WASHINGTON, 22 AUG 2026 — By the end of 2025, 21 US states had enacted 33 laws governing artificial intelligence in healthcare, drawn from more than 250 bills introduced across 47 states. Legislatures continued through 2026.

The recurring provisions are narrow and consistent: restrict autonomous clinical decision-making, require that patients be told when an AI tool is involved, and in some cases require informed consent. There is no federal statute setting a floor beneath any of it.

The shape of the patchwork

21 statesWith enacted healthcare AI laws
33 lawsEnacted by end of 2025
250+ billsIntroduced across 47 states in 2025
No federal floorState law is the operative law

The gap between 250 bills introduced and 33 enacted shows how this patchwork came to be. A one-in-eight success rate is normal for legislation, but it means the result is not a considered national design but an accidental collection of what survived in various statehouses.

Restricting autonomous decisions is the substantive provision

Of the three recurring themes, the restriction on autonomous clinical decision-making is the one that changes products rather than paperwork.

The concern being legislated against is specific and reasonable. A system that denies a prior authorisation, triages a patient down a queue or recommends against a treatment without a clinician exercising judgement moves a consequential decision from a licensed professional to a vendor's model, and does so without the accountability structure medicine has built around licensure.

Requiring a human in the loop is the obvious response, and it is weaker than it appears. A clinician nominally reviewing hundreds of algorithmic recommendations a day, under production pressure, with no practical ability to interrogate the model, provides the legal form of oversight without its substance. Automation bias is well documented, and a review step that cannot realistically be exercised is a signature rather than a safeguard.

The laws that will matter are the ones specifying what review must involve — access to the reasoning, time to conduct it, and authority to overrule without penalty. Those are harder to draft and harder to comply with, which is why most statutes stop at requiring a human.

Disclosure is easier to legislate and easier to satisfy

Telling patients that AI was involved is the most common provision and the least demanding, and its value depends entirely on what the disclosure enables.

A notice that a hospital uses AI somewhere in its operations tells a patient nothing actionable. A notice that a specific decision about their care was informed by a specific tool, with a route to request human reconsideration, is a control. Most disclosure requirements sit closer to the first.

Informed consent goes further, and raises a question the statutes tend not to answer: what happens when the patient declines. If refusing AI involvement means a slower pathway or no pathway at all, consent is nominal. If it means a parallel human process must exist, the requirement carries real operational cost. The distinction is rarely spelled out.

The federal device regime already covers some of this, which is the complication

Clinical decision support software is not unregulated territory that states are filling. Parts of it already fall under federal medical device oversight, and the boundary is contested.

The long-standing distinction is between software that recommends while allowing a clinician to review the basis of the recommendation, and software that directs. The first has generally been treated more permissively on the reasoning that the clinician remains the decision-maker; the second looks more like a device making a clinical determination.

State statutes restricting autonomous clinical decisions are legislating on precisely that line, from a different direction and with different definitions. A tool can therefore sit on the permissive side of the federal boundary and still be constrained by a state requirement, or satisfy a state's human-review rule while remaining subject to federal obligations that have nothing to do with it.

This overlap makes compliance much harder than simply counting 21 statutes suggests. It also supplies the strongest argument for a federal standard: two regimes drawing the same line in different places is an unworkable arrangement.

Why fifty rulebooks is a worse outcome than one strict one

This fragmentation is a substantive problem, not an inconvenience, and it hurts smaller companies the most.

A large vendor selling nationally can afford a compliance function that tracks 21 regimes and configures behaviour per state. The cost is real but absorbable, and it functions as a moat: complexity favours incumbents who can pay for it.

A smaller vendor, even one with a better clinical tool, cannot afford this and must either restrict sales to a few states or build to the strictest common denominator. Neither outcome is good for patients, and the second is indistinguishable from a national standard that nobody deliberately chose.

Health systems operating across state lines inherit the same problem in reverse, needing the same clinical workflow to behave differently depending on where the patient is sitting.

What this means for regional health systems buying American software

Hospitals and insurers across ASEAN procure clinical software from American vendors, so the product decisions shaped by these statutes are exported globally.

A vendor that builds mandatory clinician-review steps and patient disclosure into its product to satisfy US state law generally ships that behaviour everywhere, for the same reason any global product converges on its strictest market. Buyers here are therefore likely to receive American procedural safeguards without local regulators having required them.

While this is mostly beneficial, the safeguards are calibrated to American clinical staffing, liability exposure, and consent norms. A mandatory review step designed for a market with a particular physician-to-patient ratio behaves differently in a system with a different one, and a consent framework built around American malpractice risk is not obviously the right one elsewhere.

The practical question at procurement is which behaviours are configurable and which are hard-coded to a US requirement, because the answer determines whether the tool fits local practice or merely imports someone else's.

What remains unconfirmed

Which 21 states and which 33 laws is not enumerated in the material reviewed, and the count is stated as of end-2025 while legislation continued through 2026 — the current total is likely higher and is not given.

It is also unclear how many laws are in force versus enacted with future effective dates. Key details are missing, such as how the statutes define autonomous clinical decision-making, what enforcement mechanisms they include, and whether any enforcement has occurred. The interaction with existing federal medical device regulation is also not established.

What to watch for

Whether any state moves beyond requiring a human to specifying what review must involve is the development that would change products rather than documentation.

Federal preemption is the second major development to watch. A national standard would resolve the fragmentation, but it would also fix the level of regulation — making the fight over preemption a fight about stringency disguised as one about jurisdiction.

Finally, watch whether vendors begin publishing state-configurability matrices. If they do, fragmentation will have become a product feature — the point at which a temporary problem hardens into permanent architecture.