United States - Utah - AI Policy Act (SB 149)

Utah SB 149 — Artificial Intelligence Policy Act

United States

RAI-US-UT-US1AIXX-2024
Effective: May 1, 2024
In Force(In Force)
ActGovernance and OversightTransparency and DisclosureEnforcement and Penalties
Export PDF

Utah Senate Bill 149, the Artificial Intelligence Policy Act, signed March 13, 2024, became the first US state law regulating private-sector use of generative artificial intelligence. The law requires businesses using generative AI in consumer interactions to clearly disclose AI involvement when asked, prohibits AI-generated content from being used to defraud consumers, creates the Office of Artificial Intelligence Policy, and establishes a regulatory sandbox for AI innovation. The Division of Consumer Protection enforces the law under the Consumer Sales Practices Act.

Overview

Utah Senate Bill 149, the Artificial Intelligence Policy Act, represents a milestone in US AI governance as the first state law specifically regulating private-sector use of generative artificial intelligence. Signed by Governor Spencer Cox on March 13, 2024, the legislation took effect May 1, 2024, positioning Utah at the forefront of state-level AI policy. The law reflects Utah's characteristic approach to technology regulation—establishing baseline consumer protections while maintaining a business-friendly environment that encourages innovation. Sponsored by Senator Kirk Cullimore, the legislation addresses growing concerns about AI transparency and consumer deception while avoiding the prescriptive requirements that might stifle technological development. The Act creates the Office of Artificial Intelligence Policy to centralize state expertise and coordination, establishes disclosure requirements for generative AI in consumer interactions, extends existing consumer protection laws to AI-generated fraudulent content, and provides a regulatory sandbox for AI experimentation. Utah's early action positions the state to influence emerging federal standards while attracting AI companies seeking a predictable regulatory environment.

Definitions

SB 149 establishes key definitions tailored to generative AI applications. Artificial intelligence means a machine-based system that, for explicit or implicit objectives, infers from input it receives how to generate outputs, such as predictions, content, recommendations, or decisions, that can influence physical or virtual environments. Generative artificial intelligence means artificial intelligence that can generate derived synthetic content, including text, images, video, and audio, that emulates the structure and characteristics of the AI's training data. This definition specifically targets systems capable of creating human-like content that could mislead consumers about whether they are interacting with humans or machines. Consumer means a natural person who purchases, leases, or obtains goods, services, or credit for personal, family, or household purposes. Person includes individuals, corporations, partnerships, associations, and other legal entities, capturing the full range of businesses that might deploy generative AI. The law's focus on generative AI rather than all AI systems reflects the legislature's concern about specific risks from AI-generated content that can convincingly mimic human communication, while preserving flexibility for other AI applications that may present different risk profiles.

Governance and Institutional Framework

SB 149 creates a new institutional infrastructure for AI governance in Utah. The Office of Artificial Intelligence Policy is established within the Utah Department of Commerce, creating dedicated state capacity for AI policy development and coordination. The Office is led by a director appointed by the executive director of the Department of Commerce, with responsibilities including monitoring AI technological developments, recommending statutory and regulatory changes to the legislature and governor, coordinating with federal agencies and other states on AI policy, supporting state agencies in AI adoption and governance, and providing guidance to businesses on AI compliance. The Division of Consumer Protection within the Department of Commerce enforces the law's consumer protection provisions under the existing Consumer Sales Practices Act framework. This integration leverages established enforcement mechanisms rather than creating new regulatory structures. The AI Learning Laboratory Program (regulatory sandbox) is administered by specified agencies with authority to relax regulatory requirements for approved participants testing AI innovations. The Office serves a coordination function across agencies, ensuring consistent AI policy approaches while respecting individual agency expertise in their regulatory domains.

Key Focus Areas

  • Disclosure Requirements: Persons using generative AI in consumer interactions must clearly and conspicuously disclose AI involvement when a consumer asks whether they are interacting with AI or a human.
  • Anti-Fraud Provisions: Using generative AI to generate content with intent to defraud, deceive, or manipulate consumers constitutes a deceptive trade practice.
  • Office of AI Policy: New office established to centralize AI expertise, monitor developments, and coordinate policy across state government.
  • Regulatory Sandbox: AI Learning Laboratory Program allows testing of AI products under relaxed regulations while maintaining consumer protections.
  • Consumer Sales Practices Act Integration: AI-related violations enforceable under existing consumer protection framework with established penalties.
  • Professional Licensing: Clarifies that AI tools used by licensed professionals remain subject to professional licensing requirements and standards.
  • State Agency AI Use: Establishes framework for state agency adoption and governance of AI systems.
  • Innovation Promotion: Explicitly recognizes importance of supporting AI innovation alongside consumer protection.

Implementation Framework

SB 149 took effect May 1, 2024, with most provisions immediately operative. The Office of Artificial Intelligence Policy was established upon enactment, with the Department of Commerce responsible for staffing and operationalizing the new office. The director position and core functions became effective immediately, enabling Utah to begin building AI governance capacity. Businesses using generative AI in consumer interactions must comply with disclosure requirements from the effective date—when consumers ask whether they are interacting with AI, businesses must provide clear and conspicuous disclosure. The anti-fraud provisions apply to conduct occurring after the effective date, prohibiting use of generative AI to defraud or deceive consumers. The AI Learning Laboratory Program requires implementing rules from participating agencies before accepting sandbox applications, with timelines varying by agency. Professional licensing provisions clarify existing requirements rather than creating new obligations, applying immediately to AI tools used in professional practice. State agencies must develop AI governance approaches consistent with Office guidance as it is issued. The law does not impose registration requirements, impact assessments, or documentation obligations beyond existing Consumer Sales Practices Act record-keeping, reflecting its light-touch approach. Future rulemaking may elaborate on disclosure requirements and sandbox procedures as implementation experience accumulates.

Monitoring and Evaluation

SB 149 establishes monitoring primarily through the Office of Artificial Intelligence Policy's ongoing functions. The Office is charged with monitoring AI technological developments nationally and internationally, identifying emerging risks and opportunities that may warrant policy responses. Annual reporting to the governor and legislature provides structured evaluation of AI trends and policy recommendations. The Division of Consumer Protection monitors consumer complaints involving AI-related deception through existing complaint intake processes, providing data on enforcement needs and emerging fraud patterns. The AI Learning Laboratory Program includes monitoring requirements for sandbox participants, with agencies tracking outcomes and consumer impacts of experimental AI products. No formal external auditing or third-party evaluation mechanisms are established, consistent with the law's light-touch approach. The Office's coordination function with federal agencies and other states enables Utah to learn from experiences in other jurisdictions and incorporate best practices. Market-based feedback through consumer complaints, media coverage, and business community engagement provides informal monitoring channels. The legislature retained authority to expand monitoring requirements in future sessions as implementation experience reveals gaps or emerging risks requiring attention.

Penalties, Liability, and Appeals

SB 149 incorporates enforcement into Utah's Consumer Sales Practices Act (CSPA), leveraging established penalty structures. Violations of the disclosure requirement and the prohibition on AI-generated fraudulent content constitute deceptive acts or practices under the CSPA. The Division of Consumer Protection may investigate complaints, issue cease-and-desist orders, and refer matters for civil prosecution. Civil penalties under the CSPA can reach up to $2,500 per violation, with each transaction potentially constituting a separate violation. The Division director may assess penalties administratively, subject to appeal to the Department of Commerce director. Private consumers may bring civil actions under CSPA for actual damages, with courts authorized to award up to three times actual damages for willful violations, plus attorney's fees and costs. The CSPA's existing affirmative defenses apply, including good-faith compliance with agency guidance. No criminal penalties are established specifically for AI-related violations, though fraudulent conduct may implicate other criminal statutes. The AI Learning Laboratory sandbox provides enforcement flexibility for participants, relaxing certain regulatory requirements while maintaining consumer protection baselines. Appeals from administrative enforcement follow existing Department of Commerce procedures, with judicial review available in state courts.

Relationship to Other Instruments

SB 149 operates within Utah's broader regulatory framework while addressing novel AI-specific concerns. The Utah Consumer Sales Practices Act provides the enforcement foundation, with AI provisions integrated as specific applications of existing deceptive practices prohibitions. Utah's professional licensing statutes continue to govern AI use by licensed professionals, with SB 149 clarifying rather than displacing those requirements. The law complements federal consumer protection authority under the FTC Act, which the FTC has begun applying to AI-related deception. Executive Order 14110 establishes federal AI policy that Utah's Office of AI Policy monitors and coordinates with. Compared to Colorado's SB24-205, Utah's approach is significantly lighter-touch, lacking impact assessment requirements, risk management mandates, or algorithmic discrimination prohibitions. Utah's disclosure requirement is narrower than requirements in some other jurisdictions, applying only when consumers affirmatively ask about AI involvement rather than requiring proactive disclosure. The AI Learning Laboratory Program builds on Utah's prior regulatory sandbox legislation for financial technology, extending the sandbox concept to AI applications. Future federal AI legislation may preempt aspects of state law, though Utah's consumer protection focus may survive under traditional state police powers.

International Alignment

Utah's Artificial Intelligence Policy Act takes a distinctive approach compared to comprehensive international AI frameworks. Unlike the European Union AI Act's risk-based system covering all AI applications, Utah focuses narrowly on generative AI in consumer interactions, avoiding broad categorization schemes. The EU Act's extensive transparency, documentation, and conformity assessment requirements contrast sharply with Utah's minimal disclosure obligation. The UK's approach emphasizing sector-specific regulation through existing regulators aligns somewhat with Utah's integration into the Consumer Sales Practices Act framework. Canada's proposed AI legislation, like the EU Act, takes a more comprehensive approach than Utah's targeted intervention. Utah's regulatory sandbox concept has international precedents, particularly in UK and Singapore financial technology sandboxes that informed Utah's prior fintech legislation. The Office of AI Policy's coordination function parallels AI governance coordination bodies emerging in other jurisdictions, though with narrower scope than the UK's AI Safety Institute or Singapore's AI governance initiatives. Utah's innovation-friendly approach may appeal to international AI companies seeking a US beachhead with predictable regulation, though companies serving multiple jurisdictions must meet the higher requirements of more comprehensive frameworks. The disclosure-upon-request model differs from international transparency requirements that typically mandate proactive disclosure.

Implementation Timeline

DateMilestone
January 2024SB 149 introduced in Utah Legislature
March 4, 2024Bill passes Utah House and Senate
March 13, 2024Governor Spencer Cox signs SB 149 into law
May 1, 2024Law takes effect; Office of AI Policy established
May 1, 2024Disclosure requirements and anti-fraud provisions effective
OngoingAI Learning Laboratory Program accepting applications (agency-specific timelines)
AnnuallyOffice of AI Policy reports to governor and legislature

Compliance Checklist

RequirementDetails
Identify Generative AI UseAssess where generative AI is used in consumer-facing interactions (customer service, chatbots, sales)
Implement Disclosure CapabilityEnsure systems can provide clear disclosure of AI involvement when consumers ask
Train Customer-Facing StaffPrepare employees to respond to consumer inquiries about AI use
Review Marketing PracticesEnsure AI-generated marketing content does not deceive consumers
Audit for Fraudulent UseVerify AI systems are not used to generate fraudulent or manipulative content
Consider Sandbox ProgramEvaluate whether AI Learning Laboratory participation benefits innovation projects
Monitor Office GuidanceTrack guidance issued by the Office of AI Policy for updated compliance expectations
Professional Licensing ReviewIf in licensed profession, ensure AI tool use complies with professional standards

Sources and References

SourceType
SB 149 Bill Page - Utah LegislaturePrimary Source
Utah Code Title 13 Chapter 62 - AI Policy ActEnacted Law
Utah Department of CommerceParent Agency
Utah Division of Consumer ProtectionEnforcement Agency
Plain English

Utah's Artificial Intelligence Policy Act, effective May 1, 2024, regulates how businesses use generative AI when interacting with consumers, focusing on transparency and preventing deception. This landmark law applies to any business or individual using generative artificial intelligence—AI that creates synthetic content like text, images, or audio—in interactions with consumers, defined as natural persons buying goods or services for personal use.

The Act establishes two main requirements for businesses. First, if you use generative AI in consumer interactions, you must clearly and conspicuously disclose its use when a consumer asks whether they are interacting with AI or a human. Second, the law prohibits using generative AI to create content with the intent to defraud, deceive, or manipulate consumers, classifying such acts as deceptive trade practices.

Enforcement is handled by the Utah Division of Consumer Protection, operating under the existing Consumer Sales Practices Act. Violations, including failing to disclose AI use when asked or engaging in AI-driven fraud, can incur civil penalties of up to $2,500 per violation, with each individual transaction potentially counting as a separate offense. Consumers can also pursue private lawsuits for actual damages, which courts may triple for willful violations, alongside attorney's fees.

A crucial practical takeaway is the law's "light-touch" approach: it does not mandate proactive disclosure of AI use. Instead, businesses only need to disclose when a consumer specifically asks. This means companies should focus on training customer-facing staff and ensuring systems are equipped to provide clear, conspicuous answers upon inquiry. The state has also established an Office of Artificial Intelligence Policy to centralize expertise and guide future AI development, alongside a "regulatory sandbox" program for testing AI innovations under relaxed rules.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 5 marked complete

Plain-English obligations under United States - Utah - AI Policy Act (SB 149). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalMay 1, 2024

    Applies to: Persons using generative AI in consumer interactions.

    Persons using generative AI in consumer interactions must clearly and conspicuously disclose AI involvement when a consumer asks whether they are interacting with AI or a human.
  2. #2CriticalMay 1, 2024

    Applies to: Persons using generative AI.

    Using generative AI to generate content with intent to defraud, deceive, or manipulate consumers constitutes a deceptive trade practice.
  3. #3ImportantMay 1, 2024

    Applies to: Licensed professionals using AI tools.

    Clarifies that AI tools used by licensed professionals remain subject to professional licensing requirements and standards.
  4. #4Important

    Applies to: Businesses using AI.

    The Office... providing guidance to businesses on AI compliance.
  5. #5Recommended

    Applies to: Businesses developing AI innovations.

    The AI Learning Laboratory Program (regulatory sandbox) is administered by specified agencies with authority to relax regulatory requirements for approved participants testing AI innovations.

© Regulations.AI — created on 05-Aug-2026