EXPLAINER

Who regulates a mental health app? Mostly no one, and increasingly the states

Most wellness apps make no disease claim and face no federal review. Into that gap, US states are writing their own AI-in-mental-health laws — four already diverge, leaving users unevenly protected.

Most mental health and wellness apps are regulated by essentially no one at the federal level, because they are careful not to claim to treat a disease — and into that vacuum, US states have begun writing their own rules, which already disagree with each other [s1]. The result is a patchwork: uneven protection depending on where a user lives, and uncertainty for the companies building the tools [s1]. For a reader, the practical takeaway is that "available in the app store" carries no promise that anyone has vetted the product for safety or effectiveness.

The line that decides everything: the claim

Oversight of health software turns on what an app says it does. An app that claims to treat, diagnose or manage a specific disease is a medical device and must be authorised — the pathway behind FDA-cleared prescription digital therapeutics. An app that stays in the language of "wellness," "support," "stress" or "mood" makes no disease claim and falls outside that review entirely. The same regulated line now runs through wearables, where a device can estimate a physiologic value without review but not tell you what it means. Almost the entire consumer mental health app market lives on the unregulated side of that line, by design.

That matters because the gap between "wellness tool" and "treatment" is exactly where the risk lives for a distressed user who cannot tell the difference. A person in crisis does not consult the marketing disclaimer; they use the app as help. And the safety scaffolding on that side of the line is thin: a 2026 review of purpose-built mental health chatbots found human oversight limited, crisis-referral protocols mostly underdeveloped, and adverse-event monitoring sparse, with documented failures including missed suicidal ideation and inaccurate clinical information [s3]. Those are the harms an oversight regime would exist to prevent, occurring in products that no oversight regime currently covers.

The states are moving first

With no federal framework, individual states have started to legislate, and a 2026 analysis of the statutory text in four of them — Illinois, Utah, New York and Nevada — found them taking fundamentally different approaches [s1]. Two broad strategies emerged. One regulates the use of AI in clinical contexts — governing what a licensed provider may do with the technology. The other regulates the technology itself, regardless of setting [s1]. Some states have combined elements of both [s1].

The divergence is not cosmetic; it reflects genuine disagreement about where the risk sits — in the clinical relationship, or in the tool [s1]. And because AI for mental health operates across both the clinical and consumer domains at once, the analysis argues that neither approach alone can address the full range of risk [s1]. The consequences the authors identify are the predictable ones of a patchwork: uneven protections for consumers, and regulatory uncertainty for developers, vendors, deployers and clinicians who must somehow comply with a different rule in every jurisdiction [s1]. Their proposed remedy is a coordinated, risk-based federal regulatory floor — a baseline of protection that applies everywhere — rather than fifty separate ceilings [s1].

A pattern beyond mental health

The same oversight gap has been flagged in adjacent app categories. A 2025 JAMA viewpoint made the case that apps marketed for substance-use reduction also need oversight they do not currently receive [s2] — another domain where products intervene in a serious health condition while sitting outside device regulation. The common thread is that the commercial incentive runs toward the unregulated side: a "wellness" claim reaches the market faster and cheaper than a "treatment" claim that must be proven to a regulator.

What it means for a reader

Treat the regulatory status of a health app as unknown unless it is stated. A product that claims to treat a diagnosed condition and cites FDA authorisation has cleared a real bar; the vast majority of apps, which speak in wellness terms, have cleared nothing and may still be governed differently — or not at all — depending on the user's state [s1]. That does not make them worthless, but it shifts the burden of judgement onto the user, particularly for anyone in genuine distress, where the products are least supervised and the stakes are highest [s1][s3]. The oversight is coming, unevenly and from the states first; for now, the buyer does the vetting.

Sources

  • [s1] Governing AI for Mental Health: Fragmented State Approaches and the Case for a Federal Framework — JMIR (2026)
  • [s2] The Need for Oversight Over Apps for Substance Use Reduction — JAMA (2025)
  • [s3] Safety Mechanisms and Risk Mitigation in Generative AI Mental Health Chatbots: A Systematic Scoping Review — Healthcare (2026)

Sources

  1. Governing AI for Mental Health: Fragmented State Approaches and the Case for a Federal FrameworkJMIR (Journal of Medical Internet Research) , July 28, 2026
  2. The Need for Oversight Over Apps for Substance Use ReductionJAMA , December 1, 2025
  3. Safety Mechanisms and Risk Mitigation in Generative AI Mental Health Chatbots: A Systematic Scoping ReviewHealthcare , May 20, 2026
Related coverage