It's always good to refresh one's ethical awareness, and so a periodical reread of the Code of Professional Ethics for Psychologists (2017) is a good use of one's time. But today, besides scanning the work as a whole, I paid particular attention to the ethics governing the use of technology. Of course, issued in 2017, there is nothing here discussing AI — but as we discussed in the previous article, there is nothing technologically unique (as pertains to privacy) about AI-enriched software platforms. I am sure we will be delivered — in due course — with a clear set of ethical guidelines governing the use of AI in clinical formulation and decision making, in report writing, in assisting with and collecting assessment data, in delivering psychotherapeutic interventions, and goodness knows what else. But as of now, only general guidelines have been offered on the Israeli scene, and those too will be summarized in this article. As promised in the previous article, this one begins to explain how to stay legally safe as well as professional and ethical while integrating more technology, and especially AI technology, into your practice. It is worth stating at the outset that a formal ethics guideline has been released — and is linked below — but I wish to offer a more rigorous treatment. So let's take a dive into the clauses of the ethical code (whose relevant extracts are cited) that seem most relevant. 2.1 התערבות פסיכולוגית פסיכולוגים יבססו את עבודתם על שיקול דעת מדעי ומקצועי, וזאת גם כשנוקטים שיטות חדשות וניסיוניות. נימוקי ההתערבות המקצועית אמורים להיות מובנים ללקוח או למייצגיו החוקיים כך שיוכלו להסכים עליה מדעת. This one seems to mandate that all decisions you take as a psychologist are based on professional judgment — and it explicitly extends that duty to new and experimental methods, which is precisely where AI sits today. To make use of AI-based interventions, arguably in both psychotherapy and psychological assessment, you have to be confident that YOUR professionalism underpins your decisions. Moreover, the nature of the AI's assistance needs to be made clear to the client in terms they can understand to ensure you have fully informed consent. 3.11 העברת רשומה פסיכולוגית במאגרי מידע אין להעביר רשומות פסיכולוגיות למאגרי מידע שמחוץ למערכות שבהן עובדים הפסיכולוגים. פסיכולוג שיודע כי המידע שקיים על לקוח שלו מועבר למאגר מידע חיצוני למערכת שבה התקבל המידע, יידע על כך את הלקוח. This clause is tricky to interpret. Its first element implies a blanket prohibition on transferring records outside the core systems with which you work, and there are no workarounds. The second clause does not sound like a licence to do so anyway provided you cooperate and obtain the consent of the client — it seems to specifically address a case where the transfer is outside your control; when data moves to an external database for reasons you didn't initiate and can't prevent. In light of this clause, what remains unclear is: Does this apply to placing parts of the client's file in an external system, or only to moving the entire file? In other words, would it even cover running OCR on a single document? And if the client's consent is received before outsourcing their data, is this permitted? Surely it should be — consent is the backbone of all interventions and much of the code — but the text doesn't say so, and is thus confusing. And finally, how about if the data is anonymized, so that no external software holds anything identifying? 3.13 רשומת אבחון ומסירת חומרי גלם אין למסור חומרי גלם למי שאינו פסיכולוג. זאת, מטעמי שמירה על ביטחון המבחנים. רשומת האבחון המלאה וחומרי הגלם יימסרו ישירות רק לידי פסיכולוג בעל מומחיות בניתוח ממצאי האבחון שאותו הרשומה מסכמת. הפסיכולוג המאבחן יוודא את זהות הפסיכולוג שאליו מבקשים הלקוח או באי כוחו להעביר את החומרים. I think this one could conceivably be stretched to forbid passing raw assessment data to an AI, pointing either to the concern of data leaks — as though your passing the data would expose it to the web when the rest of the entire internet has already done so many times over — or to the claim that data may only be passed to a qualified professional. I think such an argument is farfetched. Firstly, legal contracts with the AI provider forbid the divulging of uploaded information, especially when using secure, enterprise-grade platforms. Secondly, when considering the receiving professional's qualification, one must intuit the underlying principle: only those who both have the ability to use these materials and respect the need to shield test content from the public should be privy to them, because they can be trusted not to contaminate the instrument. That principle applies just as well to an AI bound by a legal contract not to retain or republish what it receives. As for its capacity to derive professional-grade insights that match or surpass humans — that's a discussion for another time. Opponents of AI are quick to point to its imperfections, often holding these against an idealized standard of perfect and utterly objective human assessment. Those who sit on statutory committees and see actual assessments likely have a more nuanced perspective on this issue. 4.4 חשיפת מידע הקשור בלקוחות הקלטה, צילום, צפייה במראה חד־כיוונית וכן נוכחותו של אדם נוסף בעת ההתערבות המקצועית ובמהלך מחקר, יתקיימו רק לאחר השגת הסכמה של המשתתפים או מייצגיהם החוקיים. It goes without saying that using AI-based transcription software for recording, summarizing and dissecting your interactions with clients requires their prior consent. The clause is triggered by the recording itself, before you even reach the question of what the AI then does with it. 4.5 הגנה על מידע חסוי במאגרי נתונים אם מידע חסוי הנוגע ללקוחות של פסיכולוגים מוכנס לבסיס נתונים או למערכת רישום בהיתר ועל פי דין, ואם בסיס הנתונים או מערכת הרישום זמינים לאנשים שהלקוחות לא אישרו להם גישה למידע שמאוחסן בו בעניינם, ישתמשו הפסיכולוגים בקודים או בשיטות אחרות כדי למנוע הכללת רכיבים מזהים אישיים של הלקוחות (כגון: שם, מספר זהות וכדומה). This is relevant should a psychologist share a software account — AI or otherwise — with colleagues. In other words, practically speaking: if you use software that stores client data, you must ensure that each psychologist has an individual account, such that only they can access their own client files. 5.1 הסכמה מדעת להתערבות מקצועית החוזה המקצועי, בכתב או בעל־פה, הוא ההסכם שבין הפסיכולוג לבין הלקוח או מייצגיו החוקיים, והוא מחייב את שני הצדדים... סמוך ככל האפשר לראשיתה של ההתערבות, פסיכולוגים יספקו מידע הולם על אופייה של ההתערבות הכולל את תכליתה, סיכוייה, סיכוניה וחלופותיה. בראשיתה של ההתערבות על הפסיכולוגים ליידע את הלקוח על דבר קיומו של תיק פסיכולוגי ועל הרשומות שבו על אודותיו. על הפסיכולוגים להבהיר את התנאים לשמירתו, לזכויות העיון בו ולקבלת העתק ממנו. באחריות הפסיכולוגים ליזום את קבלת ההסכמה מדעת, לדאוג לקיומה לאורך כל ההתערבות ולתעד אותה ברשומה. ההסכמה מדעת הנדרשת מהלקוחות וממייצגיהם החוקיים תוצג כתנאי לקיומה של ההתערבות. ההסכמה מדעת יכולה להתקבל בחתימת הלקוח או מייצגיו או בהיגדיהם שבעל־פה. אם ההסכמה מדעת התקבלה בעל־פה, יש לתעד אותה ברשומה וליידע את הלקוח על דבר התיעוד. If AI is used in any way, shape or form to handle client data or to assist in the assessment or therapy process, clients must be informed. As regards data privacy, there seems to be once again a disproportionate hysteria about warning them of the potential for data leaks. As explained in my previous article, this is based on not understanding information technology, and was a genuine concern specifically with free models from which one did or could not opt out of using prompt uploads for model training. Once you are working on an enterprise model — one contracted not to train on your inputs, not to retain them, and to hold them to the same encryption standard as every other online software system — there is no principled reason to single out AI for privacy warnings you never give about any of the other software you use. Treating AI privacy as a distinct category of exposure merely because it is the newest arrival, is not caution but unfamiliarity dressed as caution. Does one need to go into retail detail every time a client presents with general anxiety — walking them through cyberthreats and encryption in all its gory detail? I suggest not. It should suffice to state that only platforms conforming to the PHI-level standards set out by leading world regulators are used. More fundamental, to my mind, is explaining how you will use AI in the assessment or therapy process. How carefully will you double-check its outputs? At what points will you consult human supervision? Where exactly does the human sit in the loop, and what decisions never leave your hands? 8.2 שימוש הולם בכלי אבחון והערכה פסיכולוגים יקפידו להשתמש בכלים אשר ידוע שמהימנותם ותקפותם מקובלים במדעי ההתנהגות ביחס למטרות האבחון. הם יפעילו שיקול דעת מקצועי בבחירת כלי האבחון וינמקו את בחירתם בהסתמך על אמות המידה והגישות התאורטיות המקובלות. על פסיכולוגים לבחור כלים המתאימים לנבדק בהתאם לגורמים אישיים כמו שפה, גיל ומין, ובהתאם לגורמים תרבותיים־חברתיים. פסיכולוגים ישתמשו בכלי אבחון ובטפסים תקניים לציינון, זאת לאחר שקיבלו הרשאה לכך מבעלי זכויות היוצרים או מנציגיהם החוקיים. As we enter a new era in which AI-based assessment tools are slowly rolling out and digital platforms become more widely available for administration, these questions are likely to move centre stage. Are small normed samples gathered by human researchers one to three decades ago superior to machine-collected norms drawn from far larger and more up-to-date samples, albeit without human oversight during administration? Where is the cutoff between an impression-based tool and a diagnostic tool? We would also be wise not to adopt double standards and hold new tools — by virtue of their being new and digital — to higher standards than their paper counterparts. For example, is it acceptable to diagnose SLDs using instruments for reading comprehension and mathematics that have no researched norms at all? Or via reading measures whose norms are decades old? Or processing speed, executive functioning (e.g., NC and TMT) and learning-curve measures (e.g., REY) that are likewise decades old? In other words, it is only fair to apply a common standard to the new and the old. If we are going to hold digital norms, AI-derived or otherwise, to a strict evidentiary bar, we should be holding the legacy instruments in our current testing cupboards to the same one. 8.4 פירוש של תוצאות אבחון פסיכולוגים אחראים להשתמש בכלי אבחון ולפרש את תוצאותיהם, וזאת גם אם השתמשו בשירותים ממוחשבים או אחרים לצורך הפירוש. בפירוש תוצאות אבחון, כולל פירוש ממוחשב, פסיכולוגים יתחשבו במגוון גורמים הקשורים בכלי האבחון ובאפיוני האדם המאובחן. עליהם להיות ערים לאפיונים שבכוחם להשפיע על שיפוטם או לפגוע בדיוק פירושיהם. בעת מתן פירוש לתוצאות המבחנים, על פסיכולוגים לציין את ההסתייגויות המרכזיות שיש להם לגבי דיוק פירושיהם או מגבלותיהם. This clause already recognizes the possibility of using software to interpret test findings. In 2017, this was likely available mainly for questionnaire-based measures and for computerized tests such as the MOXO screening test for ADHD. However, there is no fundamental distinction between the acceptability of those programs and that of AI-based ones, besides the fact that AI models reason over the data whereas the 2017 generation ran on binary logic — if the score is "x", print paragraph "y". Ultimately, I think this clause makes clear that the responsibility for delivering and explaining the findings, and for flagging the reservations that attach to them, lies with the psychologist regardless of who generated the draft. 8.5 רשומת האבחון וחוות הדעת המבוססת עליה בהכנת ההערכות, ההמלצות והדוחות הפסיכולוגיים, יתבססו הפסיכולוגים על איסוף מדעי שיטתי ועל כלי אבחון מקובלים המספקים בסיס הולם לממצאיהם. פסיכולוגים יציינו בפירוט בכל דוח פסיכולוגי באילו כלים השתמשו לביצוע האבחון. פסיכולוגים יבטיחו שחוות דעת הנכתבות על ידם יתבססו על חומר האבחון וההערכה, ועליהן להיות מנומקות לפי חומר זה. It is arguable whether this clause has any unique applicability to the use of AI in interpreting, conceptualizing and reporting on psychoassessment findings. Suffice it to say that, in my opinion, if the AI is used as a tool to inform the psychologist, who then uses their own discretion to accept what seems to them correct and reject what seems to them false, this is fair practice. Arguably, for psychologists today to ground their conclusions optimally in the nuanced totality of test data across its thousands of data points, AI assistance is the ideal fulfilment of the value underlying this clause rather than a threat to it. Note, though, the requirement to specify in detail which tools were used — which may require explicitly stating all the AI tools as well. 8.8 שמירה על ביטחון כלי האבחון פסיכולוגים לא ישתמשו במבחנים באופן שעלול לפגום בתקפותם ובמהימנותם. כלל זה מורה לפסיכולוגים לא להכין נבדקים לקראת אבחון פסיכולוגי ולא למסור חומרי גלם של אבחון לאלו שלא מוסמכים לכך. אם עולה דרישה לקבלת חומרי הגלם של כלי האבחון, הם יימסרו רק לפסיכולוג בעל בקיאות באותו כלי אבחוני. פסיכולוגים יכשירו בכלי אבחון פסיכולוגיים רק את אלה שהם פסיכולוגים, מתמחים או סטודנטים לפסיכולוגיה. See what I wrote above regarding clause 3.13; the same reasoning applies here. 10.1 התערבות מקצועית באמצעות מדיה, שאינה פנים אל פנים כל כללי האתיקה והחוק החלים על התערבות פסיכולוגית פנים אל פנים חלים גם על התערבות פסיכולוגית מרחוק. גם בהתערבות זו על פסיכולוגים להקפיד לקיים רמה מקצועית גבוהה, לשמור על כבוד הלקוחות ולשמור על כבוד המקצוע. התערבות מקצועית פסיכולוגית באמצעים אלקטרוניים מחייבת ראשית לכול מיומנות בהתערבות מקצועית פנים אל פנים. על פסיכולוגים להיות בקיאים בידע המקצועי והמחקרי העוסק בטיפול באמצעים אלקטרוניים, ולהתעדכן בו. עליהם להתחשב בו בקבלת החלטות לגבי השיטות והתנאים שבהם תיערך ההתערבות. על ההתערבות הפסיכולוגית מרחוק להיות מותאמת ומתוכננת על פי הצרכים של הלקוח ובהתחשב במגבלות הטכנולוגיה האלקטרונית. This is especially pertinent when using AI chatbots to administer assessment modules, and even more so when they are tasked with assisting in or delivering psychotherapeutic ones. While it seems clear that this clause was written with platforms such as Zoom in mind, it seems reasonably coherent to hold that the same standards apply to AI-delivered modules — where the human stands behind them from a more distant position of vantage and influence, but stands behind them nonetheless. Note also the requirement to be conversant with the professional and research literature on delivery by electronic means, and to keep up with it: applied to AI, that is a live and fast-moving obligation. And for that, reading this blog is a step in the right direction! 10.3 אמצעים לאבטחת פרטיות של התערבות מרחוק על פסיכולוגים העובדים באמצעים טכנולוגיים המאפשרים קיומה של התערבות מרחוק מוטלת האחריות להבטיח שתישמר הפרטיות של לקוחותיהם. על הפסיכולוגים ללמוד טכנולוגיות לשמירה על פרטיות באמצעים אלקטרוניים, ולהשתמש בהן כדי להבטיח שמירה על פרטיות הלקוחות. עליהם לדווח ללקוחותיהם באילו אמצעי זהירות נקטו לשמירת הפרטיות, ומה על הלקוחות לעשות כדי לשמור במקביל על פרטיותם במקום שבו הם נמצאים. Here is the earliest extant reference to cybersecurity in the pre-AI era — and interestingly, here too it appears in the context of novel communication technologies, as though these posed a greater risk than the standard word processing, database and messaging software that had sat on everyone's computers for decades. Perhaps the novel simply creates anxiety; or perhaps it strikes us specifically in the areas to which we have not yet become accustomed and desensitized. Regardless, these requirements are vague: learn what is available out there to keep your client safe, implement it, and inform them what standards you are applying. To what extremes of data protection must one go? How granular must one's report to the client be? Is it sufficient to tell them that you use only software matching HIPAA-level or other internationally recognized standards? The clause doesn't say. What it does do is lay down the values that should govern the kinds of learning and software choices psychologists make today in the field of AI-assisted tools. 10.7 אבחון פסיכולוגי והערכה מרחוק בהתערבות מרחוק על הפסיכולוג לשקול ביתר שאת שאלות של שמירה על תקפות ומהימנות, חשיפה של כלי אבחון ופגיעה בזכויות יוצרים של מחברי כלי אבחון. The questions of copyright are legal as well as ethical, and extremely complex. Yes, great care is needed in this era. As regards norming: is it acceptable to use MOXO scores obtained from a computer-based administration in the client's home rather than the clinic? Currently, tools continue to be normed almost exclusively on clinic- and classroom-based research. There are real issues of generalizability here, but these will likely fade — my prediction — as norms developed specifically for digitally delivered assessments are accumulated. The Israeli Psychological Association's guidelines And finally, let us look at the May 2024 document released by the Israeli Psychological Association (הסתדרות הפסיכולוגים בישראל), with overarching guidelines for AI usage. They highlight several ethical concerns in introducing AI into psychology, once again flagging as "high severity" the use of AI for processing and reporting on client data. My critique is that this once again attributes to AI a unique technological status, as though it risks the privacy of client data more than other software does. Yes, this was true of specific free platforms where opt-out of prompt logging was non-enacted, but I fear it conditioned a fear response to AI as a whole. To summarize their key points: Responsibility. Remember that as regards responsibility for decisions and formal outputs, it is you and not the AI who bears ultimate responsibility. Due diligence. Learn the tools that are out there, and understand the basics of how AI software operates. Don't automatically assume that outputs provided without reasoning are valid; and if diagnostic data are provided, these must be justified theoretically or statistically. Instruments claiming research-level accuracy ought to share that data openly. Software claiming high security ought to provide a detailed breakdown of how it achieves it. Stay away from consumer-grade AI platforms when uploading client files. These files are PHI, and such platforms explicitly state that their privacy controls are insufficient for handling data this sensitive. Do your due diligence to ensure that dedicated platforms are up to standard. They point specifically to the new Israeli requirements under הגנת הפרטיות. I will discuss this at length in the next post, but suffice to say for now that a platform which keeps no database of its own, and instead expects you to store all outputs client-side, clears the benchmarks set by this law far more easily than you do on your own computer! In other words, for several of the AI report-writing tools available today, the weakest link in the chain is not the AI platform at all: it is your insecure Google account, your shared family laptop. To an extent, our profession has quietly tolerated this for thirty years while now casting enormous doubt on servers whose actual PHI retention is zero. Inform your clients that you intend to use AI, and how and why. I have had one client think twice about it, but ultimately even they agreed. Once more: overblowing the ostensibly novel data-breach threat of AI makes clients unnecessarily anxious. AI is a form of software, and the same data risks that apply elsewhere apply here. Explain that if they are comfortable with you emailing or WhatsApping the report to them, at least the same level of security — in fact a higher one — applies when using dedicated PHI-grade software with AI components. TIP: I recommend having clients sign an explicit clause regarding the type of AI software I will be using. Should there, God forbid, be an unexpected data leak, this could go a long way toward protecting you from litigation. Parallel use. If you have reason to think your client is using AI alongside the intervention you are providing, attempt to discuss this with them and evaluate its pros and cons together. Documentation. If you use AI in an intervention, note it in the client's file. In practice, if you use dedicated session-transcription tools, this takes care of itself: the session is recorded, summarized and unpacked by the AI, providing the user with an output that can be pasted into the client file as is. Research. If you use AI in research, be open about it — whether in generating data sets or in analysing them. Legal contexts. Be extra careful to state the use of AI when your work is being used in legal contexts. For developers: ensure that your tools are up to standard and that your objectives are not fundamentally self-serving, whether financially or as an ego-pump. This is ultimately the new face of the profession, so build in accordance with the highest reasonable standards of data safety, and strive to build the most accurate and the most professionally and psychologically beneficial tools you can. If they have imperfections, be upfront about them. The official ethics guidelines for AI use are available on the Israeli Psychological Association's site. I pasted the link below. So yes, it is a long discussion — and kudos to you if you got this far — but I think this is a comprehensive and worthwhile overview. The bottom line: Use AI responsibly, and ensure you use AI software built according to the relevant standards of data protection — look for a "kashrut" certificate, or for a transparent policy and rationale for the software's security profile, or get in touch with the developers and ask for more information. And of course, let your clients know when and why you are using AI. But once more: please remember that this is the same as with every other piece of software you already rely on. Remarkably, there is a missing link skipped over at present by the ethical recommendations of the Israeli team, and that is the mandatory use of signed agreements between software providers and practitioners, ensuring that the entire software chain is protected by clearly articulated and binding commitments to the highest standards. In the USA this is a must — the BAA under HIPAA does exactly this work — and I imagine (and hope) it will enter the Israeli space soon too. So that's it for this post. Next time, a look at the law: חוק הגנת הפרטיות, and how it shapes your responsibility and liability when processing your clients' data on ANY computer using ANY software, AI included. Sources: Code of Professional Ethics for Psychologists in Israel https://www.psychology.org.il/sites/psycho/UserContent/files/%D7%A2%D7%A7%D7%A8%D7%95%D7%A0%D7%95%D7%AA%20%D7%95%D7%9B%D7%9C%D7%9C%D7%99%20%D7%90%D7%AA%D7%99%D7%A7%D7%94%20%D7%9C%D7%A9%D7%99%D7%9E%D7%95%D7%A9%20%D7%91%D7%9B%D7%9C%D7%99%20%D7%91%D7%99%D7%A0%D7%94%20%D7%9E%D7%9C%D7%90%D7%9B%D7%95%D7%AA%D7%99%D7%AA(1).pdf Disclaimer: This is not professional legal advice. It was assembled via human research and written by human hand, then fact-checked, lightly edited and translated to Hebrew using AI. If you identify an error, please reach out so it can be corrected for the benefit of others.