The Utah Artificial Intelligence Policy Act and Disclosure Duties


The Utah Artificial Intelligence Policy Act, enacted in 2023, introduces specific obligations for organisations using AI systems, particularly regarding transparency and disclosure. The Act applies to businesses operating in Utah or those offering AI services to Utah residents. It requires organisations to disclose when an AI system is being used to make decisions or generate content, especially in contexts such as employment, housing, or credit decisions. The focus is on protecting individuals from potential bias or lack of clarity in automated decision-making processes.
The disclosure duty under the Act is not merely about informing users but also about ensuring accountability. For example, a company using AI to screen job applications must notify candidates that their applications have been reviewed by an AI tool. This obligation helps maintain trust and allows individuals to understand how decisions affecting them are made. The Act also compels organisations to maintain records of AI usage, including data sources, decision criteria, and outcomes, to support auditability and compliance.
The Act places particular emphasis on high-risk AI systems, such as those used in law enforcement or healthcare. In these sectors, organisations must implement risk mitigation strategies and ensure that AI tools are not used in ways that could cause harm or discrimination. For instance, a healthcare provider using AI to diagnose patients must ensure that the system is accurate, fair, and reviewed regularly. The Act also requires that these systems undergo impact assessments to identify potential risks to individuals or groups.
The Utah AI Policy Act aligns with broader efforts to regulate AI systems at the state level, similar to initiatives in California and Colorado. Companies operating across multiple US states must now consider these varied frameworks when designing AI governance strategies. The Act’s disclosure requirements, combined with similar laws in other jurisdictions, complicate compliance efforts. For example, a US-based company with operations in California, Colorado, and Utah must ensure that its AI disclosures meet the standards of each state, which may differ in detail or scope.
The Act also introduces obligations for AI developers and vendors. These entities must provide documentation that explains how their AI systems operate, including any limitations or potential biases. This is particularly important for organisations that contract AI services from third-party providers. For example, a financial institution using an AI tool to assess creditworthiness must obtain detailed information from the vendor about the tool’s design, training data, and decision-making logic. This transparency helps ensure that AI systems are used responsibly and ethically.
The Act’s enforcement mechanism involves state regulators who have the authority to investigate complaints and impose penalties. Although the Act does not specify detailed penalties, similar frameworks in other US states indicate that violations could result in fines or operational restrictions. Companies must therefore take these obligations seriously and develop internal processes to ensure compliance. This includes training staff, updating policies, and conducting regular audits of AI usage.
The Utah AI Policy Act reflects a growing trend towards AI regulation at the state level, driven by concerns over fairness, transparency, and accountability. As AI systems become more embedded in daily operations, such laws play a key role in protecting individuals and ensuring responsible use. Companies must stay informed about these evolving frameworks and adapt their AI governance strategies accordingly. The Act’s focus on disclosure highlights the importance of clear communication with users and stakeholders, which is central to building trust in AI technologies.
The Act also underscores the importance of AI governance frameworks such as ISO/IEC 42001:2023. This international standard provides a structured approach to managing AI risks and ensuring compliance with legal and ethical requirements. Organisations that adopt this framework can demonstrate due diligence in their AI practices, which may be beneficial during regulatory scrutiny. The standard’s emphasis on risk management, data governance, and continuous improvement aligns with the principles underlying the Utah Act.
The Act’s provisions also have implications for organisations that operate internationally. Companies must ensure that their AI practices meet not only US state laws but also global regulations such as the EU AI Act. The EU AI Act’s Article 50 transparency duties, which apply from 2 August 2026, require machine-readable marking of generative AI systems. This compels organisations to maintain detailed records of AI usage, including data sources, training processes, and outputs. Companies must also ensure that these systems are properly identified and labelled, especially when they are used in content generation or decision-making processes.
The Utah AI Policy Act, combined with similar frameworks in other US states, highlights the increasing complexity of AI regulation. Companies must develop strategies that accommodate these diverse requirements. This involves creating flexible governance structures, implementing cross-functional compliance teams, and investing in AI literacy training for staff. The goal is to ensure that AI systems are not only effective but also aligned with legal and ethical standards. The Act’s focus on transparency and accountability makes these efforts essential for long-term success.
