Considerations for Policymakers
- Set the stage for success. Use flexible, risk-based approaches rather than rigid mandates, and offer safe harbors tied to recognized risk management frameworks.
- Reduce confusion and compliance costs. Align definitions of key terms across California laws and, where possible, with other states.
- Incentivize innovation through nuanced regulation. Require transparency that helps users make informed decisions about AI tools while protecting competitively sensitive information.
As artificial intelligence increasingly reshapes health care delivery, California policymakers face a critical challenge: crafting regulation that protects patients while fostering innovation that can improve the system for all. Researchers with the Duke-Margolis Institute for Health Policy reviewed 26 recent California bills affecting AI in health care, in addition to relevant legislation from other states and the federal government. Their report Key Themes in California Health AI Policy, includes considerations for future lawmaking.
The Landscape at a Glance
In April 2026, CHCF held a briefing in Sacramento about health AI policymaking.
At the federal level, the current administration is emphasizing rapid AI innovation and reducing regulatory barriers, which shifts risks and liability to health care organizations that deploy AI tools and their patients.
All 50 states introduced AI legislation in 2025, and California has been among the most active. Of the 26 California bills analyzed, seven were specific to health care AI, and 19 were related to foundation or frontier models, which may be used within some AI health tools. Among the themes emerging from this review, four stand out as particularly significant: governance and risk management frameworks, disclosing the use of AI, transparency, and combating bias.
Four Key Themes and What Policymakers Should Know
1. Governance and Risk Management: Flexibility Over Rigidity
Nine of the bills analyzed addressed risk management and governance, and four were enacted. Because AI evolves quickly, requiring organizations to follow structured risk management frameworks — rather than prescribing specific technical mandates — gives the field room to adapt. Policymakers can incentivize best practices by offering safe harbors: legal protections for entities that follow recognized frameworks such as the AI Risk Management Framework, developed by the National Institute of Standards and Technology. Texas and Colorado have enacted models worth studying. Safe harbors give clear direction to less-resourced health systems and smaller developers, helping ensure that effective AI tools reach safety-net providers and the communities they serve, not just large, well-resourced health systems.
2. Disclosing the Use of AI: Meaningful, Not Mechanical
Thirteen bills included disclosure requirements, and eight were enacted. Disclosure serves important goals: ensuring patients know when AI is involved in their care, enabling them to request human review, and preventing fraud. However, policymakers should design disclosure requirements that remain meaningful over time and avoid becoming so common that patients stop paying attention. Disclosure is most effective when it is tailored to the level of AI involvement, provides clear instructions for reaching a human provider, and includes information on how to appeal AI-assisted decisions.
3. Transparency: Balancing Accountability with Practicality
Seven bills included transparency requirements, and three were enacted. Common elements include disclosing the purpose of an AI tool, the data used to train it, performance measures, and risk mitigation steps. Transparency helps health systems make informed purchasing and deployment decisions and helps patients understand the basis for AI-assisted recommendations. At the same time, developers have legitimate concerns about trade secrets and compliance burden. One state’s promising approach allows sensitive technical information to be submitted confidentially to a state agency for certification rather than disclosed publicly.
4. Combating Bias: Ambitious Goals, Realistic Pathways
Four bills focused on AI-related discrimination and bias; none were enacted. Addressing bias in health AI is essential to advancing health equity, but legislation must be carefully constructed. Bills should precisely define “bias” and specify protected populations, since vague language can create unintended consequences. For example, an AI tool that significantly narrows a health equity gap but does not eliminate it entirely could be deemed noncompliant under some proposed standards. This could potentially block tools that would meaningfully improve outcomes for underserved communities. A section of the Affordable Care Act offers a useful model, as explained in the slide deck.
Three Key Considerations for Policymakers
Set the stage for success
Use flexible, risk-based approaches rather than rigid mandates. Offer safe harbors tied to recognized risk management frameworks to encourage responsible adoption across all types of health systems, including safety-net providers.
Reduce confusion and compliance costs
Align definitions of key terms across California laws and, where possible, with other states. Consistent language makes compliance more manageable for smaller developers and community health organizations.
Incentivize innovation through nuanced regulation
Well-designed regulation can drive better access, outcomes, and innovation. Establish clear liability frameworks that place accountability on the entities best positioned to act. Require transparency that helps users make informed decisions about AI tools while protecting competitively sensitive information. Direct state investments toward AI applications with the greatest potential to advance health equity and expand access.
To learn more, including specific legislative examples across the four themes, review the full report below.






