See how Trussed maps to your regulation in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Enterprise AI Compliance

    Utah AI Policy Act Compliance Guide for Enterprises

    A practical guide for enterprise teams evaluating generative AI disclosures, accountability, agent controls, auditability, and runtime governance under the Utah AI Policy Act.

    What the Utah AI Policy Act covers

    Utah AI Policy Act compliance starts with determining whether an enterprise AI workflow involves generative AI interactions with Utah consumers or regulated-service recipients. The operational focus is not broad model registration or general AI development controls. It is the way generative AI appears in covered interactions, how disclosures are presented, and how the enterprise remains accountable for AI-enabled conduct.

    For enterprise teams, this means compliance work should begin with an inventory of affected use cases. Customer support chatbots, voice bots, externally facing copilots, sales or service assistants, and AI agents that communicate with users should be reviewed for jurisdiction, disclosure triggers, regulated-service context, permissions, and auditability.

    Utah AI Policy Act compliance focus areas

    Generative AI interactions

    Identify chatbots, voice bots, copilots, and agents that communicate with Utah users.

    Disclosure controls

    Apply clear, timely disclosures when the Act requires users to be told they are interacting with generative AI.

    Accountability

    Treat AI-enabled statements and actions as governed enterprise conduct, not as a separate defense.

    Runtime evidence

    Log disclosures, prompts, outputs, tool calls, escalations, and human overrides for compliance review.

    Disclosure and accountability obligations to evaluate

    Enterprises should evaluate where required disclosures must appear in covered contexts and whether those disclosures remain reliable across channels, devices, model updates, and agent workflows. A disclosure should be clear enough for the user to understand that they are interacting with generative AI when the Act requires that notice.

    Accountability also requires operational ownership. AI-enabled statements, recommendations, communications, or workflow actions should be governed as enterprise conduct. Compliance teams should understand which business owner approved the use case, which policies apply, how the system is monitored, and how escalations or remediations occur.

    Implementation principle: Treat disclosure, escalation, permissioning, and audit logging as runtime controls. Static documentation is useful, but it is not enough if production AI interactions can bypass the approved behavior.

    Runtime governance controls for AI agents and copilots

    Enterprises should treat disclosures as runtime controls, not static policy statements. A disclosure that appears in a design document but is missing in a voice flow, hidden on a small screen, bypassed by an agent, or removed during a model update will not provide reliable compliance evidence. Disclosure injection should be handled at the application or orchestration layer so the required language appears before or during the covered interaction even if the underlying model, prompt, or vendor feature changes.

    Runtime governance is especially relevant where AI agents can decide what to say, which tools to call, when to escalate, or which business record to modify. Compliance leaders should ask whether agent permissions are limited by approved purpose, jurisdiction, risk tier, user role, and transaction authority. A customer support agent, for example, may need access to knowledge retrieval and ticket creation but not account changes, refund execution, or outbound communications unless those actions are specifically approved and monitored.

    Auditability should cover the full interaction path. Useful records include disclosure presentation events, user prompts, system prompt versions, model versions, retrieved content sources, generated outputs, tool calls, escalation decisions, human overrides, and remediation actions. These records help compliance, security, and legal teams reconstruct what happened and determine whether the AI system stayed within approved boundaries.

    Governance need Runtime control Evidence to retain
    Disclosure reliability Inject required disclosure language at the application or orchestration layer. Disclosure presentation events, channel context, and interaction timing.
    Agent permissions Limit agent actions by approved purpose, jurisdiction, risk tier, user role, and transaction authority. Permission settings, tool calls, approval workflows, and blocked actions.
    Output oversight Monitor prompts, system prompt versions, model versions, retrieved sources, and generated outputs. User prompts, system prompts, model versions, retrieved content sources, and outputs.
    Escalation and remediation Define when agents escalate, when humans override, and how issues are remediated. Escalation decisions, human overrides, monitoring alerts, and remediation actions.

    A practical implementation approach

    Enterprise compliance programs can translate the Utah AI Policy Act into a set of operating controls. The work is not limited to legal review. Product, security, compliance, support, and engineering teams all need a shared view of where generative AI is used and how governed behavior is enforced in production.

    1. Inventory affected AI use cases

      Identify customer-facing and regulated workflows where generative AI communicates with Utah consumers or regulated-service recipients. Include chatbots, voice bots, copilots, AI agents, and internal tools whose outputs influence external communications or regulated services.

    2. Validate disclosure triggers

      Determine when a covered interaction requires users to be told they are interacting with generative AI. Review the disclosure location, timing, channel behavior, and accessibility across devices and user flows.

    3. Govern permissions and tool use

      Limit AI agent authority to approved purposes. Review whether agents can call tools, modify records, execute refunds, send outbound communications, or make other business changes that require approval and monitoring.

    4. Maintain auditable runtime evidence

      Retain records of disclosures, prompts, model versions, outputs, tool calls, escalation decisions, human overrides, monitoring alerts, and remediation actions so teams can reconstruct AI-enabled interactions.

    Governance checklist for enterprise AI compliance teams

    • Map where generative AI interacts with Utah consumers or regulated-service recipients.
    • Document covered use cases, business owners, approved purposes, and affected user journeys.
    • Confirm required disclosure language and when it must appear in the interaction.
    • Implement disclosure delivery at the application or orchestration layer.
    • Review agent permissions, tool access, transaction authority, and escalation paths.
    • Monitor prompts, model versions, retrieved sources, generated outputs, and tool calls.
    • Retain audit records for disclosure presentation, human overrides, alerts, and remediation.

    Utah AI Policy Act compliance questions

    Does the Utah AI Policy Act apply to all enterprise AI systems?

    Not necessarily. The Act’s key operational provisions focus on generative AI interactions in covered consumer-protection and regulated-occupation contexts. Enterprises should still inventory broader AI workflows because internal tools may influence external communications or regulated services.

    Are disclosures required for internal copilots?

    The evidence packet does not establish a general disclosure requirement for purely internal copilots. However, internal copilots should be reviewed when their outputs are used in customer communications, regulated services, sales, support, billing, claims, or other externally consequential workflows.

    What records should be retained for auditability?

    Useful records include approved use cases, disclosure text, disclosure presentation events, prompts, model versions, outputs, tool calls, escalation decisions, human overrides, monitoring alerts, and remediation actions.

    How can Trussed AI relate to this compliance work?

    Trussed AI provides runtime governance and security for enterprise AI agents, including policy enforcement, runtime monitoring, agent permissions, least privilege, tool approval workflows, and audit logging. These controls can support operational oversight, but legal obligations should be confirmed by counsel.

    Operationalize AI governance at runtime

    Utah AI Policy Act compliance depends on more than policy language. Enterprises need visibility into AI agents, disclosures, permissions, tool use, and interaction evidence across production workflows.

    Explore Runtime Governance