AI Regulation Guide · Utah
Utah AI Policy Act: who's covered, what it requires
Utah AI Policy Act carries 4 tracked obligations for companies in scope. This guide lists who is covered, the duty tiers, and every obligation with its deadline and statutory citation — all from Shieldra's versioned regulation pack, verified 2026-07-29.
By the Shieldra Compliance Team · Last updated 2026-07-29
Who does Utah AI Policy Act apply to?
Out of scope only if: The Utah AI Policy Act's disclosure duties attach to generative-AI interactions with Utah consumers; none reported.
The Act is scheduled for repeal on 1 July 2027 (sunset extended by SB 332 (2025)) unless the legislature extends it — re-verify around the 2027 General Session. Separately, Utah's abuse-of-personal-identity law (as amended by SB 271 (2025)) covers unauthorised AI-generated likenesses and voices of real people in advertising and solicitation, with a private right of action — outside this pack's scope, but check it if you use AI-generated likenesses in marketing. Utah HB 276 (signed 24 March 2026) adds provenance duties that apply from 1 January 2027/2028 but only above 1M-monthly-user and platform thresholds — most SMBs owe nothing under it.
- What best describes you?
- Do you serve consumers in Utah?
- Do consumers interact with generative AI in your product or service?
- Does the interaction collect sensitive personal information (health, financial, or biometric data), or provide personalized recommendations, advice, or information a person could reasonably rely on to make significant personal decisions — including financial, legal, medical, or mental health advice or services?
- Does the AI itself clearly and conspicuously disclose that it is generative AI, is not human, or is an AI assistant — at the outset and throughout the interaction?
- Would a reasonable user believe your AI provides mental health therapy or acts as a mental health chatbot?
What are the duty tiers under Utah AI Policy Act?
Prominent disclosure required (Utah Code §13-77-103(2) (as amended by SB 226))
Citation: Utah Code §13-77-103(2) (as amended by SB 226) — https://le.utah.gov/xcode/Title13/Chapter77/13-77.html
The statute is conjunctive: prominent disclosure binds an individual providing services in a regulated occupation AND only where the generative-AI use constitutes a high-risk interaction. A non-regulated business has no prominent-disclosure duty in any interaction — its statutory duty is on-request disclosure only.
Disclosure on request (Utah Code §13-77-103(1) (as amended by SB 226))
Citation: Utah Code §13-77-103(1) (as amended by SB 226) — https://le.utah.gov/xcode/Title13/Chapter77/13-77.html
Enforced by the Utah Division of Consumer Protection (a violation is a deceptive practice under 13-11-4(1)): administrative fines up to $2,500 per violation; courts may add up to $2,500 per violation plus injunction, disgorgement, and fees; violating an order carries up to $5,000 per violation. No private right of action (13-77-105).
What are the obligations and deadlines under Utah AI Policy Act?
| Obligation | Who | Deadline | Citation |
|---|
| Regulated professional: disclose AI use prominently in high-risk interactions | regulated_professional | in force since 7 May 2025 (SB 226; the original blanket duty dated from 1 May 2024 and was narrowed) | Utah Code §13-77-103(2)–(3) — https://le.utah.gov/xcode/Title13/Chapter77/13-77.html |
| Disclose AI use when a consumer clearly asks | business, regulated_professional | as amended 7 May 2025 (SB 226) | Utah Code §13-77-103(1) — https://le.utah.gov/xcode/Title13/Chapter77/13-77.html |
| Implement the §13-77-104 safe harbor: have the AI identify itself | business, regulated_professional | available since 7 May 2025 (SB 226) | Utah Code §13-77-104 — https://le.utah.gov/xcode/Title13/Chapter77/13-77.html |
| Mental health chatbot: comply with the Utah 13-72a regime | business, regulated_professional | in force since 7 May 2025 (HB 452) | Utah Code §13-72a (HB 452) — https://le.utah.gov/xcode/Title13/Chapter72a/13-72a.html |
What should you do about each obligation?
Regulated professional: disclose AI use prominently in high-risk interactions (Utah Code §13-77-103(2)–(3))
When generative AI is used to provide services in a Utah-regulated occupation AND the use constitutes a high-risk interaction, disclose prominently that the consumer is interacting with AI — verbally at the start of a verbal interaction, and in writing BEFORE a written interaction starts (13-77-103(3)). SB 226 narrowed the original blanket duty: non-high-risk professional interactions carry only the on-request duty. You must also comply with all requirements of your regulated occupation when providing services through generative AI (13-77-103(2)(b)).
Disclose AI use when a consumer clearly asks (Utah Code §13-77-103(1))
If a consumer clearly and unambiguously asks whether they are dealing with a human or AI, disclose that it is AI. The duty binds a supplier using generative AI in connection with a consumer transaction (defined via 13-11-3) — and after SB 226 it is the only statutory duty for non-regulated businesses and for regulated professionals in non-high-risk interactions. Ensure support flows and the model's own responses answer this truthfully.
Implement the §13-77-104 safe harbor: have the AI identify itself (Utah Code §13-77-104)
Recommended practice, not a statutory duty: configure the AI to clearly and conspicuously disclose — at the outset and throughout the interaction — that it is generative AI, is not human, or is an AI assistant (any of the three formulations in 13-77-104(1)(b); the Division may specify qualifying forms by rule). Maintaining this bars enforcement for disclosure violations, which is the cheapest way to take Utah disclosure risk off the table.
Mental health chatbot: comply with the Utah 13-72a regime (Utah Code §13-72a (HB 452))
Suppliers of mental health chatbots face a separate, stricter regime: disclose the AI's non-human status before first access, again after 7+ days of inactivity, and whenever the user asks; do not advertise products or services within the conversation without disclosing the advertisement and any sponsorship; do not sell or share individually identifiable health information or user input; and maintain the required documentation and policies. Penalties reach $2,500 per violation plus administrative penalties.
Disclaimer
Compliance guidance, not legal advice. Confirm obligations with counsel. Content version 2026.07.29-3, verified 2026-07-29.
Frequently asked questions
Who does Utah AI Policy Act apply to?
The Utah AI Policy Act's disclosure duties attach to generative-AI interactions with Utah consumers; none reported. Coverage turns on the screening questions listed on this page — each obligation then applies its own statutory gate.
When does Utah AI Policy Act take effect?
in force since 7 May 2025 (SB 226; the original blanket duty dated from 1 May 2024 and was narrowed). as amended 7 May 2025 (SB 226). available since 7 May 2025 (SB 226). in force since 7 May 2025 (HB 452)
What are the obligations under Utah AI Policy Act?
Regulated professional: disclose AI use prominently in high-risk interactions; Disclose AI use when a consumer clearly asks; Implement the §13-77-104 safe harbor: have the AI identify itself; Mental health chatbot: comply with the Utah 13-72a regime.