Where support ends and treatment begins

Abstract
A conversational wellbeing system can produce conversations whose transcript does not allow support to be distinguished from treatment; the distinction resides in the scope the system declares and in the evidence that holds that declaration up. As of July 20, 2026, four US states—Illinois, Nevada, Rhode Island and Maine—prohibit an AI system from providing therapy to the public and four others—Utah, New York, California and Nebraska—regulate the practice without banning it; the Future of Privacy Forum’s chatbot legislation tracker follows 98 chatbot-specific bills across 34 states, plus three federal proposals. A KFF survey fielded between February 24 and March 2, 2026 on 1,343 US adults found that one in six had turned to AI in the past year for information or advice about their mental health. The National Academy of Medicine’s review of mental health chatbots records the absence of consensus on a chatbot’s capacity to take the place of therapy and the absence of clinically validated therapeutic chatbots. Scope delimitation admits operationalization: a minimum evidence threshold for any transfer, the bounding of each transfer to a population, a purpose and a context, communication tied to the level of evidence attained, and a certification revocable through periodic audit.
Introduction
A conversational system that asks how the day went, reflects back what it hears and suggests a breathing exercise may be offering support or may be stepping into the ground of treatment. The transcript of the conversation rarely settles it. What separates one from the other is the scope the system declares and the evidence that holds that declaration up.
Regulators have reached that boundary from the outside and have started with the label: with what a system may claim about itself before it reaches anyone. As of July 20, 2026, four US states prohibit an AI system from providing therapy to the public, and four others regulate the practice without banning it.
Regulatory framework in the United States and the European Union
The map of state bans places in the first group Illinois, whose law was signed on August 1, 2025, Nevada, in force since July 1, 2025, Rhode Island, signed on June 22, 2026, and Maine, in force since July 29, 2026. In those four states, therapy is reserved to licensed professionals and an AI system cannot act as the therapist.
The second group regulates the practice without banning it. Utah requires disclosure that the user is talking to an AI before access and whenever asked. New York repeats the notice every three hours and requires referral to crisis services on expressions of self-harm. California adds crisis-response protocols and break reminders for minors. Nebraska, with compliance required from July 2027, adds the duty to route users to crisis resources.
The chatbot legislation tracker at the Future of Privacy Forum follows 98 chatbot-specific bills across 34 states, plus three federal proposals. In California, Senator Steve Padilla filed SB 903, a state bill that would bar companies from advertising a chatbot as therapy and would subject any therapeutic decision to review by a licensed professional. The regulatory sequence begins with the commercial promise—what a system may say about itself before reaching anyone—and precedes the regulation of the technical quality of its answers.
The KFF tracking poll on health information and trust, fielded between February 24 and March 2, 2026 on a nationally representative sample of 1,343 US adults, found that one in six had turned to AI in the past year for information or advice about their mental health. Among those under 30, the share rises to 28%.
All that legislation is American. In Europe the frame is Regulation (EU) 2024/1689, whose transparency obligations have applied since August 2026 and whose high-risk regime arrives in December 2027.
Planes of distinction between support and treatment
A supportive conversation and a therapeutic one can share vocabulary, rhythm and the exercises they suggest. The difference sits outside the text, across four planes.
- Declared intent. What the system says it is for, and what it expressly rules out.
- The framework of responsibility. A licensed professional works within a scope of practice, a duty of care, peer supervision and a complaints route.
- The attribution of responsibility for harm. An unfortunate reply carries different consequences depending on who signs it and under what cover.
- The expectation of the person using the system. The expectation someone brings into a conversation conditions the weight they give what they receive.
The National Academy of Medicine review of mental health chatbots describes the state of the field: there is no consensus that a chatbot can take the place of therapy, and clinically validated therapeutic chatbots do not yet exist. An organization that deploys or certifies a conversational system therefore needs a delimitation criterion of its own, because the surface of the conversation does not supply one.
Declared scope as an operating criterion
A system that presents itself as support is making a checkable claim about the scope for which it has been validated. The four states that ban AI-provided therapy and the bills pursuing misleading advertising work that same boundary from the commercial register inward: the label a system gives itself is a claim about its evidence, and it is settled before the first line of conversation is written, while it can still be backed by a file.
At yeshcube, that decision is ordered by the ERL scale, and its function is restrictive. No solution is transferred below ERL-3: a solution that works in the laboratory, is well received in testing and is technically feasible remains untransferred while its evidence falls short of that level, however much commercial demand exists.
Each transfer is bounded to a specific population, purpose and context: taking the same solution to another case requires reviewing requirements, risks and evidence from the start, so a validation in offices does not authorize a deployment in a classroom.
The same criterion settles what may be claimed about a solution: a level of evidence supports one kind of statement and rules out the rest, and communication stays tied to the same file that authorizes the transfer. Validation runs across six dimensions, regulatory and ethical compliance among them, with a scientific committee and an ethics committee that can veto progress and stop rules that halt it in the face of harm or inconsistent results.
Limitations of the available evidence
The regulatory map corresponds to a cutoff date, July 20, 2026, over a legislative landscape still in motion: the Future of Privacy Forum count records bills, with no indication of how many will be enacted, and California’s SB 903 is a state bill pending passage.
The usage figure comes from a single cross-sectional, self-reported survey of the US population: it describes the frequency of recourse to AI, without informing on its effects, and transferring it to other populations would require a measurement of their own.
The National Academy of Medicine review records the absence of clinically validated therapeutic chatbots at the time of the review; that state of the field may change with new trials.
The four planes of distinction and certification with revocation constitute frameworks of criteria; their efficacy as protection mechanisms lacks a specific evaluation in the sources reviewed.
Conclusions
The distinction between support and treatment in a conversational system is settled by the declared scope and by the evidence that holds it up; the transcript of the conversation does not suffice to establish it. US regulation converges on the commercial promise: four states reserve therapy to licensed professionals and pending bills pursue the advertising of a chatbot as therapy. The state of the evidence, with no clinically validated therapeutic chatbots according to the National Academy of Medicine review, makes scope delimitation a decision prior to deployment. That delimitation admits operationalization through a minimum evidence threshold, the bounding of each transfer to a population, a purpose and a context, communication tied to the evidence file, and a revocable certification.
The hub’s integration certification: Somia Within
When another organization wants to build conversational AI into its product, the threshold has to exist before the contract. Somia Within is the seal with which yeshcube approves those integrations, and its operating content is the list of what it blocks.
It requires at least ERL-3 for an active transfer: evidence replicated across several real contexts, robust aggregated samples, statistically significant results, evaluation of efficacy, safety, usability and acceptance, independent peer review, and full regulatory compliance. It leaves out ideas, unbuilt prototypes and projects at the conceptual stage: a demonstration that works does not reach the threshold.
The committees can require changes rather than approve. The seal is audited periodically and revoked in the face of degraded standards or breached principles, so certification expires with the product’s behavior. The same bar governs the hub’s own products and those of external manufacturers; that absence of internal exceptions is the condition for holding a third party to it. A certification without a revocation clause lacks discriminating value between products that maintain the standards and products that have degraded them.
On the system’s behavior the requirement is explicit: it keeps its condition as artificial intelligence visible, does not present itself as a person, does not simulate feeling and does not replace professional care. When a situation exceeds its scope, it refers on or stops.
Collaborating on the validation of integrations
yeshcube develops this work within Allies, its scientific collaboration system, with four partner types and three principles: value for value, traceability and independence. No partner can veto a publication.
Fixing where support ends calls for evidence no single team assembles alone. It is of interest to scientific teams researching the validation of conversational systems, to manufacturers wanting to incorporate the architecture under checkable criteria, and to health or education organizations needing to tell an accredited integration from one that only works in a demonstration.
References
- Psychology.com. Map of state bans on AI-provided therapy. Verified as of July 20, 2026.
- Future of Privacy Forum. 2026 chatbot legislation tracker. Count of 98 chatbot-specific bills across 34 states, plus three federal proposals.
- Route Fifty. Coverage of California’s SB 903, filed by Senator Steve Padilla. 2026.
- KFF. Tracking poll on health information and trust: use of AI for health information and advice. Survey fielded from February 24 to March 2, 2026, nationally representative sample of 1,343 US adults.
- National Academy of Medicine. Review of AI chatbots for mental health.
- European Union. Regulation (EU) 2024/1689. 2024.
Frequently asked questions
What separates support from treatment in a conversational system?
The scope the system declares and the evidence that holds that declaration up. A supportive conversation and a therapeutic one can look alike on the surface, and they differ in declared intent, the framework of responsibility, who answers for harm, and what is promised to the person using it.
What are US states regulating?
As of 20 July 2026, Illinois, Nevada, Rhode Island and Maine prohibit an AI system from providing therapy, which is reserved to licensed professionals. Utah, New York, California and Nebraska regulate without banning, requiring disclosure that the user is talking to an AI, referral on expressions of self-harm, and protections for minors.
What does Somia Within certification require?
For an active transfer it requires at least ERL-3, which means evidence replicated across several real contexts, robust aggregated samples, statistically significant results, evaluation of efficacy, safety, usability and acceptance, independent peer review, and full regulatory compliance. It does not certify ideas or unbuilt prototypes.
What happens if an integration stops meeting the criteria?
The seal is audited periodically and can be revoked if degradation of standards or breach of principles is found. The scientific and ethics committees can require changes rather than approve an integration, and the same bar applies to the hub's own products and to those of external manufacturers.


