Skip to content

Utah's AI Policy Act: the Generative AI Disclosure Duty

9 min read · updated August 11, 2026

Utah was the first American state to require a business to say it is using generative AI. Then in 2025 it narrowed that duty substantially, and most summaries still describe the 2024 version.

What the Act is, and what it is not

Senate Bill 149, the Artificial Intelligence Policy Act, was signed in March 2024 and took effect on 1 May 2024. It is codified at Utah Code Title 13, Chapter 72, and it does two unrelated things: it attaches disclosure and responsibility rules to the use of generative AI in consumer transactions, and it creates an Office of Artificial Intelligence Policy with power to enter regulatory mitigation agreements under a learning laboratory programme.

It is not a risk-classification statute. There is no equivalent of the EU AI Act’s risk tiers , no impact assessment, no developer/deployer split, and nothing about training data. The Act’s definition of generative artificial intelligence in section 13-72-101 is behavioural: a system trained on data, that interacts with a person using text, audio or visual communication, and that generates non-scripted outputs similar to human-generated outputs with limited or no human oversight. A scripted decision-tree chatbot is outside it. The current code text is at the Utah Legislature.

Not legal advice. The chapter has been amended twice since enactment, and the version that binds you is the one in force on the date of your conduct — check the code rather than a description of the original bill, including this one.

The consumer disclosure, as narrowed in 2025

As enacted in 2024, the general rule was that a person who uses generative AI to interact with an individual in connection with a consumer transaction must disclose that the individual is interacting with generative AI and not a human, if the individual asks or prompts. It was already a reactive duty — trigger on request, not proactive — but it applied across consumer transactions generally.

Senate Bill 226, enacted in the 2025 session and effective in May 2025, narrowed it in two ways that matter. The duty now attaches to a high-risk artificial intelligence interaction, and the disclosure is owed when the individual asks whether they are dealing with a human. High-risk interactions are defined by reference to the nature of the exchange: collection of sensitive personal information, and the provision of personalised recommendations or advice concerning finance, legal matters, medicine, or mental health. Routine commerce — a support chatbot on an order status, a booking assistant — falls outside the narrowed definition.

The practical consequence is that a Utah-facing product needs to answer two design questions rather than one: does this interaction fall into a high-risk category, and if a user asks “am I talking to a person”, does the system reliably answer honestly? The second is harder than it sounds — a model instructed to be maximally conversational will often deflect the question, and a deflection is not a disclosure. Compare California SB 1001, which is proactive rather than reactive in its own narrower domain, and the EU AI Act’s Article 50 chatbot duty, which requires disclosure at the point of interaction regardless of whether anyone asks.

The stricter rule for regulated occupations

A separate and more demanding rule applies to regulated occupations — those requiring a licence or state certification, such as medicine, law, accountancy, engineering, therapy and the trades. Where generative AI is used in the provision of regulated services, the disclosure is proactive rather than on request, and the statute sets the moment: prominently, at the start of an oral exchange or conversation, and before a written exchange begins.

This is the part of the Utah Act that most resembles California AB 3030, and the comparison is instructive. California targets one sector and specifies both a disclaimer and a human-contact route, with an exemption where a licensed provider reviews the output. Utah targets all licensed occupations, requires disclosure only, and has no review-based exemption in the same form. A telehealth service operating in both states is subject to both, and the strictest-element approach means disclosing proactively and providing the human route.

No blaming the model

The Act’s other substantive provision is the one that has the most doctrinal interest. It establishes that where a person’s use of generative AI would otherwise violate Utah consumer protection law, the fact that the statement or act was produced by generative AI is not a defence. As originally drafted this was flat; the 2025 amendment softened it, and the current text should be read directly rather than assumed.

The point of the provision is to foreclose an argument before it gets established anywhere: that a deceptive statement generated by a model was not the business’s statement. Utah answered that question by statute in 2024, and no American court needed to reach it. The same conclusion has since been reached by other routes elsewhere — most visibly in the British Columbia Civil Resolution Tribunal’s decision on an airline chatbot, discussed in that ruling’s page — which is worth reading precisely because it arrived at a similar place with no AI statute at all.

Enforcement, the Office, and the sunset

Enforcement sits with the Utah Division of Consumer Protection, which may impose administrative fines of up to $2,500 per violation and seek court relief including injunctions, disgorgement and civil penalties. The Attorney General may bring an action for the same. There is no private right of action, which places Utah with California and Texas rather than with Illinois.

The Office of Artificial Intelligence Policy is the part of the Act that has no analogue elsewhere. It administers a learning laboratory under which a participant can enter a regulatory mitigation agreement: a negotiated set of restrictions and reduced penalties for a defined period, in exchange for participating and sharing information. It is a regulatory sandbox in substance, and it is the closest American equivalent to the EU AI Act’s sandbox provisions.

Finally, the chapter carries a sunset date, which Senate Bill 332 in the 2025 session extended. A sunset means the whole chapter expires unless the legislature acts again, so the relevant date is both a compliance fact and a signal about how settled Utah considers the question. Check the current repeal date in the Utah Code before treating any of this as durable.