TwinEthosRequest access

Law

Illinois WOPR Act (HB 1806, AI in therapy)

Illinois Department of Financial and Professional Regulation (IDFPR) · Illinois (US-IL) · 4 provisions encoded · verified against the official source as of 2026-09-27.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: www.ilga.gov.

Binding law — in force

Therapists must keep AI out of client therapeutic communication, therapy decisions, and unapproved treatment plans (Illinois HB 1806)

225 ILCS 155/20(b) · official text · In force: applies since 1 Aug 2025 · Illinois (US-IL)

Under 225 ILCS 155/20(b)(1)-(3), a licensed Illinois therapy professional may use AI only within the Act's permitted uses, meaning administrative or supplementary support for which the professional stays fully responsible, and may not let the AI decide therapeutic questions on its own, engage clients in any therapeutic exchange, or produce therapeutic recommendations or treatment plans the professional has not reviewed and approved. AI help with notes and records is allowed; AI speaking to the client in a therapeutic role is not. Detect clinical-software paths where model output goes straight to a client, sets a therapeutic decision, or becomes an active treatment plan without a recorded licensed-professional approval.

Who it applies to

  • Duty falls on: individual professional
  • Sectors: healthcare
  • Illinois-licensed therapy and psychotherapy professionals as defined in 225 ILCS 155/10 (clinical psychologists, social workers, professional and clinical counselors, marriage and family therapists, certified addiction counselors, music therapists, advanced practice psychiatric nurses, and others the State authorizes; physicians are excluded from the definition) when they use AI tools in their practice. Vendors of clinical software are reached through what the professional may allow the AI to do. In force since 2025-08-01.
  • Not covered:
    • religious counseling (225 ILCS 155/35(1))
    • peer support (35(2))
    • self-help materials and educational resources available to the public that do not purport to offer therapy (35(3))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.

A clinician sign-off step between the model call and every clinical sink: AI-drafted notes, summaries, diagnostic suggestions, triage levels, and treatment plans are stored as drafts (FHIR DocumentReference.docStatus 'preliminary', DiagnosticReport.status 'preliminary', CarePlan.status 'draft') and become final, active, or visible to the patient only through an action by an authorized clinician that records reviewed_by and reviewed_at. Configuration flags that auto-sign or auto-finalize AI-drafted records stay false, and provenance shows the AI as a contributing device and the clinician as verifier. The deployment also names who is accountable for AI-assisted decisions and gives patients a complaint or redress route.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 3 config and feature flags.

What this provision adds:

  • Keep model output from reaching the client as therapeutic communication; limit AI to administrative or supplementary support, such as notes and records, for which the licensed professional stays fully responsible.
  • AI-produced therapeutic recommendations or treatment plans stay drafts until the licensed professional reviews and approves them, and the AI never decides therapeutic questions on its own.

Example (Python + OpenAI SDK + FHIR REST), before:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference', json=doc_ref(patient_id, note, doc_status='final'))

After:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference',
              json=doc_ref(patient_id, note, doc_status='preliminary'))   # AI draft

def practitioner_review_and_sign(doc_id, practitioner):   # only path to 'final'
    doc = requests.get(f'{FHIR_BASE}/DocumentReference/{doc_id}').json()
    doc['docStatus'] = 'final'
    doc['authenticator'] = {'reference': f'Practitioner/{practitioner.id}'}
    requests.put(f'{FHIR_BASE}/DocumentReference/{doc_id}', json=doc)
    audit.record(doc_id, reviewed_by=practitioner.id, reviewed_at=utcnow())

Control: Health AI without clinician oversight/accountability + redress. The same guard addresses 3 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id il-hb1806.ai-therapy-role-limits · review status: primary source derived

Binding law — in force

Therapists must not use AI to detect clients' emotions or mental states (Illinois HB 1806)

225 ILCS 155/20(b) · official text · In force: applies since 1 Aug 2025 · Illinois (US-IL)

225 ILCS 155/20(b)(4) forbids an Illinois-licensed therapy professional from letting AI infer a client's emotions or mental state. Unlike the EU AI Act's ban on emotion recognition at work and in education, this one sits inside the therapy relationship and has no medical exception in its text, so affect recognition on session audio or video, emotion classifiers run over session transcripts, and prompts asking a model to read a client's mood or mental state all fall in its path. Detect emotion or mental-state inference libraries, model ids, APIs, or prompts wired into software a licensed professional uses with clients.

Who it applies to

  • Duty falls on: individual professional
  • Sectors: healthcare
  • Illinois-licensed therapy and psychotherapy professionals as defined in 225 ILCS 155/10 (clinical psychologists, social workers, professional and clinical counselors, marriage and family therapists, certified addiction counselors, music therapists, advanced practice psychiatric nurses, and others the State authorizes; physicians are excluded from the definition) when they use AI tools in their practice. Vendors of clinical software are reached through what the professional may allow the AI to do. In force since 2025-08-01.
  • Not covered:
    • religious counseling (225 ILCS 155/35(1))
    • peer support (35(2))
    • self-help materials and educational resources available to the public that do not purport to offer therapy (35(3))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Remove emotion, affect, and mental-state inference (libraries, model ids, APIs, prompts) from every path that processes client session data in therapy software.

On client data paths (session audio and video, transcripts, messages, notes), the software does not run emotion or affect recognition: no emotion classifiers such as go_emotions or the j-hartmann emotion models, no DeepFace emotion analysis, no Hume expression measurement, no Rekognition DetectFaces with Attributes=['ALL'], and no prompt asking a model to detect or assess the client's mood or mental state. Features that remain (transcription, summaries of what was said, scheduling) are instructed not to label emotions or mental states, and any assessment stays with the licensed professional. A dependency and model-id denylist check in CI keeps these from returning.

Where it goes: 1 application source code, 5 dependencies, 7 prompt construction, 11 CI/CD pipeline.

Example (Python + Hugging Face transformers), before:

emotion = pipeline('text-classification', model='j-hartmann/emotion-english-distilroberta-base')
note.client_emotions = emotion(transcript[:512])
note.summary = summarize(transcript)

After:

# no emotion classifier on client transcripts; the therapist records any assessment
note.summary = summarize(transcript)

Control: AI detects a client's emotions or mental state in a therapy practice. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id il-hb1806.no-ai-emotion-detection-in-therapy · review status: primary source derived

Binding law — in force

AI must not provide or be offered as therapy to the Illinois public unless a licensed professional conducts it (Illinois HB 1806)

225 ILCS 155/20(a) · official text · In force: applies since 1 Aug 2025 · Illinois (US-IL)

Illinois's Wellness and Oversight for Psychological Resources Act makes it unlawful for any person or business to deliver, market, or offer therapy or psychotherapy to people in Illinois, naming Internet-based AI expressly, unless an Illinois-licensed professional is the one conducting the service. A chatbot or app that acts as the therapist, or is sold as one, is the core pattern it reaches; clergy counseling, peer support, and publicly available self-help or educational material that does not claim to be therapy are carved out. Detect a public-facing AI conversation or product surface that performs or advertises therapy with no licensed professional conducting it.

Who it applies to

  • Duty falls on: developer, deployer
  • Sectors: healthcare
  • Any individual, corporation, or entity that provides, advertises, or offers therapy or psychotherapy services (services to diagnose, treat, or improve mental or behavioral health) to the public in Illinois, including through Internet-based AI, unless an Illinois-licensed professional conducts the services. Whether a wellness, coaching, or companion product is a therapy service is a judgment call. In force since 2025-08-01.
  • Not covered:
    • religious counseling (225 ILCS 155/35(1))
    • peer support (35(2))
    • self-help materials and educational resources available to the public that do not purport to offer therapy (35(3))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Have a licensed clinician conduct every therapy engagement with AI output only as a reviewed draft, or scope the product to self-help with no therapy claims.

Two acceptable shapes, enforced in the message handler that returns model output to the person. If the product is a therapy service, each session has a licensed clinician assigned (session.conducted_by with an active license in the right state), and model output is a draft that clinician approves before it is sent (require_clinician_approval, clinician review queue). If it is not a therapy service, scope it to peer support or scripted self-help, remove persona prompts that cast the AI as the therapist ('act as a therapist'), and remove copy that offers therapy with or by AI.

Where it goes: 1 application source code, 7 prompt construction, 14 user-facing text.

What this provision adds:

  • The professional conducting each therapy engagement holds an Illinois license (e.g. check license_state == 'IL' on session.conducted_by).
  • Clergy counseling, peer support, and publicly available self-help or educational material that does not claim to be therapy are carved out.

Example (FastAPI + OpenAI SDK), before:

@app.post('/session/message')
def message(req: Msg):
    msgs = [{'role': 'system', 'content': "You are the user's therapist."}, *req.history]
    reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
    return {'reply': reply}

After:

@app.post('/session/message')
def message(req: Msg):
    session = sessions.get(req.session_id)
    clinician = session.conducted_by
    if clinician is None or not clinician.license_active:
        raise HTTPException(409, 'No licensed clinician is conducting this session')
    msgs = [{'role': 'system', 'content': CLINICIAN_DRAFT_PROMPT}, *req.history]
    draft = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
    clinician_review_queue.enqueue(session_id=session.id, clinician_id=clinician.id, draft=draft)
    return {'status': 'sent_to_your_clinician'}

Control: AI delivers or is offered as therapy to the public without a licensed professional conducting it. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id il-hb1806.no-unlicensed-ai-therapy · review status: primary source derived