AAI Compliance Atlas
FrameworksState lawsIndustriesToolsNews
GuidesMap my obligations →
AAI Compliance Atlas

Structured, continuously verified reference for US AI compliance — federal frameworks, state laws, and the obligations that connect them.

Atlas

  • Frameworks
  • State laws
  • Industries
  • By role
  • Comparisons

Tools

  • Compliance Checker
  • Penalty Calculator
  • Impact Assessment
  • Vendor Questionnaire

Resources

  • Guides
  • News
  • Blog
  • Methodology

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 AI Compliance Atlas. Informational only — not legal advice. Consult qualified counsel before making compliance decisions.Verified Jul 28, 2026
  1. Home/
  2. Utah/
  3. Utah Artificial Intelligence Policy Act
In effectSB 149 (2024); amended by SB 226, HB 452, SB 332 (2025) and HB 320 (2026)Utah

Utah Artificial Intelligence Policy Act

Compliance reference — obligations, penalties, applicability, and primary sources.

Last verified July 27, 2026

Effective
May 7, 2025
Max penalty
$5K
Applies to
deployer + vendor
Status
In effect

Summary

The Utah Artificial Intelligence Policy Act (UAIPA), enacted as SB 149 in March 2024, now anchors three operative Utah AI compliance layers: Chapter 77 for generative-AI consumer disclosures and enforcement, Chapter 72 for the Office of Artificial Intelligence Policy and AI Learning Laboratory, and Chapter 72a for mental-health chatbot protections. The current private-sector disclosure duties took effect May 7, 2025 after SB 226 and HB 452. Source: Utah Code Chapter 77, retrieved 2026-07-27.

What changed after SB 149

SB 149 originally placed generative-AI liability and disclosure in Utah Code § 13-2-12. SB 226 repealed that old section and enacted the current disclosure framework, which Utah now publishes as Utah Code Title 13, Chapter 77 — Generative Artificial Intelligence — Consumer Disclosures and Enforcement. Compliance records should cite Chapter 77 rather than the repealed § 13-2-12 section for the current GenAI disclosure rule.

The Act also created the Office of Artificial Intelligence Policy (Utah Code § 13-72-201) and the AI Learning Laboratory Program (§ 13-72-301). HB 320 updated Chapter 72 effective May 6, 2026: the laboratory now supports both regulatory mitigation agreements and joint interpretation agreements, and the current eligibility test addresses technical capability, financial resources, expected consumer benefit, risk monitoring, and a limited testing scale, scope, and duration. Sources: HB 320 enrolled text and Utah Code § 13-72-402, retrieved 2026-07-27.

Utah AI disclosure rules in 2026

Chapter 77 uses two disclosure triggers:

  • Consumer transactions: a supplier using generative AI to interact with an individual in connection with a consumer transaction must disclose that the individual is interacting with generative AI and not a human if the individual clearly and unambiguously asks or prompts about whether AI is being used. Source: Utah Code § 13-77-103, retrieved 2026-07-27.
  • Regulated occupations: an individual providing services in a regulated occupation must prominently disclose generative-AI use when the service interaction is a high-risk artificial intelligence interaction, and must provide the disclosure verbally at the start of a verbal interaction or in writing before a written interaction.

A high-risk AI interaction includes generative-AI interactions involving sensitive personal information — health, financial, or biometric data — and personalized recommendations, advice, or information that could reasonably be relied upon for significant personal decisions, including financial, legal, medical, or mental-health advice. Source: Utah Code Chapter 77, retrieved 2026-07-27.

Safe harbor and enforcement

Chapter 77 creates a practical safe harbor: a person is not subject to an enforcement action for violating § 13-77-103 if the generative AI clearly and conspicuously discloses at the outset and throughout the interaction that it is generative AI, is not human, or is an artificial intelligence assistant. Source: Utah Code § 13-77-104, retrieved 2026-07-27.

The Division of Consumer Protection administers Chapter 77. The statute authorizes administrative fines up to $2,500 for each violation and civil penalties up to $5,000 for each violation of an administrative or court order. Chapter 77 also states that generative AI is not a defense to a consumer-protection violation if the AI made the violative statement, undertook the violative act, or was used in furtherance of the violation.

Mental health chatbot rules under Chapter 72a

HB 452, effective May 7, 2025, created Utah Code Title 13, Chapter 72a (Artificial Intelligence Applications Relating to Mental Health) for mental health chatbots offered to any "Utah user." A mental health chatbot is AI technology designed to engage in interactive conversations similar to confidential communications with a licensed mental health therapist; scripted outputs and human-therapist referral services are excluded.

Suppliers of in-scope chatbots must:

  • Disclose AI status at three trigger points (Utah Code § 13-72a-203): before any chatbot features are accessed; at the beginning of any interaction after a seven-day gap; and any time a user prompts the chatbot about whether AI is being used.
  • Identify advertisements clearly and conspicuously, including any sponsorship, business affiliation, or third-party agreement (§ 13-72a-202); user input may not be used to target advertisements.
  • Not sell or share individually identifiable health information or the user's input with any third party (§ 13-72a-201).

HB 452 establishes an affirmative defense for suppliers that maintain a written policy meeting statutory requirements, file the policy with the Utah Division of Consumer Protection, and document training data, user practices, and safety efforts. There is no private right of action. Source: Utah Code Chapter 72a, retrieved 2026-07-27.

2027 future-effective AI chapters

HB 276 enacted two additional, future-effective chapters: Chapter 72b, the Digital Voyeurism Prevention Act, and Chapter 72c, the Digital Content Provenance Standards Act. The current Utah Code index marks both chapters effective January 1, 2027, so they are implementation watch items rather than duties in force on July 27, 2026. Sources: HB 276 enrolled text and the Utah Code Title 13 index, retrieved 2026-07-27.

2026 companion chatbot watch item

Utah considered a broader HB 438 Artificial Intelligence Amendments bill in the 2026 General Session that would have created an AI companion chatbot safety act. The official Utah Legislature bill listing shows HB 438 ended as House/filed rather than Governor-signed, so it remains a proposal rather than a current compliance duty. Source: Utah Legislature 2026 bill listing, retrieved 2026-07-27.

What Utah AI compliance actually requires now

Practical Utah AI compliance after May 7, 2025 looks like:

  • Map every consumer-facing GenAI deployment against Chapter 77: consumer-transaction chatbot, regulated-occupation service, high-risk interaction, or out of scope.
  • Implement the safe harbor wherever feasible: have the AI itself disclose at the outset and throughout the interaction that it is AI and not human.
  • Run a separate Chapter 72a checklist if any product is a mental health chatbot — three disclosure trigger points, advertising-disclosure controls, no third-party sale or sharing of input or health information, and a filed affirmative-defense policy.
  • Track the AI Learning Laboratory pathway (Utah Office of Artificial Intelligence Policy) for novel deployments where a mitigation agreement or joint interpretation agreement may fit the deployment.
  • Keep future-effective and pending controls separate from current duties: HB 276's Chapters 72b and 72c start January 1, 2027, while HB 438 did not pass in the 2026 General Session.
  • Plan for the July 1, 2027 sunset. Compliance programs should not assume permanence; SB 332's sunset extension may or may not be renewed in the 2027 session.

Compliance programs typically pair these Utah-specific controls with the NIST AI Risk Management Framework (Map and Manage functions are most directly relevant) and ISO/IEC 42001 clause 6.1.4 risk treatment, since Utah's primary control vector — disclosure plus safe harbor — is procedural rather than substantive.

Utah Artificial Intelligence Policy Act by compliance topic

Focused breakdowns of each part of the law — obligations, scope, penalties, and disclosures — with the primary source behind every requirement.

  • Utah Artificial Intelligence Policy Act compliance checklist

    A step-by-step checklist of the obligations to satisfy, each tied to the statutory section behind it.

  • Who must comply with Utah Artificial Intelligence Policy Act

    The organizations, roles, and thresholds that bring an AI system within scope of the law.

  • Utah Artificial Intelligence Policy Act penalties and enforcement

    Civil penalty amounts, how violations are counted, and the enforcement path under the statute.

  • Utah Artificial Intelligence Policy Act disclosure requirements

    The notices and disclosures the law mandates, and which consumers, employees, or downstream parties must receive them.

Industry implementation routes

  • Utah AI Policy Act for financial services

    Financial-services implementation route for the Utah high-risk generative-AI disclosure rules.

Key obligations

Specific compliance requirements derived from the primary source. Each item links to the relevant statutory section where applicable.

  • DisclosureRole: deployerUtah Code § 13-77-103

    A supplier using generative AI in a consumer transaction must disclose that the individual is interacting with generative AI and not a human when the individual makes a clear and unambiguous request about whether AI is being used; regulated-occupation providers must prominently disclose GenAI use for high-risk AI interactions, verbally at the start of verbal interactions or in writing before written interactions.

    Deadlineon_clear_request_or_before_regulated_service_interaction

  • GovernanceRole: deployerUtah Code § 13-77-102

    Maintain accountability for consumer-protection compliance when generative AI makes a violative statement, undertakes a violative act, or is used in furtherance of a violation; Chapter 77 states that generative AI is not a defense to statutes administered and enforced by the Division of Consumer Protection.

    Deadlineongoing

  • Data handlingRole: vendorUtah Code § 13-72a-201

    Mental health chatbot suppliers may not sell or share individually identifiable health information or a Utah user's chatbot input with a third party, and must keep Chapter 72a privacy controls separate from the general Chapter 77 consumer-transaction disclosure rule.

    Deadlineongoing

  • DisclosureRole: vendorUtah Code § 13-72a-203

    Mental health chatbot suppliers must clearly and conspicuously disclose that the chatbot is artificial intelligence technology and not human before features are accessed, at the beginning of an interaction after a seven-day gap, and whenever a Utah user asks or prompts about whether AI is being used.

    Deadlinebefore_access_after_7_day_gap_or_on_prompt

Related comparisons

Use the side-by-side comparisons to see how this law interacts with adjacent US AI laws and governance frameworks.

  • Utah AI Policy Act vs California SB 942

    Compare source-backed AI law records, applicability, penalties, and compliance scope.

Build a compliance program around these obligations

A single law is one input to a broader program. These guides show how to assign accountability, map every obligation to a control, and split developer-versus-deployer duties across the systems a team operates.

  • AI governance: building an AI compliance program

    The operating model — owners, committee, decision rights, lifecycle gates — that turns a law into an accountable, auditable program anchored to the NIST AI RMF GOVERN function.

  • AI compliance framework: the regulatory control map

    How to map each AI system to the laws it triggers, the controls that satisfy them, and the evidence that proves the controls operate.

  • Deployer vs developer obligations

    Which duties attach to building an AI system versus putting one into use — the split most state AI laws turn on.

Operationalize Utah Artificial Intelligence Policy Act compliance with OneTrust

partner link

Map obligations to controls, run impact assessments, and maintain audit-ready evidence in a single platform used by hundreds of regulated enterprises.

See OneTrust AI Governance →

Frequently asked questions

When does Utah Artificial Intelligence Policy Act take effect?

Utah Artificial Intelligence Policy Act has been effective since May 7, 2025.

What is the maximum penalty under Utah Artificial Intelligence Policy Act?

Up to $5K per violation under Utah Artificial Intelligence Policy Act.

Who must comply with Utah Artificial Intelligence Policy Act?

Utah Artificial Intelligence Policy Act applies to deployer, vendor of AI systems within its jurisdictional scope.

Sources

Every fact above is sourced from the official primary source. Independent verification recommended before acting on the information.

  • Officialle.utah.gov — Utah Code Title 13, Chapters 77, 72, and 72a
  • le.utah.gov
  • le.utah.gov
  • le.utah.gov
  • le.utah.gov
  • le.utah.gov
  • le.utah.gov
  • le.utah.gov
  • le.utah.gov
  • le.utah.gov
  • le.utah.gov
  • commerce.utah.gov
  • dcp.utah.gov

Last reviewed July 27, 2026. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.

Legal disclaimer

This content is informational only and does not constitute legal advice. Laws change frequently and vary by jurisdiction. Consult qualified legal counsel before making compliance decisions. Information accuracy not guaranteed as of any specific date.

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.