Industry News

Washington Spent 2026 Trying to Erase State AI Laws. The Ones That Reach Your Scribe Were Never on the List.

Executive Order 14365 does not mention healthcare once. Meanwhile Rhode Island and Louisiana wrote the ambient AI scribe into statute, five states rewrote what a therapist may do with one, and eight states put humans back in front of AI claim denials. Here is every 2026 healthcare AI law that actually binds a practice — and why preemption is not coming to save anyone.

By MedAI Directory · September 10, 2026

The federal government spent 2026 trying to make state AI laws go away. It has not worked, and more to the point, it was never aimed at you.

While Washington fought over preemption, statehouses quietly passed the most consequential year of healthcare AI legislation so far. Tallies from groups tracking the issue put it at roughly 14 healthcare-specific AI laws across about a dozen states in 2026 alone — on top of the 2025 wave. Three of them, for the first time, write the ambient AI scribe into statute by name. Several more rewrite what a therapist is allowed to do with one.

None of those laws is on the federal target list. Here is what actually passed, what binds you today, and why the preemption fight is not going to rescue anyone.

The federal fight is real. It is also aimed somewhere else.

On December 11, 2025, the White House signed Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence" (published in the Federal Register December 16, 2025). It is the most aggressive federal move against state AI regulation to date. It directs the Attorney General to stand up an AI Litigation Task Force within 30 days to challenge state AI laws, tells Commerce to publish an evaluation identifying "onerous" state laws and to condition certain broadband funding on it, and instructs the FCC and FTC to explore federal standards that would displace conflicting state rules.

Read the order closely and one thing jumps out: it does not mention healthcare or medical AI anywhere.

Its stated targets are laws that "require AI models to alter their truthful outputs" and laws that compel developers to disclose or report information — with Colorado's "algorithmic discrimination" statute cited by name as the example. The carve-outs it proposes for any future preemption bill are child safety, AI compute and data center infrastructure, and state government procurement of AI. Healthcare disclosure and scope-of-practice rules are in neither bucket. They are simply not what this fight is about.

The follow-on National Policy Framework the White House sent to Congress in March 2026 is a legislative recommendation, not law. And Congress has repeatedly declined to act:

  • The 10-year state AI moratorium tucked into the 2025 budget reconciliation bill was stripped by the Senate 99–1 before the bill was signed on July 4, 2025.
  • A similar moratorium was left out of the 2025 National Defense Authorization Act.
  • Bipartisan omnibus attempts through mid-2026 stalled on the same impasse.

Meanwhile the machinery in the order has moved slowly. The Commerce evaluation of "onerous" state laws was due March 11, 2026; reporting through mid-2026 found it had still not been publicly released, along with the BEAD policy notice. The DOJ Task Force's one significant action has been intervening on April 24, 2026 in xAI's challenge to Colorado SB 24-205 — not a healthcare law. Enforcement of that statute was suspended by joint motion on April 27, 2026, and Colorado then repealed and replaced it with SB 26-189, signed May 14, 2026, effective January 1, 2027.

The only state AI statute the federal government has actually gone to court over is a general algorithmic-discrimination law — and the state repealed it anyway. Not one healthcare-specific AI law has been challenged.

States, for their part, have not slowed much. One mid-year count put 109 state AI laws enacted by July 1, 2026, against 121 by the same date in 2025.

Three states now regulate the scribe itself

Until this year, AI scribes were governed by general rules that happened to apply: HIPAA, state wiretapping statutes, and broad AI-disclosure laws like California's AB 3030 and Texas's TRAIGA. In 2026, states started naming the tool.

Rhode Island — the first law written at AI documentation

Rhode Island's Use of Artificial Intelligence by Healthcare Providers Notification Act (companion bills H 7538 and S 2570) was signed by Governor Dan McKee on June 22, 2026 and took effect immediately — no delayed date, no rulemaking runway.

The operative sentence is short enough to quote whole:

"Any and all healthcare providers and healthcare facilities that employ artificial intelligence ('AI') to document in-person or telehealth visits shall notify patients of the use of AI for that sole purpose and review the AI-generated documentation for accuracy after the visit."

Two obligations: tell the patient, and read the note. It reaches physicians, PAs, dentists, RNs and LPNs, APRNs, other health-department-licensed professionals, and facilities.

Now the part worth getting right, because a lot of coverage got it wrong. Several law firm alerts and trade headlines described this as an opt-out law. The enacted text contains no opt-out. It contains no consent mechanism, no right of refusal, and no stated penalty. A sponsor described patients as having "the option to opt out" in public remarks; that language never made it into the statute. What Rhode Island actually created is a notification-and-accuracy-review duty on providers, not a patient consent right.

That distinction matters for your workflow. A consent regime means building a refusal path and a fallback documentation method. A notification regime means updating your intake script and making sure someone genuinely reviews the note — which, as the accuracy research keeps showing, you should be doing anyway. (See Can You Trust AI Scribe Notes?.)

Louisiana — say it out loud, before you hit record

Louisiana's HB 475, enacted as Act 649 and effective August 1, 2026, requires a health care professional to verbally disclose the use of any recording device, software, or service before recording any part of an appointment or treatment that will be transcribed by AI.

Two design choices define it. The disclosure must be spoken, not buried in a signed intake packet. And it must come before the recording starts. Earlier drafts went further — requiring explicit patient consent and an opt-out — but those provisions were amended out during passage. As enacted, Louisiana clinicians must announce; patients have no statutory right to refuse.

Texas — already live, and broader than either

Texas's Responsible Artificial Intelligence Governance Act (HB 149) has been in effect since January 1, 2026. It requires providers to disclose AI involvement in a patient's diagnosis or treatment, in clear, conspicuous, plain language, no later than the date of service — or as soon as reasonably possible in an emergency. It is broader than a scribe rule, but it captures scribes. We covered it and California's AB 3030 in AI Disclosure Laws Are Here.

If you practice across state lines — and if you do telehealth, you do — the patient's location generally drives which of these applies.

Behavioral health got its own rulebook, and it is stricter

The largest cluster of 2026 laws restricts what AI may do in a mental health setting. Five states enacted therapy-AI statutes this year, joining Illinois and Nevada from 2025.

  • Maine — LD 2082, signed by Governor Mills April 13, 2026 (Public Law 2025, ch. 687), effective July 29, 2026. Licensees may use AI for administrative support (scheduling, billing, logistical messages) and supplementary support (preparing records, organizing referrals) under their own responsibility. AI may not make independent therapeutic decisions, directly engage clients in therapeutic communication, or generate recommendations or treatment plans without the licensee's review and approval. Where a session is recorded or transcribed, the client must be informed in writing and give written, revocable consent — through a clear, explicit, affirmative act, not a broad terms-of-use click. Offering therapy to the public through AI instead of a licensed professional is treated as a violation of Maine's Unfair Trade Practices Act.
  • Colorado — HB 26-1195, enacted June 3, 2026, effective August 12, 2026. Same administrative-and-supplementary-only shape, with advance written notice and clear, written, revocable consent for recording or transcription — and an explicit rule that clients cannot be denied services for refusing or revoking consent. AI is also barred from detecting emotions or mental states.
  • Rhode Island — S 2197, the Oversight of Artificial Intelligence Technology in Mental Health Care Act, signed June 22, 2026 and effective immediately. Written consent required for recorded or transcribed sessions; AI barred from independent therapeutic decisions, therapeutic communication, treatment plans, and emotion or mental-state detection. FDA-cleared tools are carved out.
  • Vermont — H 816 (Act 156), signed June 17, 2026. Entities may not deliver mental health services independently through AI; AI may not make diagnoses or generate treatment plans. Enforcement runs through unprofessional-conduct findings and Vermont's Consumer Protection Act.
  • Tennessee — SB 1580, signed April 1, 2026, effective July 1, 2026. Narrower than the others: it targets marketing, prohibiting anyone developing or deploying an AI system from advertising or representing it as capable of acting as a qualified mental health professional. Violations are unfair or deceptive acts under the Tennessee Consumer Protection Act, with civil penalties up to $5,000 per violation and an explicit private right of action. Clinician-supervised use of AI is untouched.

Add a regulator to the list. Arizona's Board of Behavioral Health Examiners adopted rules requiring that, beginning January 1, 2027, informed consent include notification of any artificial intelligence, machine learning, deep learning, or other human-simulation modality used to provide, record, or document clinical services. That language reaches transcription tools explicitly.

The practical read for therapists: the note-taking tools are still legal. Upheal, Mentalyc, and the rest of the AI therapy notes category sit squarely inside "administrative and supplementary support." What changed is the paperwork around them. In Maine, Colorado, and Rhode Island, a recorded session now needs written, revocable consent — a higher bar than the one-party recording consent those states otherwise allow, and higher than the checkbox most practices are using. For solo therapy practices and behavioral health group practices, that is a consent-form rewrite, not a tool change. Our therapy AI comparison and the privacy rules guide cover the tool side.

Delaware went at the problem from a different direction. HB 191, signed April 23, 2026, prohibits any nonhuman entity — explicitly including AI agents — from being licensed as a professional nurse, APRN, LPN, physician, or physician assistant, and bars nonhuman entities from using protected titles and abbreviations: doctor, physician, MD, DO, nurse, RN, APRN, CRNA, PA. It does not restrict your tools. It restricts what a vendor may call one.

The biggest cluster is aimed at your payer, not you

Eight states passed laws in 2026 limiting how health plans use AI in utilization review, prior authorization, and claim adjustment. These create obligations for insurers, and leverage for practices:

  • Alabama SB 63 (enacted April 17, 2026; effective October 1, 2026) — standards for the data AI tools rely on; AI recommendations are expressly supplemental, and a licensed professional must evaluate them against the enrollee's circumstances and the treating provider's recommendation.
  • Colorado HB 26-1139 (enacted June 2, 2026) — coverage decisions may not rest solely on AI-generated group data; individual medical history required.
  • Georgia SB 444 (enacted May 5, 2026; effective January 1, 2027) — AI may automate tasks, but may not issue an adverse determination until a qualified natural person conducts a utilization review with a clinical peer participating.
  • Illinois SB 3114, the Transparency in Downcoding Act, signed July 10, 2026 as Public Act 104-0568 — every downcoding determination must be made or reviewed by a natural person; payors may not downcode based solely on reported diagnosis codes, and may not target clinicians who routinely treat complex or chronic patients. It passed the House 111–0.
  • Indiana HEA 1271 (effective July 1, 2026) — bars plans from using an automated tool as the sole basis for downcoding without review of the medical record, and requires disclosure when AI drives an adverse prior-auth determination or a downcode.
  • Iowa HF 2635 (effective July 1, 2026) — AI may assist, but may not be the sole basis to deny, delay, or downgrade a medical-necessity request.
  • Utah SB 319 (enacted March 19, 2026; effective January 1, 2027) — decision-makers must exercise independent medical judgment and may not rely solely on recommendations from any other source, AI included.
  • Washington SB 5395 (effective June 11, 2026) — only a licensed physician or health professional acting in scope may deny a prior-auth request on medical necessity grounds.

If you appeal denials, this is the most useful development of the year. A denial produced by an algorithm without a named human reviewer is now a compliance problem for the plan in a growing number of states. Pair it with CMS-0057-F and the WISeR model for the federal half of the picture.

One catch worth flagging. Indiana's law is not purely payer-side. HEA 1271 also prohibits providers from using AI to submit claims without review by the provider or a billing professional. If you run an autonomous AI coding or RCM workflow in Indiana, that is a direct constraint on your setup — see AI Medical Coding and Billing in 2026 and what your payer's algorithm already noticed.

What to do about it

  • Check the patient's state, not just yours. Rhode Island, Louisiana, and Texas rules follow the patient. A multi-state telehealth panel means multiple rulebooks.
  • Move consent out of the intake packet. Louisiana wants it spoken. Maine, Colorado, and Rhode Island want it written and revocable for behavioral health recordings. A buried terms-of-use clause satisfies none of them.
  • Build a refusal path where consent is required. Colorado bars denying services to a client who refuses or revokes. That only works if you have a non-AI documentation fallback ready.
  • Document that someone reviewed the note. Rhode Island now requires accuracy review after the visit. Make it a visible step, not an assumption.
  • Ask vendors which states they have mapped. A vendor that cannot tell you how its consent flow handles Maine or Louisiana has not done the work.
  • Do not wait for preemption. No federal statute displaces any of this. The one law the government has litigated was repealed by its own legislature.

The throughline

Strip out the bill numbers and 2026's healthcare AI laws say three things, over and over: tell the patient, keep a licensed human accountable for the judgment, and read what the machine wrote. That is the same shape as 2025's laws, applied with more precision and, increasingly, to named tools rather than abstract categories.

The federal preemption campaign is loud, and it may eventually reshape how states regulate algorithmic discrimination or model transparency. It has shown no interest in whether your patient knows a microphone is on. Practices waiting for Washington to simplify this are waiting for something that is not coming.

Browse AI tools by use case, compare options for your specialty, or start with the HIPAA fundamentals.


This article is for general information only and is not legal or medical advice. State AI laws are changing rapidly, effective dates shift, and summaries here are condensed from enacted text and reputable legal analysis — verify the current statute and consult qualified counsel before relying on any specific rule. Always confirm a vendor's compliance posture directly with the vendor.

Tags
state-ai-lawsfederal-preemptioneo-14365ai-scribe-consentrhode-islandlouisianamainebehavioral-healthprior-authorizationdowncodingcompliance2026