Utah Artificial Intelligence Policy Act (SB 149, as amended by SB 226 and SB 332 in 2025)
Last reviewed Sep 25, 2026.
In short
Utah's AI Policy Act, in force since 1 May 2024, was the first US state generative-AI disclosure law. As amended in 2025, a business must clearly disclose that a person is interacting with generative AI when asked, and proactively in 'high-risk' interactions — those collecting sensitive data or giving financial, legal, medical or mental-health advice. Regulated professionals must disclose up front. Using AI is no defence to a consumer-protection breach. The Act created an Office of AI Policy and a sandbox and sunsets on 1 July 2027 unless renewed.
Who it applies to
- Organisations that build or use AI systems in United States · Utah.
- Use cases in scope: chatbots, generated content.
- Size: everyone, including solo operators.
- Applies to anyone using generative AI in a consumer interaction covered by Utah consumer-protection law, with stricter rules for regulated occupations and 'high-risk' interactions.
Key dates
- Mar 13, 2024✓SB 149 signed
- May 1, 2024✓In effect — first US state generative-AI disclosure law
- May 7, 2025✓SB 226 / SB 332 amendments in effect: disclosure narrowed to on-request and 'high-risk' interactions; sunset extended
- Jul 1, 2027UpcomingAct sunsets unless renewed
What you have to do
- Programme your chatbot to state clearly that it is AI whenever a user asks whether they are talking to a human.
- Disclose AI use at the start of any high-risk interaction involving health, financial or biometric data or advice on legal, financial or medical matters.
- If you are a licensed professional, disclose generative AI use prominently before the interaction begins.
- Do not rely on 'the AI said it' as a defence: you remain liable for consumer-protection violations.
- Consider the safe harbour: clear disclosure at the outset or throughout the interaction.
Penalties
Administrative fine of up to $2,500 per violation by the Utah Division of Consumer Protection; civil penalty of up to $5,000 per violation of a court or administrative order. Generative-AI use is not a defence to other consumer-protection penalties.
Related lessons
Real cases
- Ruling2024 · CA-BCMoffatt v. Air Canada — airline liable for its chatbot's wrong answer
Decision 2024 BCCRT 149 (February 2024). Air Canada was ordered to pay C$812.02 in total: C$650.88 in damages (the fare difference) plus pre-judgment interest and tribunal fees. Small money, but the first widely reported ruling that a company answers for what its customer-facing AI says.
- Settlement2024 · US-federalFTC v. DoNotPay — the 'robot lawyer' that was never tested against real lawyers
Proposed consent order announced 25 September 2024; finalised 11 February 2025 after a 5–0 Commission vote. DoNotPay must pay $193,000 in monetary relief, stop claiming its service performs like a real lawyer without evidence, and notify everyone who subscribed between 2021 and 2023 about the settlement.
Industries where it matters
Sources
- SB 149 Artificial Intelligence Amendments (2024) — Utah Legislature ↗
- SB 226 Artificial Intelligence Consumer Protection Amendments (2025) — Utah Legislature ↗
- Chatbots in Check: Utah's Latest AI Legislation — Future of Privacy Forum ↗
Last reviewed Sep 25, 2026.