Utah passed the nation's first state law targeting generative AI in March 2024, and then did something unusual: it wrote the law to expire. That sunset clause has already forced Utah's legislature back to the table twice, producing a law that looks meaningfully different today than it did at signing. If you're tracking state AI disclosure requirements, Utah is the one that keeps changing shape.

Quick answer

Utah's Artificial Intelligence Policy Act (2024) requires AI disclosure only for "high-risk" interactions involving sensitive data or significant decisions, after 2025 amendments narrowed its original broader scope. A companion law, HB 452, separately regulates AI mental health chatbots with strict disclosure timing and data-sharing restrictions. Penalties run up to $2,500 per violation, enforced by Utah's Division of Consumer Protection.

The 2024 Original — and Why It Almost Expired

Governor Cox signed SB 149, the Artificial Intelligence Policy Act (UAIPA), in March 2024, taking effect May 1, 2024. It required businesses using consumer-facing generative AI to disclose that interaction to users when directly asked, established an Office of Artificial Intelligence Policy, and created a regulatory sandbox — the AI Learning Laboratory Program — for companies developing new AI applications under temporary "regulatory mitigation" agreements. Critically, the original law was written with an automatic repeal date of May 7, 2025 — a built-in sunset clause almost no other state AI law includes.

The 2025 Narrowing: SB 226 and SB 332

Rather than let the UAIPA lapse, Utah's legislature passed two amendments in March 2025. SB 332 simply extended the sunset date to July 1, 2027. SB 226 did something more consequential: it narrowed mandatory proactive disclosure to only "high-risk AI interactions" — those involving sensitive personal data (health, financial, biometric) combined with significant decisions like medical, legal, or financial advice. For ordinary consumer interactions outside that high-risk category, disclosure is now only required when a user directly and unambiguously asks.

SB 226 also introduced a genuine safe harbor: a business faces no enforcement action if its generative AI clearly discloses, at the outset and throughout the interaction, that the user is talking to AI rather than a human. This incentive structure — disclose proactively and get legal certainty, or disclose only on request and accept some residual risk — is a distinctive design choice among state AI disclosure laws.

HB 452: The Mental Health Chatbot Law

Separately, Utah passed HB 452 in March 2025, creating a dedicated regulatory regime for AI mental health chatbots — defined as generative AI systems designed to simulate the kind of confidential conversation a licensed mental health therapist would have. This is significantly stricter than the general UAIPA disclosure rules:

  • Disclosure timing is specific and repeated, not just proactive: before a user can access the chatbot, again after seven days of non-use, and whenever the user asks.
  • Health data can't be sold or shared with third parties, except as strictly necessary for the chatbot's function or to a licensed provider with user consent under HIPAA.
  • Advertising restrictions apply directly to the conversation itself — suppliers can't use a mental health chatbot to advertise products without clear, conspicuous disclosure that it's an advertisement, and user input can't be used to target or customize ads.
  • An affirmative defense exists for suppliers who develop and file a detailed compliance policy with the state, covering licensed-professional involvement in development, testing and review processes, and safeguards against discriminatory treatment.

Violations of HB 452 carry civil penalties up to $2,500 per violation, enforced by Utah's Division of Consumer Protection, which can also seek injunctions — a remedy that can be more operationally damaging than a fine, since it can force a company to stop specific practices outright rather than simply pay a cost of doing business.

Why Utah's Model Is Worth Watching

Utah's risk-tiered, sunset-clause approach has become a genuine reference point for other states considering chatbot-specific legislation — Hawaii, Idaho, Illinois, and Massachusetts have all considered bills requiring disclosure specifically when a reasonable user might mistakenly believe they're talking to a human, echoing Utah's structure rather than a blanket AI-disclosure mandate. The narrowing from SB 226 also fits a broader national pattern: 2025-2026 state legislation has trended toward risk-based, targeted rules rather than the broad omnibus AI statutes that defined the 2024 legislative wave.

How This Compares to Other States

Utah's disclosure-focused, sunset-clause model sits apart from the frameworks used in Colorado (consequential-decision ADMT disclosure), Texas (intent-based prohibitions), and NYC's Local Law 144 (mandatory bias audits) — Utah never adopted a risk-assessment or audit requirement at all, relying instead on disclosure and a genuine safe-harbor incentive. For a multi-state compliance program, Utah is usually the easiest jurisdiction to satisfy once your disclosure language is solid, precisely because it doesn't require documentation infrastructure the way audit-based or impact-assessment-based state laws do.

Practical Compliance Steps

  • Classify your AI interactions against the "high-risk" definition — sensitive data plus significant decision-making — since that determines whether proactive disclosure is legally required or only owed on request.
  • Build disclosure language that qualifies for the SB 226 safe harbor even where not strictly mandatory — the legal certainty is worth the minor UX cost in most consumer-facing products.
  • If you operate a mental health-adjacent chatbot, treat HB 452 as its own compliance track, not an extension of general UAIPA disclosure — the timing, data-handling, and advertising rules are materially stricter and separately enforced.
  • Track the July 2027 sunset date — Utah's pattern suggests further amendment before expiration is more likely than a clean lapse, but the law's exact shape by then is genuinely uncertain given its two-amendment history already.

Frequently Asked Questions

Does Utah require all AI chatbots to disclose they're AI?

Only in "high-risk" interactions involving sensitive personal data and significant decisions, or when a user directly asks. Amendments in 2025 narrowed what was originally closer to a blanket disclosure requirement.

What is Utah's AI mental health chatbot law?

HB 452, effective May 2025, imposes specific disclosure timing, health-data restrictions, and advertising limits on AI systems designed to simulate mental health therapy conversations — separate from and stricter than Utah's general AI disclosure law.

Why does Utah's AI law have a sunset clause?

The original 2024 law was written to automatically expire in 2025, a distinctive design forcing periodic legislative reconsideration rather than permanence — it has since been extended to July 2027.

What are the penalties for violating Utah's AI laws?

Up to $2,500 per violation under both the general UAIPA and HB 452, enforced by Utah's Division of Consumer Protection, which can also seek injunctive relief.

Related reading: Colorado's SB 26-189 disclosure model, NYC's Local Law 144 bias audit requirements, and how to build an AI governance program from scratch.