Healthcare AI regulation used to be a federal question. In 2026, it is fifty separate questions. More than 250 healthcare AI bills have been introduced across over 34 states, and several of the most consequential ones, in Colorado, Utah, and California, took effect or were signed this year. If your practice uses an AI scribe, an AI agent for intake or scheduling, or any tool that touches a clinical decision, you now have disclosure obligations that did not exist eighteen months ago. This guide covers what changed, what it means for your practice, and how to build compliance in rather than retrofit it after the fact.
Why This Matters Even If You Did Not Build the AI Yourself
The detail practices miss most often: your organization is the responsible party under nearly every state law on this list, regardless of whether you built the AI tool or licensed it from a vendor. A gap in your vendor's compliance posture becomes your compliance gap the moment you deploy their product with a patient. A signed Business Associate Agreement covers HIPAA. It does not automatically cover the disclosure and consent requirements these newer state laws introduce.
This is the same principle that applies to any outsourced clinical function. You can delegate the work. You cannot delegate the liability.
Colorado: SB 26-189 Replaces the Colorado AI Act
Colorado signed SB 26-189 on May 14, 2026, repealing and replacing the original Colorado AI Act (SB 24-205). The new law takes effect January 1, 2027, and shifts the state to a disclosure-based framework closer to what Texas and California already require, rather than the heavier algorithmic impact assessment model the original act proposed.
For healthcare organizations operating in Colorado, this means the compliance bar is lower than the original act would have set, but it is not zero. Disclosure obligations remain, and the effective date gives practices roughly a year to get ahead of it rather than scrambling in December 2026.
Utah: Direct Disclosure to Patients and to Regulators
Utah has taken one of the most direct approaches in the country. Hospitals in Utah must now disclose AI use in patient care directly to patients. Separately, insurers operating in Utah must publicly disclose whether AI is used to review prior authorization requests, and must file a disclosure notice with the state Department of Insurance.
The pattern here matters beyond Utah's borders: regulators are increasingly drawing a hard line between AI that assists a clinician and AI that makes or influences a coverage or treatment decision. The latter carries a materially higher disclosure bar, and more states are expected to follow this same split.
California: Disclosure Plus a Human Alternative
California's rules require healthcare organizations to disclose when a patient-facing communication was generated or substantially drafted by an AI system. Critically, California also requires that patients be able to access a human alternative on request. A chatbot or AI-drafted message is not enough on its own. The workflow has to include an easy, working path to a human, not a buried phone number in a footer.
This is a meaningful design requirement, not just a legal disclaimer. If your intake, scheduling, or patient messaging AI does not have a clear human escalation path, it likely does not meet the California standard even with a disclosure notice attached.
The Federal Layer: HTI-1 Model Cards Are Still in Force
At the federal level, the ONC's HTI-1 Final Rule requires developers of certified health IT with predictive decision support features to publish a model card: a structured disclosure covering 31 source attributes, including what data trained the model, its intended use, and known limitations. This has been in force since Base EHR certification requirements took effect.
A proposed rule, HTI-5, would roll back these model card requirements. The comment period closed February 27, 2026, and as of this writing the rule has reached the Office of Information and Regulatory Affairs for review, the last procedural step before publication, but it has not been finalized. Until HTI-5 is finalized and published, the HTI-1 model card requirements remain in force. Practices and vendors should plan around the current rule, not the proposed one.
What This Actually Means for Your Practice
Strip away the state-by-state detail and three practical obligations show up almost everywhere:
1. Patients Need to Know When They Are Interacting With AI
Whether it is a scribe recording their visit, a chatbot handling their intake, or a message drafted by an AI agent, the trend across every state law here is toward clear, conspicuous notice. Buried consent language in a general treatment form is increasingly not sufficient on its own.
2. A Human Alternative Has to Actually Work
Several states now require this explicitly, and it is good practice even where it is not yet mandated. If a patient wants to reach a person instead of an AI system, that path needs to be real, fast, and not designed to be avoided.
3. Vendor Contracts Need to Cover This, Not Just HIPAA
A BAA protects PHI. It does not, by itself, guarantee your AI vendor's tool generates the disclosures your state requires, retains the audit trail a regulator might ask for, or supports a human escalation path. Review vendor contracts specifically for these gaps rather than assuming HIPAA coverage is sufficient.
Building Compliance In, Not Bolting It On
The organizations struggling most with this landscape are the ones treating each new state requirement as a separate patch. A more durable approach is to build disclosure, consent, human escalation, and audit logging into the AI deployment itself, so that a new state law is a configuration change rather than a rebuild.
This is one of the reasons AI agents built and operated by a team that understands healthcare compliance behave differently from a generic automation tool pointed at a healthcare workflow. The disclosure notice, the consent record, and the escalation path are part of the system from day one, not an afterthought added after a state passes a new law.
What to Do Before Your Next AI Deployment
- Confirm which states you operate in and check each one's current disclosure requirements, not just HIPAA and your BAA
- Review existing patient-facing AI tools (scribes, chatbots, scheduling agents) for a working human escalation path, not just a disclosure notice
- Ask AI vendors directly whether their tool supports the audit logging and disclosure generation your state requires, and get the answer in writing
- Track the HTI-5 rule status if you rely on certified health IT with predictive decision support features, since the model card requirement could change without much notice once the rule is finalized
- Build new AI deployments around disclosure and consent from the start, rather than treating compliance as a separate project after launch
The regulatory landscape here will keep shifting for the next several years. The practices in the best position are not the ones waiting for a final, settled rulebook. They are the ones building AI deployments flexible enough to absorb the next state law without a rebuild.
For help evaluating whether your current AI tools meet these disclosure requirements, or building new AI agents with compliance handled from day one, review our agentic AI services or schedule a compliance review.
Futureaiit
AI & Technology Experts