Utah’s AI Sandbox Is Becoming a Test of Regulated Healthcare, Not a General Safe Harbor
Utah’s Office of Artificial Intelligence Policy is turning a difficult regulatory question into a controlled experiment: what should happen when an AI product does something existing professional rules were not written to address?
The state’s answer is not a blanket exemption. A regulatory mitigation agreement is a written, temporary agreement among a participant, the Office of Artificial Intelligence Policy, and the relevant agency or governmental entity. Within its express scope, it may waive or modify how identified Utah laws or rules apply while an AI use is tested under stated conditions.
That distinction is becoming more consequential as Utah’s public list of authorized AI pilots expands. The list now includes healthcare uses involving prescription renewals, acne treatment, pelvic-floor physical therapy, psychiatry, and other regulated services. It also includes master agreements with University of Utah Health and Intermountain Health that create a path for future pilots without authorizing one by themselves.
Utah is therefore building a governance model around supervised evidence. For companies, the attraction is a defined route through an outdated or uncertain rule. For regulators, the bargain is narrower: a product may proceed only within a documented scope, with safeguards, reporting, human oversight, and a way to stop or tighten the experiment.
The legal mechanism is narrower than a blanket waiver
Under Utah Code Chapter 72, the office may temporarily grant regulatory mitigation by entering an agreement with a participant and the relevant agency head or governmental-entity head. The agreement may waive or modify how identified Utah laws or rules apply, but only for the covered technology and use and on the agreement’s stated terms.
The office cannot grant that relief alone. The agreement does not amend the underlying law or rule; a broader change still requires legislation or ordinary agency rulemaking.
Utah Code § 13-72-401 requires the agreement to specify limitations on use, safeguards, mitigation, consumer disclosures, and reporting requirements. The arrangement is a supervised, time-limited test authorization—not a professional license or general safe harbor. Section 13-72-401(8) expressly states that participation creates no property right or license.
Two different things appear on Utah’s pilot list
Utah’s public record combines approved pilots and master agreements. Treating them as the same would overstate what the state has authorized.
| Arrangement | What it does | What it does not do | | — | — | — | | Approved pilot | Permits a specified AI use under an agreement with the office and the relevant regulator | Does not authorize unrelated products, workflows, or later phases without approval | | Master agreement | Sets standing terms for proposing future pilots through written addenda | Does not authorize a pilot or grant regulatory relief by itself |
The distinction is visible in the September 10, 2026 master agreement with University of Utah Health. The agreement creates a process for proposing pilots across the health system, but the state’s page says no pilot has been approved under it yet. Intermountain Health has a similar master agreement. Each future project still requires its own written addendum, scope, safeguards, and approval.
The approved-pilot side is more concrete. Nolla Health’s active pilot, which runs from October 5, 2026 through October 5, 2027, concerns acne treatment for Utah adults with mild to moderate acne. The system assesses photographs and can issue first-time prescriptions and refills for specified topical treatments. The agreement excludes oral medication and isotretinoin and sets out eligibility and escalation limits.
Two additional healthcare pilots signed on October 2 had not yet begun their demonstration periods when Utah’s public page was reviewed. Expect Fitness concerns pelvic-floor physical therapy. Its system scores answers to standard clinical questionnaires and drafts an exercise and care plan, with a licensed physical therapist reviewing every plan in the initial phase. August AI concerns routine refills of existing prescriptions for a fixed list of noncontrolled medications. It does not write a new prescription, change a dose, or substitute one medication for another.
Doctronic illustrates a different stage of the program. Its pilot concerns 30-, 60-, and 90-day renewals of medication already prescribed by a licensed provider. The company remains in Phase 1, where every request requires authorization by a licensed medical practitioner. Moving to a later phase requires the office’s approval, and the state’s page says Phase 2 has not been approved.
The guardrails are the substance of the bargain
The pilot descriptions repeatedly use the same basic architecture, even though the clinical risks differ.
First, the state narrows the use case. A pilot may cover a specific medication list, patient population, treatment category, or geographic area. A company cannot assume that approval for one narrow workflow extends to a broader product.
Second, the state phases human review. August AI’s agreement requires prospective licensed-provider review of the first 250 refills, retrospective review of each of the next 1,000 refills, and later physician spot checks of at least 5 percent of prescriptions in each medication class. Nolla’s first stage requires two Utah-licensed physicians to review every prescription before it is sent. Expect Fitness begins with a licensed physical therapist reviewing every plan.
Third, the agreements create hard stops. The August AI pilot sends cases to a licensed provider when there is suicidal thinking, a new side effect, a dangerous interaction, or missing laboratory monitoring. The Nolla pilot stops for conditions such as pregnancy, breastfeeding, a weakened immune system, or a past reaction to a listed medication. Expect Fitness identifies symptoms that require urgent care rather than continued automated processing.
Fourth, the agreements require reporting. The public descriptions refer to monthly reporting, adverse-event reporting, agreement rates between AI outputs and reviewing clinicians, and public quarterly reporting for the master-agreement participants once pilots are approved. A pilot is meant to produce evidence that the office and the relevant regulator can review, not merely a contract that lets a product launch quietly.
Finally, Utah’s FAQ says participation does not eliminate accountability. Mitigation extends only to the Utah provisions expressly waived or modified; all other legal and regulatory requirements remain in force. Outside that express relief, participants remain subject to applicable civil and criminal penalties, and the FAQ states that patients retain traditional civil and medical-malpractice remedies. An agreement or pilot addendum may nevertheless establish specific cure periods, penalty limits, or safe harbors within its defined scope. Participation is not state endorsement.
What companies should not infer
The Utah model creates several traps for loose compliance summaries.
An agreement is not a statewide approval. The relief applies to the participant and the covered use described in the agreement.
An agreement is not a permanent rule change. Utah describes demonstration periods as temporary, with limited extensions, and says the office may end an agreement.
A master agreement is not a live pilot. University of Utah Health and Intermountain Health have a process for proposing projects, but the master agreements themselves authorize no pilot.
Regulatory mitigation is not blanket immunity. Requirements not expressly waived or modified remain in force, and violations of those requirements or the agreement can result in removal and applicable penalties. Any cure period, penalty cap, or safe harbor exists only to the extent stated in the governing agreement or pilot addendum.
Human oversight is not a slogan. It appears in the agreement as a named reviewer, a phase threshold, an escalation route, a reporting duty, or a condition for moving to the next stage.
A practical review for regulated AI products
Companies considering a similar arrangement should be able to answer five questions before asking for relief:
- What exact activity does the existing rule restrict, and what part of the proposed AI workflow creates the conflict?
- What is the smallest pilot that can answer the safety or compliance question without expanding the product’s claims?
- Which cases must always go to a licensed human, and what events automatically stop the automated path?
- What evidence will the regulator receive, on what schedule, and who is responsible for acting on a bad result?
- Which duties remain fully in force even if the agreement adjusts one rule?
Those questions turn a general request for “sandbox access” into a reviewable control plan. They also make it harder to describe a narrow agreement as a broad government endorsement.
Bottom line
Utah’s AI sandbox is becoming a useful case study in how regulators can test AI without pretending that an experimental approval is a permanent answer. The state is allowing specific healthcare uses to proceed under written conditions, while keeping the underlying rules, human accountability, reporting duties, and ordinary legal remedies in view.
The important development is not simply that Utah has authorized more AI pilots. It is that the state is publishing the scope, safeguards, phases, and limits of those pilots. That record gives companies a clearer compliance model—and gives regulators evidence they can use when deciding whether an old rule should eventually change.
This article is general information, not legal advice. The agreements, Utah Code, agency rules, and official pilot pages should be reviewed for the specific product, use case, and regulated profession involved.

Leave a Reply