Skip to content
Wednesday, August 26, 2026
3G TIMESFINTECH LAW · LEGAL TECH · COMPLIANCE
Home / Regulation
Regulation

Utah's AI Policy Act: Disclosure Duties When Regulated Professions Use Generative Tools

The first state statute to regulate generative AI in professional practice is short, civil-penalty enforced, and the template other states copied.

William Elliott, · July 21, 2026 · 7 min read
ShareXFacebookLinkedInTelegramEmail
Infographic of disclosure triggers from consumer question to chatbot notice

Utah's Artificial Intelligence Policy Act, SB 149 (2024), effective May 1, 2024, was the first state statute to regulate generative AI in professional services: when asked directly, a regulated occupation using generative AI in its work must disclose that fact; mental-health chatbot services must disclose upfront and connect users to human help in crisis; and enforcement sits with the state's Division of Consumer Protection with administrative fines up to $2,500 per violation. The legislature paired the Act with an AI policy office and a learning-agenda process — a distinctive measure-first approach — and followed with 2025 amendments that refined rather than replaced the frame.

3G Times publishes information, not legal advice. The Act's application turns on occupation and interaction specifics; Utah-facing practices should assess with counsel.

What does the Act actually require?

Three duties, precisely bounded. The asked-question rule: a person in a regulated occupation — the statute points to occupations licensed under Utah's Division of Professional Licensing — who uses generative AI in their work must answer honestly when a consumer asks whether generative AI is being used. Passive nondisclosure is permitted; a lie is not. The chatbot rule: a person offering mental-health services through generative AI must disclose the AI's role before the conversation begins and provide crisis-line access — the rare statutory acknowledgment that some interactions carry safety stakes beyond consumer preference. The liability rule: the Act makes clear that deploying generative AI does not shield a person from their profession's existing duty of care — you cannot contract around malpractice by attributing the error to the model. Enforcement is administrative, via the Division, with the $2,500 ceiling per violation — small numbers that matter mostly because they are civil-penalty enforceable without private litigation.

Why does a small statute matter outside Utah?

Because it set the template. The ask-when-asked disclosure standard, the chatbot-upfront rule for sensitive services, and the no-liability-shield principle reappear, with variations, in other states' AI bills — and the Utah legislature's office-and-agenda apparatus (an AI policy office reporting, a learning agenda studying) is the governance model several states imported. For multi-state practices, Utah is where the disclosure question first became a statute rather than a bar-ethics opinion; the compliance program built to answer Utah's version answers the successors faster. And the Act's interaction with professional licensing makes it directly relevant to fintech's regulated-adjacent lines: tax preparation, financial-advice-adjacent services, and any offering where a Utah license governs the human behind the tool.

DutyTriggerOperational read
Asked-question disclosureConsumer asks about AI useStaff scripts, truthful answers
Chatbot upfront disclosureMental-health services via AIPre-conversation notice + crisis path
No liability shieldProfessional duty allegedAI errors answer to licensure standards
Division enforcementViolation of the aboveCivil penalty up to $2,500 per act

How should a Utah-facing practice implement it?

Modestly, by enterprise-AI-compliance standards — and completely. The occupational mapping: which of the practice's services run under Utah professional licenses, and which staff roles touch generative AI in delivering them. The script: front-line staff need a truthful one-sentence answer to "are you using AI," with enough specificity (for drafting? for analysis? for this response?) that the answer is honest — the Act's teeth bite on the misleading answer, not the uninformed customer. The chatbot lane: only for practices offering mental-health-adjacent services, where the upfront disclosure and crisis-path requirements are specific and safety-bearing. And the supervision bridge: because the no-shield rule keeps professional duties fully intact, the AI-assistance workflows licensed professionals use need the same verification gates their unassisted work always had — the Act adds the disclosure duty on top of, never instead of, the licensure standard.

What changed in the 2025 follow-on legislation?

Direction, not reversal. The 2025 session refined the office-and-oversight structure and extended Utah's measure-first posture — broadening study mandates and adjusting the policy machinery — while leaving the 2024 duties substantively in place. The signal for compliance teams is durability: Utah built its regime to be studied and tuned rather than replaced, which makes it a stable baseline for multi-state program design. The states that copied the template will tune on their own calendars; Utah's version is the one with two years of operating history.

What does this mean in practice?

Utah's Act is often described as modest, and by enforcement dollars it is. Its actual weight is structural: the first state to say, in statute, that generative AI inside a licensed practice is the practice — disclosable on request, unshieldable in liability, and safety-marked where stakes demand. The practices that internalized that sentence find every successor statute familiar.

The precedent note for program managers: Utah's two years of operating history include no reported enforcement wave — the measure-first design appears to be working as intended, studying before penalizing. That history is the argument for treating the Act as a compliance-toolkits floor rather than a litigation exposure, and for copying its scripts before other states copy its statutes with sharper teeth.

The closing read for compliance planners: the Act's significance was never its penalty ceiling — it was the precedent that generative AI in professional practice is statutory territory, not just ethics-memo territory. Every successor statute will be longer than Utah's six pages; the practices that built their disclosure muscle on the short one will read the long ones as amendments rather than new laws.

How does the Act interact with bar ethics rules?

In parallel: a Utah-licensed attorney's AI use answers both the statute's asked-question duty and the ethics guidance's confidentiality-and-competence frame — one truthful script satisfies both, and neither excuses the other. Practices that drafted the script from the ethics analysis first found the statutory duty already covered; the reverse order usually missed the chatbot lane.

Frequently asked questions

Does the Act require proactive AI disclosure in every interaction?

No — disclosure is triggered by the consumer's question, except the chatbot context where it must precede the conversation. The Act's design accepts AI assistance as ordinary; it punishes the dishonest answer about it.

Who enforces, and can consumers sue?

The Division of Consumer Protection enforces administratively with per-violation fines up to $2,500; the Act creates no private right of action. Consumers' existing remedies under professional and consumer law are untouched — the no-shield rule keeps those doors open.

Does it apply to out-of-state providers serving Utah customers?

The enforcement posture note belongs with the mapping: the Division has treated the Act's duties as a consumer-protection floor, and complaint-driven inquiries — not audits — have been the typical vector, which places truthful-answer training squarely on the front line where the statute actually bites.

The occupational duties attach to practice within the licensing frame Utah regulates; remote services reaching Utahans under Utah licenses read as inside. Multi-state programs typically build to the strictest applicable disclosure trigger rather than jurisdiction-hopping the analysis.

Frequently Asked Questions

Does the Act require proactive AI disclosure in every interaction?
No — disclosure triggers on the consumer's question, except the chatbot context, where it must precede the conversation. The design accepts AI assistance as ordinary and punishes the dishonest answer about it.
Who enforces, and can consumers sue?
The Division of Consumer Protection enforces administratively with fines up to $2,500 per violation; no private right of action is created. Existing professional and consumer remedies are untouched — the no-shield rule keeps those doors open.
Does it apply to out-of-state providers serving Utah customers?
The duties attach to practice within Utah's licensing frame; remote services under Utah licenses read as inside. Multi-state programs build to the strictest applicable trigger rather than jurisdiction-hopping the analysis.