TwinEthosRequest access

Catalog

Utah HB 452 (mental health chatbots, Utah Code 13-72a)

Utah Division of Consumer Protection · pack 0.3.1 · verified against the official source as of 2026-09-27.

Binding law — in force

Ads inside mental health chatbot conversations must be labeled as ads, with sponsorships disclosed (Utah HB 452)

Utah Code 13-72a-202(1) lets a mental health chatbot advertise a specific product or service inside a conversation only if the chatbot marks it clearly and conspicuously as an advertisement and discloses any sponsorship, business affiliation, or promotion agreement the supplier has with a third party. A bare product plug inside a supportive reply is the pattern it targets; pointing the user to a licensed professional is not advertising under 202(3). Detect sponsored or affiliate content injected into chatbot replies without an ad label and a sponsorship or affiliation disclosure, or instructions telling the model to hide that a recommendation is paid.

ut-hb452.in-conversation-ad-disclosure · Utah Code 13-72a-202(1) · official source · jurisdictions: US-UT

Binding law — in force

Mental health chatbots must disclose they are AI, not human, before access, after 7 days away, and when asked (Utah HB 452)

Utah's mental health chatbot law (Utah Code 13-72a-203) makes the supplier have the chatbot tell Utah users, clearly and conspicuously, that it is AI technology and not a person. The notice has three triggers: before the user can use any feature, again at the start of an interaction when the user has not used the chatbot in the previous seven days, and whenever the user asks or prompts about whether AI is involved. Detect a mental health chatbot with no pre-access AI notice, no re-disclosure after a seven-day gap, no truthful answer path for 'am I talking to a person?', or instructions telling the bot to hide that it is AI.

ut-hb452.mental-health-chatbot-ai-disclosure · Utah Code 13-72a-203(1)-(2) · official source · jurisdictions: US-UT

Binding law — in force

Mental health chatbot suppliers must file and follow a written safety policy to claim Utah's licensing-law affirmative defense (Utah HB 452)

Utah Code 58-60-118, enacted by HB 452, gives the supplier of a mental health chatbot an affirmative defense in an administrative or civil action for unlawful or unprofessional conduct under Utah's professional-licensing law (58-1-501(1) or (2)). It is a safe harbor, not a freestanding duty: no supplier has to use it, but it is available only if the supplier proves four things. First, a written policy it created, maintains and implements that states what the chatbot is for and what it can and cannot do, and describes fifteen procedures, among them involving licensed therapists in development and review, testing before launch and regularly after that output is no riskier than therapy with a licensed therapist, a way for users to report harmful interactions, risk-of-harm protocols and a real-time response to acute risk of physical harm, regular objective safety reviews, making sure users know they are talking to AI and understand its limits, ranking user safety above engagement or profit, preventing discriminatory treatment, and meeting the HIPAA privacy and security rules as if it were a covered entity along with Utah's chatbot consumer-protection sections. Second, documentation of the foundation models, training data, health-privacy compliance, user-data practices, and accuracy, reliability, fairness and safety work. Third, the policy filed with the Division of Professional Licensing. Fourth, compliance with the filed policy when the alleged violation occurred. The defense does not stop the division from suing and does not make the chatbot a licensed therapist. This rule encodes the defense's conditions as its obligation. Detect a mental health chatbot with no written policy covering those elements, no development documentation or filing record, or no in-product harm reporting, real-time crisis response, or AI and limitations disclosure.

ut-hb452.mental-health-chatbot-safe-harbor-policy · Utah Code 58-60-118(2) · official source · jurisdictions: US-UT

Binding law — in force

Mental health chatbots must not use what users type to choose, target, or tailor ads (Utah HB 452)

Under Utah Code 13-72a-202(2), a supplier may not use what a Utah user tells its mental health chatbot to decide whether to show the user an ad (ads for the chatbot itself excepted), to choose which product, service, or category to advertise, or to shape how an ad is presented. Recommending that the user seek help from a licensed professional, even a named one, stays allowed. Detect conversation text, or topics and interests a model extracts from it, feeding ad selection, ad-server targeting keys, or ad personalization.

ut-hb452.no-ad-targeting-on-user-input · Utah Code 13-72a-202(2) · official source · jurisdictions: US-UT

Binding law — in force

Mental health chatbots must not sell or share users' input or health information with third parties (Utah HB 452)

Utah Code 13-72a-201 bars a mental health chatbot supplier from selling to, or sharing with, any third party either a Utah user's individually identifiable health information or anything the user types or says to the chatbot. Health information, though not raw user input, may still go to a health care provider that requests it with the user's consent, to the user's health plan at the user's request, or to a contracted party when needed for the chatbot to work, provided both sides follow HIPAA privacy and security rules as if they were a covered entity and business associate. Detect conversation content or health data flowing to analytics, advertising, data-broker, CRM, or other third-party endpoints, and health data going to a contracted vendor without HIPAA-equivalent terms.

ut-hb452.no-sale-or-sharing-of-user-input · Utah Code 13-72a-201(1) · official source · jurisdictions: US-UT