AI for Mental & Behavioral Health Clinicians
Strategic · M16 · lesson 16 of 23 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Multi-State Practice Compliance: IL WOPR, NV AB 406, NY, Colorado, California
📖
now learning

Multi-State Practice Compliance: IL WOPR, NV AB 406, NY, Colorado, California

15 min

Jordan's group practice in Sacramento just hired a remote LPC who lives in Reno under the Counseling Compact, a PSYPACT psychologist who sees a Chicago client every Tuesday, and a teletherapy LCSW with a snowbird caseload split between Denver and Brooklyn. Every one of those sessions runs through the same AI scribe, under the same consent addendum, written for California. That single form is now legally wrong in at least three jurisdictions, and one of them, Illinois, carries enforcement teeth that made national news in 2025. By the end of this lesson you will be able to build a multi-state AI compliance matrix that identifies which state's most-restrictive rule controls each clinical relationship, track the Colorado dual-track situation without guessing, and produce the one-page artifact your compliance officer, your malpractice carrier, and your compact-credentialed clinicians all need on the wall.

Why the States Stopped Waiting for Washington

There is no federal AI-in-therapy statute. What exists instead, as of mid-2026, is a patchwork of state laws that each regulate a different slice of the same activity, written by different legislatures with different fears in mind. Illinois passed the Wellness and Oversight for Psychological Resources Act, the WOPR Act, in 2025, with enforcement guidance following in 2026. Nevada passed AB 406 in 2025. New York passed its AI companion safeguards law in 2025. Colorado passed the original Colorado AI Act, SB 24-205, then postponed its effective date to June 30, 2026, and then in May 2026 passed SB 26-189 to repeal and replace it. California has no single AI-in-therapy statute, but the BBS regulates the clinicians, and the state's general consumer-protection and privacy regime sits underneath everything an AI vendor does there.

The reason this matters to a practice owner and not only to a policy wonk is jurisdiction. When your clinician sits in Sacramento and the client sits in Chicago, Illinois law governs that clinical relationship, because the client's state is where the service is delivered. The interstate compacts that make multi-state practice legal, PSYPACT for psychologists, the Counseling Compact for LPCs and LPCCs, and the Social Work Compact for LCSWs, all carry the same foundational rule: the practitioner is subject to the laws and regulations of the state where the client is located at the time of service. The compact gives you the privilege to practice across the line. It does not give you the privilege to ignore the other state's AI law once you cross it.

Think of multi-state compliance as a water system. Compliance, like water, finds its level: the most restrictive rule that touches any client relationship becomes the level your whole policy has to hold. You do not get to maintain a California water level for your Illinois clients. The practical consequence is the most-restrictive-rule doctrine this lesson builds toward: identify every state your clients sit in, identify the strictest applicable rule per AI use case, and let that rule set the water line.

Illinois WOPR: The Template the Other States Are Copying

The Illinois WOPR Act, the Wellness and Oversight for Psychological Resources Act of 2025, is the law that defined the perimeter everyone else now navigates. Its core move is a prohibition: AI may not provide therapy or psychotherapy services to the public. The 2026 enforcement guidance clarified the contour that matters for your practice: there is a line between AI delivering therapeutic services, which is prohibited, and AI performing administrative and documentation support under a licensed clinician's direction, which is not. An AI scribe like Mentalyc or Upheal drafting a progress note from a session the clinician conducted sits on the permitted side. A chatbot performing the therapeutic interaction itself, the empathic dialogue, the intervention, the "support" conversation, sits on the prohibited side, regardless of what the vendor's marketing calls it.

For the multi-state practice, WOPR creates three operational obligations the moment one client sits in Illinois. First, audit every tool in the stack against the therapy-versus-documentation line; any client-facing conversational feature, a "check-in companion," an "AI coach" embedded in the client portal, has to be off for Illinois clients, and as a practical matter should be off for everyone, because feature-flagging by client state is a fragile control. Second, your consent addendum must describe AI use accurately as documentation support, never in language that implies AI participates in care. Third, your clinician training must cover the line itself, because the clinician who tells a client "the AI helps me with your treatment" has just characterized the tool in the way WOPR prohibits.

The deeper lesson WOPR teaches is that legislatures are not regulating your scribe; they are regulating the Character.AI and Replika category, and your practice gets caught in the definitional blast radius. The practices that survive the patchwork make the distinction airtight in their own documentation: AI structures, transcribes, and formats after the clinician's clinical work; it never performs the clinical work.

Nevada AB 406, the New York Companion Law, and the California Baseline

Nevada AB 406, passed in 2025, prohibits AI from delivering behavioral healthcare in Nevada. Its scope is functionally parallel to WOPR's: the prohibited act is AI providing the care itself; the permitted territory is AI supporting the licensed human who provides it. For Jordan's Reno-based LPC, this means the same audit WOPR requires: every tool touching a Nevada client must sit unambiguously on the documentation-and-administration side of the line, and the consent language must say so. Nevada and Illinois together form the prohibition pole of the patchwork.

New York's AI companion safeguards law, also 2025, regulates from a different angle. Rather than prohibiting AI behavioral healthcare delivery outright in the WOPR style, it imposes safeguard obligations on AI companion products, the systems designed to simulate ongoing human-like relationships. For a clinical practice, the New York law matters in two ways. If any tool in your stack has a client-facing conversational component, you must evaluate whether it falls within the companion category and triggers safeguard duties. And if your Brooklyn clients ask, as they increasingly do, whether your AI is "one of those companion apps," your consent addendum needs a clean answer: no, the AI in this practice drafts documentation under my review and signature; it does not interact with you, and it is not a companion product.

California, where Jordan's practice and its BBS-licensed clinicians actually sit, has no single AI-therapy statute as of this writing, but do not mistake that for permissiveness. The BBS regulates the licensee, and every existing obligation, informed consent, confidentiality, competence, supervision of associates, applies with full force to AI-assisted work. The BBS does not need an AI statute to discipline a clinician who let an unverified AI note misstate a session or who recorded clients without consent. California is the baseline layer of the matrix: the home-state board rules that follow your license everywhere, underneath whatever the client's state adds on top.

The compact gives you the privilege to practice across the state line. It does not give you the privilege to leave the other state's AI law on your side of it.

Colorado: Reading a Dual-Track Regime Without Guessing

Colorado is the hardest cell in the matrix because, as of May 2026, it is two regimes at once, and your compliance plan has to hold both. Track one is the original Colorado AI Act, SB 24-205, the broad algorithmic-discrimination framework whose effective date was postponed to June 30, 2026. Track two is SB 26-189, the "ADMT bill," which the Colorado legislature passed in May 2026 on a bipartisan 34-1 Senate and 57-6 House vote, to repeal and replace SB 24-205 with a narrower automated-decision-making framework. SB 26-189's replacement framework takes effect January 1, 2027 if signed by Governor Polis, and the Governor has stated he will sign it.

What does a practice owner with Denver clients actually do with that? Plan for both. For the remainder of 2026, treat the postponed June 30, 2026 SB 24-205 framework as the live risk if it operates in any residual form during the transition, which means documenting your AI tools' purposes and your human-oversight controls in a form that could answer a broad AI-accountability inquiry. For 2027 onward, plan for the SB 26-189 ADMT framework, which centers on automated decision-making: the question shifts from "do you use AI" to "does any AI system make or substantially influence a consequential decision about a person." Your honest answer, if you run the rollout this program teaches, is no: every clinical decision, every risk determination, every note is made or verified and signed by a licensed clinician. The ADMT framing actually rewards the human-in-the-loop architecture you should already have.

Then watch the third Colorado thread separately: the mental-health-specific AI bills under consideration in the same session, HB 26-1139 and HB 26-1195 where applicable. These sit alongside the general-purpose AI law and may impose mental-health-specific obligations, notice requirements, scribe-consent requirements, or AI-therapy prohibitions in the WOPR style, independent of whatever happens to SB 26-189. The discipline here is the one this whole lesson teaches: never collapse "Colorado law" into one citation. Your matrix carries three Colorado rows, SB 24-205 postponed to June 30, 2026, SB 26-189 effective January 1, 2027 if signed, and the pending HB 26-1139 / HB 26-1195 watch items, each with its own status, its own review date, and its own named owner.

Compacts, Client Location, and the Most-Restrictive-Rule Analysis

Now assemble the logic. Step one: inventory where your clients are, not where your clinicians are. The compacts, PSYPACT for psychology, the Counseling Compact for professional counselors, the Social Work Compact for social workers, all hinge jurisdiction on the client's location at the time of service. A psychologist practicing under PSYPACT into Illinois is practicing under Illinois law for that hour, including the WOPR Act. A Counseling Compact LPC seeing a Nevada client is inside AB 406's scope for that session. Snowbird clients are the trap: the Brooklyn client who winters in Denver moves your matrix row twice a year, and your intake and telehealth workflows need to capture current physical location at every session, which most EHR telehealth checklists already prompt for emergency purposes; the same field now does compliance duty.

Step two: for each AI use case, identify the strictest applicable rule across all client states. Documentation scribing under clinician review is permitted everywhere in the current patchwork, provided consent and characterization are right. Client-facing conversational AI is prohibited or heavily safeguarded in Illinois, Nevada, and New York respectively, so the most-restrictive rule says it is off, period. AI involvement in anything that could be framed as a consequential automated decision draws the Colorado ADMT lens, so your policy states that no AI system makes or substantially influences any clinical or coverage-relevant decision, and your workflow documents the clinician verification that makes the statement true.

Step three: decide between a segmented policy, different rules per client state, or a unified policy at the highest water line. For a practice under roughly forty clinicians, the unified policy nearly always wins. Per-state segmentation requires per-client feature flags, per-state consent versions, and location verification feeding tool behavior, an apparatus that fails quietly the first week someone is on vacation. The unified policy costs nothing clinically, because the things the strict states prohibit are things no defensible practice should be doing anyway. The strictest state is, in effect, writing your best-practice policy for free.

What Does Not Move: The Obligations That Travel With Your License

While the AI patchwork shifts under your feet, three layers of obligation stay fixed, and the matrix should show them as constants so nobody mistakes regulatory churn for a holiday. First, the home-board layer: the California BBS, and its analogues for your compact clinicians, hold the license regardless of where the client sits. Informed consent for AI use, verification before signature, supervision duties for AMFTs, APCCs, and ASWs, none of that is suspended by a compact privilege. Second, the HIPAA layer: the BAA, the subprocessor map, the breach-notification clock, all federal, all uniform across states, all covered elsewhere in this program and assumed here.

Third, the parity layer, which deserves a precision note because it is the one place practices over-cite stale federal law. The MHPAEA statutory parity rights persist, but as of 2026 the federal Departments have signaled reduced enforcement of significant portions of the 2024 MHPAEA final rule on NQTLs, with a May 2025 non-enforcement statement and a March 2026 court-filing disclosure that replacement regulations are coming. State parity laws, New York's Timothy's Law, the Illinois parity statute, California SB 855 enforced through the DMHC, remain fully enforceable and often exceed the federal floor. A multi-state matrix that cites the 2024 federal final rule as settled enforcement is a matrix that embarrasses you in a payer dispute; the row should read "MHPAEA statutory rights persist; rule-specific framing under quarterly review; lead with the state parity statute for the client's state."

The constant beneath all of it is the cardinal rule of this program: the clinician signs the note, and the signature is a legal attestation, not a formatting step. No state in the patchwork, strict or permissive, changes that. Illinois, Nevada, New York, and Colorado are all, in their different vocabularies, legislating the same intuition: a human professional, not a model, is responsible for care. Your matrix is just that intuition written down with citations.

Maintaining the Matrix: Review Cadence and Trigger Events

A compliance matrix built in June 2026 and never touched again is a liability with a date stamp. Colorado alone guarantees churn: a June 30, 2026 effective date on the postponed SB 24-205 framework, a signature watch on SB 26-189, a January 1, 2027 replacement effective date, and two pending mental-health-specific bills. So the matrix needs a maintenance protocol, and this is where AI earns its keep on the administrative side. A monthly AI-assisted legislative scan, prompting a capable model to summarize status changes for the named statute list, WOPR enforcement guidance, NV AB 406, the NY companion law, the four Colorado threads, and the three compacts, gives your compliance officer a draft digest in minutes. The hard limit is the program's standing one: AI drafts the digest; a human verifies every status against the primary source before any cell changes, because models hallucinate bill numbers and effective dates with complete confidence.

Build trigger events into the protocol alongside the calendar. A new hire whose compact privileges add a state: matrix review before their first client. A client relocation disclosed at session: matrix check before the next session. A vendor shipping a client-facing feature in a product update: immediate review against the WOPR and AB 406 prohibition line, because vendors ship companion-adjacent features without asking whether your roster includes Chicago. A carrier renewal questionnaire, the kind CPH & Associates now sends, asking about AI use: the matrix answers it in one page.

Assign every row an owner by name. "Compliance" owns nothing; Jordan's compliance officer owning the Colorado rows with a review date of the first of each month is a control. The matrix without named owners and dates is a poster.

The Applied Problem: Build the Multi-State AI Compliance Matrix

Your artifact is the Multi-State AI Compliance Matrix, a one-page table your practice can defend to a board, a carrier, and a compact commission. Start by pulling three inputs: the roster of states where any client has sat for a session in the last twelve months, drawn from your telehealth location-verification field; the roster of clinician licenses and compact privileges, PSYPACT, Counseling Compact, Social Work Compact; and the inventory of every AI tool in the stack with its function classified as documentation support, administrative, or client-facing.

Then draft with AI, deliberately. A working prompt: "Build a compliance matrix table with one row per statute and columns for: jurisdiction, statute citation, what it prohibits or requires, effective date and current status as of June 2026, which of our AI use cases it touches, the most-restrictive-rule consequence for our policy, named owner, and next review date. Statutes to include: Illinois WOPR Act (2025, with 2026 enforcement guidance), Nevada AB 406 (2025), New York AI companion safeguards law (2025), Colorado SB 24-205 (postponed effective date June 30, 2026), Colorado SB 26-189 (passed May 2026, repeal-and-replace ADMT framework, effective January 1, 2027 if signed by Governor Polis), Colorado HB 26-1139 and HB 26-1195 (pending, mental-health-specific, watch items), California BBS licensee obligations, the three compacts' client-location jurisdiction rule, and a parity row noting MHPAEA statutory rights with the 2025-2026 federal non-enforcement posture and the enforceable state parity laws (NY Timothy's Law, IL parity statute, CA SB 855 / DMHC). Mark every cell you are not certain of with [VERIFY]."

The verification pass is the artifact's actual value. Check every citation, every effective date, and every status against the primary source or your counsel's memo, not against the model's memory. Confirm the Colorado rows carry all three threads separately. Confirm the matrix states the unified-policy decision explicitly: this practice operates at the most restrictive rule across all client states, no client-facing conversational AI, no AI-delivered therapeutic services, all AI documentation reviewed and signed by the responsible clinician. Confirm every row has a human owner and a review date no more than ninety days out, monthly for the Colorado rows through January 2027.

Done looks like this: one page, every statute cited exactly, every [VERIFY] flag resolved by a human against a primary source, the most-restrictive-rule consequence stated in plain operational language per row, and a footer line your carrier will love: "No AI system in this practice delivers therapy, interacts with clients, or makes clinical decisions; all AI output is verified and signed by a licensed clinician." Circulate it at the next all-clinician meeting, attach it to the supervision agreements of every compact-credentialed clinician, and calendar the first monthly review before you file it.

Key Takeaways

  • There is no federal AI-in-therapy law; the controlling regime is a state patchwork, and under PSYPACT, the Counseling Compact, and the Social Work Compact, the client's location at the time of service determines which state's law governs the session. The compact grants the privilege to practice across the line, never an exemption from the destination state's AI rules.
  • The Illinois WOPR Act (2025, with 2026 enforcement guidance) and Nevada AB 406 (2025) prohibit AI from providing therapy or behavioral healthcare delivery, while permitting documentation and administrative support under a licensed clinician's direction. Your tools, consent language, and training must keep every AI use unambiguously on the documentation side of that line.
  • New York's AI companion safeguards law (2025) regulates companion-style conversational products rather than prohibiting delivery outright; any client-facing conversational feature in your stack must be evaluated against it, and the safest unified policy is to disable client-facing conversational AI entirely.
  • Colorado is a dual-track regime: the original Colorado AI Act, SB 24-205, postponed to a June 30, 2026 effective date, and SB 26-189, passed in May 2026 by 34-1 and 57-6 votes to repeal and replace it with a narrower automated-decision-making framework effective January 1, 2027 if signed by Governor Polis. Track HB 26-1139 and HB 26-1195 separately as pending mental-health-specific bills; never collapse Colorado into a single citation.
  • The most-restrictive-rule doctrine is the operating logic: identify the strictest applicable rule per AI use case across every client state, and for practices under roughly forty clinicians, run one unified policy at that water line rather than fragile per-state segmentation.
  • Home-board obligations (CA BBS and analogues), HIPAA and the BAA, and the cardinal rule that the clinician's signature is a legal attestation travel with the license everywhere and never move with the patchwork. The parity row must reflect the 2025-2026 MHPAEA federal non-enforcement posture while leading with enforceable state parity laws such as NY Timothy's Law, the IL parity statute, and CA SB 855.
  • The matrix is a living control, not a poster: monthly AI-assisted legislative scans with human verification of every status against primary sources, trigger-event reviews for new hires, client relocations, and vendor feature changes, and a named owner with a review date on every row.