Resources / 8: Ethical, Legal & Professional Issues / AI in Practice

Maya holds a balance scale with the bunny in one pan and books in the other

AI in Practice

8: Ethical, Legal & Professional Issues

Why AI Ethics Is Now Exam Material

Note-taking scribes that listen to sessions, chatbots that draft reports, algorithms that suggest a treatment plan. AI tools are already inside psychological practice, and the Ethics Code was last amended before most of them existed. APA has filled the gap with guidance documents, and the EPPP tests emerging issues like these under the ethics domain. This lesson covers the two documents you need: APA's Ethical Guidance for AI in the Professional Practice of Health Service Psychology (updated July 2025) and the APA Ethics Committee's FAQ on artificial intelligence and social media (November 2023).

Think of the Ethics Code as the building code and these documents as the inspector's notes on a brand-new kind of wiring. The notes are not law, but they tell you how the existing rules apply.

What This Guidance Is (and Isn't)

Know the status of the AI guidance cold, because status questions are easy points:

  • It was written by APA's Mental Health Technology Advisory Committee (MHTAC) and adopted by the APA Ethics Committee.
  • It is not official APA policy, not exhaustive, and its considerations are not mandatory or enforceable. It is not meant to guide regulatory action.
  • It is informed by the 2017 Ethics Code and aligned with the five General Principles (Beneficence and Nonmaleficence, Fidelity and Responsibility, Integrity, Justice, Respect for People's Rights and Dignity).
  • Psychologists must still follow the standards of their practice setting and all federal and state law.

This is the same guidelines-versus-standards distinction the Code's Introduction draws (covered in the Standards 1 and 2 lesson). Standards are enforceable rules. Guidance describes best practice.

The Ethics Committee FAQ adds a decision-making tool: Behnke's four-bin approach. Sort a dilemma into its ethical, legal, clinical, and risk-management parts, work each bin, then reintegrate them. Haug and Gandhi (2021) added a fifth sociocultural bin for identity, systems, and power dynamics. The FAQ applies these bins to every AI scenario it discusses.

The Six Areas of the Guidance

AreaWhat it asks of youPrinciple it leans on
Transparency and informed consentDisclose AI use, obtain consent, honor opt-outsE: Rights and Dignity
Bias and equityCheck how tools were normed and trainedE: Rights and Dignity
Data privacy and securityHIPAA-compliant tools, know where data goesA, B, E
Accuracy and misinformationValidate before use, keep evaluatingA and Integrity
Human oversightAI augments judgment, never replaces itA and B
LiabilityNegligent reliance on AI is your liabilityLegal, still emerging

Transparency and Informed Consent

Disclosure scales with substance. Predictive text in your notes is subtle and low stakes. A health system using AI to pick a patient's treatment approach is substantial and needs real discussion. Disclose AI use to the people receiving care, to other relevant providers, and to any third party who counts as a client (a court, for example), in a culturally and linguistically appropriate manner.

The consent conversation should cover the tool's role, limitations, risks, and benefits. Clients have the right to opt out of certain AI-driven interventions, and best practice is to spell out the alternatives (non-AI care with you, staying on a waitlist, referral) with the pros and cons of each. Tell clients whom to contact if they have concerns or want to withdraw consent. Written consent forms may state when, how, and which AI tools you use.

This flows straight from the Code. Standard 3.10 requires informed consent for services delivered in person or via electronic transmission. Standard 4.02(c) requires anyone offering services electronically to inform clients of the risks to privacy and limits of confidentiality. Standard 10.01(b) says that when a treatment lacks generally recognized techniques, you disclose its developing nature, risks, alternatives, and the voluntary nature of participation.

Mitigating Bias and Promoting Equity

An AI tool can quietly widen mental health disparities if it was trained or normed on a narrow population. A ruler calibrated in one neighborhood measures everyone else wrong. Review how a tool was normed and what data it learned from, watching for anything that reinforces stereotypes. Principle E asks psychologists to strive to eliminate the effect of bias on their work. The guidance also encourages psychologists to help build representative datasets, especially from underrepresented regions, within privacy rules.

Data Privacy and Security

Any tool that touches client data must be usable in compliance with HIPAA and other federal and state privacy law. Know how the tool uses, stores, and shares data, including aggregated or de-identified data, and tell clients. If security concerns arise, avoid the tool or discontinue it.

A consumer chatbot is a postcard, not a sealed envelope. Whatever you type can be read, stored, and used to train the next version. The FAQ is blunt: never input identifiable client information into ChatGPT or similar tools. It also covers an AI meeting bot that joined a consultation group without permission. Ask whether organizational policy allows it, whether it is HIPAA compliant, and whether clients know a program is collecting their information. The relevant standards are 4.01 (confidentiality in any medium), 4.02 (limits of confidentiality), 3.10 (informed consent), 3.04 (avoiding harm), 6.01 (records documentation), and 6.02 (confidential records, including automated ones). Standard 6.02(b) adds that when client information enters a database others can access without the client's consent, you use coding to avoid personal identifiers.

Accuracy and Misinformation

AI output can be wrong, made up, or biased. Critically evaluate AI-generated content both when you start using a tool and on an ongoing basis, and critically evaluate any tool you recommend to clients. Prefer products whose developers have published their accuracy and reliability testing, disclose their training data, and offer ways to audit performance. Under Integrity, you take responsibility for the quality of information in your practice, which includes promptly dropping a tool when misinformation concerns arise. Standard 2.04 (judgments rest on established scientific and professional knowledge) and Standard 9.09 (select automated scoring or interpretation services on evidence of validity, and retain responsibility for their use) are the Code hooks.

Human Oversight and Professional Judgment

AI should augment, not replace, human decision-making. Treat the model like a bright intern: useful drafts, your signature. Build human-in-the-loop checkpoints into any AI workflow so a psychologist reviews output before it affects care. You remain responsible for the final decision, and you approve or reject AI recommendations using your own judgment, the research evidence, and professional standards. An AI recommendation is never a defense for a bad clinical call.

Liability and Ethical Responsibility

The law here is still forming, but one point is clear: negligent reliance on AI without validation or oversight can create liability. Understand the legal and ethical risks of the tools you select, make sure staff are trained on them, and remember that transparency and competence are what manage legal risk.

Staying Competent as the Tools Change

Standard 2.03 requires ongoing efforts to maintain competence, and Standard 2.01(c) says that before you use a technology new to you, you undertake relevant education, training, supervised experience, consultation, or study. Standard 2.01(e) covers emerging areas with no recognized training standards yet: you still take reasonable steps to ensure competence and protect clients from harm. The AI guidance turns this into concrete habits. Participate in continuing education on mental health AI, join interdisciplinary discussions, collaborate with developers, and engage with the organizations shaping AI policy, because staying out leaves the decisions to people without psychological expertise. The FAQ adds a practical step: experiment with the tools yourself to learn what they do well and where they fail.

AI in Teaching and Supervision

The FAQ's first scenario is students using ChatGPT for assignments and assessment reports. Standards 7.01 (program design) and 7.06 (assessing performance) support a written syllabus or organizational policy on AI use. Students should document what is their original work versus AI output and show critical thinking beyond it. Oral exams can assess competence when written work is easy to outsource. Trainees must never paste identifiable client data into these tools (Standard 4.01), and because psychologists are responsible for the accuracy of test interpretation (Standard 9.09), any AI used in testing or report writing must be cited and checked.

Common Misconceptions

Misconception 1: "APA's AI guidance is now part of the Ethics Code."

Reality: It is guidance adopted by the Ethics Committee, informed by the Code, and explicitly not enforceable. The Code still governs through existing standards like 3.10, 4.01, and 2.01.

Misconception 2: "If the AI tool made the recommendation, the tool is responsible."

Reality: The psychologist keeps responsibility for every final decision. Negligent reliance on AI is a liability risk for you.

Misconception 3: "Small AI uses like autocomplete need the same consent discussion as an AI treatment planner."

Reality: Disclosure scales with how substantial the use is. Subtle uses may need little; anything shaping care needs real discussion and consent.

Misconception 4: "De-identifying the data means I can use any chatbot."

Reality: You must still know how the tool stores and shares data, use HIPAA-compliant tools for client information, and stop using a tool when security concerns arise.

Misconception 5: "Once a tool is validated I can stop checking it."

Reality: Evaluation is ongoing, not one-time, and you discontinue a tool promptly if misinformation concerns appear.

Practice Tips

  • Status questions: guidance, adopted by the Ethics Committee, not enforceable, informed by the 2017 Code.
  • Consent questions: disclose, explain limits and risks, offer opt-out with alternatives, name a contact for concerns.
  • Data questions: HIPAA-compliant, know the data flow, never identifiable data in consumer tools.
  • Judgment questions: the human decides; the AI advises.
  • Competence questions: 2.01(c) for new technology, 2.03 for ongoing effort, continuing education on mental health AI.

Key Takeaways

  • The AI guidance is not enforceable policy; it maps the existing Code and General Principles onto AI tools.
  • Transparency and informed consent rest on Principle E and Standards 3.10, 4.02(c), and 10.01(b); clients can opt out.
  • Check how tools were normed and trained so they do not widen disparities.
  • Use HIPAA-compliant tools, know where data goes, and discontinue tools with security concerns.
  • Validate AI output at the start and continuously; Standards 2.04 and 9.09 keep responsibility with you.
  • AI augments judgment; human-in-the-loop review is advised and negligent reliance creates liability.
  • Competence with new technology is a Code duty (2.01(c), 2.01(e), 2.03) met through continuing education and hands-on experimentation.
  • In training settings, set AI policies, require disclosure of AI-assisted work, and keep client data out of consumer tools.

Ready to practice?

Get started in the app