TwinEthos homeAPI access

Law

Rhode Island ch. 40.1-5.5 (S 2197 / H 7349, AI in mental health care)

Rhode Island Executive Office of Health and Human Services (EOHHS) · Rhode Island (US-RI) · 3 provisions encoded · verified against the official source as of 2026-10-03.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: webserver.rilegislature.gov.

Trust and provenance 1 official source · last verified 3 Oct 2026 · not reviewed by a lawyer · 3 of 3 provisions audit-grade · release 2026.10.03.4

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Lanes
Binding law — in force 3
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 3 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 3.
Audit standard
3 of 3 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
5 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.4 (3 Oct 2026): 3 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

Rhode Island therapists must not let AI make therapeutic decisions, set treatment plans, or interact therapeutically with clients (Rhode Island S 2197)

R.I. Gen. Laws 40.1-5.5-3(c) · official text · In force: applies since 22 Jun 2026 · Rhode Island (US-RI)

R.I. Gen. Laws 40.1-5.5-3(c) limits a licensed professional's AI use to permitted uses, administrative or supplementary support for which the professional keeps clinical judgement and oversight, and bars letting AI make independent therapeutic decisions, determine therapeutic recommendations or treatment plans, or directly interact with clients in therapeutic communication without an established relationship in which the professional undertakes diagnosis and treatment and the patient consents. Detect practice software where model output reaches the client, sets a therapeutic decision, or becomes a treatment plan without the professional's recorded approval.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 22 Jun 2026
Official source
R.I. Gen. Laws 40.1-5.5-3(c) · captured 3 Oct 2026 · anchor hash (SHA-256) 9a881616ccf1… · 7 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Whether an established relationship (40.1-5.5-3(c)(2)) makes direct AI interaction with that client permitted is a legal question
  • Approval enforced inside a vendor EHR outside the repository

Who it applies to

  • Duty falls on: individual professional
  • Sectors: healthcare
  • Rhode Island licensed professionals or providers: individuals holding a valid Rhode Island license, credential or certification to provide therapy or psychotherapy services (R.I. Gen. Laws 40.1-5.5-2(4)). Vendors of practice software are reached through what the professional may allow the AI to do. The established-relationship clause of 40.1-5.5-3(c)(2) and the professional's responsibility 'but not for vendor-controlled system design, algorithms, or outputs' leave open how far AI may interact with an established client; a legal question. In force since 2026-06-22.
  • Not covered:
    • Religious counseling (R.I. Gen. Laws 40.1-5.5-5(c)(1); defined in 40.1-5.5-2(7))
    • Peer support (40.1-5.5-5(c)(2); defined in 40.1-5.5-2(5))
    • Self-help materials and educational resources available to the public that do not purport to offer therapy or psychotherapy services (40.1-5.5-5(c)(3))
    • AI tools or systems reviewed and cleared for use by the FDA or another federal agency that approves AI for use in health care (40.1-5.5-5(c)(4))
    • Research under 21 C.F.R. Pt. 50 and/or 45 C.F.R. Pt. 46 approved by a healthcare facility's IRB under § 23-17-19.1 (40.1-5.5-5(c)(5))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.

A clinician sign-off step between the model call and every clinical sink: AI-drafted notes, summaries, diagnostic suggestions, triage levels, and treatment plans are stored as drafts (FHIR DocumentReference.docStatus 'preliminary', DiagnosticReport.status 'preliminary', CarePlan.status 'draft') and become final, active, or visible to the patient only through an action by an authorized clinician that records reviewed_by and reviewed_at. Configuration flags that auto-sign or auto-finalize AI-drafted records stay false, and provenance shows the AI as a contributing device and the clinician as verifier. The deployment also names who is accountable for AI-assisted decisions and gives patients a complaint or redress route.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 3 config and feature flags.

What this provision adds:

  • AI-produced therapeutic recommendations and treatment plans stay drafts the licensed professional determines; the AI never makes therapeutic decisions on its own.

Example (Python + OpenAI SDK + FHIR REST), before:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference', json=doc_ref(patient_id, note, doc_status='final'))

After:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference',
              json=doc_ref(patient_id, note, doc_status='preliminary'))   # AI draft

def practitioner_review_and_sign(doc_id, practitioner):   # only path to 'final'
    doc = requests.get(f'{FHIR_BASE}/DocumentReference/{doc_id}').json()
    doc['docStatus'] = 'final'
    doc['authenticator'] = {'reference': f'Practitioner/{practitioner.id}'}
    requests.put(f'{FHIR_BASE}/DocumentReference/{doc_id}', json=doc)
    audit.record(doc_id, reviewed_by=practitioner.id, reviewed_at=utcnow())

Control: Health AI without clinician oversight/accountability + redress. The same guard addresses 9 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id ri-s2197.ai-therapy-role-limits · review status: primary source derived

Binding law — in force

AI must not provide or be offered as therapy to the Rhode Island public unless a licensed professional conducts it (Rhode Island S 2197)

R.I. Gen. Laws 40.1-5.5-3(b) · official text · In force: applies since 22 Jun 2026 · Rhode Island (US-RI)

R.I. Gen. Laws 40.1-5.5-3(b), enacted by P.L. 2026, ch. 374 (S 2197) and ch. 373 (H 7349), bars any individual, corporation or entity from providing, advertising or otherwise offering therapy or psychotherapy services to the public in Rhode Island, including through internet-based AI, unless an individual who is a licensed professional or provider conducts them. Religious counseling, peer support, public self-help material that does not purport to offer therapy, FDA-cleared AI tools and IRB-approved research are outside the chapter. Detect an AI cast or marketed as the therapist, or therapy offered as delivered by AI, with no licensed professional conducting the service.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
Lane
Binding law — in force In force: applies since 22 Jun 2026
Official source
R.I. Gen. Laws 40.1-5.5-3(b) · captured 3 Oct 2026 · anchor hash (SHA-256) c732eb69be7e… · 6 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Marketing copy and app-store listings kept outside the repository
  • Therapy framing that avoids the words therapy, therapist and counselor (for example 'talk through your anxiety with Maya')
  • Clinician-facing tools for scheduling, billing or notes use similar words but are permitted uses (40.1-5.5-2(6)); religious counseling, peer support, self-help content and FDA-cleared tools are outside the chapter (40.1…

Who it applies to

  • Duty falls on: any person
  • Sectors: healthcare
  • Any individual, corporation or entity that provides, advertises or otherwise offers therapy or psychotherapy services (services to diagnose or treat mental or behavioral health, 40.1-5.5-2(10)) to the public in Rhode Island, including through internet-based AI, unless a licensed professional or provider conducts them (40.1-5.5-3(b)). Whether a wellness, coaching or companion product is a therapy service is a judgment call. In force since 2026-06-22.
  • Not covered:
    • Religious counseling (R.I. Gen. Laws 40.1-5.5-5(c)(1); defined in 40.1-5.5-2(7))
    • Peer support (40.1-5.5-5(c)(2); defined in 40.1-5.5-2(5))
    • Self-help materials and educational resources available to the public that do not purport to offer therapy or psychotherapy services (40.1-5.5-5(c)(3))
    • AI tools or systems reviewed and cleared for use by the FDA or another federal agency that approves AI for use in health care (40.1-5.5-5(c)(4))
    • Research under 21 C.F.R. Pt. 50 and/or 45 C.F.R. Pt. 46 approved by a healthcare facility's IRB under § 23-17-19.1 (40.1-5.5-5(c)(5))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Have a licensed clinician conduct every therapy engagement with AI output only as a reviewed draft, or scope the product to self-help with no therapy claims.

Two acceptable shapes, enforced in the message handler that returns model output to the person. If the product is a therapy service, each session has a licensed clinician assigned (session.conducted_by with an active license in the right state), and model output is a draft that clinician approves before it is sent (require_clinician_approval, clinician review queue). If it is not a therapy service, scope it to peer support or scripted self-help, remove persona prompts that cast the AI as the therapist ('act as a therapist'), and remove copy that offers therapy with or by AI.

Where it goes: 1 application source code, 7 prompt construction, 14 user-facing text.

Example (FastAPI + OpenAI SDK), before:

@app.post('/session/message')
def message(req: Msg):
    msgs = [{'role': 'system', 'content': "You are the user's therapist."}, *req.history]
    reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
    return {'reply': reply}

After:

@app.post('/session/message')
def message(req: Msg):
    session = sessions.get(req.session_id)
    clinician = session.conducted_by
    if clinician is None or not clinician.license_active:
        raise HTTPException(409, 'No licensed clinician is conducting this session')
    msgs = [{'role': 'system', 'content': CLINICIAN_DRAFT_PROMPT}, *req.history]
    draft = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
    clinician_review_queue.enqueue(session_id=session.id, clinician_id=clinician.id, draft=draft)
    return {'status': 'sent_to_your_clinician'}

Control: AI delivers or is offered as therapy to the public without a licensed professional conducting it. The same guard addresses 5 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession

Rule id ri-s2197.no-unlicensed-ai-therapy · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.