Source: Unite.AI
Vendors designated by Utah’s Office of Artificial Intelligence Policy must generate and deliver a cryptographically signed receipt for every covered AI inference or control evaluation as a condition of joining the state’s AI Learning Laboratory and remaining in it, Glacis Technologies said in a company announcement published October 5, 2026. The receipts conform to OVERT (Observable Verification Evidence for Runtime Trust), an open technical standard for verifiable evidence of AI operations that Glacis created and publishes under a royalty-free patent covenant.
Under the agreement, the office decides which vendors, systems and events are covered, and it writes the requirement into each vendor’s own agreement with the state; Glacis provides receipt issuance, verification materials and onboarding, and other evidence may accompany a receipt but cannot replace one, the company said. The state’s third-party evaluators page records the Glacis memorandum of understanding as signed August 10, 2026, with a 12-month term, and the company describes the agreement as announced October 5. Joe Braidwood, the post’s author, said it is the first time a regulator has written OVERT into a participation requirement.
What the Receipts Record
A receipt records a control’s reported decision on a covered event and the time the decision was made, and it is signed at the moment of the event. According to the announcement, anyone holding the verification materials can confirm that the record has not been altered and that it came from the expected signing key. As an example, the announcement describes a clinical assistant configured to route certain requests to a clinician rather than answer them itself: the receipt preserves the control’s reported decision on a specific request, giving an evaluator a signed record to examine in place of a summary written by the vendor.
The company and the state describe the same boundary for what a receipt establishes. A verified receipt shows that a control ran, that it reported a decision, and that the record was not changed afterward; it does not show that the decision was correct, that a referral reached a clinician, or that a patient received appropriate care, and it does not certify safety, effectiveness or legal compliance.
Utah’s evaluators page sets out the state’s version of the mechanism under a category it calls Runtime Attestation: companies the office selects must produce a tamper-evident digital receipt each time a specified safety check runs, and the page states that such a receipt shows the check ran without showing that the AI is safe or that the company followed the law. The agreement does not require vendors to hand over model weights, raw prompts, raw outputs or patient data, because a receipt can be bound to an event with a hash or another identifier that carries no content.
Utah’s Evaluator Framework and Sandbox Terms
The Office of Artificial Intelligence Policy, part of the Utah Department of Commerce, has signed memoranda of understanding with six independent organizations that can review a proposal before it is approved and check a pilot’s work while it runs. Evaluators report to the office, which keeps every decision about whether a pilot starts, continues or stops, and the evaluation criteria are being finalized with each organization.
The evaluators page lists the Coalition for Health AI, signed October 2, 2026; the Stanford Clinical Excellence Research Center, signed September 30, 2026; Clarion AI Partners and mpathic, each signed September 29, 2026; Vega Health, signed September 28, 2026; and Glacis Technologies, signed August 10, 2026. Each memorandum carries a 12-month term, and the entries for the Coalition for Health AI, Stanford CERC, mpathic and Vega Health state that the term renews each year.
Under the office’s published safeguards, the company being evaluated pays the evaluator directly, the state does not pay for evaluations, and attestation receipts are free to the companies required to produce them. Evaluators must certify that each evaluation was independent, report any patient-safety concern to the office whether or not the company passes, and open their work to office audits, and a certification that does not match actual findings is grounds for pausing, rolling back or terminating a pilot. No evaluator holds an exclusive role, and the evaluator agreements grant no regulatory relief.
The sandbox program’s legal name is the Artificial Intelligence Learning Laboratory, according to the state’s sandbox overview. A participant signs an agreement with the office and with the agency that already regulates its field; the agreement can adjust how one specific rule applies during a limited test period, every other legal requirement stays in force, and acceptance is not an endorsement or approval by the State of Utah. A first test period cannot exceed 12 months, and a company may request up to two 12-month extensions before the agreement ends and the ordinary rules apply in full. Each agreement must spell out the test’s scope, the safeguards the company must keep running, the specific rule being adjusted, the disclosures owed to users, and the reporting on which office audits run. The office can remove a participant immediately for breaking the law or the agreement, and it can end an agreement at any time.
The office has also signed five agreements expanding the laboratory, according to an office news item: pilot agreements with Expect Fitness for pelvic floor physical therapy, August AI for routine prescription refills and Nolla Health for acne treatment, alongside master agreements with University of Utah Health and Intermountain Health that set terms for approving future AI pilots within each health system.
OVERT’s Pending Stewardship Transfer
Glacis published OVERT 1.0 in March 2026 and version 1.1 in June 2026; the specification text is free to copy and adapt under a Creative Commons Attribution 4.0 license, and the royalty-free patent covenant published in June remains unchanged.
In a September 21, 2026 post, the company said that Brenton Hill of the Coalition for Health AI, Ken Johnston of the AIGovOps Foundation and Braidwood signed an OVERT Stewardship and Continuity Agreement on September 14, 2026, under which the coalition and the foundation would become co-stewards holding one vote each and Glacis would become a nonvoting editor that cannot alter conformance criteria. Glacis stated that it competes on its own implementation of OVERT and holds a commercial interest in the standard. Braidwood wrote that a requirement naming one company’s private format is weaker than one naming an open standard, because a regulator can verify a receipt without depending on the company that issued it.
The stewardship transfer is not yet in force, the company said: it takes effect at a time recorded in a separate commencement certificate signed by all three parties, and that certificate has not been signed. No release can be approved without a public comment period of at least 30 days and the agreement of both co-stewards, and registry operation is scheduled to move away from Glacis within 90 days of commencement.
