← Blog

Utah AI Policy Act Controls Mapping: Trigger, Owner, Test and Evidence

Utah SB 226 replaced the original SB 149 consumer-facing AI provision with Chapter 13-75 in 2025. This mapping connects current scope, reactive disclosure, high-risk regulated-service notice, safe harbor, consumer-protection liability and enforcement response to accountable owners, implementation points, tests and evidence. Coverage is graded at the authenticated HTTP model boundary, with presentation and legal classification kept outside it.

ByParminder Singh· Founder & CEO, DeepInspect Inc.
Compliance & Regulationcomplianceregulationai-complianceai-governancepolicy-enforcementaudit
Utah AI Policy Act Controls Mapping: Trigger, Owner, Test and Evidence

Utah's AI disclosure control changes based on the interaction. A supplier answers after a clear consumer question. Professionals give an earlier notice when generative AI creates a high-risk interaction in regulated services. The separate safe harbor uses opening and continuing identification. One generic “AI disclosure” control misses those branches.

This Utah AI Policy Act AI controls mapping uses the current primary text. Senate Bill 149 created the Act effective 1 May 2024. Senate Bill 226 repealed the original consumer provision and enacted Chapter 13-75 effective 7 May 2025. I map objective, owner, implementation, test, evidence and coverage for the current rules.

Legal-version control

The objective is to apply the provision in force on the interaction date. A 2024 complaint can require the original SB 149 text, while current product controls should follow Chapter 75 and applicable Division rules.

Legal maintains the version register, while compliance operations implements date-based case selection. Test a session on each side of 7 May 2025 and verify that the complaint file selects the right source, definitions and disclosure branches. Evidence includes the timestamp, legal version, rule retrieval date and reviewer approval.

Gateway coverage is outside scope. Runtime timestamps provide a join key, but the legal-version decision remains a legal control.

Supplier and transaction-scope control

Chapter 75 incorporates supplier and consumer-transaction concepts from Utah consumer-protection law. The objective is to identify the entity and activity subject to the disclosure chapter before configuring technical rules.

Legal and the business owner classify the service. Product maintains the feature inventory. Test one Utah-facing flow by tracing the entity, product representation, transaction, channel and model-backed component. Evidence is the signed scope sheet and system record.

Coverage is partial for discovering observed model endpoints connected to a service. An HTTP gateway cannot decide the legal entity, consumer context or statutory role.

Generative-AI inventory control

SB 226 defines generative AI around a trained system designed to simulate human conversation through text, audio or visual communication and generating non-scripted human-like output with limited or no human oversight.

The AI platform owner inventories provider endpoints and product owns the conversational features. Reconcile the approved inventory with observed HTTP model traffic. Seed one approved and one unapproved hostname, then verify the unapproved destination receives a restrictive outcome and investigation ticket.

Coverage can be full for routed HTTP destination policy. Embedded vendor AI, local models and traffic bypassing the enforcement point require procurement, endpoint and network controls.

Reactive-disclosure control

Section 13-75-103 requires a supplier to disclose generative AI in a consumer transaction when the individual clearly and unambiguously asks if AI is being used. The objective is to detect the trigger and return approved wording.

Product owns conversational behavior, legal approves the trigger definition and quality assurance owns tests. Positive cases ask directly if the interaction is with AI or a human. Negative cases use nearby wording with a different purpose. Evidence contains the full conversation, expected result, release version and reviewer.

Request policy provides partial coverage by identifying a model call and, if explicitly designed, classifying a trigger phrase. The application remains responsible for delivering and displaying the approved response in context.

High-risk regulated-service control

The proactive branch applies to an individual providing regulated services when generative AI use constitutes a high-risk interaction. SB 226 includes sensitive health, financial or biometric information, specified personalized advice affecting significant personal decisions and applications set by Division rule.

The licensed-service owner and legal team classify the use. Privacy defines data classes, and product configures the channel notice. Test oral and written clean sessions, including the first AI-generated service message. Evidence combines occupation status, high-risk analysis, approved notice, timing capture and release.

Coverage is partial for data-class and route policy. Professional status, advice classification, Division-rule interpretation and consumer-facing timing sit outside the model request path.

Safe-harbor control

Section 13-75-104 provides protection against enforcement for violating the disclosure section when generative AI clearly and conspicuously identifies itself at the outset and throughout covered interactions. The Division may specify acceptable forms and methods.

Legal owns reliance on the safe harbor. Product design owns continuing presentation and accessibility owns perceptibility tests. Exercise resumed sessions, handoffs, compact layouts and error states. Evidence includes every sampled state, release hash, legal approval and rule version.

Gateway coverage is outside scope for presentation. An application-supplied disclosure-state value can support correlation, but the interface evidence must prove what the individual received.

Consumer-protection liability control

Section 13-75-102 prevents AI involvement from serving as a defense to a Division-administered statutory violation. The objective is to preserve the facts surrounding a disputed statement or act and route the complaint to accountable humans.

Legal owns the conclusion, consumer operations handles the case, product preserves the conversation and security retrieves model events. Test a seeded misleading statement through intake, evidence collection, escalation, correction and retest. The evidence package includes product representations, full exchange, model route, policy, reviewer and remediation.

Coverage is partial across this liability control. HTTP records can reconstruct a routed request and decision. Consumer harm, legal violation, downstream action and complaint resolution require separate evidence.

Enforcement-response control

Section 13-75-105 gives the Division of Consumer Protection administrative and court enforcement routes. The objective is a reproducible, scoped response rather than a collection assembled manually after the inquiry arrives.

Legal coordinates product, compliance, consumer operations and AI platform custodians. A tabletop starts with complaint UT-226-17, runs the saved collection query and ends with an indexed response plus clean retest. Evidence records custodians, hashes, export date and reviewer.

Coverage is partial because request records support affected-event search, policy retrieval and retesting. Legal submissions, interface artifacts, consumer remediation and Division communication remain outside the gateway.

Change-control and rule-monitoring control

SB 226 authorizes Division rules about safe-harbor disclosure forms and methods. Product changes can also alter notice timing, continuing identifiers, model routes and session joins.

Legal monitors rules and product governance controls releases. Every relevant change ticket should carry legal impact, disclosure regression, route test, owner and approval. Test a release that moves the notice component and confirm both visual timing and request-event joins survive.

Coverage is partial for detecting route and policy drift. Rule monitoring, interface review and release governance need legal and software-delivery controls.

Consolidated mapping

  • Version: Legal selects the operative text by interaction date. Runtime timestamps provide correlation only.
  • Scope: Legal and the service owner classify supplier and transaction status. Route observation supplies partial inventory evidence.
  • Inventory: AI platform reconciles approved and observed endpoints. Routed HTTP destination policy can provide full coverage.
  • Reactive disclosure: Product and legal test clear consumer questions. Gateway evidence is partial and presentation stays with the application.
  • High-risk services: Licensed owners, privacy and legal classify the service. Data-class policy supplies partial coverage.
  • Safe harbor: Legal and product prove opening and continuing identification. Gateway coverage is outside scope.
  • Liability: Legal and consumer operations investigate disputed statements or acts. Runtime reconstruction supplies partial evidence.
  • Enforcement: Legal coordinates a reproducible complaint response. Request search and retesting are partial.
  • Change control: Legal and product monitor rules and releases. Route drift evidence is partial.

A good map has visible handoffs. My opinion is that collapsing notice presentation and model traffic into one control would make both weaker. Put the white notice capture beside event UT-226-17; the shared session and release keys should connect them without pretending they are the same artifact.

DeepInspect

DeepInspect implements the authenticated HTTP model-traffic slice of this mapping. It evaluates application-supplied identity context, request classification, destination and policy before transmission, then creates a signed, tamper-evident per-decision record outside the calling application's write path.

That provides a testable point for model-route and data-class controls and creates evidence for complaint reconstruction, affected-request search, policy retrieval and retests. Stable application-supplied session and notice references are required to join those records to presentation proof. DeepInspect leaves legal scope, professional status, high-risk analysis, consumer-facing disclosure, safe-harbor reliance and Division communications with their accountable owners. Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Which Utah law should current controls use?

Use current Chapter 13-75 for interactions after its 7 May 2025 effective date, alongside current Division rules. Preserve SB 149 and historical code versions for earlier interactions because complaint evidence must match the law in force at the time.

Can one disclosure pattern cover every branch?

A broader opening and continuing disclosure may support the statutory safe harbor if its conditions are met. The underlying control map should still preserve the reactive consumer trigger, high-risk regulated-service branch and legal basis for safe-harbor reliance.

What does Full gateway coverage mean here?

Full means an authenticated HTTP request-path control can implement and test the mapped objective, such as blocking an unapproved model destination. It says nothing about consumer-facing notice presentation, legal classification or local model traffic.

Which prerequisite supports disclosure correlation?

The application must supply stable session, release and notice-version identifiers that can be joined to the model event. Without those keys, a request record proves model traffic occurred but fails to identify the interface state the consumer received.

Does the Utah Act require every request to be logged?

Chapter 75 contains no universal per-request logging command. Per-decision records are operating evidence that supports inventory, complaint scope, policy retrieval and retesting. The article labels them as implementation guidance.