Key Takeaways
- ·Texas TRAIGA (effective January 1, 2026) requires healthcare providers to give patients clear and conspicuous disclosure when AI is used in their care, even for uses that seem obvious like AI chatbots. Emergency exceptions apply.
- ·Texas SB 1188 (effective September 1, 2025) additionally requires licensed practitioners using AI in diagnostic contexts to review all AI-generated records for accuracy and retain ultimate responsibility for clinical decisions.
- ·Illinois HB 1806 (effective August 2025) bans AI from independently providing psychotherapy or making therapy decisions without licensed professional review, and requires disclosure to patients when AI is used in care.
- ·California AB 3030 (effective January 1, 2025) requires disclaimers on AI-generated clinical communications identifying the content as AI-generated and providing instructions to contact a human provider.
- ·California AB 489 (effective October 2025) prohibits AI from using professional credentials that imply licensed human oversight when none exists.
- ·Multi-state health systems should build their compliance approach around the most stringent state requirements rather than managing separate standards per state.
- ·Colorado SB 26-189 (signed May 14, 2026, effective January 1, 2027) replaces the original Colorado AI Act's risk management mandate with a disclosure-based framework. Organizations in Colorado should review their specific obligations before the January 2027 effective date.
The short answer
The disclosure requirements depend on which states your facilities operate in. For health systems with operations in Texas, California, or Illinois, you have live obligations in effect now. Colorado's requirements take effect January 1, 2027. The most practical compliance path for multi-state organizations is to build a unified policy and patient notification approach that meets the most stringent applicable state requirements, rather than maintaining separate compliance tracks per state. CHIME recommends a single overarching consent or notification form using plain language reviewed during patient intake. That approach is defensible, scalable, and reduces the operational complexity of state-by-state management.
Why State Laws Are Driving This Landscape
At the federal level, AI-specific disclosure requirements for healthcare providers don't exist as a formal mandate. ONC's proposed HTI-5 rule would have established some federal AI transparency standards, but deregulatory action has shifted responsibility to the states. The result is a patchwork of state laws, each with different triggers, different disclosure standards, and different enforcement mechanisms.
For most health systems, this means that compliance posture depends first on geography. A hospital operating exclusively in a state with no AI disclosure law faces different near-term obligations than one operating in Texas or California. But the trajectory of state legislative activity suggests that most states will eventually enact some form of AI disclosure requirement for healthcare, and organizations that build compliant disclosure practices now are better positioned for that expansion than those who manage it state by state as laws arrive.
The Texas AG's 2024 settlement with Pieces Technologies is also relevant here. The settlement demonstrates that existing consumer protection laws can be applied to AI vendors who make misleading claims, even before AI-specific laws are enacted. States don't need new legislation to pursue enforcement action in the right circumstances.
Texas: Two Laws, Both Now in Effect
Texas has enacted two separate AI-related laws affecting healthcare providers, both of which are now in effect. They address different but overlapping concerns.
Texas HB 149 (TRAIGA), Effective January 1, 2026
The Texas Responsible AI in Healthcare Act requires healthcare providers to give patients clear and conspicuous disclosure when AI is being used in their care. The requirement applies broadly, even to uses that seem obvious, such as an AI chatbot fielding a patient inquiry. Disclosure must occur before or at the time of interaction with the AI system. An exception applies in emergency situations where obtaining disclosure before treatment would delay necessary care. Non-compliance creates exposure to state license consequences and potential legal action under Texas consumer protection statutes. Health systems operating in Texas should have disclosure practices in place as of January 1, 2026.
Texas SB 1188 (Effective September 1, 2025)
This law addresses a narrower but clinically important context: AI used by licensed practitioners in diagnostic settings. Practitioners using AI in diagnostics are required to review all AI-generated records for accuracy, and ultimate responsibility for clinical decisions remains with the licensed practitioner. This isn't just a disclosure requirement. It's a practice standard. The law creates an explicit expectation that practitioners are actively reviewing and verifying AI-generated outputs rather than passing them through to the clinical record without review. Documentation practices should reflect this.
Texas Enforcement Context
The Texas AG's 2024 settlement with Pieces Technologies demonstrates the enforcement appetite. That action was brought under existing fraud and consumer protection statutes, before TRAIGA took effect. With TRAIGA now in effect, providers in Texas face both the new disclosure obligations and the backdrop of an AG's office that has shown willingness to pursue AI-related enforcement action in healthcare. Non-compliance with TRAIGA's disclosure requirements creates exposure on multiple fronts: state licensing action, consumer protection claims, and the reputational consequences of an enforcement action.
Illinois: Behavioral Health AI Restrictions
Illinois HB 1806, the Wellness and Oversight for Psychological Resources Act, took effect in August 2025. The law addresses a specific and clinically sensitive context: AI in behavioral health and psychotherapy settings.
The law bans AI from independently providing psychotherapy or making therapy decisions without licensed professional review. The specific prohibitions are worth noting in detail: AI may not make independent therapeutic decisions, may not directly interact with clients in therapeutic communication without licensed oversight, and may not generate treatment plans without licensed professional review. Any licensed professional using AI in patient care must inform the patient or their representative that AI is being used.
Scope of the prohibition
The Illinois law is explicitly targeted at AI in psychotherapy and behavioral health contexts. A general-purpose clinical AI tool used in a behavioral health setting is subject to these requirements. Health systems with behavioral health service lines in Illinois should review their AI deployments specifically against the HB 1806 prohibitions. The prohibition on AI making independent therapeutic decisions has practical implications for any AI tool that generates care recommendations in a behavioral health context.
Disclosure obligation
Beyond the prohibition on certain autonomous AI functions, the law requires disclosure to patients or their representatives whenever AI is being used in their care. This is a patient rights provision, and it applies regardless of whether the AI is performing a prohibited function. The disclosure requirement applies to any AI use in the care of Illinois behavioral health patients.
The supervised autonomy standard
What the law is establishing is a supervised autonomy standard: AI may support licensed professionals in behavioral health settings, but it may not operate independently in therapeutic decision-making. This maps directly to the broader governance principle that AI in high-stakes clinical contexts should augment licensed human judgment, not replace it. Health systems that have already implemented governance policies reflecting this principle are well-positioned for HB 1806 compliance.
California: Three Laws Covering Different AI Uses
California has enacted three separate laws addressing AI in healthcare contexts. They address different facets of AI use (clinical communications, professional identity, and mental health chatbots), and together create a more complete regulatory picture than any single law.
California's approach reflects the state's broader pattern of sector-specific AI legislation rather than a single omnibus AI law. For health systems operating in California, this means compliance requires attention to three separate statutes with different applicability and different trigger conditions.
California AB 3030 (Effective January 1, 2025)
Healthcare providers using generative AI for clinical communications must include disclaimers stating that the content is AI-generated, and must provide instructions for contacting human providers. The law applies specifically to generative AI in clinical communications: the category of AI that produces text, responses, or recommendations patients or clinicians will read and act on. If your health system uses generative AI for after-visit summaries, patient messaging, care instructions, or similar clinical communications, AB 3030's disclaimer requirements apply. This law has been in effect since January 1, 2025.
California AB 489 (Effective October 1, 2025)
This law prohibits AI systems from using professional terminology or post-nominal credentials (MD, DO, RN, and similar designations) that imply licensed human oversight when no licensed human is actually involved. Enforcement is through state professional licensing boards. The practical implication is that AI tools in California-based healthcare settings may not present themselves or their outputs using credentialed professional language unless a licensed professional is actually supervising the AI's function. This is directly relevant to AI that patients interact with in clinical contexts and that might otherwise use clinical professional language in a way that creates a misleading impression about whether a licensed person is involved.
California SB 243 (Effective January 2026)
This law mandates that AI companion and mental health chatbots clearly disclose that they are AI and not human practitioners, with specific additional protections for minors. The minor-specific protections include requirements preventing AI chatbots from generating or facilitating sexually explicit or suicide-related content without appropriate safeguards. For health systems with patient-facing AI mental health support tools, particularly tools that may be accessed by minors, SB 243 creates specific disclosure and safety obligations beyond the general adult-facing disclosure requirements.
Colorado: New Disclosure Law Takes Effect January 2027
Colorado was the first state to enact a broad AI governance law for high-risk systems, and then substantially revised it two years later. On May 14, 2026, Governor Polis signed SB 26-189, which repeals and replaces the original Colorado AI Act (SB 24-205). The revision changes what compliance looks like for organizations operating in Colorado.
The original SB 24-205 required deployers of high-risk AI systems to maintain risk management programs, conduct impact assessments, and meet duty-of-care obligations. It was scheduled to take effect February 1, 2026, was delayed to June 30, and was frozen from enforcement by court order on April 27, 2026. SB 26-189 replaces that framework with a disclosure-based approach with limited consumer rights in specific circumstances. It passed 34-1 in the Senate and 57-6 in the House and takes effect January 1, 2027.
What changed for Colorado healthcare organizations
The original law would have required formal risk management programs and documented impact assessments for high-risk AI deployments. SB 26-189 shifts to a disclosure-based framework, closer in scope to what Texas and California already require. Organizations that had been building toward SB 24-205's governance program requirements may find the new framework asks considerably less of them. That said, disclosure obligations under SB 26-189 still apply, and organizations should review their specific requirements directly or with legal counsel before the January 2027 effective date.
What the Colorado reversal means for multi-state compliance planning
Colorado was widely watched as a test case for broad state AI governance. The near-unanimous legislative decision to replace its governance mandate with a disclosure framework reflects real tension: states want to address AI risk, but the original law's compliance burden drew enough opposition to reverse course. For multi-state health systems, Colorado's experience points toward a near-term regulatory landscape of expanding disclosure requirements rather than broad governance mandates. That's a different compliance problem, and a more manageable one, but it still requires planning.
Building a Multi-State Compliance Strategy
Multi-state health systems face the most complex version of this problem. Each state's requirements differ in their triggers, their specific disclosure content requirements, their exceptions, and their enforcement mechanisms. Managing separate compliance tracks for each state is operationally expensive and creates inconsistency that itself creates risk.
The approach recommended by CHIME is to develop a unified policy meeting the most stringent applicable requirements and implement it across operations. This uses state fragmentation as a driver toward governance best practices rather than a source of confusion. If you're doing what California requires, you're covered in Texas. If you're doing what Texas requires, you're partway to CHIME's broader recommendations.
Single overarching consent and notification form
CHIME recommends implementing a single overarching consent or notification form explaining AI use in clinical settings, reviewed during patient intake, using plain language and accessible formats. This form should cover the disclosure requirements of all states where you operate. It should be reviewed when your AI tool inventory changes, since new tools may trigger disclosure requirements that weren't in scope when the form was originally drafted.
Disclosure at the point of AI interaction
Several state laws require disclosure before or at the time of AI interaction, not just at intake. For synchronous AI interactions, such as a patient communicating with an AI chatbot or receiving real-time AI-assisted recommendations, point-of-interaction disclosure needs to be built into the workflow. This is a different requirement from intake consent forms, and it applies to different types of AI use.
Documentation of disclosure practices
If your disclosure practices are ever challenged, the question will be whether you can demonstrate that disclosure was provided as required. Document your disclosure mechanisms: what patients are told, when they're told it, and how that disclosure is recorded. For patient-facing AI interactions, this may mean logging the disclosure event in the patient record or the AI interaction record.
Vendor coordination on AI identification
Several state laws' requirements can only be met if you know which of your vendor's tools constitute AI under the applicable definition, and what those tools are doing. Work with your AI vendors to understand which tools trigger disclosure obligations in each state where you operate. Vendors who are reluctant to characterize their tools as AI for disclosure purposes are creating compliance risk for you, not reducing it.
The Federal Vacuum and State Proliferation
The current state-driven regulatory environment is a direct consequence of the absence of a federal AI disclosure standard for healthcare. ONC's HTI-5 proposal would have established some federal transparency requirements, but deregulatory action removed that floor. As long as federal requirements are absent or minimal, state legislatures will continue filling the gap, and each state's law will reflect local political priorities rather than a coherent national framework.
The practical implication for health systems is that the number of states with AI disclosure laws will grow, not shrink. Organizations that build flexible disclosure infrastructure now are in a better position than those who take a wait-and-see approach. By the time disclosure laws are in force in enough states to make the wait-and-see calculation clearly wrong, the organizations that were waiting will face simultaneous compliance pressure from multiple state laws.
Frequently Asked Questions
Common questions healthcare executives ask about AI disclosure and consent requirements.
Does Texas TRAIGA apply to all healthcare providers in Texas or only certain types?
TRAIGA applies to healthcare providers broadly. The law uses the term to capture the range of licensed and certified healthcare practitioners and entities operating in Texas. This means hospital systems, physician practices, behavioral health providers, and other healthcare organizations operating in Texas are subject to the disclosure requirements. The specific trigger is AI use in patient care interactions. If your organization uses AI in a context that interacts with or affects the care of Texas patients, the disclosure requirements apply. The emergency exception is the primary carve-out: disclosure requirements are suspended in emergency situations where obtaining disclosure before care would delay necessary treatment. Routine clinical encounters, patient communications, and AI-assisted workflows don't qualify for the emergency exception.
What does 'clear and conspicuous' disclosure actually require under Texas TRAIGA?
TRAIGA requires disclosure that is clear and conspicuous, meaning it must be presented in a way that a reasonable patient would notice and understand. Disclosure buried in a general consent form that patients sign on admission alongside dozens of other provisions is unlikely to meet this standard. The disclosure needs to be specific to AI use and presented in a context where the patient can understand it before or at the time of the AI interaction. For patient-facing AI tools, this may mean an explicit disclosure screen or statement when the patient first interacts with the AI system. For AI tools that affect care but aren't directly patient-facing, the disclosure approach may differ, but the standard of clarity and conspicuousness still applies.
Does California AB 3030 apply to AI tools our EHR vendor has built into their platform?
Yes, if your organization uses the EHR's generative AI features for clinical communications and those communications reach patients. AB 3030's obligations run to the healthcare provider (your organization), not just to the AI vendor or tool developer. If your organization sends patients AI-generated after-visit summaries, AI-generated care instructions, or AI-generated responses to patient portal messages, those communications need to include the AB 3030 disclaimer regardless of whether the AI is a third-party tool, an EHR-native feature, or something your organization built internally. Work with your EHR vendor to understand which features qualify as generative AI under AB 3030's definition and whether the vendor's default outputs include the required disclaimers.
Our organization operates in multiple states. How do we build a compliance program that works across all of them?
The approach CHIME recommends, and which the evidence supports, is to build your compliance program around the most stringent applicable requirements rather than managing separate standards per state. Identify which states you operate in, identify the disclosure requirements in each, and build your policies and patient-facing forms to satisfy the strictest applicable standard. A unified intake notification explaining AI use in clinical settings, written in plain language and reviewed by a patient or their representative, addresses the core disclosure requirements in Texas, California, and Illinois, and positions your organization for Colorado's requirements taking effect January 1, 2027. Point-of-interaction disclosures need to be built into specific AI workflows. The advantage of the unified approach is that it scales as more states enact requirements and it produces consistency in the patient experience across your system.
Can our AI vendor handle the disclosure requirements on our behalf?
Partially, but the compliance obligation is yours. Vendors can build disclosure language into their patient-facing products, and many are doing so in response to state law requirements. But your organization's obligation to ensure disclosure happens doesn't transfer to the vendor through a contract provision. You need to verify that the vendor's disclosure mechanisms actually satisfy the requirements of each state you operate in, that the disclosures are being delivered as required, and that you have documentation of the disclosure practices. Relying entirely on vendor implementations without verifying them creates compliance risk. Build your own disclosure verification into your AI governance and vendor management processes.
What are the penalties for non-compliance with these state laws?
The penalty structures vary by state and by law. Texas TRAIGA's non-compliance creates exposure to state licensing action (which for a healthcare organization means potential license consequences affecting the ability to operate) and to legal action under Texas consumer protection statutes. California's laws are enforced through state professional licensing boards for the professional credentials provisions, and through the Attorney General and local prosecutors for some consumer protection provisions. Illinois HB 1806 has enforcement mechanisms tied to professional licensing for the practitioners involved. The enforcement architecture suggests that the primary risk for organizations is regulatory action affecting operations and licenses, in addition to civil liability exposure in individual patient claims that allege violation of the disclosure requirements contributed to harm. The Texas AG's demonstrated willingness to pursue AI-related enforcement action against vendors is a data point that suggests enforcement appetite at the state level is real.
Sources
- Texas HB 149, Texas Responsible AI in Healthcare Act (TRAIGA). Effective January 1, 2026.
- Texas SB 1188. Effective September 1, 2025.
- Illinois HB 1806, Wellness and Oversight for Psychological Resources Act. Effective August 2025.
- California AB 3030. Effective January 1, 2025.
- California AB 489. Effective October 1, 2025.
- California SB 243. Effective January 2026.
- Colorado SB 26-189 (signed May 14, 2026). Effective January 1, 2027. Repeals and replaces Colorado SB 24-205, the Colorado AI Act.
- CHIME AI Governance Principles. College of Healthcare Information Management Executives. 2024.
- AI Governance in Healthcare: Current State, Frameworks, Implementation Evidence, and Gaps. Internal knowledge synthesis. 2025.
- State of Texas v. Pieces Technologies, Inc. Office of the Texas Attorney General. 2024.
Related Questions
- ›Who is liable when an AI clinical decision support tool contributes to harm?
- ›How should we document AI-assisted decisions in the medical record?
- ›Does our vendor's BAA actually prevent them from using our patient data?
- ›Do our malpractice insurance policies cover liability from AI-assisted clinical decisions?
- ›How to govern generative AI and agentic AI in health systems?
- ›What does Joint Commission AI guidance mean for my health system?

