The State AI Law Map: A Multi-State Compliance Strategy for Providers
ByClunic Research Team11 min read
Need it signed off?
Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.
Book an evaluation callWhy do multi-state groups need a strategy rather than a checklist?
Because the four state regimes do not regulate the same thing, so a checklist built from one of them does not partially satisfy the others. It satisfies none of them.
California regulates the content of communications and who may make a medical necessity decision. Texas regulates whether the patient was told. Utah regulates disclosure by licensed professionals. Colorado, from 2027, regulates the process around a consequential decision made with automated technology. A practice that disclosed diligently in Texas has done nothing about California's utilization review restriction, and a payer that fixed its utilization review has done nothing about disclosure.
The second reason is churn. Colorado's law has changed twice in under a year: the original SB 24-205 was pushed from February 1, 2026 to June 30, 2026 by amendments signed on August 28, 2025, and then repealed and replaced by SB 26-189, signed on May 14, 2026. Utah has amended its act more than once since 2024. A checklist goes stale. A policy built on a principle survives, and only the citations underneath it need updating. The wider federal and state calendar is tracked in the regulation tracker.
How do the four state regimes compare?
Side by side, with the thing each one actually bites on.
| State | Instrument | What it bites on | Who it binds | Effective |
|---|---|---|---|---|
| California | AB 3030, Health care services: artificial intelligence | Generative AI used in patient communications about clinical information must carry a disclaimer and tell the patient how to reach a human | Health facilities, clinics, physician offices, group practices | January 1, 2025 |
| California | SB 1120, Health care coverage: utilization review | An AI or algorithmic tool may not deny, delay or modify care based on medical necessity. Only a licensed professional may | Health care service plans and disability insurers | January 1, 2025 |
| Texas | HB 149, Responsible Artificial Intelligence Governance Act | Clear and conspicuous plain language disclosure that the recipient is interacting with an AI system | Licensed, registered or certified healthcare providers, among others | January 1, 2026 |
| Utah | SB 149, Artificial Intelligence Amendments, as amended | Disclosure of generative AI use by persons in state regulated occupations, which includes licensed clinicians | Regulated occupations and, in narrower form, consumer transactions | Signed March 13, 2024, amended since |
| Colorado | SB 26-189, Automated Decision-Making Technology | Notice at the point of interaction, plain language explanation after an adverse outcome, correction and human review rights | Developers and deployers of covered automated decision-making technology | Developer duties from January 1, 2027 |
Note what is missing. None of these is a licensing regime for clinical AI, none requires pre-market approval, and none of them displaces HIPAA, which continues to apply everywhere and remains the rule an enforcement action is most likely to be brought under.
What does California actually require?
Two separate things, from two bills both chaptered on September 28, 2024 and operative from January 1, 2025.
AB 3030 applies when a health facility, clinic, physician's office or group practice uses generative AI to produce patient communications about clinical information. The communication must carry a disclaimer that it was generated by AI, formatted according to the channel: prominently at the beginning of written communications, displayed throughout chat-based interactions, spoken at the start and the end of audio, and displayed throughout video. It must also tell the patient how to reach a human. The exemption is the operationally important part: a communication generated by AI and then read and reviewed by a licensed or certified human provider is not covered.
SB 1120 applies to health care service plans and disability insurers, not to providers. It requires that an AI or algorithmic utilization review tool base its determinations on the individual patient's medical history and clinical circumstances rather than on group datasets alone, that it not replace provider decision-making, and that it be subject to periodic review for accuracy. The binding sentence is that such a tool may not deny, delay or modify health care services based, in whole or in part, on medical necessity. Only a licensed physician or a competent licensed professional may do that.
For a provider organisation the practical reading of AB 3030 is that the review exemption is the whole design. If a clinician reads and approves before it goes out, you are outside the requirement, which is also the workflow you want for clinical safety reasons. That is why we treat clinical inbox triage as a drafting tool with a human signature rather than an autonomous responder. More detail sits on the California page.
What do Texas and Utah require, and how do they differ?
Both are disclosure regimes, and the difference is timing and trigger.
Texas HB 149 was signed on June 22, 2025 and took effect on January 1, 2026. Its healthcare provision requires that a licensed, registered or certified provider of healthcare services or treatment make a clear and conspicuous disclosure, in plain language, that the recipient is interacting with an AI system. The disclosure is due no later than the date the service or treatment is first provided, or as soon as reasonably possible in an emergency. It applies even where the AI use is obvious, and dark patterns that obscure the disclosure are prohibited.
Utah's Artificial Intelligence Policy Act, SB 149, was signed on March 13, 2024 and has been amended since. Its structure distinguishes regulated occupations, which include licensed health professionals, from ordinary consumer transactions, and imposes the more demanding disclosure duty on the former. Because the act has been revised more than once, treat the current statutory text and the Utah Office of Artificial Intelligence Policy as the source rather than any secondary summary, including this one. The Utah page carries the current reading.
The practical distinction: Texas is proactive and tied to the start of the service, so it changes your intake paperwork and your phone agent greeting. Utah is occupation-scoped, so it changes who has to disclose rather than when. If you satisfy Texas everywhere, you have generally satisfied Utah, which is the first piece of the strictest-state argument.
What survived in Colorado, and what does it mean for healthcare?
Less than the 2024 headlines suggested, and on a later clock.
SB 26-189, Automated Decision-Making Technology, was signed on May 14, 2026 and replaces SB 24-205. It drops the two heaviest obligations of the original act, the mandatory risk management programme and the annual impact assessment. What remains is a transparency and rights framework. Developers of covered automated decision-making technology must supply deployers with technical documentation covering intended uses, categories of training data, known limitations and instructions, must notify deployers of material updates, and must keep compliance records for at least three years. Those developer duties commence on January 1, 2027. Deployers must give consumers clear notice at the point of interaction, and where the system produces an adverse outcome must provide a plain language description of the technology's role within 30 days. Consumers get correction rights and a right to meaningful human review after an adverse decision. Enforcement is centralised with the attorney general, and implementation detail is left to rulemaking.
For healthcare the live question is what counts as a consequential decision. Coverage, eligibility and access to services are the usual answers, which puts payer-side and access-side workflows closer to the line than clinical documentation. An ambient scribe drafting a note is not making a decision. A tool that screens which patients get an appointment might be, and that is worth deciding deliberately rather than discovering. The Colorado page tracks the rulemaking.
How should a multi-state group decide what to build?
Four questions, in order. The order matters because each one removes work from the next.
- Does the tool communicate with a patient, or does it inform a person who communicates with the patient? If it drafts and a clinician reviews and sends, most of the disclosure regimes fall away and your obligation becomes an internal one about review discipline. Designing for review is cheaper than designing for disclosure.
- Does the tool make or materially influence a decision about a person? Coverage, access, triage priority and scheduling eligibility are decisions. Documentation is not. If the answer is yes, you are in Colorado's territory and, if you are a payer, California's.
- Are you a provider or a payer? SB 1120 binds plans. AB 3030 and the Texas provision bind providers. Groups that do both, including risk-bearing organisations, need both policies and usually miss the payer one.
- In how many states does this run? If the answer is more than one, build once to the strictest requirement and deploy it everywhere. Two policies for one workflow is how disclosure gets missed in the state that needed it.
Applied to the current four states, strictest looks like this: disclose proactively at first contact in plain language, keep a human review step before anything clinical reaches a patient, never let a model make a medical necessity determination, and be able to produce, within 30 days, a plain language explanation of what the system did in any adverse case. A group that does those four things is compliant in all four states and will probably remain so through the next round of amendments.
There is a cost objection to this, and it is worth answering honestly. Building to the strictest state means some of your sites carry a disclosure or a review step their own state does not require. In a large group that is real friction. The counter is that the alternative is a per-state matrix that has to be re-derived every time a legislature moves, and every time you open a location, and that has to be trained into staff who move between sites. The matrix is cheaper on paper and more expensive in practice, because the failure mode is not a fine, it is a clinician in the wrong state following the wrong rule and nobody noticing for a year.
The exception worth carving out is the payer side. If your group takes risk or operates a plan, the California utilization review restriction is a different obligation with a different owner, and folding it into a provider-facing disclosure policy tends to bury it.
What does the strictest-state policy look like in practice?
Short. One page of policy, three artefacts, one owner.
The policy states which AI systems are in scope, what disclosure each triggers, who reviews clinical output before it reaches a patient, and what the escalation path is. The artefacts are a system inventory, a disclosure register recording the exact wording used in each channel, and a decision log for anything that touched a coverage or access decision. The owner is a named person, not a committee, and the review cadence is quarterly.
The system inventory is the one people skip and later regret. You cannot apply a state disclosure rule to a tool nobody has written down, and in most organisations the list is longer than leadership expects once you include the scheduling assistant, the phone system's voice agent and the intake agent a single clinic bought on a credit card.
Two links worth having open while you write it: the regulations index, which is the current reading of each rule, and the HIPAA-compliant AI tools shortlist, which is where vendor posture is compared. If you would rather not draft it from a blank page, the AI governance and compliance engagement produces exactly this set of artefacts, and the multi-state version is the common case rather than the exception.
Sources
Primary material behind the claims above. Read the source before acting on any summary of it.
- StateCalifornia AB 3030, health care services: artificial intelligence (opens in a new tab)
- StateCalifornia SB 1120, health care coverage: utilization review (opens in a new tab)
- StateTexas HB 149, Responsible Artificial Intelligence Governance Act (opens in a new tab)
- StateUtah SB 149, Artificial Intelligence Amendments (opens in a new tab)
- StateUtah Office of Artificial Intelligence Policy (opens in a new tab)
- StateColorado SB26-189, Automated Decision-Making Technology (opens in a new tab)
- OtherExecutive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence (opens in a new tab)
- HHSHIPAA Security Rule guidance, HHS (opens in a new tab)
Questions we get asked
Which state has the strictest healthcare AI law?
It depends on what you are doing. California is strictest on patient-facing generative AI content and on payer utilization review. Texas is strictest on proactive disclosure at the start of treatment. Colorado will be strictest on process around consequential decisions once SB 26-189 takes hold from January 1, 2027. There is no single answer, which is why a strictest-of-each policy is easier than a per-state one.
Does my AI scribe trigger these state laws?
Usually not the disclosure rules, if it drafts a note that a clinician reviews and signs, because the output is a record rather than a patient communication. It may trigger the Texas disclosure duty depending on how the interaction is framed to the patient. HIPAA applies in every case, since encounter audio is protected health information.
Is the Colorado AI Act still coming into force?
Not in its original form. SB 24-205 was repealed and replaced by SB 26-189, signed May 14, 2026, which drops the mandatory risk management programme and annual impact assessments in favour of notice, disclosure and human review rights. Developer obligations begin January 1, 2027, with implementation detail left to rulemaking.
We operate in a state with no AI law. Do we need any of this?
You need the HIPAA layer regardless, and you should assume the state layer arrives eventually. Building the disclosure and human review discipline now costs very little, and it is what lets you open a clinic in Texas or California without a compliance project. Telehealth licensure across state lines can also pull you into another state's regime sooner than a physical expansion would.
Will a federal AI law replace the state patchwork?
Not as of August 2026. Executive Order 14365, signed December 11, 2025, sets federal policy toward a national framework, but it is not a statute and it has not displaced any state healthcare AI law. Every regime described here remains in force or on its stated schedule.
Who should own multi-state AI compliance internally?
One named person with authority over both the vendor list and the clinical workflow, typically sitting with compliance but reporting into operations. A committee produces a policy and no inventory. The test of whether ownership is real is whether that person can name every AI system currently touching patients and say which state rules each one triggers.
Know what changed before your vendor tells you
A monthly regulatory and vendor intelligence note for people who have to sign off on this. What moved in HIPAA, ONC and state AI rules, and which vendor claims stopped being true.
Book an evaluation call at any point. No obligation.