How New State AI Laws Affect Marriage and Family Therapists

A guide for LMFTs covering AI chatbot bans, insurer rules, and documentation duties.

By Emily CarterReviewed by Editorial & Advisory TeamUpdated August 22, 202616 min read
AI Healthcare Laws for MFTs: 2026 State Rules

What you’ll learn in this article…

  • Fourteen state AI healthcare laws passed across 11 states in 2026.
  • Seven states require human clinician review of insurance denials, not AI.
  • Five states ban AI chatbot therapy, Illinois fines reach $10,000 per violation.

Can a state law stop an insurer from letting an AI algorithm deny a marriage and family therapy session? In 2026, 14 new state healthcare AI laws across 11 states begin to answer that question. Seven states now limit AI in insurance authorization decisions, requiring a licensed clinician or physician to review denials. Five states ban AI chatbot therapy services.

For marriage and family therapists, these laws protect both reimbursement and scope of practice. An AI system cannot override a clinician's medical-necessity judgment, and a chatbot cannot stand in for relational human therapy. The state-by-state map is uneven, but compliance pressure is now concrete, especially for telehealth and AI documentation tools.

State-By-State Snapshot: 2026 AI Healthcare Laws MFTs Should Watch

The 2026 legislative session produced a wave of state laws limiting how AI can be used in healthcare decisions and therapy delivery. For marriage and family therapists, these laws protect clinical judgment and set boundaries around AI chatbots, prior authorization, and clinical documentation.

StateBill NumberEffective DateKey AI Provision
AlabamaSB 63October 1, 2026Regulates AI in health insurance coverage and prior authorization decisions. Requires insurers to disclose AI use, base determinations on the patient's medical history and unique clinical circumstances, and prohibits AI from being the sole basis for denials.
ColoradoHB 1139N/ARequires coverage denials to be reviewed by a licensed clinician or physician. AI may be used as a tool, but a human must make the final adverse determination.
GeorgiaSB 444N/AProhibits coverage decisions based solely on AI systems. Human review is required for prior authorization and adverse coverage decisions.
IowaHF 2635N/AAllows AI for initial review but prohibits sole reliance on AI for denial decisions. A human must make the final medical necessity or coverage determination.
UtahSB 319N/ARequires disclosure of AI use in authorization review and independent medical judgment in adverse determinations. AI cannot be the final word on coverage denials.
WashingtonSB 5395June 11, 2026Specifies that only a licensed physician or licensed health professional may deny a prior authorization request based on medical necessity. AI may be used as a tool but cannot be the sole means to deny, delay, or modify care.
ColoradoHB 26-1139August 12, 2026Prohibits AI therapy chatbots and restricts licensed psychologists, counselors, social workers, marriage and family therapists, and other psychotherapy providers from using AI in specified ways in therapy practice.
MaineN/AN/AProhibits AI chatbots from providing therapy services independently. Requires human clinicians to remain responsible for mental health treatment and limits AI-delivered therapy.
Rhode IslandH 7349AN/ARegulates aspects of healthcare and mental-health practice by requiring identification of AI use, keeping a licensed professional responsible, and ensuring AI-supported outputs are reviewed before becoming consequential clinical actions or records.
Rhode IslandS 2570AN/ARegulates healthcare and mental-health practice by requiring disclosure and review of AI use and keeping licensed professionals responsible for AI-influenced clinical actions or records.
TennesseeN/AN/AProhibits AI chatbots from delivering therapy independently. Keeps human mental health professionals responsible for treatment and limits AI-only therapy.
VermontN/AN/ABars AI chatbots from providing therapy services independently. Requires human clinical oversight and restricts AI use in therapy.
NevadaN/AN/ARestricts AI from delivering therapy outright. Prevents AI systems from acting as independent therapy providers and reserves treatment delivery to licensed human clinicians.
UtahN/AN/ARegulates mental-health chatbots through disclosure and data rules. Specifies conditions under which AI can interact with users in a mental-health context, emphasizing transparency and data protection rather than allowing AI-only therapy.
IllinoisN/A2025First state (with Nevada) to prohibit commercial therapy services via AI chatbots. AI chatbots cannot provide therapy independently; licensed human therapists remain responsible.

The AI Chatbot Therapy Bans: What LMFTs Can and Cannot Delegate

Seven states now have laws prohibiting AI chatbot-based therapy1, and Illinois set the compliance stakes with fines up to $10,000 per violation.2 Illinois and Nevada led in 2025, and five additional states joined during 2026.1

What the bans actually prohibit

These laws target commercial AI chatbot therapy services that present themselves as mental healthcare providers. They do not ban licensed telehealth or online family therapy delivered by an LMFT. Illinois explicitly bars AI from independent therapeutic decisions, direct therapeutic communication, generating treatment plans without review, and emotion detection.3

Where human oversight still applies

Nevada permits AI only under direct supervision of a licensed professional and requires disclosure. Illinois allows administrative support such as scheduling or billing, and supplementary uses like processing transcripts, but only with written, specific, revocable patient consent and licensed professional review of all AI outputs.4 Maine's broad prohibition and Tennessee's ban on AI representing itself as a qualified mental health professional6 reinforce the same rule: a licensed human must remain responsible.

What this means for LMFT scope

For marriage and family therapists, the practical line is clear. You cannot delegate core therapeutic functions to an AI chatbot or let AI act as the treating entity.2 AI may assist with notes, scheduling, or workflow through practice management solutions for MFTs if state law and consent requirements allow, but clinical judgment, diagnosis, treatment planning, and direct therapeutic communication remain squarely within LMFT scope.

As of mid-2026, 14 new state laws regulating AI in healthcare have been enacted across 11 states, with 7 states limiting AI in insurance authorization decisions. For MFTs, that means the legal landscape is moving fast, and human clinical judgment remains protected.

Insurer AI Rules and Prior Authorization: Protecting Clinical Judgment

Seven new state laws now make it impossible for insurers to hide behind algorithms when denying, delaying, or downcoding mental health treatment.1 For LMFTs, these rules protect clinical judgment and give you legal leverage in reimbursement disputes, from LMFT insurance credentialing to denial appeals, while reinforcing the MFT career outlook.

The Human-Review Mandates

  • Alabama SB 63: Insurers must disclose AI use, and denials based on medical necessity require a licensed physician or health professional weighing individual circumstances.2
  • Georgia SB 444 and Colorado HB 1139: Coverage decisions cannot rely solely on AI, and denials must be reviewed by a licensed clinician or physician.1
  • Iowa HF 2635: AI may assist initial review, but a human cannot rely on it alone for denial decisions.1
  • Utah SB 319: AI use in authorization review must be disclosed, and adverse determinations need independent medical judgment.1
  • Washington SB 5395: Only a licensed physician or health professional may deny prior authorization based on medical necessity; AI cannot be the sole means for negative decisions.3
  • Illinois SB 3114 (awaiting signature): Downcoding determinations must be made or reviewed by a natural person.1

Script for Contesting AI-Driven Denials

Do not accept an unexplained denial. Say: "I request a licensed clinician review this denial under [state law]. Please disclose whether AI was used and provide the name and license of the human reviewer." Many insurers must now comply.

As of July 27, 2026, 14 new state laws regulating AI in healthcare have been enacted across 11 states, with five banning AI chatbot therapy.
Transparency Coalition analysis

Ethical and Documentation Compliance for AI Tools in MFT Practice

Administrative AI vs. Therapeutic AI

Not all AI tools carry the same ethical weight. Administrative uses such as scheduling, billing, and drafting progress notes from a clinician's dictation are generally lower risk when paired with human review. Therapeutic uses are different. Letting a chatbot conduct therapy, make diagnoses, or direct treatment would raise serious ethical and legal problems, and several 2026 state laws now prohibit AI chatbot therapy outright. MFTs should treat AI as a documentation assistant, never as a clinical replacement.

When State Consent Rules Apply

Consent for AI-assisted documentation is not a single federal standard, so clinicians should check the state where the client sits and any telehealth regulations for couples therapy that apply. Iowa's mental health disclosure law requires voluntary written authorization before mental health information is shared outside treatment, payment, and healthcare operations, and a copy must be placed in the client record.2 If an AI vendor receives identifiable session content, that authorization may be required by inference. Psychotherapy notes need separate, specific consent.3 Florida requires written informed consent at least 24 hours before recording or transcribing a counseling session.4 In California, board guidance calls for transparency and clear labeling of AI-generated content.5 Proposed behavioral sciences policy would require written informed consent for AI use in recorded or transcribed sessions.6

What a Written AI Consent Form Should Include

  • Tool name and what it does during the session
  • Who receives or stores the data, including any AI vendor
  • Retention period and deletion procedure
  • Human review: confirm a clinician reviews and edits all AI-generated notes before they enter the record
  • The right to decline AI tools without affecting quality of care

Ethics and Board Expectations

The AAMFT Code of Ethics requires informed consent for technology-assisted services such as HIPAA compliant teletherapy platforms for MFTs, written disclosure of risks, adequate security, and appropriate training.7 Disclosure is not optional. Clinicians who use ambient scribes should document that consent separately from general treatment consent, and supervisors should ensure trainees follow the same board and state rules.8

HIPAA and Vendor Contract Risks for AI Therapy Tools

Some AI tools are built for healthcare and sign a business associate agreement before touching protected health information.1 Others are general-purpose apps that refuse to sign, and that difference decides whether a therapist can use them with session content.

When a BAA Is Non-Negotiable

Under HIPAA, any AI vendor that creates, receives, maintains, or transmits PHI on a practice's behalf is a business associate.4 A signed BAA must exist before PHI processing, even if the vendor only stores encrypted data without the decryption key.1 For AI notes and transcription, that threshold is crossed the moment they handle session content. The rule: "No BAA, no PHI."

Security Rule Safeguards for Scribes

The Security Rule applies to electronic PHI at both practice and vendor.4 AI transcription tools must encrypt data in transit and at rest, enforce strong access controls, keep audit logs, and support integrity protections.2 For an MFT private practice, include each tool in the risk analysis and risk management process, train staff, and document the BAA.2

Red Flags in Vendor Contracts

  • Model training: A vendor that trains models on PHI without documented, permissible terms should be rejected by default.
  • Data retention: State law and board rules govern clinical records, not a fixed HIPAA retention period. Require deletion or anonymization on request or termination.
  • Subcontractors: Disclose all subprocessors, including third-party LLM APIs, and require equivalent BAA terms.
  • Breach notification: Require vendor reporting within 24 to 72 hours, so you can meet the 60-day patient notification timeline.4

Covered vs. Non-Covered Tools

A general-purpose transcription app that refuses a BAA is not a HIPAA-compliant option for session notes. Choose healthcare-designed tools that agree to return or destroy PHI at termination.4

Cross-State Telehealth and Licensure: When AI Tools Cross Borders

When an MFT sees a client across state lines, the telehealth session is treated as occurring where the client is physically located. That simple place-of-service rule, outlined in Can Therapists Practice Across State Lines?, means the client's state controls LMFT licensure portability and practice requirements, while the therapist's licensing state can also impose concurrent duties.

Which state's AI rules apply?

For AI tools, the strictest applicable rule usually wins. California's SB 1234 requires written consent for AI recording or transcription and limits AI to administrative support when services reach California residents, even if the therapist is licensed elsewhere.1 Five states passed laws banning AI chatbot-based therapy services in 2026, a shift tracked among new state laws regulating AI in health care. Those bans can reach telehealth if automated care is offered into those states. Most states, however, have telehealth policies with no explicit AI language.

Practical workflow for MFTs

  • Verify that you hold the correct license or registration in the client's state before the first session.
  • Check both state boards for current AI guidance, even when guidance is sparse or silent.
  • Treat the most restrictive applicable rule as the baseline for recording, transcription, or chatbot features.
  • Do not rely on the Counseling Compact. It covers licensed professional counselors only and has no AI provisions2, and no LMFT compact exists as of 20263.
  • When AI use is unclear, disable the tool and document that the session was human-led.

When in doubt, the client's state board is the authority that will enforce the rule after a session.

For MFTs, the real tradeoff is convenience versus defensibility: a time-saving AI documentation tool becomes a liability when the consent form, vendor agreement, or human-review trail is missing.

Consent and Clinical Workflow

  • Obtain signed AI consent: Secure separate written consent before using any AI to record, transcribe, or analyze sessions. Iowa's 2026 law requires patient consent for AI recording and transcription in clinical interactions.
  • Require human review of AI output: No AI-generated note, summary, or treatment plan should enter the clinical record until a licensed MFT has reviewed and corrected it.
  • Document AI use explicitly: Record the tool name, date, and clinician review in the progress note. This creates an audit trail similar to the transparency expectations in Alabama SB 63 and Washington SB 5395.

Vendor and Telehealth Safeguards

  • Execute a BAA: Confirm every AI vendor that touches protected health information signs a HIPAA business associate agreement covering storage, deletion, and breach duties.
  • Review vendor data use: Check whether session audio or transcripts are used to train models or shared with third parties. Require no retention for model training.
  • Check telehealth state rules: Before using AI documentation across state lines, confirm the patient's state does not classify the tool as a prohibited AI therapy service, and follow telehealth safety protocols for therapists. Illinois, Nevada, and the five 2026 chatbot ban states restrict AI chatbot therapy, so keep AI in documentation-only roles.
  • Align with your licensing board: Board ethics guidance can be stricter than state statute; document a board consultation or ethics advisory opinion and complete free ethics CEUs for MFTs.
  • Build an incident response step: If an AI tool breaches or misrecords, log the incident, notify patients where required, and report to your malpractice carrier.

Future Outlook: Where AI Regulation for Mental Health Is Headed

Which pending AI healthcare rules should MFTs watch next as 2026 laws take effect? The state snapshot already shows 14 new laws across 11 states, with Illinois SB 3114 still awaiting a governor's signature. Its requirement that downcoding decisions be made or reviewed by a natural person signals how the next wave will reach behavioral health documentation and billing, not just physical healthcare.

From medical authorization to mental health records

Most enacted 2026 statutes focus on insurer prior authorization and medical necessity denials. MFTs submit treatment plans and claims through these same systems, so payer-side AI safeguards will increasingly cover therapy coverage disputes. Add the five state laws banning AI chatbot therapy, and the regulatory direction is clear: licensed human judgment remains the legal floor for marriage and family therapy modalities.

Build an annual compliance rhythm

State associations are already tracking implementation dates, clinician review standards, and disclosure duties. Join one state professional association and set quarterly MFT Medicare billing and telehealth AI check-ins. Reassess consent forms, documentation templates, and AI vendor terms each January, since 2026 laws passed in March and May took effect within months.

Treat this year as the baseline, not the finish line. Create a 12-month calendar that flags state board alerts and new bill language such as "solely," "natural person," and "licensed clinician." If you can demonstrate human override at every AI-assisted step, you will be prepared for the next enforcement wave.

Recent News

Recent Articles