More than 240 bills touching AI in healthcare were introduced across 43 states in 2026. Roughly a dozen became law. That is the practical governance picture right now: there is no single national healthcare AI statute, so the rules that actually bind a health system, a payer, or a digital health company are written state by state, with different effective dates, different enforcement bodies, and occasionally different answers to the same question.

This tracker records what is enforceable as of the review date, what is already scheduled, and what the recurring obligations look like once the individual bills are set side by side. It is organized by date rather than by state, because the date is what determines whether a compliance gap is theoretical or current.

In Effect as of September 15, 2026

These laws are live. An organization operating in these states is already subject to them.

State healthcare AI laws in force as of September 15, 2026.
State Law Core obligation In effect since
California AB 3030 (2024) Patient communications generated by AI that include clinical information must carry an AI disclaimer and clear instructions for reaching a human clinician. Applies to health facilities, clinics, and physician practices. January 1, 2025
California SB 1120 (2024) Medical necessity determinations in utilization review must be made by a licensed physician or other qualified licensed professional. An algorithm may inform the review but cannot make the determination. January 1, 2025
California AB 489 (2025) AI systems may not use language implying licensed healthcare credentials in patient-facing communication or marketing. January 1, 2026
Texas HB 149, TRAIGA (2025) Disclosure when AI is used in relation to a healthcare service or treatment, plus prohibitions on discriminatory intent, manipulation toward self-harm, and unlawful biometric capture. Attorney General enforcement, 60 day cure period, no private right of action. January 1, 2026
Utah SB 150 (2026) AI providing patient advice or treatment without practitioner interaction does not qualify as a regulated scope-of-practice innovation. Enacted March 24, 2026
Iowa HF 2635 (2026) AI may support initial prior authorization review but may not be the sole basis for a denial. Enacted May 13, 2026
Maryland HB 1563 (2026) Quarterly insurer reporting of adverse determinations, service type, and whether AI was involved, with commissioner authority to investigate rising denial rates. June 1, 2026
Washington SB 5395 (2026) Only a licensed physician or licensed health professional may deny or delay a service on medical necessity grounds. Reporting to the insurance commissioner required. June 11, 2026
Vermont H 816 (2026) Mental health services must be delivered by licensed professionals rather than an independent AI system. June 17, 2026
Indiana HB 1271 (2026) AI may not be the sole basis for downcoding a claim without review by a healthcare professional, and AI-submitted claims require provider review. July 1, 2026
Tennessee SB 1580 (2026) AI systems may not be represented or advertised as a qualified licensed mental health professional. Violations are treated as unfair or deceptive practices. July 1, 2026
Maine LD 2082 (2026) Behavioral health providers may use AI for administrative functions only. Therapeutic communication, treatment decisions, and independent patient interaction are barred, and recording tools require consent. July 29, 2026
Iowa HB 475 (2026) Verbal disclosure required before an appointment is recorded for AI transcription. August 1, 2026
Colorado HB 1195 (2026) Restricts AI therapy chatbots and bars licensed mental health professionals from delegating independent therapeutic decisions to AI. August 12, 2026
Illinois Wellness and Oversight for Psychological Resources Act (2025) AI may not deliver therapy independently or be marketed as a therapist unless a licensed professional remains accountable. Civil penalties up to 10,000 dollars per violation. August 2025
Nevada AB 406 (2025) AI may not stand in for a counselor or psychologist, including in school settings. July 2025
Utah HB 452 (2025) Mental health chatbots must disclose that they are software, with limits on advertising and on use of the personal data users disclose. 2025

Scheduled: October 2026 Through July 2027

These are already enacted with future effective dates. The lead time is the useful part. A governance committee that starts in the quarter before an effective date is generally ahead of the requirement rather than reacting to it.

Enacted state healthcare AI laws with effective dates still ahead, as of September 15, 2026.
State Law Core obligation Takes effect
Alabama SB 63 (2026) Coverage authorization decisions must reflect the beneficiary's own medical history and clinical circumstances rather than group data alone. Insurers must disclose AI use, denials must come from a licensed professional, and annual certification is required. October 1, 2026
Colorado HB 1139 (2026) Utilization review AI must rely on individual clinical history, must not be applied in a discriminatory way, and must be periodically audited for accuracy. Covers insurers, pharmacy benefit managers, private review organizations, behavioral health administrative services organizations, and managed care entities. Licensed clinician review of denials required. January 1, 2027
Georgia SB 444 (2026) Coverage decisions may not be based solely on AI. An adverse determination requires a utilization review in which a clinical peer participates, and AI may not supersede that clinical judgment. January 1, 2027
Utah SB 319 (2026) Insurers must disclose AI use in preauthorization review, and the individual reviewing an adverse determination must apply independent medical judgment. January 1, 2027
Rhode Island H 7349 and S 2197 (2026) Therapy services require a licensed professional, and licensed providers may not use AI for independent therapeutic decisions. January 1, 2027
Oregon SB 1546 (2026) Disclosure for AI companions, evidence-based self-harm detection protocols, heightened safeguards for minors, and a private right of action. January 1, 2027
Arizona Behavioral health board regulations Documented informed consent required before using AI, machine learning, or human simulation modalities with a client. January 1, 2027
Colorado SB 26-189 (2026) Replaces the repealed 2024 Colorado AI Act with a narrower automated decision-making technology statute: pre-use consumer notices, 30 day adverse-outcome explanations, meaningful human review rights, and developer documentation duties. January 1, 2027
Idaho Conversational AI Safety Act (2026) Mandatory disclosure when a user is interacting with AI, crisis protocols for suicidal ideation, and a prohibition on representing the system as a professional healthcare provider. July 1, 2027
Nebraska Conversational AI Safety Act (2026) Substantially the same obligations as the Idaho statute. July 1, 2027

Pending at the Review Date

Illinois SB 3114 would prevent automated processes from bypassing healthcare professional review when a claim is downcoded, requiring human review for all downcoding determinations. It had passed the legislature and was awaiting the governor's signature at the most recent source review. Treat it as likely rather than settled, and confirm status before building it into a compliance calendar.

What Colorado Tells You About Planning Horizons

Colorado is the clearest warning against building a compliance program around a single statute. The 2024 Colorado AI Act, widely treated as the template other states would copy, had its effective date delayed and was then repealed and replaced by SB 26-189, signed May 14, 2026, with substantive obligations starting January 1, 2027. Organizations that mapped controls to the original text spent a year preparing for requirements that no longer exist in that form.

The durable lesson is to govern the obligation rather than the citation. Human review of adverse determinations, disclosure of AI involvement, individualized clinical evidence, and auditability survive across every version of every bill in this tracker. Statute numbers do not.

The Four Obligations That Repeat Across States

Read the whole set together and the drafting converges on four requirements. Building controls against these four covers most of the individual statutes without tracking each one separately.

  1. A licensed human decides. AI may triage, summarize, draft, and recommend, but an adverse coverage determination, a medical necessity denial, a downcode, or a therapeutic decision must be made by a licensed professional who can be named.
  2. The decision must be individualized. Several statutes specifically bar reliance on group or population data alone, which means the organization has to be able to show the individual clinical record the decision rested on.
  3. Disclosure is owed to the person affected. Whether it is an AI-drafted patient message, a recorded visit, a prior authorization review, or a chatbot, the obligation is to tell the patient or member plainly, in the interaction itself.
  4. The system must be auditable after go-live. Accuracy audits, annual certifications, quarterly denial reporting, and adverse-outcome explanations all assume the organization retained enough evidence to reconstruct what the model did and why.

What a Provider Organization Should Do This Quarter

  1. Inventory every AI system that touches a coverage decision, a clinical recommendation, a patient-facing message, or a recorded encounter, and name an accountable clinical owner for each.
  2. Map that inventory against the states where the organization operates or holds licensure, not only the state of the head office.
  3. Confirm that every adverse determination workflow produces a named licensed reviewer and a retained record of the individual clinical evidence used.
  4. Check that AI-generated patient communications and recording consent language are already deployed, since the California and Iowa disclosure requirements are live now.
  5. Put the October 1, 2026 and January 1, 2027 effective dates on the governance committee calendar, and read them against the wider hospital AI governance framework rather than as isolated compliance tasks.

How This Tracker Relates to the Rest of the Library

This page covers state statute only. For the federal and agency layer, including FDA authorization, HIPAA, and ONC information blocking rules, see what actually governs healthcare AI. For turning these obligations into a standing committee structure, see the AI governance framework for hospitals and where AI compliance accountability sits. For the vendor side of the same questions, see the healthcare AI company market map.

Method, Scope, and Known Conflicts

Entries are limited to enacted state law and adopted board regulations that specifically govern AI in healthcare delivery, health insurance determinations, behavioral health, or healthcare credential representation. General-purpose state AI statutes appear only where they carry an explicit healthcare provision. Federal rules, agency guidance, and proposed bills that have not passed are out of scope.

Bill designations vary between chambers and between trackers. Maine LD 2082 is listed as HB 2082 in some sources, and at least one law firm alert lists the Georgia utilization review law as SB 544 where the enrolled bill is SB 444. Where sources conflict, this tracker follows the designation supported by the legislature's own record and notes the variant here. Effective dates are stated as reported by the cited sources on the review date, and a date recorded as an enactment date rather than an effective date is labeled that way.

This tracker is reviewed monthly and after any significant legislative action. The review date, the next scheduled review, and the date each entry was last confirmed are published at the top of the page so a reader can judge how current it is without guessing.