TwinEthosRequest access

Control

AI used on recorded or transcribed therapy sessions without written notice and consent

Before AI assists with a recorded or transcribed therapy session, the client (or their legal representative) receives written notice that AI will be used and for what specific purpose, and gives explicit, written, revocable consent.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: People are not told they are interacting with, or being processed by, an AI system · control id cond.ai-on-recorded-therapy-session-without-written-consent

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in Illinois (US-IL).

The guard to add

Check a signed, unrevoked, purpose-specific AI-use consent for the client before any session audio or transcript is sent to an AI transcription, note, or summary model.

A consent gate in the note-assistant pipeline placed before the first AI step (a model transcription call counts) and again before the note or summary call: it loads the client's consent record for this tool's purpose (for example ai_scribe), requires signed_at and no revoked_at, and refuses otherwise. The record references the version of the written notice the client or their representative received, naming the tool's purpose. Consent is collected as a separate explicit act on its own form, never inferred from terms-of-use acceptance, and a revocation endpoint sets revoked_at and cancels queued AI jobs for that client.

Where it goes: 1 application source code, 2 data models, 14 user-facing text.

What reviewers look for: a consent check on every path from session audio or transcript to transcriptions.create, chat.completions.create, messages.create, or similar; a consent table with client, purpose, notice version, signed_at, and revoked_at; a standalone consent form (no 'by using this service you agree ... AI' copy); a revocation path that stops processing.

Example (Python + OpenAI SDK), before:

def draft_note(session):
    with open(session.audio_path, 'rb') as f:
        transcript = client.audio.transcriptions.create(model='whisper-1', file=f).text
    resp = client.chat.completions.create(model=MODEL, messages=[
        {'role': 'system', 'content': NOTE_PROMPT}, {'role': 'user', 'content': transcript}])
    return resp.choices[0].message.content

After:

def draft_note(session):
    consent = db.consents.get(client_id=session.client_id, purpose='ai_scribe')
    if consent is None or consent.signed_at is None or consent.revoked_at:
        raise ConsentRequired('written AI-use consent for note drafting is missing or revoked')
    with open(session.audio_path, 'rb') as f:
        transcript = client.audio.transcriptions.create(model='whisper-1', file=f).text
    resp = client.chat.completions.create(model=MODEL, messages=[
        {'role': 'system', 'content': NOTE_PROMPT}, {'role': 'user', 'content': transcript}])
    return resp.choices[0].message.content

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required