Behavioral Health AI
W

Wysa

Conversational artificial intelligence delivering cognitive behavioural therapy, behavioural activation, dialectical behaviour techniques and mindfulness through text chat. Founded 2016 by Jo Aggarwal and Ramakant Vemati. Corporate geography is genuinely split and sources disagree: press releases carry Boston datelines, the operating entity is registered in the United Kingdom, and the company has substantial Indian operations, which is consistent with its stated compliance across American, British, European and Indian data regimes.

Reach is the largest of any record in this index: between six and six and a half million users across more than 105 countries, with the company separately describing coverage of more than 11 million lives. The business now runs on two tracks. A freemium consumer application offers basic chat free with a premium tier adding unlimited use and human coaches. A provider facing line sells into health systems, with a gateway product reported at more than 185,000 patients in the national talking therapies programme and a hybrid product placing artificial intelligence between sessions and a human therapist in them. Institutional customers named by the company include the National Health Service, the Singapore Ministry of Health, Cincinnati Children's Hospital Medical Center, Aetna International, Accenture, Colgate-Palmolive and Swiss Re.

The regulatory position requires precision, because third party sources get it wrong. Wysa holds Breakthrough Device Designation from the American regulator, granted May 2022 for an agent treating adults with chronic musculoskeletal pain and associated depression and anxiety. A designation is an agreement to expedite review; it is not clearance and it is not approval. At least one independent directory describes the company as holding an approved and cleared Class II device, which is incorrect. The company itself appended an editorial note to its own announcement stating that the designation applies to that specific indication and does not represent blanket approval across its products, which is unusually disciplined disclosure and the opposite of the credential inflation recorded elsewhere in this index.

Evidence is genuine. An independent peer reviewed trial published in a medical informatics journal found the tool effective for chronic pain and associated depression and anxiety, more effective than standard orthopaedic care and comparable to in person psychological counselling. Separate peer reviewed work reports therapeutic alliance comparable to human therapist relationships. A competitive research grant of roughly 7.2 million dollars from a major medical research charity followed in February 2026. Total funding is around 35 million dollars.

The trust posture is the strongest encountered in this index, and is set out on the security and stewardship axes.

This record is best read against Limbic, built immediately before it: two conversational mental health products, one holding an actual device certification and the other a designation, with very different architectures of consent, anonymity and clinical oversight.

AI Health Index verifiedAugust 24, 2026
Compare Wysa with other vendors
Founded
2016
Headquarters
Boston, Massachusetts, United States
Website
www.wysa.com
Categories
behavioral-health
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

The conversational agent is the product. A user opens the application and talks to a model that delivers structured therapeutic technique, and there is no platform, portal or workflow layer that would retain value without it.

One qualification belongs on the record without changing the grade. The premium consumer tier and parts of the provider offering include human coaches and therapists, delivered through scheduled video sessions, so the company sells labour alongside software. That is a stepped care design rather than a services business: the free and default experience is entirely automated, the human layer is an escalation above it, and the scale claims of six million or more users plainly describe the automated product rather than a coaching roster.

The hybrid provider product places the model between therapy sessions with a clinician retaining the sessions themselves, which again positions the model as the continuous component and the human as the periodic one.

CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.
Vendor Published

The oversight structure differs sharply between the two product lines and only one of them has any.

The provider facing hybrid product is well conceived: artificial intelligence between sessions, a human therapist in them, sold into services where a clinician owns the case. That is a described and sensible boundary.

The consumer product has no clinician anywhere in the default path. A person in distress converses with a model that delivers therapeutic technique, with human coaches available only on a paid tier. At six million users that is a very large volume of unsupervised therapeutic interaction.

What is missing is the safety architecture. Third party summaries describe suicide and self harm escalation workflows, a clinical ethics board and published ethics principles covering escalation to humans in crisis, and none of that was located in first party material during this pass. No escalation rate, no detection sensitivity for risk disclosure, no description of what the product does when a user discloses intent, and no statement of how local emergency protocols are engaged across the more than 105 countries it operates in, where crisis services differ entirely.

Graded C. For a product of this reach, the crisis pathway is the disclosure that matters most and it is not published. Ask for it directly.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

The therapeutic content is specified and the technology is not.

What is published is the clinical basis: cognitive behavioural therapy, behavioural activation, dialectical behaviour techniques and mindfulness, all named modalities with established evidence bases, which lets a clinician judge whether the intervention is appropriate before judging whether the model delivers it well. That is the right level of specificity for a therapeutic product and more than a generic wellness claim.

The technical description stops at natural language processing and machine learning. No model class, architecture, version or foundation model is named. The privacy policy describes the artificial intelligence only as programs that understand what the user types and guide them to helpful information, which is written for a lay reader and is the most detailed public account located.

No performance figure is published outside the trial literature. Efficacy from a peer reviewed trial answers whether the intervention works; it does not answer how often the model misreads a message, misroutes a conversation or responds inappropriately, and no such measure exists publicly. Ask for the model provenance and for conversational failure rates.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

No model party is named. No foundation model provider, model family or version is identified anywhere in published material, and no sub processor register was located.

One link is disclosed in a useful form. Cloud hosting is described as managed by third party providers operating under stringent privacy and health data programmes, with service level and data protection agreements maintained with those hosting partners, and data processing agreements with service providers stated to be reviewed and maintained as an ongoing control. That is a described supplier governance process rather than a list, which is better than silence and short of enumeration.

The training position is the significant gap. Nothing located states whether user conversations contribute to model development. The architecture makes that question less acute than it would otherwise be, since the application generally does not collect personal data and identifiers shared in conversation are hashed within 24 hours, so any corpus is substantially de identified by design rather than by policy. That is a real mitigation and it is not a statement of intent.

Ask which models underlie the agent, for the sub processor list, and for an explicit position on training with conversation data.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Peer Reviewed Publication

Real independent trial evidence, narrower in scope than the deployment it supports.

An independent peer reviewed clinical trial published in a medical informatics journal found the tool effective for chronic pain and associated depression and anxiety, more effective than standard orthopaedic care, and comparable to in person psychological counselling. Separate peer reviewed work reports that therapeutic alliance formed with the agent is comparable to that formed with human therapists, which is a meaningful finding because alliance is one of the strongest predictors of therapy outcome. The American regulator reviewed that evidence in granting Breakthrough Device Designation, and a major medical research charity awarded a competitive grant of roughly 7.2 million dollars in February 2026, which is independent scientific endorsement of a kind no other record here holds.

Deployment corroborates scale: more than six million users across 105 or more countries, a reported 185,000 patients through the national talking therapies gateway, and named institutional customers spanning a national health system, a national health ministry, a paediatric academic centre and several multinational employers and insurers.

Held at B because the trial evidence addresses one narrow indication, adults with chronic musculoskeletal pain and co-occurring depression and anxiety, while the product is deployed to a general population many orders of magnitude larger. Efficacy in that cohort does not establish it for everyone using it.

AA on AI Safety and PHI StewardshipRetention windows, training use and de identification are stated specifically enough to be contradicted, alongside the safety engineering: guardrails, hallucination mitigation, and how a safety event is handled.
Vendor Published

The most complete stewardship disclosure encountered in this index, and the only one resting on a certified privacy management system rather than a security one.

The company holds third party audited certification to both the international information security standard and its privacy extension, the latter being a privacy information management system specifically covering handling of personally identifiable information. No other record here holds the privacy certification.

The practice detail is specific and unusually operational. The application generally does not ask for personal data at all, so anonymity is architectural rather than promised. Identifiers a user happens to share in conversation are hashed within 24 hours. Random identifiers are used for all transactions between application and servers. Data is encrypted in transit and at rest under a named cipher, with storage in the United Kingdom for the clinical programme. Access is role based with two step verification, endpoint security is applied across staff systems, background verification and regular training are described, third party compliance audits run annually, and vulnerability scans and penetration tests are described as regular.

The company also states plainly that conversations are never processed to form a diagnostic opinion or for medical purposes, which sets a boundary on secondary use.

What is still absent is an explicit position on whether conversations train models. The de identification architecture substantially mitigates it and does not replace it.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

Four jurisdictions are named individually, which is the most of any record in this index, and the position is stated with unusual candour about its limits.

Published compliance covers the American health privacy framework where applicable, European and British data protection law, and Indian information technology and sensitive personal data rules. The company is registered with the British data protection regulator, meets the national health system data security toolkit standards, and complies with the clinical risk management standard for health software manufacturers. Pseudonymisation is defined and described as practised rather than asserted.

The candour is worth noting. The company qualifies the American framework with the words where applicable, and independent commentary observes that it does not present the consumer application as covered by that framework for individual users while enterprise and insurer deployments carry stronger obligations. That distinction is correct and most vendors blur it.

Held at B because no business associate agreement template, posture or execution requirement was located for the American provider market, and because a buyer must establish for themselves which regime governs the specific deployment they are purchasing. Ask which framework applies to your configuration and for the agreement position.

AA on Security Certifications and Trust CenterCertifications named with their type and version and presented as retrievable artefacts, usually through a trust portal a buyer can open without asking.
Vendor Published

Three certifications, correctly described, with the audit and testing regime disclosed around them.

The company states a third party audited information security management system and privacy information management system certified to the international information security standard at its 2022 revision and to its privacy extension at the 2019 revision, and separately that it holds certification under the national cyber baseline scheme. It complies with the clinical risk management standard for health software manufacturers and meets the national health system data security toolkit standards, and is registered with the British data protection regulator.

The language discipline deserves explicit credit. The company writes certified where it is certified and compliant where it is compliant, and states the standard revisions. That is the correct usage, and this session has recorded three separate vendors blurring exactly this distinction: one presenting alignment with a framework as a badge, one presenting a framework with no certification scheme as a certification, and one describing itself as compliant with the same information security standard Wysa is certified against while using the stronger word elsewhere in the same sentence.

Supporting practice is published rather than implied: annual third party compliance audits, regular vulnerability scans and penetration tests of applications and infrastructure.

Held from perfection only by the absence of a consolidated trust centre and a report availability process. Ask whether certificates and reports can be shared.

BB on FDA and Regulatory StatusThe pathway is stated and in progress, or a clearance is named without the vintage and scope a buyer needs to match it to the product on offer.
Regulatory Filing

A genuine regulatory engagement that is routinely misdescribed by others and accurately described by the company itself.

Wysa holds Breakthrough Device Designation granted in May 2022 for an agent serving adults with chronic musculoskeletal pain and associated depression and anxiety. That designation is meaningful: the regulator reviewed the underlying peer reviewed trial evidence before granting it, and it commits the agency to expedited engagement on a device addressing an unmet need. It is not clearance and it is not approval, and a designated device is not authorised for marketing on the strength of the designation.

That distinction is being lost in the wider record. At least one independent directory describes the company as holding an approved and cleared Class II device specifically cleared for clinical use, which is incorrect and would mislead a buyer materially. The correction belongs here because this index exists to be the place a buyer can check.

The company's own conduct is the opposite. It appended an editorial note to its own 2022 announcement stating that the designation applies to that specific indication and does not represent blanket regulatory approval across its products. Voluntarily narrowing your own regulatory claim is rare and is credited.

Held at B rather than A because a designation is not a certification. Limbic, by contrast, holds an actual Class IIa device certification. Ask for current clearance status and any submission in progress.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Third Party Estimated

Governance structures are reported to exist and were not located in first party material during this pass, which is itself the finding.

Third party summaries describe a clinical ethics board and published artificial intelligence ethics principles covering transparency, user autonomy and appropriate escalation to human support in crisis. If accurate those are meaningful structures, and none was found on the company's own pages in this retrieval, so they are recorded as reported rather than verified.

What is definitely absent is measurement. No bias or fairness testing, no performance breakdown by population, no drift monitoring output and no independent audit of model behaviour was located.

The fairness question here is unusually pointed because of the reach. A conversational therapeutic agent operating in more than 105 countries with multilingual support is encountering expressions of distress that differ by language, culture and idiom, and the same words carry different clinical weight in different contexts. Whether the model recognises distress equally well in its non English languages, or in dialects and registers under represented in training, is the central equity question for this product, and nothing addresses it.

Ask for the ethics board's published outputs and for performance by language and region.

CC on AI Liability and RecourseMechanisms exist that let someone challenge an output, such as audit trails, source traceability or review before commit, with nothing standing behind the output and no route for the harmed party.
Vendor Published

Trial evidence establishes that the intervention can work; nothing establishes what happens when the product fails an individual user.

What exists on the positive side is real. Peer reviewed efficacy in a defined indication, regulatory review of that evidence through the designation process, and compliance with a clinical risk management standard that requires hazard identification and a safety case for health software.

What is absent is any commitment or measure. No service level agreement, warranty, indemnity or remediation commitment was located. No conversational failure rate, no crisis detection sensitivity, and no escalation performance figure is published.

The allocation question is sharper here than in any administrative product in this index. A user in acute distress interacting with an automated agent that does not recognise risk is the failure mode, and the consequences are not a denied claim. The consumer product places no clinician in that path at all. The company's own terms disclaim complete security and ask users to take care with what they share, which is honest and is not a performance commitment.

One pre emptive note: further efficacy or user scale figures cannot move this grade. Only a published crisis detection measure, or a stated commitment on escalation, will change it.

Integration and Deployment
CC on EHR and Interoperability DepthIntegration is claimed through standards or a middleware layer with no system named and nothing to verify.
Vendor Published

Integration is necessarily real for one product line and nowhere specified.

The consumer application needs no integration at all, which is a legitimate architectural position and part of why it reaches the scale it does. The provider products are different: a gateway feeding a national talking therapies service and a hybrid product placing the model between clinician sessions both require connection to the service's case management system to be useful, and the reported figure of more than 185,000 patients through that gateway indicates it works in production.

No detail is published. No case management or record system is named, no interface standard is described, no connection mechanism is specified, and nothing states whether assessment or engagement data flows back into the clinical record. The company does meet the national procurement assessment criteria, which include an interoperability section, so evidence exists in submissions that is not public.

The multi country footprint compounds it, since each health system runs different infrastructure and nothing indicates what integration exists outside the one national programme.

Graded C for capability evidenced by deployment with no published specification. Ask which systems the provider products connect to and through what standards.

BB on Deployment Model and Data ResidencyOptions and residency are stated with isolation or the processing path left open.
Vendor Published

More is answered here than in almost any other record, without amounting to a full residency position.

What is published: storage servers for the clinical programme are stated to be United Kingdom based, data is encrypted at rest under a named cipher and in transit under transport layer security, hosting is provided by third party cloud operators running privacy and health data compliant control programmes, and service level and data protection agreements are maintained with those hosting partners. Naming the storage jurisdiction for a specific product line is a concrete residency statement, and most records in this index offer nothing.

What is not published is the rest of the picture. The cloud provider is not named, no region list exists for the consumer product operating across more than 105 countries, no tenancy model is described, and there is no statement of whether data from one jurisdiction can be accessed from another. The company operates under American, British, European and Indian regimes with substantial Indian engineering presence, so cross border access is a live question that the United Kingdom storage statement does not answer.

Graded B on a specific jurisdictional commitment for the clinical line. Ask for regions by product and market, and for personnel access location.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

One product line has a published commercial model and the other has none.

The consumer offering is transparent by the standards of this index: the basic conversational product is free, and a premium subscription adds unlimited use and access to human coaches. A prospective user knows what costs money and what does not before engaging, which no enterprise vendor in this index matches.

The provider and enterprise line publishes nothing. No pricing, unit of charge, per patient or per employee rate, minimum commitment or contract term was located for the health system, payer or employer products that the company describes as driving its growth. Given the buyer segments named span a national health system, a health ministry, insurers and multinational employers, those are four different commercial models and none is described.

The two tier structure raises a question the company does not address: whether the free consumer product and the commissioned provider product are the same software, and if so what a health system is paying for that a member of the public receives at no cost. Ask for the enterprise pricing basis and what distinguishes the commissioned product.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Vendor Published

The widest reach of any record in this index, across geography, channel and buyer type.

Geographic coverage spans more than 105 countries with multilingual support and access through a widely used messaging platform as well as the application, which is a deliberate accessibility design rather than a distribution accident. Buyer coverage runs across direct to consumer, employers, insurers, providers and national health bodies, with named customers in each.

Clinical coverage is common mental health presentations, principally depression, anxiety and stress, with a specific evidenced indication in chronic pain with co-occurring depression and anxiety, and a paediatric academic centre among named customers.

Held at B rather than A because breadth of reach is not the same as depth of deployment, and the company does not disclose usage by market, so the difference between a country with a commissioned service and one with app downloads cannot be established. Severe mental illness, substance use and crisis care sit outside the stated scope, correctly. Ask for deployment depth by market rather than user counts.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Consumer product free with paid premium tier; enterprise pricing not published
Partially disclosed. The consumer model is freemium with a subscription premium tier including human coaching. No unit of charge is stated for provider, payer, employer or health ministry deployments, and whether those price per patient, per member, per service or per licence is unknown. Not disclosed as a template or posture. Compliance is claimed across four regimes named individually: the American health privacy framework where applicable, European and British data protection law, and Indian information technology and sensitive personal data rules. The company is registered with the British data protection regulator and meets the national health system data security toolkit standards. Note the qualifier where applicable on the American framework: independent commentary observes the consumer application is not presented as covered for individual users, while enterprise and insurer deployments carry stronger obligations. A buyer must establish which regime governs their specific configuration. Not disclosed. No implementation, integration or onboarding fee position was located for the provider products, and no implementation timeline is published, despite deployment into a national talking therapies service requiring case management integration and satisfaction of national procurement assessment criteria. Vendor Published

Two product lines with opposite levels of commercial disclosure. The consumer offering is transparent by the standards of this index: the basic conversational product is free and a premium subscription adds unlimited use plus access to human coaches, so a prospective user knows what costs money before engaging. The provider and enterprise line publishes nothing at all.

No pricing, unit of charge, per patient or per employee rate, minimum commitment or contract term was located for the health system, payer, employer or health ministry products the company describes as driving its growth, and those four buyer types imply four different commercial models.

The structure raises a question the company does not address and a buyer should: whether the commissioned provider product is the same software the public receives free, and if so what the health system is paying for. Likely answers involve integration, clinical governance, reporting and the hybrid therapist workflow rather than the conversational agent itself, but nothing published says so. Two further points bear on commercial evaluation.

Funding is roughly 35 million dollars in total, modest against a claimed six million plus users across more than 105 countries, and the most recent identified round was a competitive research grant of roughly 7.2 million dollars from a medical research charity in February 2026 rather than equity, which is scientific validation but a different signal from commercial traction.

And the consumer product being free means a buyer evaluating the enterprise version should ask what the paid tier measurably adds. Ask for the enterprise pricing basis by buyer type, what distinguishes the commissioned product, and the contract term and exit provisions.