose when you’re recording, and you’re compliant almost everywhere. The bigger risk right now isn’t the law itself — it’s the practices that don’t know it exists yet. If you want the full compliant workflow built out lesson by lesson, with the exact de-identification and documentation habits that hold up under every state’s framework, our AI for Therapy Notes & HIPAA Workflow course walks through it step by step, and Therapists and Counselors covers the broader practice. Free to start, Pro for the full path.
Sources
- Illinois General Assembly — Public Act 104-0054 (WOPR Act), effective Aug. 1, 2025
- Taft Law — New Illinois Law Restricts AI Use in Therapy Sessions
- Colorado General Assembly — HB26-1195, Psychotherapy Artificial Intelligence Restrictions
- Maine Legislature — LD 2082, P.L. 2025 ch. 687
- Transparency Coalition — 84 New AI Laws Enacted in 27 States in 2026 (Mid-Year Report, July 21, 2026)
- Transparency Coalition — AI Legislative Update, September 4, 2026
- APA — Discussing AI Use in Therapy
- APA — Topline Data Tables for APA’s 2026 Chatbots and Mental Health Survey
- HHS Office for Civil Rights — Guidance on HIPAA & Cloud Computing
- NPR — Therapists are using AI to take notes (May 26, 2026)
- Baker Donelson — Illinois Passes Extensive Law Regulating AI in Behavioral Health
- Brown University study on ChatGPT-as-therapist ethical violations, cited via X/Twitter research thread (@heynavtoor), March 2026
- Reports on the April 2026 Kaiser Northern California therapist walkout over AI-driven screening, via X/Twitter (@rohanpaul_ai)
- Healthcare compliance commentary on state AI-therapy law penalties, via X/Twitter (@jvjinfinity), August–September 2026