By
October 11, 2026
10 min read
What the Utah AI Policy Act Requires Before You Launch a Customer-Facing Chatbot
What the Utah AI Policy Act actually requires
The Utah AI Policy Act does not require every chatbot on every website to announce itself as a robot. It requires disclosure when the interaction touches health information, financial information, biometric data, or personalized advice, and it requires it without the customer having to ask. That's the current rule, and it's narrower than most of what gets written about it.
Utah passed the original version as S.B. 149 in March 2024, effective that May. It made Utah the first US state with a law specifically targeting consumer interactions with generative AI, a point confirmed by Skadden's client alert at the time. The original text set up an "on request" standard: if a customer asked whether they were talking to AI, you had to tell them.
That changed in 2025. S.B. 226 amended the law to flip the trigger from reactive to mandatory for a defined set of high-risk interactions, as Davis Polk's analysis lays out. If your chatbot discusses a customer's health, their finances, biometric data, or gives them individualized advice, you now have to disclose the AI's involvement up front. No one has to ask anymore. Outside those four categories, the lighter "on request" standard still applies.
The law also created a state Office of Artificial Intelligence Policy and an AI Learning Laboratory Program, a regulatory sandbox where businesses can test AI systems under temporary mitigation agreements with the state. Almost nobody writing about this law mentions the sandbox, which is a shame, because it's one of the more useful mechanisms for a company trying to ship something novel without guessing at how a regulator will read it later.
Who has to disclose, and when
The law names regulated occupations explicitly: anyone licensed in Utah as a health care provider, lawyer, accountant, or financial professional who uses generative AI to communicate with a client has obligations under the Act regardless of the four-category trigger. If you hold one of those licenses and you're deploying AI to talk to clients, treat disclosure as automatic, not conditional.
For everyone else, the question is whether the conversation falls into one of the mandatory-disclosure categories. A furniture retailer's order-status chatbot almost certainly doesn't. A chatbot that helps someone choose a health insurance plan, discusses loan terms, or gives a customer financial guidance almost certainly does. The line isn't the industry you're in; it's what the specific conversation is about.
"Clear and conspicuous" in practice means the disclosure has to be noticeable at the point of interaction, not buried in a terms-of-service link three clicks away. A line at the top of the chat window ("You're chatting with an AI assistant") or a spoken disclosure at the start of a voice call satisfies the intent. A footer disclaimer in 8-point gray text does not, even if it technically exists somewhere on the page.
Do I need to tell my customers they're talking to an AI chatbot?
If your bot touches health, financial, biometric, or personalized-advice territory, yes, every time, without being asked. If it doesn't, you only need to disclose when a customer specifically asks. That's the entire operational answer to the question most founders are actually trying to answer when they search this topic.
The practical trap is scope creep. A general customer-service bot that starts in the "no mandatory disclosure" bucket can drift into the mandatory bucket the moment someone asks it about their outstanding balance or their account's health benefits. If your agent can plausibly wander into those four categories during a normal conversation, build the disclosure in from the start rather than trying to detect the drift in real time.
The mental health chatbot rules under HB 452
If your product touches mental health in any way, the rules are stricter and the enforcement risk is higher. Utah's H.B. 452, passed in 2025, specifically targets AI mental health chatbots. It bans inserting undisclosed advertising into a conversation (no quietly recommending a sponsored product mid-session), and it prohibits selling or sharing a user's health data without their consent.
This matters beyond therapy apps. Any customer-facing agent that discusses symptoms, stress, medication, or wellbeing, even as a side function of a broader support bot, can trip this. It also sits directly on top of HIPAA if the entity or its business associates handle protected health information, and the two frameworks don't automatically overlap the way people assume. HIPAA governs who can access and transmit the data; HB 452 governs what you can do with it commercially and how transparent you have to be about the AI itself. We've written through what HIPAA-compliant AI actually requires beyond a signed BAA in more depth, and it's worth reading alongside this if health data touches your chatbot at all: what HIPAA-compliant AI actually requires.
Genta has built intake and case-management agents for healthcare and medical-legal clients where this exact overlap, consent, disclosure, and data handling, had to be designed into the architecture rather than patched in after launch. It's a different build when you start from "this conversation might contain regulated health data" versus retrofitting consent logging onto a chatbot that was never meant to touch it.
Utah isn't alone: the multistate disclosure wave
Utah was first, not last. California's SB 243 imposes its own disclosure trigger for companion chatbots: if a reasonable person could mistake the bot for a human, you have to disclose clearly and conspicuously, a standard summarized well by Regulations.ai. California's older BOT Act already required bot disclosure in commercial and political contexts. Illinois introduced SB 317 in 2026 with similar logic, and a federal AI Labeling Act proposal would apply disclosure requirements nationally if it ever passes.
The scale of this is easy to underestimate if you only track your own state. According to the Colorado legislature's own research citing NCSL data, at least 41 states introduced 247 AI-and-health bills between 2023 and 2025. That's not a Utah problem or a California problem. It's a pattern, and if your customer base extends beyond one state, "we're not based in Utah" is not a compliance plan.
We've covered two of the other major pieces of this patchwork in depth: Colorado's AI Act, the first comprehensive state AI law we tracked, and Texas's TRAIGA, which takes a lighter-touch approach than Colorado but still has teeth. The useful exercise for a multistate operator isn't picking the strictest law and building to it by accident. It's mapping which states your customers actually sit in and which triggers apply where, then building one disclosure architecture flexible enough to satisfy all of them.
What happens if you don't comply
Utah's Division of Consumer Protection can fine violators up to $2,500 per violation, and that climbs to $5,000 per violation if the Attorney General or a court gets involved. Courts can also order injunctive relief and force disgorgement of profits tied to the violation. Per-violation, not per-incident, matters here: a chatbot handling thousands of undisclosed health-related conversations a month isn't looking at one fine, it's looking at a multiplier.
And even if your state has no AI-specific statute at all, you're not in the clear. The FTC has pursued multiple enforcement actions against deceptive AI chatbot practices under Section 5 of the FTC Act's unfair-and-deceptive-practices authority, documented in the FTC's own AI use policy and in case summaries from firms tracking the agency's chatbot enforcement actions, including chatbots that gave false legal or financial advice without disclosing their nature. The FTC has also opened a 6(b) inquiry specifically into AI companion chatbots. "My state hasn't passed an AI law" has never meant "we have no exposure." It just means the exposure comes from a different statute.
Building disclosure into the agent, not bolting it on
The single biggest mistake we see is treating disclosure as a UI copy change made the week before launch. It isn't. Disclosure, consent logging, and data handling are architectural decisions, and retrofitting them after a chatbot is already live with real customer data flowing through it is a much more expensive and riskier project than building them in from the start. This is the same diagnosis-first instinct that shapes how Genta AI Solutions approaches every build: figure out what the system actually needs to do and what it's legally exposed to before a line of agent logic gets written, not after.
A practical checklist that holds up across Utah, California, and most of what's coming behind them:
Disclosure fires automatically the moment a conversation enters a regulated category (health, financial, biometric, personalized advice), not as a static message at the start of every chat regardless of content.
Every disclosure event gets logged with a timestamp, the triggering category, and the exact text shown to the user, so you can produce an audit trail if a regulator or plaintiff ever asks.
Consent for data use, especially health data under HB 452-style rules, is captured as a distinct event from the disclosure itself. Telling someone they're talking to AI is not the same as getting consent to use their health data commercially.
For regulated-industry deployments, data residency and retention policies are decided before the model is chosen, not after. If a client can't have their data touching a third-party model provider's training pipeline, that constrains your architecture from day one, which is part of why Genta runs self-hosted open-source models on a client's own infrastructure with zero data retention for regulated, data-sensitive work.
Voice agents get the same treatment as chat. A spoken disclosure at call start, logged the same way as a chat disclosure, closes a gap a lot of teams miss because they built their compliance checklist thinking only about text.
None of this requires exotic engineering. It requires deciding where disclosure logic lives in the system before the agent ships, and treating the audit trail as a first-class output of the system, not an afterthought you'd produce manually if someone ever asked.
What to ask an AI chatbot vendor before you sign
If you're buying a chatbot platform rather than building one, the disclosure and consent logic you just read about has to live somewhere, and it's worth confirming where before you sign. Ask whether the platform supports category-based disclosure triggers (health, financial, biometric, advice) out of the box, or whether that's a custom configuration you'll own. Ask whether consent events are logged separately from general conversation logs, and whether you can export that audit trail on demand. Ask where the underlying model runs, who has access to conversation data, and whether any of it is used for model training or sold to third parties, because that question sits right at the center of both HB 452 and most state privacy laws.
These are the same questions that belong in any AI vendor evaluation, not just a chatbot-specific one. We've laid out a fuller version of this in what to ask an AI vendor before you sign the contract, and it's worth running through before any customer-facing deployment, disclosure law or not.
If you're working through this decision, this is exactly what our Discovery phase maps out before anything gets built, and we're happy to compare notes.
Frequently asked questions
Do I have to tell customers they're talking to an AI chatbot?
In Utah, yes, automatically, if the conversation touches health, financial, biometric, or personalized-advice topics. Outside those categories, disclosure is only required if the customer asks. Other states, like California under SB 243, use a broader "could a reasonable person be fooled" standard, so the right answer depends on where your customers are.
What is the Utah AI Policy Act and who does it apply to?
It's Utah S.B. 149, effective May 2024, requiring disclosure of generative AI use in certain consumer interactions, amended in 2025 by S.B. 226. It applies to any business interacting with Utah consumers through AI, with stricter automatic obligations for licensed health, legal, accounting, and financial professionals.
Which US states require AI chatbot disclosure in 2026?
Utah and California currently have AI-specific chatbot disclosure statutes in force (SB 149/226 and SB 243, respectively). Illinois has similar legislation pending (SB 317), and a federal AI Labeling Act has been proposed. At least 41 states have introduced AI-and-health-related bills since 2023, so this list keeps growing.
What happens if my business doesn't comply with Utah's AI disclosure law?
The Utah Division of Consumer Protection can fine businesses up to $2,500 per violation, rising to $5,000 per violation if the Attorney General or a court is involved, plus possible injunctive relief and profit disgorgement. Separately, the FTC can pursue deceptive AI practices under Section 5 regardless of state law.
Does Utah's mental health chatbot law (HB 452) apply to my customer service bot?
It applies if your bot discusses mental health, wellbeing, or related topics in any capacity, not just dedicated therapy apps. It bans undisclosed advertising inserted into those conversations and prohibits selling or sharing a user's health data without consent, obligations that sit alongside, not instead of, HIPAA where applicable.
