State legislatures become testing ground for mental health AI oversight
Artificial intelligence tools for mental health are moving quickly from research labs into therapy sessions, apps, and everyday care, often faster than the rules meant to govern them. While lawmakers are racing to catch up, a new analysis finds that most state-level efforts still fall short, leaving major gaps in safety standards, clinical oversight, and protections for patients.
The analysis, published in JMIR Mental Health, reviewed legislation introduced across all 50 states from 2022 through mid-2025 and identified 143 bills with potential implications for mental health AI. Generative models and predictive tools are already being used by psychiatrists and directly by patients, and reports of harmful outputs have surfaced in media and safety databases, highlighting the stakes of deploying these technologies without firm standards.
More than 700 million people now use ChatGPT each week, with therapy and companionship among the most-cited use cases. At the same time, health care systems are piloting AI tools for clinical decision support, population health management, and administrative triage. This parallel expansion into both clinical care and consumer use complicates regulation, because existing oversight structures were built largely for physician-mediated interventions rather than technologies patients can access on their own.
At the federal level, responsibility for regulating these tools is split among multiple agencies, including the Food and Drug Administration, Federal Trade Commission, and Department of Health and Human Services, with no single body providing comprehensive oversight tailored to mental health AI. The FDA’s traditional pathways focus on software as a medical device, which can require premarket review for higher-risk applications, but enforcement has been inconsistent.
The FTC, meanwhile, has issued warnings about deceptive health claims and inadequate data security, though its authority centers on consumer protection rather than clinical efficacy. As a result, many tools marketed directly to consumers fall outside traditional medical device rules, particularly when positioned as wellness products rather than clinical technologies.
States move to fill the regulatory gap
In the absence of unified federal leadership, state legislatures have emerged as de facto laboratories for AI policy. Of the bills identified in the analysis, 20 have been enacted across 11 states, with notable variation in approach and emphasis.
Some states have focused on transparency mandates, requiring disclosure when patients interact with AI rather than human clinicians. Others have emphasized data protection, extending existing health privacy laws to cover AI-generated insights and algorithmic outputs. A smaller subset has attempted to establish standards for algorithm validation or require independent audits before deployment in clinical settings.
What state AI bills focus on and what they miss
The analysis identifies four prominent themes across the legislative landscape: professional oversight, harm prevention, patient autonomy, and data governance. Bills frequently tackle disclosure and consent requirements, civil penalties for noncompliance, and transparency in AI system design. Data protection appears in many proposals, although specific privacy protections for sensitive mental health information are often weak or absent.
Professional oversight and accountability are central concerns, as lawmakers grapple with how to integrate AI tools into licensure frameworks and malpractice law. Provisions around human-in-the-loop requirements and postmarket monitoring reflect concern that AI systems should not operate unchecked in therapeutic contexts. Questions remain about liability when AI recommendations lead to adverse outcomes: should responsibility rest with the developer, the deploying institution, the supervising clinician, or some combination?
Despite this activity, explicit mental health AI provisions remain rare. Most bills treat mental health as incidental to broader AI or health care legislation, raising the risk that laws could diverge from clinical reality. Professional associations, including psychiatric and psychological organizations, have so far offered limited detailed guidance, leaving lawmakers without consistent clinical reference points.
How state laws could shape national standards
This patchwork approach means that protections for patients and duties for providers can vary sharply from one state to another. For example, California alone accounted for nearly 20 of the bills meeting inclusion criteria, whereas 12 states had none.
In areas like telemedicine and EHR adoption, early state laws shaped later national standards. But the complexity of AI and its potential for harm in mental health settings, where vulnerability and confidentiality are paramount, adds urgency to effective legislation.
For health IT professionals, this fragmentation creates operational challenges. Multistate health systems must navigate varying disclosure requirements, data handling rules, and clinical documentation standards. Vendors developing mental health AI tools face the prospect of customizing products for different regulatory environments, potentially slowing innovation or creating compliance burdens that favor larger, better-resourced companies over startups.
The authors urge active engagement by clinicians, researchers, and patient advocates in shaping these laws. Without such input, legislation may prioritize theoretical risks over practical safeguards or impose burdens that deter beneficial innovation.