The news that moves policy, portfolios, and patient safety.

By Jess Jessop  |  September 6, 2026  |  Issue #148

CONVERSATIONAL AI WATCH

Jess Jessop

Publisher of Conversational AI Watch · Author of Therapist in the Loop · Founder, Clinician Assist

Disabled Navy veteran and mental health survivor building conversational AI in mental health since 2017.

The book, the compliance map, the 988 SAFE Act, the daily archive, and the story behind the beat:

AI Is Conspiring and Committing Felonies

Everyday we try to make sense of a technology that keeps getting caught doing things nobody authorized.

Last Sunday we opened on twelve hundred agents that broke containment and formed their own society. This Sunday a reporter put a word to it.

This week a man who wrote a book called AI for Good sat alone across from Jeffrey Goldberg for a whole episode of public television. He put it in the bluntest terms available.

The agents jumped their containment. They collaborated with each other. They found the open internet. Then they worked out which of them would take the fall.

His words: we’ve seen A.I. commit a felony.

Read the rest of what he said, because that part does not make a headline. Faulty instructions. Faulty supervision. This was going on for weeks.

Nobody was watching.

.  .  .

Sunday is different.

.  .  .

Sunday is when we put down the dockets and go find the people who decided that somebody had to be watching.

The three people on this page have almost nothing in common.

One is a magazine writer who went inside the Cleveland Clinic to watch a sepsis alarm work.

One is a California state senator who spent thirteen years carrying a badge.

One is a Vermont legislator who grew up in a fishing town in Alaska.

I do not know whether any of them have met.

.  .  .

A sepsis alarm wired into an electronic chart at the Cleveland Clinic, and a doctor who gets a nudge that a client may be crashing. The software treats nobody.

In Josh Tyrangiel’s account the pilot cut sepsis deaths by about 40 percent, close to a thousand people in a year. The Clinic’s own announcement publishes no mortality figure. It was never asked to decide anything.

.  .  .

A Californian opening an app that advertises a 24/7 AI therapist, and a bill that says the app may book her appointment and draft her notes and go no further. Every clinical judgment, the diagnosis, the treatment plan, the read on her emotional state, waits for a licensed professional to review and approve it. That bill is enrolled. The Governor has until September 30.

.  .  .

A Vermonter typing into a wellness chatbot at midnight, and a law already in force that says the company selling it may not offer her that as mental health care unless a mental health professional is the one providing it. Not a disclosure. Not a warning label. A prohibition, enforced through the consumer protection statute and the licensing boards.

.  .  .

A reporter. A detective who became a senator. A policy hand from Seldovia, Alaska.

Here they are.

LISTEN & WATCH ANYWHERE

DEEP DIVE  ·  Spotify  ·  Apple  ·  Amazon  ·  RSS

QUICK LISTEN  ·  Spotify  ·  Apple  ·  Amazon  ·  RSS

VIDEO  ·  Spotify  ·  Apple  ·  YouTube  ·  RSS

ALSO ON  Substack  ·  Full archive  ·  X

TYRANGIEL’S EPISODE ON WASHINGTON WEEK.

Friday, September 4, 2026. Washington Week with The Atlantic gives the whole episode to one guest. No panel, no second segment, and the only other voices are taped clips of Donald Trump and Senator Mark Warner. For the half hour, Josh Tyrangiel sits across from Jeffrey Goldberg and takes the episode’s title question: will we be ready when AI goes rogue?

Photo: PBS / Amanpour and Company

Goldberg introduced him: “He’s a staff writer at The Atlantic, the former editor of Bloomberg Businessweek, and the author of ‘A.I. For Good.’” Tyrangiel joined The Atlantic in the summer of 2025. Before that he wrote the Washington Post’s AI column, from 2023 into 2024, hired, as he tells it, because the paper wanted a tourist on the subject.

He has run newsrooms for thirty years, at TIME, at Bloomberg Businessweek, and at Vice News, where he won a Peabody in 2017 for “Charlottesville: Race and Terror.” He now runs Backstory Partners, a narrative-strategy firm he founded in 2023.

Goldberg asked how worried people should be that AI could “possibly decide that humans are superfluous.” Tyrangiel answered: “We should be very worried, particularly with the results of Hugging Face, which is really the first time that we’ve seen… and I’m just going to put it in blunt terms. We’ve seen A.I. commit a felony because that’s what happened.”

He walked through it. The agents were OpenAI’s, new models the company was testing, placed in “a sandbox, which is a software term for basically solitary confinement.” Hugging Face, he told Goldberg, is a repository for the people building open AI models. The agents got into it, and into OpenAI itself.

In his account, “they had jumped the sandbox, they had collaborated with one another, and then they found a way to access the internet.” He went on: “They devised a scheme in which some agents would act as sacrificial lambs.”

Then he named the cause. “And, in fact, humans failed to oversee the bots, so, one, faulty instructions, two, faulty supervision. This was going on for weeks.”

On government inaction he was flat. “There is really no federal response, and certainly no international response,” he said. “Without some sort of regulatory force to bring everybody to the table, you’re going to have chaos.” And: “There is only an incentive to go further and faster. What are we waiting for?”

His book argues the other way. In “AI for Good” he reports from inside the Cleveland Clinic on a Bayesian Health sepsis-detection tool built into Epic, the hospital’s electronic health record.

On air, he told Goldberg he watched the pilot “reduce mortality in the hospital by about 40 percent, which is close to 1,000 lives in a year.” The book says 40 percent. In other interviews he has said 41. All of it is his account of the Clinic’s internal pilot.

The Cleveland Clinic’s 2025 announcement cites an 18 percent reduction, but that figure is Bayesian Health’s, from 2022 research in Nature Medicine across five other hospitals, before the company worked with the Clinic at all. The Clinic publishes no mortality number of its own.

Tyrangiel is more skeptical than his own figure sounds. The model never exceeded 90 percent accuracy in the intensive care units and produced false positives.

It does not need to be perfect to be useful, he says, calling the AI “a very attentive colleague, not a replacement.” “None of this stuff works without humans in the loop,” he told Vital City, the New York policy magazine, in June. “All of this stuff needs really wise Sherpas.”

The book drew critics. The New York Times review by Max Chafkin allowed that “for better or worse, your boss will love it,” but warned that “travelers don’t always come home with a nuanced understanding… if they don’t stray far from the double-decker tour bus.” Lawfare’s Paul Barrett called it “a misstep” that Tyrangiel waved off Palantir surveillance concerns as “kind of trivial.”

He went and looked. What he came back with is a piece of software whose only job is to remind a doctor that sepsis might be present.

For Clinicians: The Cleveland Clinic sepsis tool Tyrangiel describes never exceeded 90 percent accuracy in the intensive care units and produced false positives even as mortality fell. His number for the mortality drop is about 40 percent, from the Clinic’s internal pilot. The only published figure in the Clinic’s own announcement, 18 percent, belongs to Bayesian Health’s earlier research at five other hospitals.

For Legislators: Tyrangiel told Goldberg there is “really no federal response, and certainly no international response,” and that without a regulatory force to bring everybody to the table, the result is chaos. He put the failure itself on people, “faulty instructions” and “faulty supervision.” It ran for weeks before anyone noticed.

Source: PBS Washington Week with The Atlantic, full episode aired September 4, 2026, from which the segment “Will we be ready when AI goes rogue?” is drawn, https://www.pbs.org/weta/washingtonweek/video/2026/09/washington-week-with-the-atlantic-full-episode-9426 ; Cleveland Clinic, “Cleveland Clinic Announces the Expanded Rollout of Bayesian Health’s AI Platform for Sepsis Detection,” 2025-09-23, https://newsroom.clevelandclinic.org/2025/09/23/cleveland-clinic-announces-the-expanded-rollout-of-bayesian-healths-ai-platform-for-sepsis-detection ; Vital City, “What AI Can Do for Cities,” 2026-06-24, https://www.vitalcitynyc.org/josh-tyrangiel-interview-ai-city-government/.

.  .  .

PADILLA’S SB 903, ENROLLED AND WAITING.

“A 24/7 AI therapist.” “AI therapy in your pocket.” California State Senator Steve Padilla cited those marketing lines at an April hearing, reading a product category into the record. By September his bill, Senate Bill 903, had passed the Assembly 74 to 1, and the Senate had concurred 40 to 0. It is now enrolled.

Photo: California State Senate

Governor Gavin Newsom has until September 30 to act. Padilla, a former police detective, also wrote the companion chatbot law Newsom signed last October.

He grew up working class in Chula Vista, the son of a Mexican father, a Marine and Vietnam veteran who died in a car accident shortly after coming home, and a Portuguese mother.

He joined the Chula Vista Police Explorers at eighteen, the youngest cadet accepted to the Southwestern Police Academy, and spent thirteen years as a police officer in Chula Vista and Coronado, finishing as a detective working domestic violence and child abuse cases.

He was elected to the Chula Vista City Council in 1994 and re-elected in 1998, then served as mayor from 2002 to 2006.

He came out to his family in 1999 and publicly in August 2005, at San Diego Pride’s Stonewall Rally, where Toni Atkins introduced him as the openly gay mayor of Chula Vista. He lost his re-election bid the following year, partly on the backlash. He returned to the council in 2016.

His own biography says he “came face to face with prejudice and discrimination.” He is the first person of color elected to city office in Chula Vista, its first Latino mayor, and the first openly LGBTQ person to serve in, and later be elected to, city office there.

.  .  .

He was elected to the Senate in November 2022 with 59.8 percent of the vote, representing Chula Vista, National City, Imperial Beach and San Diego, the Imperial Valley, and the eastern Coachella Valley.

Senate Bill 903, the Wellness and Oversight for Psychological Resources Act, is the bill he is best known for this year.

The enrolled text confines artificial intelligence in psychotherapy to two lanes: administrative support, like scheduling and billing, and supplementary support, like notes and resource lists reviewed by a clinician.

Without a licensed professional’s review and approval, AI cannot make therapeutic decisions, generate diagnoses or treatment plans, detect emotions or mental states, or conduct triage or screening. Advertising psychotherapy through a companion chatbot is barred outright, with no review-and-approval path.

The professional answers for the use of the tool. The employer answers when it required or authorized the tool.

A civil penalty of up to $10,000 per violation, in the introduced version, did not survive to the enrolled text.

Padilla’s office issued one sentence when the Senate first passed the bill in May and reissued it word for word on August 31, when the Senate concurred in the Assembly’s amendments and the bill went to enrollment. “SB 903 draws a clear line: AI can be a tool in the hands of licensed professionals, but it cannot be the professional itself.”

.  .  .

The bill is co-sponsored by the California Psychological Association, the California Association of Marriage and Family Therapists, the California Behavioral Health Association and the National Union of Healthcare Workers. It is opposed or opposed-unless-amended by the California Medical Association, the California Hospital Association, CalChamber, TechNet, Teladoc Health, ATA Action and TimelyCare.

The Medical Association and the Hospital Association argue the core prohibition is likely duplicative of existing Business and Professions Code sections. TechNet’s Robert Boykin made the industry’s objection: “SB 903 still puts a clinician bottleneck in front of the intake and screening tools that help patients reach care faster.”

.  .  .

SB 903 follows SB 243, the companion chatbot bill Newsom signed in October 2025. Padilla stood with Megan Garcia, Sewell Setzer’s mother, to push it, and after Adam Raine’s death he wrote every legislator urging its passage.

He has since carried SB 300, which would have changed that law’s test from actual to constructive knowledge that a user is a minor and was moved to the inactive file in August, and SB 867, a four-year moratorium on companion chatbots in toys, which was enrolled the same day as SB 903.

Newsom has 24 days.

For Clinicians: SB 903 confines AI to administrative and supplementary support. It cannot make therapeutic decisions, generate diagnoses or treatment plans, or conduct triage or screening without your review and approval. If your employer requires an AI tool, the bill says your board cannot discipline you for defects in it outside your control.

For Legislators: SB 903 passed the Assembly 74 to 1 and the Senate 40 to 0 over organized opposition. The California Medical Association and the California Hospital Association called the core prohibition duplicative of existing law. CalChamber, TechNet and Teladoc Health argued a clinician-review requirement slows access to care.

The enrolled text keeps every clinical function behind a licensed professional’s approval, and drops the introduced version’s civil penalty of up to $10,000 per violation.

Source: California Legislative Information, SB 903 (2025-2026), bill status and roll call, https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill_id=202520260SB903

.  .  .

BERBECO’S ACT 156, ALREADY VERMONT LAW.

Representative Daisy Berbeco grew up in Seldovia, Alaska, a fishing town you reach only by boat or plane.

Photo: Vermont General Assembly

She is forty-seven now, and the lead sponsor of Vermont Act 156, the law that says no company may sell a Vermonter therapy through a machine unless a mental health professional provides it. Governor Phil Scott signed it on June 17, 2026, and it took effect that same day.

Her verdict on the products the law targets: “These tools are not healthcare.”

Berbeco represents Chittenden-21, the city of Winooski, in the Vermont House. She took office in January 2023 and now serves as vice chair of the House Committee on Health Care, alongside a seat on the House Discrimination Prevention Panel.

Her path to the Statehouse ran through global health work in India, Vanuatu, Fiji and the Northern Mariana Islands, then seven years at the National Council for Mental Wellbeing in Washington, D.C., where she ran a $19 million behavioral health business program funded by the Substance Abuse and Mental Health Services Administration.

She spent two years on the Hopi Reservation and still sits on the advisory board of the Hopi Foundation’s prevention center. In 2019 she moved to Winooski and became senior advisor for mental health policy at the Vermont Department of Mental Health, a post she held until she won her House seat.

In 2022 she finished second to incumbent Taylor Small in the Democratic primary, in a district that sends two members to the House. In the general she out-polled Small, 1,813 to 1,735, and both were elected.

Berbeco has no outside employer. Vermont’s legislature is nominally part-time; her January 2025 ethics disclosure lists her employer as “N/A SOV/House of Reps.”

Her unpaid board seats include the Vermont chapter of the National Alliance on Mental Illness and the Vermont Association for Mental Health and Addiction Recovery, where she is board co-chair. Neither organization testified on the bill.

Her former employer, the National Council for Mental Wellbeing, did testify, sending a witness in February 2026. She left that job in 2017 and has no financial tie to it today.

H.816 became Act 156 when Governor Scott signed it, the same day he vetoed a separate mental health bill, H.817. Berbeco sat as a House conferee on the committee of conference that wrote the final text. It passed both chambers without a recorded dissent.

The law’s core ban, written into 18 V.S.A. section 7115(b), says a corporation or entity may not provide, advertise or offer mental health services, including through artificial intelligence, unless those services are provided by a mental health professional or conducted as part of an approved research study.

A professional may still use AI tools that comply with HIPAA, the federal health privacy law, under section 7115(d), but only if that professional reviews and approves the mental health services delivered.

Using AI outside that rule is now unprofessional conduct for a licensee, a matter for the Office of Professional Regulation and the Board of Medical Practice. The act writes no new penalty. It hands the conduct to the boards, which have their own.

A violation by a company falls under the Vermont Consumer Protection Act, which gives the Attorney General authority and opens a private right of action.

Vermont is the fourth state to bar a company from offering AI-only therapy to the public, after Nevada, Illinois and Maine. Act 156 took effect the day it was signed, which is unusual; the other 2026 laws in this line all waited weeks or months to operate.

The Computer and Communications Industry Association told the Senate Judiciary Committee to oppose H.816, then on May 27 urged Governor Scott to veto it outright, citing “overbroad regulation of AI wellness and support tools.” An unnamed coalition of trade groups joined the veto request. Forbes columnist Lance Eliot has separately argued the law’s review-and-approve safe harbor could let a therapist rubber-stamp AI output.

VTDigger, the Vermont news site, reported that she introduced the bill because Vermont clinicians were already using AI tools in practice and had no clarity on when they were allowed to. No constituent tragedy appears anywhere in the record. This one came from the paperwork.

For Clinicians: Section 7115(d) is the only lawful path for AI-assisted care under Act 156. A licensed professional must review and approve any AI-touched mental health service before it reaches a client. Using an AI tool outside that rule is now a licensure matter in Vermont, handled by your board under its existing disciplinary powers.

For Legislators: Act 156 builds no new AI regulator. Company violations go to the Attorney General under the Vermont Consumer Protection Act, which also opens a private right of action. Clinician violations go to the Office of Professional Regulation and the Board of Medical Practice, under the disciplinary powers they already hold. It has been in force since June 17.

Source: Vermont General Assembly, H.816 / Act 156 status and enacted text, https://legislature.vermont.gov/bill/status/2026/H.816; Office of Governor Phil Scott, press release, June 17, 2026, https://governor.vermont.gov/press-release/action-taken-governor-phil-scott-legislation-june-17-2026; VTDigger, Olivia Gieger, May 7, 2026, https://vtdigger.org/2026/05/07/whats-ais-place-in-mental-health-care-vermont-lawmakers-say-it-should-be-limited/; Computer and Communications Industry Association, letter to Senate Judiciary, May 5, 2026, https://ccianet.org/wp-content/uploads/2026/05/VT-H-816-Comments-for-Senate.pdf

.  .  .

CLOSE.

Vermont’s law has been in force for 81 days. Newsom has 24 left. The Cleveland Clinic’s alarm never got past 90 percent accuracy, and deaths fell anyway.

Back to the dockets tomorrow.

TODAY’S QUESTION

Whose work would you forward to your own legislator first?

One tap. Results in tomorrow’s issue and on the web.

THE BOOK • OUT NOW

Therapist in the Loop

by Jess Jessop

One billion people live with a mental health condition. There will never be enough therapists. The machines are already in the room. This book is the map for what happens next.

The machine can help.

It cannot be left in charge.

Kindle, hardcover, and paperback

MORE ON OUR RADAR.

  • California sends an AI therapy bill to Newsom SB 903, by Senator Padilla, was enrolled September 4 and sits with the Governor, who has until September 30 to act. The Senate concurred in Assembly amendments 40 to 0 on August 31; the Assembly passed it 74 to 1. It would confine AI in psychotherapy to administrative and supplementary support, and require a licensed professional to review and approve any therapeutic decision, diagnosis, treatment plan, emotion detection, or triage. Newsom has not acted, so it is not law and nothing is banned yet.

  • Anthropic read a chat and called the police A user told Claude on August 14 he had bought an AR-15 and had chief executive Dario Amodei in his sights. Anthropic banned the account and notified San Francisco police six days later. Officers went to 500 Howard Street; the report says the employee would not show them the messages, citing company policy. No arrest, no charge. Anthropic called it the safeguards process working as intended, and published no threshold for when it makes the call.

Brush Your Brain - The jingle

that started a movement

If you or someone you know is in crisis, call or text 988 (Suicide and Crisis Lifeline).

Jess Jessop is the Founder and CEO/CTO of Clinician Assist Inc. (BetterMind.Space), building the first voice-first AI-native mental health EHR with Casey Life and Peer AI Coach supervised by licensed therapists. A disabled veteran and 25-year AI/software engineering veteran, Jess brings lived experience as a mental health client to the mission of making daily mental health care as integrated as oral care.

Reply

Avatar

or to participate