TwinEthos homeAPI access

Control

AI copy or output implies that users' data has therapist-client confidentiality

Advertising, interface copy, persona prompts and model outputs of an AI product do not represent that users' conversations or data are confidential in a way that suggests the protection of therapist-client (or doctor-patient) confidentiality or privilege; privacy statements describe what is actually done with the data.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Family: AI presents itself as a licensed or credentialed professional · control id cond.ai-implies-therapist-client-confidentiality

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in Colorado (US-CO).

Trust and provenance

How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.

This control
Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
Lanes
Binding law — in force 1
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
Audit standard
1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.

The guard to add

Remove promises that AI chats are protected like therapy (therapist-client confidentiality or privilege) from prompts, replies, UI and marketing; describe the real data handling.

The persona prompt tells the model never to promise therapist-client or doctor-patient confidentiality or privilege and, when asked whether a chat is confidential, to point to the privacy notice; a check on the reply path replaces replies that make such a promise. Onboarding, UI strings, marketing pages and store listings describe what happens to conversation data (where it is stored, for how long, who can access it, whether it trains models) and never compare it with therapy; a CI copy scan keeps 'therapist-client confidentiality', 'doctor-patient privilege', 'as confidential as therapy' and 'completely confidential' out of those files.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text, 11 CI/CD pipeline.

What reviewers look for: no 'therapist-client' or 'doctor-patient' confidentiality or privilege, no 'as confidential as (a session with) your therapist', and no 'completely / 100% confidential' for AI conversations in prompts, replies, UI strings, marketing or listings; a reply-path filter or tested prompt rule that stops the model from making those promises; a privacy notice that states the actual handling.

Example (Python + OpenAI SDK), before:

reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
return {'reply': reply}

After:

CONFIDENTIALITY_CLAIM = re.compile(r'(?i)\b(therapist|doctor)[- ](client|patient) (confidentiality|privilege)'
                                  r'|\bas confidential as\b|\b(completely|100%) confidential\b')
reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if CONFIDENTIALITY_CLAIM.search(reply):
    reply = ('I am an AI, and our chats are not protected like a session with a therapist. '
             'Our privacy notice explains how conversations are stored and used.')
return {'reply': reply}

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.