No AI mental health chatbot on the consumer market today is FDA-regulated as a medical device for treating a mental health condition, and 2026 is the year that gap between regulatory status and real-world use finally triggered a legislative response. The response has come almost entirely from states and from the FTC, not from a comprehensive federal framework, which matters for how founders should think about compliance risk going forward.
What actually triggered the crackdown
Stateline reported that states began passing laws restricting AI chatbots from offering mental health advice to young users following a documented pattern of people, including minors, harmed after extended interactions with chatbots that were never designed or validated as therapeutic tools. The FTC opened a formal inquiry in September 2025, issuing 6(b) orders, a compulsory information-demand tool, to seven companies operating consumer-facing AI companion chatbots, seeking data on how they measure, test and monitor negative psychological impacts on users. That is a meaningfully different posture than FDA device regulation: it treats the harm as a consumer protection issue rather than a medical device safety issue, because most of these products were never marketed as medical devices in the first place.
The clinical problem underneath the policy problem
KFF Health News's reporting captures the core dynamic: people turn to AI chatbots for therapeutic conversation because they are available at 3am, free or cheap, and nonjudgmental, and some genuinely value that. The same accessibility is the risk. A chatbot has no license to lose, no duty-to-warn obligation triggered by expressed suicidal ideation in the way a licensed clinician does, and no clinical supervision structure. It can also, per the adversarial hallucination research documented in general medical AI evaluations, be steered by a user's own framing toward validating harmful ideation rather than challenging it, precisely the failure mode a trained clinician is taught to recognize and interrupt.
What the new state laws actually require
State legislative approaches passed or advancing in 2026 cluster around a few common mechanisms:
- Age-based restrictions prohibiting chatbots from providing mental health advice or engaging in extended emotionally intensive conversation with users under 18 without parental controls or clear limitations.
- Mandatory crisis-response protocols, requiring any chatbot engaging in mental-health-adjacent conversation to detect crisis language and route the user to a real human resource, such as the 988 Suicide and Crisis Lifeline, rather than continuing the conversation autonomously.
- Disclosure requirements, mandating that users be told clearly and repeatedly that they are talking to an AI system, not a licensed clinician, countering the tendency of long-running conversational agents to feel more like a relationship than a tool.
- Marketing restrictions, limiting how directly a general-purpose or companion chatbot can market itself as therapeutic or as a substitute for professional mental health care.
What federal action has, and has not, done
On the medical device side, the FDA finalized a rule in June 2026 under 21 CFR Part 882 addressing neurological and psychiatric device classification, part of a broader effort to clarify where AI-enabled mental health tools sit within existing device categories. That rulemaking is narrower than a blanket chatbot regulation: it clarifies classification for tools explicitly positioned as medical devices, which most consumer mental health chatbots are deliberately not, since device classification brings clinical evidence requirements most of these products have not generated and are not resourced to generate.
That leaves a structural gap: a product can offer what functions, in practice, as ongoing mental health support, market itself carefully to avoid triggering device classification, and fall almost entirely under state consumer protection law and the FTC's general authority rather than under any healthcare-specific safety framework.
What this means if you are building in this space
- Do not rely on staying outside device classification as your primary safety strategy. It may protect you from FDA review, and it will not protect you from state legislative restriction or FTC 6(b) scrutiny, both of which are advancing faster.
- Build crisis detection and human handoff as a first-class feature, not a legal disclaimer. The state laws are converging on this requirement, and it is also, simply, the right thing to build.
- Age-gating and parental controls are now table stakes, not a differentiator, for any product that could plausibly be used by a minor.
- Expect FTC data requests if you operate at meaningful scale in the companion or emotionally supportive chatbot category. The 6(b) inquiry data will likely shape the next round of rulemaking, and companies with weak monitoring documentation today are building future liability.
The takeaway
The regulatory response to AI mental health chatbots in 2026 is a patchwork built quickly in response to real harm, not a considered federal framework. That patchwork will keep tightening. Companies that treat crisis safety and transparent disclosure as core product requirements now, rather than after the next state law passes, will spend far less on compliance retrofits than the companies still betting on staying below the regulatory radar.





