Newsom Vetoes SB 903: What California Therapists Using AI Notetakers Need to Do Now
Published October 03, 2026
- Governor Newsom vetoed SB 903 on September 30, 2026, after it passed the Senate 39-0 and the Assembly 71-4.
- The vetoed bill would have required written disclosure and affirmative consent before AI could record or transcribe any psychotherapy session, with civil penalties up to $10,000 per violation.
- With no SB 903 backstop, therapists' AI consent obligations now rest on HIPAA, CMIA, and licensing-board rules — architecture choice becomes the primary risk control.
- Cloud notetakers (Otter, Fireflies, and even BAA-covered clinical scribes) create a vendor-breach surface and training-data exposure that on-device tools eliminate by design.
- On-device transcription using Apple's SFSpeechRecognizer keeps audio on the clinician's iPhone or Mac — no BAA, no cloud copy, no subpoena target.
Quick answer: Governor Newsom vetoed SB 903 on September 30, 2026, calling it "overly broad." The bill would have required written disclosure and affirmative patient consent before any AI could record or transcribe a therapy session in California. With the statute gone, therapists are left with HIPAA, state confidentiality laws, and professional-ethics rules — making the architecture of your notetaker (on-device vs. cloud) the primary risk control.
On September 30, 2026 — the last day he could act on bills from the 2025–2026 session — California Governor Gavin Newsom vetoed Senate Bill 903, the measure that would have put statutory guardrails around how AI records, transcribes, and triages psychotherapy sessions in the state. The bill had passed the Senate 39–0 and the Assembly 71–4. In his veto message, Newsom called SB 903 “overly broad” and said it "would drastically limit a clinician's use of tools that benefit the delivery of care today, including by requiring routine screening determinations to receive direct approval." For California therapists using — or considering — AI notetakers, the entire compliance landscape just shifted overnight.
What SB 903 would have required
SB 903, authored by Senator Steve Padilla, was narrower than its tabloid framing. It didn't ban AI in mental health care. It drew a specific line around when AI could record, transcribe, or triage inside licensed psychotherapy. According to the enrolled bill text at leginfo.legislature.ca.gov, the operative language would have prohibited any “individual, corporation, or entity” from using AI to record or transcribe psychotherapeutic communications or sessions — or to triage a person for the need for psychotherapy — unless the patient was informed that AI would be used, told the purpose of the tool, and gave consent.
Three elements of the vetoed bill mattered most for the AI-notetaker market:
- Written disclosure and affirmative consent before AI could record or transcribe a session.
- A prohibition on sharing, selling, storing, or training models on data obtained from psychotherapy in a manner inconsistent with existing confidentiality law — language codified against the Confidentiality of Medical Information Act.
- Civil penalties up to $10,000 per violation, enforceable by the Department of Consumer Affairs, as originally proposed by Senator Padilla's office when the bill was introduced.
The California Board of Psychology formally supported the bill in February 2026, and when staff asked whether the measure specified data-retention rules, they were told the bill as introduced did not — a gap the board agreed to monitor through amendments.
Why Newsom vetoed it
The Imperial Valley Press reported that Padilla pushed back hard, noting Newsom had just signed companion-chatbot protections for minors and calling the veto “disappointing.” Newsom's objection — per his veto message as reported by multiple outlets — was that requiring licensed-professional sign-off on "routine screening determinations" would slow care in a system already short on clinicians.
Whatever your politics on the veto itself, the operational reality for California practices is unambiguous: the law that would have told your AI notetaker vendor exactly what consent form to use, what training-data uses to disallow, and what penalties applied for violation — is gone, at least until the next session.
What rules still apply to AI notetakers in therapy
Even without SB 903, a California therapist using an AI notetaker is not operating in a legal vacuum. At least four overlapping frameworks still govern the use:
1. HIPAA and the HHS breach-notification rule
If an AI notetaker vendor receives, maintains, or transmits protected health information (PHI) on behalf of a covered-entity therapist, it is a Business Associate under the HIPAA regulations at HHS.gov. A signed Business Associate Agreement is required, and the vendor inherits breach-notification obligations under the HHS Breach Notification Rule.
2. California's Confidentiality of Medical Information Act (CMIA)
CMIA imposes California-specific confidentiality duties on providers and anyone handling medical information. The vetoed SB 903 would have explicitly tied AI-generated psychotherapy records back to CMIA. Without the bill, CMIA still applies on its own terms — it just no longer has the AI-specific overlay.
3. Licensing-board rules and professional ethics codes
The California Board of Psychology voted on February 13, 2026 to support SB 903, and board staff noted at that meeting they had been preparing to accept AI-related complaints since the prior year's AB 489. That enforcement posture doesn't disappear because the bill was vetoed. The APA, CAMFT, and NASW ethics codes already treat introducing a new party to a session — and that includes an AI vendor — as material to informed consent.
4. CCPA, as amended by AB 1008
Separately from HIPAA, California's consumer-privacy regime now treats AI-generated outputs as personal information. For a deeper read, see our analysis of how data-privacy-aware AI meeting notes work in regulated industries.
The breach surface SB 903 was trying to shrink
SB 903 wasn't drafted in a vacuum. 2026 has been a brutal year for cloud mental-health data. A running wrap-up by MyPrivacy.blog catalogued, among other incidents, Confidant Health leaving 5.3 terabytes of therapy session videos exposed on the open internet, and a European mental-health network whose entire patient database was exfiltrated and ransomed back to individual patients at roughly 200 euros per head.
And the NPR reporting from May 2026 captured the human side: patients discovering mid-session that an AI tool was recording their therapy, driving home replaying the session in their head, and never returning. Nearly half of Americans surveyed told KFF they are worried about how AI systems store and use their health information.
Cloud AI notetaker vs. on-device: the comparison therapists actually need
The vetoed SB 903 would have put legal teeth behind patient consent. With the bill gone, the primary way to shrink your exposure is architectural, not contractual. Here is how the two models compare on the dimensions a therapist actually has to defend to a licensing board:
| Attribute | Cloud AI Notetaker (Otter, Fireflies, Zoom AI Companion, most clinical scribes) | On-Device (Basil AI) |
|---|---|---|
| Where session audio is processed | Uploaded to vendor cloud servers | Processed on the clinician's iPhone or Mac via Apple Neural Engine |
| Business Associate Agreement required | Yes — must be in place before any PHI touches the vendor | No vendor receives PHI, so no BAA chain to manage |
| Training-data clause risk | Varies — some policies reserve rights to train on de-identified audio | Audio never leaves the device; nothing to train on |
| Breach surface (vendor-side) | Vendor DB, backups, log pipelines, subprocessors | None — the clinician's device is the only copy |
| Subpoena-ready cloud copy | Yes — vendor can be compelled to produce | No vendor custodian exists |
| Offline operation | Requires network | Fully offline capable |
| Patient disclosure burden | “We send your audio to [vendor] in [region] where it is stored for [N] days” | “I use an on-device tool; the audio stays on this iPhone and never leaves it” |
Note what the second column is really saying: with a cloud notetaker, every attribute you have to defend to the Board of Psychology depends on a vendor's security program and contract language. The on-device column collapses most of those rows because there is no vendor in the data path to begin with.
What cloud notetaker privacy policies actually say
Most clinicians never read the vendor terms end-to-end. For context when you do: Otter.ai's privacy policy and Fireflies' privacy policy both describe broad rights over user content. An analysis published by Humla noted that Otter's policy effective June 16, 2026 explicitly contemplates training on de-identified audio and transcripts that "may contain Personal Information," and Granola's privacy policy effective July 24, 2026 described de-identified training with an opt-out buried in account settings.
None of that is illegal under HIPAA if the vendor's BAA permits it — which is exactly why SB 903 was going to tighten the standard specifically for psychotherapy. With the veto, those vendor-written defaults are once again the governing framework for anything your AI tool sends to the cloud.
The post-veto consent conversation
Even without a statute, the practical consent conversation with a patient is harder to defend when the answer to "where does my voice go?" is "to a server in Virginia operated by a company called X." The California Board of Psychology staff signaled they would start accepting AI-related complaints last year, and the WGBH republication of the NPR story included a national YouGov survey showing only 11% of Americans would be open to AI in mental health care and only 8% say they trust it.
Those numbers mean that even a lawful consent conversation can quietly destroy the therapeutic alliance. The architectural answer — audio that never leaves the room — makes the consent conversation shorter and the alliance intact.
How Basil AI solves this: on-device transcription for therapy sessions
Basil AI was built on a single premise: the only way to guarantee a cloud breach doesn't happen is to not use a cloud. Transcription happens on the iPhone or Mac itself, using Apple's SFSpeechRecognizer framework configured with requiresOnDeviceRecognition = true. The audio never leaves the device, there is no vendor server in the processing path, and there is no BAA chain to manage because no third party ever receives PHI.
Concretely, for a California therapy practice responding to the SB 903 veto, that means:
- No cloud copy to subpoena, breach, or train on. The audio and transcript live on the clinician's device.
- Up to 8 hours of continuous recording, enough for a full day of back-to-back sessions without touching a network.
- Clinician-controlled retention. Deletion is immediate and local, not a ticket with a vendor's data team.
- Patient disclosure is simpler: "The audio stays on my iPhone. No vendor processes it. I delete the recording when I'm done with the note."
This is not a claim that Basil AI is “HIPAA compliant” or that the SB 903 veto is irrelevant — neither is true. Compliance is a determination the covered entity (the therapist or group) makes, and the vetoed bill reflected a real policy judgment that patients deserve stronger consent protections than the current patchwork provides. What Basil AI does provide is an architecture where most of the breach-surface rows in the table above collapse to zero, by design.
The buyer's checklist to use this week
If you are a California therapist and your AI notetaker is a cloud tool, here are the questions to put to your vendor — or your own compliance officer — before your next client comes in:
- Where exactly is session audio processed and stored? Name the cloud region.
- Is my BAA current, and does it explicitly prohibit training on my patients' data — de-identified or otherwise?
- What is the default retention period for audio? For transcript? Can I shorten it?
- If a subpoena arrives at the vendor tomorrow for a patient's session, who gets notice first — me or law enforcement?
- Which subprocessors (speech-to-text, LLM summarization, analytics) touch the audio? Are they also under BAA?
- In the event of a breach, who notifies my patients — the vendor, or me?
- What is the vendor's SOC 2 report scope, and does it cover the AI-summarization pipeline, not just the storage layer?
- Can I operate the tool fully offline for a session?
If the honest answers to questions 1–7 make you uncomfortable, question 8 matters a great deal. For related reading on how on-device capture changes the compliance posture for other regulated roles, see our deep-dive on AI meeting notes for compliance officers keeping recordings off the cloud, and our comparison of bot-free vs. bot-based AI notetakers for client-facing meetings.
Where the AI-notetaker legal story goes next
SB 903 is dead in its current form, but Padilla's statement after the veto strongly suggested he will reintroduce a modified version in 2027. In the meantime, the federal picture is unsettled: California's own 2026 session also saw Newsom sign three other healthcare-AI bills, including measures on chatbot disclosure, even as he vetoed SB 903 and a clinical-decision-support measure. Separately, cloud AI notetakers remain in active federal litigation — the consolidated In re Otter.AI Privacy Litigation survived its motion to dismiss on August 13, 2026, with the ECPA, CIPA, and BIPA claims proceeding to discovery, and Chamberlain v. Granola was filed July 30, 2026 in the Northern District of California.
That litigation isn't about therapy specifically — but it is about whether a cloud AI notetaker that records a meeting (or a session) without clear all-party consent is a wiretap. If courts answer yes, the question for therapists stops being “did my patient consent?” and becomes “did my vendor obtain the kind of consent the statute requires?” An on-device tool sidesteps that entire theory because there is no third-party recorder.
The bottom line for California therapists
SB 903 would have given you a statutory floor to stand on when a patient asked what happens to their voice. Without it, your floor is whatever your vendor contract and your licensing board say — and your vendor contract was written by the vendor. The architectural question — cloud or on-device — is now the clearest control you have.
If your practice already uses a cloud notetaker, this week's work is updating the consent form, re-reading the BAA, and documenting the training-data clause. If you are evaluating a notetaker for the first time, the SB 903 veto is a good moment to ask whether the audio needs to leave the device at all.
Frequently Asked Questions
Did Governor Newsom sign SB 903?
No. SB 903 passed the California Senate unanimously (39-0) and the Assembly 71-4, but Governor Gavin Newsom vetoed it on September 30, 2026, calling the bill "overly broad." In his veto message he said SB 903 would have drastically limited clinicians' use of AI tools, including by requiring routine screening determinations to receive direct licensed-professional approval.
Do California therapists still need patient consent to use an AI notetaker?
Yes — just not under SB 903. Consent obligations still flow from HIPAA, the California Confidentiality of Medical Information Act (CMIA), the Board of Psychology's and BBS's professional-conduct rules, and the ethics codes of APA, CAMFT, and NASW. Introducing a new party (an AI vendor) into a session is still a disclosure most boards treat as material to informed consent.
Is an AI notetaker that uploads audio to the cloud HIPAA compliant for therapy?
It can be, if the vendor signs a Business Associate Agreement (BAA), encrypts audio in transit and at rest, and contractually agrees not to use PHI to train models. But HIPAA compliance is not a breach guarantee — the 2024 Confidant Health incident exposed 5.3 TB of therapy session videos, and HHS enforcement actions in 2024-2025 show BAA-covered vendors still leak. On-device processing removes the vendor from the chain entirely.
What makes on-device transcription different for therapy?
On-device tools like Basil AI run Apple's SFSpeechRecognizer and the SpeechAnalyzer framework locally on the iPhone or Mac using the Neural Engine. The audio never leaves the device, so there is no vendor server to breach, no BAA to negotiate, no training-data clause to audit, and no subpoena-ready cloud copy. The clinician controls retention and deletion directly.
Can therapy session audio be used to train AI models?
Under SB 903 it would have been explicitly prohibited to share, sell, store, or train models on psychotherapy data in a manner inconsistent with applicable law. With the veto, that prohibition reverts to being governed by vendor contracts and HIPAA's permitted-uses rules. Several cloud notetakers' public privacy policies as of mid-2026 reserved the right to train on de-identified audio and transcripts.
What should a California therapist do this week in response to the veto?
Three steps: (1) read your current notetaker's privacy policy and BAA for training-data and retention clauses; (2) update your written informed-consent form to disclose the specific AI tool, where audio is processed, retention periods, and the patient's right to decline; (3) evaluate whether an on-device alternative removes the vendor-breach surface for your practice. Your licensing board, not Sacramento, will set the standard.