Utah's Artificial Intelligence Policy Act, SB 149 (2024), effective May 1, 2024, was the first state statute to regulate generative AI in professional services: when asked directly, a regulated occupation using generative AI in its work must disclose that fact; mental-health chatbot services must disclose upfront and connect users to human help in crisis; and enforcement sits with the state's Division of Consumer Protection with administrative fines up to $2,500 per violation. The legislature paired the Act with an AI policy office and a learning-agenda process — a distinctive measure-first approach — and followed with 2025 amendments that refined rather than replaced the frame.
3G Times publishes information, not legal advice. The Act's application turns on occupation and interaction specifics; Utah-facing practices should assess with counsel.
What does the Act actually require?
Three duties, precisely bounded. The asked-question rule: a person in a regulated occupation — the statute points to occupations licensed under Utah's Division of Professional Licensing — who uses generative AI in their work must answer honestly when a consumer asks whether generative AI is being used. Passive nondisclosure is permitted; a lie is not. The chatbot rule: a person offering mental-health services through generative AI must disclose the AI's role before the conversation begins and provide crisis-line access — the rare statutory acknowledgment that some interactions carry safety stakes beyond consumer preference. The liability rule: the Act makes clear that deploying generative AI does not shield a person from their profession's existing duty of care — you cannot contract around malpractice by attributing the error to the model. Enforcement is administrative, via the Division, with the $2,500 ceiling per violation — small numbers that matter mostly because they are civil-penalty enforceable without private litigation.
Why does a small statute matter outside Utah?
Because it set the template. The ask-when-asked disclosure standard, the chatbot-upfront rule for sensitive services, and the no-liability-shield principle reappear, with variations, in other states' AI bills — and the Utah legislature's office-and-agenda apparatus (an AI policy office reporting, a learning agenda studying) is the governance model several states imported. For multi-state practices, Utah is where the disclosure question first became a statute rather than a bar-ethics opinion; the compliance program built to answer Utah's version answers the successors faster. And the Act's interaction with professional licensing makes it directly relevant to fintech's regulated-adjacent lines: tax preparation, financial-advice-adjacent services, and any offering where a Utah license governs the human behind the tool.
| Duty | Trigger | Operational read |
|---|---|---|
| Asked-question disclosure | Consumer asks about AI use | Staff scripts, truthful answers |
| Chatbot upfront disclosure | Mental-health services via AI | Pre-conversation notice + crisis path |
| No liability shield | Professional duty alleged | AI errors answer to licensure standards |
| Division enforcement | Violation of the above | Civil penalty up to $2,500 per act |
How should a Utah-facing practice implement it?
Modestly, by enterprise-AI-compliance standards — and completely. The occupational mapping: which of the practice's services run under Utah professional licenses, and which staff roles touch generative AI in delivering them. The script: front-line staff need a truthful one-sentence answer to "are you using AI," with enough specificity (for drafting? for analysis? for this response?) that the answer is honest — the Act's teeth bite on the misleading answer, not the uninformed customer. The chatbot lane: only for practices offering mental-health-adjacent services, where the upfront disclosure and crisis-path requirements are specific and safety-bearing. And the supervision bridge: because the no-shield rule keeps professional duties fully intact, the AI-assistance workflows licensed professionals use need the same verification gates their unassisted work always had — the Act adds the disclosure duty on top of, never instead of, the licensure standard.
What changed in the 2025 follow-on legislation?
Direction, not reversal. The 2025 session refined the office-and-oversight structure and extended Utah's measure-first posture — broadening study mandates and adjusting the policy machinery — while leaving the 2024 duties substantively in place. The signal for compliance teams is durability: Utah built its regime to be studied and tuned rather than replaced, which makes it a stable baseline for multi-state program design. The states that copied the template will tune on their own calendars; Utah's version is the one with two years of operating history.
What does this mean in practice?
- Map licensed services to AI touchpoints — the asked-question duty attaches at the license, so the inventory starts there.
- Script the honest answer — staff who cannot say what the AI does produce the misleading-answer risk the Act prices.
- Check the chatbot lanes — mental-health-adjacent offerings carry the upfront rule regardless of how the product is marketed.
- Keep verification gates at licensure strength — the no-shield rule means AI-assisted errors are professional errors, full stop.
Utah's Act is often described as modest, and by enforcement dollars it is. Its actual weight is structural: the first state to say, in statute, that generative AI inside a licensed practice is the practice — disclosable on request, unshieldable in liability, and safety-marked where stakes demand. The practices that internalized that sentence find every successor statute familiar.
The precedent note for program managers: Utah's two years of operating history include no reported enforcement wave — the measure-first design appears to be working as intended, studying before penalizing. That history is the argument for treating the Act as a compliance-toolkits floor rather than a litigation exposure, and for copying its scripts before other states copy its statutes with sharper teeth.
The closing read for compliance planners: the Act's significance was never its penalty ceiling — it was the precedent that generative AI in professional practice is statutory territory, not just ethics-memo territory. Every successor statute will be longer than Utah's six pages; the practices that built their disclosure muscle on the short one will read the long ones as amendments rather than new laws.
How does the Act interact with bar ethics rules?
In parallel: a Utah-licensed attorney's AI use answers both the statute's asked-question duty and the ethics guidance's confidentiality-and-competence frame — one truthful script satisfies both, and neither excuses the other. Practices that drafted the script from the ethics analysis first found the statutory duty already covered; the reverse order usually missed the chatbot lane.
Frequently asked questions
Does the Act require proactive AI disclosure in every interaction?
No — disclosure is triggered by the consumer's question, except the chatbot context where it must precede the conversation. The Act's design accepts AI assistance as ordinary; it punishes the dishonest answer about it.
Who enforces, and can consumers sue?
The Division of Consumer Protection enforces administratively with per-violation fines up to $2,500; the Act creates no private right of action. Consumers' existing remedies under professional and consumer law are untouched — the no-shield rule keeps those doors open.
Does it apply to out-of-state providers serving Utah customers?
The enforcement posture note belongs with the mapping: the Division has treated the Act's duties as a consumer-protection floor, and complaint-driven inquiries — not audits — have been the typical vector, which places truthful-answer training squarely on the front line where the statute actually bites.
The occupational duties attach to practice within the licensing frame Utah regulates; remote services reaching Utahans under Utah licenses read as inside. Multi-state programs typically build to the strictest applicable disclosure trigger rather than jurisdiction-hopping the analysis.
For more context, read EU AI Act Before August 2026: Credit-Scoring Deployers, FRIAs, and the Human-Oversight File.
For more context, read illinois bipa 2024 amendments.
For more context, read cftc event contracts ruling.

