Direct comparison
AI Therapy Laws: Illinois vs Nevada vs Utah
Illinois and Nevada ban AI therapy; Utah only requires disclosure. Compare scope, permitted admin uses, enforcers and penalties across all three.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · free to try
Ask about AI Therapy Laws: Illinois vs Nevada vs Utah
Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.
An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.
Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
Works on this site and inside Claude, Cursor and the AI tools you already use.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do Illinois WOPR Act (HB 1806 / PA 104-0054), Nevada AB 406, Utah HB 452 compare side by side?
The table below compares Illinois WOPR Act (HB 1806 / PA 104-0054), Nevada AB 406, Utah HB 452 across 14 procurement-relevant dimensions, from regulatory model through what a nationwide product has to solve for.
Side-by-side comparison
| Dimension | Illinois WOPR Act (HB 1806 / PA 104-0054) | Nevada AB 406 | Utah HB 452 |
|---|---|---|---|
| Regulatory model | Prohibition, built on the practice-of-a-licensed-profession question. Therapy and psychotherapy may only be provided, advertised or offered when conducted by a licensed professional, and AI is confined to support roles behind that licensed professional. | Prohibition. It is unlawful to offer an AI system programmed to provide services constituting the practice of professional mental or behavioral health care, or to represent that an AI system can provide such care. | Disclosure and data protection. The mental health chatbot stays legal; the statute governs how it identifies itself, what it may do with user input, and how it may advertise. |
| Signed and effective | Signed by Governor JB Pritzker on 4 August 2025 as Public Act 104-0054, effective immediately on signing. Note that several secondary write-ups give 1 August; the IDFPR announcement and the law-firm bulletins that followed it date the signing to 4 August 2025. | Signed by Governor Joe Lombardo on 5 June 2025, effective 1 July 2025. | Signed by Governor Spencer Cox on 25 March 2025, effective 7 May 2025. The earliest of the three. |
| What the AI may never do | Make independent therapeutic decisions; engage directly in therapeutic communication with a client; generate treatment recommendations or plans without review and approval by a licensed professional; detect emotions or mental states. The emotion-detection prohibition is the broadest of the three states and catches sentiment-scoring features that are not framed as therapy at all. | Provide services constituting the practice of professional mental or behavioral health care. An AI system may not be represented as capable of such care, and may not hold itself out using a title such as therapist, psychotherapist, counselor, psychiatrist or doctor. | Nothing, in functional terms. HB 452 imposes no prohibition on what a mental health chatbot may say or do clinically. Its prohibitions are on non-disclosure, on selling or sharing user data, and on advertising practices. |
| Restrictions on licensed professionals | A licensed professional may use AI, but not to make independent therapeutic decisions, to communicate therapeutically with a client, or to produce treatment plans or recommendations that are not reviewed and approved by that professional. | A licensed provider may not use an AI system in connection with care delivered directly to a patient. The restriction attaches to care delivery, not to the provider personally using a chatbot outside professional practice. | None. HB 452 regulates suppliers of mental health chatbots as a consumer-protection matter; it does not regulate the clinical conduct of licensed Utah therapists. |
| Permitted administrative and supplementary uses | Administrative support such as scheduling, billing and insurance processing, and logistical communications carrying no therapeutic advice. Supplementary support such as maintaining records and analysing anonymised data is also permitted under a licensed professional. | Administrative support tasks including scheduling, managing records, analysing operational data, and organising and tracking files and notes. Where AI manages billing or notes from patient sessions, the provider must independently review the output for accuracy. | Not a category the statute uses. A supplier is free to use AI administratively; the obligations that bite are disclosure, data handling and advertising. |
| Consent requirements | Written informed consent is required before an AI tool is used on a recorded or transcribed therapy session, and the consent must describe the specific AI tool and the purpose for which it is being used. | No session-level AI consent requirement in AB 406 itself. Existing Nevada privacy and health-record obligations continue to apply to administrative AI use. | Consent is not the mechanism; disclosure is. The chatbot must tell the user it is AI before access, again after seven days of non-use, and whenever the user asks or prompts about whether AI is being used. Narrow data-sharing exceptions do turn on user consent. |
| Data and advertising restrictions | Not the statute's focus. WOPR governs who may deliver therapy and what a licensed professional may delegate to AI, not the downstream commercial use of what a user disclosed. | Not addressed as a separate regime. Providers using AI administratively must comply with applicable privacy and health-record law. | The core of the statute alongside disclosure. A supplier may not sell or share a user's individually identifiable health information or user input with third parties outside narrow exceptions, may not use user input to target advertising, and must clearly identify any advertisement and disclose sponsorship, business affiliation or promotional agreements. |
| Schools and minors | No dedicated school provision. The general prohibition applies wherever therapy or psychotherapy is offered, including in an education setting. | An express provision. A public school may not use AI to perform the functions and duties of a school counselor, school psychologist or school social worker that relate to pupil mental health, and the Department of Education must develop a policy for AI use by those employees. Administrative uses such as scheduling and transcription remain available. | No dedicated school or minor provision in HB 452, though the disclosure and data rules apply to every Utah user regardless of age. |
| Exemptions and what stays legal | Religious counseling by faith leaders, peer support grounded in lived experience rather than clinical training, and publicly available self-help and educational materials are outside the Act. General wellness apps offering generalised content such as guided meditation or mood tracking, which do not simulate a therapeutic relationship, are not what the statute reaches. | AI systems designed for provider administrative support are expressly preserved. The prohibition attaches to systems programmed to deliver professional mental or behavioral health care and to representations that a system can do so. | The definition itself is the limit. A product only becomes a mental health chatbot when it holds conversations similar to the confidential communications a person would have with a licensed therapist, which leaves general wellness and information tools outside the statute. |
| Who enforces | The Illinois Department of Financial and Professional Regulation, acting after a hearing. | The Division of Public and Behavioral Health, which may investigate and bring actions to recover civil penalties. Licensing boards may discipline separately, and unlicensed practice remains a criminal matter under existing Nevada law. | The Utah Division of Consumer Protection, which handles this as consumer protection rather than professional licensure. |
| Penalty ceiling | Civil penalties of up to 10,000 dollars per violation. | Civil penalties of up to 15,000 dollars per violation, the highest of the three, plus professional discipline for licensees. | Administrative fines of up to 2,500 dollars per violation, plus disgorgement, attorney fees and other remedies. The lowest ceiling of the three, and the only one paired with a safe harbour. |
| Safe harbour | None. Compliance is binary: the conduct is either within the permitted support categories or it is the unlicensed provision of therapy. | None in the statute. The nearest equivalent is the administrative-support carve-out combined with the independent-review requirement on billing and session-note output. | Yes. A supplier that has filed a written policy with the Division of Consumer Protection and demonstrates compliance with it has an affirmative defense. This is the single most consequential structural difference for a product team: Utah offers a documented path to reduced exposure, the other two do not. |
| Statutes amended or created | A new Act, the Wellness and Oversight for Psychological Resources Act, enacted as Public Act 104-0054. | Amendments to three chapters of the Nevada Revised Statutes: NRS 391 for schools, NRS 433 for behavioral health, NRS 629 for healthcare records and provider conduct. | Amendments within the Utah Code carried by HB 452, Artificial Intelligence Amendments, sitting alongside Utah's earlier Artificial Intelligence Policy Act disclosure regime. |
| What a nationwide product has to solve for | Whether the conduct is therapy at all. Honest labelling does not cure an Illinois problem; if the system engages in therapeutic communication or produces a treatment plan without licensed review, disclosure does not help. | The same question, plus representation. Marketing copy claiming an AI system can provide mental health care is independently prohibited even where the product is never used that way. | Product surface and data flows. The disclosure triggers are interface work, and the data and advertising limits are engineering and commercial decisions rather than clinical ones. |
Common questions
Common questions about Illinois WOPR Act (HB 1806 / PA 104-0054) vs Nevada AB 406 vs Utah HB 452
Do these laws ban wellness and meditation apps?
+
No, not as a class. Illinois is the sharpest test because it has the broadest prohibition, and Section 35 of the Wellness and Oversight for Psychological Resources Act expressly excludes three categories that do not purport to offer therapy or psychotherapy: religious counseling by faith leaders, peer support grounded in lived experience rather than clinical training, and publicly available self-help and educational materials. An app that offers generalised content such as guided meditations, breathing exercises or mood tracking, and that does not simulate a therapeutic relationship, is not what the Act reaches. Nevada works the same way from the other direction: its prohibition attaches to systems programmed to provide services constituting the practice of professional mental or behavioral health care, and to representations that a system can provide such care. Utah is narrowest of all, because the obligations only attach once a product meets the definition of a mental health chatbot, meaning it holds interactive conversations similar to the confidential communications a person would have with a licensed therapist. The risk for a wellness product is therefore not the category label it gives itself but the behaviour of the model in a hard conversation. A meditation app whose chatbot starts responding to a disclosure of suicidal ideation with something that looks like clinical assessment has moved across the line in Illinois and Nevada regardless of what the app store listing says.
Does an AI scribe or ambient documentation tool violate these laws?
+
No, and all three states preserve this use, but Illinois and Nevada each attach a condition worth building around. Illinois permits administrative support such as scheduling, billing and insurance processing, and supplementary support such as maintaining records and analysing anonymised data, provided the licensed professional retains clinical responsibility and the AI is not the source of a treatment recommendation or plan that goes unreviewed. Illinois also requires written informed consent before an AI tool is used on a recorded or transcribed session, and that consent must describe the specific tool and its purpose, which is a documentation requirement most ambient scribe deployments do not satisfy by default. Nevada permits administrative support tasks including scheduling, records, operational analysis and managing notes, but where AI manages billing or notes from patient sessions the provider must independently review the output for accuracy, which makes a sign-off step a legal requirement rather than a quality preference. Utah does not regulate this at all, because a documentation tool is not holding a therapeutic conversation with a user and so is not a mental health chatbot. The Illinois emotion-detection prohibition is the one to watch: a scribe that also scores affect, flags sentiment or generates a risk rating from a session recording is doing something Illinois has separately prohibited, even though the transcription itself is permitted.
Which law applies when the chatbot is nationwide?
+
In practice, all of the ones whose residents can reach the product, which is why this group of statutes is harder to comply with than any one of them suggests. Utah applies to Utah users, Nevada frames its prohibition around offering such a system in Nevada, and Illinois bars providing, advertising or otherwise offering therapy or psychotherapy services to the public without a licensed professional conducting them, with advertising specifically named. A national operator that reads only the Utah statute and ships a disclosure banner has not addressed the Illinois or Nevada exposure, because those states are not asking whether the user was misled. They are asking whether the system is doing work reserved to a licensed professional, and an accurate disclosure is not a defence to that. The workable options are geographic segmentation of features, a design that keeps the model demonstrably outside therapeutic communication everywhere, or a licensed-professional-in-the-loop architecture. Each is a real product decision with real cost, and choosing between them is the actual compliance question rather than the drafting of a consent screen. This is also the point at which the group of statutes stops being a legal review item and becomes an architecture item, because two of the three cannot be satisfied by anything that happens in the user interface.
Why does the prohibition and disclosure split matter more than the penalty amounts?
+
Because the two models make incompatible demands on the same product, and the penalty ceilings are the least significant difference between them. Utah at 2,500 dollars per violation, Illinois at 10,000 and Nevada at 15,000 all describe per-violation exposure that scales with user count rather than a fixed cap, so none of the three is cheap at volume. The structural difference is what compliance consists of. Under the disclosure model, compliance is a feature: the chatbot says what it is, the data does not get sold, the advertising is labelled, and Utah even offers an affirmative defense to a supplier that files a written policy with the Division of Consumer Protection and follows it. Under the prohibition model, compliance is a limit on capability: the system is either permitted to do the work or it is not, no amount of transparency changes the answer, and neither Illinois nor Nevada offers a safe harbour to document your way into. A team that treats these three statutes as three intensities of the same rule will build for the most expensive one and still be unlawful in the other two.
How does this connect to NIKOLAI?
+
Through scope, not through mental health. NIKOLAI is CASRAI's own independent frontier-AI-safety dictionary, and the element that applies here is Deployment Surface on the N1 track, Actors, models and scope, which is defined as the product, API or channel through which a model becomes accessible, held deliberately separate from deployment type. These three statutes are a clean illustration of why that separation earns its keep. The same underlying model is lawful behind a licensed clinician in Illinois, lawful as a disclosed consumer chatbot in Utah, and unlawful as a direct-to-user therapy product in Nevada. The legal answer tracks the surface, not the weights. A safety framework that records only that a model is deployed externally cannot express that distinction, and a compliance team reading such a framework cannot tell which of these three obligations it has triggered. Deployment Surface carries the status Proposed in NIKOLAI, and the crosswalk rows on it are shadow mappings, meaning CASRAI's own reading of published material. No lab, evaluator or regulator named in a crosswalk row has endorsed, reviewed or been consulted on it. An organisation changes that only by filing a Mapping Declaration.
What does this mean for IRBs and university research administration?
+
It puts a state-law question upstream of the human-subjects analysis, and that ordering is the part institutions get wrong. An IRB reviewing a digital mental-health intervention study, or a university counselling centre piloting a triage chatbot, is used to asking whether risks are minimised, whether consent is adequate and whether the study design is sound. None of those questions reaches the issue these statutes raise, which is whether the intervention may lawfully be delivered at all in the state where the participants are. A protocol that is approvable in Utah, where a disclosed mental health chatbot is lawful subject to data and advertising limits, may be unlawful to run in Illinois or Nevada, where the same chatbot is offering services reserved to a licensed professional. IRB approval does not cure that, and a convened board has no authority to authorise conduct a state has prohibited. The practical implications are concrete. Multi-site studies need a site-by-site legal screen before the science is reviewed, not after. Recruitment that crosses state lines can pull a lawful protocol into a prohibiting jurisdiction without anyone amending the study. Illinois requires written informed consent describing the specific AI tool and its purpose before AI handles a recorded or transcribed session, which is a consent-document requirement, not a discretionary one. And a campus counselling service piloting a triage bot is squarely in scope in both prohibition states, including the Nevada provision on school counselors, psychologists and social workers where the institution operates a school setting. Research security and sponsored programs offices should also note that a subaward moving a digital mental-health study to a partner institution moves it into that partner's state law.








