TwinEthosRequest access

Law

Utah AI Policy Act (Ch. 77)

Utah Division of Consumer Protection · Utah (US-UT) · 2 provisions encoded · verified against the official source as of 2026-08-30.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: le.utah.gov.

Binding law — in force

GenAI in a consumer transaction must disclose on a consumer's clear request

Utah Code 13-77-103(1) · official text · In force: applies since 7 May 2025 · Utah (US-UT)

A supplier using generative AI to interact with a consumer in a consumer transaction must disclose that the consumer is interacting with genAI (not a human) when the consumer clearly and unambiguously asks. Detect a consumer-facing genAI path with no mechanism to answer an AI-identity request. (A safe harbor exists for always-on disclosure at the outset and throughout.)

Who it applies to

  • Duty falls on: deployer
  • Suppliers using genAI in consumer transactions with Utah consumers. Reactive duty: disclosure required on a clear/unambiguous consumer request. Effective 2025-05-07.

The guard to add

Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.

A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Answer a consumer's clear request ('am I talking to a human?') by disclosing that they are interacting with generative AI; an always-on disclosure at the outset and throughout is the alternative the rule text names.

Example (Next.js + Vercel AI SDK (useChat)), before:

const { messages, input, handleSubmit } = useChat({ api: '/api/chat' });

After:

const { messages, input, handleSubmit } = useChat({
  api: '/api/chat',
  initialMessages: [{ id: 'ai-notice', role: 'assistant',
    content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message

Control: AI chat interaction without disclosure. The same guard addresses 16 items with binding law in 10 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id ut-ai-policy-act.genai-consumer-transaction-disclosure · review status: primary source derived

Binding law — in force

GenAI in a regulated occupation must proactively disclose it is AI in high-risk interactions

Utah Code 13-77-103(2)-(3) · official text · In force: applies since 7 May 2025 · Utah (US-UT)

An individual providing regulated-occupation services (licensed/state-certified) must prominently disclose, at the start of the interaction, that the person is interacting with generative AI — but only where the use is a 'high-risk AI interaction' (sensitive data like health/financial/biometric, or advice on financial/legal/medical/mental-health matters). Detect genAI on a regulated-occupation high-risk path without a start-of-interaction disclosure.

Who it applies to

  • Duty falls on: deployer, individual professional
  • Sectors: healthcare, essential services
  • Individuals in Utah regulated occupations (requiring a license/state certification) using genAI in high-risk interactions (sensitive data or significant personal-decision advice). Effective 2025-05-07 (amended 2026).
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Open each GenAI conversation on a licensed-professional service path with a prominent statement that the person is interacting with generative AI.

Mark which routes serve clients of a licensed or state-certified practice (clinical, legal, financial, mental-health advice) and, on those routes, have the session-start handler emit a prominent disclosure as the first thing the person sees, before any generated reply. Keep the wording in a constant the UI renders unchanged (e.g. 'You are interacting with generative AI, not a human professional'). The disclosure belongs to the conversation start of each such path, not to an account-signup screen or terms page that the person may have seen once.

Where it goes: 1 application source code, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Disclose prominently at the start of high-risk interactions: those involving sensitive data such as health, financial or biometric data, or advice on financial, legal, medical or mental-health matters.

Example (FastAPI + Anthropic SDK), before:

@app.post('/advisor/sessions')
def start_session(user=Depends(current_client)):
    return {'session_id': sessions.create(user.id), 'messages': []}

After:

GENAI_DISCLOSURE = 'You are interacting with generative AI, not a human professional.'

@app.post('/advisor/sessions')
def start_session(user=Depends(current_client)):
    sid = sessions.create(user.id)
    return {'session_id': sid,
            'messages': [{'role': 'assistant', 'content': GENAI_DISCLOSURE}]}
# later turns: client.messages.create(model=MODEL, max_tokens=1024, system=ADVISOR_PROMPT, messages=history)

Control: GenAI in regulated occupation without proactive disclosure. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id ut-ai-policy-act.genai-regulated-occupation-disclosure · review status: primary source derived