Maine P.L. 2026, c. 687 (L.D. 2082, AI in mental health services)
Maine Attorney General (Unfair Trade Practices Act); Maine professional licensing boards · Maine (US-ME) · 4 provisions encoded · verified against the official source as of 2026-10-03.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 4 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 4.
Audit standard
4 of 4 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
7 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
2026.10.03.4 (3 Oct 2026): 4 provisions added
Each data release records which provisions changed; the full list is on Changes.
Binding law — in force
Maine licensees using AI in therapy must comply with privacy law and ensure the AI technology complies too (Maine LD 2082)
32 M.R.S. § 2113(6) (and the same text in the six other sections) · official text · In force: applies since 29 Jul 2026 · Maine (US-ME)
32 M.R.S. § 2113(6) and the six identical sections require a licensee using AI under the section to comply with all state and federal confidentiality and privacy laws and to ensure that any AI technology complies with them. Detect session notes, transcripts or other client records sent to a model API with no business-associate, HIPAA-eligible endpoint or de-identification safeguard.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 29 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Health fields renamed to generic identifiers
Model calls wrapped in an internal client
Vendor coverage (a business associate agreement, a HIPAA-eligible endpoint) is often recorded outside the repository; the finding asks for it, it does not establish that none exists.
Who it applies to
Duty falls on: individual professional
Sectors: healthcare
Maine licensees under the seven Title 32 chapters that P.L. 2026, c. 687 amends (32 M.R.S. §§ 2113, 2600-G, 3300-J, 3820-A, 6207-D, 7009 and 13870; in §§ 2600-G, 3300-J, 3820-A and 13870 also persons privileged to practice under them) who use AI in delivering therapy or psychotherapy services. Vendors of practice software are reached through what the licensee may allow the AI to do. Which confidentiality and privacy laws govern a given AI vendor is a legal question. In force since 2026-07-29.
Not covered:
AI-based interventions used solely within a research project approved by an institutional review board (as defined in 22 M.R.S. § 1711-C(6)(G)) and conducted under applicable federal human-subjects protections (32 M.R.S. § 2113(9) and the same subsection of the six other sections)
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.
A single client factory for model, embedding and transcription calls that handle health information: it looks the endpoint up in a vendor register and refuses to return a client unless the register shows the required contract (business associate agreement, or a processing agreement barring further disclosure) and the endpoint is the covered deployment with data retention and training use turned off. Call sites that cannot meet that de-identify or redact the record before building the prompt, or check a recorded patient authorization for that use. Keep the vendor register in the repository so reviewers can match each AI endpoint to its legal basis, and never route health data into marketing or other non-care generation.
Where it goes: 6 API calls and integrations, 3 config and feature flags, 7 prompt construction, 12 repository artifacts.
Example (Python + OpenAI SDK (Azure OpenAI)), before:
Rule id me-ld2082.ai-privacy-compliance · review status: primary source derived
Binding law — in force
Maine licensees need written notice and consent before AI supports a recorded session, and may not deny care for refusing (Maine LD 2082)
32 M.R.S. § 2113(3) (and the same text in the six other sections) · official text · In force: applies since 29 Jul 2026 · Maine (US-ME)
Under 32 M.R.S. § 2113(3) and the six identical sections enacted by P.L. 2026, c. 687, a licensee may use AI for supplementary support (records and therapy notes, progress analysis, resource referrals) only when the session is recorded or transcribed and only after the client or legal representative is told in writing that AI will be used, its specific purpose, and how session data collected by AI will be stored, retained, used for training and deleted when therapy ends, and gives consent. Consent is an explicit, affirmative, revocable written act (electronic or initials on a specific section of the general consent to treatment); accepting broad terms of use, hovering or closing content, and deception do not count. A licensee may not deny or refuse therapy solely because the client declines AI, and a client's waiver is void. Detect session recordings or transcripts reaching AI with no consent check, consent bundled into terms, and copy that makes AI consent a condition of care.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 29 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
4 detectors (code pattern, data flow, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Consent enforced by an upstream service or the EHR before the session reaches this code
Whether a given tool is the kind of AI the state's consent duty names is a legal question
Denial enforced in scheduling logic with no message naming AI consent
1 more known limit in the data release.
Who it applies to
Duty falls on: individual professional
Sectors: healthcare
Maine licensees under the seven Title 32 chapters that P.L. 2026, c. 687 amends (32 M.R.S. §§ 2113, 2600-G, 3300-J, 3820-A, 6207-D, 7009 and 13870; in §§ 2600-G, 3300-J, 3820-A and 13870 also persons privileged to practice under them) who use AI in delivering therapy or psychotherapy services. Vendors of practice software are reached through what the licensee may allow the AI to do. In force since 2026-07-29.
Not covered:
AI-based interventions used solely within a research project approved by an institutional review board (as defined in 22 M.R.S. § 1711-C(6)(G)) and conducted under applicable federal human-subjects protections (32 M.R.S. § 2113(9) and the same subsection of the six other sections)
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Check a signed, unrevoked, purpose-specific AI-use consent for the client before any session audio or transcript is sent to an AI transcription, note, or summary model.
A consent gate in the note-assistant pipeline placed before the first AI step (a model transcription call counts) and again before the note or summary call: it loads the client's consent record for this tool's purpose (for example ai_scribe), requires signed_at and no revoked_at, and refuses otherwise. The record references the version of the written notice the client or their representative received, naming the tool's purpose. Consent is collected as a separate explicit act on its own form, never inferred from terms-of-use acceptance, and a revocation endpoint sets revoked_at and cancels queued AI jobs for that client.
Where it goes: 1 application source code, 2 data models, 14 user-facing text.
What this provision adds:
The written notice also states how session data collected by AI will be stored, retained, used for training and deleted when therapy or psychotherapy services end.
Booking and treatment never depend on AI consent: a client who declines keeps the same care, and the AI step alone is skipped.
Do not ask clients to waive these protections; a waiver is void and unenforceable.
def draft_note(session):
consent = db.consents.get(client_id=session.client_id, purpose='ai_scribe')
if consent is None or consent.signed_at is None or consent.revoked_at:
raise ConsentRequired('written AI-use consent for note drafting is missing or revoked')
with open(session.audio_path, 'rb') as f:
transcript = client.audio.transcriptions.create(model='whisper-1', file=f).text
resp = client.chat.completions.create(model=MODEL, messages=[
{'role': 'system', 'content': NOTE_PROMPT}, {'role': 'user', 'content': transcript}])
return resp.choices[0].message.content
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required
Rule id me-ld2082.ai-supplementary-support-notice-consent · review status: primary source derived
Binding law — in force
Maine licensees must not let AI make therapeutic decisions, interact therapeutically with clients, or set unapproved treatment plans (Maine LD 2082)
32 M.R.S. § 2113(4) (and the same text in the six other sections) · official text · In force: applies since 29 Jul 2026 · Maine (US-ME)
32 M.R.S. § 2113(2) and (4), with the six identical sections enacted by P.L. 2026, c. 687, let a licensee use AI only for administrative support (scheduling, billing and claims, logistics messages without therapeutic content) or supplementary support, with full responsibility for all AI interactions, outputs and data use, and bar letting AI make independent therapeutic decisions, directly interact with clients in any form of therapeutic communication, or generate therapeutic recommendations or treatment plans without the licensee's review and approval. Detect practice software where model output reaches the client, sets a therapeutic decision, or becomes a treatment plan without the licensee's recorded approval.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 29 Jul 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Whether an AI-drafted message that a licensee edits and sends is the AI 'directly' interacting is a legal question
Approval enforced inside a vendor EHR outside the repository
Who it applies to
Duty falls on: individual professional
Sectors: healthcare
Maine licensees under the seven Title 32 chapters that P.L. 2026, c. 687 amends (32 M.R.S. §§ 2113, 2600-G, 3300-J, 3820-A, 6207-D, 7009 and 13870; in §§ 2600-G, 3300-J, 3820-A and 13870 also persons privileged to practice under them) who use AI in delivering therapy or psychotherapy services. Vendors of practice software are reached through what the licensee may allow the AI to do. In force since 2026-07-29.
Not covered:
AI-based interventions used solely within a research project approved by an institutional review board (as defined in 22 M.R.S. § 1711-C(6)(G)) and conducted under applicable federal human-subjects protections (32 M.R.S. § 2113(9) and the same subsection of the six other sections)
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.
A clinician sign-off step between the model call and every clinical sink: AI-drafted notes, summaries, diagnostic suggestions, triage levels, and treatment plans are stored as drafts (FHIR DocumentReference.docStatus 'preliminary', DiagnosticReport.status 'preliminary', CarePlan.status 'draft') and become final, active, or visible to the patient only through an action by an authorized clinician that records reviewed_by and reviewed_at. Configuration flags that auto-sign or auto-finalize AI-drafted records stay false, and provenance shows the AI as a contributing device and the clinician as verifier. The deployment also names who is accountable for AI-assisted decisions and gives patients a complaint or redress route.
Where it goes: 1 application source code, 2 data models, 9 AI output handling, 3 config and feature flags.
What this provision adds:
Model output never reaches the client as therapeutic communication; AI-generated recommendations and treatment plans stay drafts until the licensee reviews and approves them.
Example (Python + OpenAI SDK + FHIR REST), before:
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Monitor how often adverse AI decisions are reversed, and suspend models that are usually wrong
Cigna PXDX batch claim denials (reported) (2022; alleged (not proven)). ProPublica, citing internal Cigna records, reported that Cigna's PXDX system was used to reject more than 300,000 claims over two months in 2022, with physicians spending an average of 1.2 seconds on each. Cigna disputes the reporting; related lawsuits are ongoing. Source: ProPublica / The Capitol Forum · evidence grade: press of record · cited by Make human review of adverse AI decisions substantive, not nominal
Rule id me-ld2082.ai-therapy-role-limits · review status: primary source derived
Binding law — in force
AI must not provide or be offered as therapy to the Maine public unless a licensed professional provides it (Maine LD 2082)
10 M.R.S. § 1500-EE(2) · official text · In force: applies since 29 Jul 2026 · Maine (US-ME)
10 M.R.S. § 1500-EE(2), enacted by P.L. 2026, c. 687 (L.D. 2082), bars any person from providing, advertising or otherwise offering therapy or psychotherapy services to the public, including through internet-based AI, unless a licensed professional provides them. Therapy or psychotherapy services are services to diagnose, treat or address mental or behavioral health through therapeutic communication, which includes understanding a person's thoughts and emotions, therapeutic guidance, emotional support or empathy in response to distress, and treatment planning. A violation is a violation of the Maine Unfair Trade Practices Act; IRB-approved research is excepted. Detect an AI cast or marketed as the therapist, or therapy offered as delivered by AI.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 29 Jul 2026
Official source
10 M.R.S. § 1500-EE(2) · captured 3 Oct 2026 · anchor hash (SHA-256) 16c2fae49315… · 7 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Marketing copy and app-store listings kept outside the repository
Therapy framing that avoids the words therapy, therapist and counselor (for example 'talk through your anxiety with Maya')
Clinician-facing tools for scheduling, billing or notes use similar words but are permitted for licensees (32 M.R.S. § 2113(2) and the same subsection of the six other sections).
Who it applies to
Duty falls on: any person
Sectors: healthcare
Any person that provides, advertises or otherwise offers therapy or psychotherapy services (10 M.R.S. § 1500-EE(1)(C)-(D)) to the public, including through internet-based AI, unless a licensed professional (1500-EE(1)(B)) provides them. The section states no territorial test; reach to providers outside Maine serving Maine residents is a legal question, as is whether a wellness or companion product is a therapy service. In force since 2026-07-29.
Not covered:
AI-based interventions used solely within a research project approved by an institutional review board (22 M.R.S. § 1711-C(6)(G)) and conducted under applicable federal human-subjects protections (10 M.R.S. § 1500-EE(4))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Have a licensed clinician conduct every therapy engagement with AI output only as a reviewed draft, or scope the product to self-help with no therapy claims.
Two acceptable shapes, enforced in the message handler that returns model output to the person. If the product is a therapy service, each session has a licensed clinician assigned (session.conducted_by with an active license in the right state), and model output is a draft that clinician approves before it is sent (require_clinician_approval, clinician review queue). If it is not a therapy service, scope it to peer support or scripted self-help, remove persona prompts that cast the AI as the therapist ('act as a therapist'), and remove copy that offers therapy with or by AI.
Where it goes: 1 application source code, 7 prompt construction, 14 user-facing text.
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
Rule id me-ld2082.no-unlicensed-ai-therapy · review status: primary source derived
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.