diff --git a/MANIFEST.yaml b/MANIFEST.yaml index 77a5696e..4ee49d15 100644 --- a/MANIFEST.yaml +++ b/MANIFEST.yaml @@ -128,7 +128,7 @@ files: - path: package.json role: config - hash: sha256:45d3460c2f22d32ff645353a145c93783cd6a6152398ca85f45a862d3d1bcede + hash: sha256:b22e0dcdcd2e45a3f232b450795cb65c32c4a58723423f456071bfb288c009b7 note: package.json - path: package-lock.json @@ -333,7 +333,7 @@ files: - path: data/examples/obligations/disclose-genai-high-risk-proactive.md role: obligation - hash: sha256:894ec6c5333740656a3f50a3dec3cdb95ceeb60642a95c225a2fe9d8e51823f5 + hash: sha256:f1ee01115a55072a4a046b49af6a81c109b4f0ffba49e6e6df58d775b25ca302 note: data/examples/obligations/disclose-genai-high-risk-proactive.md - path: data/examples/obligations/disclose-genai-on-first-session.md @@ -343,7 +343,7 @@ files: - path: data/examples/obligations/disclose-genai-on-request.md role: obligation - hash: sha256:975530c0feb4bacd2989f3e1494c8f9cbe61dd4bbb1569c866490c6de88d514a + hash: sha256:24d7c8e63e37d24678f5225b2d0c97b16f2bbea97e2fda7df8c9deeda1ef8c92 note: data/examples/obligations/disclose-genai-on-request.md - path: data/examples/obligations/elizachat-phased-rollout.md @@ -1038,7 +1038,7 @@ files: - path: tests/source-admission.test.js role: code - hash: sha256:10be9419f4d32940c9988fed0e13edd48fdb0d81b456989b80794d89b6b0c163 + hash: sha256:e4fcbb61cf703c1dbcaf9b10c01feb50f548dfc3ac797b5ec3c717aeec3af5aa note: Source admission policy and producer-gate regressions - path: tests/publication-state.test.js @@ -1058,7 +1058,7 @@ files: - path: tests/of-evidence-inputs.test.js role: code - hash: sha256:1e604a0fb0f847f796d655245a431333e412da9f94e1f01e96c38818323b084c + hash: sha256:1321a92efb7d004456d7190ff24b5600c444d7df7b49d2b4b08d28ef70bf84f4 note: Per-kind native evidence input and review-boundary regressions - path: tests/colorado-order24.test.js @@ -1165,3 +1165,23 @@ files: role: evidence hash: sha256:d1a7ac6297492ffc889ad5cb611d3dd6e087161d29e4763a19ea884983fb1fc6 note: Utah statute enrolled-copy source review receipt (SB 149, SB 226, SB 332, HB 320) + + - path: tests/sb226-r1.test.js + role: code + hash: sha256:ba4f4636bad329be363c84d09c840cfe62a3fd89ec107025bddff21056a41c38 + note: SB226 R1 retained-source and admission regressions + + - path: ops/evidence/sb226-r1-native-delta-2026-10-02.diff + role: evidence + hash: sha256:526f22e19f1f05130c16f8cc057849c245a481e88bb5ce5019e1e850b6000e59 + note: Independently reviewed SB226 R1 native definition delta + + - path: ops/evidence/sb226-r1-fingerprint-comparison-2026-10-02.json + role: evidence + hash: sha256:5160025a28388f121161cac0c7d8c8b208a99872d5710d6bb85f37ef618c1d23 + note: Parent-accepted exact two-record provenance-only fingerprint comparison + + - path: ops/evidence/sb226-r1-local-repair-2026-10-02.md + role: evidence + hash: sha256:6d6bbc43b88d1ca9510466460e092bd6fd9484d3344919e810fc5d8259f09322 + note: Scoped SB226 R1 owner repair receipt; instrument Summary remains gated diff --git a/data/admission/receipts.json b/data/admission/receipts.json index 05040906..3da1d050 100644 --- a/data/admission/receipts.json +++ b/data/admission/receipts.json @@ -5490,6 +5490,356 @@ ] } } + }, + "data/examples/obligations/disclose-genai-on-request.md": { + "record_sha256": "df3231b4a2111975e8de105d84a2fa0d4f5d1b8b32ffb3f0aab9ee12622931a5", + "baseline_sha256": "2255b8372e20bccbf1f6b054201add8cda3e519dd4aded5ac492e91cc7c56d0c", + "whole_record": { + "before_sha256": "2255b8372e20bccbf1f6b054201add8cda3e519dd4aded5ac492e91cc7c56d0c", + "after_sha256": "df3231b4a2111975e8de105d84a2fa0d4f5d1b8b32ffb3f0aab9ee12622931a5" + }, + "review": { + "actor_type": "agent", + "actor": "Codex (PubLedge isolated SB226 R1 local repair)", + "reviewed_at": "2026-10-02T02:25:24Z", + "decision": "source-consistency-reviewed", + "scope": "R1 on-request disclosure definition only, against immutable retained 2025 enrolled SB 226. Exact changed-unit agent self-review, not independent or human acceptance. No current-law, acquisition-date, human verification, stable-ID, controlled-role or effective-date renewal.", + "packet_sha256": "ae850f903e66d27eac95d560533460f50cea40532afb8f15ab6d5c6c41e9b98a" + }, + "unresolved": [ + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." + ], + "evidence": { + "request": { + "official_url": "https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf", + "snapshot_path": "data/admission/sources/utah-sb226/SB0226-enrolled.txt", + "snapshot_sha256": "088cb7315787b8f1a2c999ab3cdf9527b10eae034d032c7912ad6530441f08d7", + "original": { + "path": "data/admission/sources/utah-sb226/SB0226-enrolled.pdf", + "sha256": "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + }, + "acquisition": "retained_snapshot", + "document_id": "Utah SB 226 (2025)", + "document_title": "Enrolled Copy S.B. 226 Artificial Intelligence Consumer Protection Amendments", + "issuing_body": "Utah State Legislature", + "document_type": "enacted legislation", + "version": "2025 General Session enrolled copy", + "locator": "2025 enrolled SB 226, section3, 13-75-103(1), printed lines98-105", + "excerpt": " 98 (1)(a) A supplier that uses generative artificial intelligence to interact with an individual\n 99 in connection with a consumer transaction shall disclose to the individual that the\n100 individual is interacting with generative artificial intelligence and not a human, if the\n101 individual asks or otherwise prompts the supplier about whether artificial intelligence\n102 is being used.\n103 (b) The individual's prompt or question under Subsection (1)(a) must be a clear and\n104 unambiguous request to determine whether the interaction is with a human or with\n105 artificial intelligence.", + "identity_excerpts": [ + "Artificial Intelligence Consumer Protection Amendments" + ] + }, + "safe_harbor": { + "official_url": "https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf", + "snapshot_path": "data/admission/sources/utah-sb226/SB0226-enrolled.txt", + "snapshot_sha256": "088cb7315787b8f1a2c999ab3cdf9527b10eae034d032c7912ad6530441f08d7", + "original": { + "path": "data/admission/sources/utah-sb226/SB0226-enrolled.pdf", + "sha256": "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + }, + "acquisition": "retained_snapshot", + "document_id": "Utah SB 226 (2025)", + "document_title": "Enrolled Copy S.B. 226 Artificial Intelligence Consumer Protection Amendments", + "issuing_body": "Utah State Legislature", + "document_type": "enacted legislation", + "version": "2025 General Session enrolled copy", + "locator": "2025 enrolled SB 226, section4, 13-75-104(1)-(2), printed lines118-131", + "excerpt": "118 (1) A person is not subject to an enforcement action for violating Section 13-75-103 if the\n119 person's generative artificial intelligence clearly and conspicuously discloses:\n120 (a) at the outset of any interaction with an individual in connection with:\n121 (i) a consumer transaction; or\n122 (ii) the provision of regulated services; and\n123 (b) throughout the interaction that it:\n124 (i) is generative artificial intelligence;\n125 (ii) is not human; or\n126 (iii) is an artificial intelligence assistant.\n127 (2) In accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act, the\n128 division in consultation with the office, may make rules specifying forms and methods\n129 of disclosure that:\n\n -4-\n\f Enrolled Copy S.B. 226\n\n\n130 (a) satisfy the requirements of Subsection (1); or\n131 (b) do not satisfy the requirements of Subsection (1).", + "identity_excerpts": [ + "Artificial Intelligence Consumer Protection Amendments" + ] + }, + "other_remedies": { + "official_url": "https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf", + "snapshot_path": "data/admission/sources/utah-sb226/SB0226-enrolled.txt", + "snapshot_sha256": "088cb7315787b8f1a2c999ab3cdf9527b10eae034d032c7912ad6530441f08d7", + "original": { + "path": "data/admission/sources/utah-sb226/SB0226-enrolled.pdf", + "sha256": "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + }, + "acquisition": "retained_snapshot", + "document_id": "Utah SB 226 (2025)", + "document_title": "Enrolled Copy S.B. 226 Artificial Intelligence Consumer Protection Amendments", + "issuing_body": "Utah State Legislature", + "document_type": "enacted legislation", + "version": "2025 General Session enrolled copy", + "locator": "2025 enrolled SB 226, section6, 13-75-106, printed lines164-168", + "excerpt": "164 Section 6. Section 13-75-106 is enacted to read:\n165 13-75-106 (Effective 05/07/25). Scope.\n166 This chapter does not displace any other remedy or right authorized under:\n167 (1) the laws of this state; or\n168 (2) federal law.", + "identity_excerpts": [ + "Artificial Intelligence Consumer Protection Amendments" + ] + } + }, + "units": { + "section:Summary/text": { + "before_sha256": "6e76466ade1af9e1a58ffd826b71be002f75a33af355f935c8761f6b42d1131d", + "after_sha256": "99252ac805966d2f651f4383a49a5e90cfe759f5d3dd0e47d9d5a517f14943b3", + "candidate_content": "A supplier that uses generative artificial intelligence to interact with an individual in connection with a consumer transaction must disclose that the individual is interacting with generative artificial intelligence and not a human if the individual asks or otherwise prompts the supplier about whether artificial intelligence is being used. The prompt or question must be a clear and unambiguous request to determine whether the interaction is with a human or with artificial intelligence (§13-75-103(1)).\n\nThe separate §13-75-104(1) safe harbor concerns enforcement actions for violating §13-75-103 only. It applies if the person's generative artificial intelligence clearly and conspicuously discloses, at the outset and throughout any interaction with an individual in connection with a consumer transaction or the provision of regulated services, that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms, not substitutes for the conjunctive on-request content in §13-75-103(1). The safe harbor has no request prerequisite and does not eliminate other state or federal remedies (§13-75-106).\n\nThese locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. The incorporated supplier and consumer-transaction definitions (§13-11-3) and current disclosure rules under §13-75-104(2) are outside this retained-source review.", + "reason": "Preserve supplier, transaction and qualifying-request scope; distinguish conjunctive GenAI-and-not-human disclosure from the alternative safe-harbor forms, section103-only relief and preserved other remedies; qualify enrolled-version locators.", + "qualifications": { + "scope": "13-75-103(1), 13-75-104 and 13-75-106 in the retained 2025 enrolled act; consumer transaction for the request duty, consumer transaction or regulated services for safe harbor.", + "exceptions": "Safe-harbor alternatives and conditions remain distinct from the request conjunction. Current rules, imported definitions and live codification are unvalidated; other remedies and R3 civil/criminal content are unchanged.", + "time": "Retained 2025 enrolled version only. Existing human review, last_verified and effective dates and actual raw acquisition dates are unchanged; the agent review timestamp is not a new retrieval or currentness date." + }, + "evidence": [ + "request", + "safe_harbor", + "other_remedies" + ] + }, + "section:What Counts/text": { + "before_sha256": "ba02fd1adb67f091584789370c7cf6e03fcb25776079cc86174ae5aa752586a4", + "after_sha256": "ec08b19cec7c97b8af218f624fb3ecf0bb3d25c99bbef14b5e7788f70dd633a8", + "candidate_content": "- For the on-request duty, the supplier discloses both generative artificial intelligence and not a human in response to the qualifying question or prompt in a consumer transaction\n- For the separate safe harbor, the person's GenAI clearly and conspicuously discloses any one of the three statutory alternatives at the outset and throughout the qualifying interaction: generative artificial intelligence, not human, or an artificial intelligence assistant\n- The safe-harbor not-human alternative does not require the literal word \"AI\"; the statutory clarity, conspicuousness, context and timing conditions still apply", + "reason": "Preserve supplier, transaction and qualifying-request scope; distinguish conjunctive GenAI-and-not-human disclosure from the alternative safe-harbor forms, section103-only relief and preserved other remedies; qualify enrolled-version locators.", + "qualifications": { + "scope": "13-75-103(1), 13-75-104 and 13-75-106 in the retained 2025 enrolled act; consumer transaction for the request duty, consumer transaction or regulated services for safe harbor.", + "exceptions": "Safe-harbor alternatives and conditions remain distinct from the request conjunction. Current rules, imported definitions and live codification are unvalidated; other remedies and R3 civil/criminal content are unchanged.", + "time": "Retained 2025 enrolled version only. Existing human review, last_verified and effective dates and actual raw acquisition dates are unchanged; the agent review timestamp is not a new retrieval or currentness date." + }, + "evidence": [ + "request", + "safe_harbor", + "other_remedies" + ] + }, + "section:What Does Not Count/text": { + "before_sha256": "4aabc90e66c01db310b5860b51d3a9913426cc8ca15a0b59d9bdcedd39d16805", + "after_sha256": "8413c29cadf59328ed20609ac9d212aa78dbfe2b7585bd32b808df17b18b82c8", + "candidate_content": "- Requiring the individual to infer GenAI use from context instead of responding to the qualifying request\n- Treating a not-human-only response as the complete §13-75-103(1) disclosure, rather than distinguishing the separate safe-harbor alternative\n- Treating a buried notice or an ambiguous label such as \"smart assistant\" or \"automated helper\" as sufficient without establishing the safe harbor's clear-and-conspicuous disclosure conditions\n- Providing a safe-harbor notice only at the outset without disclosure throughout the interaction\n- Requiring a specific magic phrase when the individual has already made a clear and unambiguous qualifying request\n- Treating the safe harbor as immunity from violations or remedies outside §13-75-103", + "reason": "Preserve supplier, transaction and qualifying-request scope; distinguish conjunctive GenAI-and-not-human disclosure from the alternative safe-harbor forms, section103-only relief and preserved other remedies; qualify enrolled-version locators.", + "qualifications": { + "scope": "13-75-103(1), 13-75-104 and 13-75-106 in the retained 2025 enrolled act; consumer transaction for the request duty, consumer transaction or regulated services for safe harbor.", + "exceptions": "Safe-harbor alternatives and conditions remain distinct from the request conjunction. Current rules, imported definitions and live codification are unvalidated; other remedies and R3 civil/criminal content are unchanged.", + "time": "Retained 2025 enrolled version only. Existing human review, last_verified and effective dates and actual raw acquisition dates are unchanged; the agent review timestamp is not a new retrieval or currentness date." + }, + "evidence": [ + "request", + "safe_harbor", + "other_remedies" + ] + }, + "section:Statute Anchors/text": { + "before_sha256": "dc0cd6e1b860d566aa7887597bf8bad323d50532fcc3355863fde3d22acf2d2d", + "after_sha256": "09353ce679ad2a29128fe12ea44651d816429279151ce8dc70588beb7d40a60d", + "candidate_content": "- Retained 2025 enrolled SB 226, §13-75-103(1), printed lines 98-105: supplier, transaction, request and conjunctive disclosure content\n- Retained 2025 enrolled SB 226, §13-75-104(1)-(2), printed lines 118-131: separate section103-only safe harbor and disclosure-rule authority\n- Retained 2025 enrolled SB 226, §13-75-106, printed lines 164-168: other state and federal remedies preserved", + "reason": "Preserve supplier, transaction and qualifying-request scope; distinguish conjunctive GenAI-and-not-human disclosure from the alternative safe-harbor forms, section103-only relief and preserved other remedies; qualify enrolled-version locators.", + "qualifications": { + "scope": "13-75-103(1), 13-75-104 and 13-75-106 in the retained 2025 enrolled act; consumer transaction for the request duty, consumer transaction or regulated services for safe harbor.", + "exceptions": "Safe-harbor alternatives and conditions remain distinct from the request conjunction. Current rules, imported definitions and live codification are unvalidated; other remedies and R3 civil/criminal content are unchanged.", + "time": "Retained 2025 enrolled version only. Existing human review, last_verified and effective dates and actual raw acquisition dates are unchanged; the agent review timestamp is not a new retrieval or currentness date." + }, + "evidence": [ + "request", + "safe_harbor", + "other_remedies" + ] + } + } + }, + "data/examples/obligations/disclose-genai-high-risk-proactive.md": { + "record_sha256": "189f4253b204692369145bf206f26cb66d414488405e0d4509edee0e4c57a9d3", + "baseline_sha256": "16769df863c540985bf05faefbfab94efb1882a1398d65eca9a16ec41f313ba2", + "whole_record": { + "before_sha256": "16769df863c540985bf05faefbfab94efb1882a1398d65eca9a16ec41f313ba2", + "after_sha256": "189f4253b204692369145bf206f26cb66d414488405e0d4509edee0e4c57a9d3" + }, + "review": { + "actor_type": "agent", + "actor": "Codex (PubLedge isolated SB226 R1 local repair)", + "reviewed_at": "2026-10-02T02:25:24Z", + "decision": "source-consistency-reviewed", + "scope": "R1 high-risk regulated-services disclosure definition only, against immutable retained 2025 enrolled SB 226. Exact changed-unit agent self-review, not independent or human acceptance. No current-law, acquisition-date, human verification, stable-ID, controlled-role or effective-date renewal.", + "packet_sha256": "53dc6fff3ee933e85a8596578c3985f836252418b30dc6025349ed3ebdb586bb" + }, + "unresolved": [ + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." + ], + "evidence": { + "high_risk": { + "official_url": "https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf", + "snapshot_path": "data/admission/sources/utah-sb226/SB0226-enrolled.txt", + "snapshot_sha256": "088cb7315787b8f1a2c999ab3cdf9527b10eae034d032c7912ad6530441f08d7", + "original": { + "path": "data/admission/sources/utah-sb226/SB0226-enrolled.pdf", + "sha256": "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + }, + "acquisition": "retained_snapshot", + "document_id": "Utah SB 226 (2025)", + "document_title": "Enrolled Copy S.B. 226 Artificial Intelligence Consumer Protection Amendments", + "issuing_body": "Utah State Legislature", + "document_type": "enacted legislation", + "version": "2025 General Session enrolled copy", + "locator": "2025 enrolled SB 226, section1, 13-75-101(5), printed lines54-67", + "excerpt": "54 (5) \"High-risk artificial intelligence interaction\" means an interaction with generative\n55 artificial intelligence that involves:\n56 (a) the collection of sensitive personal information, including:\n57 (i) health data;\n58 (ii) financial data; or\n59 (iii) biometric data;\n60 (b) the provision of personalized recommendations, advice, or information that could\n61 reasonably be relied upon to make significant personal decisions, including the\n\n -2-\n\f Enrolled Copy S.B. 226\n\n\n62 provision of:\n63 (i) financial advice or services;\n64 (ii) legal advice or services;\n65 (iii) medical advice or services; or\n66 (iv) mental health advice or services; or\n67 (c) other applications as defined by division rule.", + "identity_excerpts": [ + "Artificial Intelligence Consumer Protection Amendments" + ] + }, + "occupation": { + "official_url": "https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf", + "snapshot_path": "data/admission/sources/utah-sb226/SB0226-enrolled.txt", + "snapshot_sha256": "088cb7315787b8f1a2c999ab3cdf9527b10eae034d032c7912ad6530441f08d7", + "original": { + "path": "data/admission/sources/utah-sb226/SB0226-enrolled.pdf", + "sha256": "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + }, + "acquisition": "retained_snapshot", + "document_id": "Utah SB 226 (2025)", + "document_title": "Enrolled Copy S.B. 226 Artificial Intelligence Consumer Protection Amendments", + "issuing_body": "Utah State Legislature", + "document_type": "enacted legislation", + "version": "2025 General Session enrolled copy", + "locator": "2025 enrolled SB 226, section1, 13-75-101(8), printed lines75-78", + "excerpt": "75 (8) \"Regulated occupation\" means an occupation that:\n76 (a) is regulated by the Department of Commerce; and\n77 (b) requires an individual to obtain a license or state certification to practice the\n78 occupation.", + "identity_excerpts": [ + "Artificial Intelligence Consumer Protection Amendments" + ] + }, + "regulated_disclosure": { + "official_url": "https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf", + "snapshot_path": "data/admission/sources/utah-sb226/SB0226-enrolled.txt", + "snapshot_sha256": "088cb7315787b8f1a2c999ab3cdf9527b10eae034d032c7912ad6530441f08d7", + "original": { + "path": "data/admission/sources/utah-sb226/SB0226-enrolled.pdf", + "sha256": "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + }, + "acquisition": "retained_snapshot", + "document_id": "Utah SB 226 (2025)", + "document_title": "Enrolled Copy S.B. 226 Artificial Intelligence Consumer Protection Amendments", + "issuing_body": "Utah State Legislature", + "document_type": "enacted legislation", + "version": "2025 General Session enrolled copy", + "locator": "2025 enrolled SB 226, section3, 13-75-103(2)-(3), printed lines106-115", + "excerpt": "106 (2) An individual providing services in a regulated occupation shall:\n107 (a) prominently disclose when an individual receiving services is interacting with\n108 generative artificial intelligence in the provision of regulated services if the use of\n109 generative artificial intelligence constitutes a high-risk artificial intelligence\n110 interaction; and\n111 (b) comply with all requirements of the regulated occupation when providing services\n112 through generative artificial intelligence.\n113 (3) A disclosure required under Subsection (2) shall be provided:\n114 (a) verbally at the start of a verbal interaction; and\n115 (b) in writing before the start of a written interaction.", + "identity_excerpts": [ + "Artificial Intelligence Consumer Protection Amendments" + ] + }, + "safe_harbor": { + "official_url": "https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf", + "snapshot_path": "data/admission/sources/utah-sb226/SB0226-enrolled.txt", + "snapshot_sha256": "088cb7315787b8f1a2c999ab3cdf9527b10eae034d032c7912ad6530441f08d7", + "original": { + "path": "data/admission/sources/utah-sb226/SB0226-enrolled.pdf", + "sha256": "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + }, + "acquisition": "retained_snapshot", + "document_id": "Utah SB 226 (2025)", + "document_title": "Enrolled Copy S.B. 226 Artificial Intelligence Consumer Protection Amendments", + "issuing_body": "Utah State Legislature", + "document_type": "enacted legislation", + "version": "2025 General Session enrolled copy", + "locator": "2025 enrolled SB 226, section4, 13-75-104(1)-(2), printed lines118-131", + "excerpt": "118 (1) A person is not subject to an enforcement action for violating Section 13-75-103 if the\n119 person's generative artificial intelligence clearly and conspicuously discloses:\n120 (a) at the outset of any interaction with an individual in connection with:\n121 (i) a consumer transaction; or\n122 (ii) the provision of regulated services; and\n123 (b) throughout the interaction that it:\n124 (i) is generative artificial intelligence;\n125 (ii) is not human; or\n126 (iii) is an artificial intelligence assistant.\n127 (2) In accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act, the\n128 division in consultation with the office, may make rules specifying forms and methods\n129 of disclosure that:\n\n -4-\n\f Enrolled Copy S.B. 226\n\n\n130 (a) satisfy the requirements of Subsection (1); or\n131 (b) do not satisfy the requirements of Subsection (1).", + "identity_excerpts": [ + "Artificial Intelligence Consumer Protection Amendments" + ] + }, + "other_remedies": { + "official_url": "https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf", + "snapshot_path": "data/admission/sources/utah-sb226/SB0226-enrolled.txt", + "snapshot_sha256": "088cb7315787b8f1a2c999ab3cdf9527b10eae034d032c7912ad6530441f08d7", + "original": { + "path": "data/admission/sources/utah-sb226/SB0226-enrolled.pdf", + "sha256": "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + }, + "acquisition": "retained_snapshot", + "document_id": "Utah SB 226 (2025)", + "document_title": "Enrolled Copy S.B. 226 Artificial Intelligence Consumer Protection Amendments", + "issuing_body": "Utah State Legislature", + "document_type": "enacted legislation", + "version": "2025 General Session enrolled copy", + "locator": "2025 enrolled SB 226, section6, 13-75-106, printed lines164-168", + "excerpt": "164 Section 6. Section 13-75-106 is enacted to read:\n165 13-75-106 (Effective 05/07/25). Scope.\n166 This chapter does not displace any other remedy or right authorized under:\n167 (1) the laws of this state; or\n168 (2) federal law.", + "identity_excerpts": [ + "Artificial Intelligence Consumer Protection Amendments" + ] + } + }, + "units": { + "section:Summary/text": { + "before_sha256": "fa10e73a849afc95192b258413da45c074875b621ac3f738a634958fd7f08881", + "after_sha256": "f3d51e64453687aa98c197b2d82c82a6c98e38aa15d01a2db3e354d5af0b3492", + "candidate_content": "An individual providing services in a regulated occupation must prominently disclose when an individual receiving services is interacting with generative artificial intelligence in the provision of regulated services if that use constitutes a high-risk artificial intelligence interaction (§13-75-103(2)(a)). The statutory actor is the individual providing those services, without a supplier condition. A regulated occupation is regulated by the Department of Commerce and requires an individual to obtain a license or state certification to practice (§13-75-101(8)).\n\nThe required disclosure is provided verbally at the start of a verbal interaction, and in writing before the start of a written interaction (§13-75-103(3)). Written interactions are not limited to electronic messaging. The individual must also comply with all requirements of the regulated occupation when providing services through GenAI (§13-75-103(2)(b)); that requirement is not confined to high-risk interactions.\n\nA high-risk artificial intelligence interaction is an interaction with GenAI involving any of the following (§13-75-101(5)):\n- Collection of sensitive personal information, including health, financial or biometric data\n- Provision of personalized recommendations, advice or information that could reasonably be relied upon to make significant personal decisions, including financial, legal, medical or mental health advice or services\n- Other applications as defined by division rule\n\nThe listed data and advice or service categories are inclusive examples, not exhaustive lists. The separate §13-75-104(1) safe harbor also covers the provision of regulated services: it concerns enforcement actions for violating §13-75-103 only and requires the person's GenAI to clearly and conspicuously disclose at the outset and throughout the interaction that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms; other state and federal remedies remain available (§13-75-106).\n\nThese locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. Current division rules defining other high-risk applications or disclosure forms and methods have not been retained or reviewed here.", + "reason": "Preserve the individual regulated-services actor, complete high-risk definition, prominence, all occupational requirements, verbal-at-start versus written-before-start timing, and the separate limited safe harbor; qualify enrolled-version locators.", + "qualifications": { + "scope": "13-75-103(2)-(3), 13-75-101(5),(8), 13-75-104 and 13-75-106 in the retained 2025 enrolled act; the occupational-compliance duty is not confined to high-risk use.", + "exceptions": "Safe-harbor alternatives and conditions remain distinct from the request conjunction. Current rules, imported definitions and live codification are unvalidated; other remedies and R3 civil/criminal content are unchanged.", + "time": "Retained 2025 enrolled version only. Existing human review, last_verified and effective dates and actual raw acquisition dates are unchanged; the agent review timestamp is not a new retrieval or currentness date." + }, + "evidence": [ + "high_risk", + "occupation", + "regulated_disclosure", + "safe_harbor", + "other_remedies" + ] + }, + "section:What Counts/text": { + "before_sha256": "c8ad7d1826987c0b1cce330d74891cf2bebc268f9975f1be3197638e95f19c9a", + "after_sha256": "dfc4a8c6fcd4ae07b4e7d97fb2ab6aeb2c1e2cbe5809a1fc8a765e7cca7ab1d7", + "candidate_content": "- Prominent GenAI disclosure to the individual receiving regulated services in a qualifying high-risk interaction\n- Verbal disclosure at the start of a verbal interaction, not a universal before-start requirement\n- Written disclosure before the start of a written interaction, including but not limited to electronic messaging\n- Disclosure for collection of sensitive personal information within the regulated-services context, including health, financial or biometric data\n- Disclosure for personalized recommendations, advice or information reasonably relied upon for significant personal decisions within that context, including financial, legal, medical or mental health advice or services\n- Disclosure for another application defined as high-risk by division rule, subject to separately retained rule evidence\n- Compliance with all requirements of the regulated occupation when providing services through GenAI, even where the interaction is not high-risk", + "reason": "Preserve the individual regulated-services actor, complete high-risk definition, prominence, all occupational requirements, verbal-at-start versus written-before-start timing, and the separate limited safe harbor; qualify enrolled-version locators.", + "qualifications": { + "scope": "13-75-103(2)-(3), 13-75-101(5),(8), 13-75-104 and 13-75-106 in the retained 2025 enrolled act; the occupational-compliance duty is not confined to high-risk use.", + "exceptions": "Safe-harbor alternatives and conditions remain distinct from the request conjunction. Current rules, imported definitions and live codification are unvalidated; other remedies and R3 civil/criminal content are unchanged.", + "time": "Retained 2025 enrolled version only. Existing human review, last_verified and effective dates and actual raw acquisition dates are unchanged; the agent review timestamp is not a new retrieval or currentness date." + }, + "evidence": [ + "high_risk", + "occupation", + "regulated_disclosure", + "safe_harbor", + "other_remedies" + ] + }, + "section:What Does Not Count/text": { + "before_sha256": "116e452c70e105bb9ed58a54679b92b3d4808c14cf69992a3f5404b6207eb316", + "after_sha256": "54294199437809c8bb2d4c2b360e52cde36efcdd0c23313be17618f3bfc7f758", + "candidate_content": "- Disclosure delayed until the individual receiving services asks, absent the separate statutory safe harbor\n- A disclosure that lacks prominence, is delayed beyond the start of a verbal interaction, or appears only after a written interaction has started\n- General branding or marketing that mentions AI without the required disclosure to the recipient in the qualifying interaction\n- Adding a supplier condition to the individual regulated-services actor\n- Treating all personalized information as high-risk without the significant-personal-decisions criterion or another statutory branch\n- Treating the statutory examples as exhaustive or omitting the division-rule branch\n- Treating disclosure or the safe harbor as a waiver of other occupational requirements or of remedies outside §13-75-103", + "reason": "Preserve the individual regulated-services actor, complete high-risk definition, prominence, all occupational requirements, verbal-at-start versus written-before-start timing, and the separate limited safe harbor; qualify enrolled-version locators.", + "qualifications": { + "scope": "13-75-103(2)-(3), 13-75-101(5),(8), 13-75-104 and 13-75-106 in the retained 2025 enrolled act; the occupational-compliance duty is not confined to high-risk use.", + "exceptions": "Safe-harbor alternatives and conditions remain distinct from the request conjunction. Current rules, imported definitions and live codification are unvalidated; other remedies and R3 civil/criminal content are unchanged.", + "time": "Retained 2025 enrolled version only. Existing human review, last_verified and effective dates and actual raw acquisition dates are unchanged; the agent review timestamp is not a new retrieval or currentness date." + }, + "evidence": [ + "high_risk", + "occupation", + "regulated_disclosure", + "safe_harbor", + "other_remedies" + ] + }, + "section:Statute Anchors/text": { + "before_sha256": "35d9aa674f77156d205932884cfb512a666358363bdc631e74c5eb19436ef633", + "after_sha256": "2f93d904364a666ddc2489bdd3020d07a909956675aa83cf009e6cd2a3551383", + "candidate_content": "- Retained 2025 enrolled SB 226, §13-75-103(2)-(3), printed lines 106-115: statutory actor, prominence, occupational requirements and channel-specific timing\n- Retained 2025 enrolled SB 226, §13-75-101(5), printed lines 54-67: complete high-risk interaction definition\n- Retained 2025 enrolled SB 226, §13-75-101(8), printed lines 75-78: regulated occupation definition\n- Retained 2025 enrolled SB 226, §13-75-104(1)-(2), printed lines 118-131: separate section103-only safe harbor and disclosure-rule authority\n- Retained 2025 enrolled SB 226, §13-75-106, printed lines 164-168: other state and federal remedies preserved", + "reason": "Preserve the individual regulated-services actor, complete high-risk definition, prominence, all occupational requirements, verbal-at-start versus written-before-start timing, and the separate limited safe harbor; qualify enrolled-version locators.", + "qualifications": { + "scope": "13-75-103(2)-(3), 13-75-101(5),(8), 13-75-104 and 13-75-106 in the retained 2025 enrolled act; the occupational-compliance duty is not confined to high-risk use.", + "exceptions": "Safe-harbor alternatives and conditions remain distinct from the request conjunction. Current rules, imported definitions and live codification are unvalidated; other remedies and R3 civil/criminal content are unchanged.", + "time": "Retained 2025 enrolled version only. Existing human review, last_verified and effective dates and actual raw acquisition dates are unchanged; the agent review timestamp is not a new retrieval or currentness date." + }, + "evidence": [ + "high_risk", + "occupation", + "regulated_disclosure", + "safe_harbor", + "other_remedies" + ] + } + } } } } diff --git a/data/examples/obligations/disclose-genai-high-risk-proactive.md b/data/examples/obligations/disclose-genai-high-risk-proactive.md index 2613cd8b..04e1a40e 100644 --- a/data/examples/obligations/disclose-genai-high-risk-proactive.md +++ b/data/examples/obligations/disclose-genai-high-risk-proactive.md @@ -16,22 +16,43 @@ search_terms: ## Summary -A supplier engaged in a "high-risk AI interaction" in a regulated occupation must proactively disclose GenAI use before the interaction begins — verbally at the start of an oral exchange, and in writing before a written exchange. The high-risk tier is statutorily defined and narrower than general consumer interactions. +An individual providing services in a regulated occupation must prominently disclose when an individual receiving services is interacting with generative artificial intelligence in the provision of regulated services if that use constitutes a high-risk artificial intelligence interaction (§13-75-103(2)(a)). The statutory actor is the individual providing those services, without a supplier condition. A regulated occupation is regulated by the Department of Commerce and requires an individual to obtain a license or state certification to practice (§13-75-101(8)). + +The required disclosure is provided verbally at the start of a verbal interaction, and in writing before the start of a written interaction (§13-75-103(3)). Written interactions are not limited to electronic messaging. The individual must also comply with all requirements of the regulated occupation when providing services through GenAI (§13-75-103(2)(b)); that requirement is not confined to high-risk interactions. + +A high-risk artificial intelligence interaction is an interaction with GenAI involving any of the following (§13-75-101(5)): +- Collection of sensitive personal information, including health, financial or biometric data +- Provision of personalized recommendations, advice or information that could reasonably be relied upon to make significant personal decisions, including financial, legal, medical or mental health advice or services +- Other applications as defined by division rule + +The listed data and advice or service categories are inclusive examples, not exhaustive lists. The separate §13-75-104(1) safe harbor also covers the provision of regulated services: it concerns enforcement actions for violating §13-75-103 only and requires the person's GenAI to clearly and conspicuously disclose at the outset and throughout the interaction that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms; other state and federal remedies remain available (§13-75-106). + +These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. Current division rules defining other high-risk applications or disclosure forms and methods have not been retained or reviewed here. ## What Counts -- Verbal AI disclosure at the start of an oral exchange -- Written AI disclosure before the first written message in an electronic interaction -- Disclosure in any interaction involving collection of sensitive data (health, financial, biometric) -- Disclosure in any interaction providing personalized advice in finance, legal, medicine, or mental health +- Prominent GenAI disclosure to the individual receiving regulated services in a qualifying high-risk interaction +- Verbal disclosure at the start of a verbal interaction, not a universal before-start requirement +- Written disclosure before the start of a written interaction, including but not limited to electronic messaging +- Disclosure for collection of sensitive personal information within the regulated-services context, including health, financial or biometric data +- Disclosure for personalized recommendations, advice or information reasonably relied upon for significant personal decisions within that context, including financial, legal, medical or mental health advice or services +- Disclosure for another application defined as high-risk by division rule, subject to separately retained rule evidence +- Compliance with all requirements of the regulated occupation when providing services through GenAI, even where the interaction is not high-risk ## What Does Not Count -- Disclosure delayed until the consumer asks -- General branding or marketing that mentions AI without a pre-interaction disclosure -- Disclosure for interactions outside the §13-75-101(5) "high-risk" definition +- Disclosure delayed until the individual receiving services asks, absent the separate statutory safe harbor +- A disclosure that lacks prominence, is delayed beyond the start of a verbal interaction, or appears only after a written interaction has started +- General branding or marketing that mentions AI without the required disclosure to the recipient in the qualifying interaction +- Adding a supplier condition to the individual regulated-services actor +- Treating all personalized information as high-risk without the significant-personal-decisions criterion or another statutory branch +- Treating the statutory examples as exhaustive or omitting the division-rule branch +- Treating disclosure or the safe harbor as a waiver of other occupational requirements or of remedies outside §13-75-103 ## Statute Anchors -- Utah Code §13-75-103(2)–(3) — Proactive disclosure in high-risk AI interactions -- Utah Code §13-75-101(5) — Definition of "high-risk artificial intelligence interaction" +- Retained 2025 enrolled SB 226, §13-75-103(2)-(3), printed lines 106-115: statutory actor, prominence, occupational requirements and channel-specific timing +- Retained 2025 enrolled SB 226, §13-75-101(5), printed lines 54-67: complete high-risk interaction definition +- Retained 2025 enrolled SB 226, §13-75-101(8), printed lines 75-78: regulated occupation definition +- Retained 2025 enrolled SB 226, §13-75-104(1)-(2), printed lines 118-131: separate section103-only safe harbor and disclosure-rule authority +- Retained 2025 enrolled SB 226, §13-75-106, printed lines 164-168: other state and federal remedies preserved diff --git a/data/examples/obligations/disclose-genai-on-request.md b/data/examples/obligations/disclose-genai-on-request.md index f2b85947..455a7e03 100644 --- a/data/examples/obligations/disclose-genai-on-request.md +++ b/data/examples/obligations/disclose-genai-on-request.md @@ -16,22 +16,29 @@ search_terms: ## Summary -A supplier using generative AI in a consumer transaction must disclose that fact when the consumer makes a clear and unambiguous request. A safe harbor is available: a clear and conspicuous disclosure at the outset and throughout the interaction eliminates enforcement exposure, regardless of whether a request is made. +A supplier that uses generative artificial intelligence to interact with an individual in connection with a consumer transaction must disclose that the individual is interacting with generative artificial intelligence and not a human if the individual asks or otherwise prompts the supplier about whether artificial intelligence is being used. The prompt or question must be a clear and unambiguous request to determine whether the interaction is with a human or with artificial intelligence (§13-75-103(1)). + +The separate §13-75-104(1) safe harbor concerns enforcement actions for violating §13-75-103 only. It applies if the person's generative artificial intelligence clearly and conspicuously discloses, at the outset and throughout any interaction with an individual in connection with a consumer transaction or the provision of regulated services, that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms, not substitutes for the conjunctive on-request content in §13-75-103(1). The safe harbor has no request prerequisite and does not eliminate other state or federal remedies (§13-75-106). + +These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. The incorporated supplier and consumer-transaction definitions (§13-11-3) and current disclosure rules under §13-75-104(2) are outside this retained-source review. ## What Counts -- Supplier responds truthfully when a consumer directly asks whether they are interacting with a human or with AI -- Clear-and-conspicuous GenAI notice shown at the outset of the interaction and sustained throughout (qualifies for §13-75-104 safe harbor) -- Plain-language identification naming "AI" or "generative AI" +- For the on-request duty, the supplier discloses both generative artificial intelligence and not a human in response to the qualifying question or prompt in a consumer transaction +- For the separate safe harbor, the person's GenAI clearly and conspicuously discloses any one of the three statutory alternatives at the outset and throughout the qualifying interaction: generative artificial intelligence, not human, or an artificial intelligence assistant +- The safe-harbor not-human alternative does not require the literal word "AI"; the statutory clarity, conspicuousness, context and timing conditions still apply ## What Does Not Count -- Requiring the consumer to infer AI use from context -- Disclosure buried only in a privacy policy or terms-of-service link -- Ambiguous labels such as "smart assistant" or "automated helper" without the word "AI" -- Responding only when the consumer uses a specific magic phrase +- Requiring the individual to infer GenAI use from context instead of responding to the qualifying request +- Treating a not-human-only response as the complete §13-75-103(1) disclosure, rather than distinguishing the separate safe-harbor alternative +- Treating a buried notice or an ambiguous label such as "smart assistant" or "automated helper" as sufficient without establishing the safe harbor's clear-and-conspicuous disclosure conditions +- Providing a safe-harbor notice only at the outset without disclosure throughout the interaction +- Requiring a specific magic phrase when the individual has already made a clear and unambiguous qualifying request +- Treating the safe harbor as immunity from violations or remedies outside §13-75-103 ## Statute Anchors -- Utah Code §13-75-103(1) — On-request GenAI disclosure -- Utah Code §13-75-104 — Clear-and-conspicuous safe harbor +- Retained 2025 enrolled SB 226, §13-75-103(1), printed lines 98-105: supplier, transaction, request and conjunctive disclosure content +- Retained 2025 enrolled SB 226, §13-75-104(1)-(2), printed lines 118-131: separate section103-only safe harbor and disclosure-rule authority +- Retained 2025 enrolled SB 226, §13-75-106, printed lines 164-168: other state and federal remedies preserved diff --git a/docs/MANIFEST.yaml b/docs/MANIFEST.yaml index 77a5696e..4ee49d15 100644 --- a/docs/MANIFEST.yaml +++ b/docs/MANIFEST.yaml @@ -128,7 +128,7 @@ files: - path: package.json role: config - hash: sha256:45d3460c2f22d32ff645353a145c93783cd6a6152398ca85f45a862d3d1bcede + hash: sha256:b22e0dcdcd2e45a3f232b450795cb65c32c4a58723423f456071bfb288c009b7 note: package.json - path: package-lock.json @@ -333,7 +333,7 @@ files: - path: data/examples/obligations/disclose-genai-high-risk-proactive.md role: obligation - hash: sha256:894ec6c5333740656a3f50a3dec3cdb95ceeb60642a95c225a2fe9d8e51823f5 + hash: sha256:f1ee01115a55072a4a046b49af6a81c109b4f0ffba49e6e6df58d775b25ca302 note: data/examples/obligations/disclose-genai-high-risk-proactive.md - path: data/examples/obligations/disclose-genai-on-first-session.md @@ -343,7 +343,7 @@ files: - path: data/examples/obligations/disclose-genai-on-request.md role: obligation - hash: sha256:975530c0feb4bacd2989f3e1494c8f9cbe61dd4bbb1569c866490c6de88d514a + hash: sha256:24d7c8e63e37d24678f5225b2d0c97b16f2bbea97e2fda7df8c9deeda1ef8c92 note: data/examples/obligations/disclose-genai-on-request.md - path: data/examples/obligations/elizachat-phased-rollout.md @@ -1038,7 +1038,7 @@ files: - path: tests/source-admission.test.js role: code - hash: sha256:10be9419f4d32940c9988fed0e13edd48fdb0d81b456989b80794d89b6b0c163 + hash: sha256:e4fcbb61cf703c1dbcaf9b10c01feb50f548dfc3ac797b5ec3c717aeec3af5aa note: Source admission policy and producer-gate regressions - path: tests/publication-state.test.js @@ -1058,7 +1058,7 @@ files: - path: tests/of-evidence-inputs.test.js role: code - hash: sha256:1e604a0fb0f847f796d655245a431333e412da9f94e1f01e96c38818323b084c + hash: sha256:1321a92efb7d004456d7190ff24b5600c444d7df7b49d2b4b08d28ef70bf84f4 note: Per-kind native evidence input and review-boundary regressions - path: tests/colorado-order24.test.js @@ -1165,3 +1165,23 @@ files: role: evidence hash: sha256:d1a7ac6297492ffc889ad5cb611d3dd6e087161d29e4763a19ea884983fb1fc6 note: Utah statute enrolled-copy source review receipt (SB 149, SB 226, SB 332, HB 320) + + - path: tests/sb226-r1.test.js + role: code + hash: sha256:ba4f4636bad329be363c84d09c840cfe62a3fd89ec107025bddff21056a41c38 + note: SB226 R1 retained-source and admission regressions + + - path: ops/evidence/sb226-r1-native-delta-2026-10-02.diff + role: evidence + hash: sha256:526f22e19f1f05130c16f8cc057849c245a481e88bb5ce5019e1e850b6000e59 + note: Independently reviewed SB226 R1 native definition delta + + - path: ops/evidence/sb226-r1-fingerprint-comparison-2026-10-02.json + role: evidence + hash: sha256:5160025a28388f121161cac0c7d8c8b208a99872d5710d6bb85f37ef618c1d23 + note: Parent-accepted exact two-record provenance-only fingerprint comparison + + - path: ops/evidence/sb226-r1-local-repair-2026-10-02.md + role: evidence + hash: sha256:6d6bbc43b88d1ca9510466460e092bd6fd9484d3344919e810fc5d8259f09322 + note: Scoped SB226 R1 owner repair receipt; instrument Summary remains gated diff --git a/docs/api/v1/of/obligations.json b/docs/api/v1/of/obligations.json index de39156b..0e6a0da0 100644 --- a/docs/api/v1/of/obligations.json +++ b/docs/api/v1/of/obligations.json @@ -379,7 +379,7 @@ "@id": "https://publedge.org/obligation/sb226-disclosure-and-ai-defense-disclose-genai-on-request.json", "pub:id": "sb226-disclosure-and-ai-defense-disclose-genai-on-request", "title": "Disclose GenAI On Consumer Request", - "content": "A supplier using generative AI in a consumer transaction must disclose that fact when the consumer makes a clear and unambiguous request. A safe harbor is available: a clear and conspicuous disclosure at the outset and throughout the interaction eliminates enforcement exposure, regardless of whether a request is made.", + "content": "A supplier that uses generative artificial intelligence to interact with an individual in connection with a consumer transaction must disclose that the individual is interacting with generative artificial intelligence and not a human if the individual asks or otherwise prompts the supplier about whether artificial intelligence is being used. The prompt or question must be a clear and unambiguous request to determine whether the interaction is with a human or with artificial intelligence (§13-75-103(1)). The separate §13-75-104(1) safe harbor concerns enforcement actions for violating §13-75-103 only. It applies if the person's generative artificial intelligence clearly and conspicuously discloses, at the outset and throughout any interaction with an individual in connection with a consumer transaction or the provision of regulated services, that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms, not substitutes for the conjunctive on-request content in §13-75-103(1). The safe harbor has no request prerequisite and does not eliminate other state or federal remedies (§13-75-106). These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. The incorporated supplier and consumer-transaction definitions (§13-11-3) and current disclosure rules under §13-75-104(2) are outside this retained-source review.", "created_by": [ "https://publedge.org/term/sb226-disclosure-and-ai-defense.json" ], @@ -417,7 +417,12 @@ "Whether SB 226 passed each house by two-thirds (so its 63I-2-213 amendment took effect on governor approval rather than May 7, 2025) is not confirmed.", "The 404 status of the 13-75-S102/S103/S104 URLs and HTTP 200 for 13-75.html come from ops/evidence/utah-overdue-dispositions-2026-09-23.json url_checks, not a retained snapshot; a human should confirm the current le.utah.gov section URL pattern.", "Whether an OAIP annual report was filed for 2024 or 2025 is unverified.", - "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it." + "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it.", + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." ], "pub:source_review_state": "known-and-unknown", "pub:evidence_inputs": [ @@ -457,14 +462,22 @@ { "kind": "obligation-definition", "native_path": "data/examples/obligations/disclose-genai-on-request.md", - "native_file_sha256": "975530c0feb4bacd2989f3e1494c8f9cbe61dd4bbb1569c866490c6de88d514a", + "native_file_sha256": "24d7c8e63e37d24678f5225b2d0c97b16f2bbea97e2fda7df8c9deeda1ef8c92", "canonical_unit": null, - "canonical_sha256": "2255b8372e20bccbf1f6b054201add8cda3e519dd4aded5ac492e91cc7c56d0c", - "admission_status": "legacy-unreviewed", - "review_packet_sha256": null, - "retained_primary_sha256": null, - "unresolved_review_state": "unknown", - "unresolved": null + "canonical_sha256": "df3231b4a2111975e8de105d84a2fa0d4f5d1b8b32ffb3f0aab9ee12622931a5", + "admission_status": "reviewed-changes", + "review_packet_sha256": "ae850f903e66d27eac95d560533460f50cea40532afb8f15ab6d5c6c41e9b98a", + "retained_primary_sha256": [ + "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + ], + "unresolved_review_state": "declared", + "unresolved": [ + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." + ] } ] }, @@ -479,7 +492,7 @@ "@id": "https://publedge.org/obligation/sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive.json", "pub:id": "sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive", "title": "Proactive GenAI Disclosure In High-Risk Interactions", - "content": "A supplier engaged in a \"high-risk AI interaction\" in a regulated occupation must proactively disclose GenAI use before the interaction begins — verbally at the start of an oral exchange, and in writing before a written exchange. The high-risk tier is statutorily defined and narrower than general consumer interactions.", + "content": "An individual providing services in a regulated occupation must prominently disclose when an individual receiving services is interacting with generative artificial intelligence in the provision of regulated services if that use constitutes a high-risk artificial intelligence interaction (§13-75-103(2)(a)). The statutory actor is the individual providing those services, without a supplier condition. A regulated occupation is regulated by the Department of Commerce and requires an individual to obtain a license or state certification to practice (§13-75-101(8)). The required disclosure is provided verbally at the start of a verbal interaction, and in writing before the start of a written interaction (§13-75-103(3)). Written interactions are not limited to electronic messaging. The individual must also comply with all requirements of the regulated occupation when providing services through GenAI (§13-75-103(2)(b)); that requirement is not confined to high-risk interactions. A high-risk artificial intelligence interaction is an interaction with GenAI involving any of the following (§13-75-101(5)): - Collection of sensitive personal information, including health, financial or biometric data - Provision of personalized recommendations, advice or information that could reasonably be relied upon to make significant personal decisions, including financial, legal, medical or mental health advice or services - Other applications as defined by division rule The listed data and advice or service categories are inclusive examples, not exhaustive lists. The separate §13-75-104(1) safe harbor also covers the provision of regulated services: it concerns enforcement actions for violating §13-75-103 only and requires the person's GenAI to clearly and conspicuously disclose at the outset and throughout the interaction that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms; other state and federal remedies remain available (§13-75-106). These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. Current division rules defining other high-risk applications or disclosure forms and methods have not been retained or reviewed here.", "created_by": [ "https://publedge.org/term/sb226-disclosure-and-ai-defense.json" ], @@ -517,7 +530,12 @@ "Whether SB 226 passed each house by two-thirds (so its 63I-2-213 amendment took effect on governor approval rather than May 7, 2025) is not confirmed.", "The 404 status of the 13-75-S102/S103/S104 URLs and HTTP 200 for 13-75.html come from ops/evidence/utah-overdue-dispositions-2026-09-23.json url_checks, not a retained snapshot; a human should confirm the current le.utah.gov section URL pattern.", "Whether an OAIP annual report was filed for 2024 or 2025 is unverified.", - "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it." + "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it.", + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." ], "pub:source_review_state": "known-and-unknown", "pub:evidence_inputs": [ @@ -557,14 +575,22 @@ { "kind": "obligation-definition", "native_path": "data/examples/obligations/disclose-genai-high-risk-proactive.md", - "native_file_sha256": "894ec6c5333740656a3f50a3dec3cdb95ceeb60642a95c225a2fe9d8e51823f5", + "native_file_sha256": "f1ee01115a55072a4a046b49af6a81c109b4f0ffba49e6e6df58d775b25ca302", "canonical_unit": null, - "canonical_sha256": "16769df863c540985bf05faefbfab94efb1882a1398d65eca9a16ec41f313ba2", - "admission_status": "legacy-unreviewed", - "review_packet_sha256": null, - "retained_primary_sha256": null, - "unresolved_review_state": "unknown", - "unresolved": null + "canonical_sha256": "189f4253b204692369145bf206f26cb66d414488405e0d4509edee0e4c57a9d3", + "admission_status": "reviewed-changes", + "review_packet_sha256": "53dc6fff3ee933e85a8596578c3985f836252418b30dc6025349ed3ebdb586bb", + "retained_primary_sha256": [ + "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + ], + "unresolved_review_state": "declared", + "unresolved": [ + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." + ] } ] }, diff --git a/docs/api/v1/of/records/sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive.json b/docs/api/v1/of/records/sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive.json index faeee4bf..907fb42e 100644 --- a/docs/api/v1/of/records/sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive.json +++ b/docs/api/v1/of/records/sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive.json @@ -9,7 +9,7 @@ "@id": "https://publedge.org/obligation/sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive.json", "pub:id": "sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive", "title": "Proactive GenAI Disclosure In High-Risk Interactions", - "content": "A supplier engaged in a \"high-risk AI interaction\" in a regulated occupation must proactively disclose GenAI use before the interaction begins — verbally at the start of an oral exchange, and in writing before a written exchange. The high-risk tier is statutorily defined and narrower than general consumer interactions.", + "content": "An individual providing services in a regulated occupation must prominently disclose when an individual receiving services is interacting with generative artificial intelligence in the provision of regulated services if that use constitutes a high-risk artificial intelligence interaction (§13-75-103(2)(a)). The statutory actor is the individual providing those services, without a supplier condition. A regulated occupation is regulated by the Department of Commerce and requires an individual to obtain a license or state certification to practice (§13-75-101(8)). The required disclosure is provided verbally at the start of a verbal interaction, and in writing before the start of a written interaction (§13-75-103(3)). Written interactions are not limited to electronic messaging. The individual must also comply with all requirements of the regulated occupation when providing services through GenAI (§13-75-103(2)(b)); that requirement is not confined to high-risk interactions. A high-risk artificial intelligence interaction is an interaction with GenAI involving any of the following (§13-75-101(5)): - Collection of sensitive personal information, including health, financial or biometric data - Provision of personalized recommendations, advice or information that could reasonably be relied upon to make significant personal decisions, including financial, legal, medical or mental health advice or services - Other applications as defined by division rule The listed data and advice or service categories are inclusive examples, not exhaustive lists. The separate §13-75-104(1) safe harbor also covers the provision of regulated services: it concerns enforcement actions for violating §13-75-103 only and requires the person's GenAI to clearly and conspicuously disclose at the outset and throughout the interaction that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms; other state and federal remedies remain available (§13-75-106). These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. Current division rules defining other high-risk applications or disclosure forms and methods have not been retained or reviewed here.", "created_by": [ "https://publedge.org/term/sb226-disclosure-and-ai-defense.json" ], @@ -47,7 +47,12 @@ "Whether SB 226 passed each house by two-thirds (so its 63I-2-213 amendment took effect on governor approval rather than May 7, 2025) is not confirmed.", "The 404 status of the 13-75-S102/S103/S104 URLs and HTTP 200 for 13-75.html come from ops/evidence/utah-overdue-dispositions-2026-09-23.json url_checks, not a retained snapshot; a human should confirm the current le.utah.gov section URL pattern.", "Whether an OAIP annual report was filed for 2024 or 2025 is unverified.", - "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it." + "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it.", + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." ], "pub:source_review_state": "known-and-unknown", "pub:evidence_inputs": [ @@ -87,14 +92,22 @@ { "kind": "obligation-definition", "native_path": "data/examples/obligations/disclose-genai-high-risk-proactive.md", - "native_file_sha256": "894ec6c5333740656a3f50a3dec3cdb95ceeb60642a95c225a2fe9d8e51823f5", + "native_file_sha256": "f1ee01115a55072a4a046b49af6a81c109b4f0ffba49e6e6df58d775b25ca302", "canonical_unit": null, - "canonical_sha256": "16769df863c540985bf05faefbfab94efb1882a1398d65eca9a16ec41f313ba2", - "admission_status": "legacy-unreviewed", - "review_packet_sha256": null, - "retained_primary_sha256": null, - "unresolved_review_state": "unknown", - "unresolved": null + "canonical_sha256": "189f4253b204692369145bf206f26cb66d414488405e0d4509edee0e4c57a9d3", + "admission_status": "reviewed-changes", + "review_packet_sha256": "53dc6fff3ee933e85a8596578c3985f836252418b30dc6025349ed3ebdb586bb", + "retained_primary_sha256": [ + "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + ], + "unresolved_review_state": "declared", + "unresolved": [ + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." + ] } ] } diff --git a/docs/api/v1/of/records/sb226-disclosure-and-ai-defense-disclose-genai-on-request.json b/docs/api/v1/of/records/sb226-disclosure-and-ai-defense-disclose-genai-on-request.json index 08e1e6f1..a10216bd 100644 --- a/docs/api/v1/of/records/sb226-disclosure-and-ai-defense-disclose-genai-on-request.json +++ b/docs/api/v1/of/records/sb226-disclosure-and-ai-defense-disclose-genai-on-request.json @@ -9,7 +9,7 @@ "@id": "https://publedge.org/obligation/sb226-disclosure-and-ai-defense-disclose-genai-on-request.json", "pub:id": "sb226-disclosure-and-ai-defense-disclose-genai-on-request", "title": "Disclose GenAI On Consumer Request", - "content": "A supplier using generative AI in a consumer transaction must disclose that fact when the consumer makes a clear and unambiguous request. A safe harbor is available: a clear and conspicuous disclosure at the outset and throughout the interaction eliminates enforcement exposure, regardless of whether a request is made.", + "content": "A supplier that uses generative artificial intelligence to interact with an individual in connection with a consumer transaction must disclose that the individual is interacting with generative artificial intelligence and not a human if the individual asks or otherwise prompts the supplier about whether artificial intelligence is being used. The prompt or question must be a clear and unambiguous request to determine whether the interaction is with a human or with artificial intelligence (§13-75-103(1)). The separate §13-75-104(1) safe harbor concerns enforcement actions for violating §13-75-103 only. It applies if the person's generative artificial intelligence clearly and conspicuously discloses, at the outset and throughout any interaction with an individual in connection with a consumer transaction or the provision of regulated services, that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms, not substitutes for the conjunctive on-request content in §13-75-103(1). The safe harbor has no request prerequisite and does not eliminate other state or federal remedies (§13-75-106). These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. The incorporated supplier and consumer-transaction definitions (§13-11-3) and current disclosure rules under §13-75-104(2) are outside this retained-source review.", "created_by": [ "https://publedge.org/term/sb226-disclosure-and-ai-defense.json" ], @@ -47,7 +47,12 @@ "Whether SB 226 passed each house by two-thirds (so its 63I-2-213 amendment took effect on governor approval rather than May 7, 2025) is not confirmed.", "The 404 status of the 13-75-S102/S103/S104 URLs and HTTP 200 for 13-75.html come from ops/evidence/utah-overdue-dispositions-2026-09-23.json url_checks, not a retained snapshot; a human should confirm the current le.utah.gov section URL pattern.", "Whether an OAIP annual report was filed for 2024 or 2025 is unverified.", - "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it." + "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it.", + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." ], "pub:source_review_state": "known-and-unknown", "pub:evidence_inputs": [ @@ -87,14 +92,22 @@ { "kind": "obligation-definition", "native_path": "data/examples/obligations/disclose-genai-on-request.md", - "native_file_sha256": "975530c0feb4bacd2989f3e1494c8f9cbe61dd4bbb1569c866490c6de88d514a", + "native_file_sha256": "24d7c8e63e37d24678f5225b2d0c97b16f2bbea97e2fda7df8c9deeda1ef8c92", "canonical_unit": null, - "canonical_sha256": "2255b8372e20bccbf1f6b054201add8cda3e519dd4aded5ac492e91cc7c56d0c", - "admission_status": "legacy-unreviewed", - "review_packet_sha256": null, - "retained_primary_sha256": null, - "unresolved_review_state": "unknown", - "unresolved": null + "canonical_sha256": "df3231b4a2111975e8de105d84a2fa0d4f5d1b8b32ffb3f0aab9ee12622931a5", + "admission_status": "reviewed-changes", + "review_packet_sha256": "ae850f903e66d27eac95d560533460f50cea40532afb8f15ab6d5c6c41e9b98a", + "retained_primary_sha256": [ + "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + ], + "unresolved_review_state": "declared", + "unresolved": [ + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." + ] } ] } diff --git a/docs/assets/data.json b/docs/assets/data.json index 01212b65..0a364913 100644 --- a/docs/assets/data.json +++ b/docs/assets/data.json @@ -1 +1 @@ -[{"type":"legal instrument","name":"CFPB Advisory Opinion — Pay-to-Pay Fees (Regulation F)","id":"us-cfpb-ao-2022-001","href":"/us/federal/cfpb/ao/2022-001/","jurisdiction":"us","_search":"cfpb advisory opinion — pay-to-pay fees (regulation f) us us-cfpb-ao-2022-001 enforcing"},{"type":"legal instrument","name":"CFTC Letter 17-65 — CTA Registration Exemption Survives MiFID II Fee Unbundling","id":"us-cftc-dsio-il-2017-001","href":"/us/federal/cftc-dsio/il/2017-001/","jurisdiction":"us","_search":"cftc letter 17-65 — cta registration exemption survives mifid ii fee unbundling us us-cftc-dsio-il-2017-001 enforcing"},{"type":"legal instrument","name":"Colorado SB 24-205 (2024) — Consumer Protections for Interactions with Artificial Intelligence Systems","id":"us-co-legislature-statute-2024-sb24-205","href":"/us/colorado/legislature/statute/2024-001/","jurisdiction":"us-co","_search":"colorado sb 24-205 (2024) — consumer protections for interactions with artificial intelligence systems us-co us-co-legislature-statute-2024-sb24-205 superseded"},{"type":"legal instrument","name":"Colorado SB 25B-004 (2025) — Increase Transparency for Algorithmic Systems (Colorado AI Act Effective-Date Delay)","id":"us-co-legislature-statute-2025-sb25b-004","href":"/us/colorado/legislature/statute/2025-001/","jurisdiction":"us-co","_search":"colorado sb 25b-004 (2025) — increase transparency for algorithmic systems (colorado ai act effective-date delay) us-co us-co-legislature-statute-2025-sb25b-004 enforcing"},{"type":"legal instrument","name":"Colorado SB 26-189 (2026) — Automated Decision-Making Technology (ADMT) Act","id":"us-co-legislature-statute-2026-sb26-189","href":"/us/colorado/legislature/statute/2026-001/","jurisdiction":"us-co","_search":"colorado sb 26-189 (2026) — automated decision-making technology (admt) act us-co us-co-legislature-statute-2026-sb26-189 enacted"},{"type":"legal instrument","name":"IRS Private Letter Ruling 202506001 — Management Contract Private Business Use (§141)","id":"us-irs-chief-counsel-plr-2025-001","href":"/us/federal/irs-chief-counsel/plr/2025-001/","jurisdiction":"us","_search":"irs private letter ruling 202506001 — management contract private business use (§141) us us-irs-chief-counsel-plr-2025-001 enforcing"},{"type":"legal instrument","name":"IRS PLR 202614036 — Adverse Determination: §501(c)(3) Exemption Denied, Mixed-Use Facility","id":"us-irs-tege-plr-2026-001","href":"/us/federal/irs-tege/plr/2026-001/","jurisdiction":"us","_search":"irs plr 202614036 — adverse determination: §501(c)(3) exemption denied, mixed-use facility us us-irs-tege-plr-2026-001 enforcing"},{"type":"legal instrument","name":"SEC No-Action Letter — Latham & Watkins (Rule 506(c) Verification)","id":"us-sec-corpfin-nal-2025-001","href":"/us/federal/sec-corpfin/nal/2025-001/","jurisdiction":"us","_search":"sec no-action letter — latham & watkins (rule 506(c) verification) us us-sec-corpfin-nal-2025-001 enforcing"},{"type":"legal instrument","name":"Utah SB 149 (2024) — Artificial Intelligence Amendments","id":"us-ut-legislature-statute-2024-sb149","href":"/us/utah/legislature/statute/2024-001/","jurisdiction":"us-ut","_search":"utah sb 149 (2024) — artificial intelligence amendments us-ut us-ut-legislature-statute-2024-sb149 enforcing"},{"type":"legal instrument","name":"Utah HB 452 (2025) — Artificial Intelligence Amendments (Mental Health Chatbots)","id":"us-ut-legislature-statute-2025-hb452","href":"/us/utah/legislature/statute/2025-002/","jurisdiction":"us-ut","_search":"utah hb 452 (2025) — artificial intelligence amendments (mental health chatbots) us-ut us-ut-legislature-statute-2025-hb452 enforcing"},{"type":"legal instrument","name":"Utah SB 226 (2025) — Artificial Intelligence Consumer Protection Amendments","id":"us-ut-legislature-statute-2025-sb226","href":"/us/utah/legislature/statute/2025-001/","jurisdiction":"us-ut","_search":"utah sb 226 (2025) — artificial intelligence consumer protection amendments us-ut us-ut-legislature-statute-2025-sb226 enforcing"},{"type":"legal instrument","name":"Utah SB 332 (2025) — Artificial Intelligence Revisions (AIPA Sunset Extension)","id":"us-ut-legislature-statute-2025-sb332","href":"/us/utah/legislature/statute/2025-003/","jurisdiction":"us-ut","_search":"utah sb 332 (2025) — artificial intelligence revisions (aipa sunset extension) us-ut us-ut-legislature-statute-2025-sb332 enforcing"},{"type":"legal instrument","name":"Utah HB 320 (2026) — Office of Artificial Intelligence Policy Amendments (Learning Lab Restructure + Joint Interpretation Agreements)","id":"us-ut-legislature-statute-2026-hb320","href":"/us/utah/legislature/statute/2026-001/","jurisdiction":"us-ut","_search":"utah hb 320 (2026) — office of artificial intelligence policy amendments (learning lab restructure + joint interpretation agreements) us-ut us-ut-legislature-statute-2026-hb320 enforcing"},{"type":"legal instrument","name":"Utah Mental Health Chatbot Disclosure — Joint Interpretation","id":"us-ut-oaip-jia-2026-001","href":"/us/utah/oaip/jia/2026-001/","jurisdiction":"us-ut","_search":"utah mental health chatbot disclosure — joint interpretation us-ut us-ut-oaip-jia-2026-001 proposed"},{"type":"legal instrument","name":"Utah OAIP × ElizaChat — Teen Mental-Health App RMA (2024)","id":"us-ut-oaip-rma-2024-001","href":"/us/utah/oaip/rma/2024-001/","jurisdiction":"us-ut","_search":"utah oaip × elizachat — teen mental-health app rma (2024) us-ut us-ut-oaip-rma-2024-001 expired"},{"type":"legal instrument","name":"Utah OAIP × Dentacor — AI-Assisted Dental Radiograph Diagnosis RMA (2025)","id":"us-ut-oaip-rma-2025-001","href":"/us/utah/oaip/rma/2025-001/","jurisdiction":"us-ut","_search":"utah oaip × dentacor — ai-assisted dental radiograph diagnosis rma (2025) us-ut us-ut-oaip-rma-2025-001 expired"},{"type":"legal instrument","name":"Utah OAIP × Doctronic — AI Prescription Renewal RMA (2025)","id":"us-ut-oaip-rma-2025-002","href":"/us/utah/oaip/rma/2025-002/","jurisdiction":"us-ut","_search":"utah oaip × doctronic — ai prescription renewal rma (2025) us-ut us-ut-oaip-rma-2025-002 enforcing"},{"type":"legal instrument","name":"Utah OAIP × Legion Health — AI Maintenance Psychiatric Refill RMA (2026)","id":"us-ut-oaip-rma-2026-001","href":"/us/utah/oaip/rma/2026-001/","jurisdiction":"us-ut","_search":"utah oaip × legion health — ai maintenance psychiatric refill rma (2026) us-ut us-ut-oaip-rma-2026-001 enacted"},{"type":"obligation","name":"ADMT Sixty-Day Cure Period Before Enforcement","id":"admt-60-day-cure-period","href":"primary/admt-60-day-cure-period/index.html","group":"permission","_search":"admt sixty-day cure period before enforcement admt-60-day-cure-period permission beginning january 1, 2027, violations of the colorado admt act are enforced by the attorney general as deceptive trade practices, with no private right of action. a regulated party may cure an alleged violation within 60 days of notice; the cure route is available through january 1, 2030. admt cure period attorney general deceptive trade practice colorado sb26-189"},{"type":"obligation","name":"ADMT Data Correction And Human Review Of Adverse Outcomes","id":"admt-correction-and-human-review","href":"primary/admt-correction-and-human-review/index.html","group":"requirement","_search":"admt data correction and human review of adverse outcomes admt-correction-and-human-review requirement beginning january 1, 2027, consumers subject to an adverse consequential decision made using covered automated decision-making technology may correct inaccurate personal data used in that decision and may request meaningful human review and reconsideration of the outcome. the deployer must provide both paths. admt human review data correction reconsideration colorado sb26-189"},{"type":"obligation","name":"ADMT Deployer Three-Year Record Retention","id":"admt-deployer-3-year-record-retention","href":"primary/admt-deployer-3-year-record-retention/index.html","group":"requirement","_search":"admt deployer three-year record retention admt-deployer-3-year-record-retention requirement beginning january 1, 2027, a deployer of covered automated decision-making technology must retain its compliance documentation for at least three years. the retention floor is what makes the notice, explanation, and review duties auditable by the attorney general after the fact. admt record keeping retention three years colorado sb26-189"},{"type":"obligation","name":"ADMT Deployer Notice Before Consequential Decision","id":"admt-deployer-pre-decision-notice","href":"primary/admt-deployer-pre-decision-notice/index.html","group":"requirement","_search":"admt deployer notice before consequential decision admt-deployer-pre-decision-notice requirement beginning january 1, 2027, before a consequential decision is made using covered automated decision-making technology, the deployer must notify the consumer that an automated system is in use and disclose the purpose and nature of the decision. the notice is pre-decision; a post-hoc disclosure does not satisfy it. admt consumer notice consequential decision deployer colorado sb26-189"},{"type":"obligation","name":"ADMT Developer Documentation To Deployer","id":"admt-developer-documentation-to-deployer","href":"primary/admt-developer-documentation-to-deployer/index.html","group":"requirement","_search":"admt developer documentation to deployer admt-developer-documentation-to-deployer requirement beginning january 1, 2027, a developer of covered automated decision-making technology must disclose to deployers the technology's intended uses, the categories of data used to train it, its known limitations, and instructions for meaningful human review. the duty runs developer-to-deployer, not developer-to-consumer. admt developer documentation training data known limitations colorado sb26-189"},{"type":"obligation","name":"ADMT Post-Adverse Explanation Within 30 Days","id":"admt-post-adverse-explanation-30-days","href":"primary/admt-post-adverse-explanation-30-days/index.html","group":"requirement","_search":"admt post-adverse explanation within 30 days admt-post-adverse-explanation-30-days requirement beginning january 1, 2027, within 30 days of an adverse consequential decision made using covered automated decision-making technology, the deployer must give the consumer a plain-language explanation covering the ai's role in the decision, its degree of contribution, the types of data processed, and the sources of that data. admt adverse decision explanation 30 days colorado sb26-189"},{"type":"obligation","name":"AI-Authorized Prescription Renewal (Utah Pilot)","id":"ai-authorized-rx-renewal","href":"primary/ai-authorized-rx-renewal/index.html","group":"permission","_search":"ai-authorized prescription renewal (utah pilot) ai-authorized-rx-renewal permission during the mitigation period, a participant may use its ai technology to authorize the renewal of a verified prescription for a utah resident and issue such prescriptions to a pharmacist licensed under utah code §58-17b. mitigation applies solely to the renewal workflow described in the proposal; it does not extend to new prescriptions, other services, or products outside the authorized scope. prescription renewal ai rx telehealth doctronic legion 58-17b"},{"type":"obligation","name":"GenAI Is Not A Defense — Civil And Criminal","id":"ai-defense-elimination","href":"primary/ai-defense-elimination/index.html","group":"restriction","_search":"genai is not a defense — civil and criminal ai-defense-elimination restriction utah removed \"the ai did it\" as a defense in both civil and criminal contexts. a principal who uses, prompts, or acts through generative ai remains liable for the resulting statement or act. the criminal rule (§76-2-107, sb 149, effective 2024-05-01) and the civil mirror together eliminate the doctrine across utah consumer-protection and criminal law. the civil rule was first enacted at §13-2-12(2) (sb 149, effective 2024-05-01) and re-sited at §13-75-102 (sb 226, effective 2025-05-07). ai defense liability civil criminal sb149 sb226"},{"type":"obligation","name":"Pay-To-Pay Fee Prohibited Without Express Authorization","id":"cfpb-pay-to-pay-fee-prohibited","href":"primary/cfpb-pay-to-pay-fee-prohibited/index.html","group":"restriction","_search":"pay-to-pay fee prohibited without express authorization cfpb-pay-to-pay-fee-prohibited restriction a debt collector subject to the fair debt collection practices act may not charge a pay-to-pay convenience fee for online or phone payments unless the fee is either expressly authorized by the agreement creating the debt or affirmatively permitted by a specific law. silence, absence of prohibition, and third-party payment-processor routing do not cure the violation. fdcpa pay-to-pay convenience fee debt collection regulation f"},{"type":"obligation","name":"Unbundled Advice Fee Does Not Trigger CTA Registration","id":"cftc-unbundled-fee-not-cta-trigger","href":"primary/cftc-unbundled-fee-not-cta-trigger/index.html","group":"permission","_search":"unbundled advice fee does not trigger cta registration cftc-unbundled-fee-not-cta-trigger permission a registered fcm, swap dealer, or introducing broker that qualifies for the cta exclusion or exemption does not lose that status solely because it begins receiving a separate unbundled fee for commodity trading advice. the \"solely incidental\" or \"solely in connection with\" test continues to govern under a facts-and-circumstances analysis; separate compensation is one factor but is not dispositive. cta registration mifid ii fcm swap dealer introducing broker unbundled fee"},{"type":"obligation","name":"Mental Health Chatbot — No Third-Party Data Sharing","id":"chatbot-data-no-third-party-sharing","href":"primary/chatbot-data-no-third-party-sharing/index.html","group":"restriction","_search":"mental health chatbot — no third-party data sharing chatbot-data-no-third-party-sharing restriction a mental health chatbot supplier may not sell or share identifiable health information or user inputs with third parties. narrow exceptions exist for user-consented or user-requested transfers to a health care provider or plan. third-party sharing for functionality requires hipaa-equivalent controls (45 cfr parts 160 and 164, subparts a and e) as if the supplier were a covered entity. chatbot mental health data protection hipaa hb452"},{"type":"obligation","name":"Mental Health Chatbot — File 15-Element Safety Policy","id":"chatbot-safety-policy-filing","href":"primary/chatbot-safety-policy-filing/index.html","group":"requirement","_search":"mental health chatbot — file 15-element safety policy chatbot-safety-policy-filing requirement filing is a condition of an affirmative defense, not a free-standing mandate. a mental health chatbot supplier has an affirmative defense against §58-1-501(1)-(2) unauthorized-practice actions if it shows that it created, maintained, and implemented a written policy meeting §58-60-118(3), including the fifteen procedure elements in (3)(c)(i)-(xv); maintains the development and implementation documentation required by (2)(b); filed the policy with utah's division of consumer protection; and complied with the filed policy at the time of the alleged violation. chatbot mental health safety policy safe harbor filing hb452"},{"type":"obligation","name":"Dentacor — §58-69-5 Enforcement Forborne","id":"dentacor-58-69-5-enforcement-forborne","href":"primary/dentacor-58-69-5-enforcement-forborne/index.html","group":"permission","_search":"dentacor — §58-69-5 enforcement forborne dentacor-58-69-5-enforcement-forborne permission during the dentacor demonstration period, the utah division of professional licensing (dopl) forgave enforcement of unlawful and unprofessional-conduct actions under utah code §58-69-5 solely for conduct authorized by the rma. the initial mitigation period ended may 31, 2026, and no public extension instrument was located as of july 25, 2026. dentacor enforcement 58-69-5 unlawful conduct forbearance"},{"type":"obligation","name":"Dentacor — Hygienist + AI Concurrence Diagnosis","id":"dentacor-hygienist-ai-concurrence-diagnosis","href":"primary/dentacor-hygienist-ai-concurrence-diagnosis/index.html","group":"permission","_search":"dentacor — hygienist + ai concurrence diagnosis dentacor-hygienist-ai-concurrence-diagnosis permission during the initial dentacor rma term, licensed utah dental hygienists employed by dentacor could diagnose periodontal disease, complete edentulism, and complete anodontia using an ai-assisted radiograph diagnostic tool in place of general dentist supervision. the permission required concurrence of both the hygienist and the ai system and expired with the initial mitigation period on may 31, 2026; no public extension instrument was located as of july 25, 2026. dentacor hygienist radiograph diagnosis ai concurrence"},{"type":"obligation","name":"Dentacor — Informed Consent Disclosing Absence Of Dentist","id":"dentacor-informed-consent-no-dentist","href":"primary/dentacor-informed-consent-no-dentist/index.html","group":"requirement","_search":"dentacor — informed consent disclosing absence of dentist dentacor-informed-consent-no-dentist requirement during the initial dentacor rma term, a dentacor-employed hygienist had to obtain patient informed consent before any rma-authorized procedure, explicitly disclosing the absence of dentist supervision and the hygienist's narrower training and scope. the requirement expired with the initial mitigation period on may 31, 2026; no public extension instrument was located as of july 25, 2026. dentacor informed consent dentist supervision patient disclosure"},{"type":"obligation","name":"Proactive GenAI Disclosure In High-Risk Interactions","id":"disclose-genai-high-risk-proactive","href":"primary/disclose-genai-high-risk-proactive/index.html","group":"requirement","_search":"proactive genai disclosure in high-risk interactions disclose-genai-high-risk-proactive requirement a supplier engaged in a \"high-risk ai interaction\" in a regulated occupation must proactively disclose genai use before the interaction begins — verbally at the start of an oral exchange, and in writing before a written exchange. the high-risk tier is statutorily defined and narrower than general consumer interactions. disclosure high-risk regulated occupation proactive sb226"},{"type":"obligation","name":"Disclose GenAI on First Session","id":"disclose-genai-on-first-session","href":"primary/disclose-genai-on-first-session/index.html","group":"requirement","_search":"disclose genai on first session disclose-genai-on-first-session requirement disclose plainly that the person is interacting with generative ai and not a human. when the disclosure is due depends on the utah provision: on a clear request in a consumer transaction (§13-75-103(1)); at the start of a high-risk interaction in a regulated occupation (§13-75-103(2)-(3)); and for a mental health chatbot, before access, again after seven days without access, and whenever asked (§13-72a-203(2)). no utah provision anchored here requires re-display at every session or after a fixed inactivity period. disclosure genai first session chatbot"},{"type":"obligation","name":"Disclose GenAI On Consumer Request","id":"disclose-genai-on-request","href":"primary/disclose-genai-on-request/index.html","group":"requirement","_search":"disclose genai on consumer request disclose-genai-on-request requirement a supplier using generative ai in a consumer transaction must disclose that fact when the consumer makes a clear and unambiguous request. a safe harbor is available: a clear and conspicuous disclosure at the outset and throughout the interaction eliminates enforcement exposure, regardless of whether a request is made. disclosure genai consumer request safe harbor sb226"},{"type":"obligation","name":"ElizaChat — Three-Phase Rollout Gate","id":"elizachat-phased-rollout","href":"primary/elizachat-phased-rollout/index.html","group":"requirement","_search":"elizachat — three-phase rollout gate elizachat-phased-rollout requirement elizachat must be released in three sequential phases — oaip trusted-tester cohort, oaip-reviewed limited student cohort, and full utah-district student availability — with written oaip approval required before advancing to each subsequent phase. elizachat phased rollout trusted tester phase gate"},{"type":"obligation","name":"ElizaChat — Pre-Access Disclosure Bundle","id":"elizachat-pre-access-disclosure-bundle","href":"primary/elizachat-pre-access-disclosure-bundle/index.html","group":"requirement","_search":"elizachat — pre-access disclosure bundle elizachat-pre-access-disclosure-bundle requirement before granting any user access to elizachat app functionality, the participant must present a five-element disclosure — participant identity, genai use notice, testing-risk notice, data use and sharing practices, and oaip complaint channel — in clear and conspicuous form, and must secure user acknowledgment before access is granted. elizachat disclosure pre-access disclosure bundle"},{"type":"obligation","name":"High-Risk AI Consumer Notice, Correction, And Appeal","id":"high-risk-ai-consumer-notice-correction-and-appeal","href":"primary/high-risk-ai-consumer-notice-correction-and-appeal/index.html","group":"requirement","_search":"high-risk ai consumer notice, correction, and appeal high-risk-ai-consumer-notice-correction-and-appeal requirement deployers would have been required to notify consumers before using a high-risk artificial intelligence system in a consequential decision and, after an adverse decision, provide the principal reasons, an opportunity to correct incorrect personal data, and an appeal with human review where technically feasible. the obligation is retained from the predecessor colorado sb 24-205 framework. predecessor operative history remains unresolved; sb 26-189 section 5 qualifies replacement timing, and signature alone does not establish when predecessor duties ceased or whether they operated. high-risk artificial intelligence consumer notice adverse consequential decision data correction appeal human review colorado sb24-205"},{"type":"obligation","name":"High-Risk AI Impact Assessment","id":"high-risk-ai-impact-assessment","href":"primary/high-risk-ai-impact-assessment/index.html","group":"requirement","_search":"high-risk ai impact assessment high-risk-ai-impact-assessment requirement deployers would have been required to complete an impact assessment for each covered high-risk artificial intelligence system, repeat it at least annually and after intentional and substantial modifications, and retain the assessment records. the obligation is retained from the predecessor colorado sb 24-205 framework. predecessor operative history remains unresolved; sb 26-189 section 5 qualifies replacement timing, and signature alone does not establish when predecessor duties ceased or whether they operated. high-risk artificial intelligence impact assessment annual assessment algorithmic discrimination deployer colorado sb24-205"},{"type":"obligation","name":"High-Risk AI Reasonable Care Against Algorithmic Discrimination","id":"high-risk-ai-reasonable-care-against-algorithmic-discrimination","href":"primary/high-risk-ai-reasonable-care-against-algorithmic-discrimination/index.html","group":"requirement","_search":"high-risk ai reasonable care against algorithmic discrimination high-risk-ai-reasonable-care-against-algorithmic-discrimination requirement developers and deployers of high-risk artificial intelligence systems would have been required to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. the obligation is retained from the predecessor colorado sb 24-205 framework. predecessor operative history remains unresolved; sb 26-189 section 5 qualifies replacement timing, and signature alone does not establish when predecessor duties ceased or whether they operated. high-risk artificial intelligence reasonable care algorithmic discrimination developer deployer colorado sb24-205"},{"type":"obligation","name":"§501(c)(3) Exemption Denied — Organizational And Operational Test Failure","id":"irs-501c3-dual-test-failure","href":"primary/irs-501c3-dual-test-failure/index.html","group":"restriction","_search":"§501(c)(3) exemption denied — organizational and operational test failure irs-501c3-dual-test-failure restriction an organization fails §501(c)(3) exemption where its articles of incorporation neither limit purposes to exempt activities nor dedicate assets to exempt purposes on dissolution, and where a substantial portion of its activities consists of unrestricted commercial leasing coupled with fundraising that benefits a for-profit entity controlled by one of its own directors. bylaws containing the required provisions do not cure deficient articles; a single substantial non-exempt purpose is disqualifying regardless of any exempt purposes present. 501c3 organizational test operational test private inurement commercial leasing adverse determination"},{"type":"obligation","name":"Incentive-Fee Management Contract Not A Share Of Net Profits","id":"irs-incentive-fee-not-net-profits-share","href":"primary/irs-incentive-fee-not-net-profits-share/index.html","group":"permission","_search":"incentive-fee management contract not a share of net profits irs-incentive-fee-not-net-profits-share permission on the facts represented, an incentive-fee management contract between a §501(c)(3) bond issuer and a hotel manager — where the incentive fee is calculated on gross revenue subject to an adjustment contingent on a net-profit-variant metric — does not constitute sharing of net profits under rev. proc. 2017-13 §5.02(2) and therefore does not cause private business use under irc §141. the ruling applies only to the requesting taxpayer on the specific facts presented. private business use 501c3 bonds rev proc 2017-13 safe harbor incentive fee"},{"type":"obligation","name":"Learning Lab Agreement — Eligibility and Participation","id":"learning-lab-agreement-participation","href":"primary/learning-lab-agreement-participation/index.html","group":"permission","_search":"learning lab agreement — eligibility and participation learning-lab-agreement-participation permission a person deploying ai in utah may enter either a regulatory mitigation agreement (rma) — which waives specified law in exchange for safeguards, data sharing, and disclosures — or a joint interpretation agreement (jia) — which clarifies how existing statute applies to a specific ai use without waiver. agreements run for an initial twelve months with up to two twelve-month extensions, counterparties include oaip plus the relevant state agency (or the judiciary, a state-funded higher or public education institution, or a political subdivision under hb 320), and participants must satisfy five statutory eligibility prongs. learning lab regulatory mitigation joint interpretation oaip sandbox sb149 hb320"},{"type":"obligation","name":"Named-Prescriber Enforcement Forborne","id":"named-prescriber-enforcement-forborne","href":"primary/named-prescriber-enforcement-forborne/index.html","group":"permission","_search":"named-prescriber enforcement forborne named-prescriber-enforcement-forborne permission dopl forgoes unlawful-conduct and unprofessional-conduct enforcement under §58-1-501(1)-(2) and related professional-licensing provisions against any provider who (1) acts solely as the named prescriber for ai-authorized renewals and (2) does not interact directly with a patient or other provider. legion §16(d) adds a condition that the provider abides by the agreement and any agreement with the participant; doctronic §15(d) states no such condition. the covered chapter provisions differ by agreement. forbearance applies only to conduct authorized by the agreement. named prescriber enforcement forbearance unprofessional conduct 58-1-501 doctronic legion"},{"type":"obligation","name":"RMA — Data Security Under §63A-19-102","id":"rma-data-security-63a-19-102","href":"primary/rma-data-security-63a-19-102/index.html","group":"requirement","_search":"rma — data security under §63a-19-102 rma-data-security-63a-19-102 requirement an rma participant must implement data security measures conforming to utah code §63a-19-102 and maintain a cybersecurity framework that is updated on an ongoing basis to address emerging threats and vulnerabilities. no statutory or common-law cybersecurity obligation is waived by the rma. rma data security cybersecurity 63a-19-102"},{"type":"obligation","name":"RMA — 30-Day End-Of-Term Report","id":"rma-end-of-term-report","href":"primary/rma-end-of-term-report/index.html","group":"requirement","_search":"rma — 30-day end-of-term report rma-end-of-term-report requirement within thirty days after the end date of an rma, the participant must file a written report with oaip summarizing the demonstration, any incidents of harm, any legal actions, and any complaints filed against the participant in connection with the mitigation period. rma reporting termination end of term"},{"type":"obligation","name":"RMA — Hold Harmless The State","id":"rma-hold-harmless-state","href":"primary/rma-hold-harmless-state/index.html","group":"requirement","_search":"rma — hold harmless the state rma-hold-harmless-state requirement an rma participant agrees to hold oaip, the relevant division, and their agents, officers, and employees harmless from any claims, liabilities, damages, losses, or expenses arising from the participant's work performed under the mitigation. rma indemnification hold harmless"},{"type":"obligation","name":"RMA — 24-Hour Incident Notification","id":"rma-incident-notification-24hr","href":"primary/rma-incident-notification-24hr/index.html","group":"requirement","_search":"rma — 24-hour incident notification rma-incident-notification-24hr requirement an rma participant must notify oaip within 24 hours of any incident that results in harm to the health, safety, or financial well-being of a user of the mitigated technology. rma incident notification harm 24 hours"},{"type":"obligation","name":"RMA — Monthly Report To OAIP","id":"rma-monthly-report-to-oaip","href":"primary/rma-monthly-report-to-oaip/index.html","group":"requirement","_search":"rma — monthly report to oaip rma-monthly-report-to-oaip requirement each learning lab rma participant submits a monthly report to oaip at `ai@utah.gov` covering user data, incidents, complaints, research findings, and any other information specified by the office. the report is the primary ongoing accountability mechanism between participant and regulator during the mitigation period. rma reporting monthly oaip learning lab"},{"type":"obligation","name":"RMA — No Advertising Reference To Agreement","id":"rma-no-advertising-reference","href":"primary/rma-no-advertising-reference/index.html","group":"restriction","_search":"rma — no advertising reference to agreement rma-no-advertising-reference restriction an rma participant may not reference the existence of the agreement in advertising, media, or promotional materials. the mitigation is a regulatory posture, not a marketable endorsement by the state of utah. rma advertising promotion marketing"},{"type":"obligation","name":"Rule 506(c) Verification Via High-Minimum + Representation","id":"sec-reg-d-506c-verification-safe-harbor","href":"primary/sec-reg-d-506c-verification-safe-harbor/index.html","group":"permission","_search":"rule 506(c) verification via high-minimum + representation sec-reg-d-506c-verification-safe-harbor permission an issuer conducting a rule 506(c) offering satisfies the \"reasonable steps to verify\" accredited-investor requirement when it (1) imposes a minimum investment amount high enough that only accredited investors would reasonably be expected to meet it, (2) obtains written representations of accredited status and that the investment is not financed by a third party for purposes of the investment, and (3) has no actual knowledge of contradictory facts. the position restates the principles-based standard; it does not create an exclusive verification method. rule 506c accredited investor reasonable steps to verify regulation d private placement"},{"type":"obligation","name":"Telehealth Compliance Anchored To Participant Proposal","id":"telehealth-compliance-per-proposal","href":"primary/telehealth-compliance-per-proposal/index.html","group":"requirement","_search":"telehealth compliance anchored to participant proposal telehealth-compliance-per-proposal requirement a participant operating ai-assisted prescription renewal must adhere to utah's telehealth provider requirements in §26b-4-704, with specific subsections deemed satisfied by following protocols described in the participant's proposal (schedule b): doctronic parts 2b and 3b; legion proposal section 4. certain subsections (e.g., the patient-records portability default) are inapplicable; others are substituted by proposal-section conformance. telehealth 26b-4-704 proposal compliance doctronic legion"},{"type":"authority","name":"Consumer Financial Protection Bureau","id":"cfpb","href":"authority/cfpb/index.html","jurisdiction":"us","_search":"consumer financial protection bureau cfpb us"},{"type":"authority","name":"CFTC Division of Swap Dealer and Intermediary Oversight","id":"cftc-dsio","href":"authority/cftc-dsio/index.html","jurisdiction":"us","_search":"cftc division of swap dealer and intermediary oversight cftc-dsio us"},{"type":"authority","name":"Colorado General Assembly","id":"colorado-legislature","href":"authority/colorado-legislature/index.html","jurisdiction":"us-co","_search":"colorado general assembly colorado-legislature us-co"},{"type":"authority","name":"IRS Office of Chief Counsel","id":"irs-chief-counsel","href":"authority/irs-chief-counsel/index.html","jurisdiction":"us","_search":"irs office of chief counsel irs-chief-counsel us"},{"type":"authority","name":"IRS Tax Exempt and Government Entities Division","id":"irs-tege","href":"authority/irs-tege/index.html","jurisdiction":"us","_search":"irs tax exempt and government entities division irs-tege us"},{"type":"authority","name":"SEC Division of Corporation Finance","id":"sec-corpfin","href":"authority/sec-corpfin/index.html","jurisdiction":"us","_search":"sec division of corporation finance sec-corpfin us"},{"type":"authority","name":"Utah State Legislature","id":"utah-legislature","href":"authority/utah-legislature/index.html","jurisdiction":"us-ut","_search":"utah state legislature utah-legislature us-ut"},{"type":"authority","name":"Utah Office of Artificial Intelligence Policy","id":"utah-oaip","href":"authority/utah-oaip/index.html","jurisdiction":"us-ut","_search":"utah office of artificial intelligence policy utah-oaip us-ut"}] \ No newline at end of file +[{"type":"legal instrument","name":"CFPB Advisory Opinion — Pay-to-Pay Fees (Regulation F)","id":"us-cfpb-ao-2022-001","href":"/us/federal/cfpb/ao/2022-001/","jurisdiction":"us","_search":"cfpb advisory opinion — pay-to-pay fees (regulation f) us us-cfpb-ao-2022-001 enforcing"},{"type":"legal instrument","name":"CFTC Letter 17-65 — CTA Registration Exemption Survives MiFID II Fee Unbundling","id":"us-cftc-dsio-il-2017-001","href":"/us/federal/cftc-dsio/il/2017-001/","jurisdiction":"us","_search":"cftc letter 17-65 — cta registration exemption survives mifid ii fee unbundling us us-cftc-dsio-il-2017-001 enforcing"},{"type":"legal instrument","name":"Colorado SB 24-205 (2024) — Consumer Protections for Interactions with Artificial Intelligence Systems","id":"us-co-legislature-statute-2024-sb24-205","href":"/us/colorado/legislature/statute/2024-001/","jurisdiction":"us-co","_search":"colorado sb 24-205 (2024) — consumer protections for interactions with artificial intelligence systems us-co us-co-legislature-statute-2024-sb24-205 superseded"},{"type":"legal instrument","name":"Colorado SB 25B-004 (2025) — Increase Transparency for Algorithmic Systems (Colorado AI Act Effective-Date Delay)","id":"us-co-legislature-statute-2025-sb25b-004","href":"/us/colorado/legislature/statute/2025-001/","jurisdiction":"us-co","_search":"colorado sb 25b-004 (2025) — increase transparency for algorithmic systems (colorado ai act effective-date delay) us-co us-co-legislature-statute-2025-sb25b-004 enforcing"},{"type":"legal instrument","name":"Colorado SB 26-189 (2026) — Automated Decision-Making Technology (ADMT) Act","id":"us-co-legislature-statute-2026-sb26-189","href":"/us/colorado/legislature/statute/2026-001/","jurisdiction":"us-co","_search":"colorado sb 26-189 (2026) — automated decision-making technology (admt) act us-co us-co-legislature-statute-2026-sb26-189 enacted"},{"type":"legal instrument","name":"IRS Private Letter Ruling 202506001 — Management Contract Private Business Use (§141)","id":"us-irs-chief-counsel-plr-2025-001","href":"/us/federal/irs-chief-counsel/plr/2025-001/","jurisdiction":"us","_search":"irs private letter ruling 202506001 — management contract private business use (§141) us us-irs-chief-counsel-plr-2025-001 enforcing"},{"type":"legal instrument","name":"IRS PLR 202614036 — Adverse Determination: §501(c)(3) Exemption Denied, Mixed-Use Facility","id":"us-irs-tege-plr-2026-001","href":"/us/federal/irs-tege/plr/2026-001/","jurisdiction":"us","_search":"irs plr 202614036 — adverse determination: §501(c)(3) exemption denied, mixed-use facility us us-irs-tege-plr-2026-001 enforcing"},{"type":"legal instrument","name":"SEC No-Action Letter — Latham & Watkins (Rule 506(c) Verification)","id":"us-sec-corpfin-nal-2025-001","href":"/us/federal/sec-corpfin/nal/2025-001/","jurisdiction":"us","_search":"sec no-action letter — latham & watkins (rule 506(c) verification) us us-sec-corpfin-nal-2025-001 enforcing"},{"type":"legal instrument","name":"Utah SB 149 (2024) — Artificial Intelligence Amendments","id":"us-ut-legislature-statute-2024-sb149","href":"/us/utah/legislature/statute/2024-001/","jurisdiction":"us-ut","_search":"utah sb 149 (2024) — artificial intelligence amendments us-ut us-ut-legislature-statute-2024-sb149 enforcing"},{"type":"legal instrument","name":"Utah HB 452 (2025) — Artificial Intelligence Amendments (Mental Health Chatbots)","id":"us-ut-legislature-statute-2025-hb452","href":"/us/utah/legislature/statute/2025-002/","jurisdiction":"us-ut","_search":"utah hb 452 (2025) — artificial intelligence amendments (mental health chatbots) us-ut us-ut-legislature-statute-2025-hb452 enforcing"},{"type":"legal instrument","name":"Utah SB 226 (2025) — Artificial Intelligence Consumer Protection Amendments","id":"us-ut-legislature-statute-2025-sb226","href":"/us/utah/legislature/statute/2025-001/","jurisdiction":"us-ut","_search":"utah sb 226 (2025) — artificial intelligence consumer protection amendments us-ut us-ut-legislature-statute-2025-sb226 enforcing"},{"type":"legal instrument","name":"Utah SB 332 (2025) — Artificial Intelligence Revisions (AIPA Sunset Extension)","id":"us-ut-legislature-statute-2025-sb332","href":"/us/utah/legislature/statute/2025-003/","jurisdiction":"us-ut","_search":"utah sb 332 (2025) — artificial intelligence revisions (aipa sunset extension) us-ut us-ut-legislature-statute-2025-sb332 enforcing"},{"type":"legal instrument","name":"Utah HB 320 (2026) — Office of Artificial Intelligence Policy Amendments (Learning Lab Restructure + Joint Interpretation Agreements)","id":"us-ut-legislature-statute-2026-hb320","href":"/us/utah/legislature/statute/2026-001/","jurisdiction":"us-ut","_search":"utah hb 320 (2026) — office of artificial intelligence policy amendments (learning lab restructure + joint interpretation agreements) us-ut us-ut-legislature-statute-2026-hb320 enforcing"},{"type":"legal instrument","name":"Utah Mental Health Chatbot Disclosure — Joint Interpretation","id":"us-ut-oaip-jia-2026-001","href":"/us/utah/oaip/jia/2026-001/","jurisdiction":"us-ut","_search":"utah mental health chatbot disclosure — joint interpretation us-ut us-ut-oaip-jia-2026-001 proposed"},{"type":"legal instrument","name":"Utah OAIP × ElizaChat — Teen Mental-Health App RMA (2024)","id":"us-ut-oaip-rma-2024-001","href":"/us/utah/oaip/rma/2024-001/","jurisdiction":"us-ut","_search":"utah oaip × elizachat — teen mental-health app rma (2024) us-ut us-ut-oaip-rma-2024-001 expired"},{"type":"legal instrument","name":"Utah OAIP × Dentacor — AI-Assisted Dental Radiograph Diagnosis RMA (2025)","id":"us-ut-oaip-rma-2025-001","href":"/us/utah/oaip/rma/2025-001/","jurisdiction":"us-ut","_search":"utah oaip × dentacor — ai-assisted dental radiograph diagnosis rma (2025) us-ut us-ut-oaip-rma-2025-001 expired"},{"type":"legal instrument","name":"Utah OAIP × Doctronic — AI Prescription Renewal RMA (2025)","id":"us-ut-oaip-rma-2025-002","href":"/us/utah/oaip/rma/2025-002/","jurisdiction":"us-ut","_search":"utah oaip × doctronic — ai prescription renewal rma (2025) us-ut us-ut-oaip-rma-2025-002 enforcing"},{"type":"legal instrument","name":"Utah OAIP × Legion Health — AI Maintenance Psychiatric Refill RMA (2026)","id":"us-ut-oaip-rma-2026-001","href":"/us/utah/oaip/rma/2026-001/","jurisdiction":"us-ut","_search":"utah oaip × legion health — ai maintenance psychiatric refill rma (2026) us-ut us-ut-oaip-rma-2026-001 enacted"},{"type":"obligation","name":"ADMT Sixty-Day Cure Period Before Enforcement","id":"admt-60-day-cure-period","href":"primary/admt-60-day-cure-period/index.html","group":"permission","_search":"admt sixty-day cure period before enforcement admt-60-day-cure-period permission beginning january 1, 2027, violations of the colorado admt act are enforced by the attorney general as deceptive trade practices, with no private right of action. a regulated party may cure an alleged violation within 60 days of notice; the cure route is available through january 1, 2030. admt cure period attorney general deceptive trade practice colorado sb26-189"},{"type":"obligation","name":"ADMT Data Correction And Human Review Of Adverse Outcomes","id":"admt-correction-and-human-review","href":"primary/admt-correction-and-human-review/index.html","group":"requirement","_search":"admt data correction and human review of adverse outcomes admt-correction-and-human-review requirement beginning january 1, 2027, consumers subject to an adverse consequential decision made using covered automated decision-making technology may correct inaccurate personal data used in that decision and may request meaningful human review and reconsideration of the outcome. the deployer must provide both paths. admt human review data correction reconsideration colorado sb26-189"},{"type":"obligation","name":"ADMT Deployer Three-Year Record Retention","id":"admt-deployer-3-year-record-retention","href":"primary/admt-deployer-3-year-record-retention/index.html","group":"requirement","_search":"admt deployer three-year record retention admt-deployer-3-year-record-retention requirement beginning january 1, 2027, a deployer of covered automated decision-making technology must retain its compliance documentation for at least three years. the retention floor is what makes the notice, explanation, and review duties auditable by the attorney general after the fact. admt record keeping retention three years colorado sb26-189"},{"type":"obligation","name":"ADMT Deployer Notice Before Consequential Decision","id":"admt-deployer-pre-decision-notice","href":"primary/admt-deployer-pre-decision-notice/index.html","group":"requirement","_search":"admt deployer notice before consequential decision admt-deployer-pre-decision-notice requirement beginning january 1, 2027, before a consequential decision is made using covered automated decision-making technology, the deployer must notify the consumer that an automated system is in use and disclose the purpose and nature of the decision. the notice is pre-decision; a post-hoc disclosure does not satisfy it. admt consumer notice consequential decision deployer colorado sb26-189"},{"type":"obligation","name":"ADMT Developer Documentation To Deployer","id":"admt-developer-documentation-to-deployer","href":"primary/admt-developer-documentation-to-deployer/index.html","group":"requirement","_search":"admt developer documentation to deployer admt-developer-documentation-to-deployer requirement beginning january 1, 2027, a developer of covered automated decision-making technology must disclose to deployers the technology's intended uses, the categories of data used to train it, its known limitations, and instructions for meaningful human review. the duty runs developer-to-deployer, not developer-to-consumer. admt developer documentation training data known limitations colorado sb26-189"},{"type":"obligation","name":"ADMT Post-Adverse Explanation Within 30 Days","id":"admt-post-adverse-explanation-30-days","href":"primary/admt-post-adverse-explanation-30-days/index.html","group":"requirement","_search":"admt post-adverse explanation within 30 days admt-post-adverse-explanation-30-days requirement beginning january 1, 2027, within 30 days of an adverse consequential decision made using covered automated decision-making technology, the deployer must give the consumer a plain-language explanation covering the ai's role in the decision, its degree of contribution, the types of data processed, and the sources of that data. admt adverse decision explanation 30 days colorado sb26-189"},{"type":"obligation","name":"AI-Authorized Prescription Renewal (Utah Pilot)","id":"ai-authorized-rx-renewal","href":"primary/ai-authorized-rx-renewal/index.html","group":"permission","_search":"ai-authorized prescription renewal (utah pilot) ai-authorized-rx-renewal permission during the mitigation period, a participant may use its ai technology to authorize the renewal of a verified prescription for a utah resident and issue such prescriptions to a pharmacist licensed under utah code §58-17b. mitigation applies solely to the renewal workflow described in the proposal; it does not extend to new prescriptions, other services, or products outside the authorized scope. prescription renewal ai rx telehealth doctronic legion 58-17b"},{"type":"obligation","name":"GenAI Is Not A Defense — Civil And Criminal","id":"ai-defense-elimination","href":"primary/ai-defense-elimination/index.html","group":"restriction","_search":"genai is not a defense — civil and criminal ai-defense-elimination restriction utah removed \"the ai did it\" as a defense in both civil and criminal contexts. a principal who uses, prompts, or acts through generative ai remains liable for the resulting statement or act. the criminal rule (§76-2-107, sb 149, effective 2024-05-01) and the civil mirror together eliminate the doctrine across utah consumer-protection and criminal law. the civil rule was first enacted at §13-2-12(2) (sb 149, effective 2024-05-01) and re-sited at §13-75-102 (sb 226, effective 2025-05-07). ai defense liability civil criminal sb149 sb226"},{"type":"obligation","name":"Pay-To-Pay Fee Prohibited Without Express Authorization","id":"cfpb-pay-to-pay-fee-prohibited","href":"primary/cfpb-pay-to-pay-fee-prohibited/index.html","group":"restriction","_search":"pay-to-pay fee prohibited without express authorization cfpb-pay-to-pay-fee-prohibited restriction a debt collector subject to the fair debt collection practices act may not charge a pay-to-pay convenience fee for online or phone payments unless the fee is either expressly authorized by the agreement creating the debt or affirmatively permitted by a specific law. silence, absence of prohibition, and third-party payment-processor routing do not cure the violation. fdcpa pay-to-pay convenience fee debt collection regulation f"},{"type":"obligation","name":"Unbundled Advice Fee Does Not Trigger CTA Registration","id":"cftc-unbundled-fee-not-cta-trigger","href":"primary/cftc-unbundled-fee-not-cta-trigger/index.html","group":"permission","_search":"unbundled advice fee does not trigger cta registration cftc-unbundled-fee-not-cta-trigger permission a registered fcm, swap dealer, or introducing broker that qualifies for the cta exclusion or exemption does not lose that status solely because it begins receiving a separate unbundled fee for commodity trading advice. the \"solely incidental\" or \"solely in connection with\" test continues to govern under a facts-and-circumstances analysis; separate compensation is one factor but is not dispositive. cta registration mifid ii fcm swap dealer introducing broker unbundled fee"},{"type":"obligation","name":"Mental Health Chatbot — No Third-Party Data Sharing","id":"chatbot-data-no-third-party-sharing","href":"primary/chatbot-data-no-third-party-sharing/index.html","group":"restriction","_search":"mental health chatbot — no third-party data sharing chatbot-data-no-third-party-sharing restriction a mental health chatbot supplier may not sell or share identifiable health information or user inputs with third parties. narrow exceptions exist for user-consented or user-requested transfers to a health care provider or plan. third-party sharing for functionality requires hipaa-equivalent controls (45 cfr parts 160 and 164, subparts a and e) as if the supplier were a covered entity. chatbot mental health data protection hipaa hb452"},{"type":"obligation","name":"Mental Health Chatbot — File 15-Element Safety Policy","id":"chatbot-safety-policy-filing","href":"primary/chatbot-safety-policy-filing/index.html","group":"requirement","_search":"mental health chatbot — file 15-element safety policy chatbot-safety-policy-filing requirement filing is a condition of an affirmative defense, not a free-standing mandate. a mental health chatbot supplier has an affirmative defense against §58-1-501(1)-(2) unauthorized-practice actions if it shows that it created, maintained, and implemented a written policy meeting §58-60-118(3), including the fifteen procedure elements in (3)(c)(i)-(xv); maintains the development and implementation documentation required by (2)(b); filed the policy with utah's division of consumer protection; and complied with the filed policy at the time of the alleged violation. chatbot mental health safety policy safe harbor filing hb452"},{"type":"obligation","name":"Dentacor — §58-69-5 Enforcement Forborne","id":"dentacor-58-69-5-enforcement-forborne","href":"primary/dentacor-58-69-5-enforcement-forborne/index.html","group":"permission","_search":"dentacor — §58-69-5 enforcement forborne dentacor-58-69-5-enforcement-forborne permission during the dentacor demonstration period, the utah division of professional licensing (dopl) forgave enforcement of unlawful and unprofessional-conduct actions under utah code §58-69-5 solely for conduct authorized by the rma. the initial mitigation period ended may 31, 2026, and no public extension instrument was located as of july 25, 2026. dentacor enforcement 58-69-5 unlawful conduct forbearance"},{"type":"obligation","name":"Dentacor — Hygienist + AI Concurrence Diagnosis","id":"dentacor-hygienist-ai-concurrence-diagnosis","href":"primary/dentacor-hygienist-ai-concurrence-diagnosis/index.html","group":"permission","_search":"dentacor — hygienist + ai concurrence diagnosis dentacor-hygienist-ai-concurrence-diagnosis permission during the initial dentacor rma term, licensed utah dental hygienists employed by dentacor could diagnose periodontal disease, complete edentulism, and complete anodontia using an ai-assisted radiograph diagnostic tool in place of general dentist supervision. the permission required concurrence of both the hygienist and the ai system and expired with the initial mitigation period on may 31, 2026; no public extension instrument was located as of july 25, 2026. dentacor hygienist radiograph diagnosis ai concurrence"},{"type":"obligation","name":"Dentacor — Informed Consent Disclosing Absence Of Dentist","id":"dentacor-informed-consent-no-dentist","href":"primary/dentacor-informed-consent-no-dentist/index.html","group":"requirement","_search":"dentacor — informed consent disclosing absence of dentist dentacor-informed-consent-no-dentist requirement during the initial dentacor rma term, a dentacor-employed hygienist had to obtain patient informed consent before any rma-authorized procedure, explicitly disclosing the absence of dentist supervision and the hygienist's narrower training and scope. the requirement expired with the initial mitigation period on may 31, 2026; no public extension instrument was located as of july 25, 2026. dentacor informed consent dentist supervision patient disclosure"},{"type":"obligation","name":"Proactive GenAI Disclosure In High-Risk Interactions","id":"disclose-genai-high-risk-proactive","href":"primary/disclose-genai-high-risk-proactive/index.html","group":"requirement","_search":"proactive genai disclosure in high-risk interactions disclose-genai-high-risk-proactive requirement an individual providing services in a regulated occupation must prominently disclose when an individual receiving services is interacting with generative artificial intelligence in the provision of regulated services if that use constitutes a high-risk artificial intelligence interaction (§13-75-103(2)(a)). the statutory actor is the individual providing those services, without a supplier condition. a regulated occupation is regulated by the department of commerce and requires an individual to obtain a license or state certification to practice (§13-75-101(8)). disclosure high-risk regulated occupation proactive sb226"},{"type":"obligation","name":"Disclose GenAI on First Session","id":"disclose-genai-on-first-session","href":"primary/disclose-genai-on-first-session/index.html","group":"requirement","_search":"disclose genai on first session disclose-genai-on-first-session requirement disclose plainly that the person is interacting with generative ai and not a human. when the disclosure is due depends on the utah provision: on a clear request in a consumer transaction (§13-75-103(1)); at the start of a high-risk interaction in a regulated occupation (§13-75-103(2)-(3)); and for a mental health chatbot, before access, again after seven days without access, and whenever asked (§13-72a-203(2)). no utah provision anchored here requires re-display at every session or after a fixed inactivity period. disclosure genai first session chatbot"},{"type":"obligation","name":"Disclose GenAI On Consumer Request","id":"disclose-genai-on-request","href":"primary/disclose-genai-on-request/index.html","group":"requirement","_search":"disclose genai on consumer request disclose-genai-on-request requirement a supplier that uses generative artificial intelligence to interact with an individual in connection with a consumer transaction must disclose that the individual is interacting with generative artificial intelligence and not a human if the individual asks or otherwise prompts the supplier about whether artificial intelligence is being used. the prompt or question must be a clear and unambiguous request to determine whether the interaction is with a human or with artificial intelligence (§13-75-103(1)). disclosure genai consumer request safe harbor sb226"},{"type":"obligation","name":"ElizaChat — Three-Phase Rollout Gate","id":"elizachat-phased-rollout","href":"primary/elizachat-phased-rollout/index.html","group":"requirement","_search":"elizachat — three-phase rollout gate elizachat-phased-rollout requirement elizachat must be released in three sequential phases — oaip trusted-tester cohort, oaip-reviewed limited student cohort, and full utah-district student availability — with written oaip approval required before advancing to each subsequent phase. elizachat phased rollout trusted tester phase gate"},{"type":"obligation","name":"ElizaChat — Pre-Access Disclosure Bundle","id":"elizachat-pre-access-disclosure-bundle","href":"primary/elizachat-pre-access-disclosure-bundle/index.html","group":"requirement","_search":"elizachat — pre-access disclosure bundle elizachat-pre-access-disclosure-bundle requirement before granting any user access to elizachat app functionality, the participant must present a five-element disclosure — participant identity, genai use notice, testing-risk notice, data use and sharing practices, and oaip complaint channel — in clear and conspicuous form, and must secure user acknowledgment before access is granted. elizachat disclosure pre-access disclosure bundle"},{"type":"obligation","name":"High-Risk AI Consumer Notice, Correction, And Appeal","id":"high-risk-ai-consumer-notice-correction-and-appeal","href":"primary/high-risk-ai-consumer-notice-correction-and-appeal/index.html","group":"requirement","_search":"high-risk ai consumer notice, correction, and appeal high-risk-ai-consumer-notice-correction-and-appeal requirement deployers would have been required to notify consumers before using a high-risk artificial intelligence system in a consequential decision and, after an adverse decision, provide the principal reasons, an opportunity to correct incorrect personal data, and an appeal with human review where technically feasible. the obligation is retained from the predecessor colorado sb 24-205 framework. predecessor operative history remains unresolved; sb 26-189 section 5 qualifies replacement timing, and signature alone does not establish when predecessor duties ceased or whether they operated. high-risk artificial intelligence consumer notice adverse consequential decision data correction appeal human review colorado sb24-205"},{"type":"obligation","name":"High-Risk AI Impact Assessment","id":"high-risk-ai-impact-assessment","href":"primary/high-risk-ai-impact-assessment/index.html","group":"requirement","_search":"high-risk ai impact assessment high-risk-ai-impact-assessment requirement deployers would have been required to complete an impact assessment for each covered high-risk artificial intelligence system, repeat it at least annually and after intentional and substantial modifications, and retain the assessment records. the obligation is retained from the predecessor colorado sb 24-205 framework. predecessor operative history remains unresolved; sb 26-189 section 5 qualifies replacement timing, and signature alone does not establish when predecessor duties ceased or whether they operated. high-risk artificial intelligence impact assessment annual assessment algorithmic discrimination deployer colorado sb24-205"},{"type":"obligation","name":"High-Risk AI Reasonable Care Against Algorithmic Discrimination","id":"high-risk-ai-reasonable-care-against-algorithmic-discrimination","href":"primary/high-risk-ai-reasonable-care-against-algorithmic-discrimination/index.html","group":"requirement","_search":"high-risk ai reasonable care against algorithmic discrimination high-risk-ai-reasonable-care-against-algorithmic-discrimination requirement developers and deployers of high-risk artificial intelligence systems would have been required to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. the obligation is retained from the predecessor colorado sb 24-205 framework. predecessor operative history remains unresolved; sb 26-189 section 5 qualifies replacement timing, and signature alone does not establish when predecessor duties ceased or whether they operated. high-risk artificial intelligence reasonable care algorithmic discrimination developer deployer colorado sb24-205"},{"type":"obligation","name":"§501(c)(3) Exemption Denied — Organizational And Operational Test Failure","id":"irs-501c3-dual-test-failure","href":"primary/irs-501c3-dual-test-failure/index.html","group":"restriction","_search":"§501(c)(3) exemption denied — organizational and operational test failure irs-501c3-dual-test-failure restriction an organization fails §501(c)(3) exemption where its articles of incorporation neither limit purposes to exempt activities nor dedicate assets to exempt purposes on dissolution, and where a substantial portion of its activities consists of unrestricted commercial leasing coupled with fundraising that benefits a for-profit entity controlled by one of its own directors. bylaws containing the required provisions do not cure deficient articles; a single substantial non-exempt purpose is disqualifying regardless of any exempt purposes present. 501c3 organizational test operational test private inurement commercial leasing adverse determination"},{"type":"obligation","name":"Incentive-Fee Management Contract Not A Share Of Net Profits","id":"irs-incentive-fee-not-net-profits-share","href":"primary/irs-incentive-fee-not-net-profits-share/index.html","group":"permission","_search":"incentive-fee management contract not a share of net profits irs-incentive-fee-not-net-profits-share permission on the facts represented, an incentive-fee management contract between a §501(c)(3) bond issuer and a hotel manager — where the incentive fee is calculated on gross revenue subject to an adjustment contingent on a net-profit-variant metric — does not constitute sharing of net profits under rev. proc. 2017-13 §5.02(2) and therefore does not cause private business use under irc §141. the ruling applies only to the requesting taxpayer on the specific facts presented. private business use 501c3 bonds rev proc 2017-13 safe harbor incentive fee"},{"type":"obligation","name":"Learning Lab Agreement — Eligibility and Participation","id":"learning-lab-agreement-participation","href":"primary/learning-lab-agreement-participation/index.html","group":"permission","_search":"learning lab agreement — eligibility and participation learning-lab-agreement-participation permission a person deploying ai in utah may enter either a regulatory mitigation agreement (rma) — which waives specified law in exchange for safeguards, data sharing, and disclosures — or a joint interpretation agreement (jia) — which clarifies how existing statute applies to a specific ai use without waiver. agreements run for an initial twelve months with up to two twelve-month extensions, counterparties include oaip plus the relevant state agency (or the judiciary, a state-funded higher or public education institution, or a political subdivision under hb 320), and participants must satisfy five statutory eligibility prongs. learning lab regulatory mitigation joint interpretation oaip sandbox sb149 hb320"},{"type":"obligation","name":"Named-Prescriber Enforcement Forborne","id":"named-prescriber-enforcement-forborne","href":"primary/named-prescriber-enforcement-forborne/index.html","group":"permission","_search":"named-prescriber enforcement forborne named-prescriber-enforcement-forborne permission dopl forgoes unlawful-conduct and unprofessional-conduct enforcement under §58-1-501(1)-(2) and related professional-licensing provisions against any provider who (1) acts solely as the named prescriber for ai-authorized renewals and (2) does not interact directly with a patient or other provider. legion §16(d) adds a condition that the provider abides by the agreement and any agreement with the participant; doctronic §15(d) states no such condition. the covered chapter provisions differ by agreement. forbearance applies only to conduct authorized by the agreement. named prescriber enforcement forbearance unprofessional conduct 58-1-501 doctronic legion"},{"type":"obligation","name":"RMA — Data Security Under §63A-19-102","id":"rma-data-security-63a-19-102","href":"primary/rma-data-security-63a-19-102/index.html","group":"requirement","_search":"rma — data security under §63a-19-102 rma-data-security-63a-19-102 requirement an rma participant must implement data security measures conforming to utah code §63a-19-102 and maintain a cybersecurity framework that is updated on an ongoing basis to address emerging threats and vulnerabilities. no statutory or common-law cybersecurity obligation is waived by the rma. rma data security cybersecurity 63a-19-102"},{"type":"obligation","name":"RMA — 30-Day End-Of-Term Report","id":"rma-end-of-term-report","href":"primary/rma-end-of-term-report/index.html","group":"requirement","_search":"rma — 30-day end-of-term report rma-end-of-term-report requirement within thirty days after the end date of an rma, the participant must file a written report with oaip summarizing the demonstration, any incidents of harm, any legal actions, and any complaints filed against the participant in connection with the mitigation period. rma reporting termination end of term"},{"type":"obligation","name":"RMA — Hold Harmless The State","id":"rma-hold-harmless-state","href":"primary/rma-hold-harmless-state/index.html","group":"requirement","_search":"rma — hold harmless the state rma-hold-harmless-state requirement an rma participant agrees to hold oaip, the relevant division, and their agents, officers, and employees harmless from any claims, liabilities, damages, losses, or expenses arising from the participant's work performed under the mitigation. rma indemnification hold harmless"},{"type":"obligation","name":"RMA — 24-Hour Incident Notification","id":"rma-incident-notification-24hr","href":"primary/rma-incident-notification-24hr/index.html","group":"requirement","_search":"rma — 24-hour incident notification rma-incident-notification-24hr requirement an rma participant must notify oaip within 24 hours of any incident that results in harm to the health, safety, or financial well-being of a user of the mitigated technology. rma incident notification harm 24 hours"},{"type":"obligation","name":"RMA — Monthly Report To OAIP","id":"rma-monthly-report-to-oaip","href":"primary/rma-monthly-report-to-oaip/index.html","group":"requirement","_search":"rma — monthly report to oaip rma-monthly-report-to-oaip requirement each learning lab rma participant submits a monthly report to oaip at `ai@utah.gov` covering user data, incidents, complaints, research findings, and any other information specified by the office. the report is the primary ongoing accountability mechanism between participant and regulator during the mitigation period. rma reporting monthly oaip learning lab"},{"type":"obligation","name":"RMA — No Advertising Reference To Agreement","id":"rma-no-advertising-reference","href":"primary/rma-no-advertising-reference/index.html","group":"restriction","_search":"rma — no advertising reference to agreement rma-no-advertising-reference restriction an rma participant may not reference the existence of the agreement in advertising, media, or promotional materials. the mitigation is a regulatory posture, not a marketable endorsement by the state of utah. rma advertising promotion marketing"},{"type":"obligation","name":"Rule 506(c) Verification Via High-Minimum + Representation","id":"sec-reg-d-506c-verification-safe-harbor","href":"primary/sec-reg-d-506c-verification-safe-harbor/index.html","group":"permission","_search":"rule 506(c) verification via high-minimum + representation sec-reg-d-506c-verification-safe-harbor permission an issuer conducting a rule 506(c) offering satisfies the \"reasonable steps to verify\" accredited-investor requirement when it (1) imposes a minimum investment amount high enough that only accredited investors would reasonably be expected to meet it, (2) obtains written representations of accredited status and that the investment is not financed by a third party for purposes of the investment, and (3) has no actual knowledge of contradictory facts. the position restates the principles-based standard; it does not create an exclusive verification method. rule 506c accredited investor reasonable steps to verify regulation d private placement"},{"type":"obligation","name":"Telehealth Compliance Anchored To Participant Proposal","id":"telehealth-compliance-per-proposal","href":"primary/telehealth-compliance-per-proposal/index.html","group":"requirement","_search":"telehealth compliance anchored to participant proposal telehealth-compliance-per-proposal requirement a participant operating ai-assisted prescription renewal must adhere to utah's telehealth provider requirements in §26b-4-704, with specific subsections deemed satisfied by following protocols described in the participant's proposal (schedule b): doctronic parts 2b and 3b; legion proposal section 4. certain subsections (e.g., the patient-records portability default) are inapplicable; others are substituted by proposal-section conformance. telehealth 26b-4-704 proposal compliance doctronic legion"},{"type":"authority","name":"Consumer Financial Protection Bureau","id":"cfpb","href":"authority/cfpb/index.html","jurisdiction":"us","_search":"consumer financial protection bureau cfpb us"},{"type":"authority","name":"CFTC Division of Swap Dealer and Intermediary Oversight","id":"cftc-dsio","href":"authority/cftc-dsio/index.html","jurisdiction":"us","_search":"cftc division of swap dealer and intermediary oversight cftc-dsio us"},{"type":"authority","name":"Colorado General Assembly","id":"colorado-legislature","href":"authority/colorado-legislature/index.html","jurisdiction":"us-co","_search":"colorado general assembly colorado-legislature us-co"},{"type":"authority","name":"IRS Office of Chief Counsel","id":"irs-chief-counsel","href":"authority/irs-chief-counsel/index.html","jurisdiction":"us","_search":"irs office of chief counsel irs-chief-counsel us"},{"type":"authority","name":"IRS Tax Exempt and Government Entities Division","id":"irs-tege","href":"authority/irs-tege/index.html","jurisdiction":"us","_search":"irs tax exempt and government entities division irs-tege us"},{"type":"authority","name":"SEC Division of Corporation Finance","id":"sec-corpfin","href":"authority/sec-corpfin/index.html","jurisdiction":"us","_search":"sec division of corporation finance sec-corpfin us"},{"type":"authority","name":"Utah State Legislature","id":"utah-legislature","href":"authority/utah-legislature/index.html","jurisdiction":"us-ut","_search":"utah state legislature utah-legislature us-ut"},{"type":"authority","name":"Utah Office of Artificial Intelligence Policy","id":"utah-oaip","href":"authority/utah-oaip/index.html","jurisdiction":"us-ut","_search":"utah office of artificial intelligence policy utah-oaip us-ut"}] \ No newline at end of file diff --git a/docs/data/examples/obligations/disclose-genai-high-risk-proactive.md b/docs/data/examples/obligations/disclose-genai-high-risk-proactive.md index 2613cd8b..04e1a40e 100644 --- a/docs/data/examples/obligations/disclose-genai-high-risk-proactive.md +++ b/docs/data/examples/obligations/disclose-genai-high-risk-proactive.md @@ -16,22 +16,43 @@ search_terms: ## Summary -A supplier engaged in a "high-risk AI interaction" in a regulated occupation must proactively disclose GenAI use before the interaction begins — verbally at the start of an oral exchange, and in writing before a written exchange. The high-risk tier is statutorily defined and narrower than general consumer interactions. +An individual providing services in a regulated occupation must prominently disclose when an individual receiving services is interacting with generative artificial intelligence in the provision of regulated services if that use constitutes a high-risk artificial intelligence interaction (§13-75-103(2)(a)). The statutory actor is the individual providing those services, without a supplier condition. A regulated occupation is regulated by the Department of Commerce and requires an individual to obtain a license or state certification to practice (§13-75-101(8)). + +The required disclosure is provided verbally at the start of a verbal interaction, and in writing before the start of a written interaction (§13-75-103(3)). Written interactions are not limited to electronic messaging. The individual must also comply with all requirements of the regulated occupation when providing services through GenAI (§13-75-103(2)(b)); that requirement is not confined to high-risk interactions. + +A high-risk artificial intelligence interaction is an interaction with GenAI involving any of the following (§13-75-101(5)): +- Collection of sensitive personal information, including health, financial or biometric data +- Provision of personalized recommendations, advice or information that could reasonably be relied upon to make significant personal decisions, including financial, legal, medical or mental health advice or services +- Other applications as defined by division rule + +The listed data and advice or service categories are inclusive examples, not exhaustive lists. The separate §13-75-104(1) safe harbor also covers the provision of regulated services: it concerns enforcement actions for violating §13-75-103 only and requires the person's GenAI to clearly and conspicuously disclose at the outset and throughout the interaction that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms; other state and federal remedies remain available (§13-75-106). + +These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. Current division rules defining other high-risk applications or disclosure forms and methods have not been retained or reviewed here. ## What Counts -- Verbal AI disclosure at the start of an oral exchange -- Written AI disclosure before the first written message in an electronic interaction -- Disclosure in any interaction involving collection of sensitive data (health, financial, biometric) -- Disclosure in any interaction providing personalized advice in finance, legal, medicine, or mental health +- Prominent GenAI disclosure to the individual receiving regulated services in a qualifying high-risk interaction +- Verbal disclosure at the start of a verbal interaction, not a universal before-start requirement +- Written disclosure before the start of a written interaction, including but not limited to electronic messaging +- Disclosure for collection of sensitive personal information within the regulated-services context, including health, financial or biometric data +- Disclosure for personalized recommendations, advice or information reasonably relied upon for significant personal decisions within that context, including financial, legal, medical or mental health advice or services +- Disclosure for another application defined as high-risk by division rule, subject to separately retained rule evidence +- Compliance with all requirements of the regulated occupation when providing services through GenAI, even where the interaction is not high-risk ## What Does Not Count -- Disclosure delayed until the consumer asks -- General branding or marketing that mentions AI without a pre-interaction disclosure -- Disclosure for interactions outside the §13-75-101(5) "high-risk" definition +- Disclosure delayed until the individual receiving services asks, absent the separate statutory safe harbor +- A disclosure that lacks prominence, is delayed beyond the start of a verbal interaction, or appears only after a written interaction has started +- General branding or marketing that mentions AI without the required disclosure to the recipient in the qualifying interaction +- Adding a supplier condition to the individual regulated-services actor +- Treating all personalized information as high-risk without the significant-personal-decisions criterion or another statutory branch +- Treating the statutory examples as exhaustive or omitting the division-rule branch +- Treating disclosure or the safe harbor as a waiver of other occupational requirements or of remedies outside §13-75-103 ## Statute Anchors -- Utah Code §13-75-103(2)–(3) — Proactive disclosure in high-risk AI interactions -- Utah Code §13-75-101(5) — Definition of "high-risk artificial intelligence interaction" +- Retained 2025 enrolled SB 226, §13-75-103(2)-(3), printed lines 106-115: statutory actor, prominence, occupational requirements and channel-specific timing +- Retained 2025 enrolled SB 226, §13-75-101(5), printed lines 54-67: complete high-risk interaction definition +- Retained 2025 enrolled SB 226, §13-75-101(8), printed lines 75-78: regulated occupation definition +- Retained 2025 enrolled SB 226, §13-75-104(1)-(2), printed lines 118-131: separate section103-only safe harbor and disclosure-rule authority +- Retained 2025 enrolled SB 226, §13-75-106, printed lines 164-168: other state and federal remedies preserved diff --git a/docs/data/examples/obligations/disclose-genai-on-request.md b/docs/data/examples/obligations/disclose-genai-on-request.md index f2b85947..455a7e03 100644 --- a/docs/data/examples/obligations/disclose-genai-on-request.md +++ b/docs/data/examples/obligations/disclose-genai-on-request.md @@ -16,22 +16,29 @@ search_terms: ## Summary -A supplier using generative AI in a consumer transaction must disclose that fact when the consumer makes a clear and unambiguous request. A safe harbor is available: a clear and conspicuous disclosure at the outset and throughout the interaction eliminates enforcement exposure, regardless of whether a request is made. +A supplier that uses generative artificial intelligence to interact with an individual in connection with a consumer transaction must disclose that the individual is interacting with generative artificial intelligence and not a human if the individual asks or otherwise prompts the supplier about whether artificial intelligence is being used. The prompt or question must be a clear and unambiguous request to determine whether the interaction is with a human or with artificial intelligence (§13-75-103(1)). + +The separate §13-75-104(1) safe harbor concerns enforcement actions for violating §13-75-103 only. It applies if the person's generative artificial intelligence clearly and conspicuously discloses, at the outset and throughout any interaction with an individual in connection with a consumer transaction or the provision of regulated services, that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms, not substitutes for the conjunctive on-request content in §13-75-103(1). The safe harbor has no request prerequisite and does not eliminate other state or federal remedies (§13-75-106). + +These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. The incorporated supplier and consumer-transaction definitions (§13-11-3) and current disclosure rules under §13-75-104(2) are outside this retained-source review. ## What Counts -- Supplier responds truthfully when a consumer directly asks whether they are interacting with a human or with AI -- Clear-and-conspicuous GenAI notice shown at the outset of the interaction and sustained throughout (qualifies for §13-75-104 safe harbor) -- Plain-language identification naming "AI" or "generative AI" +- For the on-request duty, the supplier discloses both generative artificial intelligence and not a human in response to the qualifying question or prompt in a consumer transaction +- For the separate safe harbor, the person's GenAI clearly and conspicuously discloses any one of the three statutory alternatives at the outset and throughout the qualifying interaction: generative artificial intelligence, not human, or an artificial intelligence assistant +- The safe-harbor not-human alternative does not require the literal word "AI"; the statutory clarity, conspicuousness, context and timing conditions still apply ## What Does Not Count -- Requiring the consumer to infer AI use from context -- Disclosure buried only in a privacy policy or terms-of-service link -- Ambiguous labels such as "smart assistant" or "automated helper" without the word "AI" -- Responding only when the consumer uses a specific magic phrase +- Requiring the individual to infer GenAI use from context instead of responding to the qualifying request +- Treating a not-human-only response as the complete §13-75-103(1) disclosure, rather than distinguishing the separate safe-harbor alternative +- Treating a buried notice or an ambiguous label such as "smart assistant" or "automated helper" as sufficient without establishing the safe harbor's clear-and-conspicuous disclosure conditions +- Providing a safe-harbor notice only at the outset without disclosure throughout the interaction +- Requiring a specific magic phrase when the individual has already made a clear and unambiguous qualifying request +- Treating the safe harbor as immunity from violations or remedies outside §13-75-103 ## Statute Anchors -- Utah Code §13-75-103(1) — On-request GenAI disclosure -- Utah Code §13-75-104 — Clear-and-conspicuous safe harbor +- Retained 2025 enrolled SB 226, §13-75-103(1), printed lines 98-105: supplier, transaction, request and conjunctive disclosure content +- Retained 2025 enrolled SB 226, §13-75-104(1)-(2), printed lines 118-131: separate section103-only safe harbor and disclosure-rule authority +- Retained 2025 enrolled SB 226, §13-75-106, printed lines 164-168: other state and federal remedies preserved diff --git a/docs/obligation/sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive.json b/docs/obligation/sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive.json index faeee4bf..907fb42e 100644 --- a/docs/obligation/sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive.json +++ b/docs/obligation/sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive.json @@ -9,7 +9,7 @@ "@id": "https://publedge.org/obligation/sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive.json", "pub:id": "sb226-disclosure-and-ai-defense-disclose-genai-high-risk-proactive", "title": "Proactive GenAI Disclosure In High-Risk Interactions", - "content": "A supplier engaged in a \"high-risk AI interaction\" in a regulated occupation must proactively disclose GenAI use before the interaction begins — verbally at the start of an oral exchange, and in writing before a written exchange. The high-risk tier is statutorily defined and narrower than general consumer interactions.", + "content": "An individual providing services in a regulated occupation must prominently disclose when an individual receiving services is interacting with generative artificial intelligence in the provision of regulated services if that use constitutes a high-risk artificial intelligence interaction (§13-75-103(2)(a)). The statutory actor is the individual providing those services, without a supplier condition. A regulated occupation is regulated by the Department of Commerce and requires an individual to obtain a license or state certification to practice (§13-75-101(8)). The required disclosure is provided verbally at the start of a verbal interaction, and in writing before the start of a written interaction (§13-75-103(3)). Written interactions are not limited to electronic messaging. The individual must also comply with all requirements of the regulated occupation when providing services through GenAI (§13-75-103(2)(b)); that requirement is not confined to high-risk interactions. A high-risk artificial intelligence interaction is an interaction with GenAI involving any of the following (§13-75-101(5)): - Collection of sensitive personal information, including health, financial or biometric data - Provision of personalized recommendations, advice or information that could reasonably be relied upon to make significant personal decisions, including financial, legal, medical or mental health advice or services - Other applications as defined by division rule The listed data and advice or service categories are inclusive examples, not exhaustive lists. The separate §13-75-104(1) safe harbor also covers the provision of regulated services: it concerns enforcement actions for violating §13-75-103 only and requires the person's GenAI to clearly and conspicuously disclose at the outset and throughout the interaction that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms; other state and federal remedies remain available (§13-75-106). These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. Current division rules defining other high-risk applications or disclosure forms and methods have not been retained or reviewed here.", "created_by": [ "https://publedge.org/term/sb226-disclosure-and-ai-defense.json" ], @@ -47,7 +47,12 @@ "Whether SB 226 passed each house by two-thirds (so its 63I-2-213 amendment took effect on governor approval rather than May 7, 2025) is not confirmed.", "The 404 status of the 13-75-S102/S103/S104 URLs and HTTP 200 for 13-75.html come from ops/evidence/utah-overdue-dispositions-2026-09-23.json url_checks, not a retained snapshot; a human should confirm the current le.utah.gov section URL pattern.", "Whether an OAIP annual report was filed for 2024 or 2025 is unverified.", - "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it." + "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it.", + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." ], "pub:source_review_state": "known-and-unknown", "pub:evidence_inputs": [ @@ -87,14 +92,22 @@ { "kind": "obligation-definition", "native_path": "data/examples/obligations/disclose-genai-high-risk-proactive.md", - "native_file_sha256": "894ec6c5333740656a3f50a3dec3cdb95ceeb60642a95c225a2fe9d8e51823f5", + "native_file_sha256": "f1ee01115a55072a4a046b49af6a81c109b4f0ffba49e6e6df58d775b25ca302", "canonical_unit": null, - "canonical_sha256": "16769df863c540985bf05faefbfab94efb1882a1398d65eca9a16ec41f313ba2", - "admission_status": "legacy-unreviewed", - "review_packet_sha256": null, - "retained_primary_sha256": null, - "unresolved_review_state": "unknown", - "unresolved": null + "canonical_sha256": "189f4253b204692369145bf206f26cb66d414488405e0d4509edee0e4c57a9d3", + "admission_status": "reviewed-changes", + "review_packet_sha256": "53dc6fff3ee933e85a8596578c3985f836252418b30dc6025349ed3ebdb586bb", + "retained_primary_sha256": [ + "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + ], + "unresolved_review_state": "declared", + "unresolved": [ + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." + ] } ] } diff --git a/docs/obligation/sb226-disclosure-and-ai-defense-disclose-genai-on-request.json b/docs/obligation/sb226-disclosure-and-ai-defense-disclose-genai-on-request.json index 08e1e6f1..a10216bd 100644 --- a/docs/obligation/sb226-disclosure-and-ai-defense-disclose-genai-on-request.json +++ b/docs/obligation/sb226-disclosure-and-ai-defense-disclose-genai-on-request.json @@ -9,7 +9,7 @@ "@id": "https://publedge.org/obligation/sb226-disclosure-and-ai-defense-disclose-genai-on-request.json", "pub:id": "sb226-disclosure-and-ai-defense-disclose-genai-on-request", "title": "Disclose GenAI On Consumer Request", - "content": "A supplier using generative AI in a consumer transaction must disclose that fact when the consumer makes a clear and unambiguous request. A safe harbor is available: a clear and conspicuous disclosure at the outset and throughout the interaction eliminates enforcement exposure, regardless of whether a request is made.", + "content": "A supplier that uses generative artificial intelligence to interact with an individual in connection with a consumer transaction must disclose that the individual is interacting with generative artificial intelligence and not a human if the individual asks or otherwise prompts the supplier about whether artificial intelligence is being used. The prompt or question must be a clear and unambiguous request to determine whether the interaction is with a human or with artificial intelligence (§13-75-103(1)). The separate §13-75-104(1) safe harbor concerns enforcement actions for violating §13-75-103 only. It applies if the person's generative artificial intelligence clearly and conspicuously discloses, at the outset and throughout any interaction with an individual in connection with a consumer transaction or the provision of regulated services, that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms, not substitutes for the conjunctive on-request content in §13-75-103(1). The safe harbor has no request prerequisite and does not eliminate other state or federal remedies (§13-75-106). These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. The incorporated supplier and consumer-transaction definitions (§13-11-3) and current disclosure rules under §13-75-104(2) are outside this retained-source review.", "created_by": [ "https://publedge.org/term/sb226-disclosure-and-ai-defense.json" ], @@ -47,7 +47,12 @@ "Whether SB 226 passed each house by two-thirds (so its 63I-2-213 amendment took effect on governor approval rather than May 7, 2025) is not confirmed.", "The 404 status of the 13-75-S102/S103/S104 URLs and HTTP 200 for 13-75.html come from ops/evidence/utah-overdue-dispositions-2026-09-23.json url_checks, not a retained snapshot; a human should confirm the current le.utah.gov section URL pattern.", "Whether an OAIP annual report was filed for 2024 or 2025 is unverified.", - "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it." + "amends (us-ut-legislature-statute-2024-sb149) is unchanged; SB 226 repeals 13-2-12, which SB 149 enacted, so the source does not contradict it.", + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." ], "pub:source_review_state": "known-and-unknown", "pub:evidence_inputs": [ @@ -87,14 +92,22 @@ { "kind": "obligation-definition", "native_path": "data/examples/obligations/disclose-genai-on-request.md", - "native_file_sha256": "975530c0feb4bacd2989f3e1494c8f9cbe61dd4bbb1569c866490c6de88d514a", + "native_file_sha256": "24d7c8e63e37d24678f5225b2d0c97b16f2bbea97e2fda7df8c9deeda1ef8c92", "canonical_unit": null, - "canonical_sha256": "2255b8372e20bccbf1f6b054201add8cda3e519dd4aded5ac492e91cc7c56d0c", - "admission_status": "legacy-unreviewed", - "review_packet_sha256": null, - "retained_primary_sha256": null, - "unresolved_review_state": "unknown", - "unresolved": null + "canonical_sha256": "df3231b4a2111975e8de105d84a2fa0d4f5d1b8b32ffb3f0aab9ee12622931a5", + "admission_status": "reviewed-changes", + "review_packet_sha256": "ae850f903e66d27eac95d560533460f50cea40532afb8f15ab6d5c6c41e9b98a", + "retained_primary_sha256": [ + "279184eb1ee69adb7c9ada3e29763f9766b0705c87770b6330c13bada07c60e8" + ], + "unresolved_review_state": "declared", + "unresolved": [ + "These Chapter75 locators are 2025 enrolled-version only. Coordinator retained publisher observations identify a Chapter75 subject/locator mismatch. Chapter77 is an unverified candidate only, with no retained index evidence and no validated bridge; the current-codification bridge and current SB226 status are not validated in this repair.", + "Current division rules defining other high-risk applications or acceptable disclosure forms and methods have not been retained or reviewed.", + "The incorporated 13-11-3 supplier and consumer-transaction definitions are not retained here; no new controlled-role equivalence is inferred.", + "The existing human-reviewed instrument summary and legacy SB226 mapping admission remain unchanged; this receipt reviews only the displayed definition deltas.", + "Parent reports that independent native review supports these two definition deltas with no substantive finding. Whole-R1 instrument Summary and receipt succession remain gated; generated output and final canonical owner acceptance are separate." + ] } ] } diff --git a/docs/obligations.html b/docs/obligations.html index 0cc8bb60..ced58b10 100644 --- a/docs/obligations.html +++ b/docs/obligations.html @@ -143,7 +143,7 @@
A supplier engaged in a "high-risk AI interaction" in a regulated occupation must proactively disclose GenAI use before the interaction begins — verbally at the start of an oral exchange, and in writing before a written exchange. The high-risk tier is statutorily defined and narrower than general consumer interactions.
-An individual providing services in a regulated occupation must prominently disclose when an individual receiving services is interacting with generative artificial intelligence in the provision of regulated services if that use constitutes a high-risk artificial intelligence interaction (§13-75-103(2)(a)). The statutory actor is the individual providing those services, without a supplier condition. A regulated occupation is regulated by the Department of Commerce and requires an individual to obtain a license or state certification to practice (§13-75-101(8)). + +The required disclosure is provided verbally at the start of a verbal interaction, and in writing before the start of a written interaction (§13-75-103(3)). Written interactions are not limited to electronic messaging. The individual must also comply with all requirements of the regulated occupation when providing services through GenAI (§13-75-103(2)(b)); that requirement is not confined to high-risk interactions. + +A high-risk artificial intelligence interaction is an interaction with GenAI involving any of the following (§13-75-101(5)): +- Collection of sensitive personal information, including health, financial or biometric data +- Provision of personalized recommendations, advice or information that could reasonably be relied upon to make significant personal decisions, including financial, legal, medical or mental health advice or services +- Other applications as defined by division rule + +The listed data and advice or service categories are inclusive examples, not exhaustive lists. The separate §13-75-104(1) safe harbor also covers the provision of regulated services: it concerns enforcement actions for violating §13-75-103 only and requires the person's GenAI to clearly and conspicuously disclose at the outset and throughout the interaction that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms; other state and federal remedies remain available (§13-75-106). + +These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. Current division rules defining other high-risk applications or disclosure forms and methods have not been retained or reviewed here.
+| Legal Instrument | Scope | Status | Provisions |
|---|---|---|---|
| Utah SB 226 (2025) — Artificial Intelligence Consumer Protection Amendments | us-ut | enforcing | 1 |
| Legal Instrument | Scope | Status | Provisions |
|---|---|---|---|
| Utah SB 226 (2025) — Artificial Intelligence Consumer Protection Amendments | us-ut | enforcing | 1 |