Artificial intelligence, or AI, is becoming part of everyday life, and therapy is no exception. The National Institute of Standards and Technology defines AI as a machine-based system that can make predictions, recommendations, or decisions based on human-defined objectives. Generative AI is a type of AI that creates new content, such as text, audio, or images, based on patterns in the data it has learned from.
In the past few years, companies have developed a growing number of AI tools for therapists. Some can transcribe sessions and draft progress notes. Others help create treatment plans, summarize information, or suggest possible diagnoses and interventions. These tools may save therapists time, but they also raise important questions about privacy, consent, accuracy, and accountability.
The technology has developed faster than many of the laws and professional guidelines governing it. As those rules catch up, clients deserve to understand how AI may be used in their care and what questions they have the right to ask.
AI Can Support Therapy, but It Cannot Be the Therapist
A growing number of states are passing laws that place limits on AI in mental health care. The details vary, but many of these laws draw an important distinction between using AI as a support tool and allowing AI to function as the therapist.
I am licensed in Colorado, where a law enacted in 2026 places clear restrictions on the use of AI in psychotherapy. Among other requirements, the law says that AI cannot independently provide psychotherapy or make treatment recommendations without the involvement and approval of a licensed professional. Therapists may use AI for administrative or supplemental support, but they remain responsible for reviewing its output and for the care they provide.
The Colorado law also requires a therapist to tell a client in advance if an AI system will record or transcribe a session, explain why it will be used, and obtain the client’s written, informed consent. It also prohibits AI services from presenting themselves as psychotherapists or implying that users’ information receives the same confidentiality protections as information shared with a therapist.
The central idea is simple: technology may assist with therapy, but clinical responsibility must remain with a qualified human professional.
Why Human Judgment Matters
Mental health care is rarely cut and dried. There is no blood test that automatically determines whether someone has anxiety, ADHD, or a trauma-related disorder. Diagnosis and treatment require context, judgment, and an ability to hold complexity. A therapist considers not only a list of symptoms, but also a client’s history, relationships, culture, environment, strengths, and changing circumstances.
AI can produce information that sounds polished and confident while still being incomplete, biased, or simply wrong. That is one reason a licensed professional should remain responsible for diagnoses, treatment plans, interventions, and other clinical decisions.
Licensure also creates accountability. Therapists are answerable to state licensing boards and professional standards. If a licensed therapist behaves unethically or causes harm, a client has somewhere to bring a complaint. An AI system does not hold a license, does not have a professional duty to you, and cannot be held accountable by a licensing board.
Licensing boards are not perfect, and there are reasonable criticisms of how some of them operate. Still, their purpose is public protection, not generating profit for a technology company. That distinction matters when the subject is something as personal and consequential as mental health care.
Privacy, HIPAA, and Your Data
HIPAA stands for the Health Insurance Portability and Accountability Act. Among other things, HIPAA establishes privacy and security protections for certain health information.
When individually identifiable information about your health or health care is held by a HIPAA-covered provider or one of its business associates, it is generally considered protected health information, or PHI. In therapy, that may include your diagnosis, treatment plan, appointment information, and what you discuss in sessions. PHI can also include identifying information such as your name, address, phone number, or email address when it is connected to your health care.
You may have encountered these protections when one provider wanted to communicate with another. For example, your therapist may ask you to sign a release of information before speaking with your physician or psychiatrist. That release can specify who may communicate, what information may be shared, and for what purpose.
One important limitation is that HIPAA does not apply to every company that collects health-related information. It applies to specific covered entities and their business associates. A general wellness app, consumer chatbot, or technology company may collect deeply personal information without being subject to HIPAA in the same way your therapist is. A statement such as “HIPAA compliant” also does not, by itself, answer every privacy question about a product.
When a therapist uses an outside company to create, receive, maintain, or transmit PHI, HIPAA generally requires appropriate safeguards and a business associate agreement. But clients may still reasonably want to know exactly what happens to their information.
There are documented examples of mental health technology companies mishandling sensitive information. In 2023, the Federal Trade Commission finalized an order requiring BetterHelp to pay $7.8 million and restricting it from sharing consumers’ health data for advertising. The FTC alleged that BetterHelp had shared sensitive data with companies including Facebook and Snapchat after promising consumers that their information would remain private.
This case was not specifically about an AI note-taking tool, but it illustrates a larger concern: a company’s business model and privacy practices matter. Technology companies may earn money in ways that extend beyond charging a fee for a service, including through advertising, data collection, or investment-driven growth.
It is also important not to assume that every AI tool uses client information to train its models, or that none of them do. Practices differ across companies and contracts. A therapist considering an AI tool should understand whether information is stored, how long it is retained, who can access it, whether it is used to train or improve the system, and whether it is shared with any third parties.
Clients are allowed to ask those questions, too.
Professional Ethics Still Apply
State laws are only one layer of protection. Therapists may also be accountable to ethical codes established by their professional organizations. Marriage and family therapists, social workers, professional counselors, and psychologists each have professional associations that issue ethical standards and guidance for their fields.
I am a marriage and family therapist, so one of the organizations I look to is the American Association for Marriage and Family Therapy, or AAMFT. Other examples include the National Association of Social Workers, the American Counseling Association, and the American Psychological Association. Guidance continues to develop as the technology changes, but familiar ethical responsibilities, including informed consent, confidentiality, professional competence, and responsibility for clinical decisions, do not disappear simply because a therapist uses a new tool.
Even if your state has not passed a law specifically addressing AI in therapy, your therapist likely has existing legal and ethical obligations that shape how technology should be evaluated and discussed with you.
Questions You Can Ask
Therapy can sometimes feel like a black box. Even if you have been in therapy before, you may not know what happens behind the scenes or what professional standards apply. You are allowed to ask for clarity.
Questions might include:
- Do you use AI in any part of my care?
- Does any AI tool listen to, record, or transcribe our sessions?
- What does the tool do with my information, and how long is it retained?
- Is my information used to train or improve an AI model?
- Does the company have access to identifiable information about me?
- Have you entered into a business associate agreement with the company?
- Do you review and approve everything the AI tool generates?
- Can I decline the use of AI, and what happens if I do?
You may decide that you are comfortable with a therapist using an AI tool. You may decide that you are not. The point is not that every use of AI is inherently harmful (I used AI to help me turn a voice memo into this blog post). The point is that you should be told when it affects your care, given enough information to make a meaningful decision, and allowed to say no when your consent is required.
AI may become a useful support for some parts of mental health care, but convenience does not outweigh privacy, consent, or professional responsibility. You deserve to know when AI is being used, what information it can access, and who remains accountable for your care.
Most importantly, you are allowed to ask. A thoughtful therapist should be willing to explain their practices clearly and take your concerns seriously.
Sources
- National Institute of Standards and Technology: Artificial Intelligence
- Colorado General Assembly: HB26-1195, Psychotherapy Artificial Intelligence Restrictions
- U.S. Department of Health and Human Services: Summary of the HIPAA Privacy Rule
- U.S. Department of Health and Human Services: Business Associates
- Federal Trade Commission: BetterHelp Final Order
