Skip to main content
TrustEdge AI
CTEnacted

Connecticut AI Regulations

Connecticut spent three sessions on AI legislation and the bill everyone tracked is not the one that passed. Substitute SB 2 (2025) cleared the Senate and died on the House calendar. The operative law is Substitute SB 5 (2026), Public Act 26-15, "An Act Concerning Online Safety," signed May 27, 2026 — a 74-page act covering generative AI provenance, frontier-model whistleblowers, AI companions, automated employment decisions, and minors online, phasing in from October 1, 2026 through January 1, 2028. Separately and already in force, the June 2025 amendments to the Connecticut Data Privacy Act broadened consumer rights over profiling and automated decisions as of July 1, 2026, with a new profiling impact assessment duty attaching to activities created or generated on or after August 1, 2026.

Phased. CTDPA profiling amendments in force July 1, 2026; profiling impact assessments required for activities created or generated on or after August 1, 2026. Public Act 26-15 phases in October 1, 2026, then January 1, 2027, then October 1, 2027 for employment AI duties, then January 1, 20284 bills tracked

Last reviewed against primary sources: . AI legislation is moving quickly — statutes have been delayed, repealed and replaced mid-cycle. Verify against the linked primary sources before relying on any date here.

In-Depth Analysis

Connecticut is the clearest case in the country of a state where tracking the famous bill gets you the wrong law.

SB 2 was the bill the trade press covered for two years. It cleared the Senate and was widely described as the Colorado-style comprehensive AI act that would arrive next. It never got a House vote. Any compliance calendar still listing "Connecticut SB 2 — pending" is tracking a bill that has been dead since June 2025 and is missing a live deadline two months out.

What Connecticut actually enacted is structurally different from Colorado's 2024 approach and from the model most trackers expected. There is no duty of reasonable care against algorithmic discrimination, no risk management program mandate, and no algorithmic impact assessment requirement in PA 26-15. What there is instead is a set of narrow, sector-specific duties on different actors with different dates: provenance for large generative AI providers, whistleblower protection for frontier labs, safety protocols for companion chatbots, notice for employment AI, and age assurance for platforms serving minors.

The date structure of the employment provisions catches people. Sections 7 through 12 are "effective October 1, 2026," and that language appears in every summary. But read the operative text: each duty applies to technology deployed on or after October 1, 2027. The compliance date for developer disclosure, interactive disclosure, and pre-decision notice is 2027. What does bite in 2026 is different and easier to miss — the amendment making AI use unavailable as a defense to a discrimination complaint, which takes effect October 1, 2026 with no deferral. An employer whose AEDT notice program is not due until 2027 is nonetheless exposed to a discrimination claim in 2026 in which the tool provides no shelter and its bias testing, or the absence of it, is evidence.

The part with the nearest deadline is not in the AI statute at all. The CTDPA amendments in Public Act 25-113 took effect July 1, 2026. Striking "solely" from the profiling opt-out is the substantive change: a human in the loop no longer removes the decision from the opt-out right, the explanation right, or the data-review right. And the profiling impact assessment obligation attaches to activities created or generated on or after August 1, 2026 — as of this review date, that has started.

The scope change underneath it matters as much. The threshold fell to 35,000 consumers, processing any sensitive data pulls a business in on its own, and the entity-level GLBA exemption is gone. A mortgage servicer, a specialty lender, or a fintech that concluded years ago it was outside the CTDPA because it was a GLBA financial institution should redo that analysis. Depository institutions, insurers, and registered broker-dealers and advisers still have entity-level cover; much of the rest of the financial sector does not.

One asymmetry worth naming for healthcare organizations: the CTDPA retains the HIPAA entity-level exemption, but PA 26-15's employment provisions contain no equivalent. A hospital system is exempt from the CTDPA and fully covered by the AEDT rules when it screens nursing applicants with an AI tool. The exemption you rely on for patient data does nothing for hiring.

Practical Implications for SMBs & Healthcare

If your Connecticut tracker says "SB 2," it is wrong, and the correction is not cosmetic. The real statute has a duty landing October 1, 2026 and a privacy obligation that started August 1, 2026.

For healthcare organizations: your HIPAA exemption covers you under the CTDPA and does nothing for you under PA 26-15's employment provisions. Clinical AI is largely untouched by this statute. Hiring and workforce AI is squarely in it, on the 2027 clock, with the discrimination-defense change arriving in 2026.

For financial services: the question is no longer whether the AI rules apply — it is whether you are still exempt from the CTDPA. Banks, credit unions, insurers, and registered broker-dealers and advisers meeting the statutory conditions are. Non-depository lenders, servicers, and fintechs that relied on the entity-level GLBA exemption are not, and now face profiling opt-out, explanation, and impact assessment duties on data outside GLBA Title V.

For employers of any size: there is no employee-count floor in the AEDT provisions. If your applicant tracking system scores or ranks candidates in a way that meaningfully alters an outcome, you are a deployer. Ask your vendor now whether it will contract to assume your Sections 9 and 10 duties — the act expressly permits that allocation, and vendors will price it differently in 2026 than in mid-2027.

The overall posture Connecticut asks for is documentation, not architecture. Know which tools score people, know what data they use, be able to explain an outcome, and keep evidence of bias testing. Nothing in PA 26-15 requires a risk management framework. Your other obligations may.

Key Provisions

What passed, and what did not

Substitute SB 2 (2025), "An Act Concerning Artificial Intelligence," passed the Senate on May 14, 2025 as amended. Its last recorded action is House Calendar Number 599 on May 16, 2025. It was never called in the House and died with the session. It is not law and never has been. The operative statute is Substitute SB 5 (2026), enacted as Public Act 26-15 — Senate passage April 21, 2026, House passage May 1, 2026, signed by the Governor May 27, 2026. Legislators refer to it informally as the Connecticut Artificial Intelligence Responsibility and Transparency Act; the enrolled act carries no such short title.

Automated employment-related decision technology — two dates, not one

Sections 7 through 12 of PA 26-15 take effect October 1, 2026, but every duty in them is keyed to technology deployed on or after October 1, 2027. Scope is any technology processing personal data whose output is a "substantial factor" — one that meaningfully alters the outcome — in a decision to hire, promote, discipline, discharge, renew employment, select for training or apprenticeship, or set terms and conditions of employment. Developers must give deployers the information deployers need to meet their duties, and may contract to assume those duties outright, provided the contract states clearly which ones. Deployers must disclose in plain language that an applicant or employee is interacting with the technology, and must give written pre-decision notice covering the fact of deployment, the purpose and the nature of the decision, the tool's trade name, the categories of personal data analyzed and how they will be assessed, the data sources, and deployer contact information. Trade secrets may be withheld, but the withholding itself must be disclosed with its basis.

AI is not a defense to a discrimination complaint

Effective October 1, 2026, PA 26-15 amends Connecticut's employment discrimination statutes so that the use of an automated employment-related decision technology is not a defense against a discrimination complaint. The same amendment lets the commission or a court consider evidence of anti-bias testing and similar proactive efforts — specifically their quality, efficacy, recency, and scope, the results, and the response to those results. This provision is not delayed to 2027. It reaches Connecticut employers a full year before the notice duties do, and it converts bias testing from a governance nicety into admissible evidence.

Generative AI provenance data

From October 1, 2026, a "covered provider" — anyone who creates, codes, or produces a publicly accessible generative AI system with more than one million users per month — must, to the extent commercially and technically reasonable, embed provenance data in audio, image, and video content created or materially altered by that system, and must use commercially and technically reasonable methods to make it difficult to tamper with, remove, or disassociate. The act names the Coalition for Content Provenance and Authenticity standard as a relevant method. Providers are not required to include information identifying individuals, and need not disclose trade secrets or proprietary design information.

Frontier developers: whistleblower protection with a stated penalty

From October 1, 2026, a "frontier developer" is any person doing business in Connecticut who trains, initiates training of, or intends to train a foundation model using more than 10^26 integer or floating-point operations, counting original training plus any fine-tuning, reinforcement learning, or other material modification. A "large frontier developer" is one whose controlled group had annual gross revenues above $500 million in the most recent completed calendar year. Frontier developers may not adopt rules, policies, or contracts that suppress covered employees from reporting catastrophic risk, and must give covered employees clear notice of their rights by workplace posting or annual written notice. Large frontier developers must stand up an anonymous internal reporting process by January 1, 2027, with quarterly reporting to directors.

AI companions

From January 1, 2027, operators of AI companion systems must run protocols to detect and respond to suicidal ideation and self-harm, disclose non-human status on a recurring basis, provide parental controls over screen time and privacy, and refrain from engagement-maximizing and manipulative design aimed at minors. Enforcement is Attorney General only, with no private right of action.

AI-attributed layoffs and state procurement

From October 1, 2026, every employer serving a federal WARN Act notice on the Connecticut Labor Department must also disclose whether the layoffs relate to the employer's use of artificial intelligence or another technological change. Also from October 1, 2026, state agencies face restrictions on procuring and deploying AI technology. The act separately directs Charter Oak State College to establish a Connecticut AI Academy by December 31, 2026, and directs the Commissioner of Economic and Community Development to study an AI regulatory sandbox, with recommendations due later.

CTDPA profiling and automated decisions — already in force

Public Act 25-113 (SB 1295, signed June 24, 2025) rewrote the Connecticut Data Privacy Act effective July 1, 2026, and this operates independently of PA 26-15. The word "solely" was struck from the profiling opt-out: consumers may now opt out of profiling in furtherance of any automated decision producing a legal or similarly significant effect, not just fully automated ones. Where such profiling occurred, consumers may question the result, be informed of the reason it produced that decision, and review the personal data processed — and in housing decisions, correct inaccurate data and have the decision reevaluated. Controllers engaged in such profiling must conduct a profiling impact assessment covering purpose and deployment context, heightened risk of harm and mitigations, input and output categories, customization data, performance metrics and known limitations, transparency measures, and post-deployment monitoring. That assessment duty applies to activities created or generated on or after August 1, 2026.

CTDPA scope widened at the same time

From July 1, 2026 the CTDPA applicability threshold dropped from 100,000 consumers to 35,000, and now also catches any business that controls or processes sensitive data at all, or that offers personal data for sale. The entity-level exemption for Gramm-Leach-Bliley financial institutions was removed and replaced with a narrower structure: a data-level exemption for GLBA Title V data, plus entity exemptions for banks, credit unions, insurers, and registered broker-dealers and investment advisers meeting stated conditions. Non-depository financial firms that relied on the old entity-level GLBA exemption are now in scope for everything the GLBA data exemption does not cover. The HIPAA covered-entity and business-associate entity-level exemption was retained.

Minors and covered platforms — the one place private plaintiffs get in

From January 1, 2028, covered platforms must apply age assurance, obtain parental consent before personalized recommender access for minors, default recommender use to one hour per day, restrict contact from unconnected users and access to sensitive content, and file annual disclosures with the Attorney General. Unlike the AI sections, this section is made a CUTPA violation without the carve-out of Conn. Gen. Stat. § 42-110g, which leaves CUTPA's private action available to plaintiffs.

Bills & Statutes

SB 5 (2026) / Public Act 26-15

An Act Concerning Online Safety — Connecticut's omnibus AI statute

Signed by the Governor May 27, 2026 (publicly announced June 2, 2026); phases in October 1, 2026 through January 1, 2028

Read the primary source(opens in a new tab)
SB 2 (2025)

An Act Concerning Artificial Intelligence — the bill that did not pass

Passed the Senate May 14, 2025; last action House Calendar Number 599 on May 16, 2025; died without a House vote. Not law

Read the primary source(opens in a new tab)
SB 1295 (2025) / Public Act 25-113

Amendments to the Connecticut Data Privacy Act — profiling, automated decisions, scope

Signed June 24, 2025; CTDPA amendments effective July 1, 2026; profiling impact assessments for activities on or after August 1, 2026

Read the primary source(opens in a new tab)
SB 6 (2022) / Public Act 22-15

Connecticut Data Privacy Act, Conn. Gen. Stat. §§ 42-515 et seq. — the underlying statute

Signed May 10, 2022; effective July 1, 2023; mandatory 60-day cure period expired December 31, 2024

Read the primary source(opens in a new tab)

Applicability & Enforcement

Who It Applies To

Component by component. Employment AI duties reach developers and deployers doing business in Connecticut whose technology is a substantial factor in employment decisions about people in the state, for technology deployed on or after October 1, 2027 — with no HIPAA, financial services, or small-business carve-out. Provenance duties reach generative AI providers with more than one million monthly users. Frontier-developer duties reach anyone training a foundation model above 10^26 operations. The amended CTDPA reaches any business that controls or processes the personal data of 35,000 or more Connecticut consumers, or controls or processes sensitive data, or sells personal data — with entity-level exemptions retained for HIPAA covered entities and business associates, nonprofits, higher education institutions, banks and credit unions meeting stated conditions, insurers, and registered broker-dealers and investment advisers.

Enforcement

The Connecticut Attorney General, exclusively, for every AI provision. Violations of the AEDT, provenance, and AI companion sections are unfair or deceptive trade practices under Conn. Gen. Stat. § 42-110b(a), and each of those sections expressly disapplies § 42-110g — there is no private right of action. For AEDT violations occurring on or before December 31, 2027, the Attorney General may, at his discretion, issue a notice of violation and allow 60 days to cure before suing. The frontier-developer whistleblower provisions are enforced by direct civil action in the Superior Court for the judicial district of Hartford. The covered-platform provisions taking effect January 1, 2028 are the exception: they are a CUTPA violation with no § 42-110g carve-out, so private plaintiffs can sue. The CTDPA is likewise enforced solely by the Attorney General as a CUTPA violation; its mandatory 60-day cure period expired December 31, 2024 and cure is now discretionary.

Penalties

PA 26-15 sets one specific figure: up to $1,000 per violation for frontier-developer whistleblower violations, plus injunctive or equitable relief that is not stayed pending appeal, and — where the state prevails — investigation costs, expert witness fees, costs of the action, and reasonable attorney's fees. The act sets no dollar figures for the AEDT, provenance, companion, or covered-platform provisions. Those route into CUTPA, where the Attorney General can seek injunctive relief, restitution, disgorgement, and civil penalties of up to $5,000 for each wilful violation under Conn. Gen. Stat. § 42-110o. CTDPA violations carry the same CUTPA exposure. Treat any published "Connecticut AI penalty" figure beyond the $1,000 whistleblower number as a CUTPA estimate, not a number the AI statute states.

Recommended Compliance Actions

Steps organizations should consider to prepare for and comply with Connecticut's AI regulations.

  1. 1

    Replace every reference to Connecticut SB 2 in your compliance materials with Public Act 26-15. A tracker pointing at a bill that died in May 2025 is a visible credibility problem in front of a regulator or an auditor.

  2. 2

    Run the CTDPA scope test again under the July 1, 2026 thresholds: 35,000 consumers, any sensitive data processing, or any sale of personal data. If you concluded you were exempt as a GLBA financial institution, that entity-level exemption no longer exists.

  3. 3

    Stand up the CTDPA profiling impact assessment now if you profile Connecticut consumers in furtherance of decisions with legal or similarly significant effect. The duty attaches to activities created or generated on or after August 1, 2026, and the assessment must be produced to the Attorney General on request.

  4. 4

    Build the profiling response workflow the amended CTDPA requires: honor opt-outs where a human is in the loop, state the reason a profiling decision came out as it did, let consumers review the data used, and for housing decisions allow correction and reevaluation.

  5. 5

    Inventory every tool that scores, ranks, or classifies applicants or employees and determine whether it meaningfully alters an outcome. That is the substantial-factor test, and it is the scoping question for October 1, 2027.

  6. 6

    Start anti-bias testing on employment AI before October 1, 2026 and document quality, scope, recency, results, and your response to the results. From that date the tool is no defense to a discrimination complaint and this testing is what a commission or court is permitted to weigh.

  7. 7

    Negotiate the developer-deployer allocation in writing. Section 8 lets a developer contractually assume the deployer's disclosure and notice duties, but only if the contract clearly states which duties are assumed. Raise it at renewal, not in 2027.

  8. 8

    If you file WARN notices in Connecticut, add the AI-attribution disclosure to your Labor Department process for notices served on or after October 1, 2026.

  9. 9

    If you operate a companion chatbot or a generative AI service above one million monthly users, treat January 1, 2027 and October 1, 2026 respectively as hard dates and read the operative sections directly — the summaries circulating online disagree with the enrolled text on which duties fall in which year.

As of August 2, 2026. We are not lawyers and this is not legal advice. It is the responsibility of consumers of this data that they verify the applicability and current ratified statutes and legal precedence with a qualified attorney licensed in the state or country they are researching.

Need Help with AI Compliance?

Our team helps organizations build compliance-first AI systems that meet current and emerging regulatory requirements.