State AI Disclosure Laws (AB 3030, TRAIGA, Colorado)
A patient in California opens her portal message about a mildly abnormal lab. It is clear, kind, and perfectly worded, and at the bottom sits a line she has never seen before: "This message was generated with the assistance of artificial intelligence. To speak with a member of your care team, call the number below." She never thinks twice about it. What she does not know is that a single sentence, and the licensed human who may or may not have read her message before it went out, is the difference between a clinic that is complying with state law and one that has just committed a violation. Welcome to the fastest-moving, least-understood corner of clinical AI: the state disclosure laws, where the same AI-drafted message can be perfectly legal in one state, require a disclaimer in another, and demand a documented conversation in a third.
Why a Patchwork, and Why It Matters to You
There is no single national law telling clinicians when they must tell a patient that AI was involved in their care. Instead, states are legislating one at a time, at different speeds, with different triggers, different scopes, and different penalties. The result is a patchwork: a set of overlapping, non-identical rules that depend on where the patient is, what the AI did, and who reviewed the output. For a clinician, a health system that spans state lines, or a telehealth practice that sees patients wherever they happen to live, this is not an abstraction. The disclosure that satisfies one state may be silent on what another requires, and "I did not know that state had a law" is not a defense a regulator finds persuasive.
The honest framing, and the one this lesson insists on, is that you should not try to memorize fifty statutes that are changing under your feet. You should instead learn the shape of the landscape through three representative laws, understand the common logic underneath them, and adopt a default habit that keeps you safe almost everywhere: assume disclosure may be required, and keep a licensed human meaningfully in the loop. Let us take the three that best map the terrain.
Why these three, and not a longer tour? Because between them they cover the two axes along which nearly every state law varies. The first axis is what the AI did: some laws (California) fire on AI that generates a patient communication, while others (Texas) fire on AI that shapes a diagnosis or treatment decision. The second axis is how the state relates its new AI rules to existing healthcare regulation: some bolt on fresh duties, while others (Colorado) carve healthcare partly out because HIPAA already governs it. Learn to locate any new law you encounter on those two axes, and you can read it quickly without having memorized it in advance. The three examples are less a list to recall than a set of coordinates for reading whatever your state does next.
Keep one framing in mind before we go further, because it governs everything below. Every statistic, every penalty figure, every effective date in this lesson is a number to verify at the point of use, not to repeat blindly from memory or from a slide. Legislatures amend, regulators issue rules that shift the details, and enforcement guidance reinterprets phrases that looked settled. The durable skill is not the memorized figure; it is knowing which questions to ask of any given law and where the safe default sits when the answer is uncertain. Treat the specifics here as a map of the terrain, drawn accurately as of this writing, and always confirm the current text before you rely on it in practice.
Reading Any New Law in Three Questions
When a new state law lands on your desk, you do not need to become its scholar overnight. You need three answers. First, what triggers it: a generated communication, an AI-shaped diagnosis or treatment decision, or some broader category of automated decision-making. Second, what it demands once triggered: a disclaimer, a plain-language disclosure, a documented conversation, or general notice. Third, how it treats healthcare and human review: does it exempt provider-reviewed output, does it carve out HIPAA-covered entities, and does it name an enforcer with teeth. Answer those three and you have read the law well enough to act safely, even if you have not memorized a single section number. The three statutes below are simply worked examples of those three questions.
| Law | Trigger | Effective date | Enforcement | Key exemption |
|---|---|---|---|---|
| California AB 3030 | Generative AI produces a written or verbal patient clinical communication | January 1, 2025 | State licensing and enforcement authorities (regulatory, not a private suit under the AI-specific rule) | Communication read and reviewed by a licensed or certified provider before it reaches the patient |
| Texas TRAIGA (HB 149) | AI used in a patient's diagnosis or treatment | January 1, 2026 | Texas Attorney General; civil penalties roughly $10,000 to $200,000 per violation; no private right of action | No blanket healthcare carve-out, but plain-language disclosure and human accountability are the safe posture |
| Colorado SB 26-189 | Covered automated decision-making technology (ADMT), general AI duties | January 1, 2027 (signed May 14, 2026; replaced SB24-205) | State enforcement under the general framework | HIPAA-covered entities largely exempt from the heaviest developer and deployer duties, but still owe patient notice and specified disclosures |
The figures in that table, especially the penalty range and the dates, are exactly the sort of thing to verify rather than repeat blindly. They are drawn to be accurate as of this writing, but a table is a snapshot of a moving target.
California AB 3030: The Disclaimer on Generative Communications
California's AB 3030 took effect on January 1, 2025, and it is the cleanest example of a targeted, narrow disclosure rule. Its trigger is specific: it applies when a health facility, clinic, or physician's office uses generative AI to produce written or verbal patient clinical communications. Think of the AI-drafted portal reply, the automated message about a result, the generated patient-education text about a condition. When generative AI produces that kind of clinical communication, AB 3030 requires two things: a prominent disclaimer telling the patient the communication was generated by AI, and instructions for how to contact a human, a real clinician or staff member.
Now the crucial carve-out, because it is the part clinicians most need to understand and the part that connects this law to everything else in the program. AB 3030 contains a significant exemption: if the AI-generated communication is read and reviewed by a licensed or certified human health care provider before it goes to the patient, the disclaimer requirement does not apply. Sit with what that means. The law is essentially offering a choice: either put a machine-generated message in front of the patient with a clear label and a path to a human, or have a licensed human actually review it first, in which case it becomes, in effect, that provider's communication and the special AI disclaimer is not required. The exemption is not a loophole; it is the whole philosophy of safe AI use expressed as law. A human in the loop transforms the nature of the communication.
Notice what California is really rewarding: a licensed human reviewing the output. The law offers relief from the disclaimer precisely when a clinician has done the thing this entire program tells you to do anyway.
Provider-Reviewed Versus Machine-Only: A Worked Contrast
Put two nearly identical messages side by side to see where the line falls. In the first, a generative tool drafts a portal reply about a mildly elevated cholesterol result, and the clinic's system sends it automatically overnight, no human ever having opened it. That is a machine-only clinical communication, and under AB 3030 it needs the prominent disclaimer and the instructions to reach a human, because no licensed person stood behind it. In the second, the same draft lands in a nurse practitioner's inbox at 8 a.m.; she reads it, tightens one sentence about follow-up timing, confirms the recommendation matches the chart, and sends it under her name. That message is now, in substance, her communication. The AB 3030 disclaimer requirement does not apply, because the human-review exemption was earned. The words that reached the patient may be ninety percent identical; the legal status is not, and the difference is entirely the licensed human's meaningful review.
How is the exemption earned, precisely, since a compliance officer will ask? Not by a rubber stamp and not by a workflow that merely routes the message past a screen. The exemption contemplates a licensed or certified provider actually reading and reviewing the communication before it goes to the patient. A clinician who clicks approve on a queue of two hundred AI drafts without opening them has not reviewed anything, and a regulator asking what review occurred will not be satisfied by a log that shows only a bulk approval. The safe reading is that review means engagement: the provider read this message, for this patient, and takes responsibility for its content. That is more work than a disclaimer, which is exactly why the disclaimer remains available as the alternative for high-volume, genuinely machine-generated traffic.
One more nuance clinicians miss. The exemption is about the disclaimer specifically. Even when a licensed human has reviewed a message and the AB 3030 disclaimer is therefore not required, nothing stops a clinic from keeping a human-contact path on the message anyway, and there are good reasons to. It costs nothing, it builds patient trust, and it keeps the clinic in a consistent posture across states whose rules differ. The exemption tells you what you may omit, not what you must strip away.
Texas TRAIGA (HB 149): Disclosure of AI in Diagnosis and Treatment
Texas took a different angle. The Texas Responsible Artificial Intelligence Governance Act, known as TRAIGA and enacted as HB 149, took effect January 1, 2026. Where California zeroed in on generated communications, TRAIGA reaches into the clinical encounter itself. Under TRAIGA, health care providers must disclose to a patient, or the patient's representative, when AI is used in the patient's diagnosis or treatment. The disclosure must be clear and conspicuous, in plain language, and free of dark patterns, meaning it cannot be designed to manipulate, bury, or trick the patient out of understanding what is happening.
The enforcement structure is worth knowing precisely, because it tells you how serious the state is. TRAIGA is enforced by the Texas Attorney General, and it carries civil penalties that, depending on the nature and curability of the violation, can range from roughly $10,000 to $200,000 per violation. Importantly, there is no private right of action: an individual patient cannot sue you directly under TRAIGA; enforcement runs through the Attorney General. That does not make it low-stakes. Per-violation penalties in that range, applied across many patients, are exactly the kind of exposure that gets an organization's compliance and legal teams focused, and the plain-language, no-dark-patterns standard means a technically-present-but-deliberately-obscure disclosure will not save you.
The mental model to carry from Texas is that its trigger is broader and more clinical than California's. California is about a generated communication; Texas is about AI used in diagnosis or treatment, which can reach a wider range of tools, including the predictive and decision-support systems we studied under HTI-1. A clinician working in Texas should assume that if an AI tool materially shaped a diagnostic or treatment decision, the patient is owed a clear, honest, plain-language heads-up.
When the Attorney General Opens an Inquiry
Make the enforcement structure concrete. Suppose a Texas clinic used an AI decision-support tool that materially shaped a treatment recommendation, the patient later complained, and the Texas Attorney General's office opened an inquiry. What standard governs, and what does the clinic want to be able to show? The standard is not whether the AI was right or wrong; it is whether the patient received a clear, conspicuous, plain-language disclosure that AI was used in their diagnosis or treatment, free of dark patterns, and whether a licensed human remained accountable for the decision. The clinic's strongest position is documentation: a record that the disclosure was made in language the patient could actually understand, and that a named provider, not the tool, owned the clinical call. Because there is no private right of action under TRAIGA, the patient is not suing the clinic directly under this statute; the exposure runs through the Attorney General, and the remedy is civil penalties in the range of roughly $10,000 to $200,000 per violation, calibrated to the nature and curability of the violation. That penalty figure is one to verify against the current statute rather than repeat blindly, but the shape of the exposure, per-violation civil penalties assessed by the state, is the durable point.
Notice how the absence of a private right of action cuts both ways. It means an individual patient cannot turn a missed disclosure into a personal lawsuit under TRAIGA, which sounds reassuring. But per-violation penalties applied across a population of patients, assessed by a well-resourced state enforcer, are precisely the kind of aggregate exposure that focuses an organization's legal and compliance teams. A single missed disclosure is a number; a systematic failure to disclose across thousands of encounters is a number multiplied, and that multiplication is what makes the plain-language standard something an organization operationalizes rather than treats as a footnote.
It is worth dwelling on why the "plain language, no dark patterns" standard is not just legal boilerplate but a genuine clinical instruction. A disclosure buried in the ninth paragraph of a consent form, written in language a patient cannot parse, or designed with a pre-checked box and a confusing double negative, technically mentions AI while ensuring the patient never actually understands it. The law explicitly forecloses that move. The disclosure has to be the kind a real person would notice and comprehend, which is the same standard good clinicians already hold themselves to when they explain a diagnosis. In that sense TRAIGA is not asking you to become a compliance technician; it is asking you to tell the patient the truth about their care in a way they can follow, which is what informed, respectful practice looked like long before AI existed. The novelty is only that AI's involvement is now part of the truth you owe them.
Colorado: The Moving Target, and a Lesson in Humility
Colorado is the case that teaches you why memorization is the wrong strategy. Colorado passed an early, broad AI law known as SB24-205, and for a while it was the reference point everyone cited. Then it changed. SB24-205 was replaced by SB 26-189, signed May 14, 2026, with an effective date of January 1, 2027. If you had spent 2025 memorizing the details of the original statute, much of that effort would now be pointing at a law that no longer governs. That is the single most important thing Colorado teaches: these laws move, and building your practice on the exact text of one version is fragile.
What the current Colorado framework does, in broad strokes, is important for a specific reason that recurs across health AI law. Under the revised approach, HIPAA-covered entities are largely exempted from the heavier developer and deployer duties that the law imposes on AI systems generally, but they are still expected to provide patients general notice about the use of advanced technologies, often discussed as automated decision-making technology (ADMT), and to make specified disclosures. In plain terms: much of healthcare gets some relief from the most burdensome parts of the general AI law precisely because it is already regulated under HIPAA, but the expectation of patient notice and disclosure does not vanish. You are not off the hook; you are on a different, healthcare-shaped hook.
A HIPAA-Covered Clinic Weighs What It Still Owes
Walk through the question a HIPAA-covered clinic in Colorado actually asks: given that we are largely exempt from the heaviest developer and deployer duties, what do we still owe patients? The tempting misread is "we are a covered entity, so the AI law does not touch us." That is too strong. The revised framework relieves HIPAA-covered entities from the most burdensome obligations that fall on AI developers and deployers generally, precisely because HIPAA already imposes a regime, but it does not vaporize the patient-facing core. The clinic is still expected to provide general notice about the use of advanced technologies, often framed as automated decision-making technology, and to make specified disclosures when covered ADMT is involved in decisions about patients. In plain terms, the clinic trades the heavy compliance machinery of a general AI deployer for a lighter, healthcare-shaped set of notice and disclosure duties. It is relief, not immunity.
The reason this pattern matters beyond Colorado is that it repeats. A state passes a sweeping AI law; healthcare, already governed by HIPAA, argues that a second full regime stacked on top is duplicative; the law is amended to carve covered entities partly out while preserving patient notice. So the recurring question for any HIPAA-covered clinic facing a new state AI law is not "are we exempt" but "which parts are we relieved of, and which patient-facing duties survive the carve-out." Almost always, some form of patient notice survives, because that is the piece legislatures are least willing to give up. Anchor to that surviving core and you will read the next state's healthcare carve-out correctly on the first pass.
Do not overstate any of this. Colorado's rules carry a future effective date, they were recently rewritten, and the details of how the exemptions and notice requirements apply to a given practice are exactly the kind of thing that gets refined by regulation and legal guidance. The responsible clinician's takeaway is not a memorized rule but a posture: the law here is evolving, HIPAA status matters, patient notice about advanced technologies is part of the picture, and you confirm the current requirement rather than trusting last year's summary.
There is a broader pattern in the Colorado story that repeats across the country and is worth naming directly. A state passes an ambitious, general-purpose AI law; healthcare, already heavily regulated under HIPAA, argues that stacking a second regime on top is duplicative; and the law gets amended to carve healthcare partly out while preserving a core of patient-facing notice. That negotiation, between broad AI governance and existing healthcare regulation, is playing out in legislature after legislature, and it means the precise contours of any given state's rule are a moving target you should expect to change. What tends to survive every version of the negotiation, and this is the durable signal, is the expectation that patients be told, in some form, when advanced technology is being used in decisions about them. If you anchor to that surviving core rather than to the shifting details, you will rarely be caught flat-footed by an amendment.
The Common Logic and the One Safe Default
Step back from the three laws and the shared logic becomes visible. Every one of them is circling the same instinct: when AI meaningfully touches a patient's care or communication, the patient has an interest in knowing, and a licensed human should remain accountable. California expresses it through a disclaimer with a human-review exemption; Texas through a clear-and-conspicuous disclosure of AI in diagnosis and treatment; Colorado through evolving notice requirements shaped by HIPAA status. The triggers differ, the penalties differ, the mechanics differ, but the moral center is identical, and it is the same center as the rest of this program: transparency toward the patient and a human in the loop.
The triggers differ, the penalties differ, the enforcers differ. What survives every version, in every state, is the same instruction this program has repeated from the start: tell the patient the truth about their care, and keep a licensed human accountable for it.
That shared center is what makes a single safe default possible, and it is the practical heart of this lesson. You cannot reliably track every state's current statute in real time at the point of care. What you can do is adopt a habit that keeps you safe almost everywhere: assume disclosure may be required, and keep a licensed human meaningfully in the loop. If an AI drafts a patient communication, have a licensed person review it (which, not coincidentally, is exactly what California's exemption rewards) or disclose the AI involvement plainly. If an AI shaped a diagnosis or treatment, be ready to tell the patient in plain language (which is exactly what Texas requires). If you are unsure what your state currently demands, default to more transparency and more human review, not less, because the direction every one of these laws points is toward disclosure and accountability, never away from it.
A Worked Example: One Message, Three States
Watch a single fact pattern travel across state lines. A telehealth clinician, licensed in California, Texas, and Colorado, uses a generative tool to draft a portal message to a patient explaining a slightly abnormal thyroid result and next steps. The draft is excellent. She is one person, at one desk, writing what feels like one message. But the patient's location, not hers, changes the obligations, and that single fact is where clinicians most often go wrong. They assume their own state's rule travels with them; in a patchwork keyed to the patient, it usually does not.
If the patient is in California, AB 3030 is in play because this is a generative AI clinical communication. The clinician has a clean choice: send it with a prominent AI disclaimer and instructions to reach a human, or personally read and review the draft first, in which case the disclaimer is not required and the message is effectively hers. She reads it, corrects one phrase, and sends it under her name. Compliant, and safer, because a licensed human actually verified the content.
If the patient is in Texas, the sharper question is whether AI was used in the patient's diagnosis or treatment, and whether the tool's role rises to that. If AI materially shaped the clinical guidance being communicated, TRAIGA points toward a clear, conspicuous, plain-language disclosure to the patient, with no manipulative design. The clinician makes sure the patient is told, honestly and understandably, that AI assisted, and keeps her own review as the accountable act.
If the patient is in Colorado, the clinician recognizes she is on shifting ground: a recently rewritten law with a future effective date, a likely HIPAA-related exemption from the heaviest duties, but a surviving expectation of patient notice about advanced technologies. Rather than guess, she confirms her organization's current Colorado guidance, and in the meantime she does the thing that is safe in all three states: a licensed human reviewed the message, and the patient can reach a human. Notice the punch line. In all three states, the single habit of human review plus honest, plain-language transparency either satisfies the law outright or puts her in the safest available position while the specifics are confirmed. She did not need to be a lawyer. She needed a default.
Key Takeaways
- There is no single national AI-disclosure law for clinicians; states are legislating one at a time, producing an evolving patchwork where the same AI-drafted message can be legal in one state, require a disclaimer in another, and demand a documented disclosure in a third.
- California AB 3030 (in force January 1, 2025) requires a prominent disclaimer and instructions to contact a human when generative AI produces a patient clinical communication, but exempts communications that a licensed or certified human provider reads and reviews first.
- The AB 3030 exemption is the program's philosophy as law: a human in the loop transforms the communication and relieves the disclaimer requirement precisely when a clinician has verified the output.
- Texas TRAIGA / HB 149 (effective January 1, 2026) requires clear, conspicuous, plain-language disclosure, with no dark patterns, when AI is used in a patient's diagnosis or treatment, a broader and more clinical trigger than California's.
- TRAIGA is enforced by the Texas Attorney General with civil penalties from roughly $10,000 to $200,000 per violation and no private right of action, so patients cannot sue directly, but organizational exposure is real.
- Colorado teaches humility: SB24-205 was replaced by SB 26-189 (signed May 14, 2026, effective January 1, 2027), so memorizing one version is fragile; HIPAA-covered entities are largely exempt from the heaviest duties but still owe patients notice about advanced technologies (ADMT) and specified disclosures.
- Do not overstate any single law; the details shift with regulation and guidance, and the responsible posture is to confirm the current requirement rather than trust last year's summary.
- The one safe default that works almost everywhere: assume disclosure may be required, and keep a licensed human meaningfully in the loop, defaulting to more transparency and more human review, never less.
Skill.re