AI Regulation Guide · Utah

Utah AI Policy Act: who's covered, what it requires

Utah AI Policy Act carries 4 tracked obligations for companies in scope. This guide lists who is covered, the duty tiers, and every obligation with its deadline and statutory citation — all from Shieldra's versioned regulation pack, verified 2026-09-08.

Who does Utah AI Policy Act apply to?

Out of scope only if: The Utah AI Policy Act's disclosure duties attach to generative-AI interactions with Utah consumers; none reported.

Utah Code 63I-2-213 repeals Title 13, Chapter 72 (the Office of AI Policy and learning lab) on 1 July 2027 (sunset extended by SB 332 (2025)); the code site also flags Chapter 72a (mental-health chatbots) as affected, while the Chapter 77 disclosure duties in this pack carry no repeal flag on the current text — re-verify around the 2027 General Session. SB 38 (2026, effective 6 May 2026) made conforming cross-reference amendments to 13-77-101, 13-77-102, and 13-72a-204 without changing the duties. Separately, Utah's abuse-of-personal-identity law (as amended by SB 271 (2025)) covers unauthorised AI-generated likenesses and voices of real people in advertising and solicitation, with a private right of action — outside this pack's scope, but check it if you use AI-generated likenesses in marketing. Utah HB 276 (signed 24 March 2026) adds provenance duties that apply from 1 January 2027/2028 but only above 1M-monthly-user and platform thresholds — most SMBs owe nothing under it.

  • What best describes you?
  • Do you serve consumers in Utah?
  • Do consumers interact with generative AI in your product or service?
  • Does the interaction collect sensitive personal information (health, financial, or biometric data), or provide personalized recommendations, advice, or information a person could reasonably rely on to make significant personal decisions — including financial, legal, medical, or mental health advice or services?
  • Does the AI itself clearly and conspicuously disclose that it is generative AI, is not human, or is an AI assistant — at the outset and throughout the interaction?
  • Would a reasonable user believe your AI provides mental health therapy or acts as a mental health chatbot?

What are the duty tiers under Utah AI Policy Act?

Prominent disclosure required (Utah Code §13-77-103(2) (as amended by SB 226))

Citation: Utah Code §13-77-103(2) (as amended by SB 226) — https://le.utah.gov/xcode/Title13/Chapter77/13-77.html

The statute is conjunctive: prominent disclosure binds an individual providing services in a regulated occupation AND only where the generative-AI use constitutes a high-risk interaction. A non-regulated business has no prominent-disclosure duty in any interaction — its statutory duty is on-request disclosure only.

Disclosure on request (Utah Code §13-77-103(1) (as amended by SB 226))

Citation: Utah Code §13-77-103(1) (as amended by SB 226) — https://le.utah.gov/xcode/Title13/Chapter77/13-77.html

Enforced by the Utah Division of Consumer Protection (a violation is a deceptive practice under 13-11-4(1)): administrative fines up to $2,500 per violation; courts may add up to $2,500 per violation plus injunction, disgorgement, and fees; violating an order carries up to $5,000 per violation. The Act creates no private right of action of its own, but because a violation is deemed a deceptive practice under the Utah Consumer Sales Practices Act and 13-77-106 preserves other remedies, consumer remedies under 13-11-19 may attach — confirm with counsel.

What are the obligations and deadlines under Utah AI Policy Act?

ObligationWhoDeadlineCitation
Regulated professional: disclose AI use prominently in high-risk interactionsregulated_professionalin force since 7 May 2025 (SB 226; the original blanket duty dated from 1 May 2024 and was narrowed)Utah Code §13-77-103(2)–(3) — https://le.utah.gov/xcode/Title13/Chapter77/13-77.html
Disclose AI use when a consumer clearly asksbusiness, regulated_professionalas amended 7 May 2025 (SB 226)Utah Code §13-77-103(1) — https://le.utah.gov/xcode/Title13/Chapter77/13-77.html
Implement the §13-77-104 safe harbor: have the AI identify itselfbusiness, regulated_professionalavailable since 7 May 2025 (SB 226)Utah Code §13-77-104 — https://le.utah.gov/xcode/Title13/Chapter77/13-77.html
Mental health chatbot: comply with the Utah 13-72a regimebusiness, regulated_professionalin force since 7 May 2025 (HB 452)Utah Code §13-72a (HB 452) — https://le.utah.gov/xcode/Title13/Chapter72a/13-72a.html

What should you do about each obligation?

Regulated professional: disclose AI use prominently in high-risk interactions (Utah Code §13-77-103(2)–(3))

When generative AI is used to provide services in a Utah-regulated occupation AND the use constitutes a high-risk interaction, disclose prominently that the consumer is interacting with AI — verbally at the start of a verbal interaction, and in writing BEFORE a written interaction starts (13-77-103(3)). SB 226 narrowed the original blanket duty: non-high-risk professional interactions carry only the on-request duty. You must also comply with all requirements of your regulated occupation when providing services through generative AI (13-77-103(2)(b)).

Disclose AI use when a consumer clearly asks (Utah Code §13-77-103(1))

If a consumer clearly and unambiguously asks whether they are dealing with a human or AI, disclose that it is AI. The duty binds a supplier using generative AI in connection with a consumer transaction (defined via 13-11-3) — and after SB 226 it is the only statutory duty for non-regulated businesses and for regulated professionals in non-high-risk interactions. Ensure support flows and the model's own responses answer this truthfully.

Implement the §13-77-104 safe harbor: have the AI identify itself (Utah Code §13-77-104)

Recommended practice, not a statutory duty: configure the AI to clearly and conspicuously disclose — at the outset and throughout the interaction — that it is generative AI, is not human, or is an AI assistant (any of the three formulations in 13-77-104(1)(b); the Division may specify qualifying forms by rule). Maintaining this bars enforcement for disclosure violations, which is the cheapest way to take Utah disclosure risk off the table.

Mental health chatbot: comply with the Utah 13-72a regime (Utah Code §13-72a (HB 452))

Suppliers of mental health chatbots face a separate, stricter regime: disclose the AI's non-human status before first access, again after 7+ days of inactivity, and whenever the user asks; do not advertise products or services within the conversation without disclosing the advertisement and any sponsorship; do not sell or share individually identifiable health information or user input; and maintain the required documentation and policies. The Division of Consumer Protection may impose administrative fines up to $2,500 per violation, and a court may add fines up to $2,500 per violation, injunctions, disgorgement, and fees, with up to $5,000 per violation for breaching an order (13-72a-204). The code site flags Chapter 72a as affected by the 1 July 2027 repeal in 63I-2-213 — re-verify before then.

Disclaimer

Compliance guidance, not legal advice. Confirm obligations with counsel. Content version 2026.09.08-1, verified 2026-09-08.

Frequently asked questions

Who does Utah AI Policy Act apply to?

The Utah AI Policy Act's disclosure duties attach to generative-AI interactions with Utah consumers; none reported. Coverage turns on the screening questions listed on this page — each obligation then applies its own statutory gate.

When does Utah AI Policy Act take effect?

in force since 7 May 2025 (SB 226; the original blanket duty dated from 1 May 2024 and was narrowed). as amended 7 May 2025 (SB 226). available since 7 May 2025 (SB 226). in force since 7 May 2025 (HB 452)

What are the obligations under Utah AI Policy Act?

Regulated professional: disclose AI use prominently in high-risk interactions; Disclose AI use when a consumer clearly asks; Implement the §13-77-104 safe harbor: have the AI identify itself; Mental health chatbot: comply with the Utah 13-72a regime.