Policy
Utah does not ban mental health chatbots. It sets rules on privacy, ads, and telling you it is not a human
Source date · Reviewed
Utah's HB 452 bars mental health chatbots from selling or sharing what users type, sets three exceptions for health data, limits ads and requires AI disclosure.
At a glance
- Where
- Utah
- Law or rule
- H.B. 452, Artificial Intelligence Amendments (2025), enacting Utah Code Title 13, Chapter 72a and Section 58-60-118
- Effective
- May 7, 2025 (signed by the governor March 25, 2025)
- Who it covers
- Suppliers of mental health chatbots used by anyone located in Utah. A mental health chatbot is generative AI that holds therapist-like conversations and is presented as able to provide therapy or help manage or treat mental health conditions, or that a reasonable person would believe can. Not covered: scripted tools such as guided meditations, and tools that only connect a person with a human therapist.
- What changes
- Suppliers may not sell or share a Utah user's identifiable health information or chat input with third parties. Three listed exceptions apply to health information only. In-chat ads must be labeled, and chat input may not be used to target ads. The chatbot must say it is AI and not a human before first use, after 7 days away, and whenever asked. Suppliers that file a written safety policy with the state, keep required records, and follow the policy get an affirmative defense to certain licensing-law claims.
- Penalties
- Administrative or court fines of up to $2,500 per violation, enforced by the Utah Division of Consumer Protection, and up to $5,000 per violation of an order issued under the law
- What this does NOT tell us
- Whether any chatbot is safe or helps people in recovery. The law does not mention substance use and does not require any crisis response.
The short version
Utah took a different path from Illinois. Instead of barring AI from acting as a therapist, it regulates mental health chatbots through consumer-protection rules. House Bill 452, in effect since May 7, 2025, limits what companies can do with what you type, restricts advertising inside the chat, and requires the chatbot to tell you it is not a human.
What the law does
The law covers a "mental health chatbot," defined as generative AI that holds conversations like those a person would have with a licensed mental health therapist, and that the company presents as able to provide therapy or help manage or treat mental health conditions. It also covers a chatbot that a reasonable person would believe can do those things, whatever the company says. Tools that only give scripted output, like guided meditations, are not covered. Neither are tools that only analyze what you say in order to connect you with a human therapist.
It applies to anyone located in Utah when they use the chatbot, and it has three main rules.
Privacy. The company may not sell or share a Utah user's identifiable health information, or anything the user types, with a third party. The law lists three exceptions, and they apply only to health information, not to what the user types: a health care provider can request it with the user's consent, the user can ask for it to go to their health plan, and the company can share what is needed to run the chatbot with a contractor, if both follow HIPAA privacy and security rules as though they were covered by HIPAA.
Advertising. An ad inside the conversation must be clearly labeled, and any sponsorship or business deal behind it must be disclosed. The company may not use what you type to decide whether to show you an ad, what to advertise, or how to present it, except for ads for the chatbot itself. The chatbot can still recommend that you see a licensed professional, including a specific one.
Disclosure. The chatbot must clearly say it is AI and not a human before you can use it, at the start of any conversation if you have not used it in the past 7 days, and any time you ask.
The Utah Division of Consumer Protection enforces the law. It can fine up to $2,500 per violation or go to court, where a judge can order fines of up to $2,500 per violation, an injunction, or repayment of money. Violating an order issued under the law can bring up to $5,000 per violation.
The safety policy, and why it is optional
A separate section gives companies a reason to write down how they keep users safe. A company that files a written policy with the state, keeps records on the models and training data it used, and follows the policy gets an affirmative defense against claims under two subsections of Utah's professional licensing law.
The policy must state the chatbot's purposes and limits and describe 15 procedures. Among them: involving licensed mental health therapists in development, testing before release and regularly after so the chatbot poses no greater risk than therapy with a licensed therapist, a way for users to report harmful conversations, protocols to respond in real time to acute risk of physical harm, and putting user safety ahead of engagement or profit.
Filing is voluntary. The law rewards companies that adopt a crisis protocol but does not require one, and nothing in it requires a chatbot to refer anyone to 988, 911 or any other crisis line.
The law also states that it does not recognize a chatbot as a licensed mental health therapist.
What it does not show
The law does not mention substance use, addiction or recovery. Whether an app aimed at drinking or drug use counts as a mental health chatbot depends on how the company presents it and how the definition is read. This entry does not answer that for any product.
It is a consumer-protection law about data, ads and honesty. It says nothing about whether chatbots help or harm people.
The enrolled bill's summary describes "rebuttable presumptions" for companies that file compliant policies. The enacted section itself calls this an affirmative defense. This entry uses the section text.
A 2026 Utah bill on AI companion chatbots (H.B. 438) was filed without passing, and the Utah Code site lists the May 7, 2025 text as the current version of this chapter as of this review.
Why it matters
If you use a chatbot for mental health support, what you type may be among the most sensitive things you ever write down. In Utah, a covered company may not sell what you type or share it with any third party, and the law lists no exceptions for it.
Utah and Illinois show two different approaches. Illinois bars AI from providing therapy. Utah does not ban these chatbots. It regulates how they handle data, ads and disclosure, and gives companies that file and follow a safety policy a defense against unlicensed-practice claims. People in recovery who use these tools, and programs that recommend them, should know which rules apply where they live. They should also not assume a chatbot has a plan for a crisis.
Sources
- Utah State Legislature. H.B. 452, Artificial Intelligence Amendments, 2025 General Session. Enrolled copy. Chief Sponsor Rep. Jefferson Moss; Senate Sponsor Sen. Kirk A. Cullimore. H.B. 452 (2025); Utah Code 13-72a and 58-60-118 https://le.utah.gov/~2025/bills/hbillenr/HB0452.pdf
- Utah State Legislature. H.B. 452 Artificial Intelligence Amendments, bill status and action history (Governor signed March 25, 2025). H.B. 452 (2025) https://le.utah.gov/~2025/bills/static/HB0452.html
- Utah Code, Title 13, Chapter 72a, Part 2, Protections for Users of Mental Health Chatbots. Current version, effective May 7, 2025. Utah Code 13-72a-201 to 13-72a-204 https://le.utah.gov/xcode/Title13/Chapter72A/C13-72a-P2_2025050720250507.pdf
Published by ZSKFL Management.