Utah’s AI Policy Act, Executive Order 2026-08, and SEDI
On October 6, 2026, Governor Spencer J. Cox signed Executive Order 2026-08, Establishing Utah’s Pro-Human Approach to Artificial Intelligence in State Government. It names Utah’s State-Endorsed Digital Identity (SEDI) Framework as the state’s trust infrastructure for AI. This page reads the order next to the Utah Artificial Intelligence Policy Act, including its safe harbor, and maps both onto c=US’s agent identity and authorization controls. For each requirement it says whether c=US demonstrates it, only proposes it, or does not address it.
What the executive order says
The order directs the Department of Government Operations (DGO), which also runs SEDI, to:
Four other provisions bear directly on agent identity and accountability:
- Rogue agents. DGO must establish safeguards protecting state systems and data from “cyberattacks, malicious actors, and unauthorized or rogue AI agents,” and help agencies put equivalent protections in place (§ 4(a)).
- Human in the loop. Agencies deploying AI must ensure “human-in-the-loop review for determinations affecting individual rights” (§ 4(b)(i)).
- Transparency. Each agency must document “how AI systems, including their inputs, outputs, and roles in decision-making, are integrated into Agency processes that impact the public” (§ 5(d)).
- Existing law still governs. The order does not limit or alter obligations under GRAMA, the Government Data Privacy Act, or federal privacy and civil-rights law (§ 7(b)).
Its preamble describes SEDI as a framework that prevents “identity fraud, impersonation, unauthorized AI agent activity, and fraudulent digital content,” and it calls for privacy-preserving ways to verify “individuals, organizations, AI agents, and digital information.” DGO’s first progress report is due July 1, 2027.
What the order does not say
- It does not say state AI agents will rely on SEDI person information. It tells DGO to use SEDI “where applicable” as trust infrastructure. Which state agents would consume a person’s SEDI presentation, and for what purposes, is left to DGO and to future agency standards.
- It does not make an AI agent a SEDI holder. The SEDI statute defines “individual” as “a human being” (Utah Code § 63A-20-201(14)). The order’s talk of verifying AI agents has to work through the humans and organizations accountable for them, or through some mechanism not yet defined. That is the same constraint the SEDI walkthrough builds on.
- It does not mention the AI Policy Act. The order governs executive-branch agencies. The Act governs suppliers and licensed professionals. They are separate instruments.
- It does not cover every state body. The definition of “agency” excludes higher education, the State Board of Education, the Attorney General’s, State Auditor’s and State Treasurer’s offices, independent entities, and the legislative and judicial branches (§ 2(a)(ii)).
The AI Policy Act as it stands
The Utah Artificial Intelligence Policy Act (S.B. 149) took effect May 1, 2024. Several 2025 bills reshaped it. S.B. 226 replaced the original disclosure rule with a new chapter, now codified as Utah Code Title 13, Chapter 77, Generative Artificial Intelligence — Consumer Disclosures and Enforcement. S.B. 332 extended the repeal date of Title 13, Chapter 72, the Artificial Intelligence Policy Act itself (the Office of Artificial Intelligence Policy and its programs), to July 1, 2027. The Chapter 77 disclosure rules and safe harbor carry no such date. H.B. 452 added separate rules for mental-health chatbots.
- Disclosure on request. A supplier using generative AI in a consumer transaction must disclose that the person is dealing with AI, not a human, if the person makes “a clear and unambiguous request” to find out (§ 13-77-103(1)).
- Prominent disclosure in high-risk interactions. A licensed or state-certified professional must disclose generative AI use up front when the interaction is high-risk: it collects health, financial, or biometric data, or gives personalized financial, legal, medical, or mental-health advice that could be relied on for significant personal decisions (§§ 13-77-101(5), 13-77-103(2)–(3)). The disclosure is spoken at the start of a voice interaction and written before a written one.
- No “the AI did it” defense. It is not a defense to a consumer-protection violation that generative AI made the statement, took the act, or was used to commit it (§ 13-77-102).
- The Office of Artificial Intelligence Policy (Chapter 72), in the Department of Commerce, runs a learning laboratory and can enter regulatory mitigation agreements. These are time-limited arrangements that can provide a cure period and reduced penalties while a participant tests an AI technology.
The safe harbor
The safe harbor covers only the disclosure duties in § 13-77-103. It is not a defense to any other consumer-protection violation, and § 13-77-102 says the AI’s involvement never is. The Division of Consumer Protection may adopt rules specifying which forms of disclosure do and do not qualify (§ 13-77-104(2)).
Read together, the Act and the order ask for the same two things. Make it verifiable that an agent is an agent: the Act through disclosure and its safe harbor, the order through stopping “unauthorized AI agent activity” and impersonation. And keep a human answerable for what the agent does: the Act by refusing the “the AI did it” defense, the order through human-in-the-loop review and documented roles in decision-making.
c=US is built on both ideas. The agent gets its own certificate-backed identity, which never stands in for a person. A separately recorded human sponsor is accountable for it. The safe harbor’s disclosure is a sentence shown to a person. A c=US certificate is a machine-checkable claim that the counterparty is an agent, presented to another system. The two complement each other, and neither replaces the other.
How the requirements map to c=US
| Requirement | Source | c=US mechanism | Status |
|---|---|---|---|
| Disclose clearly, at the outset and throughout, that the counterparty is AI | § 13-77-104 (safe harbor) | c=US does not generate user-facing disclosure text; that is the deploying application’s job. The agent’s mTLS certificate (wimse://cequs.com/agents/<id> SAN) lets another system verify it is talking to a registered agent. | Partial / proposed |
| A human stays answerable; “the AI did it” is no defense | § 13-77-102; EO § 4(b)(i) | cequsAccountableSponsor names a proofed person entry, kept separate from the self-asserted cequsSponsor. The maple agent can only propose a grade (maple.lot.grade.propose); a person decides. | Schema exists; proofing not built |
| Block unauthorized or rogue agents | EO § 4(a), § 4(c) | The gateway maps a verified certificate fingerprint to a directory entry and checks status, scope, and the grant window, failing closed. Browser-supplied names never establish identity. | Demonstrated locally |
| SEDI as trust infrastructure for AI | EO § 4(c) | A sponsor presents their own SEDI credential; c=US verifies it, records the sponsor relationship separately, and issues a scoped grant. The agent is never the holder. See the SEDI walkthrough. | Not implemented |
| Document AI inputs, outputs, and role in decisions | EO § 5(d) | The published agent manifest states purpose, capabilities, and limits. Agent outputs are signed and timestamped (XAdES-T) and logged in the attestation log. | Demonstrated for the maple agent |
| Use personal information only for its purpose | Utah Code §§ 63A-20-701–702 (SEDI); EO § 7(b) | Signed mandates, data-use checks, and one-use permits in the Duty of Loyalty demonstration. | Synthetic scenarios only |
| Regulatory mitigation or learning-lab participation | Title 13, Office of AI Policy | c=US has not applied and claims no agreement. | Not applicable |
How a state agent could rely on SEDI person information
This is a design interpretation, not something the order prescribes. It assumes a future state service in which an AI agent acts for an agency and needs to know who it is serving.
- The resident presents, the agent does not hold. The resident shares a SEDI presentation from their own wallet, under notice that explains why the information is requested. The agent never becomes a SEDI holder, and it holds no copy of the person’s identifier beyond what the stated purpose needs.
- The agency verifies as a relying party. The agency checks issuer trust, the presentation binding, and non-revocation. Utah GovOps feedback recorded on the SEDI walkthrough says one organization commonly does both verification and reliance, and that a legal name is not automatically needed.
- The agent proves what it is, separately. The agent authenticates with its own certificate, and the gateway checks its grant. This is the machine-readable side of “is not human”, and it is how § 4(a) of the order’s “unauthorized AI agent activity” gets refused.
- A person makes determinations that affect rights. The agent’s scope stops at proposing. Any determination affecting individual rights goes to a human reviewer, as § 4(b)(i) requires, and the proposal, the evidence, and the reviewer’s decision are logged.
- Purpose limits follow the data. SEDI’s duty of loyalty and primary-purpose rules (§§ 63A-20-701–702), GRAMA, and the Government Data Privacy Act still govern what the agency may keep or reuse. A verified presentation is not blanket consent.
Where this is honestly incomplete
No compliance claim. Nothing on this site has been reviewed by the Division of Consumer Protection, the Office of Artificial Intelligence Policy, or DGO. This page is not legal advice. Whether a particular deployment counts as a “supplier,” a “regulated occupation,” or a high-risk interaction is a question for counsel.
Human-to-AI delegation is not enacted. Utah GovOps correspondence anticipates possible discussion of human-to-AI delegation in the 2027 session. Until then, nothing lets a person’s SEDI identity be delegated to an agent, and c=US’s grants are its own mechanism, not a SEDI one.
The law may change. Chapter 72, which creates the Office of Artificial Intelligence Policy and its regulatory mitigation program, is scheduled for repeal on July 1, 2027, unless the Legislature acts. The Chapter 77 disclosure rules and safe harbor have no repeal date. The order’s first progress report is due the same day as that repeal. Either could reshape this mapping.
What is built. The mTLS gateway, grant checks, signed outputs, and duty-of-loyalty scenarios run as local or synthetic demonstrations. Sponsor identity proofing, SEDI verification, and wallet interoperability are not built.
Sources
- Executive Order 2026-08, Establishing Utah’s Pro-Human Approach to Artificial Intelligence in State Government, signed October 6, 2026: governor.utah.gov (PDF). All quotes from the order were read directly from this PDF. Governor’s news release.
- Utah Code § 13-77-104, Safe harbor: le.utah.gov. S.B. 226 (2025), enrolled copy, the source of §§ 13-77-101 to -105: le.utah.gov (PDF).
- S.B. 332 (2025), extending the repeal date of Title 13, Chapter 72 (Utah Code § 63I-2-213(5)): le.utah.gov (PDF). Original S.B. 149 (2024): le.utah.gov.
- SEDI statute, S.B. 275 (2026): le.utah.gov (PDF), as quoted on this site’s SEDI walkthrough.
- This project’s
schema/cus-registry.schema(cequsSponsor,cequsAccountableSponsor) and the published agent manifest.
Drafted by Claude (Anthropic) from the primary sources above, at the student’s request. The mapping and the five-step flow are AI-generated analysis, kept separate from the statutory and executive-order text they cite, and awaiting the student’s review.