AI is becoming increasingly common in clinical practice, from ambient documentation tools and imaging analysis to diagnostic support and treatment recommendations. As adoption increases, an important question has emerged: Must physicians tell patients when AI is being used?
The answer is increasingly yes, but the requirement depends on how AI is used and where the physician practices.
As of this publication, there is no single federal law requiring physicians to disclose every use of AI in clinical practice. However, existing informed consent, privacy, and professional standards may require disclosure when AI materially affects a patient's care. The legal landscape is evolving rapidly, and several states have enacted specific AI disclosure requirements.
State requirements vary considerably. Take the following examples.
California
California AB 3030 requires physician offices, clinics, and health facilities using generative AI to generate written or verbal patient communications pertaining to clinical information to include:
An important exception applies when the AI-generated communication has been reviewed by a licensed or certified healthcare provider.
Texas
Effective January 1, 2026, the Texas Responsible Artificial Intelligence Governance Act (HB 149) requires healthcare providers using an AI system in relation to healthcare services or treatment to provide the required AI disclosure to the patient or the patient's representative no later than when the service or treatment is first provided.
Emergencies are excepted until disclosure is reasonably possible.
Texas's law is particularly noteworthy because it broadly applies to an "artificial intelligence system" used in relation to healthcare services or treatment.
Utah
Utah’s Artificial Intelligence Policy Act (SB 149, as amended by SB 226) requires licensed professionals to disclose when a patient is interacting with generative AI in a "high-risk" interaction. Examples include interactions involving:
For verbal interactions, disclosure must occur at the beginning of the interaction. For written interactions, disclosure must occur before the interaction begins.
Even when state law does not prescribe specific disclosure requirements, a prudent risk management approach is to disclose AI use when it meaningfully influences:
The more directly AI affects a patient's clinical care, autonomy, privacy, or decision-making, the stronger the case for disclosure.
When disclosure is appropriate, the explanation should be understandable rather than highly technical. The disclosure may include:
Transparency regarding AI use is increasingly being viewed as both an ethical best practice and, in some cases, a legal requirement. Failure to disclose AI involvement when it significantly influences patient care may create concerns related to:
As AI adoption grows, disclosure practices may become increasingly important in demonstrating transparency and maintaining patient confidence.
Healthcare organizations should establish written AI policies addressing when disclosure and consent are required. These policies should be reviewed and updated regularly as state laws and regulatory expectations continue to evolve. Organizations should also monitor developments in applicable state laws to ensure ongoing compliance with emerging requirements.
The legal requirements surrounding AI disclosure continue to evolve, but the overall trend is toward greater transparency. Even when disclosure is not expressly required by law, physicians should carefully evaluate whether AI materially influences patient care, communication, privacy, or decision-making. When it does, clear disclosure may help support informed decision-making, strengthen patient trust, and reduce risk.
Healthcare organizations that proactively develop AI governance and disclosure policies will be better positioned to adapt as regulatory requirements continue to develop.
No. As of this publication, there is no single federal law requiring disclosure of every use of AI in clinical practice.
No. AI disclosure requirements vary significantly from state to state.
In many situations, disclosure may be a prudent risk management practice, particularly when AI materially influences patient care or communication.
Examples may include AI systems used for patient communications, diagnostic support, image interpretation, risk assessment, treatment recommendations, or other functions that materially affect patient care.
Transparency helps support informed decision-making, patient trust, privacy expectations, and compliance with evolving legal and professional standards.
Looking for more guidance? Explore our risk management catalog and practice resources. If you're not currently insured with PICA, fill out our online form to receive a free, no-obligation quote.
Disclaimer: The information contained on the PICA Blog does not establish a standard of care, nor does it constitute legal advice. The information is for general informational purposes only. We encourage all blog visitors to consult with their personal attorneys for legal advice, as specific legal requirements may vary from state to state. Links or references to organizations, websites, or other information is for reference use only and do not constitute the rendering of legal, financial, or other professional advice or recommendations. In the event any of the information presented conflicts with the terms and conditions of any policy of insurance offered by ProAssurance Insurance Company of America, the terms and conditions of the actual policy will apply. All information contained on the blog is subject to change.