Do doctors have to tell patients when AI is used?

Short answer

No federal law requires physicians to tell patients in general that AI was used in their care, as of Sept. 30, 2026 (ASTP/ONC; 45 CFR 92.210). A growing number of states require it in particular situations, among them Texas for AI used in diagnosis or treatment, California for AI-generated clinical messages, written or spoken, that no clinician has reviewed, and Rhode Island and Louisiana for AI scribes (Texas SB 1188; Texas HB 149; AB 3030; Rhode Island H 7538; Louisiana Act 649). Recording laws apply to ambient scribes regardless; California requires every party's consent to record a confidential conversation (JAMA; Penal Code 632).

No general federal duty

HHS's algorithm transparency rule, HTI-1, requires certified health IT to let "a limited set of identified users" see plain-language information about the decision support tools its developer supplies (45 CFR 170.315; ASTP/ONC). The department's health IT office, which described that information as transparency for "health care organizations and clinical users," has proposed removing the rule's AI "model card" requirements; as of Sept. 30, 2026, the proposal was not final (ASTP/ONC; Federal Register; Federal Register search). HHS's nondiscrimination rule requires covered entities to make reasonable efforts to identify decision support tools that use race, color, national origin, sex, age or disability as inputs and to mitigate the risk of discrimination, but says nothing about notifying patients (45 CFR 92.210).

Where states require disclosure

In Texas, since Sept. 1, 2025, a health care practitioner who uses AI "for diagnostic purposes," including recommendations on diagnosis or treatment, "must disclose the practitioner's use of that technology to the practitioner's patients" (Texas SB 1188; LegiScan). Under a second Texas law, since Jan. 1, 2026, when an AI system is used "in relation to" a health care service or treatment, the provider must disclose it to the patient or a personal representative by the date the service is first provided, or as soon as reasonably possible in an emergency, clearly and conspicuously, in plain language (Texas HB 149; LegiScan).

Since Jan. 1, 2025, California has required physicians' offices, clinics and health facilities that use generative AI to write or voice patient communications about clinical information to include a disclaimer and instructions for reaching a human, unless a licensed or certified provider "read and reviewed" the communication; scheduling, billing and other administrative matters are excluded (AB 3030; Medical Board of California). Since May 1, 2024, Utah has required licensed professionals, physicians among them, to disclose prominently when people are interacting with generative AI in the provision of their services; since May 7, 2025, the duty has applied only to "high-risk" interactions, such as generative AI that collects health data or gives personalized medical or mental health advice (Utah SB 149; Utah SB 226; LegiScan; Utah DOPL). From Jan. 1, 2027, HIPAA covered entities operating in Colorado must give patients "a general notice of use of advanced technologies" (Colorado SB26-189; LegiScan). A federal court order of April 27, 2026, in xAI's lawsuit against Colorado's attorney general, bars him from starting enforcement of the state's AI law, including 2026 legislation replacing or amending it, for violations that occur until 14 days after the court rules on xAI's motion for a preliminary injunction (court order).

Scribes, recording and therapy

Since June 22, 2026, Rhode Island has required physicians, other licensed providers and health care facilities that use AI to document visits to notify patients and to review the AI-generated documentation for accuracy; the law does not mention consent (Rhode Island H 7538; LegiScan). Since Aug. 1, 2026, Louisiana has required licensed health care professionals, physicians among them, to disclose verbally to the patient "the use of any recording device, software, or service" before recording any part of an appointment or treatment that AI will transcribe (Louisiana Act 649; Louisiana Legislature; R.S. 37:1262).

Federal law permits recording when one party to a conversation consents (18 U.S.C. 2511), but California requires "the consent of all parties to a confidential communication" (Penal Code 632), as does Washington for private conversations (RCW 9.73.030); about 11 states primarily require all-party consent, according to the Reporters Committee for Freedom of the Press (RCFP). The Federation of State Medical Boards advises that because encounter data may be put into AI tools, "physicians should receive a patient's consent prior to application of a tool to a patient's care" (FSMB).

Since Aug. 1, 2025, Illinois has required licensed therapists to tell clients in writing that AI will be used, and for what purpose, and to obtain consent before using it on a recorded or transcribed session; the law's definition of licensed professional excludes physicians (Illinois HB 1806; LegiScan). Maine has applied a similar rule since July 29, 2026, to physicians who provide therapy or psychotherapy (Maine LD 2082; Maine statutes; Maine Legislature). Nevada has barred psychiatrists and other mental health providers since July 1, 2025, from using AI in care provided directly to a patient, while allowing administrative uses such as scheduling and billing (Nevada AB 406; LegiScan).

What the AMA, FSMB and Joint Commission say

The American Medical Association's principles say that when AI "impacts access to care or impacts medical decision making at the point of care," its use "should be disclosed and documented to both physicians and/or patients" (AMA). The Federation of State Medical Boards says "physicians should disclose to patients when and how AI is used in their care" (FSMB). Guidance from the Joint Commission and the Coalition for Health AI says patients should be notified, when appropriate, "when AI directly impacts their care," and that "where and when relevant, consent should be obtained" (Joint Commission and CHAI).

What is unsettled

Informed consent doctrine requires disclosing information "material to a reasonable patient's decision to accept a health care service," or in some states information that bears on "a reasonable physician's decision about which treatment to offer," Michelle Mello and colleagues wrote in JAMA in 2025; they proposed that health care organizations base what patients are told on the risk of harm and whether patients can act on it (JAMA). I. Glenn Cohen's "best reading" of the doctrine, in a 2020 Georgetown Law Journal article, was that "in general, liability will not lie for failing to inform patients" about AI used to help formulate treatment recommendations, though the doctrine may reach further in some situations, such as when patients ask (Georgetown Law Journal). Texas's diagnostic AI law does not say when or how the disclosure must be made (Texas SB 1188).

What decides whether a disclosure rule applies

  1. Is AI used in diagnosis or treatment, or does it generate written or spoken clinical messages that no clinician reviews?
  2. Do patients interact directly with generative AI?
  3. Is the visit recorded, and what do the state's consent and notice rules require?
  4. Is the service therapy or psychotherapy?
  5. What do the organization's policies and the licensing board expect?

General information, not legal or medical advice. Every fact links to its source, and the page shows the date it was last reviewed.