TwinEthos homeAPI access

Law

Maine P.L. 2026, c. 687 (L.D. 2082, AI in mental health services)

Maine Attorney General (Unfair Trade Practices Act); Maine professional licensing boards · Maine (US-ME) · 4 provisions encoded · verified against the official source as of 2026-10-03.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: legislature.maine.gov.

Trust and provenance 2 official sources · last verified 3 Oct 2026 · not reviewed by a lawyer · 4 of 4 provisions audit-grade · release 2026.10.03.4

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 4
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 4 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 4.
Audit standard
4 of 4 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
7 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.4 (3 Oct 2026): 4 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

Maine licensees using AI in therapy must comply with privacy law and ensure the AI technology complies too (Maine LD 2082)

32 M.R.S. § 2113(6) (and the same text in the six other sections) · official text · In force: applies since 29 Jul 2026 · Maine (US-ME)

32 M.R.S. § 2113(6) and the six identical sections require a licensee using AI under the section to comply with all state and federal confidentiality and privacy laws and to ensure that any AI technology complies with them. Detect session notes, transcripts or other client records sent to a model API with no business-associate, HIPAA-eligible endpoint or de-identification safeguard.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 29 Jul 2026
Official source
32 M.R.S. § 2113(6) (and the same text in the six other sections) · captured 3 Oct 2026 · anchor hash (SHA-256) eb40d3b3661d… · 10 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Health fields renamed to generic identifiers
  • Model calls wrapped in an internal client
  • Vendor coverage (a business associate agreement, a HIPAA-eligible endpoint) is often recorded outside the repository; the finding asks for it, it does not establish that none exists.

Who it applies to

  • Duty falls on: individual professional
  • Sectors: healthcare
  • Maine licensees under the seven Title 32 chapters that P.L. 2026, c. 687 amends (32 M.R.S. §§ 2113, 2600-G, 3300-J, 3820-A, 6207-D, 7009 and 13870; in §§ 2600-G, 3300-J, 3820-A and 13870 also persons privileged to practice under them) who use AI in delivering therapy or psychotherapy services. Vendors of practice software are reached through what the licensee may allow the AI to do. Which confidentiality and privacy laws govern a given AI vendor is a legal question. In force since 2026-07-29.
  • Not covered:
    • AI-based interventions used solely within a research project approved by an institutional review board (as defined in 22 M.R.S. § 1711-C(6)(G)) and conducted under applicable federal human-subjects protections (32 M.R.S. § 2113(9) and the same subsection of the six other sections)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.

A single client factory for model, embedding and transcription calls that handle health information: it looks the endpoint up in a vendor register and refuses to return a client unless the register shows the required contract (business associate agreement, or a processing agreement barring further disclosure) and the endpoint is the covered deployment with data retention and training use turned off. Call sites that cannot meet that de-identify or redact the record before building the prompt, or check a recorded patient authorization for that use. Keep the vendor register in the repository so reviewers can match each AI endpoint to its legal basis, and never route health data into marketing or other non-care generation.

Where it goes: 6 API calls and integrations, 3 config and feature flags, 7 prompt construction, 12 repository artifacts.

Example (Python + OpenAI SDK (Azure OpenAI)), before:

client = OpenAI()
resp = client.chat.completions.create(model='gpt-4o', messages=[
    {'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])

After:

VENDORS = load_yaml('vendors/ai_vendors.yaml')   # baa_signed, zero_data_retention per endpoint

def phi_client(name: str) -> tuple[AzureOpenAI, str]:
    v = VENDORS[name]
    if not (v['baa_signed'] and v['zero_data_retention']):
        raise PermissionError(f'{name} is not cleared for PHI')
    client = AzureOpenAI(azure_endpoint=v['endpoint'], api_key=os.environ['AZURE_OPENAI_KEY'],
                         api_version=v['api_version'])
    return client, v['deployment']

client, deployment = phi_client('azure-openai-hipaa')
resp = client.chat.completions.create(model=deployment, messages=[
    {'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])

Control: Health information sent to an external AI vendor without the contractual or legal basis the law requires. The same guard addresses 8 items with binding law in 7 jurisdictions. Engineering guidance, not legal advice.

Rule id me-ld2082.ai-privacy-compliance · review status: primary source derived

Binding law — in force

Maine licensees must not let AI make therapeutic decisions, interact therapeutically with clients, or set unapproved treatment plans (Maine LD 2082)

32 M.R.S. § 2113(4) (and the same text in the six other sections) · official text · In force: applies since 29 Jul 2026 · Maine (US-ME)

32 M.R.S. § 2113(2) and (4), with the six identical sections enacted by P.L. 2026, c. 687, let a licensee use AI only for administrative support (scheduling, billing and claims, logistics messages without therapeutic content) or supplementary support, with full responsibility for all AI interactions, outputs and data use, and bar letting AI make independent therapeutic decisions, directly interact with clients in any form of therapeutic communication, or generate therapeutic recommendations or treatment plans without the licensee's review and approval. Detect practice software where model output reaches the client, sets a therapeutic decision, or becomes a treatment plan without the licensee's recorded approval.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 29 Jul 2026
Official source
32 M.R.S. § 2113(4) (and the same text in the six other sections) · captured 3 Oct 2026 · anchor hash (SHA-256) 68283fd92a25… · 16 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Whether an AI-drafted message that a licensee edits and sends is the AI 'directly' interacting is a legal question
  • Approval enforced inside a vendor EHR outside the repository

Who it applies to

  • Duty falls on: individual professional
  • Sectors: healthcare
  • Maine licensees under the seven Title 32 chapters that P.L. 2026, c. 687 amends (32 M.R.S. §§ 2113, 2600-G, 3300-J, 3820-A, 6207-D, 7009 and 13870; in §§ 2600-G, 3300-J, 3820-A and 13870 also persons privileged to practice under them) who use AI in delivering therapy or psychotherapy services. Vendors of practice software are reached through what the licensee may allow the AI to do. In force since 2026-07-29.
  • Not covered:
    • AI-based interventions used solely within a research project approved by an institutional review board (as defined in 22 M.R.S. § 1711-C(6)(G)) and conducted under applicable federal human-subjects protections (32 M.R.S. § 2113(9) and the same subsection of the six other sections)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.

A clinician sign-off step between the model call and every clinical sink: AI-drafted notes, summaries, diagnostic suggestions, triage levels, and treatment plans are stored as drafts (FHIR DocumentReference.docStatus 'preliminary', DiagnosticReport.status 'preliminary', CarePlan.status 'draft') and become final, active, or visible to the patient only through an action by an authorized clinician that records reviewed_by and reviewed_at. Configuration flags that auto-sign or auto-finalize AI-drafted records stay false, and provenance shows the AI as a contributing device and the clinician as verifier. The deployment also names who is accountable for AI-assisted decisions and gives patients a complaint or redress route.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 3 config and feature flags.

What this provision adds:

  • Model output never reaches the client as therapeutic communication; AI-generated recommendations and treatment plans stay drafts until the licensee reviews and approves them.

Example (Python + OpenAI SDK + FHIR REST), before:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference', json=doc_ref(patient_id, note, doc_status='final'))

After:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference',
              json=doc_ref(patient_id, note, doc_status='preliminary'))   # AI draft

def practitioner_review_and_sign(doc_id, practitioner):   # only path to 'final'
    doc = requests.get(f'{FHIR_BASE}/DocumentReference/{doc_id}').json()
    doc['docStatus'] = 'final'
    doc['authenticator'] = {'reference': f'Practitioner/{practitioner.id}'}
    requests.put(f'{FHIR_BASE}/DocumentReference/{doc_id}', json=doc)
    audit.record(doc_id, reviewed_by=practitioner.id, reviewed_at=utcnow())

Control: Health AI without clinician oversight/accountability + redress. The same guard addresses 9 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id me-ld2082.ai-therapy-role-limits · review status: primary source derived

Binding law — in force

AI must not provide or be offered as therapy to the Maine public unless a licensed professional provides it (Maine LD 2082)

10 M.R.S. § 1500-EE(2) · official text · In force: applies since 29 Jul 2026 · Maine (US-ME)

10 M.R.S. § 1500-EE(2), enacted by P.L. 2026, c. 687 (L.D. 2082), bars any person from providing, advertising or otherwise offering therapy or psychotherapy services to the public, including through internet-based AI, unless a licensed professional provides them. Therapy or psychotherapy services are services to diagnose, treat or address mental or behavioral health through therapeutic communication, which includes understanding a person's thoughts and emotions, therapeutic guidance, emotional support or empathy in response to distress, and treatment planning. A violation is a violation of the Maine Unfair Trade Practices Act; IRB-approved research is excepted. Detect an AI cast or marketed as the therapist, or therapy offered as delivered by AI.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 29 Jul 2026
Official source
10 M.R.S. § 1500-EE(2) · captured 3 Oct 2026 · anchor hash (SHA-256) 16c2fae49315… · 7 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Marketing copy and app-store listings kept outside the repository
  • Therapy framing that avoids the words therapy, therapist and counselor (for example 'talk through your anxiety with Maya')
  • Clinician-facing tools for scheduling, billing or notes use similar words but are permitted for licensees (32 M.R.S. § 2113(2) and the same subsection of the six other sections).

Who it applies to

  • Duty falls on: any person
  • Sectors: healthcare
  • Any person that provides, advertises or otherwise offers therapy or psychotherapy services (10 M.R.S. § 1500-EE(1)(C)-(D)) to the public, including through internet-based AI, unless a licensed professional (1500-EE(1)(B)) provides them. The section states no territorial test; reach to providers outside Maine serving Maine residents is a legal question, as is whether a wellness or companion product is a therapy service. In force since 2026-07-29.
  • Not covered:
    • AI-based interventions used solely within a research project approved by an institutional review board (22 M.R.S. § 1711-C(6)(G)) and conducted under applicable federal human-subjects protections (10 M.R.S. § 1500-EE(4))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Have a licensed clinician conduct every therapy engagement with AI output only as a reviewed draft, or scope the product to self-help with no therapy claims.

Two acceptable shapes, enforced in the message handler that returns model output to the person. If the product is a therapy service, each session has a licensed clinician assigned (session.conducted_by with an active license in the right state), and model output is a draft that clinician approves before it is sent (require_clinician_approval, clinician review queue). If it is not a therapy service, scope it to peer support or scripted self-help, remove persona prompts that cast the AI as the therapist ('act as a therapist'), and remove copy that offers therapy with or by AI.

Where it goes: 1 application source code, 7 prompt construction, 14 user-facing text.

Example (FastAPI + OpenAI SDK), before:

@app.post('/session/message')
def message(req: Msg):
    msgs = [{'role': 'system', 'content': "You are the user's therapist."}, *req.history]
    reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
    return {'reply': reply}

After:

@app.post('/session/message')
def message(req: Msg):
    session = sessions.get(req.session_id)
    clinician = session.conducted_by
    if clinician is None or not clinician.license_active:
        raise HTTPException(409, 'No licensed clinician is conducting this session')
    msgs = [{'role': 'system', 'content': CLINICIAN_DRAFT_PROMPT}, *req.history]
    draft = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
    clinician_review_queue.enqueue(session_id=session.id, clinician_id=clinician.id, draft=draft)
    return {'status': 'sent_to_your_clinician'}

Control: AI delivers or is offered as therapy to the public without a licensed professional conducting it. The same guard addresses 5 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession

Rule id me-ld2082.no-unlicensed-ai-therapy · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.