Skip to main content

Practice & Policy · 18 min read · Field Notes

CARF's New AI Standard: Written Policy, Human Oversight

2026-07-26 Matthew Sexton, LCSW, NATC All Field Notes

Quick answer VibeCheck.luxury is built so that the AI does the work and the clinician signs it, and as of July 1, 2026, that arrangement is no longer just a design preference, it is an accreditation requirement. CARF International says it is the first accreditor to implement an AI standard requiring written policies and procedures when AI is used in delivering a program or service. The standard lists seven things an organization must demonstrate. The first is human oversight as final decision-making authority. The rest are training, a governance committee, disclosure to persons served, privacy protections, incident response, and annual review. The requirement bites when AI is used in relation to the delivery of a program or service, which is broader than a clinical decision tool and narrower than any software you happen to own. It binds CARF-accredited organizations, so a solo practice with no accreditation is not covered today. — Matthew Sexton, LCSW, NATC

By Matthew Sexton, LCSW, NATC — a Licensed Clinical Social Worker and Certified Narcissistic Abuse Treatment Clinician in private practice, who built VibeCheck.luxury around this principle.

For about two years the honest answer to "what are the rules for AI in a behavioral health practice?" was that there weren't any. There was HIPAA, which predates all of this and speaks to protected health information rather than to automated decisions. There were state laws arriving one at a time, mostly aimed at chatbots that pretend to be therapists. And there was a large gray middle where a clinician quietly used a tool to draft a note and nobody had written down what that meant.

That gray middle just got smaller.

What the CARF AI standard actually asks for

CARF's own language is specific about the trigger. The requirement applies when AI is used in relation to the delivery of a program or service. The test is whether the tool touches the service, not whether it touches a clinical decision. A scheduling tool with a predictive feature is probably in scope. Your accountant's spreadsheet is not.

Diagram: the seven things CARF requires an organization to demonstrate when AI is used in delivering a program or service, with human oversight as final decision-making authority listed first.

The organization has to be able to demonstrate seven things:

  • 1. Human oversight as final decision-making authority
  • 2. Regular training for the staff who use or supervise AI tools
  • 3. A governance committee that assesses whether vendors are trustworthy and transparent
  • 4. Disclosure to persons served about how AI is being used
  • 5. Privacy protections
  • 6. Incident response protocols for when something goes wrong
  • 7. Annual review of the policy

Read that list twice and notice what it is not. It is not a ban. It is not a technical specification. There is no accuracy threshold, no approved-vendor list, no requirement to use or avoid any particular model. It is a governance standard: it asks who decided, who was trained, who was told, and what happens when it breaks.

That is the same question a chart audit asks, now aimed at software.

Requirement one is the whole argument

Put the other six aside for a moment, because the first one carries the weight.

Human oversight as final decision-making authority. An accreditation body has now written down, as a condition of accreditation, that the person is the decider and the software is not. Not "the software should be accurate." Not "the software should be supervised." The authority to decide sits with a human being, and the organization has to be able to show it.

I have been making a version of this argument for a while, and I have been making it as a product opinion, which is a weak place to argue from. A vendor saying "our AI keeps a human in the loop" is marketing. An accreditor saying "human oversight is requirement one" is something else. It converts a preference into a floor.

It also quietly settles a debate that has been running in every practice-owner forum I read. The question is usually framed as how much AI is too much. The standard reframes it: the amount is not the issue, the authority is. A tool that drafts ten notes and hands all ten to you for signature is governed. A tool that files one note without you is not, no matter how good it is.

Who the CARF AI standard binds, and who it does not

Here is where I have to be straight with you, because a lot of what gets published about this standard over the next month will overstate it.

CARF accreditation is voluntary, and it is overwhelmingly an organizational thing. Agencies, clinics, treatment programs, hospital departments, and community behavioral health organizations pursue it. If you are a solo clinician seeing clients in a fee-for-service private practice, no one is coming to audit your AI policy on July 2, and this standard by itself creates no obligation for you.

So if you are solo, why should you read the rest of this?

Because the expectation travels. Not as a rule, but as a norm. Three specific paths:

  • If you contract with, subcontract for, or take referrals from an accredited organization, that organization now has to be able to demonstrate governance over AI used in service delivery. Some of them will start asking their contracted providers what they use and what their policy says. Not all. Some.
  • If you ever want to become accredited, or join a network that requires it, the standard is now the target rather than a moving question.
  • If a complaint is ever filed about your documentation, the existence of a written, dated AI policy is the difference between "I reviewed everything" and being able to show what reviewing meant.

The standard also applies across all of CARF's manuals through its ASPIRE to Excellence framework: aging services, behavioral health, child and youth services, employment and community services, medical rehabilitation, and opioid treatment programs. This is not a behavioral-health-only rule. It is the whole book.

Somebody called this a year ago

Someone flagged this gap in advance. ECRI's Top 10 Patient Safety Concerns for 2025, an annual list from a patient-safety organization, included insufficient governance of artificial intelligence in healthcare as one of its named concerns.

That sequence is worth noticing, because it is the normal shape of how this stuff arrives. A safety body says the governance is missing. Roughly a year later, an accreditor writes governance into the standards. Then, usually, payers start asking. None of the three steps involves anyone banning the technology.

If you are trying to predict what comes next, that is the pattern to extrapolate from, not the louder debate about whether AI belongs in mental health at all.

CARF was first. COA moved too.

One detail worth getting right, because it is easy to garble and I nearly did.

CARF is the one claiming first-mover status on an AI standard requiring written policies and procedures for AI used in service delivery. Separately, COA (the Council on Accreditation) released 2026 updates adding AI standards for private, public, and Canadian organizations, aimed at responsible and ethical AI adoption in the social sector.

Two accreditors, same year, same direction. If you are accredited by COA rather than CARF, you are not exempt from the trend. You are just reading a different document. Check your own accreditor's 2026 update rather than assuming this article covers you.

What a written AI policy actually looks like

"Written policies and procedures" sounds like a consulting engagement. For a small practice it is closer to two pages, and most of it is inventory.

A serviceable policy answers:

  • What tools are in use, by name and version, and what each one touches. A scribe that hears a session and a scheduler that suggests slots carry different risk and belong in different rows.
  • Where protected health information goes, and whether a Business Associate Agreement is executed with anyone who touches it. This is the part people skip, and it is the part that matters. Note that the U.S. Department of Health and Human Services runs no certification program for the HIPAA Rules, so a vendor advertising a certification it cannot hold is telling you something about its marketing rather than its posture. What you want is HIPAA-eligible infrastructure with a signed BAA.
  • Who reviews the output before it becomes part of the record, by role, and what "review" concretely means. "I read it" is a defensible answer if it is true and consistent.
  • What clients are told, and where: intake paperwork, consent, or a conversation.
  • What happens when it is wrong. Who gets told, how the record gets corrected, and where you log that correction.
  • When the policy gets re-read. Annually is now the accreditation expectation, and it is a reasonable one, given how fast the tools change.

If you already have a documentation policy, this is a section of it, not a separate binder.

Where VibeCheck.luxury sits in this

I will be plain about the product, and plain about its limits.

VibeCheck.luxury is built on the principle the standard's first requirement describes: the AI drafts, the clinician decides, and the clinician's signature is the thing that makes it real. That is an architectural choice, made before this standard existed, and it is the reason a standard like this one reads to me as a floor rather than a threat.

What I am not going to tell you is that buying a subscription satisfies an accreditation standard. It does not. No software satisfies a governance requirement, because the requirement is about your policy, your training, your disclosure, and your review, things a vendor cannot do for you. A tool can make the review easy or make it hard. Ours tries to make it easy. That is the honest scope of the claim.

Everything in the product is one price: $77.77 a month per clinician seat, unlimited clients, no tiers.

The short version

An accreditor wrote down that a person has to be the one deciding. If you are solo, nothing here obligates you today, and the norm is still moving toward you. If you are accredited or headed there, the seven items are the checklist, and the honest work is the inventory rather than the software.

The tools were always going to arrive before the rules. This is what it looks like when the rules catch up a little. Not a prohibition, just a demand that somebody be accountable, by name, for what the software did.

If you want to talk through what a written AI policy looks like for your specific setup, book a call.

FAQ

Does CARF's AI standard apply to my solo private practice?

Not directly. CARF accreditation is voluntary, and organizations pursue it almost exclusively (agencies, clinics, treatment programs) rather than solo fee-for-service practices. If you are not CARF-accredited and not seeking accreditation, this standard creates no obligation for you on its own. It still matters indirectly: if you contract with or take referrals from an accredited organization, that organization now has to demonstrate governance over AI used in service delivery, and some will begin asking contracted providers what they use. The standard took effect July 1, 2026.

What does "human oversight as final decision-making authority" actually require?

That a person, not the software, holds the authority to decide. In practice it means output from an AI tool cannot become part of the clinical record or drive a service decision without a human accepting it, and the organization has to be able to demonstrate that this is how it works, by role, in writing. It does not set an accuracy threshold, restrict which tools you may use, or require that a human re-do the AI's work. The distinction the standard draws is about authority, not about how much of the drafting the software did.

Is CARF the first accreditor to require an AI policy?

CARF International states that it is the first accreditor to implement an AI standard requiring written policies and procedures if AI is used in relation to the delivery of a program or service, effective July 1, 2026, across all its standards manuals through the ASPIRE to Excellence framework. Separately, COA released 2026 updates adding AI standards for private, public, and Canadian organizations. If you are accredited by COA rather than CARF, consult your own accreditor's 2026 update. The direction is the same, but the document is different.

Do I need a Business Associate Agreement with an AI vendor?

If the vendor's system creates, receives, maintains, or transmits protected health information on your behalf, then yes. That is the standard HIPAA business-associate analysis, and it is unchanged by the CARF standard. The thing to watch is any vendor advertising a HIPAA certification. The U.S. Department of Health and Human Services operates no such certification program, so that phrasing describes marketing rather than a compliance status. What you want is HIPAA-eligible infrastructure and an executed BAA, and you want to know specifically whether PHI reaches the AI layer at all, or whether something strips it first.

Sources

  1. CARF International: "CARF implements first AI standard in health and human services accreditation." carf.org news release. Effective July 1, 2026.
  2. ECRI: Top 10 Patient Safety Concerns 2025, which lists insufficient governance of artificial intelligence in healthcare.
  3. Social Current: "2026 COA Accreditation Standards Updates," May 2026.
  4. U.S. Department of Health and Human Services: HHS operates no certification program for the HIPAA Rules.

About the author

Matthew Sexton, LCSW, NATC, is a practicing psychotherapist in private practice. He built VibeCheck.luxury, a HIPAA-eligible clinical support tool, for his own caseload — by a clinician who does this paperwork, for the clinician who's tired of it. It is not an AI therapist and not a replacement for the clinician.

Disclaimer

This article is for educational and informational purposes only. It does not constitute medical, clinical, legal, or therapeutic advice, and reading it does not create a therapist-client relationship with Matthew Sexton, LCSW or Mental Wealth Solutions PLLC. Although the author is a licensed clinical social worker, the content in this article is not clinical assessment, diagnosis, or treatment.

It is general information about accreditation standards and does not constitute legal, compliance, medical, or clinical advice. Matthew Sexton, LCSW, NATC, is a Licensed Clinical Social Worker in private practice and the founder of Mental Wealth Solutions. Reading this article does not create an advisory relationship. Accreditation requirements vary by accreditor, program, and jurisdiction and change over time. Confirm current requirements with your own accreditor and with counsel before relying on anything described here.

If you are in immediate emotional crisis, you can reach the 988 Suicide & Crisis Lifeline by calling or texting 988 (US). If you are experiencing domestic violence or are in physical danger, contact the National Domestic Violence Hotline at 1-800-799-7233 or visit thehotline.org. In a life-threatening emergency, call 911.

Built by a clinician who does this work too.

See VibeCheck.luxury → See pricing — $77.77/mo per seat →