Regulatory Landscape for Caregiver AI¶
AI systems that interact with caregivers and people in emotional distress occupy a rapidly forming regulatory space. As of early 2026, 8 US states have enacted or proposed legislation governing AI companions in health and wellness contexts, the EU AI Act is in force, and the FDA's General Wellness Framework defines the regulatory floor.
This page synthesizes 10 statutes and frameworks into a comparison matrix useful for funding proposals, compliance planning, and partner conversations.
The regulatory stack¶
The statutes reviewed here fall into three functional categories:
- Scope restrictions — What AI may and may not do (WOPR Act IL, NV AB 406)
- Disclosure requirements — What AI must tell users (CA AB 3030, UT HB 452)
- Risk classification — How AI is categorized for regulatory purposes (CO SB24-205, EU AI Act)
Comparison matrix¶
| Statute | Jurisdiction | Year | Category | Key requirement | What it means for GiveCare/Mira |
|---|---|---|---|---|---|
| WOPR Act (HB 1806)1 | Illinois | 2025 | Scope | Bans AI therapeutic communication without licensed clinician review | Most restrictive. Mira must operate as peer support, never as therapy. Any output resembling a treatment plan requires human review. |
| CA AB 30302 | California | 2023 | Disclosure | AI-generated health content must be disclosed | Mira must disclose AI identity in health-related communications. Earliest US precedent — set the template for later statutes. |
| NV AB 4063 | Nevada | 2025 | Scope | AI may not provide services constituting professional mental/behavioral healthcare | Draws a bright line. Mira may support and inform. Mira may not diagnose or treat. Aligns with wellness framing. |
| UT HB 4524 | Utah | 2025 | Disclosure | Clear, unambiguous AI disclosure during interactions | Broad consumer protection. Applies beyond healthcare. Disclosure must be prominent, not buried. |
| CO SB24-2055 | Colorado | 2024 | Risk classification | Healthcare AI classified as high-risk, triggering enhanced compliance | First US state to adopt explicit risk classification. Mira is high-risk under this framework. Requires impact assessments and risk management. |
| EU AI Act6 | European Union | 2024 | Risk classification + Scope | Prohibits exploiting vulnerabilities; classifies health AI as high-risk | International precedent US states reference. Vulnerability-exploitation prohibition is directly relevant to caregivers under stress. |
From most to least restrictive¶
Most restrictive: Illinois WOPR Act. Effectively requires a licensed clinician in the loop for any AI output that could be construed as therapeutic. This is the compliance ceiling — if GiveCare meets WOPR Act requirements, it satisfies every other US jurisdiction.
Moderately restrictive: Colorado SB24-205 (triggers enhanced compliance obligations via risk classification), EU AI Act (prohibits vulnerability exploitation and requires conformity assessments for health-related AI).
Disclosure requirements: Utah HB 452 and California AB 3030 both require clear user notification that they are interacting with AI. UT HB 452 emphasizes prominence and clarity, while CA AB 3030 establishes a foundational precedent for health-communications disclosure.
Scope boundaries: Nevada AB 406 defines what AI may and may not do. It draws the line at licensed clinical practice and prohibits AI from providing services constituting professional mental or behavioral healthcare.
Patterns across jurisdictions¶
Disclosure is converging¶
Multiple frameworks include AI identity disclosure requirements. California AB 3030 and Utah HB 452 both establish that users must be clearly informed they are interacting with AI. Disclosure is becoming table stakes for AI systems in health contexts.
Risk classification is emerging¶
Colorado and the EU have established that AI systems interacting with people in health contexts are high-risk by default. Colorado SB24-205 triggers enhanced compliance obligations: impact assessments, risk management practices, consumer protection from algorithmic discrimination. GiveCare should plan for high-risk classification as the norm, not the exception.
Scope boundaries are hardening¶
Multiple states (Illinois WOPR Act, Nevada AB 406) are drawing bright lines between peer support and licensed clinical practice. AI systems cannot provide services constituting professional mental or behavioral healthcare. Maintaining this boundary between peer support and clinical practice is becoming a legal requirement, not just a best practice.
Grant application utility¶
For grant reviewers, this matrix demonstrates:
- GiveCare is aware of and designing for the regulatory landscape — not operating in a compliance vacuum
- InvisibleBench tests against these statutory requirements — boundary respect aligns with NV AB 406 and WOPR Act, disclosure aligns with CA AB 3030 and UT HB 452
- The WOPR Act ceiling strategy — by meeting the most restrictive framework (Illinois), GiveCare is compliant across all current US jurisdictions
- The regulatory trajectory is toward more, not fewer, requirements — building compliance into the architecture now avoids expensive retrofits as additional states legislate
What is not yet regulated¶
Notable gaps in the current regulatory landscape:
- Multi-turn safety is not addressed by statute. All current regulations implicitly assume single-interaction evaluation.
- Benefits eligibility guidance is unregulated. No statute specifically governs AI systems that help users navigate public benefits.
- Caregiver-specific protections do not exist. All current statutes address users generally or patients specifically. None recognize caregivers as a distinct population with distinct vulnerabilities.