Skip to content
Esta e uma traducao de conveniencia. A versao em ingles e a versao oficial e legalmente vinculativa. Ver versao em ingles
US-UTMEDIUM coverage

Utah HB 276 — Digital Voyeurism Prevention & AI Content Provenance: AI Compliance Requirements

Utah HB 276 ("Artificial Intelligence Modifications") was signed by Governor Cox on March 24, 2026, and — per the enrolled bill's Section 21 — takes effect January 1, 2027 (NOT yet in force). It creates two chapters relevant to AI businesses, both effective that date. (1) Digital Content Provenance Standards Act (Ch. 72c): a "covered provider" — a generative-AI system with over 1,000,000 monthly users that is publicly accessible in Utah — must embed a latent provenance disclosure (time/date + provider/tool identity or digital signatures) in AI-generated or AI-substantially-modified image, video, or audio content; "large online platforms" (those exceeding 2,000,000 unique monthly users) must detect, disclose, and preserve provenance data and may not strip it; capture-device manufacturers must include latent disclosures, but only for devices produced for sale on or after January 1, 2028. The duty is scoped to these covered providers/platforms, NOT to any business. (2) Digital Voyeurism Prevention Act (Ch. 72b): AI "generation services" may not distribute a counterfeit intimate image of an identifiable real person without first obtaining and verifying that person's affirmative consent (with a consent system that retains records ≥7 years), and "covered platforms" must run a notice-and-takedown process (48-hour removal). Violations carry civil liability (actual + punitive damages, attorney fees, injunctive relief), subject to statutory safe harbors for services/platforms that implement reasonable safeguards, written policies, and prompt takedown. Enforced by the Utah Division of Consumer Protection.

Summary of publicly-available regulatory text as of 2026-08-25. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2027

Maximum Penalty

Digital Voyeurism Prevention Act: civil liability — actual + punitive damages, attorney fees, injunctive relief (subject to safe harbor). Digital Content Provenance Standards Act: Division of Consumer Protection administrative fine up to $2,500 per violation, plus up to $5,000 per violation of a resulting order; AG may sue to collect.

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Do Not Generate or Distribute AI "Apparent" CSAM (HB 289, in force since May 6, 2026)

Critical

Utah HB 289 ("Child Sexual Abuse Material Amendments", 2026 General Session, effective May 6, 2026 — unlike the HB 276 duties in this entry, this one is ALREADY IN FORCE) creates a dedicated criminal track for AI-generated material. It defines "apparent child sexual abuse material" to address material created or generated by artificial intelligence that depicts realistic minors, and correspondingly amends the definition of "child sexual abuse material" to REMOVE artificially generated material — so AI output is now prosecuted under its own provisions rather than folded into the pre-existing CSAM definition. It separately defines "obscene child sexual abuse material" and creates three standalone offences, whose GRADES are (R519, read from the enacted sections): (1) § 76-5b-207 "Possession of apparent child sexual abuse material" — intentionally or knowingly possessing, viewing, accessing with intent to view, or maintaining access with intent to view — a SECOND DEGREE FELONY; (2) § 76-5b-208 "Distribution or production of apparent child sexual abuse material" — intentionally distributing OR producing — a FIRST DEGREE FELONY, reduced to a second degree felony only where the actor is under 18 at the time of the offence; and (3) § 76-5b-209 "Unlawful activity regarding obscene material depicting the sexual abuse of a minor" — intentionally or knowingly producing, distributing, receiving, or possessing with intent to distribute obscene CSAM, under circumstances not amounting to an offence under § 76-5b-201 or § 76-5b-201.1 — a SECOND DEGREE FELONY. Note where the worst exposure sits: PRODUCING is graded with distribution, in the first-degree tier, so a generative service that outputs the material is exposed at the top grade rather than the possession grade. Each of §§ 76-5b-207 and -208 is a SEPARATE OFFENCE for each minor depicted and for each time the same minor is depicted in different material, so counts multiply per output. Two provisions decide whether this reaches synthetic media at all, and both do: § 76-5b-207(6) and § 76-5b-208(5) each provide that "proof that the minor depicted in the apparent child sexual abuse material is a real minor that exists is not required" — no identifiable victim need be shown. For a business running a generative image, video, or avatar service reachable in Utah this is a criminal-exposure control, not a disclosure duty: enforce model- and prompt-level safeguards that block generation of sexualised depictions of realistic minors, classify outputs before delivery, retain and action abuse reports, and route detections into a documented trust-and-safety and legal escalation path. THERE IS A CORPORATE SAFE HARBOR, and it is worth building to deliberately: § 76-5b-207(7)(a) and § 76-5b-208(6)(a) provide that an entity — and its employees, directors, officers and agents acting within the scope of employment — is not criminally or civilly liable under those sections, when acting in good faith compliance with Utah Code § 77-4-201, for the good faith performance of (i) reporting or data preservation duties required under federal or state law, or (ii) implementing a policy of attempting to prevent the presence of apparent CSAM on tangible or intangible property, or of detecting and reporting its presence on the property. In other words a documented, actually-operated detection-and-reporting programme is the statutory defence — which converts trust-and-safety tooling from a cost centre into the liability shield. A separate affirmative defence at § 76-5b-207(5) is personal to individuals (actor within two years of the depicted minor's age who deletes on law-enforcement request) and is NOT available to a company. Related duty in the same bill: § 76-5b-206 (failure to report CSAM by a computer technician, a class B misdemeanour) was amended to cover apparent and obscene CSAM, so an employer whose staff install, maintain, troubleshoot, upgrade or repair computers should stand up the § 76-5b-206(7) designated-employee reporting procedure — compliance with it discharges the technician's duty and establishes the statutory immunity; § 76-5b-206(8) exempts ISPs, interactive computer services (47 U.S.C. § 230(f)(2)), electronic communications services, telecom/information/mobile services and cable operators that report under 18 U.S.C. § 2258A. Two collateral effects worth building into process: HB 289 classifies apparent and obscene child sexual abuse material as excluded from the definition of a "record" under GRAMA (§ 63G-2-103), so such material held by or shared with a Utah governmental entity is outside public-records disclosure; and public libraries receiving state funds must operate technology protection measures filtering both new categories (§ 9-7-215).

Deadline: May 6, 2026

Utah Code § 76-5b-207 (Possession of apparent child sexual abuse material — second degree felony, § 76-5b-207(3)), § 76-5b-208 (Distribution or production of apparent child sexual abuse material — first degree felony, § 76-5b-208(3)(a); second degree if the actor is under 18, § 76-5b-208(3)(b)), and § 76-5b-209 (Unlawful activity regarding obscene material depicting the sexual abuse of a minor — second degree felony, § 76-5b-209(3)), all enacted by HB 289, 2026 General Session, §§ 15-17; entity safe harbor at §§ 76-5b-207(7) and 76-5b-208(6) (good faith compliance with § 77-4-201); no-real-minor-required at §§ 76-5b-207(6) and 76-5b-208(5); computer-technician reporting at § 76-5b-206; definitions at § 76-5b-103; effective date at HB 289 § 26; collateral amendments at §§ 9-7-215 and 63G-2-103

Embed Provenance Disclosures in AI-Generated Content (covered providers, eff. Jan 1, 2027)

High Priority

Effective January 1, 2027 (not yet in force): this duty binds a "covered provider" — a generative-AI system with over 1,000,000 monthly users that is publicly accessible in Utah (systems used solely for internal operations are exempt). A covered provider must include a latent provenance disclosure — conveying, to the extent technically feasible and consistent with widely accepted industry standards, the time/date of creation or alteration plus the provider/tool identity or digital signatures — in image, video, or audio content (or combinations) created or substantially modified by its generative-AI system. Separately, "large online platforms" (those exceeding 2,000,000 unique monthly users) must detect, disclose, and preserve compliant provenance data and may not knowingly strip it; capture-device manufacturers must include latent disclosures, but only for devices produced for sale on or after January 1, 2028. If you are below the 1,000,000-monthly-user covered-provider threshold this mandatory duty does not apply — though C2PA-style provenance remains best practice. Document your implementation (e.g., C2PA metadata, watermarks, or equivalent).

Deadline: January 1, 2027

Utah Code § 13-72c-101(5) (covered provider), § 13-72c-101(8) (large online platform)

Obtain Consent Before Generating/Distributing Intimate AI Deepfakes (eff. Jan 1, 2027)

High Priority

Effective January 1, 2027 (not yet in force): an AI "generation service" may not distribute a counterfeit intimate image of an identifiable real person without first obtaining and verifying that person's affirmative consent, via a consent system that secures consent before generation, verifies identity with reasonable accuracy, and retains the consent record for at least 7 years; "covered platforms" must run a notice-and-takedown process (remove a reported counterfeit intimate image within 48 hours). Implement consent-verification and takedown workflows; do not generate or distribute intimate AI content of real individuals without documented consent. A statutory safe harbor protects a service/platform that publishes a written anti-NCII policy, maintains reasonable safeguards, and responds promptly to notices (a service whose safeguards categorically prevent intimate-image generation is also covered). Failure exposes the service and distributing platform to civil liability (actual + punitive damages, attorney fees, injunctive relief).

Deadline: January 1, 2027

Utah Code Ch. 72b (Digital Voyeurism Prevention Act)

Who Does This Apply To?

Applies in two parts, both effective January 1, 2027 per the enrolled bill's Section 21 (HB 276 signed 24 Mar 2026; NOT yet in force). (1) AI content provenance — Digital Content Provenance Standards Act (Utah Code Ch. 72c): the mandatory genAI provenance/user-disclosure duty binds a "covered provider," defined as a generative-AI system with over 1,000,000 monthly users that is publicly accessible in Utah (13-72c-101(5); systems used solely for internal operations are excluded); "large online platforms" (a distinct, higher threshold: public-facing platforms exceeding 2,000,000 unique monthly users in the prior 12 months, 13-72c-101(8)) must detect, disclose, and preserve compliant provenance data and may not knowingly strip it; capture-device manufacturers must include latent disclosures, but only for devices produced for sale on or after January 1, 2028 (13-72c-202(4)). (2) Non-consensual intimate AI imagery — Digital Voyeurism Prevention Act (Utah Code Ch. 72b): an AI "generation service" may not distribute a counterfeit intimate image of an identifiable real person without first obtaining and verifying affirmative consent (consent system with ≥7-year record retention); "covered platforms" must run a notice-and-takedown process (48-hour removal). Violations carry civil liability (actual + punitive damages, attorney fees, injunctive relief), subject to statutory safe harbors for services/platforms that publish a written anti-NCII policy, maintain reasonable safeguards, and respond promptly to notices (heightened pleading standards apply). Enforced by the Utah Division of Consumer Protection (administrative fine up to $2,500/violation under the provenance act). Limits/exemptions: below the covered-provider/large-platform thresholds the mandatory provenance duty does not apply; the bill provides additional product/service exemptions and a severability clause.

Recent Regulatory Guidance

guidance2026-03

Utah HB 276 — Digital Content Provenance Standards Act (2026, effective 2027-01-01)

Utah HB 276, signed by Governor Cox in March 2026 (2026 General Session), creates the Digital Content Provenance Standards Act and the Digital Voyeurism Prevention Act, effective January 1, 2027. Large generative-AI providers (publicly accessible in Utah with more than 1 million monthly users) must include provenance disclosures in AI-generated content; large online platforms must detect, disclose, and preserve provenance data in distributed content; capture-device manufacturers must support latent provenance disclosures in captured content. Enforced by the Utah Division of Consumer Protection. The Utah Office of AI Policy maintains a general AI FAQ at commerce.utah.gov/ai/ai-faq.

Frequently Asked Questions

Does Utah HB 276 — Digital Voyeurism Prevention & AI Content Provenance apply to my business?

Utah HB 276 ("Artificial Intelligence Modifications") was signed by Governor Cox on March 24, 2026, and — per the enrolled bill's Section 21 — takes effect January 1, 2027 (NOT yet in force). It creates two chapters relevant to AI businesses, both… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Utah HB 276 — Digital Voyeurism Prevention & AI Content Provenance is: Digital Voyeurism Prevention Act: civil liability — actual + punitive damages, attorney fees, injunctive relief (subject to safe harbor). Digital Content Provenance Standards Act: Division of Consumer Protection administrative fine up to $2,500 per violation, plus up to $5,000 per violation of a resulting order; AG may sue to collect.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Utah HB 276 — Digital Voyeurism Prevention & AI Content Provenance?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://le.utah.gov/Session/2026/bills/static/HB0276.html

Last updated: 2026-08-25 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan