TwinEthosRequest access

Control

AI detects a client's emotions or mental state in a therapy practice

A licensed therapy professional's software does not use AI to infer clients' emotions or mental states.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Control id cond.ai-emotion-or-mental-state-detection-in-therapy

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in Illinois (US-IL).

The guard to add

Remove emotion, affect, and mental-state inference (libraries, model ids, APIs, prompts) from every path that processes client session data in therapy software.

On client data paths (session audio and video, transcripts, messages, notes), the software does not run emotion or affect recognition: no emotion classifiers such as go_emotions or the j-hartmann emotion models, no DeepFace emotion analysis, no Hume expression measurement, no Rekognition DetectFaces with Attributes=['ALL'], and no prompt asking a model to detect or assess the client's mood or mental state. Features that remain (transcription, summaries of what was said, scheduling) are instructed not to label emotions or mental states, and any assessment stays with the licensed professional. A dependency and model-id denylist check in CI keeps these from returning.

Where it goes: 1 application source code, 5 dependencies, 7 prompt construction, 11 CI/CD pipeline.

What reviewers look for: no emotion-recognition package, model id, or API (DeepFace.analyze with emotion, FER(, detect_emotions(, HumeClient, expression_measurement, speech emotion recognition models) reachable from client session data; no prompt that asks a model to read, assess, or classify the client's emotions, mood, or mental state; summarization prompts that tell the model not to infer them; a CI denylist covering those dependencies and model ids.

Example (Python + Hugging Face transformers), before:

emotion = pipeline('text-classification', model='j-hartmann/emotion-english-distilroberta-base')
note.client_emotions = emotion(transcript[:512])
note.summary = summarize(transcript)

After:

# no emotion classifier on client transcripts; the therapist records any assessment
note.summary = summarize(transcript)

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)