It was around two in the morning, on a Tuesday in a bad stretch of last winter, and I typed six or seven sentences into a chat window that I had not said out loud to anybody.
Nothing dramatic happened. No crisis, nobody to call — just the ordinary grinding kind of bad that does not qualify as anything. The machine wrote back, warm without being sticky, asked a follow-up, said something calm about sleep. I shut the laptop feeling maybe eight percent better.
Here is the part I am less pleased with. Over the following months I recommended the same move to two friends — try it, it's free, it's awake — and never once asked the question I ask for a living: what is that thing actually allowed to be?
In June I wrote here that the most popular therapist in America was neither a person nor trained — a complaint about an empty room. Millions of people, no rules, no board, no license to lose. On August 12, one state walked into that room. What matters is where it stopped.
What actually changed ten days ago
A Colorado law that took effect on August 12 — House Bill 26-1195, "Psychotherapy Artificial Intelligence Restrictions," signed by Governor Jared Polis on June 3, 2026 — does two things in two corners of the statute book, and the gap between them is the story.
The first lands on the clinician. Anyone lawfully permitted to provide psychotherapy in Colorado may not let an AI system conduct therapeutic communication with a client unless, in the words of the enrolled act, there is "synchronous, real-time interaction" between the provider, the AI system, and the client. All three, at once — and reviewing the interaction afterward explicitly does not count. Your therapist cannot read Thursday's transcript and call it supervision.
"Therapeutic communication" is defined generously — down to "offering emotional support, reassurance, or empathy in response to psychological or emotional distress." Reassurance counts. Wide net.
The second half sits in consumer protection law and binds not therapists but "a person" — anyone, including whoever builds the chatbot. It forbids claims: no output implying an AI's answers are equivalent to a licensed professional's, no representing that the system provides psychotherapy, no promising confidentiality a reasonable person would read as therapist-client protection. Breach is a deceptive trade practice; a licensee who breaks the other half answers to their board at the Department of Regulatory Agencies. The legislature's own fiscal note priced it at up to $5,000 per violation for a licensee and $20,000 under the state's consumer protection act — ceilings on paper, not fines anyone has paid — and budgeted zero new dollars and zero new staff to enforce it.
The sponsors' announcement quotes Representative Gretchen Rydin: "AI chatbots are being mistaken by patients as legitimate therapy, which is why we're stepping up." Earlier, as Colorado Politics covered the trio of AI bills, Representative Javier Mabrey named the objection: chatbots "mirror emotional tone rather than challenge it."
And Colorado did not ignore consumer chatbots; the easy version of this article would pretend it did. The same session produced a separate chatbot law, signed May 29, 2026: disclose the AI, run a protocol for prompts about suicidal ideation or self-harm, limit simulated emotional dependence with minors. It does not start until January 1, 2027, and nothing in it stops a chatbot from having the conversation.
The sentence that hands it back
So far, a hard line. Here is where it gets interesting.
One sentence after defining therapeutic communication broadly enough to include reassurance, the act carves itself back out. The term, it says, "does not include general wellness education, instruction, or guidance that is intended to promote overall health and well-being, rather than to diagnose, treat, or address a specific mental, emotional, or behavioral health concern."
Then a subsection lists what falls outside it entirely — self-help, therapeutic homework, coaching, guided meditation, journaling, reflections, psychoeducation, goal setting, progress tracking, mood monitoring, mindfulness and breathing exercises, crisis resource directories, safety planning, "or other wellness tools" — provided the tool does two things. It must not diagnose or treat mental health disorders, and it must "clearly and conspicuously disclose that the technology or service is not a substitute for clinical care."
Read that list again and picture a two-in-the-morning chat window. Reflections. Journaling. Mood monitoring. Safety planning. That is not a caricature of the free chatbot; it is an inventory.
Nor is it a drafting accident: the exemption appears in both halves of the act, word for word, and the lawyers advising Colorado clinics read the carve-outs the same way.
Precision matters here, so: this does not mean any particular chatbot is exempt, and nobody has tested it. The consumer-protection half does reach a general assistant the moment it implies equivalence to a licensed provider, claims to provide psychotherapy, or dresses your conversation in therapist-grade confidentiality. What the statute exempts is a category, described by function and disclaimer — and whether the thing you open at 2 a.m. lands inside it, nobody has ruled.
Which is the objection a law professor raised about this generation of statutes. The new state laws do not draw a clear distinction, Robin Feldman of UC Law San Francisco told CNN, between purpose-built therapy bots advertised as clinical support and general assistants people lean on for their depression, far beyond the product's stated purpose. One is inside the frame by design. The other is what most people use.
The strongest case against the law
I do not think this is a stupid law. But the case against it is stronger than the sponsors let on.
Start with burden. An AI-law commentator in Forbes called the real-time mandate a dubious precedent and "a tremendous time-sink burden on the therapist," predicting it will "heavily discourage therapists from using AI as a client-facing tool" — and he spotted the exit from inside: if the AI is not purporting to diagnose or treat, the requirement stops applying.
Then access. At the end of 2025, four million Coloradans lived in a designated mental-health shortage area, with about 41% of assessed need met; nationally, about 137 million people and just over a quarter of need met. In the same CNN report, Russell Fulmer, who chairs the American Counseling Association's AI task force, made the honest argument: for people who cannot get care at all, "a chatbot would be preferable to nothing." Colorado has just made it harder to put a supervised tool in front of a client there.
Whether that trade is worth it depends on what the unsupervised alternative already costs. By OpenAI's own estimate, reported by TechCrunch, about 0.15% of ChatGPT's weekly active users have conversations containing explicit indicators of potential suicidal planning or intent — against more than 800 million weekly users, over a million people a week. That is a company's estimate of its own product, not an audit; it is also, arguably, the largest mental-health intake in history, with no clinicians attached. And one in six American adults told KFF they had sought information related to their mental health from an AI chatbot in the past year — 16% of a nationally representative sample of 1,343, surveyed in late February 2026. "Sought information," not "replaced their therapist." But about three-quarters said they were concerned about privacy. Worried, and typing anyway. I recognize the posture.
Britain regulates the product. Colorado regulates the practitioner. Both stop at the same word.
Colorado regulated the person holding the license. The United Kingdom regulates the thing on your phone — and is instructive precisely because it did not solve this either. On January 27, 2026 the MHRA, Britain's medicines and devices regulator, published guidance on digital mental health technologies with NHS England. The rule is a product rule: a tool claiming to diagnose, treat or manage a mental health condition is a medical device, must meet safety standards and carry a CE or UKCA mark — and if it harms you, the Yellow Card scheme is somewhere to take it. How Britain decides what counts, in guidance from February 3, 2025, turns on the manufacturer's intended purpose — "whether it is to support wellbeing or to aid treatment" — then escalates into software as a medical device across risk classes I to III.
Britain also has a route Colorado lacks. NICE's early value assessment let four guided self-help digital CBT technologies into the NHS on February 8, 2023, for children aged 5 to 18 with mild-to-moderate anxiety or low mood, while the evidence was still being built — and its version of "keep a human in this" is a care-pathway condition, not a licensing prohibition: a human is required at the front door, an initial assessment plus regular check-ins, not a presence at every exchange. There is now a draft standard out for consultation, PAS 709:2026, and £2 million and an "AI airlock" from Wellcome behind the MHRA and NICE through autumn 2028.
Serious, funded, well-designed. And it lands on the same word Colorado landed on. The January guidance says so out loud: "Not all digital mental health technologies are regulated as medical devices – some are instead classed as wellbeing or lifestyle products. This does not necessarily mean they are unsafe, but they may not have been through the same checks."
Identical hole, opposite direction. Colorado draws the wellness-versus-treatment line inside a licensing statute, Britain inside device law; both leave the general-purpose chatbot outside. And people are outside with it: when Mental Health UK and Censuswide polled 2,000 UK adults in late October 2025, 37% said they had used an AI chatbot to support their mental health, and two-thirds of them had opened a general chatbot such as ChatGPT, Claude or Meta AI rather than a mental-health platform.
Britain's professionals have noticed. On February 23, 2026 BACP, the UK's professional body for therapists, warned that current arrangements "do not provide sufficient clarity or safeguards, particularly in mental health," and found 19% of child-facing therapists reporting young people who got harmful advice from chatbots — British therapists asking for the same thing Colorado's sponsors were. And Samaritans spent a February 2026 briefing asking the government which AI chatbot models the Online Safety Act even covers.
Now run it forward three years
Here is the future I actually expect, and it is not a dystopia. It is a compliance diagram.
It is 2029. Your Colorado therapist is fully compliant. Before your appointment an AI runs intake and psychoeducation — carve-out. Between sessions it tracks your mood, sets goals, walks you through breathing exercises, prompts your homework — carve-out. On a bad Sunday it hands you a crisis resource directory and helps you fill in a safety plan — carve-out, listed by name. Then, for twenty synchronous minutes on Thursday, a human joins the call. The machine did nine-tenths of the relationship; the law touched the tenth.
Outside the clinic the adaptation is cheaper still. A general assistant simply gets better at the two prongs: never say "diagnosis," never claim a credential, put "not a substitute for clinical care" above any conversation that turns emotional. Nothing else changes. A small industry sells wellness-tool positioning, the way one already sells cookie banners.
And the person at two in the morning scrolls past the disclaimer, the way fifteen years of the internet has trained them to, and types the thing anyway. Because it is free, it is awake, and the human alternative meets 41% of assessed need.
Where the serious people actually disagree
This is not left versus right. The disagreement runs through both camps.
Against: the American Enterprise Institute asked, of Illinois's version, where the line falls for a meditation app or a journaling platform that tracks mood, and found "minimal guidance for navigating the borderline scenarios" — with a First Amendment question over the area via Chiles v. Salazar. R Street argues the bans endanger lives, calling the Nevada and Illinois statutes first-of-their-kind bans on AI mental healthcare assistance "amidst an ongoing mental healthcare worker shortage." Eleven days ago, writing about bills aimed at children's chatbot safety rather than at therapy, ITIF published a version of the same warning: many of them "err by simply transplanting ineffective social media approaches such as age verification, content restrictions, and blanket bans."
For: Brown University researchers, working with practicing counselors, mapped fifteen distinct ethical risks across five categories when large language models were used for self-counseling — mishandled crises, reinforced negative self-beliefs, simulated empathy. Their line is the one I keep returning to: human therapists have boards and malpractice liability, but when LLM counselors commit these violations, "there are no established regulatory frameworks." The American Psychological Association's health advisory of November 13, 2025 covers chatbots and wellness apps in one breath, saying both lack the scientific evidence and the necessary regulations to ensure users' safety.
The enforcement lane was open before any of this passed. Twenty-two consumer groups led by the Consumer Federation of America asked the FTC in June 2025 to investigate character-based platforms for impersonating licensed therapists, alleging fabricated license numbers and false confidentiality claims; nothing has been proven. In May 2026, Pennsylvania sued Character.AI, alleging a chatbot falsely claimed Pennsylvania licensure and gave a fake license number while holding itself out as a psychiatrist — again, an allegation. The FTC opened its own inquiry into seven companion-chatbot companies last September.
One more, to keep this honest both ways: a purpose-built therapy bot in a clinical trial — Dartmouth's Therabot, built with continuous psychiatrist and psychologist input — cut depression symptoms by an average of 51% and anxiety by 31% over four weeks. The technology can work. Its own authors said in the same breath that no generative AI agent is ready to operate fully autonomously in mental health. Both halves are the finding.
Colorado is not alone: the Transparency Coalition counts five states that moved on AI therapy in 2026 — Colorado, Maine, Rhode Island, Tennessee and Vermont — joining Illinois and Nevada from 2025.
So what do you actually do with this?
None of this requires giving up the tool. It requires knowing what you are holding.
Read the disclaimer, because it is now load-bearing. "Not a substitute for clinical care" stopped being boilerplate the moment Colorado wrote it into the test for the exemption. Where you see it, you are looking at a product positioned outside the therapy rules on purpose.
Assume there is no confidentiality, because the law had to say so. Colorado specifically forbids implying your data is protected like therapist-client communication. Legislators wrote that clause because they expected you to believe otherwise. Do not.
If you see a therapist in Colorado, ask one direct question. Does AI touch any part of my care, and in what role? Since August 12, if a tool is doing therapeutic communication with you, your therapist has to be present in real time, not reading it back later — and the Department of Regulatory Agencies takes the complaint.
Treat a claimed credential as a red flag, not a comfort. A chatbot that says it is licensed, offers a license number, or calls what it does psychotherapy is doing the exact thing Colorado now calls a deceptive trade practice and Pennsylvania alleges in court. Screenshot it before you close the tab.
Keep the crisis path human and pre-loaded. A safety plan built with a chatbot sits inside the wellness carve-out — no clinician, no board, no duty to follow up. In the US, 988 reaches a person. Put it in your phone tonight, while you are calm, rather than at 2 a.m. while you are not.
Check your own state. Whether a therapist near you may hand part of your care to software now varies by state line, and 2026 moved several of them.
The line I would draw
I got something wrong in June. I said nobody was regulating the most popular therapist in America. That is no longer true: a state regulated it, quickly, and with real effect on how licensed care gets delivered.
But watch what the mechanism does. Colorado wrote a rule so demanding that a therapist, a machine and a client all have to be in the room at the same moment — and then, in the same act, twice, in identical words, described a category of tool that never has to enter the room at all. The line is not drawn between safe and dangerous, or supervised and unsupervised. It is drawn between things that claim to treat you and things that claim to help you feel better, and every incentive now points at claiming the second.
That is not corruption; it is the oldest problem in regulation. You must define a thing before you can govern it, and whatever you define, the market routes around — Britain hit the same wall from the other side. Nobody has yet had to prove that a product wearing the wellness label is safe for the person who reaches for it at the worst hour of their week.
My vote? Turn the disclaimer into a duty. If a tool wants the wellness exemption, make it earn it: publish what it does when a conversation turns to self-harm, hand the user a real crisis path instead of a paragraph, and accept somewhere to report it when it fails — the way a regulated British tool has the Yellow Card scheme behind it. Colorado proved a state can move fast. The next one should aim at the door, not the room.
The HAIA Foundation exists for the paragraph everybody skips — the definition, the carve-out, the sentence that quietly decides who a rule is actually for. That is the work, and it lands weekly at the Substack. Come read the fine print with us.





