Disclosure and the AB 3030 and TRAIGA Habit
A practice manager in a multi-state group sits with a spreadsheet of the AI tools now touching patient communication: an inbox assistant in the California clinics, an ambient scribe drafting after-visit summaries in the Texas offices, a translation feature everywhere, a chatbot on the website. Her question is not "are these legal," it is the harder one: "in which of these does a patient have to be told an AI was involved, and how, and what happens if we get it wrong." The honest answer in 2026 is that the rules differ by state, by tool, and by whether a human reviewed the output, and they are still changing. Rather than memorize a patchwork that will look different next year, this lesson teaches the durable move: build disclosure and a human-contact path into every AI-touched patient communication by default, so that you are covered no matter which law applies, and so that when you are unsure, you have already done the safe thing.
Two Laws, Two Shapes, One Instinct
Two state laws anchor the current landscape, and they are shaped differently enough to be worth learning as a contrast, because between them they cover most of what disclosure law is trying to do. California's AB 3030 targets the communication: when generative AI writes to a patient, the patient must be told, unless a licensed human reviewed it. Texas's TRAIGA targets the clinical use: when AI is used in a patient's diagnosis or treatment, the patient must be told, full stop. One law is about who wrote the message; the other is about whether AI shaped the care. Learn both, and you see the two axes along which disclosure obligations fall: the communication axis and the clinical-decision axis.
AB 3030: The Communication Rule
California AB 3030 has been in force since January 1, 2025. It provides that when a health facility, clinic, or physician's office uses generative AI to generate written or verbal patient communications about a patient's clinical information, that communication must carry a prominent disclaimer that it was AI-generated and clear instructions on how the patient can contact a human, such as a staff member or provider. The pivotal exemption, the one that defines safe practice, is that the requirement does not apply when a licensed or certified health care provider reads and reviews the AI-generated communication before it goes to the patient. In other words, human review is the safe harbor: review the message and take responsibility for it, and it is your communication, not the machine's, and the disclaimer requirement falls away.
TRAIGA: The Clinical-Use Rule
Texas's Responsible Artificial Intelligence Governance Act, TRAIGA (HB 149), takes effect January 1, 2026. Among its provisions, health care providers must disclose to a patient, or the patient's representative, when AI is used in their diagnosis or treatment. The disclosure must be clear and conspicuous, in plain language, and free of dark patterns, that is, no design tricks that bury or discourage the disclosure. TRAIGA is enforced by the Texas Attorney General, and the penalties are substantial: civil penalties ranging from roughly $10,000 to $200,000 per violation, with the exact figure depending on factors like whether the violation was curable and was cured. Note the different flavor from AB 3030: TRAIGA is not primarily about who drafted a message, it is about disclosing that AI played a role in the clinical work itself, and its enforcement teeth are real.
Sit with why that difference matters in practice. Under AB 3030, a human review can lift the disclaimer requirement, because the law's concern is that a patient not unknowingly rely on a machine-written message; once a licensed human owns the message, that concern is answered. But TRAIGA's concern is different: it is that a patient know AI was involved in the substance of their care, and reviewing the output does not un-involve the AI. If an AI system contributed to a diagnosis or a treatment decision, the patient's interest in knowing that is not satisfied merely because a clinician looked at the result. This is why you cannot assume the AB 3030 human-review reflex covers you everywhere; a single mental model ("a human reviewed it, so no disclosure needed") is correct for one axis and incomplete for the other. Understanding that the two laws are answering two different questions is what keeps you from applying the right rule to the wrong situation.
The rules will keep changing. The safe habit will not: assume disclosure may be required, keep a licensed human reviewing, and build the disclaimer and the human-contact path in by default. You do not want to be discovering an obligation after the patient already relied on the message.
What a Compliant Disclosure Actually Looks Like
It is easy to nod along to "prominent disclaimer" and "clear and conspicuous" and then produce something that satisfies neither. So make it concrete by comparing real language. Here is a disclosure that fails, the kind that gets written when someone treats the requirement as a box to check rather than a message to a patient.
Non-compliant, buried in the message footer, gray six-point type: "This communication may have been produced with the assistance of automated tools. Subject to terms of service."
Count the ways that fails. It is not prominent, it sits in a footer no patient reads. It does not name AI in plain language, "automated tools" is a hedge. It gives the patient no way to reach a human, which AB 3030 requires alongside the disclaimer. And "subject to terms of service" is exactly the kind of legalese that makes a patient stop reading, which is what "clear and conspicuous" is meant to prevent. A regulator reading that footer would not credit it as disclosure; a patient would never see it. Now compare a version built to be found and understood.
Compliant, at the top of the message, same size as the body text: "Part of this message was drafted with the help of an artificial intelligence tool. If you have any questions or would like to speak with a member of your care team, call us at (555) 010-2020 or reply to this message and a person will get back to you."
Notice what the compliant version does. It sits where the patient will see it, not in the footer. It says "artificial intelligence" in words a patient understands, no euphemism. It gives a real, specific path to a human, a phone number and a reply option, which is the second half of the AB 3030 requirement that people routinely forget. And it is short enough to actually be read. That is the whole difference between a disclosure and a decoration: one is written to be seen and acted on, the other to be technically present and functionally invisible. When you build your template, build the compliant version, and build it once, so that no busy clinician is ever composing disclosure language under pressure.
One more nuance worth internalizing: the disclaimer should match the reality of the message. If AI drafted the whole thing, say it drafted the message. If AI only translated or summarized, you can say so more precisely. Overclaiming ("this entire message is AI-generated" when a clinician wrote most of it) is as much a distortion as underclaiming. The disclosure is a factual statement to the patient about how the message was made, and like everything else in this program, it should be true and verifiable, not marketing in either direction.
The Patchwork, and Why You Should Not Try to Chase It
These two laws are not the whole picture, and that is the point. Colorado has its own evolving approach to automated decision-making, with HIPAA-covered entities largely exempt from some developer and deployer duties but still owing notice and disclosures for certain covered uses, and its statutory scheme has already been revised once and does not take full effect until 2027. Other states are drafting. Federal rules touch adjacent territory. The details, who is covered, what triggers disclosure, what the disclosure must say, when a human-review exemption applies, vary from jurisdiction to jurisdiction and are being amended as legislatures learn. For a clinician or a care team, trying to hold this entire moving patchwork in your head and apply the exactly-correct rule per message is a losing game, and worse, it is a fragile one: the day the law changes and you have not noticed, your carefully tuned per-state practice is out of date and you are out of compliance without knowing it.
The way out of that trap is to stop optimizing for the minimum each law requires and instead adopt a single conservative default that satisfies the strictest plausible reading of all of them at once. If your standing habit is that any AI-touched patient communication gets a human review and, where the patient is receiving something an AI shaped, a clear and plain disclosure with a way to reach a person, then you are compliant in California, compliant in Texas, and positioned to absorb the next state's rule with a shrug rather than a scramble. The conservative default is not just easier to run than the patchwork; it is safer, because it fails toward disclosure and human review rather than away from them, and every one of these laws is ultimately trying to push you in that same direction.
The Two-Move Habit That Covers You
Reduced to its core, the safe practice is two moves, applied by default to any communication or clinical use an AI has touched. The first move is keep a licensed human in the loop. A human who reviews the AI's output before it reaches the patient is the linchpin of AB 3030's exemption, is good practice under TRAIGA and everywhere else, and is the same human-in-the-loop discipline this entire program is built on. The review is what converts a machine output into a professional's communication, and it is the single most protective thing you can do, legally and clinically, in one motion.
The second move is disclose by default and give a path to a human. When an AI has shaped a patient communication or a clinical decision, tell the patient, in plain and conspicuous language, and give them a clear way to reach a person with questions. Build it into your templates and your workflow so it is the standard, not a special case someone has to remember to add under pressure. Two properties make a disclosure sound: it must be clear and conspicuous, actually noticeable, not buried in fine print, and it must avoid dark patterns, no design that discourages the patient from reading or acting on it. TRAIGA names these requirements explicitly, and they are simply what honest disclosure looks like anywhere. A disclosure the patient cannot find is not a disclosure; it is a compliance decoration.
The word "default" is carrying real weight here, and it is worth dwelling on why, because it is the whole reason the habit works. A disclosure step that lives in a policy binder and depends on a busy clinician remembering to add it on the right message will be skipped exactly when it matters most: on the overloaded day, in the flood of the inbox, at the end of a long shift. That is the same lesson the automation-bias material taught, applied to compliance rather than clinical checking. You do not make disclosure reliable by exhorting people to remember it; you make it reliable by wiring it into the template so it appears unless someone actively removes it. A default that fires on its own is stronger than an intention that depends on attention, and a compliance obligation that rides on individual willpower is a compliance obligation you will eventually miss. Set the default toward disclosure, and the busy day, which is when you are most exposed, is handled automatically.
A Worked Example: The Same Tool, Two States
Make it concrete with the practice manager's ambient scribe, which drafts an after-visit summary the patient receives through the portal. Consider the California clinic first. Under AB 3030, if the AI-drafted summary is sent to the patient and no licensed provider reviewed it, it needs the prominent AI disclaimer and the contact-a-human instruction. But the clinic's actual workflow has the clinician review and sign the summary before it goes out. That human review triggers the exemption: the reviewed summary is the clinician's communication, and the specific AB 3030 disclaimer is not required. The safe habit still adds a light, standing note that the visit summary may be AI-assisted and here is how to reach us, because it costs nothing and covers the edge case where a review is skipped, but the legal exposure is handled by the review itself.
Now the Texas clinic, and notice the axis shifts. If that same AI is doing something that rises to a role in the patient's diagnosis or treatment, not just transcribing, but shaping the clinical assessment or plan, TRAIGA's disclosure obligation is about that clinical use, and a human having reviewed the note does not by itself extinguish the duty to tell the patient AI was involved in their care. So the Texas workflow adds a clear, plain-language disclosure that AI was used in their care, with a way to ask a human about it, delivered conspicuously and without dark patterns. Same tool, same vendor, two different obligations, because one state is asking "who wrote this message" and the other is asking "did AI shape this care." The practice manager who tried to run a different bespoke rule per tool per state would be perpetually behind. The one who adopted the conservative default, human review everywhere plus a clear AI disclosure and human-contact path by default, is compliant in both without having to adjudicate each message.
Observe what the conservative default bought her beyond compliance: it also made her defensible. If a patient or a regulator later asks whether a given communication was AI-involved and whether the patient was told, her answer is the same everywhere, yes, a human reviewed it and the disclosure and contact path were standard, and the record shows it. She is not reconstructing which rule applied to which message on which date under which version of which state's law. She built the strict thing in once, and it holds across the patchwork and across time.
There is one more thing the worked example quietly demonstrates, and it is easy to miss: the conservative default costs almost nothing to run. Adding a standing, plain-language line that AI may have assisted with this communication and here is how to reach a person is a one-time template change, not a per-message decision. Keeping a licensed human reviewing AI output before it reaches a patient is a discipline you should be running anyway for clinical-safety reasons, entirely apart from any disclosure law. So the "conservative" default is not a heavy, defensive over-compliance that slows the clinic down; it is a light habit that mostly formalizes things a safety-minded practice already does. The cost is trivial and paid once. The alternative, tracking a shifting multi-state patchwork message by message, is expensive, fragile, and paid forever. When one option is both cheaper over time and strictly safer, the choice is not close.
A Texas Vignette, Walked Through in Full
Put a face on TRAIGA so the clinical-use axis stops being abstract. A physician in a Houston primary-care practice is working up a patient with vague chest discomfort. She runs the patient's data through an AI clinical decision support tool that returns a risk stratification and suggests a differential weighted toward a cardiac cause. She reviews it, agrees with part of it, orders a workup, and adjusts the plan based on her own judgment. The AI genuinely shaped the diagnostic reasoning: it surfaced a possibility, weighted a risk, and influenced what she ordered. Under TRAIGA, effective January 1, 2026, this is precisely the situation the law addresses, AI used in the patient's diagnosis or treatment, and the patient is owed a clear, conspicuous, plain-language disclosure that AI was part of their care.
Watch the reflexes that would get her in trouble. The first is "I reviewed it, so I own it, so nothing to disclose." That is the AB 3030 instinct, correct on the communication axis and wrong here: her review makes her clinically accountable, which is exactly right, but it does not erase the fact that AI shaped the workup, which is what TRAIGA wants the patient to know. The second trap is disclosing in a way the patient cannot use: a line in a dense consent packet, or a verbal aside rushed past at the end of the visit. TRAIGA's clear-and-conspicuous, no-dark-patterns standard is a direct answer to that. The compliant move is simple and human: tell the patient, in plain words, that an AI tool was used to help evaluate their symptoms, that she reviewed and made the decisions, and that they can ask her or the practice about it. Delivered plainly, at a moment the patient can absorb it, that satisfies the law and respects the person.
The penalties are the reason this is not optional theater. TRAIGA is enforced by the Texas Attorney General, with civil penalties running roughly from $10,000 to $200,000 per violation depending on factors like whether the violation was curable and was cured. A practice that treats disclosure as a formality to skip when busy is not risking a slap on the wrist; it is exposing itself to enforcement with real financial teeth. But treat those numbers the way this program treats every number: as figures to verify against the current statute and your counsel, not to recite from memory, because penalty ranges and the specifics of enforcement are exactly the kind of detail a legislature adjusts.
Disclosure, the Note, and the Record
Disclosure to the patient is one thing; what the chart says about it is another, and a clinician who thinks about both is far better protected than one who thinks only about the patient-facing message. The disclosure the patient sees lives in the message or the conversation. But when a regulator, an auditor, or a plaintiff's attorney asks, months later, whether a given communication was AI-involved and whether the patient was told, the answer they will trust is the one written in the record at the time, not a recollection. So the durable practice is to let the record carry a light, factual trace: that AI assisted, that a licensed provider reviewed, and that the standard disclosure and human-contact path were provided. You are not writing a legal brief in the note. You are leaving the same kind of short, honest breadcrumb this program teaches everywhere: a sentence that a future reader can rely on.
Be careful about the two ways this goes wrong. The first is a note that overclaims, implying the clinician independently reached every conclusion when an AI in fact shaped the reasoning; that is the confabulation failure in a new costume, and it corrodes the record's honesty. The second is a note that hides the AI entirely, leaving no trace that a tool was involved, so that if disclosure later becomes an issue there is nothing to show it was handled. The middle path, the honest one, is a brief factual line: AI assisted with drafting or evaluation, the provider reviewed and remains accountable, and the patient received the standard disclosure. That single sentence turns a compliance question you would otherwise have to reconstruct into a compliance question you can answer by pointing at the chart. The record is what proves the habit ran, and a habit you cannot prove is, to an auditor, a habit that did not happen.
Disclosure Is Also Just Good Care
It would be a mistake to treat all of this as pure legal defense, because disclosure and a human-contact path are also, simply, respectful patient care, and they were good practice before any of these laws existed. Patients increasingly want to know when AI is involved in their care, and telling them plainly, without either hiding it or overhyping it, builds the trust that makes the whole enterprise sustainable. A patient who learns after the fact that an AI wrote to them, and that no one told them, feels something was concealed, whether or not a law was broken. A patient who is told up front, in plain language, that AI assisted and here is how to reach a real person, experiences transparency, which is the opposite of the thing that erodes trust in medicine. The laws are, in a sense, codifying an ethical instinct that good clinicians already had: do not let a patient rely on something without knowing what it is, and always leave them a door to a human.
So the AB 3030 and TRAIGA habit is not really a compliance chore bolted onto your work; it is the patient-communication expression of the cardinal rule this whole program teaches. AI assists, a licensed human decides and reviews, the patient is told plainly and given a path to a person, and the record proves all of it. Build those two moves in as defaults, review and disclose, and you have converted a shifting, intimidating legal patchwork into a single steady habit that keeps you compliant across states, defensible over time, and, most importantly, honest with the patient in front of you. The rules will keep evolving. Your habit does not have to.
That is the note this chapter on patient communication ends on, and it ties the four lessons together. Whether you are drafting a plain-language message, answering the portal inbox, translating for a limited-English patient, or disclosing AI involvement, the same spine runs through all of it: AI can do the drafting, the sorting, the reshaping, and the translating, but a licensed human stays in the loop, the patient is treated honestly, and the record shows who was accountable. The tools will change and the statutes will be amended, but a care team that has internalized that spine will adapt to each new tool and each new rule without ever losing the two things that actually protect the patient: a human who checked, and a patient who was told the truth.
Key Takeaways
- Two state laws anchor the 2026 landscape and fall along two axes. California AB 3030 targets the communication (was a patient message AI-generated), and Texas TRAIGA targets the clinical use (did AI shape diagnosis or treatment). One asks who wrote the message; the other asks whether AI shaped the care.
- AB 3030 (in force January 1, 2025) requires a prominent AI disclaimer and human-contact instructions on generative-AI patient clinical communications, unless a licensed or certified provider reviewed the message. Human review is the safe harbor.
- TRAIGA (effective January 1, 2026) requires clear, conspicuous, plain-language disclosure, free of dark patterns, when AI is used in a patient's diagnosis or treatment. It is enforced by the Texas Attorney General with civil penalties of roughly $10,000 to $200,000 per violation.
- The landscape is an evolving patchwork: Colorado has its own revised approach effective 2027, other states are drafting, and details vary and change. Trying to run an exactly-correct per-state, per-message rule is a losing and fragile game.
- The durable move is a single conservative default that satisfies the strictest plausible reading of all of them at once, so you fail toward disclosure and human review rather than away from them.
- The habit is two moves applied by default: keep a licensed human in the loop reviewing AI output, and disclose by default with a clear path to a human. Build both into templates and workflow so they are standard, not something to remember under pressure.
- A sound disclosure is clear and conspicuous and free of dark patterns. A disclosure a patient cannot find is not a disclosure; it is a compliance decoration.
- Disclosure and a human-contact path are also just good, trust-building patient care, the patient-communication form of the cardinal rule: AI assists, a licensed human decides and reviews, the patient is told plainly, and the record proves it.
Skill.re