C=USSEDI walkthrough →

Utah’s AI Policy Act, Executive Order 2026-08, and SEDI

On October 6, 2026, Governor Spencer J. Cox signed Executive Order 2026-08, Establishing Utah’s Pro-Human Approach to Artificial Intelligence in State Government. It names Utah’s State-Endorsed Digital Identity (SEDI) Framework as the state’s trust infrastructure for AI. This page reads the order next to the Utah Artificial Intelligence Policy Act, including its safe harbor, and maps both onto c=US’s agent identity and authorization controls. For each requirement it says whether c=US demonstrates it, only proposes it, or does not address it.

What the executive order says

The order directs the Department of Government Operations (DGO), which also runs SEDI, to:

“Develop and utilize the SEDI Framework, where applicable, as the State’s strategic trust infrastructure for AI by enabling cryptographically verifiable identities, credentials, and data that protect privacy while preventing identity fraud, impersonation, unauthorized AI agent activity, and fraudulent digital content.”Executive Order 2026-08, § 4(c)

Four other provisions bear directly on agent identity and accountability:

Its preamble describes SEDI as a framework that prevents “identity fraud, impersonation, unauthorized AI agent activity, and fraudulent digital content,” and it calls for privacy-preserving ways to verify “individuals, organizations, AI agents, and digital information.” DGO’s first progress report is due July 1, 2027.

What the order does not say

The AI Policy Act as it stands

The Utah Artificial Intelligence Policy Act (S.B. 149) took effect May 1, 2024. Several 2025 bills reshaped it. S.B. 226 replaced the original disclosure rule with a new chapter, now codified as Utah Code Title 13, Chapter 77, Generative Artificial Intelligence — Consumer Disclosures and Enforcement. S.B. 332 extended the repeal date of Title 13, Chapter 72, the Artificial Intelligence Policy Act itself (the Office of Artificial Intelligence Policy and its programs), to July 1, 2027. The Chapter 77 disclosure rules and safe harbor carry no such date. H.B. 452 added separate rules for mental-health chatbots.

The safe harbor

“A person is not subject to an enforcement action for violating Section 13-77-103 if the person’s generative artificial intelligence clearly and conspicuously discloses: (a) at the outset of any interaction with an individual in connection with: (i) a consumer transaction; or (ii) the provision of regulated services; and (b) throughout the interaction that it: (i) is generative artificial intelligence; (ii) is not human; or (iii) is an artificial intelligence assistant.”Utah Code § 13-77-104(1), effective May 7, 2025

The safe harbor covers only the disclosure duties in § 13-77-103. It is not a defense to any other consumer-protection violation, and § 13-77-102 says the AI’s involvement never is. The Division of Consumer Protection may adopt rules specifying which forms of disclosure do and do not qualify (§ 13-77-104(2)).

Key point

Read together, the Act and the order ask for the same two things. Make it verifiable that an agent is an agent: the Act through disclosure and its safe harbor, the order through stopping “unauthorized AI agent activity” and impersonation. And keep a human answerable for what the agent does: the Act by refusing the “the AI did it” defense, the order through human-in-the-loop review and documented roles in decision-making.

c=US is built on both ideas. The agent gets its own certificate-backed identity, which never stands in for a person. A separately recorded human sponsor is accountable for it. The safe harbor’s disclosure is a sentence shown to a person. A c=US certificate is a machine-checkable claim that the counterparty is an agent, presented to another system. The two complement each other, and neither replaces the other.

How the requirements map to c=US

RequirementSourcec=US mechanismStatus
Disclose clearly, at the outset and throughout, that the counterparty is AI§ 13-77-104 (safe harbor)c=US does not generate user-facing disclosure text; that is the deploying application’s job. The agent’s mTLS certificate (wimse://cequs.com/agents/<id> SAN) lets another system verify it is talking to a registered agent.Partial / proposed
A human stays answerable; “the AI did it” is no defense§ 13-77-102; EO § 4(b)(i)cequsAccountableSponsor names a proofed person entry, kept separate from the self-asserted cequsSponsor. The maple agent can only propose a grade (maple.lot.grade.propose); a person decides.Schema exists; proofing not built
Block unauthorized or rogue agentsEO § 4(a), § 4(c)The gateway maps a verified certificate fingerprint to a directory entry and checks status, scope, and the grant window, failing closed. Browser-supplied names never establish identity.Demonstrated locally
SEDI as trust infrastructure for AIEO § 4(c)A sponsor presents their own SEDI credential; c=US verifies it, records the sponsor relationship separately, and issues a scoped grant. The agent is never the holder. See the SEDI walkthrough.Not implemented
Document AI inputs, outputs, and role in decisionsEO § 5(d)The published agent manifest states purpose, capabilities, and limits. Agent outputs are signed and timestamped (XAdES-T) and logged in the attestation log.Demonstrated for the maple agent
Use personal information only for its purposeUtah Code §§ 63A-20-701–702 (SEDI); EO § 7(b)Signed mandates, data-use checks, and one-use permits in the Duty of Loyalty demonstration.Synthetic scenarios only
Regulatory mitigation or learning-lab participationTitle 13, Office of AI Policyc=US has not applied and claims no agreement.Not applicable

How a state agent could rely on SEDI person information

This is a design interpretation, not something the order prescribes. It assumes a future state service in which an AI agent acts for an agency and needs to know who it is serving.

  1. The resident presents, the agent does not hold. The resident shares a SEDI presentation from their own wallet, under notice that explains why the information is requested. The agent never becomes a SEDI holder, and it holds no copy of the person’s identifier beyond what the stated purpose needs.
  2. The agency verifies as a relying party. The agency checks issuer trust, the presentation binding, and non-revocation. Utah GovOps feedback recorded on the SEDI walkthrough says one organization commonly does both verification and reliance, and that a legal name is not automatically needed.
  3. The agent proves what it is, separately. The agent authenticates with its own certificate, and the gateway checks its grant. This is the machine-readable side of “is not human”, and it is how § 4(a) of the order’s “unauthorized AI agent activity” gets refused.
  4. A person makes determinations that affect rights. The agent’s scope stops at proposing. Any determination affecting individual rights goes to a human reviewer, as § 4(b)(i) requires, and the proposal, the evidence, and the reviewer’s decision are logged.
  5. Purpose limits follow the data. SEDI’s duty of loyalty and primary-purpose rules (§§ 63A-20-701–702), GRAMA, and the Government Data Privacy Act still govern what the agency may keep or reuse. A verified presentation is not blanket consent.

Where this is honestly incomplete

Real limits, stated plainly

No compliance claim. Nothing on this site has been reviewed by the Division of Consumer Protection, the Office of Artificial Intelligence Policy, or DGO. This page is not legal advice. Whether a particular deployment counts as a “supplier,” a “regulated occupation,” or a high-risk interaction is a question for counsel.

Human-to-AI delegation is not enacted. Utah GovOps correspondence anticipates possible discussion of human-to-AI delegation in the 2027 session. Until then, nothing lets a person’s SEDI identity be delegated to an agent, and c=US’s grants are its own mechanism, not a SEDI one.

The law may change. Chapter 72, which creates the Office of Artificial Intelligence Policy and its regulatory mitigation program, is scheduled for repeal on July 1, 2027, unless the Legislature acts. The Chapter 77 disclosure rules and safe harbor have no repeal date. The order’s first progress report is due the same day as that repeal. Either could reshape this mapping.

What is built. The mTLS gateway, grant checks, signed outputs, and duty-of-loyalty scenarios run as local or synthetic demonstrations. Sponsor identity proofing, SEDI verification, and wallet interoperability are not built.

Sources

Drafted by Claude (Anthropic) from the primary sources above, at the student’s request. The mapping and the five-step flow are AI-generated analysis, kept separate from the statutory and executive-order text they cite, and awaiting the student’s review.