← Blog

Utah AI Policy Act Compliance Checklist: 9 Tests for Current Disclosure Rules

Utah SB 226 replaced the original SB 149 consumer-facing provision with Chapter 13-75 in 2025. This nine-test checklist covers legal versioning, supplier and transaction scope, reactive consumer disclosure, high-risk regulated services, safe-harbor presentation, consumer-protection liability, complaint evidence, change control and HTTP operating records. Every item names an owner, evidence artifact and objective completion condition.

ByParminder Singh· Founder & CEO, DeepInspect Inc.
Compliance & Regulationcomplianceregulationai-complianceai-governanceauditpolicy-enforcement
Utah AI Policy Act Compliance Checklist: 9 Tests for Current Disclosure Rules

Utah's Senate Bill 149 created the Artificial Intelligence Policy Act in 2024. Senate Bill 226 then repealed the original consumer-facing section and enacted Utah Code Chapter 13-75 from 7 May 2025. The current rules distinguish reactive disclosure in consumer transactions, proactive disclosure for high-risk AI interactions in regulated services and a broader disclosure safe harbor.

This Utah AI Policy Act AI compliance checklist uses nine gradable tests. Each item has an owner, required evidence and completion condition. Legal should verify the current Utah Code and Division rules before sign-off because the 2025 bill authorizes further rulemaking on disclosure methods.

1. Pin the law version to the interaction date

An investigation into a 2024 exchange and one into a 2026 exchange can involve different operative language. SB 149 took effect on 1 May 2024. SB 226 moved the consumer-protection provisions into Chapter 75 effective 7 May 2025.

Owner: Legal and compliance operations.

Evidence: Interaction date, applicable bill or code version, legal analysis, reviewer and approval date.

Done when: Every in-scope service has a versioned rule sheet, and the complaint workflow chooses the legal version using the interaction timestamp rather than the current user interface.

2. Classify the supplier and consumer transaction

Chapter 75 defines supplier and consumer transaction through the Utah Consumer Sales Practices Act. Product labels such as “assistant” or “copilot” cannot replace the legal scope analysis.

Owner: Legal and the business service owner.

Evidence: Legal entity, product, Utah connection, transaction flow, supplier conclusion and excluded-use rationale.

Done when: Each consumer-facing AI feature has an approved scope record tied to a specific entity, service and release. Conditional rows identify the fact that changes the result.

3. Inventory generative AI interaction points

SB 226 defines generative AI around systems trained on data, designed to simulate human conversation through text, audio or visual communication, and producing non-scripted human-like outputs with limited or no human oversight.

Owner: Product and AI platform.

Evidence: Feature inventory, channel, model provider, endpoint, release version, owner and production state.

Done when: A route reconciliation finds every hosted-model endpoint used by the listed features, and each unexplained destination has an investigation ticket. Local models and vendor-embedded features receive separate inventory methods.

4. Test the reactive consumer disclosure

Section 13-75-103 requires disclosure when an individual in a consumer transaction clearly and unambiguously asks if AI is being used. The answer must identify generative AI rather than a human.

Owner: Product, legal and quality assurance.

Evidence: Trigger phrases, expected disclosure, channel tests, conversation capture, release hash and reviewer.

Done when: Positive cases using clear questions receive the approved answer, nearby ambiguous language follows the documented handling rule, and each result can be reproduced under the same release version.

5. Identify high-risk regulated services

The regulated-occupation branch applies when generative AI use constitutes a high-risk interaction. SB 226 includes sensitive health, financial or biometric information and personalized financial, legal, medical or mental-health advice that could reasonably inform significant personal decisions, plus applications defined by Division rule.

Owner: The licensed professional, legal, privacy and product.

Evidence: Occupation basis, licence or certification, service description, data classes, advice category, Division-rule check and legal conclusion.

Done when: Every regulated AI service has a reviewed high-risk decision. A conditional result names the data, advice or rule change that would move the service into scope.

6. Verify notice timing for regulated services

Section 13-75-103 places the regulated-service notice at the start of a verbal interaction and before a written interaction. It also preserves the requirements of the regulated occupation when services use generative AI.

Owner: The professional service owner and product.

Evidence: Approved wording, voice recording or interface capture, first-message sequence, accessibility test and release date.

Done when: A clean oral session begins with the approved disclosure and a clean written session shows it before the first AI-generated service message. The white notice card should sit above the transcript in the review capture.

7. Test safe-harbor presentation through the session

Section 13-75-104 provides a safe harbor from an enforcement action for violating the disclosure section when the AI clearly and conspicuously identifies itself at the outset and throughout covered interactions. The Division can specify forms and methods by rule.

Owner: Legal, product design and accessibility.

Evidence: Safe-harbor approval, opening state, continuing identifier states, channel matrix, Division-rule review and regression tests.

Done when: Every state transition preserves the approved identifier, including handoff, minimized windows, resumed sessions and error states. Legal records the rule version supporting the conclusion.

8. Prepare the complaint and liability file

Section 13-75-102 says AI involvement fails as a defense to statutes administered by the Division when the AI made the violative statement, undertook the act or furthered the violation. Section 13-75-105 establishes Division enforcement under the consumer-protection framework.

Owner: Legal and consumer operations, with product and security support.

Evidence: Complaint, full interaction, product representation, applicable disclosure branch, model request and response, human escalation, investigation and remediation.

Done when: A tabletop reconstructs one disputed session without relying on an engineer's memory. The saved collection query, timestamps and release references allow a second reviewer to repeat the result.

9. Join interface proof to HTTP operating evidence

Utah's disclosure rules focus on the consumer-facing interaction. HTTP operating records can substantiate model use, destination, policy and test outcomes, but the application owns what the individual saw and heard.

Owner: Product owns notice proof; AI platform and security own request-path records.

Evidence: Stable session and request IDs, notice version, model route, authenticated identity, policy version, outcome and integrity verification.

Done when: One selected interaction joins the interface capture to the exact model event and release. My opinion is that this join is the checklist's strongest engineering test because it catches teams preserving two immaculate evidence sets that share no common key.

The Utah AI Policy Act audit evidence guide explains how to package these artifacts for a complaint, safe-harbor review or retest.

DeepInspect

DeepInspect contributes to tests 3, 4, 8 and 9 for authenticated users or agents calling HTTP-based LLM endpoints. It evaluates application-supplied identity context, request classification, destination and policy before forwarding traffic, then creates a signed, tamper-evident per-decision record outside the calling application's write path.

Those records support route inventory, model-use corroboration, complaint scoping, policy retrieval and retests. The application must supply stable session and notice-version references if reviewers need to join a request to interface proof. DeepInspect leaves legal scope, regulated-occupation analysis, high-risk classification, notice presentation, safe-harbor design and Division correspondence with their named owners. Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Did SB 226 replace the entire Artificial Intelligence Policy Act?

SB 226 repealed the original Section 13-2-12 and enacted the consumer-protection rules in Chapter 13-75. It also extended the repeal date of the separate Artificial Intelligence Policy Act chapter referenced in the bill. Current disclosure analysis should use Chapter 75.

Is the general consumer disclosure proactive?

The Section 13-75-103 consumer-transaction rule is triggered by a clear and unambiguous question about AI use. High-risk generative AI interactions in regulated services receive proactive treatment. A broader opening and continuing disclosure pattern supports the safe harbor.

What evidence proves a written regulated-service disclosure?

Keep the approved notice, release version and a clean-session capture showing the notice before the first AI-generated service message. Add the session record and channel configuration so the reviewer can reproduce the sequence.

Does the safe harbor require a continuing identifier?

The enrolled SB 226 text describes disclosure at the outset and throughout the interaction. Product should test every state that can hide or replace the identifier, while legal checks current Division rules for approved forms and methods.

Does an HTTP log complete this checklist?

It completes only the request-path evidence fields. Scope, high-risk classification, professional requirements, consumer-facing timing, safe-harbor design and regulator communication remain with legal, product and licensed-service owners.