Regulation

The Utah AI Policy Act: Disclosure Duties That Land on Licensed Clinicians

Utah Code title 13 chapter 72, the Artificial Intelligence Policy Act, as amended, together with title 13 chapter 75, Artificial Intelligence Consumer Protection, and title 13 chapter 72a, Regulation of Mental Health Chatbots

Last updated

Free tool

Healthcare AI Law Checker

This is a starting map, not legal advice.

Need it signed off?

Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.

Book an evaluation call

Regulator

Utah Division of Consumer Protection, Department of Commerce, supported by the Office of Artificial Intelligence Policy

Who it applies to

  • Suppliers using generative AI to interact with an individual in connection with a consumer transaction, who must disclose if clearly and unambiguously asked
  • Individuals providing services in a regulated occupation, meaning an occupation regulated by the Utah Department of Commerce that requires a licence or state certification, which covers physicians, nurses, mental health therapists, dentists and the rest of the state licensed health professions
  • Suppliers of mental health chatbots that engage Utah users in interactive conversation similar to the confidential communications a person would have with a licensed mental health therapist
  • Not scripted tools such as guided meditations or mindfulness exercises, and not technology that only analyses input in order to connect a person with a human therapist
  • Applies to conduct affecting Utah users, with the mental health chatbot rules keyed to an individual located in the state at the time of use

Penalties

A violation of chapter 75 is a violation of Utah Code subsection 13-11-4(1) under the Utah Consumer Sales Practices Act, administered and enforced by the Division of Consumer Protection with the Attorney General acting as its counsel. The division director may impose an administrative fine of up to two thousand five hundred dollars for each violation, and a court may impose a fine of the same amount per violation, order disgorgement and direct that disgorged money be paid to an injured individual, grant an injunction, and award the division its attorney fees, court costs and investigative fees. Violating an administrative or court order carries a civil penalty of up to five thousand dollars per violation. Chapter 72a for mental health chatbots carries the same two thousand five hundred dollar administrative fine structure. None of this displaces other state or federal remedies.

Deadlines

Dates that already bind, and dates still ahead.

DateWhat happens
SB 149 took effect, creating the Artificial Intelligence Policy Act, the Office of Artificial Intelligence Policy, the Artificial Intelligence Learning Laboratory Program, and the original disclosure duty at Utah Code 13-2-12.
SB 226 took effect. It repealed 13-2-12, enacted a new chapter 75, narrowed the general disclosure duty to cases where a person asks, and created the proactive disclosure duty for regulated occupations in high risk interactions. HB 452, regulating mental health chatbots, took effect on the same day.
SB 226 and SB 332 both extended the repeal date of title 13 chapter 72, the Artificial Intelligence Policy Act, from May 1, 2025 to July 1, 2027.
Current repeal date for title 13 chapter 72. Chapters 75 and 72a were enacted without a matching sunset, but chapter 72 supplies the definitions they rely on, so the date is worth watching.

What changed in 2025

Movement by year, newest first. Where nothing in the text moved, that is recorded too.

  • 2025

    Utah rewrote its own law a year after passing it, and the rewrite went in two directions at once.

    SB 226, Artificial Intelligence Consumer Protection Amendments, took effect on May 7, 2025. It repealed section 13-2-12 and enacted a new chapter 75. The general disclosure duty was narrowed sharply: a supplier using generative AI in a consumer transaction only has to say so if the individual asks or otherwise prompts, and the prompt must be a clear and unambiguous request to determine whether the interaction is with a human or with AI. That is a much lighter obligation than the original text, which many read as requiring disclosure on demand in a far broader set of circumstances.

    At the same time, the duty on regulated occupations was made explicit and proactive, and a safe harbour was added for systems that identify themselves throughout. The statute also confirmed that it is no defence to a consumer protection violation that generative AI made the statement or was used in furtherance of it, carrying forward the core principle of the 2024 act.

    HB 452, Artificial Intelligence Amendments, took effect the same day and created chapter 72a for mental health chatbots. It bans the sale or sharing of a Utah user's individually identifiable health information and user input, restricts advertising inside the conversation, and requires a clear disclosure that the chatbot is not human.

    SB 332, Artificial Intelligence Revisions, did one thing: it extended the repeal date of chapter 72 from May 1, 2025 to July 1, 2027. SB 226 made the same change, so the extension is carried twice in the same session, which is a drafting belt and braces rather than two separate policies.

  • 2024

    SB 149 took effect on May 1, 2024, making Utah the first US state with an operative AI statute of general application. Its architecture is the reason Utah is still worth reading even though the disclosure text has changed.

    Three ideas came out of that bill. First, liability is not laundered through a model: an actor cannot avoid a consumer protection violation by pointing at the generative AI that produced the statement, and section 76-2-107 says the same for criminal offences committed with the aid of generative AI. Second, licensed professionals do not get a lighter standard because they used software. Third, the state built an institution rather than only a rule: the Office of Artificial Intelligence Policy, now at Utah Code 13-74-201, with a Learning Laboratory Program and the power to enter regulatory mitigation agreements.

    The chapter numbering moved after a 2024 special session. What SB 149 enacted as chapter 70 now sits as chapter 72 for the Policy Act and chapter 74 for the Office. Older commentary citing 13-70 is not wrong, it is just stale.

What does the Utah AI Policy Act require in 2026?

Three duties, and only one of them lands hard on a healthcare operator.

The first is the general one. Under Utah Code 13-75-103(1), a supplier using generative AI to interact with an individual in connection with a consumer transaction must disclose that the individual is interacting with generative AI and not a human, but only if the individual asks or otherwise prompts about whether AI is being used. The statute adds that the prompt has to be a clear and unambiguous request to determine whether the interaction is with a human or with AI. A vague question does not trigger the duty.

The second is the one that matters. Under 13-75-103(2), an individual providing services in a regulated occupation must prominently disclose when a person receiving services is interacting with generative AI in the provision of those regulated services, if the use constitutes a high risk artificial intelligence interaction. No prompt required. The disclosure must be given verbally at the start of a verbal interaction, and in writing before the start of a written interaction. The same subsection adds that the professional must comply with all requirements of the regulated occupation when providing services through generative AI, which closes the argument that a standard of care bends because software was in the loop.

The third is liability allocation. Section 13-75-102 says it is not a defence to violating any statute the Division of Consumer Protection enforces that generative AI made the violative statement, undertook the violative act, or was used in furtherance of the violation. Section 76-2-107 makes the parallel point for criminal offences.

Utah is therefore the mirror image of Colorado. Colorado regulates the decision. Utah regulates the conversation, and it puts the duty on the licensed individual rather than on the organisation.

When must a licensed clinician disclose that AI is involved?

When two conditions are both met: the service is being provided in a regulated occupation, and the generative AI use amounts to a high risk artificial intelligence interaction.

A regulated occupation, under 13-75-101(8), is an occupation regulated by the Utah Department of Commerce that requires an individual to obtain a licence or state certification to practise. That is the professional licensing division's territory, so it captures physicians, physician assistants, nurses, dentists, pharmacists, psychologists and mental health therapists among many others.

The trigger is deliberately individual rather than corporate. It is the person providing services who owes the disclosure. In a hospital that is a practical problem, because the person who owes the duty is rarely the person who chose the software or configured its greeting. The organisation carries the operational risk without being the named duty holder, which is an unusual and slightly awkward posture.

The timing rules are specific and easy to fail. Verbally at the start of a verbal interaction. In writing before the start of a written interaction. Not partway through, not in a footer, not on a consent form signed at the previous visit. An AI phone agent handling clinical questions has to say what it is in its opening line, and a written intake agent collecting symptom information has to say so before the exchange begins.

This is a training and configuration problem more than a legal one, which is why it belongs in staff training and in the deployment runbook rather than in a policy manual nobody reads.

What counts as a high risk artificial intelligence interaction?

Section 13-75-101(5) defines it as an interaction with generative AI that involves either of two things, plus anything the division adds by rule.

  • The collection of sensitive personal information, expressly including health data, financial data or biometric data.
  • The provision of personalised recommendations, advice or information that could reasonably be relied upon to make significant personal decisions, expressly including financial advice, legal advice, medical advice or services, and mental health advice or services.

Read both limbs against a real clinical deployment and the scope becomes obvious. Almost every patient facing agent in healthcare collects health data. That alone puts it in the first limb. Any agent that answers a question about symptoms, medication or what to do next is in the second limb as well.

The practical conclusion for Utah is unusually clean: assume every patient facing generative AI interaction in a clinical setting is high risk, and disclose. Arguing the boundary costs more than complying with it, and the definitions were written broadly enough that the argument will usually lose.

The definition of generative AI is worth noting too, because it is narrower than the marketing usage. Under 13-75-101(4) it means a system trained on data, designed to simulate human conversation through text, audio or visual communication, that generates non scripted outputs similar to those created by a human with limited or no human oversight. A rules based scheduling bot with fixed responses is not generative AI. A triage agent writing free text answers is.

How does the Utah safe harbour work, and should you use it?

Section 13-75-104 gives a straightforward escape. A person is not subject to an enforcement action for violating section 13-75-103 if their generative AI clearly and conspicuously discloses, at the outset of any interaction connected with a consumer transaction or the provision of regulated services, and throughout the interaction, that it is generative AI, is not human, or is an artificial intelligence assistant.

Note the structure. The safe harbour covers the whole of section 13-75-103, both the reactive supplier duty and the proactive regulated occupation duty. And the three alternatives are disjunctive: saying it is an artificial intelligence assistant is enough, you do not have to recite all three.

The design implication is the most useful thing in the Utah statute. Instead of building logic to decide whether a given interaction is high risk, whether the person providing services holds a licence, and whether a question counted as a clear and unambiguous prompt, you can build a persistent identity: the agent says what it is at the start and keeps saying it. A visible persistent label in a chat interface, or a name that includes the word assistant in a voice deployment, does the same job.

That approach also travels. The same persistent identification satisfies the Texas disclosure duty, sits comfortably with California's AB 3030 disclaimer rules and AB 489 naming prohibition, and does no harm anywhere else. The division may make rules specifying forms and methods of disclosure that do or do not satisfy the safe harbour, so check for those before treating any specific wording as settled.

One thing the safe harbour does not do: it does not relieve the second half of 13-75-103(2), which requires compliance with all requirements of the regulated occupation when providing services through generative AI. Standard of care is unaffected by any label.

What are Utah's rules for mental health chatbots?

HB 452 created chapter 72a, effective May 7, 2025, and it is the strictest thing Utah has written on AI.

A mental health chatbot is defined as AI technology that uses generative AI to engage a user in interactive conversation similar to the confidential communications an individual would have with a licensed mental health therapist, and that the supplier represents, or a reasonable person would believe, can provide mental health therapy or help manage or treat mental health conditions. Scripted tools such as guided meditations are excluded, as is technology that only analyses input in order to connect the person with a human therapist.

Three duties follow.

  • No sale or sharing of data. A supplier may not sell to or share with any third party a Utah user's individually identifiable health information or user input. The exceptions are narrow: information requested by a health care provider with the user's consent, information provided to the user's health plan at the user's request, and information shared with a contracted party where necessary for the chatbot to function. In that last case, the supplier and the other party must comply with the HIPAA privacy and security provisions at 45 CFR parts 160 and 164 subparts A and E as if they were a covered entity and a business associate, even though neither may actually be one.
  • Advertising restrictions. A supplier may not advertise a product or service inside the conversation without clearly identifying it as advertising and disclosing any sponsorship, business affiliation or promotional agreement. User input may not be used to decide whether to show an advertisement, what to advertise, or how to present it. Recommending that the user seek help from a licensed professional is expressly permitted.
  • Disclosure. The chatbot must clearly and conspicuously disclose that it is AI technology and not a human, before the user can access its features, at the beginning of any interaction where the user has not used it in the previous seven days, and any time the user asks.

Section 58-60-118 provides an affirmative defence for suppliers that create and maintain qualifying policies, which is a genuine incentive to write the policy properly rather than a formality.

For a behavioural health practice, the data rule is the one to check first. It is a flat prohibition, not a consent based one, and it reaches supplier conduct that a standard business associate agreement would permit. Colorado went further still in 2026 with HB 26-1195, which requires a licensed provider to be actively present during any AI therapeutic communication.

What is the Office of AI Policy and the learning lab for?

It is a regulatory sandbox with a specific and unusual instrument attached: the regulatory mitigation agreement.

The Office of Artificial Intelligence Policy, now at Utah Code 13-74-201, administers the Artificial Intelligence Learning Laboratory Program. A person who uses or wants to use an AI technology in Utah may apply. The office may grant temporary regulatory mitigation by entering into an agreement with the participant and the relevant agencies. The agreement specifies limits on scope, including the number and types of users and geographic limits, the safeguards to be implemented, and the mitigation actually granted.

Eligibility requires the applicant to demonstrate technical expertise and capability, sufficient financial resources to meet obligations during testing, potential substantial consumer benefits that may outweigh identified risks, an effective plan to monitor and minimise those risks, and a scale, scope and duration of testing appropriately limited by risk assessment.

Three constraints keep expectations realistic. A participant remains subject to every legal and regulatory requirement not expressly waived or modified by the agreement. The office may remove a participant at any time and for any reason, and participation is not a property right. And participation is not an endorsement or approval by the state.

Who should actually use this? Not most providers. The mechanism suits a developer testing something that current professional licensing rules make awkward, or a health system piloting a novel model where the relevant Utah agency's position is genuinely unclear. For a standard scribe or scheduling deployment it is overhead with no return, because nothing about those deployments needs a rule waived. The office's existence is still useful in a second way: it means Utah has a named place to ask a question, which is more than most states offer.

How does Utah compare with the other state AI laws?

Utah is the lightest of the four in what it demands and the broadest in who it reaches, because the trigger is a conversation rather than a decision.

QuestionUtahTexasCaliforniaColorado
What triggers a dutyHigh risk generative AI interaction in a regulated occupationAI system used in relation to health care service or treatmentGenerative AI patient communication about clinical informationCovered ADMT materially influencing a consequential decision
Who owes itThe individual providing regulated servicesThe provider of the service or treatmentThe facility, clinic or practiceThe deployer, with HIPAA entities largely exempt
TimingVerbally at the start, in writing before a written interactionNo later than the date treatment is first providedBy medium: start, start and end, or throughoutBefore the decision, plus 30 days after an adverse outcome
Human review dutyNoNoYes, for payer medical necessity denialsYes, on request after an adverse outcome
Safe harbourPersistent AI identificationNIST AI RMF substantial complianceLicensed provider review of the communicationNone equivalent
EnforcerDivision of Consumer ProtectionAttorney General and licensing agenciesLicensing boards, DMHC, CDI, CPPAAttorney General only

The row that pays for itself is the safe harbour row. Utah's persistent identification and Texas's timing rule can both be satisfied by the same design decision. Add California's disclaimer placement rules and you have one disclosure specification that works in all four states. Building it four times is a choice, not a requirement.

If you deploy agents in Utah, do these things

Six items. Utah is the cheapest of the four states to comply with properly, and the easiest to fail through inattention because the duty attaches to individuals rather than to the organisation.

  1. Turn on persistent identification and take the safe harbour. Have the agent state at the outset and throughout that it is an artificial intelligence assistant. This removes the need to adjudicate whether any given interaction is high risk, and it satisfies Texas at the same time.
  2. Fix the opening line, not the footer. Verbal disclosure at the start of a verbal interaction. Written disclosure before a written interaction begins. A disclosure that arrives after the first exchange has already failed.
  3. Identify which of your agents operate in a regulated occupation context. If a state licensed professional's service is being delivered through the agent, the proactive duty applies and the licensee is the duty holder. Tell the licensees that, in writing.
  4. Assume high risk. Collecting health data alone satisfies the first limb of the definition. Do not build a classifier to decide when to disclose.
  5. If you offer anything resembling therapy, read chapter 72a properly. The prohibition on selling or sharing user input is absolute apart from three narrow exceptions, and the functionality exception drags a HIPAA equivalent standard onto parties who may not otherwise be covered.
  6. Check the current text before you rely on it. Chapter 72 carries a repeal date of July 1, 2027 as of August 2026, and Utah has amended this area in every session since 2024. Confirm at le.utah.gov rather than trusting any summary, including this one.

Utah rewards operators who make one clean design decision and document it. It punishes organisations that treat disclosure as a policy statement rather than a configuration, because the failure mode is a licensee who never knew the duty was theirs. Getting the disclosure specification, the licensee briefing and the evidence trail built once and applied across Utah, Texas, California and Colorado is what our AI governance and compliance engagement is for, layered on the federal baseline described in HIPAA and AI.

Official sources

Primary documents from the issuing authority. Where a summary and the source disagree, the source is right.

Questions we get asked

Does Utah require you to disclose that you are using AI?

It depends who you are. An ordinary supplier in a consumer transaction only has to disclose if the individual clearly and unambiguously asks. A person providing services in a regulated occupation must disclose proactively where the use is a high risk artificial intelligence interaction, verbally at the start of a verbal interaction and in writing before a written one.

Are doctors and nurses covered by the Utah AI Policy Act?

Yes. A regulated occupation is one regulated by the Utah Department of Commerce that requires a licence or state certification, which covers the professions licensed through the Division of Occupational and Professional Licensing. The duty attaches to the individual providing services, not only to the employing organisation, which is why licensees need to be told about it directly.

Is a patient facing AI agent a high risk interaction in Utah?

Almost always. The definition covers interactions involving the collection of sensitive personal information including health data, and separately covers personalised recommendations or advice that could reasonably be relied upon for significant personal decisions, naming medical and mental health advice. Most clinical agents satisfy at least one limb, so the safest operating assumption is that disclosure is required.

How does the Utah AI disclosure safe harbour work?

Under section 13-75-104, you are not subject to enforcement for a disclosure violation if the generative AI clearly and conspicuously discloses at the outset and throughout the interaction that it is generative AI, is not human, or is an artificial intelligence assistant. Any one of the three is enough. It does not relieve the separate duty to meet the professional requirements of the occupation.

What are the penalties under Utah's AI law?

A violation is a violation of the Utah Consumer Sales Practices Act, enforced by the Division of Consumer Protection. The division director may impose an administrative fine of up to two thousand five hundred dollars per violation, and a court may impose the same amount per violation plus disgorgement, injunctive relief and the division's fees. Violating an order carries up to five thousand dollars per violation.

Can an AI chatbot provide mental health therapy in Utah?

Chapter 72a does not ban mental health chatbots, but it regulates them tightly and section 58-60-118 makes clear that a chatbot is not recognised as a licensed mental health therapist. Suppliers may not sell or share a Utah user's health information or user input outside three narrow exceptions, may not target advertising using user input, and must disclose the chatbot's artificial nature before access and at the start of interactions after a seven day gap.

Should we apply to the Utah AI learning lab?

Only if an existing Utah rule genuinely blocks something you want to test. Regulatory mitigation agreements waive or modify specified requirements for a limited scope, but the participant stays subject to everything not expressly waived, can be removed at any time, and gains no state endorsement. For standard documentation, scheduling or intake deployments there is nothing to waive.