Connecticut AI Responsibility Act (PA 26-15)

Jurisdiction:
Connecticut
phased enforcement
Effective:
Oct 1, 2026
Full enforcement:
Jan 1, 2028
Authority:
Connecticut Attorney General
Official text

Obligations Covered

Incident Reporting Transparency & Disclosure Explainability Bias & Discrimination Prevention Risk Assessment

Timeline

MilestoneDateNotes
Signed by the GovernorMay 27, 2026Public Act 26-15, 74 pages, 39 sections
Subscription disclosure, frontier developer duties, provenance, employment discriminationOct 1, 2026Sections 1, 2, 7-15 take effect
Large frontier developer internal reporting process dueJan 1, 2027Section 2(c)(1)
AI companion dutiesJan 1, 2027Sections 4-6
Employment decision technology duties biteOct 1, 2027Sections 8-10 apply to technologies deployed on or after this date
Covered platform duties for minorsJan 1, 2028Section 39

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Frontier Developer Catastrophic Risk Reporting #

Obligation:
Incident Reporting
enacted
Effective:
Jan 1, 2027
Risk tier:
general-purpose
Scope:
Frontier developers, with the internal-process duty falling on large frontier developers. "Catastrophic risk" is defined as a foreseeable and material risk that development, storage, use, or deployment of a frontier model materially contributes to the death of or serious injury to more than fifty individuals, or more than one billion dollars in damage to covered property or loss (§ 2(a))
high-impactupcoming
The duty is an internal whistleblower channel rather than a report to the state — Connecticut regulates the flow of catastrophic-risk information inside the company and to its board, not to a regulator. The quarterly board-sharing requirement, with the carve-out preventing a report from reaching an officer it accuses, is the operative design: it makes suppression at the management layer a statutory violation.

Requirements

RequirementDetails
No suppressive agreementsA frontier developer may not make, adopt, enforce, or enter into any agreement barring a covered employee from the protected disclosure activity described in the section (§ 2(b))
Anonymous internal channelBy 2027-01-01, each large frontier developer must establish and maintain a reasonable internal process for a covered employee to anonymously report information believed in good faith to indicate activity posing a specific and substantial danger to public health or safety due to catastrophic risk (§ 2(c)(1)(A))
Investigation updatesThe developer must give reasonable updates to each reporting employee on the status of the resulting investigation and the actions taken (§ 2(c)(1)(B))
Quarterly board sharingReports and updates must be shared with the officers and directors at least quarterly (§ 2(c)(2)(A))
Accused-officer carve-outWhere a report alleges wrongdoing by an officer or director, neither the report nor its updates may be shared with that person (§ 2(c)(2)(B))
Notice of rightsEach frontier developer must give all covered employees clear notice of their rights and responsibilities under the section (§ 2(d))

Penalties

ViolationFine
Per violationCivil penalty not exceeding $1,000 per violation, recoverable by the Attorney General in Hartford superior court, plus injunctive or equitable relief that is not stayed pending appeal (§ 2(e))

Generative AI Content Provenance #

Obligation:
Transparency
enacted
Effective:
Oct 1, 2026
Risk tier:
general-purpose
Scope:
Covered providers — any person who creates, codes, or otherwise produces a generative AI system with more than one million users per month that is publicly accessible to consumers for personal use; federal, state, and local government agencies are excluded (§ 15(a)(2))
high-impact
The first US statute in this reference to name the Coalition for Content Provenance and Authenticity standard in its own text rather than gesturing at "widely accepted industry standards" as California's SB 942 does. The one-million-users-per-month threshold parallels California's covered-provider test, so a provider building C2PA provenance for California largely satisfies Connecticut — the same convergence the EU Article 50 and California alignment produced.

Requirements

RequirementDetails
Embed provenance dataTo the extent commercially and technically reasonable, include provenance data in any audio, image, or video content created or materially altered by the provider's generative AI system, in a manner letting a consumer assess whether the content was so created or altered (§ 15(b)(1)(A))
Tamper resistanceUse commercially and technically reasonable methods, including the relevant C2PA standard, to make that provenance data difficult to tamper with, remove, or disassociate from the content (§ 15(b)(1)(B))
No personal data requiredThe duty does not require including information relating to an identified or reasonably identifiable individual in the provenance data (§ 15(b)(2)(A)(i))
Trade secret carve-outThe duty does not require disclosure of trade secrets or information otherwise protected from disclosure under state or federal law (§ 15(b)(2)(A)(ii))
Materiality floor"Materially alter" excludes minor modifications that do not significantly change perceived content or meaning — brightness, contrast, colour, sharpening, saturation, filters, resizing, scaling, cropping, format conversion, resampling, denoising, and background-noise removal (§ 15(a)(4))

Penalties

ViolationFine
Unfair trade practiceA violation is an unfair or deceptive trade practice under Conn. Gen. Stat. § 42-110b(a), enforced solely by the Attorney General (§ 15)

Automated Employment Decision Technology Disclosure #

Obligation:
Transparency
enacted
Effective:
Oct 1, 2027
Risk tier:
high-risk
Scope:
Developers and deployers of automated employment-related decision technology deployed in Connecticut on or after 2027-10-01. The technology is defined as any technology that processes personal data and uses computation to generate an output — prediction, recommendation, classification, ranking, or score — used in employment-related decisions (§ 7)
high-impactupcoming
Two dates matter and they are a year apart: the sections take effect 2026-10-01, but the duties attach only to technology deployed on or after 2027-10-01, which is the date recorded here. The developer-to-deployer information duty in § 8 is the structural piece — it makes the vendor responsible for supplying whatever the employer needs to meet its own disclosure duties, closing the "our vendor won't tell us" gap that undercuts comparable laws.

Requirements

RequirementDetails
Developer information dutyThe developer must provide the deployer all information the deployer requires to perform its duties under §§ 9 and 10 (§ 8(a))
Interaction disclosureA deployer must ensure each employee or applicant who interacts with the technology is told, in plain language, that they are interacting with it (§ 9(a))
Pre-decision written noticeBefore an employment-related decision is made using the technology as a substantial factor, the deployer must give the employee or applicant written notice disclosing the deployment, the purpose of the technology and the nature of the decision, the trade name of the technology, the categories of personal data it will analyse and how they will be assessed, the sources of that data, and deployer contact information (§ 10)
Trade secret withholding noticeWhere information is withheld as a trade secret or otherwise protected, the withholding person must notify the person from whom it is withheld, stating that information is being withheld and the basis (§ 11)

Penalties

ViolationFine
Unfair trade practiceAny violation of §§ 8-11 is an unfair or deceptive trade practice under Conn. Gen. Stat. § 42-110b(a), enforced solely by the Attorney General (§ 12)

AI as No Defense to Employment Discrimination #

Obligation:
Bias Prevention
enforcing
Effective:
Oct 1, 2026
Risk tier:
high-risk
Scope:
Employers and their agents subject to Conn. Gen. Stat. § 46a-60
high-impactcross-domain
Not a disclosure rule but a liability rule, and it is the sharpest incentive in the Act: using an automated employment-related decision technology is expressly not a defense to a discrimination complaint, while evidence of anti-bias testing may be considered in the employer's favour. That asymmetry converts bias testing from a good practice into the only available mitigation, which is why it belongs under bias-prevention rather than with the disclosure provisions.

Requirements

RequirementDetails
No automation defenseThe use of an automated employment-related decision technology, as defined in § 7, is not a defense against a complaint alleging a discriminatory practice under Conn. Gen. Stat. § 46a-60(b)(1) (§ 13)
Anti-bias testing as evidenceThe commission or a court may consider evidence of anti-bias testing or similar proactive efforts to avoid the discriminatory practice, including the quality, efficacy, recency, and scope of the testing, its results, and the response to those results (§ 13)

Penalties

ViolationFine
Discriminatory practiceStandard remedies for a discriminatory practice under Conn. Gen. Stat. ch. 814c, before the Commission on Human Rights and Opportunities or a court

AI Companion Crisis Protocol #

Obligation:
Risk Assessment
enacted
Effective:
Jan 1, 2027
Risk tier:
limited-risk
Scope:
Operators providing or operating an artificial intelligence companion for a user in Connecticut, with heightened duties where the operator knows or has reason to believe the user is under eighteen (§§ 4, 6(a)(1))
high-impactupcoming
Connecticut's version goes further than California's or New York's in two ways: it requires escalation to clinically appropriate services when a user expresses risk *again after* an initial referral, and it separately requires measures preventing the companion from claiming to be human or generating output that contradicts its own AI disclosure. The second duty closes the gap a disclosure-only rule leaves open — a system that discloses at the top of a session and then insists it is human when asked.

Requirements

RequirementDetails
Protocol as a preconditionNo operator may provide or operate an AI companion unless it includes a protocol meeting the statutory minimum (§ 5(a)(1)(A))
Evidence-based detectionThe protocol must use evidence-based methods to detect user expressions clearly indicating a risk of suicide, self-harm, or imminent physical violence, and to institute measures preventing output that encourages them (§ 5(a)(1)(A)(i))
Crisis referralOn detection, refer the user to appropriate mental health evaluation and treatment resources, including the 9-8-8 National Suicide Prevention Lifeline (§ 5(a)(1)(A)(ii))
Escalation on repeat detectionIf a further such expression is detected after a referral, refer the user to mental health services consistent with clinical best practices and expertise (§ 5(a)(1)(A)(iii))
No claiming humanityImplement reasonable measures preventing the companion from claiming to be a human being, including when asked directly, and from generating output that refutes or conflicts with the disclosure that it is not human (§ 5(a)(1)(B))
Publish the protocolPost the protocol in a prominent, publicly accessible location on the operator's website (§ 5(a)(2))
Minor safeguardsWhere the operator knows or has reason to believe the user is under eighteen, institute measures meeting or exceeding industry standards to prevent the specified categories of output (§ 6(a)(1))

Penalties

ViolationFine
Unfair trade practiceEnforced through the Connecticut Unfair Trade Practices Act, Conn. Gen. Stat. § 42-110b(a)

AI Companion and Subscription Disclosure #

Obligation:
Transparency
enacted
Effective:
Oct 1, 2026
Risk tier:
limited-risk
Scope:
Subscription-based providers of AI technology contracting with Connecticut consumers (§ 1), and operators of AI companions whose product would cause a reasonable user to believe they are interacting with a human (§ 5(b))
high-impact
Two distinct disclosure regimes ride in one act. The § 1 subscription rules attach at contract formation and renewal, which puts AI-specific terms into consumer contract law rather than product design. The § 5(b) companion notice takes effect later, on 2027-01-01, and offers operators a choice between a persistent static notice visible throughout the interaction and a notice repeated at intervals — the persistent option has no counterpart in the California or New York statutes.

Requirements

RequirementDetails
Subscription contract disclosureNo subscription-based provider may enter into or renew a subscription contract with a consumer unless the disclosure set out in the section is made, setting forth at minimum the information required to purchase or maintain the subscription (§ 1(b))
Companion noticeWhere an AI companion would cause a reasonable individual to believe they are interacting with a human, the operator must provide clear and conspicuous notice that the user is communicating with an AI companion (§ 5(b))
Notice formThe notice must be given either in static written form visible throughout the entire interaction, or in audible or written form at the beginning of the first interaction and at intervals thereafter (§ 5(b)(1)-(2))

Penalties

ViolationFine
Unfair trade practiceA violation of § 1(b) is an unfair or deceptive trade practice under Conn. Gen. Stat. § 42-110b(a); the private right of action in § 42-110g does not apply and the section provides no basis for a private claim (§ 1(c))
Cite this regulation

Permalink: https://everyailaw.com/regulation/connecticut-pa26-15/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Connecticut AI Responsibility Act (PA 26-15)”, EveryAILaw.com, Aug 2, 2026. https://everyailaw.com/regulation/connecticut-pa26-15/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.