Artificial Intelligence Modifications

Artificial Intelligence Modifications

United States

RAI-US-UT-HB27600-2026

HB 276

Awaiting Entry(Awaiting Entry)
ActTransparency and DisclosureEnforcement and PenaltiesFundamental Rights
Export PDF

Utah HB 276 bans non-consensual deepfake intimate images and mandates transparency for AI-generated content, with most provisions effective 2027.

Overview

Utah House Bill 276, officially titled "Artificial Intelligence Modifications," is a landmark piece of legislation enacted in Utah during the 2026 General Session. Signed by Governor Spencer Cox on March 24, 2026, this Act introduces comprehensive provisions aimed at regulating artificial intelligence, particularly concerning the generation and distribution of intimate deepfake images and the broader concept of digital content provenance standards. The legislation, also known as the Digital Voyeurism Prevention Act and the Digital Content Provenance Standards Act, seeks to establish a robust framework that protects individuals from the malicious misuse of AI technology, while also fostering essential transparency in AI-generated content. Its multifaceted approach addresses both the egregious act of creating non-consensual intimate images and the critical need for clear identification of AI-generated or altered digital content across various platforms. This proactive legislative effort underscores Utah's commitment to addressing the evolving ethical and societal challenges posed by artificial intelligence, particularly in areas that can have profound impacts on personal rights, public trust, and the integrity of digital information. The Act reflects a growing national and international concern over the ethical implications of AI, particularly regarding synthetic media, the potential for widespread misinformation, and the severe personal harm that can result from its misuse.

Definitions

Utah HB 276 establishes several key definitions crucial for the accurate interpretation and consistent application of its provisions. Central to the Act is the term "counterfeit intimate image," which refers to digitally altered or entirely generated images that depict an identifiable individual in a state of nudity or engaging in sexual conduct, without their explicit consent, and where the image is not a genuine representation of that individual. This precise definition is critical for delineating the specific scope of the prohibitions and liabilities outlined in the Act, focusing specifically on the non-consensual and fabricated nature of such content. The Act also defines "generation service" as any platform, application, or service that utilizes artificial intelligence technology to create or modify intimate images. This category is a primary target of the Act's regulatory measures, particularly concerning the distribution of counterfeit intimate images, holding these services accountable for the content they facilitate. Furthermore, a "covered platform" refers to large online platforms that are subject to specific requirements regarding the detection, disclosure, and preservation of provenance data in distributed content, recognizing their significant role in content dissemination. The legislation also introduces the vital concept of "provenance data," which refers to verifiable information embedded within digital content that indicates its origin, creation method, or any modifications made by artificial intelligence. These definitions collectively form the linguistic and conceptual backbone of the Act, ensuring clarity and precision in its application to various actors and technologies within the rapidly evolving AI ecosystem.

Governance and Institutional Framework

The enforcement and oversight of Utah HB 276 are primarily vested in the Division of Consumer Protection, a pre-existing governmental body. This division is specifically tasked with ensuring robust compliance with the Act's provisions, particularly those related to the stringent prohibition of non-consensual counterfeit intimate images and the diligent implementation of digital content provenance standards. The Division's comprehensive role includes actively investigating alleged violations, initiating appropriate enforcement actions, and providing clear, actionable guidance to all entities covered by the Act. This centralized enforcement mechanism aims to provide a clear and accessible pathway for individuals to seek redress for harms suffered and for the state to impose necessary penalties on non-compliant actors, thereby upholding the integrity of the law. While the Act does not establish a new, dedicated AI regulatory agency, it strategically leverages existing governmental structures and expertise within the Division of Consumer Protection to integrate AI oversight into established consumer protection mandates. This approach allows for efficient utilization of resources and specialized knowledge already present within the division. The framework emphasizes a reactive enforcement model, where the Division responds to reports and complaints from the public, but also includes crucial proactive elements through the imposition of transparency and reporting requirements on generation services and covered platforms. The legislation's reliance on an existing agency for enforcement signifies a deliberate intent to embed AI regulation within broader consumer protection efforts, recognizing the profound potential for AI misuse to directly harm consumers and individuals.

Key Focus Areas

The central and most impactful focus of Utah HB 276 is the creation of the Digital Voyeurism Prevention Act, which directly and unequivocally addresses the non-consensual generation and distribution of counterfeit intimate images. This critical part of the legislation explicitly prohibits generation services and platforms from distributing such images without first obtaining and rigorously verifying the explicit consent of the identifiable individual depicted. This prohibition is a direct and necessary response to the increasing prevalence and severe harm caused by deepfake technology, aiming to provide robust legal recourse and essential protection for victims. The Act recognizes the profound emotional distress, reputational damage, and privacy violations that can result from the unauthorized spread of these fabricated images, establishing a clear and enforceable legal boundary for AI developers and content distributors. Beyond deepfakes, the Act also establishes comprehensive digital content provenance standards. This includes stringent requirements for large online platforms to detect, disclose, and diligently preserve provenance data in distributed content, as well as critical obligations for capture device manufacturers to include latent disclosures in all captured content. These provisions are meticulously designed to enhance transparency and accountability across the entire digital ecosystem, empowering users to accurately discern whether content has been generated or significantly altered by AI. By mandating the inclusion of verifiable provenance data, Utah aims to actively combat misinformation, enhance media literacy, and provide greater clarity regarding the authenticity of digital media. The Act also outlines crucial safe harbor protections for generation services and covered platforms that implement reasonable safeguards and respond appropriately and promptly to notices of alleged violations, thereby encouraging proactive compliance and responsible innovation within the industry.

Implementation Framework

The implementation framework for Utah HB 276 is meticulously structured to ensure a phased, comprehensive, and effective rollout, with the majority of its provisions becoming effective on January 1, 2027. This deliberate timeline allows ample time for all affected entities, including AI generation services, large online platforms, and capture device manufacturers, to thoroughly adapt their operational procedures, technological systems, and internal policies to comply with the new and stringent requirements. The Act mandates that generation services take reasonable and demonstrable measures to inform their users about the absolute prohibition of non-consensual counterfeit intimate images, the potential for significant civil liability, and the clear procedures for reporting any violations. This strong emphasis on user awareness and education is a crucial component of the overall implementation strategy, aiming to educate both providers and consumers about their respective rights and responsibilities under this new and important law. Furthermore, the Act requires covered platforms to implement robust and efficient notice and takedown procedures, alongside comprehensive disclosure requirements. These mechanisms are absolutely essential for the swift and effective removal of prohibited content and for ensuring transparency regarding the nature of AI-generated content. For capture device manufacturers, specific obligations regarding latent disclosures in captured content will take effect at a later date, on January 1, 2028, providing additional time for necessary technological adjustments, research and development, and seamless integration into existing manufacturing processes. The staggered effective dates reflect a pragmatic and thoughtful approach to implementation, acknowledging the varying complexities and lead times required for different aspects of the legislation. The Division of Consumer Protection is expected to play a pivotal role in guiding this implementation through the issuance of interpretive guidance, educational outreach, and decisive enforcement actions.

Monitoring and Evaluation

While Utah HB 276 does not explicitly detail a formal, quantitative monitoring and evaluation framework with specific metrics or predefined reporting cycles, the Act's inherent enforcement mechanisms provide a robust and ongoing basis for assessing its effectiveness and impact. The Division of Consumer Protection, as the primary enforcement body, will inevitably track key performance indicators such as the number of reported violations, the thoroughness and outcomes of investigations, and the nature and severity of penalties imposed. This aggregated data will offer invaluable insights into the prevalence of non-consensual counterfeit intimate images and the overall compliance levels of both generation services and covered platforms. The success of the Act will also be implicitly evaluated through the efficacy of its safe harbor provisions. The extent to which generation services and platforms proactively adopt and diligently maintain reasonable safeguards, and their responsiveness to notices of violations, will serve as a strong indicator of the industry's adherence to both the letter and the spirit of the law. Over time, the legal and technological landscape surrounding AI and digital content provenance is expected to continue its rapid evolution, necessitating periodic legislative reviews or amendments to ensure the Act remains relevant, effective, and capable of addressing emerging technologies and unforeseen challenges. Public feedback, stakeholder consultations, and any legal challenges related to the Act's provisions could also serve as informal yet critical mechanisms for evaluation, highlighting areas for potential refinement, clarification, or further legislative action.

Penalties, Liability, and Appeals

Utah HB 276 establishes clear and significant civil liability for violations of its provisions, particularly concerning the non-consensual generation and distribution of counterfeit intimate images. A plaintiff in an action brought under this Act is explicitly entitled to recover actual damages sustained, which may comprehensively include damages for severe emotional distress, a critical recognition of the psychological harm caused by such violations. In cases where the violation is found to be willful, reckless, or malicious, the Act allows for the potential award of punitive damages, serving as a powerful deterrent against egregious misconduct. Additionally, the Act provides for the recovery of reasonable attorney fees and costs, significantly lowering the barrier for victims to pursue legal action and ensuring access to justice. Each distinct distribution of a counterfeit intimate image depicting an identifiable individual without consent constitutes a separate violation, allowing for cumulative penalties in cases of widespread and repeated distribution. The Act also establishes a clear statute of limitations for civil actions, allowing claims to be brought within three years from the date the plaintiff discovered or reasonably should have discovered the violation, or within 10 years from the date of the violation, whichever is later, providing a reasonable window for victims to come forward. Furthermore, the legislation includes heightened pleading standards, requiring plaintiffs to plead specific facts to support their claims. This measure aims to prevent frivolous lawsuits while simultaneously ensuring that legitimate claims are thoroughly substantiated with concrete evidence. The Act also provides for injunctive relief, empowering courts to order the immediate removal of prohibited content, thereby mitigating ongoing harm. While the Act primarily focuses on robust civil remedies, the establishment of clear prohibitions and significant liabilities creates a strong and necessary deterrent against the misuse of AI for creating and distributing non-consensual intimate images.

Relationship to Other Instruments

Utah HB 276 operates harmoniously within the existing legal framework of both the United States and the State of Utah, serving to complement rather than supersede broader laws related to privacy, defamation, and intellectual property. It specifically builds upon and significantly enhances protections that might otherwise fall under general revenge porn statutes or privacy torts by directly addressing the unique and complex challenges posed by advanced artificial intelligence and deepfake technology. Unlike general statutes that may not explicitly cover AI-generated content, this Act provides targeted definitions and specific prohibitions for "counterfeit intimate images" and the generation services that create or distribute them, filling a critical legislative gap. The Act also aligns with a growing and discernible trend among U.S. states and at the federal level to proactively regulate AI and mitigate its potential harms. For example, it shares conceptual similarities with California's AI Transparency Act (CAITA) and AB 853, which also impose provenance data requirements on generative AI systems and platforms, indicating a shared understanding of the need for transparency. By establishing its own comprehensive set of standards for digital content provenance, Utah contributes significantly to a developing patchwork of state-level regulations that collectively aim to promote greater transparency, accountability, and ethical development in AI. While not directly referencing international treaties, its core principles of protecting individuals from harm and promoting transparency resonate strongly with broader global discussions on AI ethics and regulation, such as those advanced by the European Union's AI Act.

International Alignment

While Utah HB 276 is a state-level law within the United States, its core principles of combating non-consensual intimate imagery and promoting transparency in AI-generated content align remarkably well with broader international efforts and ongoing discussions on artificial intelligence ethics and regulation. Many countries and influential international bodies, such as the European Union with its groundbreaking AI Act, are actively grappling with similar complex challenges posed by generative AI, including the proliferation of deepfakes, the spread of misinformation, and the fundamental need for content authenticity. The Act's strong focus on digital content provenance standards, which require the detection, disclosure, and diligent preservation of data indicating AI creation or alteration, mirrors key recommendations and emerging international standards from respected organizations like the OECD (Organisation for Economic Co-operation and Development) and NIST (National Institute of Standards and Technology). These organizations consistently advocate for enhanced transparency, explainability, and accountability in AI systems to foster trust and mitigate risks. By establishing clear civil liability and offering well-defined safe harbor provisions, Utah's legislation also reflects a global trend towards assigning responsibility and actively encouraging the responsible development and ethical deployment of AI technologies. Although the Act does not directly engage in formal international alignment through treaties or mutual recognition agreements, its substantive provisions contribute significantly to a growing global consensus on the imperative need for robust regulatory frameworks to mitigate the inherent risks associated with advanced AI technologies, particularly those that impact fundamental human rights and erode public trust in digital information.

Implementation Timeline

MilestoneDateNotes
Bill Introduced2026-01-16House Bill 276 introduced in the Utah House of Representatives.
Governor Signed2026-03-24Governor Spencer Cox signed the bill into law.
Most Provisions Effective2027-01-01Provisions related to counterfeit intimate images, generation services, and covered platforms become effective.
Capture Device Manufacturer Provisions Effective2028-01-01Requirements for latent disclosures in captured content by capture device manufacturers become effective.

Compliance Checklist

CheckRequired Action
Consent Verification for Intimate ImagesGeneration services and platforms must obtain and verify explicit consent from identifiable individuals before distributing counterfeit intimate images.
Transparency and Reporting ProceduresGeneration services must inform users about the prohibition of non-consensual counterfeit intimate images, potential civil liability, and provide clear reporting procedures.
Notice and Takedown MechanismsCovered platforms must implement effective notice and takedown procedures for prohibited content.
Provenance Data DisclosureLarge online platforms must detect, disclose, and preserve provenance data for distributed AI-generated content.
Latent Disclosures (Capture Devices)Capture device manufacturers must include latent disclosures in captured content (effective January 1, 2028).
Reasonable Safeguards ImplementationGeneration services and covered platforms should implement reasonable safeguards to prevent the generation and distribution of prohibited content to qualify for safe harbor protections.

Sources and References

SourceType
Utah Legislature - HB 276government
Plain English

Utah's new Artificial Intelligence Modifications Act, also known as the Digital Voyeurism Prevention Act and the Digital Content Provenance Standards Act, targets AI generation services, large online platforms, and capture device manufacturers by banning non-consensual deepfake intimate images and mandating transparency for AI-generated content.

This law applies to any service that uses artificial intelligence to create or modify intimate images ("generation services"), large online platforms that distribute content ("covered platforms"), and companies that make capture devices like cameras. Its main goal is to protect individuals from harmful deepfakes and ensure people know when content is AI-generated or altered.

The most important rules are clear: generation services and platforms must not distribute "counterfeit intimate images"—digitally altered or generated images of an identifiable person in a nude or sexual state without their explicit consent. Companies must actively get and verify this consent. Additionally, large online platforms must detect, disclose, and keep "provenance data" (information about the content's origin, creation method, or AI modifications) for distributed content. Looking ahead, capture device manufacturers will also need to include "latent disclosures" in all content captured by their devices.

Most of these rules take effect on January 1, 2027. However, the requirements for capture device manufacturers start later, on January 1, 2028. The Utah Division of Consumer Protection will enforce this law. If a company violates these rules, they can face significant civil liability. Victims can recover actual damages, including for emotional distress, and potentially punitive damages if the violation was willful or malicious. Each distribution of a prohibited image counts as a separate violation, and courts can order content removal.

A key practical challenge for companies is the requirement to actively *verify* explicit consent for intimate images. This sets a high bar for generation services, demanding robust systems to confirm permission, not just assume it. Failing to meet this stringent verification standard could expose companies to significant liability, even if they believed consent was given.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under Artificial Intelligence Modifications. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalJan 1, 2027

    Applies to: Generation services and platforms.

    explicitly prohibits generation services and platforms from distributing such images without first obtaining and rigorously verifying the explicit consent
  2. #2ImportantJan 1, 2027

    Applies to: Covered platforms.

    requires covered platforms to implement robust and efficient notice and takedown procedures
  3. #3ImportantJan 1, 2027

    Applies to: Large online platforms.

    stringent requirements for large online platforms to detect, disclose, and diligently preserve provenance data in distributed content
  4. #4ImportantJan 1, 2027

    Applies to: Generation services.

    mandates that generation services take reasonable and demonstrable measures to inform their users about the absolute prohibition
  5. #5ImportantJan 1, 2027

    Applies to: Generation services.

    inform their users about... the potential for significant civil liability
  6. #6ImportantJan 1, 2027

    Applies to: Generation services.

    provide clear procedures for reporting any violations.
  7. #7ImportantJan 1, 2027

    Applies to: Covered platforms.

    implement... comprehensive disclosure requirements.
  8. #8ImportantJan 1, 2028

    Applies to: Capture device manufacturers.

    critical obligations for capture device manufacturers to include latent disclosures in all captured content.
  9. #9RecommendedJan 1, 2027

    Applies to: Generation services and covered platforms.

    safe harbor protections for generation services and covered platforms that implement reasonable safeguards
  10. #10RecommendedJan 1, 2027

    Applies to: Generation services and covered platforms.

    respond appropriately and promptly to notices of alleged violations

© Regulations.AI — created on 11-Apr-2026 using Gemini 2.5 Flash