Although a large body of policy and practice exists on the data governance of medical applications, this paper is the first to provide a systematic overview of human–AI interactions and data risks/governance in consumer-oriented health and wellness applications, which are a growing area of personal health information management. Following PRISMA (Preferred Reporting Items for Systematic Reviews and Meta-Analyses) guidelines, 116 relevant articles, 9 representative cases, and 81 policy documents from official government websites were collected and analysed using thematic analysis. Case studies were used to validate the thematic findings and identify practical response measures to governance risks. The current state of human–AI interaction is discussed in four dimensions in the literature: application scenarios, service contents, AI technologies applied, and interfaces. The interaction data types generated are related to physical indicators, lifestyle habits, personal identity and social relations, digital behaviour, health advice, and others. The data governance practices and risks comprise six categories: governance subjects, policies, standards and principles, technologies and facilities, lifecycle measures, and data rights protection and risk management. Among the most critical risks are data privacy breaches, unclear data ownership, inconsistent standards, and poor data quality. The findings highlight that current responses—primarily focused on compliance, privacy protection, and technical optimisation—remain fragmented and inadequate for addressing the critical risks identified. This study provides practical insights for policymakers, developers, and platform providers seeking to strengthen collaborative, adaptive, and trust-based governance in AI-enabled health applications.