Learn

The Utah AI Policy Act: disclosure duties and the safe harbor

Utah Artificial Intelligence Policy Act, Utah Code § 13-2-12 (SB 149, as amended May 2025)

Updated July 20, 2026

Utah's Artificial Intelligence Policy Act (Utah Code § 13-2-12, enacted as SB 149) has been in force since May 1, 2024 and was amended effective May 7, 2025. It is the US state law with the most practical teeth for everyday chatbots: every supplier using generative AI in a consumer transaction must disclose it when a consumer clearly asks, and high-risk interactions require a prominent disclosure at the outset.

The 2025 amendment added the part worth acting on: a statutory safe harbor. Disclose clearly and conspicuously at the start of the interaction and keep the disclosure visible throughout, and you are shielded from fines under the section. That turns proactive disclosure from a nice-to-have into the cheapest insurance the statute offers.

When it applies

In force since May 1, 2024; amended effective May 7, 2025 (proactive duty narrowed to high-risk interactions, statutory safe harbor added). Enforced by the Utah Division of Consumer Protection.

The obligation

A supplier using generative AI in a consumer transaction must clearly and conspicuously disclose that the person is interacting with generative AI when the person clearly asks. High-risk interactions (collecting sensitive personal information while giving advice a person could rely on for significant financial, legal, medical, or mental-health decisions) require a prominent disclosure at the outset.

The disclosure pattern it expects

Utah grants a safe harbor from fines to suppliers who disclose clearly and conspicuously at the outset of the interaction and throughout it. Disclosed's persistent badge plus first-message notice is that pattern, and it removes the need to detect 'are you a bot?' questions.

Readiness checklist

Common questions

Do I only have to disclose when someone asks?
The baseline duty triggers when a consumer clearly asks whether they are talking to AI. But high-risk interactions — collecting sensitive personal information while giving advice someone could rely on for significant financial, legal, medical, or mental-health decisions — require a prominent disclosure at the outset, and disclosing up front regardless is what earns the safe harbor.
What exactly is the safe harbor?
Suppliers who disclose the use of generative AI clearly and conspicuously at the outset of the interaction and throughout it are shielded from state fines under the section. A persistent AI badge plus a first-message notice is precisely that posture, and it removes the need to detect 'are you a bot?' questions.
Who enforces the Utah AI Policy Act?
The Utah Division of Consumer Protection. Keeping records of when and where your disclosure was shown is what turns an inquiry into a short conversation.
When did the law take effect?
May 1, 2024, with amendments effective May 7, 2025 that narrowed the proactive duty to high-risk interactions and added the statutory safe harbor.

Related guides

See also the other jurisdictions: EU AI Act, Article 50(1) · Colorado ADMT law (SB 26-189) · California B.O.T. Act

Is your chatbot actually ready?

Six questions, an instant verdict, free.

Just need the deadline handled? The one-time EUR 129 compliance pack covers a single chatbot with no subscription.

Disclosed provides compliance tooling and records; this document is not legal advice. Review it with your counsel before relying on it.