Binding law — in force
Rhode Island therapists must give written notice and get written consent before using AI on recorded or transcribed sessions (Rhode Island S 2197)
R.I. Gen. Laws 40.1-5.5-3(a) bars a licensed professional or provider from using AI designed to simulate emotional attachment, bonding or dependency, or AI companions for mental health or emotional support, to assist in supplementary support or therapeutic communication where the client's session is recorded or transcribed, unless the patient (or parent, guardian or legal representative) is told in writing that AI will be used and its specific purpose, and gives consent. Consent means an affirmative, explicit, informed, specific and revocable written agreement (electronic allowed); accepting general terms of use, hovering or closing content, and deceptive actions do not count. Detect session recordings or transcripts reaching an AI step with no per-client written consent check.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
- Lane
- Binding law — in force In force: applies since 22 Jun 2026
- Official source
- R.I. Gen. Laws 40.1-5.5-3(a) · captured 3 Oct 2026 · anchor hash (SHA-256)
9876921d8cad…· 6 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
- Data release
- Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
3 detectors (code pattern, data flow, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Consent enforced by an upstream service or the EHR before the session reaches this code
- Whether a given tool is the kind of AI the state's consent duty names is a legal question
Who it applies to
- Duty falls on: individual professional
- Sectors: healthcare
- Rhode Island licensed professionals or providers: individuals holding a valid Rhode Island license, credential or certification to provide therapy or psychotherapy services (R.I. Gen. Laws 40.1-5.5-2(4)). Vendors of practice software are reached through what the professional may allow the AI to do. The duty names AI designed to simulate emotional attachment, bonding or dependency, and AI companions for mental health or emotional support; whether it also reaches ordinary AI scribes and note tools is a legal question. In force since 2026-06-22.
- Not covered:
- Religious counseling (R.I. Gen. Laws 40.1-5.5-5(c)(1); defined in 40.1-5.5-2(7))
- Peer support (40.1-5.5-5(c)(2); defined in 40.1-5.5-2(5))
- Self-help materials and educational resources available to the public that do not purport to offer therapy or psychotherapy services (40.1-5.5-5(c)(3))
- AI tools or systems reviewed and cleared for use by the FDA or another federal agency that approves AI for use in health care (40.1-5.5-5(c)(4))
- Research under 21 C.F.R. Pt. 50 and/or 45 C.F.R. Pt. 46 approved by a healthcare facility's IRB under § 23-17-19.1 (40.1-5.5-5(c)(5))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Check a signed, unrevoked, purpose-specific AI-use consent for the client before any session audio or transcript is sent to an AI transcription, note, or summary model.
A consent gate in the note-assistant pipeline placed before the first AI step (a model transcription call counts) and again before the note or summary call: it loads the client's consent record for this tool's purpose (for example ai_scribe), requires signed_at and no revoked_at, and refuses otherwise. The record references the version of the written notice the client or their representative received, naming the tool's purpose. Consent is collected as a separate explicit act on its own form, never inferred from terms-of-use acceptance, and a revocation endpoint sets revoked_at and cancels queued AI jobs for that client.
Where it goes: 1 application source code, 2 data models, 14 user-facing text.
What this provision adds:
- The written notice states that AI will be used and the specific purpose of the AI tool or system; the patient, parent, guardian or legal representative consents in writing.
- Consent is a separate affirmative, revocable written act; acceptance of general terms of use, hovering, muting, pausing or closing content, or deceptive design does not count.
Example (Python + OpenAI SDK), before:
def draft_note(session):
with open(session.audio_path, 'rb') as f:
transcript = client.audio.transcriptions.create(model='whisper-1', file=f).text
resp = client.chat.completions.create(model=MODEL, messages=[
{'role': 'system', 'content': NOTE_PROMPT}, {'role': 'user', 'content': transcript}])
return resp.choices[0].message.contentAfter:
def draft_note(session):
consent = db.consents.get(client_id=session.client_id, purpose='ai_scribe')
if consent is None or consent.signed_at is None or consent.revoked_at:
raise ConsentRequired('written AI-use consent for note drafting is missing or revoked')
with open(session.audio_path, 'rb') as f:
transcript = client.audio.transcriptions.create(model='whisper-1', file=f).text
resp = client.chat.completions.create(model=MODEL, messages=[
{'role': 'system', 'content': NOTE_PROMPT}, {'role': 'user', 'content': transcript}])
return resp.choices[0].message.contentControl: AI used on recorded or transcribed therapy sessions without written notice and consent. The same guard addresses 3 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required
Rule id ri-s2197.ai-session-recording-notice-consent · review status: primary source derived