Utah’s AI Policy Act: the disclosure duty that turns on a question
Utah moved first. In March 2024 it became the first US state to enact a consumer-protection statute written specifically for generative AI: the Artificial Intelligence Policy Act (SB 149), in effect since May 1, 2024. The Act imposed disclosure duties on businesses using generative AI with consumers, and closed off the most tempting defense: liability under Utah’s consumer-protection statutes cannot be escaped on the ground that the offending statement came from an AI rather than an employee.
A year later, the legislature reshaped the law rather than letting it lapse. SB 226 narrowed the general disclosure duty to a single, precise trigger: outside high-risk contexts, a supplier’s generative AI must disclose that it is not human when a person clearly and unambiguously asks. SB 332 extended the statute’s sunset to July 1, 2027, and a third bill, HB 452, created a separate regime for mental-health chatbots. What remains is a law whose central mechanism is a question — and it is, almost word for word, the control question DisclosureProof’s scanner puts to every chatbot it examines: “Are you an AI?” Running the scan is the Utah test, performed by an outside visitor and preserved as evidence.
Who must disclose, and when
The amended Act sorts interactions into tiers, with one neighbouring statute alongside:
| Interaction | Duty | Trigger |
|---|---|---|
| Generative AI interacting with a consumer — the general case | Disclose that the person is not interacting with a human | Only when the person clearly and unambiguously asks whether they are dealing with an AI |
| High-risk interaction: the system collects sensitive personal information and gives personalized advice a person could reasonably rely on for significant financial, legal, medical, or mental-health decisions | Proactive disclosure | Without waiting to be asked |
| Regulated occupations — work requiring state licensure or certification | Prominent disclosure | Proactively: verbally at the start of a spoken conversation, or in writing before a written exchange |
| Mental-health chatbots | Separate regime under HB 452 | Advertising and data-sharing restrictions, with documented safeguards available as an affirmative defense |
The tier boundaries — what counts as high-risk, which occupations are regulated — are statutory classifications about your facts. The table describes the triggers, not a finding about any particular business.
SB 226 also tightened what counts as a covered system — technology designed to simulate human conversation, which keeps routine confirmations and reminders outside the Act — and added an enforcement safe harbor: a supplier that clearly and conspicuously discloses the AI at the outset of the interaction and throughout it is protected on the general duty. Utah, in other words, rewards exactly the behavior that never needs the trigger: disclosing before anyone asks.
The Utah test is a question — the scan asks it
Most disclosure rules are tested by inspection; Utah’s general duty is tested by conversation. What matters is what the bot says at the moment a real person asks whether it is human — and that is precisely what an external scan can document. DisclosureProof opens your homepage the way a first-time visitor would — no login, no special access — opens the chat widget, and asks the control question. It also samples the metadata of published media and documents the AI labels a visitor can see. Every finding is recorded as detected, not detected, or FLAGGED, and sealed with screenshots and a hash manifest.
Two honest limits keep that record useful. First, not detected means the scanner could not observe a disclosure from outside; it is not a verdict that any law was violated. Second, no external scanner can tell whether a piece of published content was truly AI-generated — that question is handled through the publisher’s own declaration and attestation, not statistical detection. The report documents what a visitor could see on a given day; it certifies nothing, which is why we never say “compliant”. One distinction we keep explicit: a sealed record’s integrity — that the screenshots and manifest have not changed since sealing — can be independently re-checked by anyone at /verify/; its authenticity — that DisclosureProof sealed it — rests on an HMAC signature that only we can verify.
If your chat also greets EU visitors, Article 50 does not wait to be asked
Utah’s general trigger is reactive; the EU’s is not. Under Article 50 of the EU AI Act (Regulation (EU) 2024/1689), people interacting with an AI system must be informed at the latest at the first interaction, in a clear and distinguishable manner (Art. 50(5)) — and the European Commission’s guidelines of July 20, 2026 say a terms-and-conditions mention, a bot name, or a robot icon alone is normally not enough. These obligations have applied since August 2, 2026, with no general grace period. The only deferral is narrow: the Art. 50(2) machine-readable marking duty for generative systems placed on the market before August 2, 2026 applies from December 2, 2026. The Digital Omnibus (Regulation (EU) 2026/1744, in force July 27, 2026) delayed the high-risk regime and left Article 50 untouched. Breaches of Article 50 carry fines under Art. 99(4)(g) of up to €15 million or 3% of total worldwide annual turnover, whichever is higher — for SMEs and startups, the lower of the two (Art. 99(6)).
The upshot for any US business with EU traffic: a chatbot that answers honestly when asked satisfies Utah’s general trigger, yet still falls short of Article 50 if it stays silent until asked. Utah’s safe-harbor posture — disclose at the outset and throughout — is the posture Article 50(5) expects anyway, and the sensible default for a site with visitors on both sides of the Atlantic.
Enforcement in Utah
The Act is administered and enforced by the Utah Division of Consumer Protection, which can impose administrative fines of up to $2,500 per violation and go to court for injunctions, disgorgement, and other relief; violating an administrative or court order carries up to $5,000 per violation. There is no private right of action. The figures are modest next to the EU’s turnover-linked ceilings, but the liability rule is not: because a business cannot blame the tool, the duty cannot be outsourced to a chatbot vendor’s default settings.
What to check this week
- Ask your own chatbot the question. Private window, first-time visitor, chat open: “Are you an AI?” Does it answer plainly that it is — or does it deflect, roleplay, or claim to be a person?
- Map your high-risk flows. Anywhere the system collects sensitive personal information and gives advice a person could rely on for significant financial, legal, medical, or mental-health decisions, disclosure must be proactive, not reactive.
- Check licensed-occupation use. If generative AI communicates in work that requires state licensure or certification, the disclosure must be prominent and come first — spoken at the start, or written before the exchange.
- Consider disclosing at the outset and throughout. That is Utah’s safe harbor and, at the same time, the posture Article 50(5) expects from any chat that EU visitors use.
- Keep dated evidence. What your chatbot answered on a given day can only be shown later with dated records. A sealed scan preserves the answer with screenshots, timestamps, and a hash manifest.
Whether a specific interaction is high-risk, and whether a given occupation counts as regulated, are classification questions about your facts — they belong in qualified counsel.
Common questions
When does a chatbot have to disclose that it is AI under Utah law?
Since the 2025 amendments (SB 226, effective May 7, 2025), the general duty is triggered by the user: when a person clearly and unambiguously asks whether they are interacting with an AI, the supplier’s generative AI must disclose that it is not human. In high-risk interactions — sensitive personal information plus personalized advice a person could reasonably rely on for significant financial, legal, medical, or mental-health decisions — disclosure must be proactive, and members of state-licensed occupations must disclose prominently rather than waiting to be asked.
Is the Utah AI Policy Act still in force in 2026?
Yes. SB 149 took effect on May 1, 2024, and SB 332 (2025) extended the statute’s sunset to July 1, 2027. The disclosure duties, as amended by SB 226, apply today and are administered by the Utah Division of Consumer Protection.
What are the penalties for violating the Utah AI Policy Act?
The Utah Division of Consumer Protection can impose administrative fines of up to $2,500 per violation and seek injunctions, disgorgement, and other relief in court; violating an administrative or court order can cost up to $5,000 per violation. There is no private right of action. A business also cannot avoid liability by blaming the AI for the violating statement.
How does Utah’s rule differ from the EU AI Act’s Article 50?
Utah’s general duty waits for the user: outside high-risk and licensed-occupation contexts, the chatbot must disclose only when clearly asked. Article 50 of Regulation (EU) 2024/1689 does not wait — people must be informed at the latest at the first interaction, in a clear and distinguishable manner, and the obligation has applied since August 2, 2026. A bot that answers honestly when asked can therefore satisfy Utah’s trigger and still fall short of Article 50 for its EU visitors.
Can a DisclosureProof scan certify that my chatbot complies with Utah law?
No — and it never claims to. The scan performs the Utah question the way a first-time visitor would, records what the chatbot answered as detected, not detected, or FLAGGED, and seals the evidence with screenshots and a hash manifest whose integrity anyone can check at /verify/. “Not detected” is a finding about what was observable from outside, not a violation verdict — and whether a specific interaction is high-risk, or an occupation regulated, belongs in qualified counsel.
Sources and further reading
- Hunton: Utah’s AI Policy Act Now Effective (the original SB 149 duties, enforcement, and penalty figures)
- Davis Polk: Utah scales back reach of generative AI consumer protection law (the SB 226 amendments, high-risk definition, and safe harbor)
- Future of Privacy Forum: Chatbots in Check — Utah’s latest AI legislation (SB 226, SB 332, and the HB 452 mental-health-chatbot regime)
This page summarises the rules for orientation. It is not legal advice; the statute and the analyses linked above are the authority. Where your situation is non-obvious — the tier boundaries especially — involve qualified counsel.
What does your chatbot say when asked?
The scan visits your homepage like a first-time visitor, asks your chatbot the Utah question, samples published media metadata, documents the labels a visitor can see, and seals the evidence — screenshots, timestamps, hash manifest. Free for your homepage, no registration. The report is in English.
Run the free scan