AI Policy Wiki
Dashboard

Utah HB 276 — Digital Voyeurism Prevention Act + Digital Content Provenance Standards Act

high confidence · updated 2026-06-06

Utah HB 276 (Effective Jan 1, 2027) bundles two acts. The Digital Voyeurism Prevention Act (Ch. 72b) makes AI generation services and platforms civilly liable for non-consensual counterfeit intimate images, with safe harbor and heightened pleading. The Digital Content Provenance Standards Act (Ch. 72c) imposes C2PA-aligned obligations on capture device manufacturers, large online platforms (>2M MAU), and covered providers (>1M MAU generative AI systems).

Utah House Bill 276 ("Artificial Intelligence Modifications") is a state law that bundles two distinct acts into a single bill: the Digital Voyeurism Prevention Act and the Digital Content Provenance Standards Act. The chief sponsor was Ariel Defay in the House, with Kirk A. Cullimore as Senate sponsor. The Digital Voyeurism Prevention Act makes AI image-generation services and platforms civilly liable for distributing non-consensual counterfeit intimate images, with a safe harbor and a heightened pleading standard. The Digital Content Provenance Standards Act imposes C2PA-aligned content-provenance obligations on capture device manufacturers, large online platforms, and covered generative-AI providers. It is the first U.S. state law to combine an anti-deepfake regime with a comprehensive C2PA-aligned content-provenance regime in a single bill, it builds explicitly on the federal Take It Down Act (P.L. 119-12), and it preserves Section 230.

Status and effective dates

The law is codified in Utah Code Title 13, the Consumer Protection Code, as new Chapters 72b and 72c. Most provisions take effect January 1, 2027. The capture-device-manufacturer requirements apply only to capture devices produced for sale on or after January 1, 2028.

Chapter 72b: Digital Voyeurism Prevention Act

Definitions (§13-72b-101)

A "counterfeit intimate image" is defined as a "digital forgery" as that term is defined in the federal Take It Down Act. A "generation service" is a person operating an interactive computer service that enables users to generate intimate images, processes generation requests through service-controlled servers, and distributes generated intimate images to users; the definition places cloud-based image generators in scope and leaves on-device tools out of scope. "Covered platform" carries the same meaning as in Take It Down Act §3.

Generation service obligations (§13-72b-201)

A generation service may not distribute a counterfeit intimate image without first obtaining consent from the depicted individual. The required consent system must require affirmative consent before distribution, assure identity with reasonable accuracy, and maintain a record for at least 7 years. The service may not require disclosure of personally identifiable information beyond what is reasonably necessary to assure identity and obtain consent.

Civil liability for generation services (§13-72b-202)

Plaintiffs may recover actual damages (including emotional distress), punitive damages (if the conduct was willful, reckless, or malicious), and attorney fees and costs. Each distribution constitutes a separate violation. The statute of limitations runs to the later of 3 years from discovery or 10 years from the violation.

Safe harbor for generation services (§13-72b-203)

A generation service qualifies for the safe harbor if it does not hold itself out as providing services for non-consensual generation; maintains a written policy prohibiting non-consensual generation and distribution, together with reasonable safeguards and violation-response procedures; acts in accordance with that policy; publishes the policy and a general description of its safeguards (with technical details subject to redaction to prevent circumvention); maintains a consent system compliant with §13-72b-201(3); and takes prompt action upon notice. A generation service that categorically prevents intimate-image generation is exempt from the consent-system requirement. The safe harbor may be asserted by motion before trial.

Heightened pleading standard (§13-72b-204)

A complaint must plead with particularity facts establishing that the service does not qualify for the safe harbor; general or conclusory allegations are insufficient. Under a two-strike dismissal rule, if an amended complaint also fails this standard, the court shall dismiss with prejudice and award attorney fees to the defendant.

Covered platform obligations (§13-72b-301, -302, -303, -304, -305)

A covered platform may not knowingly allow distribution of a counterfeit intimate image without consent. It "knowingly allows" such distribution if it receives a notice under §13-72b-302 and then fails to comply with takedown. A 48-hour takedown is required upon receipt of notice, tracking the federal Take It Down Act, and the platform must also make reasonable efforts to identify and remove identical copies. Civil liability mirrors that for generation services. A safe harbor is available if the platform implemented compliant notice-and-removal procedures and acted in good faith, and the same heightened pleading standard applies.

Relationship to federal law (§13-72b-306)

The chapter does not expand or modify the federal Take It Down Act notice-and-takedown requirements. It also does not alter, modify, or limit Section 230 (47 U.S.C. §230), meaning Utah cannot impose liability on a covered platform for acting as the publisher or speaker of third-party content.

Chapter 72c: Digital Content Provenance Standards Act

Definitions (§13-72c-101)

"Compliant system provenance data" is system provenance data compliant with widely adopted specifications of an established standards-setting body, implicitly referencing the C2PA / Coalition for Content Provenance and Authenticity standards. A "covered provider" creates, codes, or produces a generative AI system with over 1,000,000 monthly active users or visitors that is publicly accessible in Utah, excluding internal-business-only systems. A "large online platform" is a public-facing social-media, mass-messaging, or search platform that distributes content to non-collaborator users and exceeded 2,000,000 unique monthly active users in the preceding 12 months. "System provenance data" is provenance data not reasonably associable with a particular user, containing either device, system, or service generation information or content authenticity information. The act distinguishes "latent" from "manifest" disclosure, primarily requiring latent disclosures — embedded but not necessarily perceptible to the human reader — which aligns with C2PA's metadata-embed approach.

Large online platform requirements (§13-72c-201)

A large online platform shall detect whether compliant system provenance data is embedded into or attached to content, provide a user interface to disclose the availability of provenance data, and allow users to inspect all available provenance data through the interface, by download, or via link. To the extent technically feasible, a platform may not knowingly strip compliant system provenance data or digital signatures from uploaded or distributed content. This anti-stripping prohibition converts what is a voluntary practice under the C2PA specification into a legal duty.

Capture device manufacturer requirements (§13-72c-202)

A capture device manufacturer shall include a latent disclosure in captured content conveying either the manufacturer name or digital signatures sufficient to prove device-type origin, together with the time and date of creation or alteration. The user may be given the option to disable the disclosure. These requirements apply to capture devices produced for sale on or after January 1, 2028.

Covered provider requirements (§13-72c-203)

A covered provider shall include a latent disclosure in image, video, or audio content (or combinations thereof) created or substantially modified by its generative AI system, conveying the time and date of creation and either the provider identity or digital signatures sufficient to prove generative-AI origin. The disclosures must be consistent with widely accepted industry standards, in the C2PA mold.

Government provenance standards (§63A-16-215)

The Utah CIO shall make rules establishing provenance-data standards for digital content on state-agency websites that facilitate transactions or service delivery, where the CIO determines that fraudulent or misleading media could harm Utah residents.

Enforcement (§13-72c-301)

The Division of Consumer Protection administers and enforces the chapter. It may impose an administrative fine of up to $2,500 per violation, a court may impose up to $2,500 per violation, and a civil penalty of up to $5,000 per violation may apply for violation of an administrative or court order. The Attorney General may collect on behalf of the division. A court may order disgorgement, injunctive relief, and reasonable attorney fees, costs, and investigative fees.

Comparative position

HB 276 is the first U.S. state law to bundle an anti-deepfake regime and a content-provenance regime in a single bill. It builds on the federal Take It Down Act and on the federal No Fakes Act discussion. The 1,000,000-MAU threshold for covered providers scopes the provenance obligations to frontier-lab consumer products — Anthropic, OpenAI, Google, Meta, and xAI all qualify — while excluding small startups. The 2,000,000-MAU threshold for large online platforms scopes the platform obligations to major social-media and search platforms, including Meta, X, YouTube, TikTok, Reddit, Pinterest, Google Search, and Bing. The anti-stripping prohibition is the first U.S. state law making C2PA preservation a legal duty rather than an industry voluntary practice. The combination of heightened pleading, safe harbor, and 48-hour takedown closely tracks the federal Take It Down Act framework.

HB 276 is a companion to the 2026 wave of state deepfake, CSAM, and AI-generated-content laws (State Deepfake Statutes (MN, WA, TX, CA), California's CCPA Regulations on AI training data). It is not part of the chatbot/companion-AI cluster (Idaho SB 1297 — Conversational AI Safety Act, Nebraska LB525 — Conversational AI Safety Act + Agricultural Data Privacy Act, Oregon SB 1546 — Artificial Intelligence Companions, Washington ESHB 2225 — AI Companion Chatbots, California SB 243 — Companion Chatbots, Tennessee SB 1580 / HB 1470 — AI Mental-Health Professional Impersonation Prohibition), which addresses a different harm vector — conversational manipulation rather than visual deepfakes.

Relationships

Source

Primary text: Raw Sources/Utah Digital Voyeurism Prevention Act and Digital Content Provenance Standards Act (HB 276).md (source_class: foundational).