Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 25 additions & 5 deletions MANIFEST.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -128,7 +128,7 @@ files:

- path: package.json
role: config
hash: sha256:45d3460c2f22d32ff645353a145c93783cd6a6152398ca85f45a862d3d1bcede
hash: sha256:b22e0dcdcd2e45a3f232b450795cb65c32c4a58723423f456071bfb288c009b7
note: package.json

- path: package-lock.json
Expand Down Expand Up @@ -333,7 +333,7 @@ files:

- path: data/examples/obligations/disclose-genai-high-risk-proactive.md
role: obligation
hash: sha256:894ec6c5333740656a3f50a3dec3cdb95ceeb60642a95c225a2fe9d8e51823f5
hash: sha256:f1ee01115a55072a4a046b49af6a81c109b4f0ffba49e6e6df58d775b25ca302
note: data/examples/obligations/disclose-genai-high-risk-proactive.md

- path: data/examples/obligations/disclose-genai-on-first-session.md
Expand All @@ -343,7 +343,7 @@ files:

- path: data/examples/obligations/disclose-genai-on-request.md
role: obligation
hash: sha256:975530c0feb4bacd2989f3e1494c8f9cbe61dd4bbb1569c866490c6de88d514a
hash: sha256:24d7c8e63e37d24678f5225b2d0c97b16f2bbea97e2fda7df8c9deeda1ef8c92
note: data/examples/obligations/disclose-genai-on-request.md

- path: data/examples/obligations/elizachat-phased-rollout.md
Expand Down Expand Up @@ -1038,7 +1038,7 @@ files:

- path: tests/source-admission.test.js
role: code
hash: sha256:10be9419f4d32940c9988fed0e13edd48fdb0d81b456989b80794d89b6b0c163
hash: sha256:e4fcbb61cf703c1dbcaf9b10c01feb50f548dfc3ac797b5ec3c717aeec3af5aa
note: Source admission policy and producer-gate regressions

- path: tests/publication-state.test.js
Expand All @@ -1058,7 +1058,7 @@ files:

- path: tests/of-evidence-inputs.test.js
role: code
hash: sha256:1e604a0fb0f847f796d655245a431333e412da9f94e1f01e96c38818323b084c
hash: sha256:1321a92efb7d004456d7190ff24b5600c444d7df7b49d2b4b08d28ef70bf84f4
note: Per-kind native evidence input and review-boundary regressions

- path: tests/colorado-order24.test.js
Expand Down Expand Up @@ -1165,3 +1165,23 @@ files:
role: evidence
hash: sha256:d1a7ac6297492ffc889ad5cb611d3dd6e087161d29e4763a19ea884983fb1fc6
note: Utah statute enrolled-copy source review receipt (SB 149, SB 226, SB 332, HB 320)

- path: tests/sb226-r1.test.js
role: code
hash: sha256:ba4f4636bad329be363c84d09c840cfe62a3fd89ec107025bddff21056a41c38
note: SB226 R1 retained-source and admission regressions

- path: ops/evidence/sb226-r1-native-delta-2026-10-02.diff
role: evidence
hash: sha256:526f22e19f1f05130c16f8cc057849c245a481e88bb5ce5019e1e850b6000e59
note: Independently reviewed SB226 R1 native definition delta

- path: ops/evidence/sb226-r1-fingerprint-comparison-2026-10-02.json
role: evidence
hash: sha256:5160025a28388f121161cac0c7d8c8b208a99872d5710d6bb85f37ef618c1d23
note: Parent-accepted exact two-record provenance-only fingerprint comparison

- path: ops/evidence/sb226-r1-local-repair-2026-10-02.md
role: evidence
hash: sha256:6d6bbc43b88d1ca9510466460e092bd6fd9484d3344919e810fc5d8259f09322
note: Scoped SB226 R1 owner repair receipt; instrument Summary remains gated
350 changes: 350 additions & 0 deletions data/admission/receipts.json

Large diffs are not rendered by default.

41 changes: 31 additions & 10 deletions data/examples/obligations/disclose-genai-high-risk-proactive.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,22 +16,43 @@ search_terms:

## Summary

A supplier engaged in a "high-risk AI interaction" in a regulated occupation must proactively disclose GenAI use before the interaction begins — verbally at the start of an oral exchange, and in writing before a written exchange. The high-risk tier is statutorily defined and narrower than general consumer interactions.
An individual providing services in a regulated occupation must prominently disclose when an individual receiving services is interacting with generative artificial intelligence in the provision of regulated services if that use constitutes a high-risk artificial intelligence interaction (§13-75-103(2)(a)). The statutory actor is the individual providing those services, without a supplier condition. A regulated occupation is regulated by the Department of Commerce and requires an individual to obtain a license or state certification to practice (§13-75-101(8)).

The required disclosure is provided verbally at the start of a verbal interaction, and in writing before the start of a written interaction (§13-75-103(3)). Written interactions are not limited to electronic messaging. The individual must also comply with all requirements of the regulated occupation when providing services through GenAI (§13-75-103(2)(b)); that requirement is not confined to high-risk interactions.

A high-risk artificial intelligence interaction is an interaction with GenAI involving any of the following (§13-75-101(5)):
- Collection of sensitive personal information, including health, financial or biometric data
- Provision of personalized recommendations, advice or information that could reasonably be relied upon to make significant personal decisions, including financial, legal, medical or mental health advice or services
- Other applications as defined by division rule

The listed data and advice or service categories are inclusive examples, not exhaustive lists. The separate §13-75-104(1) safe harbor also covers the provision of regulated services: it concerns enforcement actions for violating §13-75-103 only and requires the person's GenAI to clearly and conspicuously disclose at the outset and throughout the interaction that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms; other state and federal remedies remain available (§13-75-106).

These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. Current division rules defining other high-risk applications or disclosure forms and methods have not been retained or reviewed here.

## What Counts

- Verbal AI disclosure at the start of an oral exchange
- Written AI disclosure before the first written message in an electronic interaction
- Disclosure in any interaction involving collection of sensitive data (health, financial, biometric)
- Disclosure in any interaction providing personalized advice in finance, legal, medicine, or mental health
- Prominent GenAI disclosure to the individual receiving regulated services in a qualifying high-risk interaction
- Verbal disclosure at the start of a verbal interaction, not a universal before-start requirement
- Written disclosure before the start of a written interaction, including but not limited to electronic messaging
- Disclosure for collection of sensitive personal information within the regulated-services context, including health, financial or biometric data
- Disclosure for personalized recommendations, advice or information reasonably relied upon for significant personal decisions within that context, including financial, legal, medical or mental health advice or services
- Disclosure for another application defined as high-risk by division rule, subject to separately retained rule evidence
- Compliance with all requirements of the regulated occupation when providing services through GenAI, even where the interaction is not high-risk

## What Does Not Count

- Disclosure delayed until the consumer asks
- General branding or marketing that mentions AI without a pre-interaction disclosure
- Disclosure for interactions outside the §13-75-101(5) "high-risk" definition
- Disclosure delayed until the individual receiving services asks, absent the separate statutory safe harbor
- A disclosure that lacks prominence, is delayed beyond the start of a verbal interaction, or appears only after a written interaction has started
- General branding or marketing that mentions AI without the required disclosure to the recipient in the qualifying interaction
- Adding a supplier condition to the individual regulated-services actor
- Treating all personalized information as high-risk without the significant-personal-decisions criterion or another statutory branch
- Treating the statutory examples as exhaustive or omitting the division-rule branch
- Treating disclosure or the safe harbor as a waiver of other occupational requirements or of remedies outside §13-75-103

## Statute Anchors

- Utah Code §13-75-103(2)–(3) — Proactive disclosure in high-risk AI interactions
- Utah Code §13-75-101(5) — Definition of "high-risk artificial intelligence interaction"
- Retained 2025 enrolled SB 226, §13-75-103(2)-(3), printed lines 106-115: statutory actor, prominence, occupational requirements and channel-specific timing
- Retained 2025 enrolled SB 226, §13-75-101(5), printed lines 54-67: complete high-risk interaction definition
- Retained 2025 enrolled SB 226, §13-75-101(8), printed lines 75-78: regulated occupation definition
- Retained 2025 enrolled SB 226, §13-75-104(1)-(2), printed lines 118-131: separate section103-only safe harbor and disclosure-rule authority
- Retained 2025 enrolled SB 226, §13-75-106, printed lines 164-168: other state and federal remedies preserved
27 changes: 17 additions & 10 deletions data/examples/obligations/disclose-genai-on-request.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,22 +16,29 @@ search_terms:

## Summary

A supplier using generative AI in a consumer transaction must disclose that fact when the consumer makes a clear and unambiguous request. A safe harbor is available: a clear and conspicuous disclosure at the outset and throughout the interaction eliminates enforcement exposure, regardless of whether a request is made.
A supplier that uses generative artificial intelligence to interact with an individual in connection with a consumer transaction must disclose that the individual is interacting with generative artificial intelligence and not a human if the individual asks or otherwise prompts the supplier about whether artificial intelligence is being used. The prompt or question must be a clear and unambiguous request to determine whether the interaction is with a human or with artificial intelligence (§13-75-103(1)).

The separate §13-75-104(1) safe harbor concerns enforcement actions for violating §13-75-103 only. It applies if the person's generative artificial intelligence clearly and conspicuously discloses, at the outset and throughout any interaction with an individual in connection with a consumer transaction or the provision of regulated services, that it is generative artificial intelligence, is not human, or is an artificial intelligence assistant. These are alternative safe-harbor forms, not substitutes for the conjunctive on-request content in §13-75-103(1). The safe harbor has no request prerequisite and does not eliminate other state or federal remedies (§13-75-106).

These locators and requirements describe the retained 2025 enrolled SB 226 only, not independently validated current codification. The incorporated supplier and consumer-transaction definitions (§13-11-3) and current disclosure rules under §13-75-104(2) are outside this retained-source review.

## What Counts

- Supplier responds truthfully when a consumer directly asks whether they are interacting with a human or with AI
- Clear-and-conspicuous GenAI notice shown at the outset of the interaction and sustained throughout (qualifies for §13-75-104 safe harbor)
- Plain-language identification naming "AI" or "generative AI"
- For the on-request duty, the supplier discloses both generative artificial intelligence and not a human in response to the qualifying question or prompt in a consumer transaction
- For the separate safe harbor, the person's GenAI clearly and conspicuously discloses any one of the three statutory alternatives at the outset and throughout the qualifying interaction: generative artificial intelligence, not human, or an artificial intelligence assistant
- The safe-harbor not-human alternative does not require the literal word "AI"; the statutory clarity, conspicuousness, context and timing conditions still apply

## What Does Not Count

- Requiring the consumer to infer AI use from context
- Disclosure buried only in a privacy policy or terms-of-service link
- Ambiguous labels such as "smart assistant" or "automated helper" without the word "AI"
- Responding only when the consumer uses a specific magic phrase
- Requiring the individual to infer GenAI use from context instead of responding to the qualifying request
- Treating a not-human-only response as the complete §13-75-103(1) disclosure, rather than distinguishing the separate safe-harbor alternative
- Treating a buried notice or an ambiguous label such as "smart assistant" or "automated helper" as sufficient without establishing the safe harbor's clear-and-conspicuous disclosure conditions
- Providing a safe-harbor notice only at the outset without disclosure throughout the interaction
- Requiring a specific magic phrase when the individual has already made a clear and unambiguous qualifying request
- Treating the safe harbor as immunity from violations or remedies outside §13-75-103

## Statute Anchors

- Utah Code §13-75-103(1) — On-request GenAI disclosure
- Utah Code §13-75-104 — Clear-and-conspicuous safe harbor
- Retained 2025 enrolled SB 226, §13-75-103(1), printed lines 98-105: supplier, transaction, request and conjunctive disclosure content
- Retained 2025 enrolled SB 226, §13-75-104(1)-(2), printed lines 118-131: separate section103-only safe harbor and disclosure-rule authority
- Retained 2025 enrolled SB 226, §13-75-106, printed lines 164-168: other state and federal remedies preserved
30 changes: 25 additions & 5 deletions docs/MANIFEST.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -128,7 +128,7 @@ files:

- path: package.json
role: config
hash: sha256:45d3460c2f22d32ff645353a145c93783cd6a6152398ca85f45a862d3d1bcede
hash: sha256:b22e0dcdcd2e45a3f232b450795cb65c32c4a58723423f456071bfb288c009b7
note: package.json

- path: package-lock.json
Expand Down Expand Up @@ -333,7 +333,7 @@ files:

- path: data/examples/obligations/disclose-genai-high-risk-proactive.md
role: obligation
hash: sha256:894ec6c5333740656a3f50a3dec3cdb95ceeb60642a95c225a2fe9d8e51823f5
hash: sha256:f1ee01115a55072a4a046b49af6a81c109b4f0ffba49e6e6df58d775b25ca302
note: data/examples/obligations/disclose-genai-high-risk-proactive.md

- path: data/examples/obligations/disclose-genai-on-first-session.md
Expand All @@ -343,7 +343,7 @@ files:

- path: data/examples/obligations/disclose-genai-on-request.md
role: obligation
hash: sha256:975530c0feb4bacd2989f3e1494c8f9cbe61dd4bbb1569c866490c6de88d514a
hash: sha256:24d7c8e63e37d24678f5225b2d0c97b16f2bbea97e2fda7df8c9deeda1ef8c92
note: data/examples/obligations/disclose-genai-on-request.md

- path: data/examples/obligations/elizachat-phased-rollout.md
Expand Down Expand Up @@ -1038,7 +1038,7 @@ files:

- path: tests/source-admission.test.js
role: code
hash: sha256:10be9419f4d32940c9988fed0e13edd48fdb0d81b456989b80794d89b6b0c163
hash: sha256:e4fcbb61cf703c1dbcaf9b10c01feb50f548dfc3ac797b5ec3c717aeec3af5aa
note: Source admission policy and producer-gate regressions

- path: tests/publication-state.test.js
Expand All @@ -1058,7 +1058,7 @@ files:

- path: tests/of-evidence-inputs.test.js
role: code
hash: sha256:1e604a0fb0f847f796d655245a431333e412da9f94e1f01e96c38818323b084c
hash: sha256:1321a92efb7d004456d7190ff24b5600c444d7df7b49d2b4b08d28ef70bf84f4
note: Per-kind native evidence input and review-boundary regressions

- path: tests/colorado-order24.test.js
Expand Down Expand Up @@ -1165,3 +1165,23 @@ files:
role: evidence
hash: sha256:d1a7ac6297492ffc889ad5cb611d3dd6e087161d29e4763a19ea884983fb1fc6
note: Utah statute enrolled-copy source review receipt (SB 149, SB 226, SB 332, HB 320)

- path: tests/sb226-r1.test.js
role: code
hash: sha256:ba4f4636bad329be363c84d09c840cfe62a3fd89ec107025bddff21056a41c38
note: SB226 R1 retained-source and admission regressions

- path: ops/evidence/sb226-r1-native-delta-2026-10-02.diff
role: evidence
hash: sha256:526f22e19f1f05130c16f8cc057849c245a481e88bb5ce5019e1e850b6000e59
note: Independently reviewed SB226 R1 native definition delta

- path: ops/evidence/sb226-r1-fingerprint-comparison-2026-10-02.json
role: evidence
hash: sha256:5160025a28388f121161cac0c7d8c8b208a99872d5710d6bb85f37ef618c1d23
note: Parent-accepted exact two-record provenance-only fingerprint comparison

- path: ops/evidence/sb226-r1-local-repair-2026-10-02.md
role: evidence
hash: sha256:6d6bbc43b88d1ca9510466460e092bd6fd9484d3344919e810fc5d8259f09322
note: Scoped SB226 R1 owner repair receipt; instrument Summary remains gated
Loading
Loading