United States - Utah - AI Consumer Protection (SB 226)
Utah SB 226 - Artificial Intelligence Consumer Protection Amendments
United States
RAI-US-UT-US2AIXX-2025United States - Utah - AI Consumer Protection (SB 226) is In Force in United States. We have not yet been able to confirm the status.
ActTransparency and DisclosureLiability and RedressEnforcement and PenaltiesUtah SB 226 regulates generative AI in consumer transactions, mandating disclosures, establishing liability, and empowering the Division of Consumer Protection for enforcement.
Summary
Utah Senate Bill 226, the Artificial Intelligence Consumer Protection Amendments, regulates generative AI in consumer transactions and regulated services. It defines key terms, mandates specific disclosures, establishes liability for AI-related consumer protection violations, and provides a safe harbor for compliant disclosures. The bill grants rulemaking and enforcement authority to the Division of Consumer Protection, sets penalties, and extends the Artificial Intelligence Policy Act's repeal date, aiming to enhance transparency and consumer protection.
Full article
Read full text ↗Overview
Utah Senate Bill 226, officially titled the Artificial Intelligence Consumer Protection Amendments, represents a significant legislative effort by the State of Utah to establish a regulatory framework for the burgeoning field of generative artificial intelligence (AI) within consumer transactions and regulated services. Enacted during the 2025 General Session, this legislation aims to foster transparency, accountability, and consumer protection in an environment increasingly influenced by advanced AI systems. The bill introduces a series of new provisions designed to define key terms, mandate specific disclosure requirements for entities utilizing generative AI, and delineate the scope of liability for potential violations of consumer protection laws involving AI. Furthermore, it establishes a crucial safe harbor for businesses that adhere to prescribed disclosure standards, thereby encouraging proactive compliance while mitigating undue regulatory burdens.
A cornerstone of SB 226 is the empowerment of the Division of Consumer Protection with explicit rulemaking and enforcement authority, underscoring the state's commitment to active oversight. This includes the power to levy penalties for non-compliance, ensuring that the regulatory framework has tangible consequences for infringements. Beyond its immediate effects on generative AI usage, SB 226 also plays a pivotal role in the broader landscape of Utah's AI policy by amending and extending the repeal date of the pre-existing Artificial Intelligence Policy Act. This extension, facilitated by related legislation (SB 332), ensures a more enduring and consistent regulatory presence in the rapidly evolving AI sector, allowing for continued adaptation and refinement of state policies as AI technologies mature and their societal impacts become clearer. The comprehensive nature of SB 226 positions Utah as a proactive leader in state-level AI governance, seeking to balance innovation with robust consumer safeguards.
Definitions
Central to the application of SB 226 are several key definitions that delineate the scope and applicability of the new regulations. The bill specifically defines "generative artificial intelligence" as an AI system that is trained on data, designed to simulate human conversation through text, audio, or visuals, and generates non-scripted outputs with limited or no human oversight. This definition is crucial for identifying the types of AI systems subject to the disclosure and liability provisions outlined in the Act. The focus on 'generative' AI highlights the legislature's intent to regulate systems capable of creating content or engaging in dynamic interactions, rather than simple automated processes.
Another critical term introduced or clarified by the Act is "high-risk artificial intelligence interaction." This term is particularly relevant for individuals providing services in regulated occupations, where prominent disclosures are required. While the bill itself does not provide an exhaustive list, related summaries indicate that high-risk interactions generally involve sensitive personal information or personalized advice that could significantly influence personal decisions. This distinction ensures that regulatory scrutiny is appropriately directed towards AI applications with the greatest potential for consumer impact or harm. The amendments also refined the definition of an “AI system” by incorporating a requirement that the system be “designed to simulate human conversation,” thereby excluding more basic AI-generated communications like routine appointment confirmations or reminders from the scope of certain disclosure obligations.
Governance and Institutional Framework
The governance and institutional framework established by Utah SB 226 primarily designates the Division of Consumer Protection as the key regulatory and enforcement authority. This Division is explicitly granted rulemaking and enforcement powers to oversee compliance with the provisions related to generative artificial intelligence in consumer transactions and regulated services. The legislation empowers the Division to develop specific rules and guidelines that will further detail the practical implementation of the Act's requirements, ensuring that the regulatory framework remains adaptable to technological advancements and market practices. This centralized authority within an existing state agency leverages established mechanisms for consumer protection, allowing for efficient integration of AI-specific regulations into broader consumer safeguards.
Complementing the Division of Consumer Protection's role, the Attorney General is tasked with providing legal advice to the Division regarding its responsibilities under this chapter. This legal counsel ensures that the Division's rulemaking and enforcement actions are consistent with state law and constitutional principles, providing a layer of legal oversight. While SB 226 primarily focuses on the Division of Consumer Protection, it operates within the broader context of Utah's existing Artificial Intelligence Policy Act, which established the Office of Artificial Intelligence Policy. This Office, while not directly responsible for the enforcement of SB 226's consumer protection provisions, plays a consultative role, engaging with businesses and stakeholders and administering programs like the AI Learning Laboratory. This multi-faceted approach indicates a comprehensive state strategy for AI governance, combining direct regulatory enforcement with broader policy development and innovation support.
Key Focus Areas
Utah SB 226 concentrates on several key areas to regulate generative artificial intelligence effectively. A primary focus is on disclosure requirements, mandating that suppliers using generative AI to interact with individuals in consumer transactions must disclose the use of AI if the individual clearly and unambiguously asks or prompts about it. This provision shifts the burden of disclosure to specific consumer inquiries rather than a blanket requirement, aiming to provide transparency where consumer concern is explicitly expressed. Similarly, individuals providing services in regulated occupations are required to prominently disclose when generative AI is used in "high-risk artificial intelligence interactions," which are situations involving sensitive personal information or significant personal decisions. This dual approach to disclosure ensures that consumers are informed in critical contexts while avoiding overly broad mandates for all AI interactions.
Another significant focus area is liability. The bill explicitly establishes liability for violations of consumer protection laws that involve artificial intelligence. This clarifies that the use of AI does not absolve entities of their responsibility to comply with existing consumer protection statutes, ensuring that consumers have avenues for redress if harmed by AI-driven interactions. To balance this, the Act introduces a safe harbor provision for entities that make clear and conspicuous disclosures about the use of generative AI at the outset of and throughout consumer interactions. This safe harbor incentivizes businesses to be transparent, offering a degree of protection from enforcement actions if they proactively inform consumers. The legislation also addresses enforcement and penalties, granting the Division of Consumer Protection the authority to investigate violations, impose fines, and seek injunctive relief, thereby providing robust mechanisms for upholding the Act's provisions. Lastly, the bill's role in extending the repeal date of the Artificial Intelligence Policy Act (via SB 332) signifies a commitment to long-term AI governance, ensuring that Utah's regulatory framework for AI remains active and can evolve with technological advancements.
Implementation Framework
The implementation framework for Utah SB 226 is designed to integrate its new provisions into existing consumer protection mechanisms, primarily through the Division of Consumer Protection. This Division is tasked with the critical responsibility of developing and promulgating administrative rules necessary for the effective execution of the Act's mandates. These rules will provide granular detail on how disclosures should be made, what constitutes a "clear and unambiguous request" from a consumer, and the specific criteria for identifying "high-risk artificial intelligence interactions" in regulated occupations. The iterative process of rulemaking allows for stakeholder input and expert consultation, ensuring that the implementation is practical, fair, and responsive to the nuances of AI technology and market dynamics. The Division's existing infrastructure for investigations and enforcement will be leveraged, streamlining the process of addressing non-compliance.
A key aspect of the implementation is the practical application of the disclosure requirements. For consumer transactions, suppliers must be prepared to identify when generative AI is being used and to provide a disclosure if a consumer explicitly asks. This necessitates internal training for customer-facing personnel and the development of clear protocols for AI-driven interaction systems. For regulated occupations, the requirement for "prominent disclosures" in high-risk scenarios will likely lead to the development of standardized disclosure formats or prominent notices within digital interfaces or verbal communications. The safe harbor provision further shapes implementation by encouraging proactive, clear, and conspicuous disclosures, which businesses can adopt to demonstrate good faith and mitigate potential liability. The Act also specifies effective dates for various sections, indicating a phased implementation approach, with some provisions taking effect earlier than others to allow for preparatory adjustments by affected entities.
Monitoring and Evaluation
Monitoring and evaluation of Utah SB 226's effectiveness will primarily fall under the purview of the Division of Consumer Protection, which has been granted explicit enforcement and rulemaking authority. The Division's ongoing activities, such as investigating consumer complaints related to AI interactions, conducting market surveillance, and reviewing compliance with disclosure requirements, will serve as continuous monitoring mechanisms. Through its enforcement actions and the collection of data on violations, the Division will be able to assess the prevalence of non-compliance and identify areas where the regulations may need clarification or adjustment. The process of administrative rulemaking also provides an avenue for periodic review and updates to the implementing regulations, allowing the state to adapt to evolving AI technologies and their impact on consumers.
While the bill does not explicitly detail a formal, periodic evaluation report, the continuous nature of the Division's enforcement and regulatory development functions inherently includes an evaluative component. Feedback from businesses seeking to comply with the safe harbor provisions, as well as input from consumer advocacy groups, will likely inform the Division's understanding of the Act's practical impact. Furthermore, the extension of the Artificial Intelligence Policy Act's repeal date to July 1, 2027, suggests an ongoing commitment to assessing and refining Utah's overall AI policy landscape. This extended timeframe allows for a more comprehensive observation of the long-term effects of SB 226 and related AI legislation, facilitating future legislative amendments or new policy initiatives based on empirical evidence and stakeholder experience.
Penalties, Liability, and Appeals
Utah SB 226 establishes a clear framework for penalties, liability, and appeals related to violations of its provisions concerning generative artificial intelligence. The Act explicitly states that a violation of its chapter constitutes a violation of Subsection 13-11-4(1) of the Utah Code, which pertains to consumer protection. This linkage ensures that the robust enforcement mechanisms already in place for general consumer protection laws can be applied to AI-related infringements. The Division of Consumer Protection is empowered to bring actions in court to enforce the chapter, and in such actions, a court may impose significant penalties. Specifically, the Division can impose administrative fines of up to $2,500 per violation. These monetary penalties serve as a deterrent against non-compliance and provide a means to penalize entities that fail to adhere to the disclosure requirements or engage in deceptive practices involving AI.
Beyond administrative fines, the courts are granted broad authority to award various forms of relief in actions brought by the Division. This includes injunctive relief, which can compel entities to cease unlawful AI practices or to implement necessary disclosures. Courts may also award other reasonable and necessary relief, ensuring that the remedies are flexible enough to address the specific harms caused by AI-related violations. In cases where judgment or injunctive relief is granted to the Division, the court is mandated to award the Division its costs and reasonable attorney fees, further incentivizing enforcement actions and ensuring that the costs of litigation do not impede the Division's ability to protect consumers. The Act also clarifies that a person who violates an administrative or court order issued for a violation of the chapter may face further consequences, underscoring the seriousness with which these regulations are to be taken. While the bill outlines the penalties and enforcement avenues, the specifics of the appeals process would generally follow established procedures for appealing administrative decisions or court judgments within the Utah legal system.
Relationship to Other Instruments
Utah SB 226 operates within and significantly amends the existing legal framework governing artificial intelligence and consumer protection in the state. It primarily interacts with and modifies the Utah Artificial Intelligence Policy Act (UAIPA), which was initially enacted in March 2024. SB 226 narrows the scope of disclosure requirements previously mandated by the UAIPA, specifically for businesses using generative AI. Where the UAIPA broadly required disclosures, SB 226 clarifies that such disclosures are primarily triggered when a consumer or supplier explicitly and unambiguously asks whether AI is being used. This amendment reflects an effort to refine the regulatory burden and focus disclosures on instances of direct consumer inquiry or high-risk interactions.
Furthermore, SB 226 is closely related to another piece of legislation, Utah SB 332, which was signed concurrently. SB 332 is critical because it extends the repeal date of the Artificial Intelligence Policy Act from its original schedule of May 1, 2025, to July 1, 2027. This extension ensures that the foundational AI policy, along with the amendments introduced by SB 226, remains in effect for a longer period, providing stability and continuity in the state's approach to AI governance. The amendments also clarify that the provisions of SB 226 do not displace any other remedy or right authorized under state or federal laws, reinforcing that these AI-specific regulations are complementary to, rather than superseding of, broader consumer protection statutes and other applicable legal instruments. This ensures a comprehensive safety net for consumers, allowing for recourse under multiple legal frameworks where appropriate.
International Alignment
As a state-level legislative enactment within the United States, Utah SB 226 primarily focuses on regulating the deployment and use of artificial intelligence within the geographical and legal jurisdiction of the State of Utah. Therefore, the document does not explicitly address or aim for alignment with international AI regulations, standards, or frameworks. Its provisions are tailored to the specific consumer protection landscape and legislative priorities of Utah, reflecting a localized approach to AI governance. The bill's emphasis on consumer disclosures, liability in consumer transactions, and enforcement by a state-level Division of Consumer Protection underscores its domestic orientation.
While there is no direct international alignment, the principles underlying SB 226, such as transparency, consumer protection, and accountability in AI systems, resonate with broader global discussions and emerging regulatory trends in AI. Many international bodies and national governments are exploring similar concepts to ensure responsible AI development and deployment. However, the specific mechanisms, definitions, and enforcement structures of SB 226 are designed for the Utah context. Any indirect alignment would stem from a shared global concern for ethical and safe AI, rather than a deliberate effort to harmonize with specific international instruments. The bill's scope is inherently limited to the state's borders, and its impact on international AI policy is not a stated objective.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Bill Introduced in Senate | 2025-02-04 | Initial introduction of S.B. 226 in the Utah Senate. |
| Governor Signed | 2025-03-27 | The Governor signed the bill into law. |
| Effective Date of Enacted Sections | 2025-05-07 | Specific sections of the Act, including new enactments, become effective. |
| Extended Repeal Date of AI Policy Act | 2027-07-01 | The repeal date of the Artificial Intelligence Policy Act (amended by SB 226 and extended by SB 332) is set for this date. |
Sources and References
| Source | Type |
|---|---|
| Utah SB 226 - Artificial Intelligence Consumer Protection Amendments | legal |
| Enrolled Copy S.B. 226 - Utah Legislature | official |
| Utah SB 332 - Artificial Intelligence Revisions | legal |
Requirements for a company
What an organisation has to do under United States - Utah - AI Consumer Protection (SB 226), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
8- Disclose generative AI use in consumer transactions if an individual clearly asks.Suppliers using generative AI in consumer transactions.
- Prominently disclose generative AI use in high-risk interactions within regulated occupations.Individuals providing services in regulated occupations using generative AI.
- Ensure all generative AI uses comply with existing Utah consumer protection laws.All entities using generative AI.
- Make clear and conspicuous disclosures about generative AI use to qualify for safe harbor.Entities using generative AI in consumer interactions.
- Develop internal policies and train staff on AI disclosure requirements and definitions.Entities using generative AI in consumer transactions or regulated occupations.
- Understand the definition of 'generative artificial intelligence' to determine applicability.All entities potentially using AI.
- +2 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under United States - Utah - AI Consumer Protection (SB 226), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Suppliers using generative AI in consumer transactions. | Disclose generative AI use in consumer transactions if an individual clearly asks. “mandating that suppliers using generative AI to interact with individuals in consumer transactions must disclose the use of AI if the individual clearly and unambiguously asks or prompts about it.” | May 7, 2025 | Key Focus Areas | Critical |
| 2 | Individuals providing services in regulated occupations using generative AI. | Prominently disclose generative AI use in high-risk interactions within regulated occupations. “individuals providing services in regulated occupations are required to prominently disclose when generative AI is used in 'high-risk artificial intelligence interactions'” | May 7, 2025 | Key Focus Areas | Critical |
| 3 | All entities using generative AI. | Ensure all generative AI uses comply with existing Utah consumer protection laws. “The bill explicitly establishes liability for violations of consumer protection laws that involve artificial intelligence.” | May 7, 2025 | Key Focus Areas | Critical |
| 4 | Entities using generative AI in consumer interactions. | Make clear and conspicuous disclosures about generative AI use to qualify for safe harbor. “The Act introduces a safe harbor provision for entities that make clear and conspicuous disclosures about the use of generative AI at the outset of and throughout consumer interactions.” | May 7, 2025 | Key Focus Areas | Important |
| 5 | Entities using generative AI in consumer transactions or regulated occupations. | Develop internal policies and train staff on AI disclosure requirements and definitions. “This necessitates internal training for customer-facing personnel and the development of clear protocols for AI-driven interaction systems.” | May 7, 2025 | Implementation Framework | Important |
| 6 | All entities potentially using AI. | Understand the definition of 'generative artificial intelligence' to determine applicability. “The bill specifically defines 'generative artificial intelligence' as an AI system that is trained on data, designed to simulate human conversation through text, audio, or visuals, and generates non-scripted outputs with limited or no human oversight.” | May 7, 2025 | Definitions | Important |
| 7 | Individuals providing services in regulated occupations. | Understand the definition of 'high-risk artificial intelligence interaction' for regulated occupations. “Another critical term introduced or clarified by the Act is 'high-risk artificial intelligence interaction.'” | May 7, 2025 | Definitions | Important |
| 8 | Entities subject to the regulation. | Monitor for administrative rules and guidelines issued by the Division of Consumer Protection. “This Division is tasked with the critical responsibility of developing and promulgating administrative rules necessary for the effective execution of the Act's mandates.” | Ongoing | Implementation Framework | Important |
Related Regulations
More AI regulation in United States
AI regulation in United States: full overview
- Virginia High-Risk AI Bill Vetoed
- Virginia Patient AI Assistant Law
- Virginia AI Chatbot Minor Protection Act
- Virginia AI Regulation Summary
- United States - Virginia - AI Commission (SB 487)
- Vermont AI Neurological Rights in Health Act
- Vermont AI Mental Health Services Regulation
- United States - Vermont - AI Oversight and Liability (H.711)
© Regulations.AI using Gemini 2.5 Flash · updated on 5 Aug 2026