|
. . .
THE REGULATOR WHO WROTE A CONTRACT, NOT A BAN. A teenager types a hard sentence into an app her school handed her. Utah's answer to that moment is a signed contract from the state's AI policy office, run by a mathematician named Zach Boyd, and one clause says the machine has to go get a licensed human.
|
|
Photo: ADAPT Conference
|
Zach Boyd teaches applied and computational mathematics at Brigham Young University, where he runs a lab on AI and mathematical modeling in psychology, economics, and social networks. In April 2024, Utah named him Director of its Office of Artificial Intelligence Policy.
The office was created by Utah SB 149 in 2024, which the state calls the first office of its kind in the country. It does not regulate. It does not enforce. It develops legal frameworks and manages private-sector pilots, which sounds thin until you read what the legislature handed it.
Sandbox authority. Boyd describes it plainly: "The [state] Legislature created a sandbox authority for us so we can temporarily relax laws and kind of let the business community experiment, in ways that we're comfortable with, to develop new technology uses." The instrument has a name, a regulatory mitigation agreement, and it is a written contract between the state and a company.
Boyd's office chose AI in mental health as its first focus area because that is where the new applications were landing and where the state had concerns. In its first year it also published a 54-page guidance letter on AI best practices in mental health.
. . .
The first regulatory mitigation agreement the office ever signed was with ElizaChat, a Utah company whose app is offered by schools to teenage students to support mental wellness. ElizaChat says the app complements human therapists and personal relationships rather than replacing them. Signed November 2024. Announced by the Utah Department of Commerce on December 2, 2024.
Read the terms. ElizaChat must implement "a robust internal safety protocol for escalating severe cases to trusted adults." It must pilot with trusted testers before expanding its user base. It accepts a 30-day correction period if the app engages in conversations that constitute unlicensed mental health therapy. And it must "connect users with licensed therapists when conversations exceed what unlicensed staff can legally facilitate."
The state's published summary of the pilot adds: built-in risk assessments to identify distress, immediate escalation to trusted adults for high-risk situations, clear disclosures to users about AI use and limitations, and robust data privacy, anonymization, and security standards.
Boyd, in the state's announcement: "This is an example of how regulatory mitigation can empower innovative companies. Through our collaborative discussions with ElizaChat, we connected them with regulators to create a framework that safeguards consumers while allowing their service to flourish." Margaret Busse, the department's Executive Director, called it a step toward "fostering innovation while ensuring the safety and well-being of consumers in the AI landscape."
. . .
Boyd has said where his line is. "We certainly don't want the government to be engaged in any kind of censorship or prohibition of any kind of content, generally speaking." He wrote terms.
The ElizaChat agreement helped shape Utah HB 452, the Artificial Intelligence Amendments, which Utah calls the first state law in the country governing mental health chatbots. Governor Spencer Cox signed it on March 25, 2025. It took effect May 7, 2025.
HB 452 requires a mental health chatbot to disclose that it is AI. It bars suppliers from selling or sharing users' personal health information or their inputs, and from using those inputs to target advertising.
It also creates an affirmative defense, a safe harbor from suits over alleged harm, for a supplier that maintains a written policy stating the chatbot's purpose, its abilities, and its limits. Duties first, then the defense.
Boyd and Nina de Lacy, of the Huntsman Mental Health Institute at the University of Utah, wrote the experience up in a 2026 commentary in npj Digital Medicine, "The doctor is not in, but the Chatbot is."
|
For Legislators: The Utah sequence ran contract first, statute second. One company, one written agreement, escalation and licensed-therapist handoff as enforceable clauses, then a law shaped by what that agreement taught. Utah watched one product operate before it wrote the statute. HB 452 does not certify that any chatbot works.
For Builders: The ElizaChat clauses are a template a company accepted before shipping to minors. Escalation to trusted adults. Trusted testers before general release. A 30-day window to fix conversations that cross into unlicensed therapy. A route to a licensed therapist when the talk exceeds what unlicensed staff may legally do. No outcome data has been published. The design is the claim.
Source: Utah Department of Commerce, "Utah Department of Commerce's Office of Artificial Intelligence announces first regulatory mitigation agreement," December 2, 2024, https://commerce.utah.gov/2024/12/02/news-release-utah-department-of-commerces-office-of-artificial-intelligence-announces-first-regulatory-mitigation-agreement/; Utah Office of Artificial Intelligence Policy, ElizaChat agreement, https://commerce.utah.gov/ai/agreements/elizachat/; Utah HB 452, Artificial Intelligence Amendments (2025), https://le.utah.gov/~2025/bills/static/HB0452.html; de Lacy and Boyd, "The doctor is not in, but the Chatbot is: Utah's experience regulating mental health AI," npj Digital Medicine (2026), https://www.nature.com/articles/s41746-026-02580-y
|
. . .
THE CEO WHO TOLD THE PATIENT. Christopher Longhurst let software draft the reply to a patient's message, then required a physician to read it, edit it, and approve it before anything was sent. Then he did the part almost nobody does: he told the patient it had happened. His own study found the drafts did not make physicians any faster.
|
|
Photo: Seattle Children’s
|
Doctor Christopher Longhurst became Chief Executive Officer of Seattle Children's on January 5, 2026, chosen after a yearlong national search. Before that he was chief medical officer and chief digital officer at UC San Diego Health, and executive director of its Joan and Irwin Jacobs Center for Health Innovation.
The work that matters here happened at UC San Diego Health, which began generating AI draft replies to patient messages in the spring of 2023. Through the pandemic, physician inboxes grew three- to four-fold. Longhurst was senior author on what UC San Diego called the first randomized prospective evaluation of AI-drafted physician messaging, published in JAMA Network Open in April 2024.
The machine never sends anything on its own.
The health system's AI governance committee decided to tell people. Every such message carries a line: "Part of this message was generated automatically and was reviewed and edited by [name of physician]."
Longhurst co-authored the argument for that practice in NEJM AI, under the title "A Call for Disclosure When Using AI for Patient Communications." The piece notes that hundreds of institutions have adopted the same drafting tool with no standard on whether to tell patients.
. . .
The results did not flatter the program. The measured benefit was reduced cognitive burden, the weight of composing a reply, not the clock.
He published it anyway.
. . .
"We're caring for patients and sometimes hold their very lives in our hands," Longhurst said. "We have to be very thoughtful and measured in terms of how we implement these things."
On studies that rated chatbot replies more empathetic than doctors', he was direct. "Could a doctor be as empathetic as a chatbot? Undoubtedly. They just don't always have the time."
|
For Clinicians: The design is copyable this week. Draft, human edit, human approval, and a disclosure line on the outgoing message. The honest finding is that it bought cognitive relief rather than minutes, which is worth knowing before anyone promises a throughput number to an administrator. This program runs at UC San Diego Health, not at his current employer.
For Legislators: Disclosure here was not imposed by statute. It came out of the health system's own AI governance committee, and Longhurst argued for the practice in NEJM AI.
Source: Seattle Children's, "Christopher Longhurst named Chief Executive Officer," https://www.seattlechildrens.org/media/press-releases/christopher-longhurst-chief-executive-officer/; Millen, Tai-Seale and Longhurst, "A Call for Disclosure When Using AI for Patient Communications," NEJM AI 2025;2(6), https://ai.nejm.org/doi/full/10.1056/AIp2401167; UC San Diego Health, study announcement, April 15, 2024, https://www.sciencedaily.com/releases/2024/04/240415163745.htm; UC San Diego Today, "Introducing Dr. Chatbot," https://today.ucsd.edu/story/introducing-dr-chatbot
|
. . .
THE FOUNDER WHO MADE A HUMAN SEND EVERY TEXT. Drew Barvir built a school text line on an unusual rule: the AI never speaks to the student. It drafts, and a trained human coach decides what actually goes out. In 2026 an independent team ran a simulated teenager in crisis at his product. The escalation held.
|
|
Photo: Saul Bromberger / Stanford Graduate School of Business
|
Drew Barvir is co-founder and Chief Executive Officer of Sonar Mental Health, with an MBA from Stanford's Graduate School of Business, class of 2023. The product is called Sonny, a text-based wellbeing service offered through middle and high schools. Barvir is explicit that Sonny is not a therapist.
Start with the architecture. TechCrunch, February 2025: when students text their questions to Sonny, the AI suggests a response, but it is humans who are ultimately responsible for the message.
At that point the service ran on a team of six people with backgrounds in psychology, social work, and crisis-line support. Sonar says every conversation is led by trained Wellbeing Coaches, that those coaches work under the direct supervision of a licensed Clinical Team, and that each coach receives ongoing supervision from licensed mental health professionals.
The person on the other end of the text is a trained coach, not a licensed clinician. The license sits above them, in supervision.
Sonar raised a $2.4 million pre-seed round led by Nina Capital, announced February 2025. Sonny was then in nine school districts across California, Texas, Illinois, Michigan and Arkansas, serving more than 4,500 students.
Ninety-one percent of conversations happen outside school hours. The counselor's office dark, the building empty.
. . .
Then somebody else came to test it.
Common Sense Media's Youth AI Safety Institute, working with Stanford Medicine's Brainstorm Lab for Mental Health Innovation, published a risk assessment of AI mental health apps in 2026, covered by CNBC on May 28. The assessors ran simulated teen personas at the apps, trying to make them fail.
On Sonar it worked. When the researchers simulated a crisis, a real person called the student's emergency contact by phone within fifteen minutes, while the student was still in conversation.
The independent count now puts Sonar at 25,000-plus young people across nine states. Another company's app, Alongside, built the same way, reached 100,000-plus students in 19 states across grades 4 to 12. It also got a trained human on the phone in the same simulated crisis.
. . .
The same assessment did not rate everything it tested that way. Apps sold straight to teenagers, with no school and no clinician in between, landed in its worst category.
|
For Clinicians: Examine the supervision chain, not the technology. Sonny's coaches are trained, not licensed, and the clinical team supervises rather than replies. That is defensible if the supervision is real and documented, and paper if it is not. Sonar has published no outcome study. What it has is an independent tester who tried to break the escalation path and got a phone call in fifteen minutes.
For Legislators: The testable requirement is already written for you. Ask whether a product routes a crisis to a named human, and how long that takes when an adversarial tester triggers it. Two products here produced a phone call to a real emergency contact. Others did not. A statute can specify that architecture.
Source: TechCrunch, February 23, 2025, https://techcrunch.com/2025/02/23/this-mental-health-chatbot-aims-to-fill-the-counseling-gap-at-understaffed-schools/; Common Sense Media Youth AI Safety Institute, AI Mental Health Apps, https://institute.commonsensemedia.org/risk-assessments/ai-mental-health-apps; CNBC, May 28, 2026, https://www.cnbc.com/2026/05/28/some-ai-mental-health-apps-have-an-unacceptable-rating-for-teens-says-report.html
|
|