Intelligence Brief

The New AI Rules Point at You,
Not at the Software

Issue 019  |  August 3, 2026

What happened this week in AI and health practice governance.

What it means for your practice.

What to do about it.

Three things happened this week, from three places that have nothing to do with each other: a nutrition journal, a national health nonprofit, and two state legislatures. None of them wrote a rule for the software. All three put the responsibility on the person giving the advice. If you work one on one with clients, that person is you, and this issue is about what that actually asks of you between now and next week.

Signal 1

Five Chatbots Were Tested on Everyday Vegetarian and Vegan Nutrition Questions, and All Five Gave Answers That Could Hurt Someone (Published August 3, 2026)

Researchers asked 58 everyday vegetarian and vegan nutrition questions, the kind a client types into their phone at night, to five chatbots anyone can open for free: ChatGPT, Gemini, Microsoft Copilot, DeepSeek, and Doubao. That produced 290 answers. Five reviewers with clinical nutrition training, none of whom knew which chatbot wrote which answer, scored every one for safety, accuracy, and warmth, and rated how trustworthy and well-sourced it was using four standard scoring tools. Every single one of the five chatbots produced answers the reviewers judged potentially harmful, and no chatbot was meaningfully safer than the others. The harmful answers clustered in six places: which B12 to take and whether the source is reliable, how much iodine or selenium is too much, pregnancy and other sensitive life stages, people who already have a chronic condition, whether a symptom needs a real referral, and answers delivered with total confidence and no source you can check. Published in Frontiers in Public Health.

What this means for you

One boundary first, because it matters. This study asked plant-based questions only, so read the specific findings as plant-based findings. What travels beyond that is the shape of the failure, and the shape is the useful part. It is not that AI gets things wrong. It is where it goes wrong. Look at that list again. None of it is obscure science. That is your Tuesday. That is the question a client asks at 11pm, between sessions, when you are not there to answer it. The chatbot did not run out of information. It ran out of judgment. It kept answering when the right move was to stop and say go ask your practitioner. Issue 016 covered the first AI device the FDA cleared for patients to use directly, and the reason it passed review is that the language model is not allowed to decide anything on its own. The free app on your client’s phone has no such rule and no such review. Add one question to your intake form, and ask it again at the end of every session. “What have you asked an AI about your health since we last talked?” When they answer, check what they were told against those six trouble spots. That is your triage list. It takes about a minute and it will surface things your clients would never think to mention.

Signal 2

A National Health Nonprofit Is Turning Existing AI Guidance Into Free Working Tools, Because 82 Percent of Health Systems Have No Process for the AI They Already Use (July 21, 2026)

On July 21, 2026, the Digital Medicine Society, a nonprofit that writes practical standards for digital health, launched a project called Operationalizing AI Governance in Healthcare. It runs inside a formal collaborative community the group holds with the FDA’s device center, and about 30 partners are taking part, including the FDA itself, the American Psychological Association, Mass General Brigham, Stanford Health, UPMC, and Children’s Nebraska. What they are building is an open, free toolkit: risk checklists, scorecards, performance monitoring guides, and real examples of what worked. The first pieces are expected within about two months and the full set by the end of 2026. The reason they gave for building it is a 2025 Healthcare Financial Management Association survey of 230 health systems, which found that 82 percent had little or no governance process for the AI they were already using.

What this means for you

Eighty-two percent of health systems, the ones with compliance officers and legal departments and full IT staff, had no working process for AI they were already running. That is not a story about how far behind you are. It is close to the opposite.

Playbooks do exist. Issue 010 covered CHAI’s eight governance playbooks, Issue 012 covered the Joint Commission’s certification, and DiMe published its own AI implementation playbook last year. So guidance is not the missing piece. The gap is between guidance and daily practice, and DiMe says as much: this project is not another framework, it is an effort to convert guidance that already exists into checklists, scorecards, and workflows a person can follow. One caveat worth keeping straight, since the Brief holds itself to it: that survey is from 2025 and predates most of those playbooks, so treat 82 percent as a picture of the gap, not a verdict on any one document. Two things follow for you either way. If organizations with governance committees and real budgets are still working out how to turn principle into practice, then the gap you feel is a design problem and not a discipline problem. And when a vendor calls a tool “governed” or “responsible,” ask which standard and who checked, because right now those words carry no agreed meaning. Sign up for the project updates at dimesociety.org so the free tools reach you as they publish, then write your own one page while you wait. Four lines: which AI tools you use, what client information each one touches, what you check before anything goes out to a client, and who is responsible when it is wrong. That last line is your name. Write it down anyway. Seeing it in writing changes how carefully you use the tools.

Signal 3

Maine’s AI Therapy Ban Started July 29, and Colorado’s Rules for Licensed Providers Start August 12 (2026)

Maine’s law, LD 2082, passed in April and took effect July 29, 2026. Therapy has to come from a licensed professional. AI can handle back-office work and can support a licensed provider, but the provider stays responsible for whatever it does, and the client has to agree in writing before AI records or transcribes anything, and can take that permission back at any time. Offering AI therapy without a licensed professional counts as an unfair trade practice in Maine. Colorado’s law, HB 26-1195, was signed June 3 and takes effect August 12, 2026. It covers every licensed, certified, or registered psychotherapy provider in the state, and it is far more specific. AI cannot carry on therapeutic conversation with a client unless the provider is right there, live, in the conversation and actively engaged, not just monitoring in the background. The provider has to read and approve anything the AI recommends before it reaches the client. Written, revocable consent is required before any AI recording. The provider is responsible for everything the AI produces. Penalties reach 5,000 dollars in administrative fines and 20,000 dollars in civil penalties under Colorado’s consumer protection law, on top of licensing board discipline. Advertising AI psychotherapy without a regulated professional behind it is a deceptive trade practice.

What this means for you

Notice who actually gets punished here. Neither state built an AI agency, and neither one fines the software company. Maine uses its unfair trade practice law. Colorado uses its licensing boards and its consumer protection law. Both of them reach the human being with the credential, because that is the person the state already has a handle on. Issue 012 covered Maine’s law back when it passed; what changed this week is that it is live. Issue 018 counted 84 new state AI laws in six months and called the result a patchwork. This is what one of those laws actually asks of a real person on a Wednesday afternoon: get consent in writing before you record, and read what the machine wrote before you send it. If you are a health coach and not a licensed therapist, neither law binds you. Read them anyway. They show you the shape of what is coming for everyone who works one on one with people, and coaching is not going to be the last room they walk into. Write your recording and AI consent today, in one or two plain sentences. Say what gets recorded, what the AI does with it, how long you keep it, and that the client can decline or change their mind without losing their spot with you. Put it in your intake packet. Colorado’s therapists have until August 12. You get to pick your own date, and that is the only real difference.

The Pattern

Put the three side by side. The chatbots your clients are already using are not safe out of the box, and they fail on the everyday questions, not the rare ones. The big health systems, the ones with lawyers, mostly have no rules for the AI they are already running. And where rules do exist, they land on the licensed human being, not on the software company. Those three facts all point the same direction. Nobody is going to hand you a safe setup. There is no form you missed and no agency arriving to sort this out on your behalf. That sounds heavier than it is. Look at what this week actually asked of you: a question on your intake form, one consent sentence, a one-page list of your tools. Small, written, and entirely within your control. Here is the part worth sitting with. What makes health advice trustworthy right now is not better information, because information is free and, as this week’s study showed, frequently wrong in the places that matter most. It is a real person, with a name and a credential, who knows when to stop and say I am not sure, let us find out. That is what you actually sell. Say so plainly, and often.

One Thing You Can Do This Week

Open the last plan, protocol, or summary you sent a client. Mark every sentence that AI wrote or helped write. If you cannot tell anymore, that is your finding, and it is the important one. Then write the one sentence you would be comfortable saying out loud if that client asked you straight out whether AI wrote it. Put that sentence in your intake packet where they will actually see it. That is the whole task. Fifteen minutes.

Last updated: August 3, 2026

Where to start: CLEARED.

The practitioner’s briefing on AI governance for solo and small health practices. The free Brief and the free Eight-Element Self-Audit, in one place.

Go to CLEARED →

Missed an issue? Read every prior brief in the archive →

← All Issues