HB 276 creates a new set of Utah laws addressing two related areas: non-consensual AI-generated intimate images and digital content provenance. First, it enacts the Digital Voyeurism Prevention Act, which prohibits generation services from distributing counterfeit intimate images without the depicted person’s consent. The bill defines key terms such as “generation service,” “covered platform,” “counterfeit intimate image,” and “consent,” and it requires generation services to build consent systems, keep consent records, and provide user-facing reporting and transparency policies.
The bill also imposes duties on covered online platforms to respond to notices of non-consensual intimate images by removing reported content within 48 hours and making reasonable efforts to remove identical copies. It creates civil causes of action against both generation services and covered platforms, allowing injured individuals or heirs to seek injunctions, actual damages, emotional distress damages, punitive damages in some cases, attorney fees, and costs. At the same time, it gives those services and platforms safe-harbor protections if they adopt and follow written policies, reasonable safeguards, and notice-and-takedown procedures, and it adds heightened pleading requirements that force plaintiffs to allege specific facts showing why safe harbor does not apply.
A second major part of the bill establishes Digital Content Provenance Standards. Large online platforms must detect and disclose compliant provenance data, allow users to inspect it, and avoid stripping it when technically feasible. Capture device manufacturers must include latent disclosures in captured content, and covered providers of generative AI systems must include latent disclosures in AI-generated or substantially modified image, video, or audio content. The bill also directs the Division of Consumer Protection to enforce these standards, authorizes administrative fines and court actions, and requires the chief information officer to set standards for certain state agency websites and applications where misleading media could harm users.
The bill’s impact on state law is broad: it amends the Division of Consumer Protection’s enforcement authority and creates multiple new code chapters and enforcement mechanisms that regulate AI tools, social media platforms, and content creation devices. It also ties Utah’s new requirements to federal law by referencing the Take It Down Act and stating that the bill does not alter Section 230 or expand federal notice-and-takedown obligations. The law takes effect January 1, 2027, with some capture-device requirements applying to devices sold in Utah on or after January 1, 2028.
Overall, the bill appears to have been broadly supported, passing the House and Senate with large margins and receiving unanimous or near-unanimous committee recommendations at several stages. The main points of contention appear to be the balance between protecting victims of deepfake intimate imagery and limiting liability for technology companies. That balance is reflected in the bill’s safe harbors, notice-based liability, and heightened pleading standards, which suggest concern about overbroad lawsuits or burdens on platforms and AI providers while still creating new remedies for non-consensual synthetic sexual imagery.
HB 276 creates new statutory duties for AI generation services, covered online platforms, large online platforms, capture device manufacturers, and certain generative AI providers, while expanding the Division of Consumer Protection’s enforcement role. It adds new civil liability provisions, notice-and-takedown obligations, provenance disclosure requirements, and administrative fine authority, and it also requires state IT rulemaking for provenance records on certain government websites and applications. The bill substantially modifies Utah’s consumer protection framework by adding Chapters 72b and 72c and amending Section 13-2-1 to include them within the Division of Consumer Protection’s enforcement jurisdiction.
The overall sentiment around HB 276 was strongly favorable. Committee votes were largely unanimous or near-unanimous, and the bill passed both chambers by wide margins, indicating broad bipartisan support for addressing AI-generated intimate image abuse and digital authenticity concerns. The final enactment and gubernatorial signature further suggest the bill was viewed as a significant but acceptable response to emerging AI-related harms.
The main tension in the bill is between victim protection and limiting exposure for technology companies. Supporters of the liability provisions appear focused on preventing non-consensual deepfakes, preserving privacy, and giving victims meaningful remedies. Potentially opposing concerns are addressed through safe harbors, notice-and-takedown procedures, heightened pleading standards, and explicit language preserving Section 230 and not expanding federal obligations. Those provisions suggest concern from platforms, AI developers, and device manufacturers about compliance burdens, litigation risk, and the technical feasibility of provenance and disclosure requirements.