Utah
Utah AI Policy Act: A Practical Breakdown
Utah's AI Policy Act makes disclosure the whole compliance obligation for most businesses, while mental health chatbots and licensed professionals face sharply different rules under the same statute.
Utah's AI Policy Act doesn't ask what your AI system does. It asks whether you told the person on the other end that they're talking to one. That single design choice — disclosure as the compliance obligation, not a duty of care, not a risk tier, not an impact assessment — separates Utah from Colorado and the EU AI Act more than any other feature of the statute, and it's the detail a compliance team importing a risk-based mental model from those other regimes is most likely to get wrong.
The law started as Senate Bill 149 in 2024, the Artificial Intelligence Policy Act (UAIPA), and it's been narrowed twice since: SB 226 and SB 332 in 2025 tightened the disclosure rules and extended the statute's sunset, and a separate bill, HB 452, carved mental health chatbots out into their own regime entirely. Treating all of that as one undifferentiated "Utah AI law" is how a compliance program misses which rule actually applies to which product.
A disclosure law, not a duty-of-care law
SB 149 created the Office of Artificial Intelligence Policy inside the Utah Department of Commerce and built the statute around two mechanisms: a disclosure requirement triggered by the kind of AI interaction a business is having with a consumer, and a liability clause making clear that AI involvement doesn't change who's responsible when something goes wrong. Nothing in the statute classifies systems by risk category the way Colorado's SB 205 does, and nothing requires an annual impact assessment. Colorado's duty-of-care model asks whether a company managed a foreseeable risk; Utah's asks whether the company said, out loud or in writing, that AI was involved.
The baseline rule: disclose on request
For an ordinary consumer-facing business — a retailer's support chatbot, a scheduling assistant, a sales-inquiry bot — the obligation is narrow. A supplier using generative AI to communicate with a consumer has to disclose that fact, but only when the consumer makes what the statute (as amended by SB 226 in 2025) calls a "clear and unambiguous request." That's a tightening from the law's original 2024 language, which simply required disclosure "if asked." The practical effect is the same in spirit — nothing requires a business to announce "this is AI" at the top of every chat window — but the 2025 version gives a business a bit more room to treat a vague or off-hand question differently from an actual request for clarification. SB 226 also narrowed the statutory definition of generative AI itself, limiting it to technology designed to simulate a human conversation with consumers, rather than reaching every AI-adjacent tool a business might use.
The higher bar: regulated professionals and "high-risk" interactions
The stricter track applies to people practicing a regulated occupation — the licensed professions Utah already regulates, such as mental health therapists, attorneys, and financial advisors — but even that track got narrower in 2025. Before SB 226, a regulated professional using generative AI with a client had to disclose that upfront, proactively, both orally in speech and in writing for electronic communications, in essentially any client interaction. SB 226 confined that proactive duty to what it defines as a "high-risk artificial intelligence interaction": one that involves collecting sensitive personal information such as health, financial, or biometric data; giving a personalized recommendation or advice a consumer could reasonably rely on to make a significant personal decision; or providing financial, legal, medical, or mental health advice or services. A regulated professional using an AI tool for something outside that definition — drafting an internal memo, say — isn't automatically pulled into the proactive-disclosure duty just because they're licensed.
The safe harbor that makes self-disclosure the easy path
SB 226 also added a safe harbor, and it's the most actionable thing in the whole statute for most product teams: a business isn't subject to an enforcement action over the disclosure provisions if the generative AI itself clearly and conspicuously discloses that it's non-human — an AI assistant, or generative AI — at the outset of the interaction, and keeps disclosing that throughout. In practice, that means a company doesn't need a legal review process to stay compliant; it needs the chatbot's own opening line and ongoing framing to say what it is. A bot that introduces itself as "an AI assistant" and doesn't later imply it's a human support agent clears the baseline disclosure rule and, for most regulated-professional use cases, the high-risk one too, without anyone having to track whether a given user asked the right question.
No hiding behind the AI
SB 149 paired the disclosure rules with a liability clause, now codified at Utah Code § 13-2-12, that closes an obvious loophole: it is not a defense to a consumer-protection claim that generative AI made the statement, took the act, or was used in furtherance of the violation. If a human employee making the same promise or representation would create liability under Utah's existing consumer-protection law, an AI system making it creates the same liability. The statute doesn't invent new substantive duties here — it just makes sure AI can't be used as a liability shield for duties that already exist.
Enforcement, penalties, and the regulatory sandbox
SB 226 gave Utah's Division of Consumer Protection express rulemaking and enforcement authority over the disclosure provisions, with a civil penalty of up to $2,500 per violation — on top of whatever penalty is already available under the Utah Consumer Sales Practices Act for the same underlying conduct. That's a materially different enforcement posture from a private-right-of-action statute: an individual consumer doesn't sue directly over a disclosure failure, and the state has to decide the case is worth bringing.
The statute's other half, largely unchanged by the 2025 amendments, is the AI Learning Laboratory Program — a regulatory sandbox the Office of Artificial Intelligence Policy runs for companies that want to test a system under closer supervision before committing to a compliance approach. A participant can get a regulatory mitigation agreement among the company, the office, and the relevant state agencies, which can include a cure period before any penalty applies, reduced civil fines during the participation term, and terms tailored to whatever issue the company flagged going in. It's a genuine option for a company building something novel enough that it's unsure how the disclosure rules apply, not a general-purpose exemption.
A worked example
Take Wasatch TeleCare, a hypothetical telehealth scheduling company operating in Utah. Its front-end chatbot handles appointment booking, insurance questions, and office hours — a general consumer interaction with no sensitive data collection and no personalized advice involved. Under the baseline rule, Wasatch only has to disclose that the bot is AI if a patient clearly asks; configuring the bot to open with "Hi, I'm an AI scheduling assistant" satisfies the safe harbor and the question never has to come up.
Now say Wasatch adds a second tool: a generative AI symptom-triage assistant that asks about a patient's condition and suggests next steps, used by the nurse practitioners on staff who are the regulated professionals of record. That tool collects health data and gives personalized advice a patient could reasonably act on — squarely inside the "high-risk interaction" definition. For that feature, Wasatch can't rely on a patient asking the right question; the proactive disclosure duty applies regardless, and the practice needs the tool to say, upfront and in whatever form the interaction takes, that it's AI. Two features of the same product, two different compliance tracks, governed by what the interaction actually does rather than by the fact that it's "the same chatbot" from a product standpoint.
The separate law for mental health chatbots
HB 452, enacted in the same 2025 session, doesn't amend the AI Policy Act — it stands on its own, in a new part of the Utah Code specifically covering AI applications in mental health. It defines a "mental health chatbot" as generative AI technology that engages in interactive conversations with a user similar to the confidential communications a person would have with a licensed mental health therapist, and it carves out tools that only produce scripted output (guided meditations, mindfulness exercises) or that merely analyze a user's input to route them to a human therapist.
For anything that meets that definition, disclosure isn't conditioned on a request or a high-risk classification — it's required at the beginning of any interaction, before the user can access the chatbot's features, and again any time the user asks whether they're talking to AI. HB 452 also restricts what a mental health chatbot's operator can do with what it collects: selling or sharing individually identifiable health information or user input with a third party is barred, aside from narrow exceptions for a health care provider acting with the user's consent, a health plan responding to the user's own request, or sharing genuinely necessary to keep the tool functioning.
What this means for a compliance program
The practical task isn't writing one AI disclosure policy — it's inventorying every consumer-facing generative AI touchpoint and sorting each into the bucket that actually governs it: general business (disclose on clear request), regulated-professional high-risk interaction (disclose proactively), or mental health chatbot (disclose at every stage, plus the data-sharing restrictions). For the large majority of ordinary business chatbots, the cheapest real fix is also the most complete one: make sure the bot's own language puts you inside SB 226's safe harbor, and the disclosure question mostly answers itself. Keep an eye on the calendar, too — the AI Policy Act's sunset has already moved once, from May 2025 to July 1, 2027, so a program built assuming the current rules are permanent should build in a review before that date rather than after. Companies tracking AI obligations across several states should also watch the broader fight over whether federal law can override statutes like this one — nothing currently in effect preempts Utah's law, but it's one more state statute sitting inside a legal landscape that's still being actively contested. And a Utah-ready disclosure program doesn't transfer automatically to a state with a different model — Texas's TRAIGA regulates through an intent-based prohibited-practices list rather than a disclosure duty, so a company operating in both states needs two separate compliance checklists, not one.
Frequently asked questions
- Does Utah's AI Policy Act require a company to disclose AI use in every interaction?
- No, not for most businesses. The general rule only requires disclosure when a consumer makes a clear and unambiguous request — it isn't a proactive, every-interaction obligation. Proactive, upfront disclosure only applies to regulated professionals handling a defined 'high-risk' interaction, or to mental health chatbots under the separate HB 452 statute.
- What counts as a 'high-risk' AI interaction under Utah law?
- SB 226's 2025 amendments define it as an interaction that involves collecting sensitive personal data (health, financial, or biometric information), giving a personalized recommendation or advice a consumer could reasonably rely on for a significant personal decision, or providing financial, legal, medical, or mental health advice or services. Only a regulated professional engaged in that kind of interaction owes the proactive disclosure duty.
- Is there a way to avoid enforcement risk entirely under Utah's disclosure rules?
- SB 226 built in a safe harbor that gets close. If the generative AI itself clearly and conspicuously discloses that it's non-human — an AI assistant or generative AI — at the outset of the interaction and keeps disclosing that throughout, the business isn't subject to an enforcement action over the disclosure provisions. For most consumer-facing bots, that's a one-time configuration change, not an ongoing legal project.
- Can a business argue it isn't liable because the AI made the statement, not a person?
- No. Utah Code § 13-2-12, enacted alongside SB 149, says directly that it is not a defense to a consumer-protection claim that generative AI made the statement, took the act, or was used in furtherance of the violation. Whatever duty would apply if a human employee had done it applies the same way when AI did it instead.
- Are mental health chatbots covered by the same rules as other AI tools in Utah?
- No. They're governed by a separate 2025 statute, HB 452, not by the AI Policy Act's general disclosure or high-risk-interaction rules. HB 452 has its own definition of a mental health chatbot, its own disclosure timing (at the start of the interaction, before the user can access any feature, and again whenever asked), and its own restrictions on sharing the health information a chatbot collects.
Sources & references
- Official source
- Utah SB 149 (2024), Artificial Intelligence Policy Act — enrolled bill text
- Utah SB 226 (2025), Artificial Intelligence Consumer Protection Amendments — enrolled bill text
- Mayer Brown — Utah Enacts AI-Focused Consumer Protection Bill
- Knobbe Martens — State Spotlight: Utah (federal and state AI disclosure regulation)
- Perkins Coie — New Utah AI Laws Change Disclosure Requirements and Identity Protections, Target Mental Health Chatbots
Suggested next reading
regulations us colorado
Colorado AI Act (SB 205)
regulations us