The Utah Artificial Intelligence Policy Act (UAIPA), enacted as Senate Bill 149 ("Artificial Intelligence Amendments") in the 2024 General Session, is the first US state statute to target generative AI specifically rather than automated decision systems more broadly. It amends Utah's Consumer Protection Act to impose generative-AI disclosure duties, establishes the Office of Artificial Intelligence Policy within the Department of Commerce, and creates the Artificial Intelligence Learning Laboratory Program, a regulatory sandbox. Commentators have described it as the first state generative-AI consumer-protection law and the first state-level AI regulatory sandbox and Office of AI Policy.
Status and timeline
SB 149 was sponsored by Sen. Kirk Cullimore (R) in the Senate and Rep. Jefferson Moss (R) in the House. Governor Spencer Cox signed it on March 13, 2024, and it took effect on May 1, 2024. The Act included a 2025 sunset on the Office of AI Policy's statutory mandate, which has since been extended.
In 2025, after practitioner concerns about the breadth of the 2024 disclosure duty, the Legislature amended the Act through SB 226 and SB 332, effective May 2025. These amendments narrowed the on-request disclosure duty so that it applies only when a reasonable person would believe they were interacting with a human; tightened the regulated-occupation always-on disclosure to enumerated mental-health-adjacent services; added a separate Mental Health Chatbot Act requiring stricter disclosures for mental-health chatbots, addressing a concern that converges with the gap California SB 243 — Companion Chatbots addresses in California; and extended the sunset for the Office of AI Policy and the Learning Laboratory.
Scope and definitions
The Act applies to any person or entity using generative AI that interacts with consumers in Utah. It is the first comprehensive US state statute directed at generative AI as such, as distinct from "automated decision systems." The 2024 text contained three main pieces: amendments to Utah's Consumer Protection Act imposing disclosure duties for generative AI; establishment of the Office of Artificial Intelligence Policy (OAIP) within the Department of Commerce; and creation of the Artificial Intelligence Learning Laboratory Program, a regulatory sandbox.
Key provisions
Generative-AI disclosure duty
The Act sets two tiers of disclosure. Persons in regulated occupations — licensed mental health, legal, financial, and other state-licensed professions — using generative AI to interact with consumers must proactively and prominently disclose the AI's use: at the start of the interaction for oral or video communication, and at the beginning of written communication. All other businesses using generative AI must clearly and conspicuously disclose that the consumer is interacting with generative AI if asked or prompted by the consumer; the 2024 version made this an on-request baseline consumer-protection duty.
Liability
A person using generative AI that violates the Consumer Protection Act cannot use the AI as a defense; the person is responsible for the AI's statements and actions as if the person had made them directly. Using AI does not diminish consumer-protection liability.
Office of Artificial Intelligence Policy
The OAIP sits within the Utah Department of Commerce. Its mandate is to analyze AI risks and benefits, coordinate with industry, administer the Learning Laboratory, recommend legislation, and publish reports. It is led by a director and reports to the Legislature's Business and Labor Interim Committee.
AI Learning Laboratory Program (regulatory sandbox)
The Learning Laboratory is the first US statutory AI-specific regulatory sandbox. Participants may apply for regulatory mitigation agreements: temporary waivers of specific Utah statutory or regulatory provisions, granted in exchange for disclosure, monitoring, and consumer protections. Mitigation agreements run up to 12 months and are extendable, shorter than the 36-month sandbox in Texas's TRAIGA (Texas Responsible AI Governance Act (TRAIGA / HB 149) — Source Summary). Participants must disclose to consumers that they are in the sandbox. The OAIP curates participants, publishes findings, and recommends permanent regulatory changes.
Enforcement and penalties
The on-request disclosure duty carries an administrative fine of up to $2,500 per violation. If the Attorney General enforces, a civil penalty of up to $5,000 per violation is available, along with actual damages.
Comparison with other state legislation
| Law | Approach | Year | Scope |
|---|---|---|---|
| Utah SB 149 | GenAI disclosure + AG liability + sandbox | 2024 (first US state GenAI law) | Generative AI in consumer interactions |
| Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) | Duty of care for deployers in high-risk decisions | 2024 | Automated decision-making generally |
| Texas Responsible AI Governance Act (TRAIGA / HB 149) — Source Summary | Intent-based prohibitions + 36-month sandbox | 2025 | AI generally, with intent-gated prohibitions |
| California SB 53 — Transparency in Frontier AI Act | Frontier developer transparency | 2025 | Frontier AI models |
| New York RAISE Act (S. 8828) | Frontier developer safety plans | 2025 | Frontier AI models |
| California AI Transparency Act (SB 942) | Watermarking + detection for GenAI providers | 2024 | Large GenAI services |
| California AB 3030 (Healthcare AI Disclosure) | Healthcare GenAI disclaimer | 2024 | Healthcare communications |
| California SB 896 (Generative AI Accountability Act) | State-government GenAI governance | 2024 | California state agencies |
| Illinois SB 3444 — Artificial Intelligence Safety Act | Developer immunity safe harbor | 2026 | Frontier developers |
SB 149 is the first-in-time US state GenAI consumer-protection law and has been referenced as a template in Texas TRAIGA (sandbox), California SB 942 (GenAI-targeted scope), and state-government AI orders. As the first state generative-AI statute, it predates the California GenAI package and the EU AI Act's application deadline, and it established the first state-level AI regulatory sandbox and the first Office of AI Policy at the US state executive-branch level. Commentary has noted it as a red-state precedent: a Republican governor and Republican-dominated legislature enacting a consumer-protection-flavored AI statute, context cited in discussions of later Texas TRAIGA design and Virginia HB 2094 veto dynamics. It is frequently cited in federal-preemption debates as a light-touch model, offered as evidence that state AI regulation need not be burdensome.
The Utah and Texas sandboxes differ along several dimensions:
| Dimension | Utah OAIP Sandbox | Texas Responsible AI Governance Act (TRAIGA / HB 149) — Source Summary Sandbox |
|---|---|---|
| Duration | Up to 12 months | Up to 36 months |
| Waived provisions | Administratively agreed | Statutory waiver, not over prohibited uses |
| Administering body | OAIP (Dept. of Commerce) | Texas AG + Advisory Council |
| Consumer disclosure required | Yes | Yes |
| First-mover | Yes (2024) | Second (2025) |
The Utah sandbox preceded the Texas TRAIGA sandbox and has been described as its template.
Reactions and debates
Practitioner commentary raised several concerns about the 2024 text. Critics argued the original on-request disclosure duty was broad enough to require nearly every chatbot, autocomplete, and AI-assisted search response to disclose on user request, which they characterized as largely unworkable; the 2025 amendments walked this back. The initial regulated-occupations provision was said to capture a wide range of licensed professions, including real estate and cosmetology, for which generative-AI disclosure was argued to add limited consumer value. Some commentators argued the no-defense clause, holding a person liable as if they had made the statement themselves, may over-penalize good-faith use of third-party AI tools whose behavior the user cannot fully control, a concern also raised in AI LEAD Act (S. 2937) debates. On sandbox transparency, observers noted that while mitigation agreements are published, trade-secret redactions can limit public accountability for which regulations were waived and why.
Relationships
- related: Texas Responsible AI Governance Act (TRAIGA / HB 149) — Source Summary — sandbox template; red-state comparator
- related: Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) — contrasting duty-of-care model
- related: California AI Transparency Act (SB 942), California AB 3030 (Healthcare AI Disclosure), California SB 896 (Generative AI Accountability Act) — contemporaneous California GenAI package
- related: California SB 243 — Companion Chatbots — converging mental-health chatbot concern
- related: US AI Regulatory Approaches Compared — adds first-state GenAI dimension
- related: Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race
Sources
- Bill page: https://le.utah.gov/~2024/bills/static/SB0149.html
- Manatt (Mar 2024); ByteBack Law (Mar 2024); Greenberg Traurig (Apr 2024); IAPP; Future of Privacy Forum "Chatbots in Check" (2025); Online and On Point practitioner guide to 2025 amendments