Utah H.B. 276 (2026: digital voyeurism, content provenance)
State of Utah (Division of Consumer Protection for chapter 13-72c) · Utah (US-UT) · 4 provisions encoded · verified against the official source as of 2026-10-04.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Sources last verified 4 Oct 2026; each provision states how.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
None of the 4 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 2.
Audit standard
4 of 4 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
5 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
2026.10.05 (5 Oct 2026): 4 provisions added
Each data release records which provisions changed; the full list is on Changes.
Binding law — not yet in force or stayed
Capture devices sold in Utah from 2028 embed a latent disclosure in captured content (Utah Digital Content Provenance Standards Act)
Utah Code 13-72c-202 (H.B. 276 (2026), Section 17) · official text · Enacted, not yet applying: applies from 1 Jan 2028 · Utah (US-UT)
For capture devices (cameras, phones with a camera or microphone, voice recorders) a manufacturer produces for sale in Utah on or after 2028-01-01, the manufacturer must include a latent disclosure in captured content conveying the manufacturer's name or digital signatures sufficient to prove whether the content was created using a type of capture device, and the time and date of creation or alteration, to the extent technically feasible and compliant with widely adopted standards; users may be given the option to disable it (Utah Code 13-72c-101, 13-72c-202). Detect device firmware or manufacturer camera apps that save captures with no provenance manifest, or ship the setting off.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Jan 2028
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Provenance embedded by the image signal processor or a vendor camera HAL outside the repository
Native code that writes files through platform APIs not named here
Applies only to a capture device manufacturer's devices produced for sale in Utah on or after 2028-01-01; a web or third-party app that records media is not a capture device. The statute allows a user option to disable…
Who it applies to
Duty falls on: provider
Systems covered: limited risk
Manufacturers of capture devices produced for sale in Utah on or after 2028-01-01 (13-72c-202(4)); the chapter takes effect 2027-01-01. Only to the extent technically feasible and compliant with widely adopted specifications of an established standards-setting body; the manufacturer may let users disable the disclosure.
Not covered:
Persons exclusively engaged in the assembly of a capture device are not capture device manufacturers (13-72c-101(3)(b))
The guard to add
Embed a signed C2PA manifest or equivalent latent disclosure in generated or captured media when it is created, and do not distribute systems or files that lack it.
Where media is created (the generation handler after images.generate or a diffusion pipeline, or the capture pipeline in device firmware or camera app), build a provenance manifest stating who and what produced it (provider or manufacturer, system or device name and version, timestamp, unique id) and sign and embed it (c2pa.Builder with builder.sign, c2patool, c2pa-node) before the file is saved, uploaded, or returned. Later re-encode steps preserve the manifest. Where the product distributes generative systems rather than media (a model or weights hosting platform), the publish or listing step checks that each system declares support for latent disclosure and blocks publication otherwise.
Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts, 14 user-facing text.
What this provision adds:
The disclosure conveys the manufacturer's name or digital signatures sufficient to prove the content came from a type of capture device, and the time and date of creation or alteration; a user option to disable it is allowed.
Rule id ut-hb276.capture-device-latent-disclosure · review status: primary source derived
Binding law — not yet in force or stayed
Large generative AI providers embed a latent disclosure in AI-generated images, video and audio (Utah Digital Content Provenance Standards Act)
Utah Code 13-72c-203 (H.B. 276 (2026), Section 18) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Utah (US-UT)
From 2027-01-01, a covered provider (a person that creates, codes or otherwise produces a generative AI system with over 1,000,000 monthly visitors or users that is publicly accessible in Utah) must include a latent disclosure in image, video or audio content its system creates or substantially modifies, consistent with widely accepted industry standards, conveying, to the extent technically feasible and reasonable, the time and date of creation or alteration and either the capture device manufacturer's name or digital signatures sufficient to prove whether a generative AI system created or substantially altered it, directly or through a link to a permanent website (Utah Code 13-72c-101, 13-72c-203). Detect media-generation code that writes or serves output with no C2PA manifest or watermark.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Jan 2027
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Provider-side marking stripped by a later re-encode
Provenance added by a separate media service
Only covered providers (over 1,000,000 monthly visitors or users, publicly accessible in Utah) are in scope; provenance added by the model vendor counts only if it survives later re-encoding.
Who it applies to
Duty falls on: provider
Covered providers: generative AI systems with over 1,000,000 monthly visitors or users, publicly accessible in Utah, for image, video and audio content they create or substantially modify. Applies from 2027-01-01, to the extent technically feasible and reasonable and consistent with widely accepted industry standards. How users are counted, and whether an application built on another company's model is itself a covered provider, need human determination.
Not covered:
A generative AI system used exclusively for the person's internal business operations and not made publicly accessible (13-72c-101(5)(b))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Embed a signed C2PA manifest or equivalent latent disclosure in generated or captured media when it is created, and do not distribute systems or files that lack it.
Where media is created (the generation handler after images.generate or a diffusion pipeline, or the capture pipeline in device firmware or camera app), build a provenance manifest stating who and what produced it (provider or manufacturer, system or device name and version, timestamp, unique id) and sign and embed it (c2pa.Builder with builder.sign, c2patool, c2pa-node) before the file is saved, uploaded, or returned. Later re-encode steps preserve the manifest. Where the product distributes generative systems rather than media (a model or weights hosting platform), the publish or listing step checks that each system declares support for latent disclosure and blocks publication otherwise.
Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts, 14 user-facing text.
What this provision adds:
The latent disclosure conveys the time and date of creation or alteration and digital signatures sufficient to prove whether a generative AI system created or substantially altered the content, directly or through a link to a permanent website.
Rule id ut-hb276.genai-latent-disclosure · review status: primary source derived
Binding law — not yet in force or stayed
AI image services verify the depicted person's consent before distributing an intimate image of them (Utah Digital Voyeurism Prevention Act)
Utah Code 13-72b-201 (H.B. 276 (2026), Section 3) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Utah (US-UT)
From 2027-01-01, a generation service (an interactive computer service that lets users generate intimate images with artificial intelligence on servers it controls and distributes them to users) may not distribute a counterfeit intimate image without first obtaining the consent of the identifiable individual depicted. It must run a consent system that requires that individual to affirmatively consent before distribution, assures the identity of the person consenting with reasonable accuracy, and keeps a record of the consent for at least seven years, asking for no more personal information than that needs; consent is specific to the image, given before generation and revocable (Utah Code 13-72b-101, 13-72b-201). Detect intimate or explicit image generation paths with no check of the depicted person's verified consent.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Jan 2027
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Consent collected and verified by a separate identity service
Intimate generation enabled by a model or vendor setting outside the repository
A service that categorically blocks intimate output (input and output classifiers that refuse it) needs no consent system for the safe harbor; confirm the block before reporting.
Who it applies to
Duty falls on: operator, provider
Generation services: operators of interactive computer services that let users generate intimate images through AI on servers the operator controls and distribute them to users (13-72b-101(7)). Applies from 2027-01-01. A service whose written policy and technical safeguards categorically prevent intimate images needs no consent system to qualify for the safe harbor (13-72b-203(3)). The terms borrowed from the TAKE IT DOWN Act and 13-72-101 are not captured; whether a general image generator that blocks sexual content is a generation service is for counsel.
Not covered:
Services that process image-generation requests solely on the user's local device are not generation services (13-72b-101(7)(b))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Classify prompts, uploads, and outputs for sexual content and minors on every image, video, or audio generation path, refuse sexual edits of real people, and keep a misuse-report route.
Layered safeguards around every generation or edit call: an input check on the prompt and any uploaded photo (moderation sexual and sexual/minors categories, or Azure AI Content Safety Sexual) that refuses sexualized requests involving an identifiable person's upload and anything involving minors; the model's own safety filter left on (no safety_checker=None, enable_safety_checker false, or a high safety_tolerance); and an output classifier plus CSAM hash matching (for example PhotoDNA) before anything is returned or stored. Nudification or clothes-removal features are not offered. A report-abuse endpoint feeds reviewed cases into the blocklist and guardrail configuration, with a reporting workflow (such as the NCMEC CyberTipline) for confirmed CSAM.
Where it goes: 1 application source code, 6 API calls and integrations, 8 model configuration, 9 AI output handling.
What this provision adds:
The consent comes from the identifiable individual depicted, is specific to the image, given before generation and revocable, with the consenting person's identity assured with reasonable accuracy.
Keep each consent record for at least seven years, and ask for no more personal information than identity assurance and valid consent need.
Example (FastAPI + OpenAI SDK (images.edit)), before:
Rule id ut-hb276.generation-service-intimate-image-consent-system · review status: primary source derived
Binding law — not yet in force or stayed
Large online platforms detect, show and keep provenance data in distributed content (Utah Digital Content Provenance Standards Act)
Utah Code 13-72c-201 (H.B. 276 (2026), Section 16) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Utah (US-UT)
From 2027-01-01, a large online platform (a public-facing social media platform, mass messaging platform or stand-alone search engine that distributes content to users who did not create it and exceeded 2,000,000 unique monthly users in the preceding 12 months) must detect whether compliant system provenance data is embedded in or attached to content it distributes, provide a user interface disclosing that provenance data is available, and let users inspect it in the interface, by download or through a link; to the extent technically feasible it may not knowingly strip standards-compliant system provenance data or digital signatures from uploaded or distributed content (Utah Code 13-72c-101, 13-72c-201). Detect upload and media pipelines that strip metadata or distribute uploads without reading provenance.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Jan 2027
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Re-encoding (Pillow save, cv2.imwrite, sharp, libvips) drops embedded manifests without any explicit strip call; confirm with a round-trip test on a signed sample
Stripping EXIF GPS for privacy while keeping the C2PA manifest is compliant; confirm what is removed. Only large online platforms (more than 2,000,000 unique monthly users) are in scope.
Provenance read in a separate ingest service
1 more known limit in the data release.
Who it applies to
Duty falls on: operator
Systems covered: limited risk
Large online platforms (more than 2,000,000 unique monthly users in the preceding 12 months; public social media, mass messaging or stand-alone search) distributing content to Utah users. Applies from 2027-01-01; the duty not to strip provenance applies to the extent technically feasible. Excludes broadband internet access and telecommunications services.
Not covered:
Broadband internet access services as defined in 47 C.F.R. 8.1(b) (13-72c-101(8)(b)(i))
Telecommunications services as defined in 47 U.S.C. 153 (13-72c-101(8)(b)(ii))
The guard to add
Read embedded C2PA provenance on upload, preserve it through media processing, and show users a Content Credentials indicator with a way to inspect the data.
In the upload or ingest handler, read embedded provenance (c2pa.Reader, c2pa-node, @contentauth/c2pa-web, or a c2patool report) and store the result with the media record: whether credentials are present, the generating system or capture device, and signature validity. Transcoding and thumbnail steps do not strip metadata (no -strip, exiftool -all=, -map_metadata -1, piexif.remove); the signed original is kept so its manifest stays inspectable. The post or media render component shows a badge stating whether provenance is available and what it says, with an inspect panel or link to the full provenance data.
Where it goes: 9 AI output handling, 1 application source code, 14 user-facing text.
What this provision adds:
Let users inspect all available compliant system provenance data in the platform's interface, by downloading it, or through a link to it on a website or another application.
Rule id ut-hb276.large-platform-provenance-detection-and-display · review status: primary source derived
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.