Manatt Health: Q2 2026 AI Policy and Health Care
Introduction:
After a surge of legislative activity in the first and second quarters of the year, with over 280 bills introduced, only 29 bills have been signed into law across 20 states. States continued to legislate artificial intelligence (AI) chatbots, payer and health care provider use of AI, and focused on transparency by mandating disclaimers to the end-user of AI. In addition, several states focused on legislating the state’s use of AI and how to encourage its use. Highlights include:
- Of the 20 states that enacted AI laws impacting health care stakeholders this year, seven states enacted laws imposing requirements on consumer-facing AI chatbots, a significant number of which include provisions specific to protecting user mental health and detecting mental health crises, as well as provisions mandating additional protections for users under the age of 18.
- Colorado—after unsuccessful attempts during the prior legislative session—finally revised their sweeping anti-discrimination and transparency law from 2025 (), significantly reducing compliance requirements for developers and deployers and introducing broad exemptions for HIPAA-covered entities and Food and Drug Administration (FDA)-regulated medical devices, leaving only minimal requirements on HIPAA-covered health care providers.
- Connecticut passed a sweeping online safety bill () with AI-related provisions, including imposing significant requirements on companion chatbots; whistleblower protections for covered employees of frontier developers who raise concerns; direction for the state to establish a plan to create an AI Regulatory Sandbox; significant investments in AI literacy; and a pilot program for the state to establish up to five Independent Verification Organizations (IVOs) to assess AI models.
As of the publication of this newsletter, only seven states (California, Michigan, Ohio, Pennsylvania, North Carolina, New Jersey, and Massachusetts) remain in session. Several bills are pending for the New York Governor’s signature. Thus, most of the bills introduced outside of the aforementioned states will not be adopted.

There has been more activity from the federal government in 2026 than in 2025, with the federal government demonstrating a potentially greater willingness to legislate or create frameworks to address certain AI safety concerns.
- On June 2, President Trump signed , “Promoting Advanced Artificial Intelligence Innovation and Security.” This represents a shift in federal AI policy toward national security and cybersecurity priorities, directing agencies to strengthen cyber defenses, expand use of AI-enabled security tools, and improve access to advanced cybersecurity capabilities for government entities and critical infrastructure operators, including rural hospitals. The EO also establishes new federal processes to assess security risks posed by highly advanced AI models, creates a voluntary framework for identifying highly advanced AI models and enabling government access (e.g., pre-release review) to assess security risks. It also creates an AI cybersecurity clearinghouse to coordinate vulnerability management and directs the Department of Justice (DOJ) to prioritize enforcement against AI-enabled cybercrime and misuse.
- On June 4, Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a of the Great American AI Act. The framework would require developers to implement plans to address catastrophic risks (with third-party auditors tasked with ensuring compliance with the plan). Notably, the draft includes language preempting state law addressing AI model development.
- In late April, after xAI Colorado challenging the Colorado AI Act (CAIA) () (April 9, 2026), DOJ in support (April 24, 2026), arguing the law's algorithmic-discrimination provisions violate the Equal Protection Clause; a federal court the law's enforcement (April 27, 2026) pending resolution. As described below, Colorado's legislature has since passed (May 14, 2026), replacing SB 205 with a significantly narrowed scope. It is not clear how the DOJ will proceed in light of the amended law.
- At the end of 2025, the White House signaled a more aggressive approach to state AI regulation through EO 14365, which directed the DOJ to challenge state AI laws deemed overly burdensome and required the Secretary of Commerce to evaluate such laws by March 11, 2026. While the order likely contributed to the lawsuit filed in Colorado, the Commerce Department has yet to publish the required evaluation, and the DOJ has otherwise not acted.
The sections below provide a deep dive into emerging themes and notable actions from states and federal government, and what we are watching as the year progresses.
State Activity in 2026:
As state legislatures conclude their sessions, the laws enacted during Q2 focus on areas similar to those we saw in the prior quarter and in 2025: states continued to legislate AI chatbots, payer use of AI, and health care provider use of AI, and focus on disclosures to the end-user of AI. While many states introduced bills addressing liability for harm caused by AI tools, no legislation passed so far in 2026 (as of the date of this publication).

1. Transparency:
In Q2, Colorado passed , which repeals and reenacts the AI consumer protection framework established in the state’s landmark consumer protection law from 2024, . After Colorado Governor Jared Polis expressed reservations with SB 205 upon signing and requested that the legislature revise the bill, and after SB 205 was explicitly named as an onerous state law in President Trump’s December 2025 , “Ensuring a National Policy Framework for Artificial Intelligence,” the Colorado legislature embarked on multiple unsuccessful attempts to amend SB 205 during the 2025 legislative session, ultimately delaying the effective date of the law to allow additional time to make revisions. After these failures, in October 2025, Governor Polis convened a Colorado AI Policy Work Group; this work group unanimously released a proposed bill to revise SB 205 before it was scheduled to go into effect on June 30, 2026. The state legislature passed this bill and Governor Polis signed it into law in May 2026.
The legislature amended the law shortly after two significant constitutional challenges were filed against Colorado: xAI sued to block SB 24-205, alleging that the law violates the First Amendment, is unconstitutionally vague, violates the dormant Commerce Clause, and denies equal protection. DOJ later intervened, focusing violations of Equal Protection arguing that the law effectively requires AI developers to consider protected characteristics such as race and sex when designing and monitoring AI systems. Together, the filings position Colorado’s AI law as a leading test case for constitutional challenges to state AI regulation.
The amended law shifts away from the prior framework centered on “high-risk AI systems” and “algorithmic discrimination” to a more streamlined approach focused on automated decision-making technology (ADMT) used in consequential decisions. Key modifications (among others) include:
- Eliminating the AI developer’s obligation to exercise “reasonable care” to prevent algorithmic discrimination;
- Removing deployer risk management and impact assessment requirements;
- Revising consumer notice requirements such that the requirement may generally be satisfied through a prominent public website posting rather than individualized notice; and,
- Revising exemptions to the law to include:
- A broadened exemption for HIPAA-covered entities operating in Colorado and their business associates (except when ADMT is used for employment decisions or to determine a patient's eligibility for financial assistance); and
- An exemption for FDA-regulated medical devices or activities.
2. AI Chatbots:
States continue to focus on AI chatbots in response to ongoing public attention on the negative impacts of these tools—particularly harmful or inaccurate responses generated by AI chatbots, failure to detect mental health crises, and deleterious impacts on minors. So far in 2026, states introduced 86 bills regulating AI chatbots, including 12 bills this quarter. Seven states enacted eight bills into law, including another law enacted in New York (described below).
Consistent with bills introduced and passed in 2025 and early 2026, most chatbot laws enacted in 2026 require chatbot operators to clearly disclose to users that they are interacting with an AI system rather than a human.
Six of the eight chatbot bills signed into law this year require more frequent or persistent disclosures when the user is a minor or when the chatbot is designed to simulate a human companion. Colorado (effective 1/1/2027), Georgia (effective 7/1/2027), Idaho (effective 7/1/2027), Connecticut (effective dates vary by provision), and Oregon (effective 1/1/2027) impose additional safeguards for minors that include more frequent disclosures, content restrictions, limitations on engagement-maximizing design features, and requirements to provide parental monitoring and privacy-management tools. New York , the “Safe by Design Act” (AI-specific provisions effective 1/1/2027), requires age-assurance measures before users can access AI companions and establishes additional protections for children under age 13, such parental consent and oversight of interactions with other users.
Six of the eight chatbot bills signed into law (Rhode Island (effective 1/1/2027), Colorado , Georgia , Connecticut , Oregon , and Idaho ) include requirements that chatbot operators ensure their systems are capable of detecting expressions of self-harm, suicidal ideation, or other mental health crises and responding appropriately (e.g., by providing referrals to crisis resources, such as the 988 Suicide and Crisis Lifeline, and implementing protocols designed to prevent chatbots from producing responses that encourage harmful behavior).
Three of these new laws contain provisions prohibiting chatbots from representing themselves as mental health care providers (Colorado , Georgia , and Idaho ). While multiple states introduced bills this year that more generally prohibit chatbots from misrepresenting themselves as licensed health care providers, mirroring provisions in IL (passed in 2025), none of those bills were enacted in 2026 to date.
In early May, the Commonwealth of Pennsylvania against Character Technologies (the creators of Character.AI). Rather than alleging negligence or consumer deception, Pennsylvania is using its Medical Practice Act to argue that the company itself engaged in the unauthorized practice of medicine after one of its chatbots allegedly represented itself as a licensed psychiatrist using a fabricated Pennsylvania license number. The Commonwealth is seeking injunctive relief before anyone needs to prove patient injury, relying on statutes designed to stop unauthorized professional practice. No court has ruled that Character.AI violated the law; through this action, regulators are testing whether an AI developer can itself become the regulated actor.
We expect this to be an area of continued state and federal interest.
3. Payer Use of AI for Utilization Management and Prior Authorization:
States have maintained focus on regulating payer use of AI throughout 2026, continuing a trend that began in 2024. States introduced 45 bills addressing payer use of AI, with only six of those introduced in Q2 of 2026. In 2026 to date, only six states enacted six bills into law.
Alabama (effective 10/1/2026), Colorado (effective 1/1/2027), Georgia (effective 1/1/2027), and Minnesota (effective 8/25/2026) prohibit payers from solely using AI to deny prior authorizations or make adverse coverage determinations without human review.
Alabama and Utah (effective 1/1/2027) require payers to disclose their use of AI in utilization review to enrollees. Colorado requires reporting to the state on use of AI in utilization review and prohibits public or private payers for reimbursing for psychotherapy services performed by an AI system. Lastly, Minnesota requires disclosure of use of AI in utilization review to enrollees and the state.
In 2026, states also had a new focus - prohibiting AI from downcoding claims without oversight by a licensed physician. As of this publication, only two bills have been signed into law. Last quarter, Indiana (effective 7/1/2026) was signed into law (please see discussion in our Q1 newsletter). This quarter, Illinois enacted (effective 1/1/2028), prohibiting payors from using AI to downcode claims and requiring physician-led clinical review, detailed notice, and an appeals process for downcoding decisions.
4. Use of AI in Clinical Care:
Consistent with trends observed in 2025 and early 2026, states continue to introduce and pass legislation regulating the use of AI in clinical care, particularly in behavioral health and psychotherapy services drawing heavily from the framework established in 2025 by Illinois (effective 8/1/2025). In 2026, 27 states introduced 46 bills addressing the use of AI in health care settings and six states enacted seven bills into law.
Two enacted laws, Colorado (effective 8/12/2026) and Maine (effective 7/29/2026), (1) permit licensed professionals to use AI only for administrative or supplementary support in therapy or psychotherapy services; (2) require licensed professionals to maintain responsibility for all AI-assisted interactions and outputs; and (3) prohibit licensed professionals from allowing AI tools to make independent therapeutic decisions, directly interact with clients in any form of therapeutic communication, or generate therapeutic recommendations or treatment plans without review by the licensed professional.
Vermont (effective 6/17/2026) affirms that mental health professionals may use AI tools that are compliant with HIPAA as long as (1) the professional is operating within their scope of practice and (2) the mental health professional reviews and approves any mental health services; this includes Software as a Medical Device (SaMD), provided use is prescribed or recommended by a mental health professional. The law additionally prohibits any corporation or entity from providing, advertising, or otherwise offering mental health services (including through the use of AI) to the public unless mental health services are provided by a mental health professional or are part of an institutional review board or privacy board study.
While Texas’ legislature is not in session in 2026, the state issued a that prohibits behavioral analysis license holders from using AI as the sole basis for treatment design, assessment, implementation, reports, or evaluations, and prohibits licensees from using AI to treat clients when doing so would exceed their training or scope of licensure. The additionally requires license holders to personally review all AI-generated or AI-assisted treatment materials to verify that AI-derived information is accurate and evidence-based (and document verification in the client's file); if AI suggests restrictive or punishment-based procedures, they must be reviewed by the license holder to confirm if less intrusive alternatives are viable, weigh benefits against harm, and document rationale.
Three enacted laws include requirements for patient consent prior to use of AI in delivery of therapeutic services:
- Maine requires that licensees inform clients or their legal representatives in writing of the use of AI for supplementary support when the session is recorded or transcribed. This disclosure must include the specific purpose of the AI tool in use and how session data collected by the AI tool will be stored, retained, used for training, and deleted upon termination of services. The client or their legally authorized representative must provide consent for the use of AI.
- Rhode Island (effective 6/22/2026) requires that psychotherapy providers inform clients or their legal representative in writing of the use of AI and its specific purpose before using AI tools designed to simulate emotional attachment or AI companions to assist in supplementary support or therapeutic communication when a client’s session is recorded or transcribed. The client or their legally authorized representative must provide consent for the use of AI.
- Colorado requires that psychotherapy providers inform clients or their legal representative in writing of the use of AI and its specific purpose, and obtain written consent, before using AI to record or transcribe a session.
While most enacted legislation has focused on the clinical use of AI in behavioral health settings, Louisiana (effective 8/1/2026) and Rhode Island (effective 6/22/2026) mandate that providers notify patients when AI is used to record or document a patient visit.
California introduced a bill () that, if passed, would be the most restrictive with regard to AI use in mental health, given that it prohibits the use of AI to record or transcribe therapeutic communications or sessions or triage or screening without informing the patient or their legal representative verbally or in writing and obtaining consent for the use of AI. As of the publication of this newsletter, the bill has been engrossed.
Indiana (7/1/2026) addresses the use of AI in health care administrative functions by prohibiting providers from using AI to submit health benefit claims without review by a provider or another individual involved in preparing the claim.
One state introduced a bill focused on provider upcoding of claims: North Carolina’s legislature introduced , which, if enacted, would prohibit developers from creating and health care providers from using any system designed to result in inappropriate and unsupported “upcoding.” The bill would also require providers to annually certify to the state that they are not using AI systems designed to promote or result in upcoding as a condition of participation in the Medicaid program. As of the publication of this newsletter, the bill has been engrossed and continues to actively move through the legislature.
5. Liability:
As health care stakeholders rapidly adopt AI, both state and federal lawmakers are grappling with who is liable for harms caused by AI tools. The of the Trump America AI Act (released by Senator Marsha Blackburn) would impose a negligence-based duty of care on AI developers, establish shared liability for developers and deployers for reasonably foreseeable harms, and create a private right of action, signaling growing federal interest in an AI-specific liability regime even though no comprehensive federal AI liability law has been enacted to date. See “” for additional analysis. Separately, state lawmakers have advanced their own approaches to AI liability, with particular attention to AI tools used in clinical care, patient-facing chatbots, and other health-related contexts.
In 2026 to date, states have introduced approximately 20 bills addressing liability for AI tools, including three introduced in Q2. Notable proposals include:
- , which would impose civil liability on owners, operators, and developers of generative AI platforms that do business or make their platforms available in the state if they fail to prevent the platform from engaging in conduct that constitutes a crime if committed by a person, including murder, assault, endangering the welfare of children, or aiding or abetting a crime.
- (introduced but dead), which would treat chatbots as products for purposes of products liability claims and would subject chatbot providers to strict liability for injuries caused by the chatbot. Therefore, a provider could still face liability even if it acted reasonably and had no direct relationship with the injured user.
- , which would limit a chatbot proprietor’s ability to disclaim liability when a chatbot provides harmful, materially misleading, incorrect, or contradictory information that results in financial liability, bodily harm, or other demonstrable harm. The bill also includes heightened protections for minors, including strict liability in certain self-harm scenarios.
- , which would expand medical malpractice standards to cover negligent or excessive reliance on AI in diagnosis, treatment, or patient care. In practical terms, the bill would make clear that providers cannot rely on AI output without appropriate clinical judgment and oversight.
- , which would prevent AI developers and deployers from avoiding liability by arguing that a clinician’s failure to override an AI output broke the causal chain. The bill is notable for health care stakeholders because it would keep potential responsibility on AI companies even when a clinician is involved in the patient-care decision.
6. AI Sandboxes and Regulatory Relief Programs:
As noted in our Q1 newsletter, state action to create AI sandboxes and regulatory relief programs began in earnest in 2024 with the passage of Utah and continued with the enactment of Texas in 2025. At the end of Q1 2026, four states had introduced bills to establish AI sandboxes or regulatory relief programs; in Q2, three additional states introduced legislation, and one bill, Connecticut , was passed and signed into law.
Connecticut (effective July 1, 2027) directs the Commissioner of Economic and Community Development to develop and submit a plan to the Governor and relevant legislative committees, by January 1, 2028, to establish an AI regulatory sandbox program. Notably, this plan must include an assessment of the feasibility of a reciprocal multistate AI sandbox program—a mechanism that could help developers and deployers operating across multiple states avoid duplicative applications and a fragmented regulatory landscape.
Idaho and Iowa introduced bills ( and , respectively) based on the Cicero Institute's . Both bills create a new category of licensed AI provider (Artificial Intelligence Augmented and Autonomous Service Provider), establish a Board of Autonomous Medical Practice, create tiered licensing based on AI autonomy and clinical function, include provisional “sandbox” licenses, contemplate insurance reimbursement, and incorporate extensive oversight and auditing requirements. The regulatory sandbox proposes with a two-year provisional licensure period during which companies can deploy AI clinical services under state supervision, subject to safety benchmarking. There are also federal and state reciprocity concepts envisioned in the bills. We do not expect either bill to advance this year, as both Idaho and Iowa have adjourned their 2026 legislative sessions.
We continue to monitor states with developing and active AI Sandbox and regulatory relief programs:
- Delaware: The state's continues to meet regularly with the Secretary of State (as required by Delaware , enacted 2025). The Commission is actively refining draft AI sandbox legislation; as Delaware's legislature adjourned on June 30, 2026, we do not expect this legislation to be introduced until the state's next legislative cycle.
- Texas: The Texas Responsible Artificial Intelligence Act (TRAIGA) (enacted by and effective 1/1/26) created an AI regulatory sandbox; there has been no publicly reported activity utilizing Texas’s sandbox.
- Utah: While the has not entered into any new regulatory mitigation agreements since its agreements with prescription renewal company (January 2026) and AI-native psychiatry company (March 2026), the state is seeing increasing pushback from stakeholders. On April 20, 2026, the Utah Medical Licensing Board sent a to the Department of Commerce calling for the Doctronic pilot's immediate suspension, arguing it had not been consulted before the program launched and that “[o]verseeing prescription refills is a task reserved for properly licensed medical practitioners for critical safety and clinical reasons.” OAIP and the Division of Professional Licensing jointly on April 21, declining to suspend the pilot—noting it remains in Phase 1, under which a licensed physician reviews every AI-generated renewal before submission to a pharmacy — but committing to consulting the board on future health care-related regulatory mitigation agreements. Nonprofit public interest organization Public Citizen separately sent a in May echoing the board's call for suspension.
We will continue to monitor Delaware, Utah, Connecticut, and Texas in the coming months.
Notable Federal Activity
The White House has continued to exert pressure on states to stop legislating AI, while also taking its first concrete steps toward direct federal cybersecurity oversight. President Trump's most recent (June 2, 2026) represents a notable shift for an Administration that has otherwise taken a deregulatory posture toward AI: it directs the federal government to take a more active oversight role over advanced AI models that pose national security risks, even as it continues to resist comprehensive AI regulation more broadly. Among its requirements, the EO:
- Directs federal agencies to upgrade cybersecurity for national security systems, defense systems, and civilian federal networks, including through the use of AI-enabled defensive tools;
- National security and defense agencies must immediately prioritize and strengthen cyber defenses for National Security Systems and Department of War systems
- The Department of Homeland Security (DHS, via CISA), with the Office of Management and Budget (OMB) and national security leadership, must issue binding directives to accelerate cybersecurity protections across civilian federal systems.
- Federal agencies are directed to deploy and expand AI-enabled cybersecurity tools and programs to improve threat detection and response.
- The government must facilitate access to cybersecurity tools and services, including advanced AI capabilities, for federal agencies, state/local entities, and critical infrastructure operators, including rural hospitals.
- Within 60 days, the EO requires a number of agencies to collectively establish a classified benchmarking process and a voluntary framework for identifying highly advanced AI models and enabling government access (e.g., pre-release review) to assess security risks.
- Within 30 days, requires the development of an AI cybersecurity clearinghouse that coordinates and deconflicts scanning for software vulnerabilities, discovers and validates such vulnerabilities, and coordinates and prioritizes remediation and distribution of vulnerability patches.
- Directs DOJ to prioritize enforcement against AI-enabled cybercrime and misuse.
We do not expect the EO to have significant impact on health care stakeholders.
Congress is separately attempting to establish a national AI regulatory framework. A bipartisan group led by Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a on June 4, 2026. The proposal is explicitly intended to create a national framework for AI governance, with key provisions including:
- Transparency requirements for large frontier AI developers, including third-party audits through IVOs and whistleblower protections; and
- A three-year preemption of state laws regulating the development of AI models, explicitly excluding laws of general applicability and laws regulating the use of AI.
The draft has not been formally introduced and remains open for stakeholder feedback.
As described in the Liability section above, Senator Marsha Blackburn (R-TN) a discussion draft of the “TRUMP AMERICA AI Act” to preempt state AI laws and codify the Trump Administration’s legislative agenda.
Federal agencies also continued implementation of several AI-related initiatives this quarter. The Centers for Medicare and Medicaid Services’ (CMS’s) Model—set to begin its first cohort on July 5, 2026—illustrates one way payment design itself may drive AI adoption: payment rates are capped at $180–$360 per patient, per year, far lower than current market rates for comparable technology-supported chronic care products. As a result, ACCESS participants are expected to lean heavily on scalable automation, AI, and care delivery processes. Separately, the FDA began receiving statements of interest for participation in its Pilot in early January 2026, and began sending follow-up requests to certain potential pilot participants in March 2026. The first participant, Dexcom, Inc., was on July 22, 2026. Per the FDA announcement, the Dexcom Glucose Health Program is “is intended to enable patients aligned to the ACCESS model and their health care professionals or caregivers to monitor metabolic and nutritional status, receive tailored guidance, and access real-time data and AI insights for informed decision-making and behavioral modifications;” it is additionally intended to aid in screening for prediabetes and type 2 diabetes through integrated digital health metrics. The also continued moving its program forward; full proposals were due April 1, 2026. We will be monitoring the ADVOCATE program for award team selection and additional action.
CMS's implementation of its model drew significant federal pushback during the quarter. The model, which uses AI and machine learning vendors to review prior-authorization requests for select Medicare fee-for-service items across six states, has been live since January 1, 2026. In May 2026, the Government Accountability Office (GAO) (May 12, 2026) that WISeR constitutes a “rule” subject to the Congressional Review Act, meaning it should have been submitted to Congress before taking effect. Senate and House Democrats subsequently introduced joint resolutions (see and ) of disapproval (May 19–20, 2026), and the House Appropriations Committee by voice vote (June 9–10, 2026) to adopt an to bar CMS from spending fiscal year (FY) 2027 funds on WISeR or similar AI prior-authorization models. The underlying spending bill has not yet passed either chamber as of the publication of this newsletter. A Democratic-led measure in the Senate to repeal WISeR on party lines on July 16. Additionally, CMS issued a from a WISeR program participant, Vertix Health, the participant in Washington, after it was found to be out of compliance with the required 72-hour turnaround time for prior authorization and pre-payment decisions for procedures covered by WISeR.
In late June, UpDoc announced that it obtained FDA clearance for an AI product that interacts directly with patients in between appointments and adjusts medication doses within parameters set by the patient’s human clinician. This approval makes UpDoc the first digital health company to receive SaMD clearance for a product that uses patient-facing large language models.
Finally, as discussed above, the DOJ’s AI Litigation Task Force, established under , took its first action this quarter. After xAI Colorado challenging the CAIA () (April 9, 2026), DOJ in support (April 24, 2026), arguing the law's algorithmic-discrimination provisions violate the Equal Protection Clause; a federal court the law's enforcement (April 27, 2026) pending resolution. As noted above, Colorado's legislature has since passed (May 14, 2026), replacing SB 205 with a significantly narrowed scope. It is not clear how the DOJ will proceed in light of the amended law.
Additional activity is described in the federal activity table below.
Conclusions and What to Watch:
While most state legislatures have adjourned or are in recess, we will continue to monitor the states still in session for additional AI activity, as several states did enact AI laws in the second half of 2025. Other areas we are watching for in 2026:
- First cohort of TEMPO participants will be announced by FDA.
- Additional guidance from FDA regarding its approach to regulating AI and additional convening of the FDA’s Digital Health Advisory Committee.
- CMS outpatient and physician fee schedules will be finalized in the fall—each of which has proposed changes to payment for ‘software as a medical service.’
- Various federal agencies may issue guidance in accordance with the December 2025 Executive Order on a national policy framework for AI.
- Continued debate over the CMS WISeR model.
- The Office of the National Coordinator for Health Information Technology (ONC)’s HTI-5 final rule which proposed removing AI model card requirements for certified health IT.
Deep Dive: State Activity
For a full list of all laws prior to and including 2026, please see .
Deep Dive: Federal Activity:
Agency | 2026 Activity to Date |
|---|---|
White House |
|
Congress |
|
FTC |
|
HHS |
|
OCR |
|
ONC |
|
CMS |
|
FDA |
|
NIH |
|
DOJ |
|
OMB |
|
ARPA-H |
|
For questions on the above, please reach out to or .
See Subtitle C, Section 121, Federalization of State Laws Regulating Artificial Intelligence Model Development.
The following bills regulating AI chatbots have been signed into law in 2026: , , , , , , , and .
The following bills regulating payer use of AI have been signed into law in 2026: Utah , Minnesota , Indiana , Georgia , Colorado , Alabama , and .
The following bill regulating the use of AI by providers have been signed into law in 2026: Vermont , Rhode Island , Rhode Island , Maine , Louisiana , Indiana , Colorado , and Colorado .
An October 2025 by Menlo Ventures found that in 2025, 22% of health care businesses have implemented domain-specific AI tools. That implementation level is a 10x increase over 2023 and more than twice the rate of the broader U.S. economy.
AI Sandboxes are structured, time-limited programs that allow developers of AI systems to test or deploy those systems in a controlled environment with defined oversight and temporary relief from select state laws or regulatory requirements, for the purpose of evaluating system performance, risks, and appropriate regulatory treatment. AI regulatory mitigation programs are similarly structured but allow testing to occur in the real world, not a controlled environment.
Several states have also enacted broader innovation or fintech sandbox programs that are not AI-specific and predate the current wave of AI sandbox activity, including Arizona, Wyoming, North Carolina, Ohio, Kentucky, West Virginia, Florida, Missouri, Kansas, and Utah. Non-AI-specific regulatory sandbox programs by state include: Arizona (enacted 2018; expanded by in 2022); Wyoming (enacted 2019); Kentucky (enacted 2019; expanded to a universal sandbox by in 2023); West Virginia (enacted 2020); Utah (enacted 2021; general multi-sector sandbox, separate from Utah's AI-specific ); Florida (enacted 2021); North Carolina (enacted 2021; administered by the ); Ohio (enacted 2022); Missouri (enacted July 2024); and Kansas (enacted July 2025).
See UpDoc’s announcement here: .
See UpDoc’s announcement here: .