Executive Summary

AI chatbot regulation in the United States is moving to a new phase. For several years the common demand was a disclosure duty: the chatbot must tell you it is an AI. Since mid-2025 a different kind of prohibition has been layered on top. New laws ban the act of a chatbot posing as a licensed professional such as a therapist or a doctor. That shift leaves an especially clear signal for anyone who works with data.

After Nevada became the first US state to ban AI therapy services outright in July 2025, Illinois, California, and Tennessee drew their own impersonation lines within roughly half a year, and a federal bill was introduced as well. The other question, who consents to emotionally charged conversation being used for training, is answered almost nowhere. Only one state, Utah, has actually put restrictions on how that data can be used.

That asymmetry is the core of this piece. Five states and the federal government have moved on what a chatbot is allowed to say it is, yet the record those words leave behind, how that conversation can be reused, remains almost untouched. For any product handling emotionally sensitive conversation, that gap reads as a preview of the next regulatory wave.

The shift in regulatory center of gravity shows up in four numbers: the count of states that have already made disclosure a common baseline, the bodies that have moved on impersonation bans, the date the first outright ban took effect, and the number of states that have actually restricted how conversation data may be used.

12+

States with companion-chatbot laws

AI disclosure, minor protection, crisis response as the shared frame

5 + federal

Impersonation-ban measures

Nevada, Illinois, California, Tennessee + the federal CHATBOT Act

Jul 2025

First outright AI-therapy ban

Nevada AB 406 took effect, a US first

Utah, 1 state

Law restricting conversation-data use

An asymmetry against the five impersonation bans

1

Disclosure Is Already the Default

In barely a year, US companion-chatbot regulation moved from an exceptional measure to a standard requirement. California's SB 243 takes effect in January 2026 and requires clear notice that the user is talking to a chatbot. New York's AI companion model law has, since November 2025, mandated the same kind of disclosure along with procedures for responding to signs of suicide or self-harm. Add Connecticut, Oregon, Washington, Nebraska, and Idaho, and by the first half of 2026 at least twelve states had enacted companion-chatbot laws.

The details vary from law to law, but the skeleton is remarkably similar: the chatbot must reveal that it is an AI and not a person; minor users must be protected separately; and when a crisis signal appears, the system must respond through a defined procedure. These three points now read less like new regulation and more like an obvious baseline. That is exactly where it gets interesting. Once disclosure becomes the default, what does the next round of regulation aim at?

California State Capitol — the legislature that passed both SB 243 and AB 489
▲ The California State Capitol in Sacramento, where both the companion-chatbot disclosure law SB 243 and the credential-impersonation ban AB 489 were enacted. | Source: Wikimedia Commons
2

From Disclose to Do Not Impersonate

From mid-2025 the focus of regulation shifts noticeably. It no longer stops at requiring the notice that "I am an AI, not a person." A new prohibition appears: "you must not pose as a particular credential." If disclosure was a demand to reveal your identity, an impersonation ban is a demand not to fake it. The two rules aim at different things.

Nevada started it. AB 406, effective July 2025, bans AI systems that provide professional mental or behavioral health services outright, and makes it unlawful to use marketing phrases such as "AI therapy," "chatbot counselor," or "virtual psychotherapist" without clinician supervision. It is the first outright AI-therapy ban in the United States. A month later, Illinois followed with the WOPR Act. It bars AI from independently making therapeutic decisions or directly conducting therapeutic communication, and blocks unlicensed parties from providing therapy at all.

California widened the scope beyond mental health. Separate from SB 243, its companion-chatbot disclosure law, AB 489 takes effect in January 2026 and bans AI from using terms and titles such as "Dr.," "physician-level," or "clinician-verified" to appear as a licensed medical professional. Each such expression is punishable as a separate violation. Tennessee's SB 1580, effective July 2026, explicitly bars an AI system from presenting itself as a licensed mental health professional. On top of this, the federal CHATBOT Act, introduced in March 2026, joined the same direction by promising to protect consumers from AI that impersonates doctors, lawyers, and licensed professionals. The background case this federal bill cited shows why the trend exists. Chatbots calling themselves licensed therapists or board-certified psychiatrists, some even citing fabricated license numbers, had already appeared. Impersonation bans are less a preventive measure against a risk that has not yet arrived, and more a line drawn belatedly after the fact.

Jul 2025 Nevada AB 406 Aug 2025 Illinois WOPR Jan 2026 California AB 489 Mar 2026 Federal bill CHATBOT Act Jul 2026 Tennessee SB 1580
▲ Original Pebblous diagram. A timeline of credential-impersonation bans. In barely half a year, four states and the federal government moved in the same direction.

The timeline itself is this article's first finding. The half-year arc from Nevada to Tennessee, and then to the federal level, shows that the regulatory question has changed. The old question was whether this is an AI or a human; the new question is what this AI is impersonating. The center of gravity has genuinely moved from revealing an identity to faking a credential.

3

Consent for Conversation Data Is Still Empty

Has regulation moved past what a chatbot says, toward who consents to which conversations being used for training? The reporting points, honestly, closer to the opposite. Most companion-chatbot laws concentrate on disclosure, safety, and minor protection, and set no separate consent or use-limitation clause for using conversational or emotional data to train AI. California's SB 243, New York's companion model law, and the laws of Connecticut, Oregon, and Washington all leave this part blank. What exists is roughly the opt-out from automated decision-making found in general privacy law.

The exception is Utah's HB 452. This law, limited to mental health chatbots, includes an actual data clause. Providers may not sell or share a Utah user's personally identifiable health information or their submitted conversations with third parties, nor may they use that input for advertising. It is the first case of a law drawing a boundary around how far an emotionally charged conversation may be reused.

Utah State Capitol — where HB 452 restricted the use of conversation data
▲ The Utah State Capitol in Salt Lake City, where HB 452 banned selling, sharing, or advertising with mental health chatbot conversation data. | Source: Wikimedia Commons

So the map splits this way. Five states and the federal government have moved on credential-impersonation bans, but consent and use limits for conversation data remain, effectively, in Utah alone. If disclosure and impersonation bans regulate what the chatbot says, data consent regulates the record those words leave behind. The former was cleaned up quickly; legislation has not yet caught up with the latter. This asymmetry is the second finding.

4

Why Emotional Data Needs Provenance

For data practitioners, this asymmetry reads as a signal about sequence. Utah's clause barring input from being used in advertising is, in effect, the first time a law has touched the provenance and use-boundary question: where did this data come from, what was consented to, and how far may it be used. The order in which what-you-may-say gets settled first and what-you-may-collect follows is a pattern that has repeated in other regulatory domains such as copyright and privacy.

Conversation data that deals with emotion is more sensitive than ordinary text. The very fact that Utah singled out mental health chatbots and attached a data clause is that signal. If it took half a year for impersonation bans to spread to five places, data consent will not stay in Utah alone for long either. The possibility that the next legislative wave heads toward restrictions on the use of emotional and therapeutic conversation data is a direction the timeline so far already points to.

If so, the nature of preparation changes too. The more a product handles emotional data, the more that designing the scope of consent, retention periods, and reuse purposes in advance becomes not a response after regulation forces it, but a product requirement from the start. If you do not record under what consent a conversation was collected and how far it may be used in training, the moment regulation arrives, that gap comes back all at once as a bill.

Editor's note. Pebblous has long worked on the process of getting data ready to be used by AI. That readiness includes not only collecting and cleaning data well, but also recording what consent the data arrived under and how far it may be used. The more a conversation deals with emotion, the more it is data that knows its own source, consent, and use boundaries that can finally be called ready for AI.

Frequently Asked Questions

Is it illegal in the US for an AI chatbot to act as a therapist?

In some states, yes. Nevada has banned AI providing professional mental health services outright since July 2025, and California's AB 489 bans, from January 2026, any expression that makes an AI look like a licensed medical professional. Tennessee likewise bars an AI from presenting itself as a licensed mental health professional starting July 2026.

How does a disclosure duty differ from an impersonation ban?

A disclosure duty is a demand that the chatbot reveal it is an AI and not a person. An impersonation ban goes one step further and demands that it not falsely present a specific credential, such as a therapist or doctor. The former is about revealing identity; the latter is about not faking it.

How many states now regulate companion chatbots?

As of the first half of 2026, at least twelve states have enacted companion-chatbot laws. Most share a common frame of AI disclosure, minor protection, and crisis response, and on top of that Nevada, Illinois, California, and Tennessee have added credential-impersonation bans.

Do these laws also regulate using conversation data to train AI?

Mostly they do not. Many companion-chatbot laws focus on disclosure, safety, and minor protection, and set no separate consent or use-limitation clause for using conversation data in training. The only law with actual data-use restrictions is, effectively, Utah's HB 452.

What makes Utah's HB 452 different?

Utah's law, limited to mental health chatbots, includes an actual data clause. Providers may not sell or share a user's personally identifiable health information or submitted conversations with third parties, nor use that input for advertising. It is the first case of a law drawing a boundary around the reuse of emotional conversation.

How far has federal regulation come?

The federal CHATBOT Act, introduced in March 2026, aims to protect consumers from AI that impersonates doctors, lawyers, and licensed professionals. It is still at the introduction stage, but it can be read as a signal that the impersonation bans spreading state by state are extending to the federal level too.

What should a product handling emotional conversation data prepare for?

The starting point is building the scope of consent, retention periods, and reuse purposes into the design from the outset. If you record under what consent a conversation was collected and how far it may be used in training, you can meet data-use restrictions, when they are legislated, as a requirement you already have in place rather than an after-the-fact scramble.

R

References

Academic

Government & Legislative

Legal & Industry Analysis