AI is already practicing medicine, and the rules are barely keeping up. It reads the scans, drafts the charts, screens the prior authorizations, and answers patients through a chatbot at 2 a.m. The federal rulebook covering all of this activity amounts to almost nothing. Congress passed the TAKE IT DOWN Act in 2025, and it targets nonconsensual intimate images, not medicine. That is most of the federal shelf here.
To compensate, the states have quickly stepped in. In just the first three months of 2026, 36 states floated more than 70 bills aimed at AI chatbots, and another 25-plus went after insurers’ use of AI, according to Manatt’s health AI policy tracker. To date, lawmakers in more than 40 states have introduced health-AI bills.
Despite all this activity, most of these bills will die in committee, and only a fraction have made it onto the books. These bills are mostly going after the same few targets, and the ones with real teeth are clustered in a handful of states.
Where the state laws converge:
The biggest fight is over who gets to say no. Most of the action targets how insurers use AI to screen prior authorizations and claims. The rule that keeps recurring, across a Holland & Knight review of the 2026 laws, is simple: AI can sort, flag, and speed things up, but a licensed human, not an algorithm, has to own any denial of medically necessary care. California’s SB 1120 wrote the template in 2025. Maryland, Arizona, Connecticut, Nebraska, Texas, and Georgia have since copied it in their own words.
Chatbots are the second front, and mental health is where it gets tense. A fast-growing set of laws goes after AI that talks to patients directly, especially the kind that acts like a therapist or a companion. The rules now in effect tend to demand the same three things: tell users they are talking to a machine, build in an escalation path when someone mentions self-harm, and never let the bot pass itself off as a licensed professional. Illinois bars AI from delivering therapy without a clinician, California regulates companion chatbots, and New York makes the self-harm handoff mandatory.
When in doubt, make them disclose. The most common move is making everyone admit when AI is in the loop. California’s AB 3030 requires a disclaimer any time unreviewed AI writes a patient’s clinical message, plus directions for reaching an actual person. More and more states now ask insurers to say, out loud, whether AI touched a coverage decision.
The comprehensive AI laws mostly dodge health care. The sweeping state AI acts label health a “high-risk” use, then either get narrowed or wave through the providers and insurers HIPAA already covers. Colorado wrote the most ambitious one of all, then repealed and replaced it before it took effect. So far, the laws with real weight are the ones with a narrower focus.
Within a federal vacuum, states start copying each other
Not only has Congress failed to pass a health-AI law, it can’t even get it together enough to stop states from passing their own—both its attempts to do so collapsed. The Senate cut a proposed ten-year moratorium out of the 2025 reconciliation law, and a similar preemption push died in the 2026 defense bill.
In the meantime, states are writing their own laws through some combination of improvisation and copying each other’s answers. Insurer rules track a model bulletin from the National Association of Insurance Commissioners that roughly half the states have now adopted. The chatbot and disclosure laws lean on California’s, which came first and turned into the default everyone else is copying. Strip away the local details and it’s easy to see that most laws have the same core: disclose when AI is in use, keep a licensed human on any decision that matters, and never let AI pose as a clinician.
Where the states split
Not everyone reached for the same template. The standouts:
California is out front, and not with one law but a whole stack. SB 1120 kills AI-only medical-necessity denials, AB 3030 forces disclaimers on AI-written clinical messages, AB 489 stops AI from posing as a licensed provider, and SB 243 reins in companion chatbots, with a private right of action worth up to $1,000 a violation.
Illinois drew the hardest line on therapy. Its 2025 law flatly bars AI from delivering mental health treatment or therapeutic decisions without a licensed professional, with fines reaching $10,000 per violation.
Utah went the other way entirely, betting on permission instead of prohibition. Rather than bans, it runs an AI regulatory sandbox out of a dedicated Office of Artificial Intelligence Policy, paired with a lighter mental-health-chatbot law that asks mainly for disclosure and recordkeeping. It is the same sandbox now letting an AI system handle routine prescription refills.
New York picked a different weapon. Its companion-chatbot law hands enforcement to the attorney general, who can stack civil penalties up to $15,000 a day, instead of the private lawsuits California invites.
Texas passed one of the broadest AI laws in the country. It bars systems built to steer people toward self-harm, routes enforcement through the attorney general, and gives companies 60 days to cure a violation. Its medical board adds two more rules: a clinician has to review AI-generated records, and patient records cannot be sent offshore.
Colorado is the cautionary tale. It passed the most comprehensive state AI act in the country, delayed it under industry pressure, then repealed and replaced it with a narrower version before the original ever took effect. What survived are targeted health rules, including a ban on payers reimbursing AI-delivered psychotherapy.
Georgia is the compromise in one sentence: insurers may run AI in prior authorization, but no AI-issued denial counts until a licensed provider reviews it and signs off.
Maine kept it to scope of practice. Mental health professionals can lean on AI for paperwork, but not for therapeutic communication or for talking to patients on its own, and they need consent before an AI scribe starts listening.
Who enforces state AI laws, and the penalties for breaking them
Depending on the law, enforcement runs through state attorneys general, insurance departments, consumer-protection divisions, or the same licensing boards that already discipline doctors and therapists. That tangle of enforcers means one product can be perfectly legal in one state and a violation in the next.
The penalties and triggers vary as much as the rules:
Illinois: up to $10,000 per violation for misuse of AI in therapy, through its professional-regulation department
Utah: up to $2,500 per violation for chatbot-disclosure failures, through its consumer-protection division
New York: up to $15,000 per day for companion-chatbot violations, through the attorney general
California: a private right of action under its companion-chatbot law, with damages up to $1,000 per violation
Most of these laws stop short of letting people sue, lean on disclosure over outright bans, and hand companies a window to fix problems before penalties land. And the effective dates are scattered across 2025, 2026, and 2027, so the compliance map keeps moving even for laws already on the books.
Can Washington override state AI laws?
Just as this state-level patchwork started to take shape, the federal government decided it wants the whole thing gone. After Congress refused to pass a moratorium, President Trump signed an executive order in December 2025 that tells the Justice Department to stand up a task force to fight state AI laws in court. The order also directs the Commerce Department to name the “onerous” laws and weigh stripping federal broadband money from the states that keep them, and points the FTC and FCC toward federal standards that would override state rules. Colorado’s AI act was called out by name, but, tellingly, California’s laws were left out of it.
Bluster and threats aside, an executive order cannot repeal a state statute. Only Congress or the courts can do that, and a bipartisan coalition of 36 state attorneys general has already told Congress, in writing, to reject exactly this kind of federal preemption. For now, all of these laws stand. Over the next year, the fight will likely move from statehouses to courtrooms.



