← All posts
Regulation

Three Healthcare AI Policy Models Pharma Teams Should Understand

A prescribing pilot, a rule against deceptive professional claims and a therapy-specific law solve different problems. Here’s how to compare them accurately.

VizLoop Editorial Published · 2026-10-10

Public sources checked October 10, 2026.

A useful comparison of healthcare AI policy starts with what each measure regulates. Utah’s sandbox can grant limited relief to a named participant. California’s AB 489 targets language that misrepresents licensed healthcare status. Illinois’s Wellness and Oversight for Psychological Resources Act governs specified AI uses in therapy and psychotherapy.

For a pharma team planning patient-facing AI, these are three different questions: what the system may do, how it presents itself and which activities require a licensed professional. Treating the states as points on a single scale from permissive to restrictive misses those distinctions.

Utah tests defined activities under individual agreements

Utah’s regulatory-mitigation process is specific to the participant and the activity described in its agreement. It can adjust how identified state requirements apply during a limited test, while obligations outside the agreement continue to apply. The state says participation does not confer product endorsement. Utah Office of AI Policy FAQ

A pharma organization evaluating an AI vendor should therefore ask to see the relevant agreement, the current operating stage and any amendments. A vendor’s participation in a pilot would not establish that every service it sells is covered, or that another organization can operate under the same terms.

The practical lesson is about scope. Record exactly which function has been authorized and who the authorization covers. Keep that record separate from the commercial description of the wider product.

California addresses misleading professional identity

California’s AB 489 took effect on January 1, 2026. It applies existing restrictions on protected professional terms, letters and phrases to developers or deployers that use them in AI advertising or functionality. It also prohibits wording that implies AI-delivered care, advice, reports or assessments are being provided by an appropriately licensed natural person. California Board of Psychology advisory, Business and Professions Code provisions reproduced by the Board of Pharmacy, pages 52–53

That focus should guide the review. Look at the assistant’s name, opening message, descriptions of its role and language used when answering a patient. If a person reviews an output, describe the actual review rather than allowing the interface to imply that the AI itself holds a professional license.

For example, a team reviewing a proposed “AI doctor” persona should examine the professional-status claim as well as the information it supplies. A product-information assistant can raise a different set of questions from a service that claims to assess an individual patient. The legal analysis needs the actual wording and functionality.

AB 489 should not be summarized as a blanket ban on healthcare AI or on every form of AI-supported clinical work. Its professional-identity provisions answer a more specific question. Other requirements may apply to the service.

Illinois sets therapy-specific practice boundaries

Illinois’s Wellness and Oversight for Psychological Resources Act, Public Act 104-0054, took effect August 1, 2025. Its scope is therapy and psychotherapy, with definitions and exceptions that matter. The Act permits specified administrative and supplementary AI support under a covered licensed professional’s responsibility. It prohibits those professionals from allowing independent AI therapeutic decisions, direct AI therapeutic communication with clients, unreviewed therapeutic recommendations or plans, and emotion or mental-state detection. Illinois Public Act 104-0054, Sections 10–20

The Act also has specific notice and consent requirements when AI supplementary support involves recording or transcribing a therapeutic session. Exceptions include religious counseling, peer support, and public self-help or educational resources that do not purport to offer therapy. Physicians are excluded from its defined term “licensed professional.” These details make it inappropriate to describe the law as a general restriction on all medical AI. Illinois Public Act 104-0054, Sections 10, 15 and 35

For teams designing a support experience, the next question is whether its actual interactions fall within the law’s defined activities. A broad label such as “wellness assistant” cannot answer that question. Review the intended conversation, the population served and what happens when the user seeks individualized support.

Three columns compare selected Utah pilot rules, California professional-identity restrictions and Illinois therapy-specific AI law.
Selected policies address different regulatory questions. This is not a complete legal map or a ranking of states by permissiveness. Sources checked October 10, 2026. Sources: Source 1, Source 2, Source 3, Source 4
Full text of this figure

SELECTED HEALTHCARE AI POLICIES Three models. Different questions. A framework for reading the policy landscape without a permissive–restrictive ranking. UTAH Bounded experimentation What can a named pilot test under specific safeguards? Participant-specific regulatory relief CALIFORNIA Professional identity Could the system falsely imply licensed human healthcare advice? AB 489 Effective January 1, 2026 ILLINOIS Therapy boundaries How may AI be used in therapy and psychotherapy services? PA 104-0054 Effective August 1, 2025 Selected policies, not a complete legal map. Interpretive summaries, not legal advice. Sources: Utah Authorized Pilots · California Board of Pharmacy, 2026 Lawbook (AB 489) Illinois General Assembly, PA 104-0054 · Status checked October 10, 2026

Compare functions before comparing states

A useful review brief begins with the product rather than a headline about the law. Document:

  • The action. Does the system retrieve information, summarize it, recommend an individual action or authorize a clinical step?
  • The representation. What does its name, interface and response language imply about the source of expertise?
  • The people and place. Who can use it, where are they located and which entity provides the service?
  • The human role. Who reviews which outputs, when does review happen and how can a user reach that person?
  • The evidence. Which source supports each clinical, product and regulatory claim, and when was it last checked?

These are questions for a cross-functional review, not a substitute for jurisdiction-specific legal advice. They help commercial, medical, regulatory and product teams give counsel a concrete service to assess.

They also help distinguish a deployment decision from an observation about public AI answers. A company operating its own patient-facing assistant has different controls from a company monitoring how an independent AI service describes its medicines. Findings from one context should not be treated as permission to act in the other.

Give reviewers the claim and its context

For pharma teams, an actionable AI-answer finding includes the exact statement, the question that produced it, the source cited and the relevant approved product information. Reviewers can then assess whether the answer omits a limitation, overstates evidence or presents individualized guidance that needs a different response.

VizLoop gives pharma teams dated AI answers, product mentions and cited sources alongside versioned FDA label evidence. Teams review that material, compare answers with their communications and remeasure after making changes. Clinical and legal judgment are still needed to decide what a finding means and how to respond.

Discuss your product.

This article compares selected measures, not the complete law of any state. It is general information, not legal or medical advice.

healthcare AI state laws California AB 489 Illinois healthcare AI law Utah AI sandbox
Read the latest posts

Email subscriptions are paused. All posts remain available on the blog.

Related posts