All field notes

California AI law

California Has Redrawn the Line Around Health Chatbots

AB 1979 places qualifying consumer health-chatbot businesses under California’s medical-information law and draws a separate boundary around licensed clinical work.

MP
Max PerfiljevFounder & CEO, AES · Architect of Autonomous Organizations
Read in Russian

California has changed the legal question for some consumer health-chatbot products. Under AB 1979, the relevant issue is no longer simply whether a company presents its system as a wellness interface, a conversational assistant or an AI product. A business offering a qualifying health-care chatbot for managing health information, or for the diagnosis, treatment or management of a medical condition, is now deemed a provider of health care under California’s Confidentiality of Medical Information Act (CMIA).

Governor Gavin Newsom approved the bill on September 30, 2026. It was chaptered the same day as Chapter 854, Statutes of 2026. The measure is not an urgency statute. Its importance is not that it declares all health AI impermissible. It does something more operational: it connects a defined class of consumer-facing chatbot businesses to medical-information obligations, while separately limiting where AI can sit inside licensed clinical work.

For product, privacy and clinical leaders, that creates a combined deployment review. The product’s marketing, the information it uses, the purpose it serves, and the clinical function it may influence now need to be assessed together. A generic “human in the loop” statement is not an adequate answer to that design problem.

The classification turns on the product, not its preferred label

AB 1979 defines a health-care chatbot as a generative-AI system with a natural-language interface that provides adaptive, human-like responses; is marketed as supporting health services; and uses health-related information supplied by the consumer, accessed from the consumer, generated about the consumer or inferred from the consumer.

Those elements matter together. The law does not say that every health, fitness or wellness chatbot is covered. Nor does a health-related topic alone settle the question. The statutory definition asks what the system is, how it is marketed, and what health-related information it uses. A consumer-facing assistant that discusses general wellbeing may therefore require a different analysis from a chatbot marketed to support health services and built around an individual’s health information.

Where the criteria and the relevant purpose are met, the consequence is substantial: the offering business is deemed a health-care provider subject to the CMIA. This is not an extension of HIPAA and should not be described as one. The CMIA is California law with its own scope, rules and exceptions. The statute also does not, by itself, answer every question about training, analytics, advertising or data sharing. Those outcomes depend on the CMIA’s specific provisions and on the facts of a particular product and data flow.

That distinction should change the order of enterprise review. Teams should not begin with the model card or an abstract risk score. They should first map the actual product claim, the consumer journey, the sources and inferences of health-related information, and the functions the chatbot is offered to perform. A product called “wellness” is not outside the analysis merely because the label is broad. Conversely, a chatbot is not automatically covered simply because it can answer a health question.

AI assistance remains possible; independent licensed practice does not

The bill establishes a second, distinct boundary for covered health facilities and practices. They must take reasonable steps to preserve a licensed professional’s ability to exercise independent judgment whenever care is informed by clinical-decision-support output.

The law also prohibits covered organizations from deploying AI to independently perform a clinical function that California law requires a licensed person to perform. They may not use AI to direct unlicensed personnel in performing such a function either. The practical point is narrow but consequential: an AI system can inform clinical decision-making, but it cannot become the independent performer of work reserved by law for a licensed professional, or a mechanism for routing that reserved work through unlicensed staff.

This is not a ban on AI-assisted clinical decision-making. It is a deployment boundary. Systems can provide clinical-decision-support output, but the surrounding workflow must preserve the professional’s independent judgment. That requires more than placing a clinician somewhere downstream of a recommendation. The implementation must leave the licensed professional able to make an independent decision rather than merely ratify a system-driven conclusion.

AB 1979 also draws a useful line around lower-judgment work. Its clinical restrictions do not cover administrative documentation and communications that do not involve professional judgment, including reminders, record-update messages and information assistance. That means a health organization should not treat every AI-enabled administrative workflow as licensed practice. But it should be precise about where administrative support ends and a legally reserved clinical function begins.

The deployment review now has four connected questions

The immediate response is not to stop health-chatbot work. It is to make product classification and clinical workflow design part of the same release decision. Four questions provide a practical starting point:

  1. Does the system meet the statutory chatbot definition: generative AI, natural-language interaction, adaptive human-like responses, health-services marketing and use of consumer health-related information?
  2. Is it offered for health-information management, or for diagnosis, treatment or management of a medical condition—the purposes that trigger the provider classification described in the bill?
  3. Which information is supplied, accessed, generated or inferred about the consumer, and how does the resulting product operation align with CMIA obligations?
  4. At every clinical handoff, is the system informing a licensed professional’s independent judgment, or independently performing—or directing unlicensed personnel to perform—a function reserved to a license?

These are not four teams’ separate checklists. Marketing can alter the classification analysis. Product design determines what information is collected and inferred. Privacy architecture determines where that information travels. Clinical workflow design determines whether decision support remains support. A release process that reviews these pieces independently can miss the legal effect created by their combination.

The most useful artifact is therefore a product-and-workflow map, not a generic AI policy. It should show the consumer-facing claim; the chatbot’s qualifying features; each health-information input, access path, output and inference; the stated purpose of the service; and the points where a clinical action is proposed, reviewed or carried out. That map gives counsel, product owners, privacy specialists and clinical leadership one shared object for deciding whether a proposed deployment crosses either statutory boundary.

What changed—and what did not

What changed on September 30 is a statutory classification and a clinical deployment limit. Qualifying consumer health-chatbot businesses can be treated as health-care providers under the CMIA. Covered facilities and practices also face explicit requirements to preserve independent licensed judgment and may not deploy AI to independently perform licensed clinical functions or direct unlicensed staff to do so.

What did not change is equally important. California did not make every health or wellness chatbot a regulated provider. It did not equate AB 1979 with HIPAA. It did not prohibit clinical decision support or ordinary administrative communications that do not involve professional judgment. And the law does not establish, on its own, that every use of health data for training, analytics, advertising or sharing is forbidden.

That precision is the point. California has not created a single category called “health AI” and applied one answer to it. It has made the business classification depend on a specific product definition and purpose, then placed a separate boundary around work reserved to licensed people. Enterprises building or buying these systems should respond with a combined review before deployment—not with looser product naming, a blanket prohibition, or a ceremonial approval step after the workflow is already designed.

Source: California AB 1979, Chapter 854, Statutes of 2026; official bill status and bill text, California Legislative Information.

BUILD WITH AES

Turn architecture into an operating company.

AES connects strategy, tasks, organizational memory, knowledge, agents, people and approvals in one execution environment.