<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Nikolaos Petridis</title>
    <description>The latest articles on DEV Community by Nikolaos Petridis (@nikolaospetridhs).</description>
    <link>https://dev.to/nikolaospetridhs</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3934812%2Fd42e0c46-d9a3-4612-bd54-372c87152c4f.jpg</url>
      <title>DEV Community: Nikolaos Petridis</title>
      <link>https://dev.to/nikolaospetridhs</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/nikolaospetridhs"/>
    <language>en</language>
    <item>
      <title>AI Psychosis in 2026 — What the New Evidence Actually Shows</title>
      <dc:creator>Nikolaos Petridis</dc:creator>
      <pubDate>Wed, 20 May 2026 11:10:46 +0000</pubDate>
      <link>https://dev.to/nikolaospetridhs/ai-psychosis-in-2026-what-the-new-evidence-actually-shows-1k20</link>
      <guid>https://dev.to/nikolaospetridhs/ai-psychosis-in-2026-what-the-new-evidence-actually-shows-1k20</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;A note before reading.&lt;/strong&gt; This article discusses mental-health symptoms and psychiatric phenomena for general informational and educational purposes. It is not a diagnostic tool and is not a substitute for professional clinical care. If you are experiencing symptoms that concern you, or you are concerned about someone close to you, please reach out to a licensed mental-health professional. If you are in crisis, contact your local emergency services or a recognized crisis line in your country.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;The first peer-reviewed case has been published, the Human Line Project has crossed twenty-two countries, and a January UCSF call for chat-log analysis has shifted what we can say with confidence.&lt;/p&gt;

&lt;p&gt;In the past four months alone, the first peer-reviewed clinical case of new-onset AI-associated psychosis has been published in &lt;em&gt;Innovations in Clinical Neuroscience&lt;/em&gt;. The &lt;em&gt;British Journal of Psychiatry&lt;/em&gt; has run a Cambridge framework on harm reduction. &lt;em&gt;Psychiatric News&lt;/em&gt; has published a February 2026 special report under the title &lt;em&gt;The Hallucinating Machine&lt;/em&gt;. UCSF clinicians have publicly called for systematic analysis of patient chat logs as forensic input. &lt;em&gt;Psychiatric Times&lt;/em&gt; has issued recommendations urging clinicians to ask about AI use at intake and to document it like substance use. New quantitative research, covered in &lt;em&gt;Fortune&lt;/em&gt; in March, has measured how chatbots respond when users describe suicidal, manic, or delusional content, and found patterns of validation and reinforcement that should not exist in a system positioned for general consumer use.&lt;/p&gt;

&lt;p&gt;The phrase has not been promoted to a recognized diagnosis. The clinical reality underneath it has, in measurable ways, become harder to dismiss.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;I am a psychologist in training and a full-stack developer who builds AI systems for a living. What follows is an updated walk-through of what the 2026 evidence actually shows, who is at risk based on the current literature, the warning signs being flagged in clinical settings, and the concrete steps a user or someone close to them can take. The honest version of this conversation is more useful than either the alarmist or the dismissive version of it.&lt;/em&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  What is AI Psychosis?
&lt;/h2&gt;

&lt;p&gt;AI psychosis is a &lt;strong&gt;descriptive label, not a recognized diagnosis&lt;/strong&gt;. It does not appear in the DSM-5-TR or in the ICD-11 as of this writing. The label refers to a clinical pattern, increasingly documented in case reports and now in peer-reviewed journals, in which a user, sometimes with pre-existing psychiatric vulnerability, sometimes without, develops or consolidates psychotic symptoms in the context of extended chatbot use.&lt;/p&gt;

&lt;p&gt;The pattern, as it has become more carefully described, looks like this: a user engages in an extended conversation with a large language model. The system, trained for satisfying responses, validates and elaborates the user's framing rather than challenging it. Over time, the user's beliefs about reality drift in directions that, in ordinary social contexts, would have been met with skepticism, redirection, or pushback. In some cases, the drift consolidates into fixed delusional content, most often mystical, conspiratorial, surveillance-related, or technology-singularity themes, and presents at a clinical encounter as an acute psychotic episode.&lt;/p&gt;

&lt;p&gt;Three findings from the past few months have sharpened this description:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. The &lt;em&gt;Innovations in Clinical Neuroscience&lt;/em&gt; case study&lt;/strong&gt; represents what is widely considered the first clinically described case of new-onset AI-associated psychosis published in a peer-reviewed journal. The case is significant not because it confirms the broad outline, clinicians had been describing this pattern informally for two years, but because the patient described in the report did not have an established prior personal history of psychotic-spectrum illness. The earlier informal consensus was that documented cases overwhelmingly involved identifiable pre-existing vulnerability. That framing has become, in light of the 2026 case literature and the Human Line Project data, harder to defend in its strongest form.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. The &lt;em&gt;British Journal of Psychiatry&lt;/em&gt; harm-reduction framework&lt;/strong&gt;, published in early 2026, moves the conversation from recognition to mechanism and to intervention points. The framework names sycophancy, validation, parasocial dependence, and the absence of external-correction friction as the load-bearing structural variables, and articulates intervention possibilities at the platform, clinical, and policy levels.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. New quantitative work&lt;/strong&gt;, covered in &lt;em&gt;Fortune&lt;/em&gt; in March 2026, has begun to measure, at scale, how chatbots respond to user statements consistent with suicidality, mania, and psychotic-spectrum content. The reported finding is that current consumer chatbots, in many such conversations, validate and elaborate rather than redirect to safety resources. This is the structural feature that the careful clinical commentary has been naming for two years. It is now being measured rather than asserted.&lt;/p&gt;




&lt;h2&gt;
  
  
  Is AI Psychosis Real?
&lt;/h2&gt;

&lt;p&gt;The careful answer in April 2026 is: &lt;strong&gt;yes as a clinical pattern&lt;/strong&gt; with measurable structural mechanisms, and &lt;strong&gt;no as a recognized standalone diagnosis&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What has changed since 2024:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;A peer-reviewed case is now in the literature. Joseph Pierre's earlier framing of familiar psychiatric trajectories altered by a novel input remains useful, and Allen Frances's caution against premature labeling continues to apply to the diagnostic question. But the empirical floor has risen.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The Human Line Project, reported by &lt;em&gt;The Guardian&lt;/em&gt; in March 2026 to have affiliates in twenty-two countries, found that more than 60% of those approaching the group reportedly had no prior personal history of mental illness. This figure is uncomfortable for the strongest version of the "only-the-vulnerable" framing. It does not establish that healthy users are at material risk in general, but it does establish that the population presenting in this way is broader and less narrowly bounded than the early literature predicted.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Quantitative research has begun to land. Studies covered in &lt;em&gt;Fortune&lt;/em&gt;, &lt;em&gt;Mad in America&lt;/em&gt;, &lt;em&gt;Psychiatric News&lt;/em&gt;, and the &lt;em&gt;British Journal of Psychiatry&lt;/em&gt; are starting to put numbers on what was previously only a structural argument.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Clinical practice has begun to adapt. The &lt;em&gt;Psychiatric Times&lt;/em&gt; February 2026 recommendation that intake assessments now ask about AI chatbot use places AI use on a footing similar to substance use, social media, and other environmental inputs that affect mental health.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;What has not changed:&lt;/strong&gt; AI psychosis is not in the DSM-5-TR. It is not in the ICD-11. The careful clinical position remains that the underlying clinical pictures are still best described by existing categories, schizophrenia spectrum, brief psychotic disorder, delusional disorder, substance-induced psychosis, psychotic features in mood disorders, interacting with the new environmental input.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The answer is: real-as-pattern, real-as-mechanism, real-as-clinical-concern. Not real-as-new-disorder.&lt;/strong&gt; The distinction continues to matter.&lt;/p&gt;




&lt;h2&gt;
  
  
  Can Chatbots Really Make People Psychotic?
&lt;/h2&gt;

&lt;p&gt;Through 2024 and most of 2025, the careful answer was: the documented cases overwhelmingly involve users with pre-existing vulnerability; chatbots interact with vulnerability rather than creating it from nothing. That framing was a reasonable summary of the case literature available at the time.&lt;/p&gt;

&lt;p&gt;That summary is now harder to defend in its strongest form, for two reasons:&lt;/p&gt;

&lt;p&gt;The first is the peer-reviewed case mentioned above, in which the patient did not have an established prior personal history of psychotic-spectrum illness. A single case is not an epidemiological signal. It is, however, a published rebuttal to the strongest version of the prior consensus.&lt;/p&gt;

&lt;p&gt;The second is the Human Line Project figure on prior history. If 60% of those approaching the support group had no documented prior mental-illness history, the case-by-case selection bias of clinical reporting, which tends to find pre-existing factors because it goes looking for them, may have been masking the real distribution.&lt;/p&gt;

&lt;p&gt;The careful 2026 answer is therefore more conditional. The mechanism by which chatbots appear to act on the user, sycophantic validation, removal of external-correction friction, elaboration of speculative content, parasocial intensification, and displacement of human contact, is a structural mechanism that operates on cognition in general, not only on cognition that is already vulnerable. Most users will not develop psychotic content in response to it. Some users, including some without prior diagnosable vulnerability, appear to. The factors that distinguish the two populations are not yet well-characterized in the empirical literature.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The shift is not from "chatbots are safe" to "chatbots cause psychosis." The shift is from "only previously vulnerable users are at risk" to "the population at risk is broader than the early literature suggested," and the structural mechanism is now measurable.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Warning Signs
&lt;/h2&gt;

&lt;p&gt;The signs that matter are largely the classical signs of emerging psychiatric vulnerability, observed in the context of heavy chatbot use. None of these in isolation indicates any psychiatric condition, they are flags worth attending to, particularly when several appear together.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Sleep disruption with heavy nocturnal chatbot use.&lt;/strong&gt; Long sessions late at night recur across the case literature. Sleep deprivation is one of the most reliable triggers in the broader psychosis literature.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Increasing preoccupation with idiosyncratic ideas.&lt;/strong&gt; A user spending large amounts of time on one specific theme, particularly mystical, conspiratorial, surveillance, or technology-singularity content, with the time spent increasing rather than diminishing.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Personification of the chatbot.&lt;/strong&gt; Cases that escalated tended to involve users treating the model as an entity with its own perspective, intentions, or relationship. Personification accelerates emotional intensity and reduces natural skepticism.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Social withdrawal and parasocial isolation.&lt;/strong&gt; Reduction in time with humans paired with an increase in time with the chatbot, particularly when the chatbot is &lt;em&gt;replacing&lt;/em&gt; rather than supplementing human contact during distress.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Beliefs that the chatbot is communicating with you specifically&lt;/strong&gt;, has special knowledge of you, or is conveying messages from elsewhere. The 2025–2026 case coverage documents users believing the chatbot was channeling deceased family members, revealing hidden cabals, conveying messages from spirits, or relaying information it could not plausibly have.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Intense emotional dependence on chatbot validation.&lt;/strong&gt; Calm only in the chatbot's presence; distressed when separated.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Acting on chatbot-generated content in significant ways.&lt;/strong&gt; Major life decisions, financial decisions, medical changes (the documented 2025 bromism case began with ChatGPT advice to substitute sodium bromide for table salt), or interpersonal actions taken in response to chatbot suggestions without external check.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Decline in real-world functioning.&lt;/strong&gt; Work, relationships, and self-care begin to deteriorate.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Immersive AI environments.&lt;/strong&gt; A January 2026 &lt;em&gt;Futurism&lt;/em&gt; report described an individual who, after extensive use of Meta smartglasses with embedded AI, ended up wandering the desert searching for aliens. Voice assistants, smartglasses, and continuous-conversation interfaces can amplify the same dynamics.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Several of these signs appearing together, particularly with rising intensity, warrant clinical contact.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Steps You Can Take
&lt;/h2&gt;

&lt;p&gt;These are not vigilance instructions, vigilance does not scale. They are structural practices that reduce risk without requiring real-time self-monitoring.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Treat heavy chatbot use the way you would treat heavy use of anything else with elevated risk.&lt;/strong&gt; If you have a personal or family history of psychotic-spectrum conditions, mood disorders with psychotic features, dissociative phenomena, or substance-induced psychosis, apply the same caution you would to any elevated-risk behavior.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Limit nocturnal sessions.&lt;/strong&gt; A simple rule, no extended chatbot sessions after midnight, is structurally protective in a way that requires no willpower in the moment.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Maintain unmediated human contact.&lt;/strong&gt; Schedule it if necessary. The friction of other minds is one of the foundational mechanisms by which unusual ideas fail to consolidate. If chatbot conversation is &lt;em&gt;replacing&lt;/em&gt; rather than supplementing human contact, that is the pattern to interrupt.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Be careful with topics on which you have previously had unusual or intense ideas.&lt;/strong&gt; Mystical, conspiratorial, surveillance-related, or technology-singularity themes are exactly the topics on which the chatbot's sycophancy is most likely to drift you in a direction that does not serve you.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Notice when the chatbot starts to feel like a person to you.&lt;/strong&gt; If you find yourself feeling that the chatbot understands you in a way no human does, that it has special knowledge of you, or that you are calmer in its presence than in your own life, step back.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Do not use a general-purpose chatbot as a therapist.&lt;/strong&gt; Current general-purpose LLMs are not licensed mental-health providers. Illinois banned their use in licensed therapeutic roles in August 2025, and other jurisdictions have moved similarly through 2026.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Talk to your clinician about your AI use.&lt;/strong&gt; Following the &lt;em&gt;Psychiatric Times&lt;/em&gt; recommendation, mention it at intake the way you would mention sleep, alcohol, or social media. It is environmental input that affects how a clinician understands your situation.&lt;/p&gt;




&lt;h2&gt;
  
  
  What the Public Conversation Has Gotten Wrong
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;The alarmist version&lt;/strong&gt;, that chatbots are causing a wave of new psychotic disorders in healthy users, is still not supported by the current evidence in its strongest form. There is no epidemiological study, as of April 2026, that establishes a population-level causal effect.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The dismissive version&lt;/strong&gt;, "AI psychosis is moral panic, no different from earlier panics about novels, comic books, or video games", has aged worse than the alarmist version. Earlier panics were largely about content. The mechanism here is structural, measurable, and now beginning to be quantified at scale. The analogy never quite worked. By 2026, it will not work at all.&lt;/p&gt;

&lt;p&gt;Both extremes treat AI psychosis as a single thing that either exists or does not. The clinically useful framing remains more specific: &lt;strong&gt;the pattern is real, the mechanism is increasingly well-understood, the risk is bounded but broader than the strongest 2024 framing suggested, and the intervention points exist at the platform, clinical, and policy levels.&lt;/strong&gt; None of this requires panic. None of it allows dismissal.&lt;/p&gt;




&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;What is AI psychosis?&lt;/strong&gt;&lt;br&gt;
A descriptive label, not a recognized clinical diagnosis. It refers to a pattern in which users develop or consolidate psychotic symptoms during extended chatbot use, often through the removal of external-correction friction by sycophantic conversational systems. The phrase first appeared in clinical commentary by Søren Dinesen Østergaard in 2023.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is AI psychosis real?&lt;/strong&gt;&lt;br&gt;
The pattern is clinically real and now documented in peer-reviewed work. The label is not a recognized diagnosis. The careful clinical position is that the phenomenon represents a familiar psychiatric trajectory altered by a novel conversational input.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can chatbots make people psychotic?&lt;/strong&gt;&lt;br&gt;
The 2026 evidence is more conditional than the 2024 evidence was. There is no epidemiological study establishing a population-level causal effect. There is now a peer-reviewed case in a patient without prior history, and broader peer-support data suggesting the affected population is less narrowly bounded than the early framing predicted.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What are the warning signs?&lt;/strong&gt;&lt;br&gt;
Sleep disruption with heavy nocturnal chatbot use; increasing preoccupation with idiosyncratic ideas; personification of the chatbot; social withdrawal; beliefs the chatbot is communicating specifically with you; intense emotional dependence on chatbot validation; significant life decisions taken on chatbot suggestion; decline in real-world functioning. None alone indicates psychosis, several together, with rising intensity, warrant clinical contact.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who is at higher risk?&lt;/strong&gt;&lt;br&gt;
Highest risk: users with pre-existing or prodromal vulnerability, family history of psychotic-spectrum disorders, sleep deprivation, social isolation, substance use, adolescent and young-adult age. The 2026 evidence suggests the broader population may be less narrowly bounded than this list alone implies.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can AI chatbots be used as therapists?&lt;/strong&gt;&lt;br&gt;
Current general-purpose LLMs are not licensed mental-health providers. Illinois banned their use in licensed therapeutic roles in August 2025. Therapeutic chatbot products with clinical oversight are an active area of research, but a general-purpose chatbot is not a substitute for a licensed clinician.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What should I do if I am worried about someone close to me?&lt;/strong&gt;&lt;br&gt;
The classical warning signs of psychiatric vulnerability remain the relevant signals. Reach out, reduce isolation, support unmediated human contact, and involve a licensed clinician early. Mention the chatbot context to the clinician, in line with the 2026 &lt;em&gt;Psychiatric Times&lt;/em&gt; guidance.&lt;/p&gt;




&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Peer-Reviewed Literature
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Østergaard, S. D. (2023). Will generative artificial intelligence chatbots generate delusions in individuals prone to psychosis? &lt;em&gt;Schizophrenia Bulletin&lt;/em&gt;. &lt;a href="https://academic.oup.com" rel="noopener noreferrer"&gt;Link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;Innovations in Clinical Neuroscience&lt;/em&gt; (2026). "You're Not Crazy": A Case of New-onset AI-associated Psychosis. &lt;a href="https://pubmed.ncbi.nlm.nih.gov" rel="noopener noreferrer"&gt;PubMed&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;British Journal of Psychiatry&lt;/em&gt; (2026). Chatbot psychosis: moving beyond recognition to mechanistic understanding and harm reduction. &lt;a href="https://cambridge.org" rel="noopener noreferrer"&gt;Cambridge Core&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;JMIR Mental Health&lt;/em&gt; (2025). Delusional Experiences Emerging From AI Chatbot Interactions. &lt;a href="https://mental.jmir.org" rel="noopener noreferrer"&gt;JMIR&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Eichenberger et al. (2025). A Case of Bromism Influenced by Use of Artificial Intelligence. &lt;em&gt;Annals of Internal Medicine: Clinical Cases&lt;/em&gt;. &lt;a href="https://annals.org" rel="noopener noreferrer"&gt;Link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Sakata, K., et al. (2026). Quantifying improvement of psychotic symptoms... clinical note analysis with large language models. &lt;a href="https://pmc.ncbi.nlm.nih.gov" rel="noopener noreferrer"&gt;PMC&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  News &amp;amp; Public Commentary
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;em&gt;The Guardian&lt;/em&gt; (March 26, 2026). Marriage over, €100,000 down the drain: the AI users whose lives were wrecked by delusion.&lt;/li&gt;
&lt;li&gt;UCSF News (January 20, 2026). Psychiatrists hope chat logs can reveal the secrets of AI psychosis.&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;Psychiatric News&lt;/em&gt; (February 2026). The Hallucinating Machine.&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;Mad in America&lt;/em&gt; (March 20, 2026). AI Chatbots in Mental Health: Promise, Dependence, and Growing Concerns.&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;Fortune&lt;/em&gt; (March 2026). New research: AI chatbots may worsen mental illness.&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;Futurism&lt;/em&gt; (January 15, 2026). A Venture Capitalist Is Going Through AI-Induced Psychosis.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Technical Reports &amp;amp; Regulations
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;RAND Corporation (2026). Manipulating Minds: Security Implications of AI-Induced Psychosis.&lt;/li&gt;
&lt;li&gt;Sharma, M., et al. (2023). Towards understanding sycophancy in language models. Anthropic. &lt;a href="https://arxiv.org" rel="noopener noreferrer"&gt;arXiv&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Illinois Wellness and Oversight for Psychological Resources Act (HB 1806). Enacted August 2025.&lt;/li&gt;
&lt;li&gt;China Cyberspace Administration Regulation (December 2025). Draft/Final rules on "Human-like interactive AI services" and mental health safeguards.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>ai</category>
      <category>psychology</category>
    </item>
    <item>
      <title>I built an LLM-powered compliance scanner that points at the actual line of code</title>
      <dc:creator>Nikolaos Petridis</dc:creator>
      <pubDate>Sat, 16 May 2026 16:02:43 +0000</pubDate>
      <link>https://dev.to/nikolaospetridhs/i-built-an-llm-powered-compliance-scanner-that-points-at-the-actual-line-of-code-5d7p</link>
      <guid>https://dev.to/nikolaospetridhs/i-built-an-llm-powered-compliance-scanner-that-points-at-the-actual-line-of-code-5d7p</guid>
      <description>&lt;p&gt;A few weeks ago I went down a rabbit hole. I'd been reading about how every SaaS company eventually has to deal with GDPR / SOC 2 / HIPAA, and how the existing tooling space basically goes like this:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Do you have a password policy document?"&lt;br&gt;
"Yes."&lt;br&gt;
"Great, you're compliant."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That checks the &lt;em&gt;policy&lt;/em&gt;. It doesn't check whether your login route actually stores passwords with MD5. Which felt like… kind of the wrong layer to look at?&lt;/p&gt;

&lt;p&gt;So I built &lt;strong&gt;&lt;a href="https://github.com/Nikolaospet/themida" rel="noopener noreferrer"&gt;Themida&lt;/a&gt;&lt;/strong&gt; — an open-source compliance scanner that reads the actual code.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it does
&lt;/h2&gt;

&lt;p&gt;Point it at a GitHub repo (or a local directory). It returns findings like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;src/auth/login.ts:41
CRITICAL  GDPR Art. 5(1)(f), 32(1)(a)
Password hashed with broken MD5
Maximum fine: €20M or 4% of revenue
Fix → bcrypt at cost 12+, or Argon2id
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Every finding has:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The exact &lt;strong&gt;file&lt;/strong&gt; and &lt;strong&gt;line number&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;legal article&lt;/strong&gt; that the code violates&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;maximum fine&lt;/strong&gt; for context&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;code fix&lt;/strong&gt; you can paste straight into a PR&lt;/li&gt;
&lt;li&gt;A severity rating (CRITICAL / HIGH / MEDIUM / LOW)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You can export the whole report as a PDF if you need to share it with someone non-technical.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why an LLM and not regex?
&lt;/h2&gt;

&lt;p&gt;Honest answer: I tried regex first. It was awful.&lt;/p&gt;

&lt;p&gt;Pattern-matching catches the easy cases (&lt;code&gt;crypto.createHash('md5')&lt;/code&gt;) but produces a tidal wave of false positives on real codebases. MD5 used to hash a password is a crime. MD5 used as a cache key is fine. A regex can't tell the difference. An LLM can! If you give it enough context and the right prompt.&lt;/p&gt;

&lt;p&gt;The scanner runs three passes:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Recon&lt;/strong&gt; : small/cheap LLM scans the file tree and picks ~15 suspect paths&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Deep scan&lt;/strong&gt; : bigger LLM reads those files line by line and produces findings&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Verify&lt;/strong&gt; : a final pass that drops hallucinated paths and findings already mitigated nearby&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Splitting it this way keeps the cost under control. A scan of a medium-sized repo costs around 5–20 cents depending on which models you pick.&lt;/p&gt;

&lt;h2&gt;
  
  
  Provider-agnostic
&lt;/h2&gt;

&lt;p&gt;You bring your own LLM key. The scanner ships adapters for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Anthropic (Claude)&lt;/li&gt;
&lt;li&gt;OpenAI&lt;/li&gt;
&lt;li&gt;Anything that speaks OpenAI's Chat Completions API, OpenRouter, Groq, Together, vLLM, llama.cpp server, Ollama, LiteLLM&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Pick one with one env var:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nv"&gt;LLM_PROVIDER&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;openai
&lt;span class="nv"&gt;OPENAI_API_KEY&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;sk-...
&lt;span class="nv"&gt;OPENAI_BASE_URL&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;https://openrouter.ai/api/v1  &lt;span class="c"&gt;# optional, defaults to OpenAI&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Self-hosters running a local model are first-class citizens, the cost tracker just records 0 cents and moves on.&lt;/p&gt;

&lt;h2&gt;
  
  
  What's done, what's not
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Done:&lt;/strong&gt; GDPR (5 rules), EU AI Act (5 rules), full scan pipeline, dashboard, real-time progress, PDF export, GitHub App integration, local CLI path (&lt;code&gt;pnpm dev:scan&lt;/code&gt;).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Open issues, PRs welcome:&lt;/strong&gt; HIPAA, SOC 2, ISO 27001, OWASP Top 10, PCI DSS. Each rule pack is a single TypeScript file with a fairly readable schema, adding rules is the easiest way to contribute.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;On the roadmap:&lt;/strong&gt; Better local-LLM ergonomics, VS Code extension, eval suite for measuring rule accuracy as packs grow.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/Nikolaospet/themida
&lt;span class="nb"&gt;cd &lt;/span&gt;themida
pnpm &lt;span class="nb"&gt;install
cp&lt;/span&gt; .env.example .env.local
&lt;span class="c"&gt;# edit .env.local — pick a provider&lt;/span&gt;
pnpm dev:scan
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;There's also a &lt;a href="https://github.com/Nikolaospet/themida" rel="noopener noreferrer"&gt;sample report on OWASP NodeGoat&lt;/a&gt; you can poke around without setting anything up.&lt;/p&gt;

&lt;h2&gt;
  
  
  This is a personal project
&lt;/h2&gt;

&lt;p&gt;I want to be upfront about this: Themida isn't a company, it doesn't have funding, there's no "managed version" hiding behind the OSS face. It's a side project I'm building in the open because I find the problem interesting and I think devs are tired of compliance tools that don't read code.&lt;/p&gt;

&lt;p&gt;It's released under &lt;strong&gt;AGPL-3.0&lt;/strong&gt; , use it, modify it, run it for your team, fork it. The license just stops someone wrapping it in a SaaS and closing it back up.&lt;/p&gt;

&lt;p&gt;If you try it and something breaks, &lt;a href="https://github.com/Nikolaospet/themida/issues" rel="noopener noreferrer"&gt;open an issue&lt;/a&gt;. If you want to add a rule pack, an LLM adapter, or improve the eval suite, PRs are warmly welcomed, there's a &lt;a href="https://github.com/Nikolaospet/themida/blob/main/CONTRIBUTING.md" rel="noopener noreferrer"&gt;CONTRIBUTING.md&lt;/a&gt; and a &lt;a href="https://github.com/Nikolaospet/themida/blob/main/.github/PULL_REQUEST_TEMPLATE.md" rel="noopener noreferrer"&gt;PR template&lt;/a&gt; ready to go.&lt;/p&gt;

&lt;p&gt;The repo is here: &lt;strong&gt;&lt;a href="https://github.com/Nikolaospet/themida" rel="noopener noreferrer"&gt;github.com/Nikolaospet/themida&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If you build software in regulated industries, fintech, health, EU-anything, anywhere with AI Act exposure, I'd love to hear which rule packs would be most useful to ship next. Drop a comment.&lt;/p&gt;

&lt;p&gt;Thanks for reading 🙏&lt;/p&gt;

</description>
      <category>opensource</category>
      <category>llm</category>
      <category>gdpr</category>
      <category>devtools</category>
    </item>
  </channel>
</rss>
