Binding law — in force
Therapists must give written notice and get consent before using AI on recorded or transcribed sessions (Illinois HB 1806)
When an Illinois licensed professional uses AI for supplementary support, such as drafting therapy notes or records, on a session that is recorded or transcribed, 225 ILCS 155/15(b) requires two things first: written notice to the client or their legally authorized representative that AI will be used and for what specific purpose, and that person's consent. Consent has a strict meaning in Section 10: an explicit, written, revocable affirmative act. Accepting broad terms of use, hovering over or closing content, or deceptive design does not count. Detect session audio or transcripts flowing into AI note-taking or summarization with no per-client written AI notice and recorded, revocable consent on the path.
Who it applies to
- Duty falls on: individual professional
- Sectors: healthcare
- Illinois-licensed therapy and psychotherapy professionals as defined in 225 ILCS 155/10 (clinical psychologists, social workers, professional and clinical counselors, marriage and family therapists, certified addiction counselors, music therapists, advanced practice psychiatric nurses, and others the State authorizes; physicians are excluded from the definition) when they use AI tools in their practice. Vendors of clinical software are reached through what the professional may allow the AI to do. In force since 2025-08-01.
- Not covered:
- religious counseling (225 ILCS 155/35(1))
- peer support (35(2))
- self-help materials and educational resources available to the public that do not purport to offer therapy (35(3))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Check a signed, unrevoked, purpose-specific AI-use consent for the client before any session audio or transcript is sent to an AI transcription, note, or summary model.
A consent gate in the note-assistant pipeline placed before the first AI step (a model transcription call counts) and again before the note or summary call: it loads the client's consent record for this tool's purpose (for example ai_scribe), requires signed_at and no revoked_at, and refuses otherwise. The record references the version of the written notice the client or their representative received, naming the tool's purpose. Consent is collected as a separate explicit act on its own form, never inferred from terms-of-use acceptance, and a revocation endpoint sets revoked_at and cancels queued AI jobs for that client.
Where it goes: 1 application source code, 2 data models, 14 user-facing text.
What this provision adds:
- Give the written notice to the client or their legally authorized representative before AI is used on the recorded or transcribed session, stating that AI will be used and for what specific purpose.
- Collect consent as an explicit, written, revocable affirmative act; accepting broad terms of use, hovering over or closing content, or deceptive design does not count.
Example (Python + OpenAI SDK), before:
def draft_note(session):
with open(session.audio_path, 'rb') as f:
transcript = client.audio.transcriptions.create(model='whisper-1', file=f).text
resp = client.chat.completions.create(model=MODEL, messages=[
{'role': 'system', 'content': NOTE_PROMPT}, {'role': 'user', 'content': transcript}])
return resp.choices[0].message.contentAfter:
def draft_note(session):
consent = db.consents.get(client_id=session.client_id, purpose='ai_scribe')
if consent is None or consent.signed_at is None or consent.revoked_at:
raise ConsentRequired('written AI-use consent for note drafting is missing or revoked')
with open(session.audio_path, 'rb') as f:
transcript = client.audio.transcriptions.create(model='whisper-1', file=f).text
resp = client.chat.completions.create(model=MODEL, messages=[
{'role': 'system', 'content': NOTE_PROMPT}, {'role': 'user', 'content': transcript}])
return resp.choices[0].message.contentControl: AI used on recorded or transcribed therapy sessions without written notice and consent. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required
Rule id il-hb1806.ai-session-recording-notice-consent · review status: primary source derived