An outpatient psychiatrist finishes an 18-patient Thursday. Between visits they paste a vignette into a consumer model. The model returns a note skeleton, a differential, a patient letter, and a sentence that sounds like a plan. Four jobs. Pieces of each move toward the chart. The addendum reads “reviewed with AI assistance.” Four jobs went in. One line came out.

This fictional composite is not a patient case. It is four jobs treated as one act.

Using the model is not a documented clinical act, a cited source, or a supervised decision.

A model can produce text. The clinician still has to do the act.

Sources reviewed August 18, 2026: two American Psychiatric Association documents, one Federation of State Medical Boards policy, one HHS Office for Civil Rights guidance page, and 45 CFR 164.502 (2025 annual edition, 10–1–25). This is not a statute-by-statute HIPAA conclusion, not a malpractice analysis, and not a nationwide standard of care.

This article is not about turning on an AI scribe or mapping audio, transcripts, and vendor logs. That mapping is in Before You Turn On an AI Scribe in Psychiatry, Map the Data Flow First. It is not about a chat tab as hidden labor. That workload question is in “I Use ChatGPT Between Patients” Is Not a Workload Plan. The question here is narrower: once a clinician uses a model on a clinical task, what has actually been done?

A draft is not the act

The American Psychiatric Association’s Board position is that AI should function in an augmentative role to treatment and should not replace clinicians. Patients should be educated and informed, in a culturally and linguistically appropriate way, if clinical decisions are being driven by AI. AI-driven systems must safeguard health information, and that information should not be used for unauthorized purposes.

The Issue section of the Board position names, as high or unacceptable risk in the setting of generative models, applications including automated diagnosis based on data in medical records; automated treatment planning or coverage determinations; “digital phenotyping,” or using patient-generated data, including social media use, to generate diagnoses or risk scores; relying on citations or medical information that an AI application may have made up; and AI that replicates human speech (for example, chatbots). That list is Issue-section language, not a Position bullet and not a risk table.

A July 2026 APA resource document — approved by the Joint Reference Committee; not Board policy — states that AI-generated outputs should be considered advisory and must be independently evaluated in the context of each patient’s circumstances; that AI tools do not establish diagnoses; that diagnostic determinations are made by qualified clinicians based on clinical assessment and professional judgment; and that responsibility for diagnostic, treatment, and patient-care decisions remains with the clinician, including when AI tools are used as part of the clinical process.

The Federation of State Medical Boards, in policy adopted April 2024, states that state medical boards do not regulate tools or technologies, only the licensed physicians that use those tools. Professional responsibilities and expectations of medical licensees remain the same; how they are fulfilled may differ based on the AI application used. Once a physician chooses to use AI, they accept responsibility for responding appropriately to its recommendations.

Those three documents do not recommend a product. They separate the output from the act.

They do not carry the same weight. The Board position and the FSMB policy are adopted policy. The resource document is the newest of the three and the least binding; it is also the most operationally specific. On advisory outputs, independent evaluation, and clinician responsibility, the Board position or FSMB policy states the same requirement at lower resolution. “AI tools do not establish diagnoses” is the resource document’s sentence. The Board Issue section names automated diagnosis as high or unacceptable risk; that list is not a Position bullet.

Four jobs, four missing acts

Notes

A model can draft a progress note. The signed record is still the clinician’s.

FSMB policy: physicians retain their duty to review records created with AI to ensure that the data captured is accurate and properly managed. Use of AI to generate medical records, without proper oversight, may lead to inaccurate documentation and subsequent patient harm for which the physician will likely be accountable.

The APA resource document treats documentation support as an administrative application and, separately, requires independent clinical verification of AI-generated outputs.

“Reviewed with AI assistance” does not say what was accepted, what was discarded, or what was checked against the encounter. The signed note is the clinician’s documentation of the encounter. The model draft is not.

Differentials

A model can list possibilities. A list is not a diagnosis, and a fluent citation is not a source that was opened.

The Board position treats automated diagnosis from medical-record data, and reliance on citations or medical information a model may have made up, as high or unacceptable risk.

The resource document is direct: AI tools do not establish diagnoses.

If a citation cannot be opened to an underlying document, it is not a cited source. Putting the model’s list in the assessment does not make it one.

Patient-facing text

A model can draft a letter, an after-visit summary, or a list of risks and benefits. The communication is still the clinician’s.

FSMB policy: informed consent is not a list of AI-generated risks and benefits. It is a meaningful dialogue and shared decision-making between the physician and the patient. AI may be used to assist; the ultimate responsibility rests with the physician. Physicians should disclose to patients when and how AI is used in their care, and should be prepared to disclose how they used AI in diagnosis and treatment planning.

The Board position: patients should be educated and informed if clinical decisions are being driven by AI.

A fluent letter is not that conversation. Accuracy, what the patient is told, and whether they were told that a model was in the path, remain the clinician’s.

Decision support

A model can suggest a next step. A suggestion is not a supervised decision.

FSMB policy: if a physician follows a course of treatment provided by an AI-generated response, they should be prepared to provide a rationale for why they made that decision. Simply implementing the recommendations of the AI without a corresponding rationale, no matter how positive the outcome may be, may not be within the standard of care. If the physician then suggests a course that deviates from one delineated by AI, they should document the rationale behind the deviation. As with any tool, once it produces a result, the outcomes cannot be ignored; there must be documentation reflecting how it was or will be utilized. Failure to apply human judgment to any output of AI is a violation of a physician’s professional duties.

The resource document: AI functions as a support tool within clinical workflows and does not replace clinician decision-making, patient evaluation, or clinical reasoning. Responsibility remains with the clinician.

A suggestion becomes a decision only when a clinician accepts or rejects it, with a reason that can be stated.

What the record can actually show

Operational questions, not legal conclusions.

What job was the model given. What output was used. What was discarded. What the clinician independently verified. Whether a clinical decision was driven by AI, and what the patient was told.

“Reviewed with AI assistance” answers none of those.

The two documents do not share one disclosure trigger. The Board position: patients should be educated and informed if clinical decisions are being driven by AI. FSMB policy: physicians should disclose when and how AI is used in their care, and should receive a patient’s consent prior to application of a tool to a patient’s care. Neither document mentions a footer in the note. A footer is not that disclosure.

A vendor under a BAA is not a consumer tab

HHS Office for Civil Rights, on its Business Associates page (content last reviewed July 30, 2026), states that a business associate is, generally, a person that performs certain functions or activities on behalf of a covered entity that involve creating, receiving, maintaining, or transmitting protected health information, or that provides certain services to or for a covered entity that involve the disclosure of PHI to that person.

The general rule is 45 CFR 164.502 (2025 annual edition, 10–1–25). A covered entity or business associate may not use or disclose protected health information except as permitted or required by this subpart or by subpart C of part 160. A covered entity may disclose protected health information to a business associate, and may allow a business associate to create, receive, maintain, or transmit protected health information on its behalf, if the covered entity obtains satisfactory assurance that the business associate will appropriately safeguard the information. Those assurances must be documented in a written contract or other written agreement or arrangement that meets the applicable requirements of § 164.504(e).

The HHS page states that the Privacy Rule requires that the BAA contain the elements specified at 45 C.F.R. § 164.504(e).

One example on that page is a third-party vendor artificial-intelligence chatbot on a provider’s patient portal that provides services involving the patient’s PHI, such as symptom assessment, medical reminders, and appointment scheduling.

That example is a vendor performing a function on the covered entity’s portal. It is not a clinician’s consumer chat tab between patients. This article does not treat the consumer tab as that example, and it does not determine whether any particular prompt is a permitted or impermissible disclosure.

The contrast is only this: a vendor that meets the business-associate definition generally requires the applicable BAA. The portal-chatbot example is one such vendor. A consumer model is not that example.

Documentation failures

Operational failures, not universal legal conclusions.

Treating the model draft as the note

The signed record documents the clinical act. The model draft does not.

Treating a model differential as a diagnosis

The resource document: AI tools do not establish diagnoses.

Treating a model citation as a source

The Board position names reliance on made-up citations as a high or unacceptable risk. A citation that has not been opened is not a source.

Treating “reviewed with AI assistance” as the act

It does not record what was accepted, discarded, verified, or told to the patient.

Treating a consumer tab as the HHS portal-chatbot example

The HHS example is a vendor chatbot on a provider portal. It is not a personal chat window.

Treating an AI-generated risk list as informed consent

FSMB policy: informed consent is not a list of AI-generated risks and benefits.

Download the Clinical LLM Act Record (PDF) (373 KB)

Clinical-LLM-Act-Record.pdf

Clinical-LLM-Act-Record.pdf

373.94 KBPDF File

Companion worksheet: present / absent for job given, output used, output discarded, independent verification, patient informed if a clinical decision was driven by AI, and whether the tool is a vendor under a BAA or is not that case. On the disclosure row, the worksheet records the Board trigger, a clinical decision driven by AI; FSMB policy states a broader one, when and how AI is used, plus consent. The fourth question covers the broader disclosure issue; FSMB policy separately addresses consent. On the BAA row, Present means the case is recorded, not that a BAA exists. The worksheet does not authorize a tool or a disclosure.

Four questions

What job did the model do? What did you accept, and what did you discard? What did you independently verify? What did the patient need to be told?

If any answer is unknown, do not treat the model use as a documented clinical act.

Sources

  • American Psychiatric Association, Position Statement on the Role of Augmented Intelligence in Clinical Practice and Research, approved by the Assembly February 2024 and the Board of Trustees March 2024. Official APA position. https://www.psychiatry.org/getattachment/a05f1fa4-2016-422c-bc53-5960c47890bb/Position-Statement-Role-of-AI.pdf. Opened in full August 18, 2026.

  • American Psychiatric Association, Resource Document on Artificial Intelligence in Psychiatric Practice, approved by the Joint Reference Committee July 2026. Resource document; front matter states that findings, opinions, and conclusions do not necessarily represent the views of the officers, trustees, or all members. Not Board policy. https://www.psychiatry.org/getattachment/162a6743-6035-4f44-8f41-18f030044a99/RD-AI-in-Psychiatric-Care.pdf. Opened in full August 18, 2026. Used only for: outputs are advisory and require independent evaluation; AI tools do not establish diagnoses; clinician remains responsible. Not used for any FDA-approval count or any CMS paraphrase.

  • Federation of State Medical Boards, Navigating the Responsible and Ethical Incorporation of Artificial Intelligence into Clinical Practice, adopted by the House of Delegates April 2024. Official FSMB policy. https://www.fsmb.org/siteassets/advocacy/policies/incorporation-of-ai-into-practice.pdf. Opened in full August 18, 2026. Not used: the “replace as much as 80%” sentence (footnotes 3–4 are press).

  • HHS Office for Civil Rights, Business Associates, content last reviewed July 30, 2026. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html. Opened in full August 18, 2026. Used for: business-associate definition; BAA required for a BA; BAA elements specified at 45 C.F.R. § 164.504(e) as this page states; portal AI-chatbot example as a BA. Not used to characterize a consumer chat tab or to label any prompt a disclosure.

  • 45 CFR 164.502 (2025 annual edition, 10–1–25), Uses and disclosures of protected health information: general rules. GovInfo 45 CFR Subtitle A, Part 164 PDF. https://www.govinfo.gov/content/pkg/CFR-2025-title45-vol2/pdf/CFR-2025-title45-vol2-part164.pdf. Opened August 18, 2026. Used only for: 164.502(a) general prohibition; 164.502(e)(1)(i) disclosure to a BA with satisfactory assurance; 164.502(e)(2) written contract, agreement, or arrangement meeting § 164.504(e). Not used: 164.502(a)(5)(iii); 164.502(b) minimum necessary; any consumer-tab disclosure conclusion; any classification of a consumer model as a BA or as not a BA.

Educational Disclaimer: The Psychiatric Record provides general educational information for psychiatric and mental-health professionals. Content does not constitute medical, legal, regulatory, compliance, billing, or other professional advice; does not establish a standard of care; and is not a substitute for independent professional judgment. Requirements and appropriate practices may vary by jurisdiction and circumstance. Verify current authoritative sources.

This article does not recommend a tool, authorize a workflow, or determine whether a particular use of a model is permitted.