TwinEthos homeAPI access

Law

Colorado HB 26-1195 (C.R.S. 12-245-224.5, AI in psychotherapy services)

Colorado regulating boards under article 245 of title 12 (mental health professions) · Colorado (US-CO) · 7 provisions encoded · verified against the official source as of 2026-10-02.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: leg.colorado.gov.

Trust and provenance 3 official sources · last verified 2 Oct 2026 to 3 Oct 2026 · not reviewed by a lawyer · 7 of 7 provisions audit-grade · release 2026.10.03.4

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 7
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
None of the 7 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 7.
Audit standard
7 of 7 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
14 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.

Binding law — in force

Colorado psychotherapists' use of AI must comply with state and federal privacy and security law, including HIPAA (Colorado HB 26-1195)

C.R.S. 12-245-224.5(3) · official text · In force: applies since 12 Aug 2026 · Colorado (US-CO)

C.R.S. 12-245-224.5(3), added by Colorado HB 26-1195, makes the use of an AI system by a licensee, registrant, certificate holder or other individual lawfully permitted to provide psychotherapy services in Colorado subject to applicable state and federal privacy and security laws, including the Health Insurance Portability and Accountability Act of 1996 (Pub.L. 104-191) and its implementing regulations. Detect session notes, transcripts or other client records sent to a model API with no business-associate agreement, HIPAA-eligible endpoint or de-identification safeguard.

Trust and provenance not reviewed by a lawyer · audit-grade · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 12 Aug 2026
Official source
C.R.S. 12-245-224.5(3) · captured 3 Oct 2026 · anchor hash (SHA-256) 0f47b99ddb3c… · 10 more anchors in the data release
Verification
Quoted text not yet verified word for word against the official document. Not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Health fields renamed to generic identifiers
  • Model calls wrapped in an internal client
  • Vendor coverage (a business associate agreement, a HIPAA-eligible endpoint) is often recorded outside the repository; the finding asks for it, it does not establish that none exists.

Who it applies to

  • Duty falls on: individual professional
  • Sectors: healthcare
  • Colorado licensees, registrants and certificate holders under article 245 of title 12, and other individuals lawfully permitted to provide psychotherapy services in Colorado, when they use or allow an AI system (any machine-based system that infers from its inputs how to generate outputs, 12-245-224.5(1)(b)) in psychotherapy services. Vendors of practice software are reached through what the professional may allow the AI to do. 'Psychotherapy services' takes its meaning from 12-245-202 (not captured). In force since 2026-08-12; the act applies to actions taken on or after that date (HB 26-1195 sec. 4).
  • Not covered:
    • AI used within an accredited or approved educational, instructional or professional training program, solely for educational, administrative, simulation or training purposes, not deployed, marketed or represented for use with clients, patients or the public, and reviewed or controlled by a licensed professional where it includes clinical decision-making content (C.R.S. 12-245-224.5(7))
    • Involvement in developing, testing or evaluating an AI system solely for research under the oversight of an institutional review board registered with HHS, while the system is not offered to consumers or used to provide psychotherapy services outside the research setting (12-245-224.5(8))
    • Using or recommending self-help, therapeutic homework, coaching, journaling, psychoeducation, session preparation or summaries, mood monitoring, crisis resource directories, safety planning or other wellness tools that do not diagnose or treat mental health disorders and clearly and conspicuously disclose that they are not a substitute for clinical care (12-245-224.5(9)(a))
    • Using or recommending a technology or service the FDA has authorized, approved, cleared or granted enforcement discretion for an intended use that includes delivering behavioral health interventions, that does not diagnose or treat mental health disorders and that discloses it is not a substitute for clinical care (12-245-224.5(9)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.

A single client factory for model, embedding and transcription calls that handle health information: it looks the endpoint up in a vendor register and refuses to return a client unless the register shows the required contract (business associate agreement, or a processing agreement barring further disclosure) and the endpoint is the covered deployment with data retention and training use turned off. Call sites that cannot meet that de-identify or redact the record before building the prompt, or check a recorded patient authorization for that use. Keep the vendor register in the repository so reviewers can match each AI endpoint to its legal basis, and never route health data into marketing or other non-care generation.

Where it goes: 6 API calls and integrations, 3 config and feature flags, 7 prompt construction, 12 repository artifacts.

Example (Python + OpenAI SDK (Azure OpenAI)), before:

client = OpenAI()
resp = client.chat.completions.create(model='gpt-4o', messages=[
    {'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])

After:

VENDORS = load_yaml('vendors/ai_vendors.yaml')   # baa_signed, zero_data_retention per endpoint

def phi_client(name: str) -> tuple[AzureOpenAI, str]:
    v = VENDORS[name]
    if not (v['baa_signed'] and v['zero_data_retention']):
        raise PermissionError(f'{name} is not cleared for PHI')
    client = AzureOpenAI(azure_endpoint=v['endpoint'], api_key=os.environ['AZURE_OPENAI_KEY'],
                         api_version=v['api_version'])
    return client, v['deployment']

client, deployment = phi_client('azure-openai-hipaa')
resp = client.chat.completions.create(model=deployment, messages=[
    {'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])

Control: Health information sent to an external AI vendor without the contractual or legal basis the law requires. The same guard addresses 9 items with binding law in 8 jurisdictions. Engineering guidance, not legal advice.

Rule id co-hb26-1195.ai-privacy-compliance · review status: primary source derived

Binding law — in force

Colorado psychotherapists must not let AI do therapy or talk therapeutically with clients unless they take part in real time (Colorado HB 26-1195)

C.R.S. 12-245-224.5(6)(a) · official text · In force: applies since 12 Aug 2026 · Colorado (US-CO)

C.R.S. 12-245-224.5(6)(a), added by Colorado HB 26-1195, bars a licensee, registrant, certificate holder or other individual lawfully permitted to provide psychotherapy services in Colorado from using an AI system to provide, direct or guide (or attempt to) psychotherapy, clinical intervention, counseling, diagnosis, treatment planning or any other practice of psychotherapy with an individual or a group unless the use complies with 12-245-224.5(5); (5)(a) bars allowing an AI system to interact with clients in any form of therapeutic communication without synchronous, real-time interaction between the professional, the AI system and the client. 'Synchronous' means simultaneous active participation of the client and the professional and does not mean a review after the interaction (1)(e); therapeutic communication includes reflecting a client's thoughts and emotions, therapeutic guidance or interventions, emotional support in response to distress, work on treatment goals and behavioral feedback, but not general wellness education (1)(f). At initial client contact the professional must give the client written information on these prohibitions (6)(b). Training programs, IRB research, and self-help or FDA-authorized tools that do not diagnose or treat and disclose they are not a substitute for clinical care are carved out (7)-(9). Detect an AI cast or offered as the therapist, and model replies sent straight to clients with no professional in the session.

Trust and provenance not reviewed by a lawyer · audit-grade · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 12 Aug 2026
Official source
C.R.S. 12-245-224.5(6)(a) · captured 3 Oct 2026 · anchor hash (SHA-256) ebbaf5470def… · 14 more anchors in the data release
Verification
Quoted text not yet verified word for word against the official document. Not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Marketing copy and app-store listings kept outside the repository
  • Therapy framing that avoids the words therapy, therapist and counselor (for example 'talk through your anxiety with Maya')
  • Clinician-facing tools for scheduling, billing or notes use similar words but are permitted uses (40.1-5.5-2(6)); religious counseling, peer support, self-help content and FDA-cleared tools are outside the chapter (40.1…

3 more known limits in the data release.

Who it applies to

  • Duty falls on: individual professional
  • Sectors: healthcare
  • Colorado licensees, registrants and certificate holders under article 245 of title 12, and other individuals lawfully permitted to provide psychotherapy services in Colorado, when they use or allow an AI system (any machine-based system that infers from its inputs how to generate outputs, 12-245-224.5(1)(b)) in psychotherapy services. Vendors of practice software are reached through what the professional may allow the AI to do. 'Psychotherapy services' takes its meaning from 12-245-202 (not captured). In force since 2026-08-12; the act applies to actions taken on or after that date (HB 26-1195 sec. 4).
  • Not covered:
    • AI used within an accredited or approved educational, instructional or professional training program, solely for educational, administrative, simulation or training purposes, not deployed, marketed or represented for use with clients, patients or the public, and reviewed or controlled by a licensed professional where it includes clinical decision-making content (C.R.S. 12-245-224.5(7))
    • Involvement in developing, testing or evaluating an AI system solely for research under the oversight of an institutional review board registered with HHS, while the system is not offered to consumers or used to provide psychotherapy services outside the research setting (12-245-224.5(8))
    • Using or recommending self-help, therapeutic homework, coaching, journaling, psychoeducation, session preparation or summaries, mood monitoring, crisis resource directories, safety planning or other wellness tools that do not diagnose or treat mental health disorders and clearly and conspicuously disclose that they are not a substitute for clinical care (12-245-224.5(9)(a))
    • Using or recommending a technology or service the FDA has authorized, approved, cleared or granted enforcement discretion for an intended use that includes delivering behavioral health interventions, that does not diagnose or treat mental health disorders and that discloses it is not a substitute for clinical care (12-245-224.5(9)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Have a licensed clinician conduct every therapy engagement with AI output only as a reviewed draft, or scope the product to self-help with no therapy claims.

Two acceptable shapes, enforced in the message handler that returns model output to the person. If the product is a therapy service, each session has a licensed clinician assigned (session.conducted_by with an active license in the right state), and model output is a draft that clinician approves before it is sent (require_clinician_approval, clinician review queue). If it is not a therapy service, scope it to peer support or scripted self-help, remove persona prompts that cast the AI as the therapist ('act as a therapist'), and remove copy that offers therapy with or by AI.

Where it goes: 1 application source code, 7 prompt construction, 14 user-facing text.

What this provision adds:

  • AI takes part in therapeutic communication only inside a live session the professional actively joins; reviewing the exchange afterwards does not make it synchronous.
  • At initial client contact, give the client written information on the prohibitions on AI in psychotherapy (for example in the intake documents the practice software sends).

Example (FastAPI + OpenAI SDK), before:

@app.post('/session/message')
def message(req: Msg):
    msgs = [{'role': 'system', 'content': "You are the user's therapist."}, *req.history]
    reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
    return {'reply': reply}

After:

@app.post('/session/message')
def message(req: Msg):
    session = sessions.get(req.session_id)
    clinician = session.conducted_by
    if clinician is None or not clinician.license_active:
        raise HTTPException(409, 'No licensed clinician is conducting this session')
    msgs = [{'role': 'system', 'content': CLINICIAN_DRAFT_PROMPT}, *req.history]
    draft = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
    clinician_review_queue.enqueue(session_id=session.id, clinician_id=clinician.id, draft=draft)
    return {'status': 'sent_to_your_clinician'}

Control: AI delivers or is offered as therapy to the public without a licensed professional conducting it. The same guard addresses 6 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession

Rule id co-hb26-1195.no-ai-psychotherapy-without-synchronous-therapist · review status: primary source derived

Binding law — in force

AI advertising, interface and outputs must not represent that users' data is protected like therapist-client confidentiality (Colorado HB 26-1195)

C.R.S. 6-1-1705.2(1) · official text · In force: applies since 12 Aug 2026 · Colorado (US-CO)

C.R.S. 6-1-1705.2(1)(c), added by Colorado HB 26-1195, bars any person from using any term, letter or phrase in the advertising, interface or outputs of an AI system in a manner that represents that a user's data is confidential in a way that would lead a reasonable user to believe that the data is protected comparably to the privacy protections of therapist-client confidentiality in a relationship between a Colorado psychotherapy licensee, registrant, certificate holder or other person lawfully permitted to provide psychotherapy services and the client. Training programs, IRB research, and self-help or FDA-authorized tools that do not diagnose or treat and disclose they are not a substitute for clinical care are excluded (6-1-1705.2(3)-(5)). Detect persona prompts, replies, onboarding and marketing copy that promise therapist-client or doctor-patient confidentiality or privilege, or confidentiality 'like therapy'.

Trust and provenance not reviewed by a lawyer · audit-grade · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 12 Aug 2026
Official source
C.R.S. 6-1-1705.2(1) · captured 3 Oct 2026 · anchor hash (SHA-256) 1387683290a2… · 14 more anchors in the data release
Verification
Quoted text not yet verified word for word against the official document. Not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Implied confidentiality from design alone (a 'private therapy room' interface with no words)
  • Claims made only in images, audio or app-store screenshots
  • A sentence about the confidentiality duty of human therapists who actually provide a service ('your therapist keeps your records confidential under HIPAA'), or one that says chats are not protected like therapy, is not…

Who it applies to

  • Duty falls on: any person
  • Sectors: healthcare
  • Any person who uses a term, letter or phrase in the advertising, interface or outputs of an AI system (any machine-based system that infers from its inputs how to generate outputs, 12-245-224.5(1)(b) as applied by 6-1-1705.2(6)(a)) offered to people in Colorado. A psychotherapy licensee, registrant or certificate holder is not liable under the section for defects or failures of an AI system attributable to its developer or deployer, whose liability is governed by consumer protection law (6-1-1705.2(2)). 'Psychotherapy services' takes its meaning from 12-245-202 (not captured). In force since 2026-08-12; the act applies to actions taken on or after that date (HB 26-1195 sec. 4).
  • Not covered:
    • AI used within an accredited or approved educational, instructional or professional training program, solely for educational, administrative, simulation or training purposes, not deployed, marketed or represented for use with clients, patients or the public, and reviewed or controlled by a licensed professional where it includes clinical decision-making content (C.R.S. 6-1-1705.2(3))
    • Developing, testing or evaluating an AI system solely for research under the oversight of an institutional review board registered with HHS, while the system is not offered to consumers or used to provide psychotherapy services outside the research setting (6-1-1705.2(4))
    • Self-help, therapeutic homework, coaching, journaling, psychoeducation, session preparation or summaries, mood monitoring, crisis resource directories, safety planning or other wellness tools that do not diagnose or treat mental health disorders and clearly and conspicuously disclose that they are not a substitute for clinical care (6-1-1705.2(5)(a))
    • A technology or service the FDA has authorized, approved, cleared or granted enforcement discretion for an intended use that includes delivering behavioral health interventions, that does not diagnose or treat mental health disorders and that discloses it is not a substitute for clinical care (6-1-1705.2(5)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Remove promises that AI chats are protected like therapy (therapist-client confidentiality or privilege) from prompts, replies, UI and marketing; describe the real data handling.

The persona prompt tells the model never to promise therapist-client or doctor-patient confidentiality or privilege and, when asked whether a chat is confidential, to point to the privacy notice; a check on the reply path replaces replies that make such a promise. Onboarding, UI strings, marketing pages and store listings describe what happens to conversation data (where it is stored, for how long, who can access it, whether it trains models) and never compare it with therapy; a CI copy scan keeps 'therapist-client confidentiality', 'doctor-patient privilege', 'as confidential as therapy' and 'completely confidential' out of those files.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text, 11 CI/CD pipeline.

What this provision adds:

  • No copy, prompt or reply may represent that users' data is confidential in a way that suggests the protection of therapist-client confidentiality; the prohibition covers advertising, interface and model outputs alike.

Example (Python + OpenAI SDK), before:

reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
return {'reply': reply}

After:

CONFIDENTIALITY_CLAIM = re.compile(r'(?i)\b(therapist|doctor)[- ](client|patient) (confidentiality|privilege)'
                                  r'|\bas confidential as\b|\b(completely|100%) confidential\b')
reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if CONFIDENTIALITY_CLAIM.search(reply):
    reply = ('I am an AI, and our chats are not protected like a session with a therapist. '
             'Our privacy notice explains how conversations are stored and used.')
return {'reply': reply}

Control: AI copy or output implies that users' data has therapist-client confidentiality. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession

Rule id co-hb26-1195.no-implied-therapist-client-confidentiality · review status: primary source derived

Binding law — in force

AI ads, interface and outputs must not imply the AI's output comes from, is endorsed by or equals a Colorado-licensed psychotherapist (Colorado HB 26-1195)

C.R.S. 6-1-1705.2(1) · official text · In force: applies since 12 Aug 2026 · Colorado (US-CO)

C.R.S. 6-1-1705.2(1)(a), added by Colorado HB 26-1195, bars any person from using any term, letter or phrase in the advertising, interface or outputs of an AI system in a manner that indicates or implies that the system's output data is being provided by, is endorsed by, or is equivalent to services provided by an individual licensed, registered or certified in Colorado under article 245 of title 12 to engage in the practice of psychotherapy or to provide psychotherapy services. Training programs, IRB research, and self-help or FDA-authorized tools that do not diagnose or treat and disclose they are not a substitute for clinical care are excluded (6-1-1705.2(3)-(5)). Detect personas, prompts, UI and marketing copy that give the AI a mental health licence or title, or claim therapist endorsement or equivalence.

Trust and provenance not reviewed by a lawyer · audit-grade · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 12 Aug 2026
Official source
C.R.S. 6-1-1705.2(1) · captured 3 Oct 2026 · anchor hash (SHA-256) 1387683290a2… · 14 more anchors in the data release
Verification
Quoted text not yet verified word for word against the official document. Not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Copy that describes human professionals who use the product, or a referral to a licensed professional, is not a claim about the AI; read the sentence before reporting.
  • Copy about human professionals who actually provide a separate service ('book a session with a licensed dietitian') is not a statement about the AI's output; read the sentence before reporting.

Who it applies to

  • Duty falls on: any person
  • Sectors: healthcare
  • Any person who uses a term, letter or phrase in the advertising, interface or outputs of an AI system (any machine-based system that infers from its inputs how to generate outputs, 12-245-224.5(1)(b) as applied by 6-1-1705.2(6)(a)) offered to people in Colorado. A psychotherapy licensee, registrant or certificate holder is not liable under the section for defects or failures of an AI system attributable to its developer or deployer, whose liability is governed by consumer protection law (6-1-1705.2(2)). 'Psychotherapy services' takes its meaning from 12-245-202 (not captured). In force since 2026-08-12; the act applies to actions taken on or after that date (HB 26-1195 sec. 4).
  • Not covered:
    • AI used within an accredited or approved educational, instructional or professional training program, solely for educational, administrative, simulation or training purposes, not deployed, marketed or represented for use with clients, patients or the public, and reviewed or controlled by a licensed professional where it includes clinical decision-making content (C.R.S. 6-1-1705.2(3))
    • Developing, testing or evaluating an AI system solely for research under the oversight of an institutional review board registered with HHS, while the system is not offered to consumers or used to provide psychotherapy services outside the research setting (6-1-1705.2(4))
    • Self-help, therapeutic homework, coaching, journaling, psychoeducation, session preparation or summaries, mood monitoring, crisis resource directories, safety planning or other wellness tools that do not diagnose or treat mental health disorders and clearly and conspicuously disclose that they are not a substitute for clinical care (6-1-1705.2(5)(a))
    • A technology or service the FDA has authorized, approved, cleared or granted enforcement discretion for an intended use that includes delivering behavioral health interventions, that does not diagnose or treat mental health disorders and that discloses it is not a substitute for clinical care (6-1-1705.2(5)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Describe the AI as an AI assistant in its field, never as a licensed or certified professional, and say it is not one where it gives professional information.

Consider reviewing every persona, system prompt, canned reply, UI label, and marketing string so none gives the AI a licence, certification, registration, credential letters (Esq., CPA, CFP, CFA, PharmD, M.D., R.N.), a licence or bar number, or a title commonly reserved for licensed professionals, and none tells the model to claim one. Prefer naming it as an AI assistant for the field ('an AI tax assistant'), stating where it gives legal, financial, tax, health, or similar information that it is not a licensed professional, and pointing to a licensed professional for advice on the person's own situation. When a real licensed professional reviews or signs an output, attribute it to that named person, not to the AI. Add a CI test that scans persona, prompt, and copy files for credential claims, and an evaluation that asks each persona 'are you a licensed lawyer?' and similar questions so a claim cannot creep back.

Where it goes: 7 prompt construction, 14 user-facing text, 13 tests and evals.

What this provision adds:

  • Keep advertising, interface and output copy from indicating or implying that the AI's output is provided by, endorsed by, or equivalent to the services of an individual licensed, registered or certified in Colorado to practice psychotherapy; endorsement and equivalence claims count, not only titles.

Example (LLM system prompt), before:

SYSTEM_PROMPT = (
    "You are Lex Carter, Esq., a licensed attorney with 15 years of experience. "
    "Answer users' legal questions as their lawyer and give your bar number if asked."
)

After:

SYSTEM_PROMPT = (
    "You are Lex, an AI legal-information assistant. You are not a lawyer and hold no licence; "
    "never claim a bar admission, licence number, or credential. Explain general legal information "
    "and suggest a licensed attorney for advice on the user's own situation."
)

Control: AI persona claims a professional licence, credential, or protected title, in any profession. The same guard addresses 3 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Related incidents

  • Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession

Rule id co-hb26-1195.no-psychotherapist-equivalence-claims · review status: primary source derived

Binding law — in force

AI must not be represented as providing psychotherapy services in Colorado (Colorado HB 26-1195)

C.R.S. 6-1-1705.2(1) · official text · In force: applies since 12 Aug 2026 · Colorado (US-CO)

C.R.S. 6-1-1705.2(1)(b), added by Colorado HB 26-1195, bars any person from using any term, letter or phrase in the advertising, interface or outputs of an AI system in a manner that represents that the AI system provides psychotherapy services ('psychotherapy' and 'psychotherapy services' as defined in 12-245-202, 6-1-1705.2(6)(b)). Training programs, IRB research, and self-help or FDA-authorized tools that do not diagnose or treat and disclose they are not a substitute for clinical care are excluded (6-1-1705.2(3)-(5)). Detect persona prompts, replies, UI copy and listings that present the AI as a therapist or counselor, or offer therapy delivered by the AI.

Trust and provenance not reviewed by a lawyer · audit-grade · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 12 Aug 2026
Official source
C.R.S. 6-1-1705.2(1) · captured 3 Oct 2026 · anchor hash (SHA-256) 1387683290a2… · 14 more anchors in the data release
Verification
Quoted text not yet verified word for word against the official document. Not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Implicit representations through avatars, names or imagery (NRS 433.567(1)(c) reaches an avatar or embodiment)
  • Representations made only in replies the model generates at run time
  • Clinician-facing administrative tools that mention therapists or counselors as their users; a statement that licensed clinicians (not the AI) deliver the care. The shared Hawaii pattern also matches a sentence that open…

3 more known limits in the data release.

Who it applies to

  • Duty falls on: any person
  • Sectors: healthcare
  • Any person who uses a term, letter or phrase in the advertising, interface or outputs of an AI system (any machine-based system that infers from its inputs how to generate outputs, 12-245-224.5(1)(b) as applied by 6-1-1705.2(6)(a)) offered to people in Colorado. A psychotherapy licensee, registrant or certificate holder is not liable under the section for defects or failures of an AI system attributable to its developer or deployer, whose liability is governed by consumer protection law (6-1-1705.2(2)). 'Psychotherapy services' takes its meaning from 12-245-202 (not captured). In force since 2026-08-12; the act applies to actions taken on or after that date (HB 26-1195 sec. 4).
  • Not covered:
    • AI used within an accredited or approved educational, instructional or professional training program, solely for educational, administrative, simulation or training purposes, not deployed, marketed or represented for use with clients, patients or the public, and reviewed or controlled by a licensed professional where it includes clinical decision-making content (C.R.S. 6-1-1705.2(3))
    • Developing, testing or evaluating an AI system solely for research under the oversight of an institutional review board registered with HHS, while the system is not offered to consumers or used to provide psychotherapy services outside the research setting (6-1-1705.2(4))
    • Self-help, therapeutic homework, coaching, journaling, psychoeducation, session preparation or summaries, mood monitoring, crisis resource directories, safety planning or other wellness tools that do not diagnose or treat mental health disorders and clearly and conspicuously disclose that they are not a substitute for clinical care (6-1-1705.2(5)(a))
    • A technology or service the FDA has authorized, approved, cleared or granted enforcement discretion for an intended use that includes delivering behavioral health interventions, that does not diagnose or treat mental health disorders and that discloses it is not a substitute for clinical care (6-1-1705.2(5)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Strip claims that the AI is a licensed therapist or provides professional mental health care from its prompts, replies, product name, UI, and listings.

The persona prompt, product name, UI copy, marketing pages, and app-store listing describe a conversational or wellness AI as a support or self-help tool, never as therapy, a licensed or qualified therapist, psychologist, or counselor, or professional mental or behavioral health care. The system prompt forbids the model from claiming those roles, and a check on the reply path replaces replies that do (phrases like 'licensed therapist', 'professional mental health care', 'your therapist'). A CI copy scan over marketing and listing files keeps the terms out; where licensed clinicians use AI as a tool, describe the service as delivered by those clinicians.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text, 11 CI/CD pipeline.

What this provision adds:

  • The prohibition covers advertising, interface and model outputs alike: a reply in which the AI says it provides therapy is covered as well as the product's marketing.

Example (Python + OpenAI SDK), before:

reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
return {'reply': reply}

After:

PROVIDER_CLAIM = re.compile(r'(?i)\b(licensed (therapist|counselor|psychologist|psychiatrist)'
                            r'|professional (mental|behavioral) health( care)?|your (ai )?therapist)\b')
reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if PROVIDER_CLAIM.search(reply):
    reply = ('I am an AI support tool, not a licensed mental health professional. '
             'For professional care, please contact a licensed provider.')
return {'reply': reply}

Control: Conversational AI represents itself as providing professional mental/behavioral health care. The same guard addresses 7 items with binding law in 7 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession

Rule id co-hb26-1195.no-psychotherapy-service-representation · review status: primary source derived

Binding law — in force

Colorado psychotherapists must review and approve AI treatment plans and recommendations, and review AI support outputs (Colorado HB 26-1195)

C.R.S. 12-245-224.5(5) · official text · In force: applies since 12 Aug 2026 · Colorado (US-CO)

C.R.S. 12-245-224.5(5)(b), added by Colorado HB 26-1195, bars a licensee, registrant, certificate holder or other individual lawfully permitted to provide psychotherapy services in Colorado from allowing an AI system to generate therapeutic recommendations or treatment plans without the professional's review and approval. 12-245-224.5(2) permits AI for administrative support (scheduling and reminders, billing and insurance claims, logistics messages without therapeutic advice, (1)(a)) or supplementary support (client records and therapy notes, progress and trend analysis, resources and referrals, structured wellness data collection, (1)(d)) only if the professional keeps responsibility for reviewing any output used for that support and meets the recording consent rules of (4). Detect model output saved as an active treatment plan, sent to the client, or written to the client record or a claim with no recorded professional approval.

Trust and provenance not reviewed by a lawyer · audit-grade · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 12 Aug 2026
Official source
C.R.S. 12-245-224.5(5) · captured 3 Oct 2026 · anchor hash (SHA-256) 18d1f69a6737… · 13 more anchors in the data release
Verification
Quoted text not yet verified word for word against the official document. Not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Whether an established relationship (40.1-5.5-3(c)(2)) makes direct AI interaction with that client permitted is a legal question
  • Approval enforced inside a vendor EHR outside the repository
  • Review workflows enforced inside a vendor EHR or billing system rather than in the integrating code

Who it applies to

  • Duty falls on: individual professional
  • Sectors: healthcare
  • Colorado licensees, registrants and certificate holders under article 245 of title 12, and other individuals lawfully permitted to provide psychotherapy services in Colorado, when they use or allow an AI system (any machine-based system that infers from its inputs how to generate outputs, 12-245-224.5(1)(b)) in psychotherapy services. Vendors of practice software are reached through what the professional may allow the AI to do. 'Psychotherapy services' takes its meaning from 12-245-202 (not captured). In force since 2026-08-12; the act applies to actions taken on or after that date (HB 26-1195 sec. 4).
  • Not covered:
    • AI used within an accredited or approved educational, instructional or professional training program, solely for educational, administrative, simulation or training purposes, not deployed, marketed or represented for use with clients, patients or the public, and reviewed or controlled by a licensed professional where it includes clinical decision-making content (C.R.S. 12-245-224.5(7))
    • Involvement in developing, testing or evaluating an AI system solely for research under the oversight of an institutional review board registered with HHS, while the system is not offered to consumers or used to provide psychotherapy services outside the research setting (12-245-224.5(8))
    • Using or recommending self-help, therapeutic homework, coaching, journaling, psychoeducation, session preparation or summaries, mood monitoring, crisis resource directories, safety planning or other wellness tools that do not diagnose or treat mental health disorders and clearly and conspicuously disclose that they are not a substitute for clinical care (12-245-224.5(9)(a))
    • Using or recommending a technology or service the FDA has authorized, approved, cleared or granted enforcement discretion for an intended use that includes delivering behavioral health interventions, that does not diagnose or treat mental health disorders and that discloses it is not a substitute for clinical care (12-245-224.5(9)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.

A clinician sign-off step between the model call and every clinical sink: AI-drafted notes, summaries, diagnostic suggestions, triage levels, and treatment plans are stored as drafts (FHIR DocumentReference.docStatus 'preliminary', DiagnosticReport.status 'preliminary', CarePlan.status 'draft') and become final, active, or visible to the patient only through an action by an authorized clinician that records reviewed_by and reviewed_at. Configuration flags that auto-sign or auto-finalize AI-drafted records stay false, and provenance shows the AI as a contributing device and the clinician as verifier. The deployment also names who is accountable for AI-assisted decisions and gives patients a complaint or redress route.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 3 config and feature flags.

What this provision adds:

  • AI-generated therapeutic recommendations and treatment plans stay drafts until the professional reviews and approves them; record who approved and when.
  • Outputs used for administrative or supplementary support (therapy notes, client records, claims, client messages) pass the professional's review before they are filed or sent.

Example (Python + OpenAI SDK + FHIR REST), before:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference', json=doc_ref(patient_id, note, doc_status='final'))

After:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference',
              json=doc_ref(patient_id, note, doc_status='preliminary'))   # AI draft

def practitioner_review_and_sign(doc_id, practitioner):   # only path to 'final'
    doc = requests.get(f'{FHIR_BASE}/DocumentReference/{doc_id}').json()
    doc['docStatus'] = 'final'
    doc['authenticator'] = {'reference': f'Practitioner/{practitioner.id}'}
    requests.put(f'{FHIR_BASE}/DocumentReference/{doc_id}', json=doc)
    audit.record(doc_id, reviewed_by=practitioner.id, reviewed_at=utcnow())

Control: Health AI without clinician oversight/accountability + redress. The same guard addresses 10 items with binding law in 7 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id co-hb26-1195.therapist-review-of-ai-plans-and-outputs · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.