Utah S.B. 226 (Artificial Intelligence Consumer Protection Amendments), signed March 27, 2025 and effective May 7, 2025, replaced the Utah AI Policy Act's broad disclosure rule with a narrower generative-AI chapter, now Title 13, Chapter 77. A supplier using generative AI with a consumer must disclose that the individual is interacting with generative AI and not a human only when the individual clearly and unambiguously asks; licensed professionals must disclose proactively, verbally or in writing, in a high-risk interaction, defined to include the collection of health, financial or biometric data and financial, legal, medical or mental-health advice. It is no defense to a consumer-protection violation that generative AI made the statement, a safe harbor protects a system that discloses clearly at the outset and throughout, and the Division of Consumer Protection can fine up to $2,500 per violation. A companion bill, SB 332, signed March 25, 2025, extended the repeal date of the Utah AI Policy Act (Chapter 72) from May 1, 2025 to July 1, 2027.
OFFICIAL TEXT: le.utah.gov ↗ · IN FORCE · UTAH DIVISION OF CONSUMER PROTECTION
| Document | Utah SB 226 (2025) — S.B. 226 Artificial Intelligence Consumer Protection Amendments |
| Issued by | Utah — Division of Consumer Protection, Department of Commerce (administers and enforces the generative-AI disclosure chapter, Utah Code Title 13, Chapter 77), and the Office of Artificial Intelligence Policy (Artificial Intelligence Policy Act, Chapter 72: learning laboratory and regulatory mitigation agreements) |
| Type | Statute |
| Status | In force |
| Published | Mar 27, 2025 |
| Effective | May 7, 2025 |
| Applies to | Suppliers that use generative AI to interact with an individual in a consumer transaction (disclosure on request) and individuals providing services in occupations regulated by the Department of Commerce that require a license or state certification (proactive disclosure in a high-risk AI interaction). A bank's customer-facing generative AI is within the supplier rule; the occupation rule does not ordinarily describe a bank. Enforced by the Division of Consumer Protection through the Utah Consumer Sales Practices Act |
| Official source | le.utah.gov ↗ |
| Use cases | Customer-facing chatbots · Generative & agentic AI · Data & privacy · AI governance (general) |
What are the key points of Utah SB 226 (2025)?
- Section 13-77-101 (enacted as 13-75-101 in the enrolled bill): generative AI is an AI technology system that is trained on data, is designed to simulate human conversation with a consumer through text, audio or visual communication, and generates non-scripted outputs similar to a human's with limited or no human oversight; a 'high-risk artificial intelligence interaction' involves collection of health, financial or biometric data, or personalized advice that could reasonably be relied on for significant personal decisions, including financial advice or services, or other applications defined by division rule.
- Section 13-77-102: it is not a defense to the violation of any statute administered and enforced by the Division of Consumer Protection that generative AI made the violative statement, undertook the violative act, or was used in furtherance of it.
- Section 13-77-103(1): a supplier that uses generative AI to interact with an individual in connection with a consumer transaction shall disclose that the individual is interacting with generative AI and not a human if the individual asks or otherwise prompts the supplier; the request must be clear and unambiguous.
- Section 13-77-103(2)–(3): an individual providing services in a regulated occupation shall prominently disclose a generative AI interaction when it is a high-risk interaction, verbally at the start of a verbal interaction and in writing before a written interaction, and must still meet all requirements of the occupation.
- Section 13-77-104: a person is not subject to enforcement for violating Section 13-77-103 if the generative AI clearly and conspicuously discloses at the outset of the interaction, and throughout it, that it is generative AI, is not human, or is an AI assistant; the Division, in consultation with the Office of Artificial Intelligence Policy, may make rules on disclosure forms that do or do not satisfy the safe harbor.
- Section 13-77-105: a violation is a violation of Section 13-11-4(1), the Consumer Sales Practices Act's deceptive-act provision; the Division director may fine up to $2,500 per violation, a court may declare, enjoin, order disgorgement and fine up to $2,500, and violation of an order carries a civil penalty of up to $5,000 per violation. The Attorney General acts as counsel to the Division.
- Section 13-77-106 preserves other remedies under Utah and federal law. SB 226 repealed original Section 13-2-12 and amended Section 63I-2-213, but the repeal-date list in that section names only Title 13, Chapter 72, the AI Policy Act, not the disclosure chapter.
- SB 332 (Artificial Intelligence Revisions), signed March 25, 2025, amended Section 63I-2-213 to repeal Chapter 72 on July 1, 2027 instead of May 1, 2025; in 2026 HB 320 (signed March 18, 2026, effective May 6, 2026) amended Chapter 72's learning-laboratory provisions, and a 2026 amendment (2026 General Session, Chapter 95, effective May 6, 2026) updated cross-references in Section 13-77-101.
What did Utah SB 226 (2025) change for banks?
SB 226 narrowed Utah's 2024 disclosure rule: it is no longer enough that a person used generative AI in any act the Division administers, because the proactive duty now applies only to licensed professionals in high-risk interactions and other disclosure happens only when a consumer clearly asks. It added a safe harbor and a 'high-risk' definition that names financial data and financial advice, which are the bank-relevant cases. The no-defense principle and the penalties carried over, and SB 332 kept the Office's regulatory sandbox alive until July 1, 2027.
What does Utah SB 226 require of banks that use generative AI with customers?
Utah S.B. 226, effective May 7, 2025 and codified in Title 13, Chapter 77, requires a supplier that uses generative AI with a consumer to say so only when the consumer clearly and unambiguously asks whether they are dealing with a human or AI (Section 13-77-103(1)); it does not require an unprompted notice. It also provides that using generative AI is no defense to any consumer-protection violation (Section 13-77-102), so a bank answers for what its chatbot says. A bank gets a safe harbor if its generative AI clearly and conspicuously discloses at the outset and throughout the interaction that it is generative AI or not human (Section 13-77-104). The stricter proactive duty applies to individuals in occupations regulated by the Department of Commerce when the interaction is high-risk, which includes collection of financial data and financial advice. The Division of Consumer Protection can fine up to $2,500 per violation.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Section 13-77-101 — Definitions ↗ | Utah Division of Consumer Protection | Defines generative AI, 'high-risk artificial intelligence interaction' (collection of health, financial or biometric data; personalized advice that could be relied on for significant decisions, including financial advice), and 'regulated occupation' (licensed or certified by the Department of Commerce). | In force since May 7, 2025 |
| Section 13-77-102 — AI is no defense ↗ | Utah Division of Consumer Protection | It is not a defense to a violation of a statute the Division of Consumer Protection administers that generative AI made the statement, took the act, or was used in furtherance of the violation. | In force since May 7, 2025 |
| Section 13-77-103(1) — Disclosure on request ↗ | Utah Division of Consumer Protection | A supplier using generative AI in a consumer transaction must disclose that the individual is interacting with generative AI and not a human if the individual asks, in a clear and unambiguous request. | In force since May 7, 2025 |
| Section 13-77-103(2)–(3) — High-risk interactions in regulated occupations ↗ | Utah Division of Consumer Protection | An individual providing regulated-occupation services must prominently disclose generative AI use in a high-risk interaction, verbally at the start of a verbal interaction and in writing before a written one. | In force since May 7, 2025 |
| Section 13-77-104 — Safe harbor ↗ | Utah Division of Consumer Protection | No enforcement for violating Section 13-77-103 where the generative AI discloses at the outset and throughout that it is generative AI, not human, or an AI assistant; the Division may set by rule disclosure forms that do or do not qualify. | In force since May 7, 2025 |
| Section 13-77-105 — Enforcement and penalties ↗ | Utah Division of Consumer Protection | A violation is a deceptive act under Section 13-11-4(1); administrative and court fines up to $2,500 per violation, disgorgement and injunctions, and a $5,000 per-violation penalty for violating an order. | In force since May 7, 2025 |
| SB 226 Section 8 — Repeal of Section 13-2-12 | Utah Division of Consumer Protection | Repeals the SB 149 disclosure section, so the 2024 broad rule no longer applies. | From May 7, 2025 |
| SB 332 — Section 63I-2-213 repeal date ↗ | Utah Division of Consumer Protection | Extends the repeal date of Title 13, Chapter 72, the Artificial Intelligence Policy Act, to July 1, 2027; no new business duty. | Signed March 25, 2025 |
SB 149's disclosure section applied to any act the Division administers. SB 226 reduced the default to a disclosure on request, added a bright-line safe harbor that rewards proactive disclosure, and confined the unprompted duty to licensed occupations in a high-risk setting. A bank's chatbot that is clearly labelled as an AI assistant throughout the conversation is within the Section 13-77-104 safe harbor and need not parse each customer question.
The principal exposure for a bank is Section 13-77-102 read with Section 13-11-4(1). Because a violation of the AI chapter is a deceptive act under the Consumer Sales Practices Act, and because AI is no defense, an inaccurate or misleading chatbot statement about a product is attributed to the bank. Utah's Consumer Sales Practices Act excludes the credit terms of a transaction otherwise subject to it (Section 13-11-22(1)(d)), which limits its reach for loan pricing but not for other statements in a transaction. There is no Utah credit-underwriting AI rule; fair-lending exposure remains federal.
Beyond the disclosure rule, SB 226 and its companions show the direction: Utah chose enforcement through its consumer-protection division and a sandbox, rather than an impact-assessment regime. The Division may write rules on disclosure forms and on additional high-risk applications, and the Office of Artificial Intelligence Policy remains available for regulatory mitigation agreements until Chapter 72's scheduled repeal on July 1, 2027.
WHAT THIS MEANS IN PRACTICE
- Label customer-facing generative AI as an AI assistant at the start of every session and keep the label visible throughout; that is the Section 13-77-104 safe harbor and removes the need to judge whether a customer's question was clear and unambiguous.
- Make sure a human-handoff or 'are you a human?' intent is handled honestly by the bot; a clear request must get a truthful answer.
- Treat chatbot statements as the bank's own for deception purposes under Section 13-77-102; apply product-claim review and monitoring to AI-generated responses.
- If advisers in Utah-licensed occupations (individuals in occupations licensed by the Department of Commerce) use generative AI in high-risk interactions, build the verbal and written disclosure steps in Section 13-77-103(3).
- Watch for Division rules on disclosure form (Section 13-77-104(2)) and on additional high-risk interactions (Section 13-77-101(5)(c)); either could add specifics for financial services.
Does Utah SB 226 apply to banks?
Partly. A bank that uses generative AI to interact with a consumer in a consumer transaction is a 'supplier' under Section 13-77-103(1) and must disclose that it is AI if the consumer clearly asks. The proactive high-risk disclosure in Section 13-77-103(2) applies to individuals in occupations regulated by the Department of Commerce, which does not ordinarily describe a bank. Utah's Consumer Sales Practices Act also excludes the credit terms of a transaction.
When did Utah SB 226 take effect and what did it change?
SB 226 was signed March 27, 2025 and took effect May 7, 2025. It repealed the broader disclosure requirement of Section 13-2-12 from SB 149 and replaced it with Title 13, Chapter 77: disclosure on clear request, a safe harbor, a high-risk interaction rule for licensed professionals and the same $2,500 per-violation fine.
What is Utah SB 332?
SB 332 (Artificial Intelligence Revisions), signed March 25, 2025, extends the repeal date of the Utah Artificial Intelligence Policy Act (Title 13, Chapter 72) from May 1, 2025 to July 1, 2027 by amending Section 63I-2-213. It does not change any duty on businesses.
What are the penalties under Utah's generative AI disclosure law?
The Division of Consumer Protection director may impose an administrative fine of up to $2,500 per violation, and a court may fine up to $2,500 per violation, order disgorgement, and issue injunctions (Section 13-77-105). A person who violates an administrative or court order is subject to a civil penalty of up to $5,000 per violation.
| Date | Document | Status |
|---|---|---|
| Mar 13, 2024 | Utah AI Policy Act (SB 149) — S.B. 149 Artificial Intelligence Amendments (creating the Utah Artificial Intelligence Policy Act) | In force |
| Sep 28, 2026 | AB 1609 — Customer Service Chatbots (Right to Human Customer Service Act) | Final |
| Aug 11, 2026 | Colorado AG proposed ADMT rules — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing) | Comment period open |
| Jul 24, 2026 | Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) | In force |
| Jul 20, 2026 | Commission guidelines on AI Act Article 50 transparency — Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689 (AI Act) | In force |
| Jun 24, 2026 | RBI draft Guidance on Regulatory Principles for Model Risk Management — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments) | Proposed |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning