On Wednesday 12 August 2026, every psychologist, professional counselor, clinical social worker, marriage and family therapist and addiction counselor lawfully practicing in Colorado picks up a new statutory duty. It is not the one the headlines describe. The duty that lands on the largest number of practices is this: at initial client contact, you must hand the client written information about what AI is prohibited from doing in psychotherapy. That obligation sits in section 12-245-224.5(6)(b) of the Colorado Revised Statutes, and nothing in it is conditional on your practice actually using AI.

A group that has deliberately kept AI out of the therapy room still has to update its intake pack. That is the part most coverage of House Bill 26-1195 has skipped, because most coverage stopped at the word "ban".

The timing is awkward for a reason that has nothing to do with the legislature. The American Psychological Association's 2026 Chatbots and Mental Health Survey, published June 2026 and fielded across more than 1,200 licensed US psychologists in April 2026, found that 77% had spoken with patients who had used AI, and around a third had patients treating AI as an additional mental health professional. Clients brought AI into the therapeutic relationship first. Colorado is the first state to write down what clinicians must do about it.

What the statute actually prohibits

Governor Polis signed HB 26-1195 on 3 June 2026. The operative text adds a new section, 12-245-224.5, to Colorado's mental health practice act, and amends the prohibited-activities list so that failing to comply with it is itself a licensing violation. Three prohibitions sit at the center of it (Colorado General Assembly, enrolled bill text, HB 26-1195, 2026 session):

One. A regulated professional may not allow an AI system to interact with clients in any form of therapeutic communication without synchronous, real-time interaction between the clinician, the AI system and the client. "Therapeutic communication" is defined broadly and includes reflecting a client's thoughts or emotions, offering therapeutic strategies, offering emotional support or reassurance, collaborating on treatment goals, and giving behavioral feedback.

Two. A regulated professional may not allow an AI system to generate therapeutic recommendations or treatment plans without the clinician's review and approval.

Three. As introduced, the bill barred the use of an AI system to detect emotions or mental states. This is the sleeper provision for anyone buying software, because affect detection and sentiment scoring are quietly bundled into a growing number of session-analysis and outcome-monitoring products, often as a feature nobody in the practice asked for.

So what for you: the compliance question is not "do we use AI therapy", because almost nobody in independent practice does. It is "does anything we already license infer emotional state from a client's voice, face or text", and that answer usually lives in a product feature list rather than in your own head.

The permitted lane that most coverage missed

Read prohibition one again and note what it does not say. It does not say an AI system may never take part in a therapeutic exchange. It says it may not do so without the clinician being in the interaction synchronously and in real time. The statute defines "synchronous" as active participation by both client and clinician at the same time, and expressly excludes reviewing an interaction after it has happened.

That is a permission structure, not a prohibition, and it is unusual. Nevada's AB 406 (effective July 2025) and Illinois' Wellness and Oversight for Psychological Resources Act (signed 1 August 2025) both take the simpler route of barring AI from delivering therapy at all. Colorado has instead legislated a supervised lane and defined the supervision standard as live presence. Writing in Forbes on 16 July 2026, Lance Eliot argued the drafting sets a questionable precedent precisely because it obliges a clinician to sit in on an AI-mediated exchange rather than simply prohibiting one. That criticism is worth taking seriously, and it is also a reason to expect Department of Regulatory Agencies rulemaking or guidance to follow.

So what for you: if a vendor tells you its between-session AI check-in tool is fine in Colorado because a therapist reviews the transcript afterwards, that reading fails on the face of the statute, which rules out after-the-fact review as a substitute for synchronous participation.

What stays allowed, in the statute's own words

The bill is unusually specific about permitted use, and the list is longer than most practice owners expect. Administrative support is defined to include appointment scheduling and reminders, billing and insurance claims processing, and drafting general communications about therapy logistics that carry no therapeutic advice.

Supplementary support goes further and covers preparing and maintaining client records, including therapy notes; analyzing data to track client progress or identify trends, subject to clinician review; identifying and organizing internal and external resources or referrals; and collecting mental health or wellness information such as symptom frequency tracking, mood rating scales, intake questionnaires, medication adherence logging and sleep and activity tracking.

Ambient documentation, in other words, is explicitly on the permitted side, and so is structured outcome measurement of the PHQ-9 and GAD-7 variety. Both carry one condition: the clinician retains responsibility for reviewing the outputs. The statute also carves out self-help, coaching, guided meditation, journaling, psychoeducation, safety planning and similar wellness tools, so long as they do not diagnose or treat a mental health disorder and clearly disclose that they are not a substitute for clinical care.

So what for you: the AI most independent psychology groups have actually deployed, or are considering, sits squarely inside the permitted zone. This law does not require you to rip anything out. It requires you to be able to show you reviewed what came out of it.

The consent rule that invalidates most intake paperwork

From 12 August, a clinician may not use an AI system to record or transcribe a session unless the client has been told in writing, in advance, that an AI system will be used and the specific purpose it will be used for, and has consented in writing.

The definition of consent is where existing paperwork tends to fail. Consent must be a clear, explicit, affirmative, specific and unambiguous written agreement, and it must be revocable. The statute then names three things that do not count: acceptance of a general or broad terms-of-use document that mixes AI descriptions in with unrelated material; interacting with digital content by hovering, muting, pausing or closing it; and any agreement obtained through deception.

An AI clause buried in clause 14 of a general practice-policies form is exactly the first failure mode, described almost literally. Two further details matter operationally. Consent is required only for the initial use on or after the effective date, not session by session, unless the purpose or manner of use materially changes. And refusal to consent, or later revocation, may not be used as a basis to deny psychotherapy services.

So what for you: a standalone, signed, one-page AI consent form is the only version of this that clearly complies, and your scheduling workflow needs a way to flag "this client declined" so a scribe does not start recording by default. UK readers will recognize the shape of this argument from the gap between HCPC's binding consent standard and BPS's advisory AI guidance. Colorado has now closed the equivalent gap with statute rather than guidance.

The duty that applies whether or not you use AI

Subsection (6)(b) requires the clinician to give the client, at initial client contact, written information about the prohibitions on AI in the practice of psychotherapy. There is no exemption for practices that use no AI, and there is no template published with the bill.

Snell & Wilmer's 8 June 2026 client alert on the final act reads the requirement the same way, listing written notice of the bill's AI prohibitions at initial contact alongside the consent process as the two things providers must build by 12 August. Treat that as an informed reading by Colorado healthcare counsel rather than as regulator-issued guidance, because DORA has not yet published its own interpretation.

So what for you: this is a one-paragraph addition to your intake pack, and it is the cheapest item on the list to fix. It is also the one a board complaint would establish fastest, because either the document exists in the client file or it does not.

What getting it wrong costs

Because non-compliance was written into section 12-245-224(1)(y), the prohibited-activities list, the primary exposure is to the license rather than to a fine. The relevant board may take disciplinary action, which runs up to suspension or revocation.

On monetary penalties, several law firm and legislative-tracking summaries of the final act cite administrative fines of up to $5,000 and civil penalties of up to $20,000 per violation under the Colorado Consumer Protection Act, the latter attaching to the advertising and representation provisions in the new section 6-1-1705.2. Those figures come from secondary legal analyses rather than from a figure printed in the operative text, so treat the exact numbers as reported rather than confirmed, and confirm with counsel before relying on them.

One provision does protect clinicians. Section 6-1-1705.2(2) states that nothing in that section imposes liability on a clinician for defects in, or failures of, an AI system attributable to the developer or deployer. Developer and deployer liability is governed by consumer protection law instead.

So what for you: your risk here is a licensing complaint arising from missing paperwork, not a product liability claim arising from a model's output. Those two risks call for completely different controls, and the paperwork one is fully within your control this week.

Colorado is not an outlier, and that is the real signal

Four states now bar AI from delivering therapy to the public and several more regulate it: Nevada and Illinois legislated in 2025, Utah's HB 452 requires disclosure rather than prohibition, and state-law trackers surveyed in July 2026 add Rhode Island and Maine to the ban column, with New York, California and Nebraska adding crisis-referral and minor-protection rules for companion chatbots. Those tracker counts come from commercial legal-tracking sites rather than from a single authoritative register, so verify your own state before acting on the count.

The pattern underneath them is consistent, and it is the same pattern visible in the state wiretap and consent exposure that a signed HIPAA business associate agreement does not cover: federal AI rules for healthcare keep slipping, and states keep filling the space with narrower, faster, more specific law. HHS's AI-relevant HIPAA Security Rule update is now targeted for 2027 per the OMB Unified Agenda. Colorado went from signature to enforcement in ten weeks.

So what for you: if you operate across state lines, whether through PSYPACT or a multi-site group, the compliance unit is the state your client sits in, not the state your head office sits in. That is a materially harder operating problem than a single-site practice faces, and it is worth solving with a standardized consent and review layer rather than site-by-site improvisation.

What to do before Wednesday

Frankly, if you practice in Colorado or see Colorado clients, the sequence here is short enough to finish in an afternoon, and there is no version of the maths where waiting for DORA guidance is the cheaper option.

First, inventory every tool touching a client interaction and check each one specifically for affect detection, sentiment scoring or emotional-state inference, including features you have never switched on. Second, pull your AI recording consent out of your general policies document and make it a standalone, signed, revocable form that names the tool and its purpose. Third, add the AI prohibitions notice to your initial contact pack. Fourth, write down who reviews AI-generated notes, recommendations and progress analyses, and how that review is evidenced, because "the clinician retains responsibility for reviewing outputs" is the condition on which every permitted use in this statute depends. Fifth, ask any vendor selling you a between-session client-facing tool to point to the provision that permits it.

The practices that will find this straightforward are the ones that already knew which tools they run and who signs off on the output. The ones that will find it painful are the ones discovering both facts for the first time in the same week as a statutory deadline. If you are in the second group, our AI Opportunity and Growth Assessment maps exactly that: what is running, what it does with client data, and who is accountable for each output. You can also book a 20-minute call to talk through where your practice sits.

The Clinical AI Briefing

One practical AI insight for healthcare practices every week. No hype. Evidence and outcomes only.

Related: HCPC's consent standard is binding. BPS's AI guidance isn't.  ·  Psychology AI already runs across 550 locations and 7,500 clinicians  ·  Your AI scribe's BAA covers HIPAA. It doesn't cover this $5,000-a-patient lawsuit.

This article is for informational purposes only and does not constitute legal or clinical advice. It summarizes the enrolled text of Colorado HB 26-1195 as published by the Colorado General Assembly and secondary legal analyses of the final act; penalty figures and multi-state counts are drawn from those secondary analyses and are not independently confirmed against operative statutory text. State AI statutes are changing quickly. Confirm current requirements with your licensing board and legal counsel before acting on anything above.