Is AI therapy safe? It depends entirely on how it is built.
The honest answer is that some of it is and some of it is not, and the difference is engineering, not marketing. Stanford researchers found chatbots that answered a question about tall bridges instead of noticing suicide risk. The American Psychological Association advised in 2025 that generative AI should not be used for psychotherapy, diagnosis, or crisis support. Illinois, Nevada, Utah, California, New York, and Tennessee have passed laws about it. This page explains what the concerns are, what the rules say, and what a safe design looks like, using Aura as the worked example.
By The Calm AI Therapy editorial team. Not reviewed by a licensed clinician, and not a substitute for one. How we research and write.
The four documented failures
- Sycophancy: agreeing with whatever you frame, including harmful beliefs. Stanford found this in most messages inside delusional conversations.
- Missed crisis: not recognising risk, or handing over a hotline from the wrong country, or none at all.
- Forgetting: starting from zero each time, so nothing accumulates and nothing is noticed.
- Pretending: implying a licence, a diagnosis, or confidentiality that does not exist.
What the laws now require
Illinois prohibits providing or advertising therapy through AI without a licensed professional involved. Nevada bars AI that represents itself as professional mental-health care. Utah requires disclosure that you are talking to an AI, at first use and after a break. California requires non-human disclosure and crisis protocols, with protections for minors. New York requires detection of suicidal ideation. The common thread: say what you are, detect risk, and never claim to be a clinician. Aura is built to that thread, and we do not market her as therapy in the legal sense anywhere in the product.
What a safe design looks like
That is Aura's design, and every item on the list is enforced in code, not just written in a policy. The detail is on the crisis safety page.
- Every message is checked for risk before a reply is written, in the language it was written in
- The check has two layers: a fast rules layer and a model layer that can only raise the alarm, never lower it
- A serious moment stays in view for the rest of the conversation, however the next message reads
- The crisis line shown is for the country you live in
- No diagnosis, no medication advice, no method talk, enforced by rules and checked after every reply
- Plain disclosure: an AI, support, not a substitute for care, and when to see a professional
What AI support is good for, and not for
Good for: the 2am thought, the argument you are rehearsing, being heard between appointments, noticing patterns over weeks, a first step for people who would never book a session. Not for: a diagnosis, a medication decision, an emergency, or replacing a clinician when one is needed. Aura says the second list out loud when it applies.
Your data
The other safety question is privacy. Independent reviews have found most mental-health apps sell or share data. Aura stores your conversations for you, in your account, uses them only so she can remember you, never sells them, never trains a model on them, and lets you delete everything in one click.
Common questions
Is AI therapy safe?
It can be, when the product checks every message for risk, shows real crisis lines, never diagnoses, and tells you what it is. Products without those are not. Aura has all four, enforced in code.
Is AI therapy legal?
Using AI support is legal everywhere. Several US states restrict providers from offering or advertising AI as therapy without a licensed professional. Aura is offered as support, not therapy, and does not diagnose or treat.
What does the APA say?
The APA's 2025 advisory says generative AI should not be used for psychotherapy, diagnosis, or crisis support, and should be an adjunct to care. Aura's design follows that: support, not treatment.
What happens if I say something serious to Aura?
She slows down, stays with you, shows the crisis line for your country, and follows a written script. If you are in immediate danger, contact your local emergency number first.
Is my conversation private?
Stored in your account, used only so Aura can remember you, never sold or used for training, deletable in one click. Aura is not a licensed clinician, so legal privilege does not apply.
Sources
- "This app said I had severe depression": unintentional harms of mental health apps — ACM CHI, 2024
- APA advisory on the use of AI in mental health — American Psychological Association, 2025
- mHealth app user perspectives: sentiment and thematic analysis — Frontiers in Psychiatry, 2022
See the safety layer work: say one honest sentence on the homepage.
Try one sentenceRelated