The Wellness and Oversight for Psychological Resources Act is usually described as scope-of-practice law: who may provide therapy. Read through a privacy lens, it is something more consequential — the first U.S. health statute to prohibit machine inference of emotional and mental states, enacted in the state with the fiercest privacy-enforcement record in the country. Deployers who file it under "licensure" will govern the wrong risk.
Strip WOPR (HB 1806, effective August 2025) to its operative mechanisms and it reads like data-protection law.
WOPR was not enacted into a vacuum. Illinois courts have spent seven years demonstrating what happens when organizations treat this state's privacy statutes as aspirational.
WOPR is enforced differently — by the Department of Financial and Professional Regulation at up to $10,000 per violation, with no private right of action. But the BIPA record is the correct climate model for three reasons. First, per-violation penalty structures compound in exactly the Cothron pattern: an ambient tool running unlawfully across a season of therapy sessions is not one violation. Second, the absence of a private right of action in WOPR is not the absence of private litigation: Illinois's Mental Health and Developmental Disabilities Confidentiality Act (740 ILCS 110) independently protects therapy records with its own private right of action, damages, and attorney's fees — and AI processing that violates WOPR's consent gate will frequently also be an MHDDCA disclosure problem. Third, plaintiffs' firms have already shown, in the BIPA and genetic-privacy waves, that they industrialize Illinois privacy statutes at scale once a theory is proven.
Courts and state enforcers are converging on the same territory WOPR regulates — from different directions.
The synthesis: liability theories are consolidating around design (product liability, duty of care), representation (consumer protection), and process (consent, confidentiality). WOPR sits at the intersection — it converts process failures in exactly the encounters the wrongful-death cases involve into per-violation statutory penalties, and it supplies the standard of care a negligence plaintiff will cite. A deployer whose AI use in behavioral health violates WOPR has handed future litigants a negligence-per-se argument gift-wrapped.
Public-records law is quietly becoming AI governance infrastructure — in both directions.
Plaintiffs are using FOIA to build foreseeability records. Within days of the Garcia settlement, plaintiffs' counsel filed federal FOIA requests targeting the FTC's internal analyses from its inquiry into seven chatbot companies — groundwork for arguing that safer designs were known and available. Public records are becoming the discovery-before-discovery of AI litigation. Deployers should assume that what regulators know about a tool's risks will eventually be arguing foreseeability against everyone who kept using it.
Providers can run the same play defensively. The Illinois Freedom of Information Act (5 ILCS 140) reaches IDFPR's WOPR enforcement activity — complaint volumes, disciplinary outcomes, interpretive positions. Monitoring that record is how a deployer learns where the regulator draws lines before the lines are drawn on them. This is the enforcement-intelligence discipline 5Q builds into governance programs: regulatory posture informed by what enforcers actually do, not only what statutes say.
And note the asymmetry forming. Illinois's new frontier-AI law, SB 315 (signed July 6, 2026, with obligations phasing in through January 2028), is built on redacted disclosure: developers publish summaries and redacted copies of safety and audit materials while the Attorney General receives fuller versions. The state will see more about AI risk than the public will. For deployers, that asymmetry raises the value of every transparency artifact that is obtainable — published frameworks, audit summaries, enforcement records — and of the governance capacity to collect and act on them.
5Q Health builds AI governance programs for safety-net and rural providers where consent architecture, confidentiality stacks, and regulatory monitoring are designed together — because in behavioral health AI, they fail together. Vendor-neutral, audit-oriented, scoped to organizations the market skips.
Talk with 5Q HealthAnalysis prepared July 11, 2026; v1.1 reviewed, fact-checked, and updated July 13, 2026 (statutory consent language tightened to "written" consent; SB 315 characterization revised from FOIA-amendment to redacted-disclosure architecture per multiple law-firm analyses; Garcia settlement corroborated via national press reporting of Jan. 7, 2026). Statutory sources: HB 1806 (WOPR) via IDFPR release, Holland & Knight, and Taft Law analyses; 740 ILCS 110; 5 ILCS 140; 815 ILCS 505; 45 C.F.R. § 164.508(a)(2); 42 C.F.R. Part 2. Case authorities: Rosenbach v. Six Flags Ent. Corp., 2019 IL 123186; Tims v. Black Horse Carriers, 2023 IL 127801; Cothron v. White Castle Sys., 2023 IL 128004 (and 2024 legislative response); Garcia v. Character Techs., 785 F. Supp. 3d 1157 (M.D. Fla. 2025), settlement reported Jan. 2026 (CNN, CNBC); Raine v. OpenAI (ongoing, per court-filing reporting); Texas v. Pieces Technologies settlement (Sept. 2024). Confidence notes: Illinois Supreme Court BIPA holdings, MHDDCA structure, and WOPR's "detect emotions or mental states" prohibition — HIGH (settled law; statutory language verified against law-firm analyses of the enacted text). Garcia holding and settlement — HIGH-MED (national press corroboration; docket-level confirmation recommended before client citation). Raine posture, Kentucky AG filing, and the FTC-FOIA development — MED (secondary reporting; verify before client citation). The characterization of WOPR's inference ban as "first of its kind in U.S. health law" is the author's analytical claim, believed accurate as of this date and open to correction. Litigation described is active and will move; this page will be updated accordingly.