Skip to main content

There are more than 20,000 mental health apps sitting in the iOS and Google stores. How many of the teams behind them chose which side of the regulatory line their product sits on? 

Many health technologies choose a brand position, write app store copy, and potentially inherited a regulatory status by accident.

Two things decide that status: what you claim your software does, and what your software does with a user's data. Your brand positioning is irrelevant to both. "Wellness" is a description of purpose, not a category you can opt into by writing the word on your homepage.

 

Regulators read your app store listing

Under the UK Medical Devices Regulations 2002, software placed on the market for a medical purpose needs a UKCA mark. Medical purpose means diagnosis, prevention, monitoring, treatment or alleviation of disease. MHRA's guidance on stand-alone software puts symptom checkers at Class I, then moves them to Class IIa the moment they allow direct diagnosis. One capability, two regulatory worlds.

In the US, the FDA is blunter about the evidence it uses. Its position is that a product's regulatory status gets determined largely by website and promotional claims, product labelling, and app store descriptions. Its General Wellness guidance, finalised on 6 January 2026, contains the clearest worked example anyone has published. Software that helps someone with diagnosed PTSD, depression or OCD "maintain their behavioural coping skills" through a daily skills prompt sits under enforcement discretion. Software claiming to treat the condition is a device.  Same content, different verb.

The EU draws the line hardest. MDCG 2019-11 and Rule 11 of the MDR mean software pursuing a medical purpose for an individual patient lands at Class IIa or above in almost every case, which drags in a Notified Body, an ISO 13485 quality system and a clinical evaluation. Software that exclusively pursues administrative, lifestyle or wellness purposes stays outside. There's very little middle ground.

So the practical question for any supplier is somewhat simple: Does anything in your product, or in the copy describing it, name a condition and then act on it?

 

7 features that might move you across the line

  1. Naming a condition rather than describing a state
    "Manage stress" and "build coping skills" describe states. "Treat anxiety" and "reduce depression" name conditions and promise clinical outcomes. This one word choice is where most products decide their regulatory fate, usually without noticing.

  2. Validated questionnaires that drive an output
    A PHQ-9 administered passively, score stored, number shown back to the user: low risk. The moment that score changes what the app recommends, routes the user somewhere, or produces a risk flag, your software is providing information for a clinical decision. That's medical device software under Rule 11 and under MHRA's reading.

  3. Triage, risk scoring or anything resembling diagnosis
    The clearest trigger there is, and the one with the sharpest classification jump.

  4. A structured therapy programme
    Delivering CBT, ACT or DBT as a sequenced course pulls you into device territory and raises the evidence bar considerably. Rejoyn, SilverCloud and Deprexis all sit on this side of the line, and all three needed clinical trial data to get there.

  5. Generative AI that responds to what users disclose
    The fastest-moving area, and the one under most scrutiny. The FDA's Digital Health Advisory Committee spent 6 November 2025 on generative AI in digital mental health and named three risks specific to this class of product: bias, hallucination, and sycophancy, where the model tells the user what they want to hear at the expense of accuracy. Sycophancy is the interesting one. A chatbot optimised for engagement and a chatbot that's safe for a distressed user pull in opposite directions.

  6. Crisis detection and escalation
    This one cuts both ways. Building it can push you toward device status, and leaving it out is worse. NHS England required the Spring PTSD product to add crisis support information before approval, New York now mandates suicide-risk protocols for AI companions, and the Character.AI litigation turns on failure to escalate rather than on anything the product claimed.

  7. Reporting into clinical records or back to a clinician
    Once a clinician acts on your output, you're in clinical decision support territory, with the interoperability and data obligations that follow.

 

The disclaimer defence has already failed

Plenty of products carry a line saying "this is not a therapist" and treat it as cover. Illinois closed that door.

The Wellness and Oversight for Psychological Resources Act, signed on 1 August 2025, prohibits offering therapy through AI unless a licensed professional delivers it, reaches advertising as well as conduct, and comes with penalties up to $10,000 per violation. The principle regulators have landed on is that a disclaimer saying a chatbot is not a therapist does nothing for a product that functions as one, or that markets itself as one.

As of July 2026, five US states ban AI-delivered therapy outright: Illinois, Nevada, Tennessee, Vermont, Rhode Island and Maine. Utah, New York, California and Nebraska regulate instead. The real exposure for suppliers is the patchwork. One product can satisfy Utah's disclosure requirements to the letter and still be practising illegally in Illinois.

 

Staying on the wellness side has a price

There's a reasonable case for staying out of scope. Lower cost, no Notified Body queue. Class IIa MDR certification runs 13 to 24 months and €10,000 to €30,000 in Notified Body fees alone, before you count ISO 13485 and the clinical evidence itself.

The cost sits on the other side of the ledger. Germany's DiGA scheme and France's PECAN both require medical device status, so a wellness app can't be prescribed or reimbursed in either country. NHS Talking Therapies wants a UKCA or CE mark where the product is a device, then DTAC, then a separate Digitally Enabled Therapies assessment, and NHS England is explicit that these products must be delivered with practitioner support.

Payers and employers in the US want clinical evidence well beyond any regulatory minimum. Positioning as wellness to avoid regulation forecloses every route where the money is.

 

The binary is a poor instrument, and everyone knows it

The wellness/clinical split is a crude way to sort products by risk, and the people using it know that. When researchers tested how consistently assessors could place digital health tools into NICE evidence tiers, agreement was poor (a Cohen's κ of 0.32, which is roughly coin-toss territory for a framework people are meant to plan around). NICE's own standards, the EU AI Act's tiers and MHRA's post-market surveillance reforms all reach for risk proportionality instead of categories, because categories break at the edges.

Regulators are pulling in different directions too. The FDA's January 2026 guidance on general wellness and clinical decision support is openly deregulatory. The European Commission proposed amending Rule 11 in December 2025 to let more software back into Class I, though nothing lands before 2027 at the earliest.

None of that helps a supplier trying to arbitrage the boundary. MDCG guidance warns that modular architectures must not be used to bypass classification rules, Tennessee is pursuing mental health AI marketing under a consumer protection statute from 1977, and the FTC has gone after health app data sharing twice at scale.


Decide early, because retrofitting is the expensive failure

The teams that get hurt are the ones that discover their regulatory status two years in, from a buyer's due diligence questionnaire or a warning letter. By then the quality system and the design history have to be reconstructed backwards.

For AI products, some of it can't be reconstructed at all. Training data provenance, model versioning, the rationale behind a change made 18 months ago by an engineer who has since left: that record either exists contemporaneously or it doesn't exist. Everything the FDA now expects for generative AI devices, from predetermined change control plans to model drift monitoring, assumes you were writing it down as you went.

So pick your side at concept stage. Audit every claim in your marketing, your app store listing, your onboarding flow and your sales deck against the state-versus-condition test. If anything in your product names a condition and acts on it, assume Class IIa and build accordingly.

The products that make it into care pathways are the ones whose makers chose that path deliberately, and started building the file on day one.