If your dental office has a chatbot on its website, or an AI assistant answering the phone or replying to messages, Utah's Artificial Intelligence Policy Act applies to you. The fix is small. The risk of ignoring it is not. This post explains what the law asks of a dental practice in plain English, with the details a lawyer would want you to know.
The law in one paragraph
Utah's AI Policy Act (SB 149) took effect on May 1, 2024 and was narrowed by amendments effective May 7, 2025. It says that any business using generative AI to interact with a consumer must clearly and conspicuously disclose that fact when the consumer asks. In "high-risk" interactions, which include health care, financial and legal advice, and the collection of sensitive personal data, and for state-licensed professionals, the disclosure must be prominent and made at the start of the interaction. Our Utah AI Policy Act page tracks the text, the dates and the sources.
The law is currently scheduled to sunset on July 1, 2027 unless the legislature extends it, which is worth knowing but not worth planning around.
Why a dental office is in the strict tier
Two reasons, and either one is enough:
- Health care is a high-risk interaction. A chatbot that answers "does this hurt," "what does a crown cost" or "can I book a cleaning" is talking to a patient about health care.
- Dentists are state-licensed professionals. The stricter timing applies to regulated occupations regardless of what the conversation is about.
So the "only when asked" version of the rule is not enough for you. The notice has to be there, prominently, at the start.
What the notice has to say
The law asks for a clear and conspicuous statement that the person is interacting with generative AI and not a human. It does not prescribe wording. Two lines that meet it, from our disclosure examples:
You're chatting with an AI assistant, not a person. Ask for a member of our team at any time.
Hi! I'm [Practice]'s AI assistant. I'm not a person, but I can answer questions and connect you with our front desk.
Prominent means the patient can't miss it. Beside the chat window when it opens is the usual place. A line buried in a privacy policy is not prominent.
When it has to appear
For a dental office, at the start of the interaction. In practice that means:
- Website chat: the notice shows when the chat opens, before the patient types anything.
- AI on the phone: the assistant says it in its greeting.
- Text and email replies written by AI: say so in the message.
- When a patient asks "am I talking to a real person?" the bot must answer truthfully, every time. This is where practices get caught. Some chatbots are set up to sound human and will deflect the question. Put a line in the bot's instructions that tells it to say it is AI.
If a person on your team takes over the chat, tell the patient that too, and again if the AI comes back.
What happens if you don't
The Utah Division of Consumer Protection enforces the Act. Administrative fines run up to $2,500 per violation, plus court-ordered remedies, and up to $5,000 per violation for breaking an administrative or court order. There is no private right of action, so patients can't sue under this law directly, but a complaint to the Division is easy to file and a practice's marketing, website and chat logs are all evidence.
"Per violation" is the phrase to notice. A chatbot with no notice doesn't commit one violation. It commits one per conversation.
Keeping proof
Here is the part most practices miss. A complaint arrives in March about a conversation in September. The question is not "do you have a notice today," it's "was the notice shown to that patient on that day." A screenshot taken after the fact proves little, and the website has probably changed since.
That is what a disclosure record is for: an entry each time the notice is displayed, with the time, the page and an anonymous visitor fingerprint, kept in a form that shows if anyone has changed it. Our page on how the disclosure record works explains what is stored, why it holds no patient data, and how a complaint is matched to it.
A checklist for this week
- List every place AI talks to patients: website chat, phone, texts, email replies, appointment tools.
- Put a clear notice at the start of each one, using the wording above or your own.
- Tell your chatbot to say it is AI whenever a patient asks.
- Decide how you'll prove the notice was there: a record, not a memory.
- Check whether other states' laws reach you too. Our AI disclosure laws by state index is the quickest way, and the free website scan shows what your site looks like to a visitor today.
Frequently asked questions
Our chatbot is only for booking appointments. Does the law still apply?
Yes. The law looks at whether a person is interacting with generative AI, not at what the conversation is for. A booking bot at a licensed practice is in the strict tier.
The chat tool is provided by a vendor. Isn't the disclosure their job?
The duty sits with the business using the AI with its consumers. Your vendor may give you the tools to show a notice, but the obligation is yours.
Do we need a notice if the patient can obviously tell it's a bot?
Yes. The law asks for a clear and conspicuous disclosure, not for the patient to work it out. Obvious to you is not obvious to an anxious patient at 11 pm.
What about patients from other states?
Utah's law protects Utah consumers. If your website serves patients across state lines, Maine, California and others have their own rules. The state index lists them.
Not legal advice. This post summarises the law as of its date; effective dates and penalties change. The Future of Privacy Forum's summary of Utah's amendments and the statute itself are the authority.
