Domain Atlas / Behavioral-health & crisis triage
Woebot (a governed app wind-down)
Work with this case in the PAN Lab ↗
Woebot, a rule-based (non-generative) cognitive behavioral therapy chatbot used by roughly 1.5 million people over its lifetime, was deliberately retired by its maker on a pre-announced schedule: the app was taken down on June 30, 2025, with a transcript-request window (deadline July 15, 2025) and all account data anonymized as of July 31, 2025, removing personally identifying information rather than silently abandoning the service. The founder and chief executive attributed the shutdown to the cost of meeting FDA marketing-authorization requirements and to a regulatory-pathway gap, framing the exit as economic and regulatory rather than a clinical failure - a self-reported account, not an independently audited finding. The roughly 1.5 million figure is a cumulative lifetime number reported in press coverage, not an audited point-in-time active-user count.[3]
What happened
Woebot was a fully automated cognitive behavioral therapy (CBT) chatbot delivered through a smartphone app, built by Woebot Health (formerly Woebot Labs) and founded by Alison Darcy. It delivered self-help CBT through a rule-based, pre-scripted conversational agent: even though the interaction felt conversational, its responses followed authored decision paths rather than free-form generative text (STAT News, 2025), so it could not invent novel clinical claims at runtime. Roughly 1.5 million people used Woebot over its lifetime — a cumulative figure reported in press coverage, not an audited point-in-time active-user count. Its peer-reviewed efficacy record is a single early-stage study: a 2017 randomized controlled trial in JMIR Mental Health (Fitzpatrick, Darcy, Vierhile; n=70, ages 18–28, two weeks) found the Woebot group significantly reduced depression symptoms on the PHQ-9 against an information-only self-help control, a moderate between-groups effect of about d = 0.44, and concluded that conversational agents can be a feasible and engaging way to deliver CBT. That is an efficacy signal, not regulatory validation: the trial was small, short, and unblinded, and the authors were the tool's own people.
A separate, investigational, prescription-only variant, WB001, received an FDA Breakthrough Device Designation in May 2021 — an expedited-review status, not marketing authorization — as an 8-week smartphone digital therapeutic combining CBT and interpersonal-psychotherapy elements for postpartum depression, to be used under clinician supervision (Business Wire, 2021). WB001 entered a pivotal, multi-center, double-blind Software as a Medical Device (SaMD) trial with the first patient enrolled in January 2023 (Business Wire, 2023); it remained investigational and never received FDA marketing authorization. The consumer app that shut down and the investigational device that WB001 was are two different things and should not be conflated. The company had raised substantial capital — a $90 million Series B in July 2021 co-led by JAZZ Venture Partners and Temasek, bringing total funding to $114 million (Business Wire, 2021), context for the founder's later argument that authorization economics, not lack of investment, ended the product. (A secondary industry summary labeled the round a "Series C" and totaled funding at about $107.5 million; the primary press-release figures are preferred here and the discrepancy is noted, not resolved.)
The defining event is the exit. In April 2025 Woebot Health announced it would shut the app down (HLTH, 2025), and it did so deliberately and on a published schedule. Per the company's own FAQ, the Woebot app was retired on June 30, 2025; the deadline for requesting a transcript of your conversations was July 15, 2025; and all account data is anonymized as of July 31, 2025 — personally identifying information removed rather than the service silently abandoned or the data retained indefinitely (Woebot Health FAQ, 2025). Founder and chief executive Alison Darcy attributed the shutdown largely to the cost of meeting the FDA's requirements for marketing authorization and to a mismatch between a fast-moving AI landscape and regulatory frameworks that lacked a clear pathway, framing the exit as economic and regulatory rather than a clinical failure (STAT News, 2025). That attribution is her own on-record account, not an independently audited finding. Commentators read the exit as a signal about AI-in-mental-health regulation: a clinically studied, transparently governed, non-generative tool was decommissioned while unregulated general-purpose chatbots reached far larger audiences without clinical validation, precisely because they are not marketed as health tools (STAT News; HLTH, 2025).
The sociotechnical reading
Almost every other case in this Atlas asks one of two questions: should this system have been deployed at all, and when it ran, did the human loop catch what the model got wrong. The halted cases — a predictive tool stopped before it ever scored a live child, a risk model shelved after its false-positive rate came back — answer the first question by not deploying. Woebot answers a question none of the others do. It was deployed. It ran for years, was used by roughly 1.5 million people, carried a peer-reviewed (if early-stage) efficacy signal, and was non-generative by design. And then its maker chose to turn it off. The governance that matters in this case is not whether to build it or whether the model was accurate on any given day. It is the governance of the ending: what a running service does, on the way out, with the most sensitive thing it ever accumulated.
Read on the system map, the model node is the quiet one. A rule-based agent that follows authored decision paths cannot drift or invent a novel clinical claim at runtime, so the error-generation surface is bounded by design — which is exactly why improving the model is not the lever here. The load-bearing node is the record store: a per-user archive of mental-health conversations, the most sensitive corpus a service like this can hold. In the ordinary course that store just accumulates. The danger arrives at decommissioning, when the business reason to keep watching it disappears: attention lapses, the team that maintained it leaves, and an orphaned transcript archive can drift toward a successor system, an unpurged backup, or a third party — the latent egress the map keeps drawn but empty until a wind-down without a plan opens it. What Woebot did, and what makes it the Atlas's governed-exit reference point, is treat the teardown as the governance rather than as cleanup: a pre-announced retirement date, a bounded window to retrieve your own transcripts, and a scheduled anonymization that removed identifying information by a published date. On the map those are the record-teardown levers — purge, minimize, and a dated cadence someone can be held to — and they are what separate a governed exit from a silent abandonment.
A second, quieter governance surface sits on the evidence. The temptation on the way out is to say a tool used by more than a million people was proven to work. The record does not support that: the efficacy evidence is one small, short, unblinded early-stage trial authored by the tool's own people, an efficacy signal rather than a validation, and the investigational prescription variant that did engage a formal regulatory pathway never reached marketing authorization. The distinct lesson this case adds to the Atlas is that the end of a system's life is a governable event in its own right, with its own failure modes — an orphaned record store and an overstated evidence claim — that none of the deployment-time or human-in-the-loop cases capture. The governable surface at a decommissioning is the teardown of the record the service accumulated, the schedule that makes the teardown accountable after everyone stops watching, and the honesty of what is claimed about the tool as it leaves. The honest boundary throughout: nothing here models symptoms, recovery, or crisis, and the people who used this app are not on the map. A transcript on this diagram is an institutional record to be wound down responsibly, never a person — and the cause of the shutdown is carried as the founder's own reported account, not as an audited fact.
The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.