Utah AI Legislation in 2026
Utah had a record AI policy session in 2026, passing 9 AI bills covering schools, deepfakes, health insurance, age verification, and digital content provenance. All 9 bills were sent to the governor.
The Utah Picture
Utah occupies a genuinely distinctive position in the American AI policy landscape, and I would frame it to any executive as the regulatory equivalent of a first mover that chose pragmatism over prohibition. With SB 149 in 2024, Utah became the first US state to enact a broad statute governing private-sector generative AI, and it did so by building institutions rather than simply writing rules. The Office of Artificial Intelligence Policy and the companion AI Learning Laboratory Program created the country's first state-run AI regulatory sandbox. That matters because the sandbox lets companies test AI products under negotiated regulatory mitigation, trading transparency and cooperation with the state for relief from the full weight of enforcement. For builders, Utah is less a compliance minefield and more a structured on-ramp, provided you engage with the Office proactively.
The throughline across every Utah measure is disclosure rather than design mandates or algorithmic auditing. Utah has deliberately avoided the heavier risk-classification model seen in Colorado or the EU. Instead it asks a narrower question: does the consumer know they are dealing with a machine. The 2025 amendments sharpened this focus considerably. SB 226 pulled back the original blanket disclosure duty so that, for ordinary interactions, the obligation triggers only when a consumer expressly asks, while preserving a proactive duty for high-risk contexts involving health, financial, biometric, or advisory interactions. It also added a clean safe harbor: if your AI announces itself as non-human up front and throughout, you are insulated from disclosure-based enforcement. SB 332 then extended the framework's sunset to July 1, 2027.
The most instructive development for any business is how Utah layered sector-specific and harm-specific rules on top of the general regime. HB 452 is the country's most concrete mental health chatbot law, imposing pre-engagement and recurring disclosure, a hard prohibition on selling user health inputs, advertising limits, and an affirmative defense available only to operators who file a compliant policy with the Division of Consumer Protection. SB 271 modernized the right of publicity for the synthetic-media era by sweeping AI-cloned voice and likeness into protected personal identity. In 2026, HB 276 pushed Utah into content provenance and deepfake territory with the Digital Content Provenance Standards Act and the Digital Voyeurism Prevention Act, effective January 1, 2027, and HB 320 retooled the Office and sandbox.
My bottom line for builders and businesses operating in or serving Utah residents is fourfold. First, implement clear and conspicuous AI self-identification at the start of any consumer interaction to capture the SB 226 safe harbor, because it is the cheapest reliable protection available. Second, treat health, financial, legal, and biometric interactions as high-risk and disclose proactively without waiting to be asked. Third, if you operate anything resembling a mental health or therapeutic chatbot, build to HB 452 now, including the data-sale prohibition and the filed-policy affirmative defense. Fourth, prepare engineering roadmaps for content provenance and metadata obligations ahead of the January 1, 2027 HB 276 deadline, and consider the Learning Lab sandbox as a strategic channel for novel products.
Tracked Utah AI Bills
Artificial Intelligence Policy Act
Signed March 13, 2024, effective May 1, 2024. Created the first state-level Office of AI Policy and a regulatory sandbox, and set consumer disclosure duties for generative AI, with a stricter proactive standard for regulated professions.
Key Provisions
- Office of Artificial Intelligence Policy, first in the US
- AI Learning Laboratory regulatory sandbox
- Generative AI disclosure on request, proactive for licensed professions
- No AI defense to consumer-protection liability
AI Consumer Protection Amendments
Enacted 2025, effective May 7, 2025. Narrowed the general disclosure duty to trigger on request, kept a proactive duty for high-risk interactions, and added a safe harbor for clear up-front AI disclosure.
Key Provisions
- Disclosure on request for ordinary interactions
- Proactive disclosure for high-risk interactions
- Safe harbor for clear and conspicuous AI self-identification
Mental Health Chatbot Law
Signed March 25, 2025, effective May 7, 2025. Regulates AI mental health chatbots with disclosure duties, a prohibition on selling user health inputs, advertising limits, and a filed-policy affirmative defense.
Key Provisions
- Disclosure before engagement and after seven days logged out
- Prohibition on selling or sharing user health information
- Affirmative defense conditioned on a filed compliance policy
Unauthorized AI Impersonation Amendments
Signed March 27, 2025. Expanded personal identity to include AI-cloned voice and audiovisual likeness and barred unauthorized use implying endorsement, with First Amendment carveouts.
Key Provisions
- Protects AI-cloned voice and audiovisual likeness
- Bars unauthorized commercial use implying endorsement
- Carveouts for newsworthiness, art, and parody
Digital Content Provenance and Voyeurism Prevention
Signed March 24, 2026, effective January 1, 2027. Creates the Digital Content Provenance Standards Act and the Digital Voyeurism Prevention Act, requiring provenance data and barring nonconsensual synthetic intimate imagery.
Key Provisions
- Provenance embedding by platforms, devices, and AI providers
- Prohibition on nonconsensual counterfeit intimate imagery
- Metadata storage and retention standards
Download The AI Law Brief of All 50 States
A formatted PDF covering every tracked AI bill across all 50 states, with status, effective dates, and key provisions. Useful for compliance teams and board packs.
* You will also be subscribed to my newsletter.
Brief sent. Check your inbox.