A Complete Guide to AI Healthcare Laws in 2026
Who Decides? The States Are Answering
In previous coverage of artificial intelligence in medicine, I kept returning to the same question: Who decides? Who has the authority to approve a procedure, deny a claim, diagnose a condition, or prescribe a treatment when an algorithm is involved? That question was mostly theoretical, debated in conference panels and white papers while federal lawmakers waited for consensus.
The waiting ended in 2026. State legislatures stopped asking and started writing. By the end of this year's legislative sessions, more than two dozen new laws and regulations across eighteen states will have redrawn the boundaries of what AI may do in healthcare. Additionally, there is Federal legislation in process that may conflict with everything states have done so far. Here I survey the full landscape in the following categories:
Prior Authorizations
Therapy
Consent and Disclosure
Chatbot Safety
Professional Licensing
As always, if you enjoy reading, subscribe and tell a friend.
Sam
Prior Authorizations
The most active legislative front in 2026 was prior authorization. Seven states enacted laws that draw a hard line between AI assistance and AI decision-making for coverage denials. Two additional states also took related approaches targeting claims downcoding and oversight reporting.
Alabama SB 63, enacted on April 17, requires health insurers to disclose their use of AI, base authorization decisions on a patient’s individual medical history, and ensure that any denial is issued by a licensed professional. It is similar to the disclosure-plus-human-review framework seen elsewhere, but it explicitly ties authorization decisions to individual medical records rather than group data.
Colorado HB 1139, signed June 2, prohibits insurers from basing a denial solely on group data or algorithms and requires a licensed clinician to review any adverse decision. The subtle but critical distinction here is the explicit ban on group-level data as the basis for individual denials, a protection Alabama and Washington do not spell out as directly.
Georgia SB 444, enacted May 5, is one of the shortest and most direct statutes in this category: a blanket prohibition on coverage decisions based solely on AI systems or software tools. It is nearly identical in spirit to Iowa’s approach but without Iowa’s explicit carveout allowing AI to conduct initial screening.
Illinois SB 3114, awaiting the governor’s signature, is the only law in this category that targets downcoding, the practice of reducing reimbursement codes, rather than prior authorization denials. It prohibits AI from bypassing provider documentation to downgrade claims and requires a natural person to review any downcoding determination.
Indiana HB 1271, enacted March 4 and effective July 1, is the only law regulating AI on both sides of the transaction: it prohibits insurers from using AI as the sole basis for downcoding and bars providers from using AI to submit claims without human review. It bridges the gap between utilization-review laws and claims-integrity laws.
Iowa HF 2635, enacted May 13, creates a two-step process: AI may screen prior authorization requests, but only a human may deny, delay, or downgrade them. The statute is nearly identical in structure to Utah’s approach but with less detail on time limits and validity periods.
Maryland HB 1563, enacted April 28, takes an oversight approach rather than a direct prohibition. It requires insurers to file quarterly reports on AI-assisted adverse decisions and allows the insurance commissioner to investigate spikes in denials, particularly for emergency department services. It is the only authorization-related law focused on regulatory monitoring rather than rewriting decision-making rules.
Utah SB 319, enacted March 19, requires disclosure of AI use in preauthorization, mandates independent medical judgment by reviewers, and sets minimum validity periods for chronic condition authorizations. It is the most procedurally detailed of the authorization statutes, paired with a separate scope-of-practice law passed the same week.
Washington SB 5395, enacted March 23, expands the state’s existing prior authorization framework and explicitly bars AI from modifying care, not just denying it. This is a broader prohibition than most, covering any adverse modification of a treatment plan.
Therapy
While prior authorization laws dominated, therapy bans consumed the headlines. Six states enacted statutes prohibiting AI from providing psychotherapy or representing itself as a mental health professional. Most took effect in 2026 or will take effect in 2027.
Colorado HB 1195, enacted June 3, is the most comprehensive therapy ban in the country. It prohibits unlicensed AI chatbots from offering psychotherapy and also restricts licensed psychologists, counselors, and social workers from using AI to provide independent therapeutic services. It is the only law that explicitly limits both the unlicensed and licensed sides of the equation.
Maine LD 2082, enacted April 13, prohibits AI from providing therapy or psychotherapy and classifies offering therapy via AI without a license as an unfair trade practice. It also adds a patient-consent requirement for ambient listening and AI-powered recording during sessions. It is nearly identical in scope to Nevada’s law but adds the recording consent provision.
Nevada AB 406, enacted in 2023 and effective July 1, 2025, was the first therapy-bot ban in the nation. It applies to any AI system in Nevada, including telehealth platforms, and imposes civil penalties of up to $1,500 per violation. It served as the model for several 2026 statutes, including Maine’s and Rhode Island’s.
Rhode Island H 7349 / S 2197, enacted June 22, contains a dual prohibition: unlicensed AI may not practice therapy, and licensed providers may not use AI for independent therapeutic decisions or treatment plans. It is nearly identical in structure to Colorado’s law but lacks the explicit licensed-provider restrictions seen in Colorado’s statute.
Tennessee SB 1580, enacted April 1, prohibits developing or deploying AI systems that advertise or represent themselves as qualified mental health professionals. It treats such misrepresentation as a deceptive practice under state consumer protection law. It is narrower than Colorado’s ban, and targets the advertising and representation rather than the therapeutic act itself.
Vermont H 816, enacted June 17, safeguards individuals seeking mental health services by ensuring delivery by professionals rather than independently by AI systems. The wording lacks the explicit title protections and civil penalties seen in Nevada and Rhode Island. It is the least prescriptive of the therapy bans.
Consent and Disclosure
Four states enacted or implemented disclosure requirements in 2025 and 2026, creating a patchwork of transparency obligations that providers and insurers now must navigate.
Arizona Board of Behavioral Health Examiners adopted regulations in November 2025, effective January 1, 2027, requiring behavioral health professionals to obtain and document informed consent before providing services involving AI. It is the only regulatory (non-statutory) entry in this survey and applies only to behavioral health, making it narrower than California’s statewide disclosure laws.
California AB 3030, enacted in 2024 and effective January 1, 2025, was the first statewide disclosure law in the nation. It requires any generative AI communication to a patient to include a clear disclaimer that the message was generated by AI. AB 489, enacted in 2025 and effective January 1, 2026, goes further by prohibiting AI systems from presenting themselves as licensed medical professionals. Together, these two laws create a layered transparency framework that no other state has fully replicated.
Louisiana HB 475, enacted June 2, requires verbal disclosure of any recording device or AI transcription before recording any clinical visit. It is the only law in the country that mandates verbal (not just written) disclosure for AI transcription, and it applies to all healthcare settings including telehealth.
Texas SB 1188, enacted in 2025 and effective September 1, 2025, is the most permissive framework in this category. It explicitly allows AI to diagnose and treat patients, provided the patient is informed and the Texas Medical Board has reviewed the technology. It is the only state that affirmatively authorizes AI clinical decision-making rather than merely restricting it.
Chatbot Safety
Three states enacted what are effectively “Chatbot Safety Acts”: laws that do not regulate medical practice directly but impose safety and disclosure requirements on AI chatbots that might interact with patients in crisis.
Idaho SB 1297, enacted March 31 and effective July 1, 2027, requires disclosure and crisis-response protocols for any conversational AI system that provides health-related information. The law is nearly identical to Nebraska’s, suggesting both states may have used model legislation.
Nebraska LB 525, enacted April 14, combines the Agricultural Data Privacy Act with a Conversational AI Safety Act that applies to all public-facing AI chatbots with healthcare safety requirements. It is identical in structure to Idaho’s law but applies to all public-facing chatbots, not just health-specific ones.
Oregon SB 1546, enacted March 31, is the most comprehensive chatbot safety law in the country. It includes a private right of action, safeguards for minors, and covers AI companions. It is significantly broader than the Idaho and Nebraska statutes, extending beyond healthcare to cover emotional support AI.
Professional Licensing
Two states passed laws clarifying that AI is not a licensed professional, using different legal techniques to reach the same conclusion.
Delaware HB 191, enacted April 23, prohibits any nonhuman entity, including AI, from being licensed or certified as a nurse, physician, or physician assistant. It also bars AI from using protected professional titles. It is the most explicit title-protection law in the survey.
Utah SB 150, enacted March 24, uses a negative-definition approach: AI providing advice or treatment without a practitioner-patient interaction does not qualify as an “innovation” within the scope of practice. It is the only law that defines AI out of scope rather than explicitly prohibiting licensure. Paired with Utah’s SB 319, enacted the day before, these two laws create the most comprehensive AI regulatory framework of any single state.
The Horizon: Pending Bills and Federal Counter-Trends
Three jurisdictions have legislation still pending that could reshape the landscape by 2027.
New York S7896 / A8556, introduced in the 2025-2026 session, would establish comprehensive AI utilization review requirements. It is the most detailed authorization law proposed to date, with specific reporting and human-review mandates that go beyond the 2026 enacted statutes.
Pennsylvania HB 1925, introduced in the 2025-2026 session, would amend both the Health and Insurance titles to require AI utilization review and reporting by insurers, hospitals, and clinicians. It is broader than most authorization bills because it covers providers as well as insurers.
Federal H.R. 238, the Healthy Technology Act, stands in direct counterpoint to the state trend. Introduced in the 119th Congress, it would allow AI and machine learning systems to qualify as practitioners able to prescribe FDA-approved drugs, effectively federalizing the expansion of AI clinical authority that Texas alone has permitted at the state level. If it advances, it would create a direct conflict with the authorization and therapy bans enacted by more than two dozen states.

