Connecticut AI Responsibility Act (PA 26-15)

Jurisdiction:
Connecticut
phased enforcement
Effective:
Oct 1, 2026
Full enforcement:
Jan 1, 2028
Authority:
Connecticut Attorney General
Official text

Obligations Covered

Incident Reporting Transparency & Disclosure Explainability Bias & Discrimination Prevention Risk Assessment

Timeline

MilestoneDateNotes
Signed by the GovernorMay 27, 2026Public Act 26-15, 74 pages, 39 sections
Subscription disclosure, frontier developer duties, provenance, employment discriminationOct 1, 2026Sections 1, 2, 7-15 take effect
Large frontier developer internal reporting process dueJan 1, 2027Section 2(c)(1)
AI companion dutiesJan 1, 2027Sections 4-6
Employment decision technology duties biteOct 1, 2027Sections 8-10 apply to technologies deployed on or after this date
Covered platform duties for minorsJan 1, 2028Section 39

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Frontier Developer Catastrophic Risk Reporting

Copy link to this provision

Obligation:
Incident Reporting
enacted
Effective:
Oct 1, 2026
Risk tier:
general-purpose
Scope:
Persons doing business in Connecticut who intend to train, initiate training, or train a foundation model using or intending to use more than 10^26 integer or floating-point operations, including original training and subsequent fine-tuning, reinforcement learning, or other material modifications. The internal-process duty applies to large frontier developers whose prior-calendar-year annual gross revenues exceed $500 million together with controlling, controlled, and commonly controlled persons (§ 2(a)(8)-(9))
high-impactupcoming
Section 2 takes effect on 2026-10-01, including the anti-retaliation rules and notice duties for frontier developers. Large frontier developers must establish the internal anonymous reporting process no later than 2027-01-01. Reports and investigation updates go to officers and directors at least quarterly, except that an accused officer or director must not receive the report or its updates. Section 2(c) requires an internal channel and board sharing; it does not require submitting these reports to the state. Catastrophic risk requires a foreseeable and material risk that a frontier model's development, storage, use, or deployment materially contributes to the death of, or serious injury to, more than fifty individuals, or more than $1 billion in damage to or loss of covered property, arising from a single incident. The incident must involve expert-level assistance creating or releasing a chemical, biological, radiological, or nuclear weapon, or conduct without meaningful human oversight, intervention, or supervision that constitutes a cyberattack or would constitute murder, assault, extortion, or theft if performed by an individual. Covered property includes tangible and intangible property but excludes equity (§ 2(a)(1), (3)). The definition excludes risks from otherwise publicly accessible, substantially similar information; lawful federal-government activity; and combinations of a foundation model with other software where the model does not materially increase the risk (§ 2(a)(1)(B)). A covered employee is an employee responsible for assessing, managing, or addressing the specified model-weight security, catastrophic-risk, loss-of-control, or deceptive-technique risks (§ 2(a)(2)); the section does not treat every employee as a covered employee.

Requirements

RequirementDetails
Anti-retaliation rulesA frontier developer may not make, adopt, enforce, or enter into any rule, regulation, policy, or contract allowing it to discharge, discipline, or otherwise penalize any employee for activity protected by Conn. Gen. Stat. § 31-51m(b). It also may not authorize any person with authority over a covered employee, or another covered employee with investigative or corrective authority, to discipline or retaliate against that employee for reporting, on reasonable cause, activity posing the specified catastrophic-risk danger (§ 2(b)(1)-(2))
Anonymous internal channelBy 2027-01-01, each large frontier developer must establish and maintain a reasonable internal process for a covered employee to anonymously report information believed in good faith to indicate activity posing a specific and substantial danger to public health or safety due to catastrophic risk (§ 2(c)(1)(A))
Investigation updatesThe developer must give reasonable updates to each reporting employee on the status of the resulting investigation and the actions taken (§ 2(c)(1)(B))
Quarterly board sharingReports and updates must be shared with the officers and directors at least quarterly (§ 2(c)(2)(A))
Accused-officer carve-outWhere a report alleges wrongdoing by an officer or director, neither the report nor its updates may be shared with that person (§ 2(c)(2)(B))
Notice of rightsEach frontier developer must give covered employees clear notice of their rights and responsibilities, either through continuous workplace posting plus equivalent notices to new hires and periodic notices to remote workers, or through at least annual written notice received and acknowledged by each covered employee (§ 2(d)(1)-(2))

Penalties

ViolationFine
Per violationCivil penalty not exceeding $1,000 per violation, recoverable by the Attorney General in Hartford superior court, plus injunctive or equitable relief that is not stayed pending appeal. A prevailing state may recover investigation costs, expert witness fees, action costs, and reasonable attorneys' fees; remedies and penalties are cumulative (§ 2(e))

Generative AI Content Provenance

Copy link to this provision

Obligation:
Transparency
enacted
Effective:
Oct 1, 2026
Risk tier:
general-purpose
Scope:
Covered providers — any person who creates, codes, or otherwise produces a generative AI system with more than one million users per month that is publicly accessible to consumers for personal use; federal, state, and local government agencies are excluded (§ 15(a)(2))
high-impact
The first US statute in this reference to name the Coalition for Content Provenance and Authenticity standard in its own text rather than gesturing at "widely accepted industry standards" as California's SB 942 does. The one-million-users-per-month threshold parallels California's covered-provider test, so a provider building C2PA provenance for California largely satisfies Connecticut — the same convergence the EU Article 50 and California alignment produced.

Requirements

RequirementDetails
Embed provenance dataTo the extent commercially and technically reasonable, include provenance data in any audio, image, or video content created or materially altered by the provider's generative AI system, in a manner letting a consumer assess whether the content was so created or altered (§ 15(b)(1)(A))
Tamper resistanceUse commercially and technically reasonable methods, including the relevant C2PA standard, to make that provenance data difficult to tamper with, remove, or disassociate from the content (§ 15(b)(1)(B))
No personal data requiredThe duty does not require including information relating to an identified or reasonably identifiable individual in the provenance data (§ 15(b)(2)(A)(i))
Trade secret carve-outThe duty does not require disclosure of trade secrets or information otherwise protected from disclosure under state or federal law (§ 15(b)(2)(A)(ii))
Materiality floor"Materially alter" excludes minor modifications that do not significantly change perceived content or meaning — brightness, contrast, colour, sharpening, saturation, filters, resizing, scaling, cropping, format conversion, resampling, denoising, and background-noise removal (§ 15(a)(4))

Penalties

ViolationFine
Unfair trade practiceA violation is an unfair or deceptive trade practice under Conn. Gen. Stat. § 42-110b(a), enforced solely by the Attorney General (§ 15)

Automated Employment Decision Technology Disclosure

Copy link to this provision

Obligation:
Transparency
enacted
Effective:
Oct 1, 2027
Risk tier:
high-risk
Scope:
Developers and deployers of automated employment-related decision technology deployed in Connecticut on or after 2027-10-01. The technology is defined as any technology that processes personal data and uses computation to generate an output — prediction, recommendation, classification, ranking, or score — used in employment-related decisions (§ 7)
high-impactupcoming
Two dates matter and they are a year apart: the sections take effect 2026-10-01, but the duties attach only to technology deployed on or after 2027-10-01, which is the date recorded here. The developer-to-deployer information duty in § 8 is the structural piece — it makes the vendor responsible for supplying whatever the employer needs to meet its own disclosure duties, closing the "our vendor won't tell us" gap that undercuts comparable laws.

Requirements

RequirementDetails
Developer information dutyThe developer must provide the deployer all information the deployer requires to perform its duties under §§ 9 and 10 (§ 8(a))
Interaction disclosureA deployer must ensure each employee or applicant who interacts with the technology is told, in plain language, that they are interacting with it (§ 9(a))
Pre-decision written noticeBefore an employment-related decision is made using the technology as a substantial factor, the deployer must give the employee or applicant written notice disclosing the deployment, the purpose of the technology and the nature of the decision, the trade name of the technology, the categories of personal data it will analyse and how they will be assessed, the sources of that data, and deployer contact information (§ 10)
Trade secret withholding noticeWhere information is withheld as a trade secret or otherwise protected, the withholding person must notify the person from whom it is withheld, stating that information is being withheld and the basis (§ 11)

Penalties

ViolationFine
Unfair trade practiceAny violation of §§ 8-11 is an unfair or deceptive trade practice under Conn. Gen. Stat. § 42-110b(a), enforced solely by the Attorney General (§ 12)

AI as No Defense to Employment Discrimination

Copy link to this provision

Obligation:
Bias Prevention
enforcing
Effective:
Oct 1, 2026
Risk tier:
high-risk
Scope:
Employers and their agents subject to Conn. Gen. Stat. § 46a-60
high-impactcross-domain
Not a disclosure rule but a liability rule, and it is the sharpest incentive in the Act: using an automated employment-related decision technology is expressly not a defense to a discrimination complaint, while evidence of anti-bias testing may be considered in the employer's favour. That asymmetry converts bias testing from a good practice into the only available mitigation, which is why it belongs under bias-prevention rather than with the disclosure provisions.

Requirements

RequirementDetails
No automation defenseThe use of an automated employment-related decision technology, as defined in § 7, is not a defense against a complaint alleging a discriminatory practice under Conn. Gen. Stat. § 46a-60(b)(1) (§ 13)
Anti-bias testing as evidenceThe commission or a court may consider evidence of anti-bias testing or similar proactive efforts to avoid the discriminatory practice, including the quality, efficacy, recency, and scope of the testing, its results, and the response to those results (§ 13)

Penalties

ViolationFine
Discriminatory practiceStandard remedies for a discriminatory practice under Conn. Gen. Stat. ch. 814c, before the Commission on Human Rights and Opportunities or a court

AI Companion Crisis Protocol

Copy link to this provision

Obligation:
Risk Assessment
enacted
Effective:
Jan 1, 2027
Risk tier:
limited-risk
Scope:
Operators providing or operating an artificial intelligence companion for a user in Connecticut, with heightened duties where the operator knows or has reason to believe the user is under eighteen (§§ 4, 6(a)(1))
high-impactupcoming
Connecticut's version goes further than California's or New York's in two ways: it requires escalation to clinically appropriate services when a user expresses risk *again after* an initial referral, and it separately requires measures preventing the companion from claiming to be human or generating output that contradicts its own AI disclosure. The second duty closes the gap a disclosure-only rule leaves open — a system that discloses at the top of a session and then insists it is human when asked.

Requirements

RequirementDetails
Protocol as a preconditionNo operator may provide or operate an AI companion unless it includes a protocol meeting the statutory minimum (§ 5(a)(1)(A))
Evidence-based detectionThe protocol must use evidence-based methods to detect user expressions clearly indicating a risk of suicide, self-harm, or imminent physical violence, and to institute measures preventing output that encourages them (§ 5(a)(1)(A)(i))
Crisis referralOn detection, refer the user to appropriate mental health evaluation and treatment resources, including the 9-8-8 National Suicide Prevention Lifeline (§ 5(a)(1)(A)(ii))
Escalation on repeat detectionIf a further such expression is detected after a referral, refer the user to mental health services consistent with clinical best practices and expertise (§ 5(a)(1)(A)(iii))
No claiming humanityImplement reasonable measures preventing the companion from claiming to be a human being, including when asked directly, and from generating output that refutes or conflicts with the disclosure that it is not human (§ 5(a)(1)(B))
Publish the protocolPost the protocol in a prominent, publicly accessible location on the operator's website (§ 5(a)(2))
Minor safeguardsWhere the operator knows or has reason to believe the user is under eighteen, institute measures meeting or exceeding industry standards to prevent the specified categories of output (§ 6(a)(1))

Penalties

ViolationFine
Unfair trade practiceEnforced through the Connecticut Unfair Trade Practices Act, Conn. Gen. Stat. § 42-110b(a)

AI Companion and Subscription Disclosure

Copy link to this provision

Obligation:
Transparency
enacted
Effective:
Oct 1, 2026
Risk tier:
limited-risk
Scope:
Subscription-based providers of AI technology contracting with Connecticut consumers (§ 1), and operators of AI companions whose product would cause a reasonable user to believe they are interacting with a human (§ 5(b))
high-impact
Two distinct disclosure regimes ride in one act. The § 1 subscription rules attach at contract formation and renewal, which puts AI-specific terms into consumer contract law rather than product design. The § 5(b) companion notice takes effect later, on 2027-01-01, and offers operators a choice between a persistent static notice visible throughout the interaction and a notice repeated at intervals — the persistent option has no counterpart in the California or New York statutes. A second, separately enacted subscription regime starts the same day: Public Act 26-100 § 46 (Substitute HB 5222, signed 2026-06-02) requires subscription-based providers of generative AI systems with more than one million monthly users to disclose usage limits (tokens, images, transcription) and any discretion to reduce functionality, with renewal re-disclosure, enforced by the Attorney General under CUTPA. PA 26-100 does not repeal or amend § 1; the two sections differ in covered actors and required content and both apply from 2026-10-01. A model-generated claim that PA 26-100 replaced § 1 was checked against the retained PA 26-100 text and is not supported.

Requirements

RequirementDetails
Subscription contract disclosureNo subscription-based provider may enter into or renew a subscription contract with a consumer unless the disclosure set out in the section is made, setting forth at minimum the information required to purchase or maintain the subscription (§ 1(b))
Companion noticeWhere an AI companion would cause a reasonable individual to believe they are interacting with a human, the operator must provide clear and conspicuous notice that the user is communicating with an AI companion (§ 5(b))
Notice formThe notice must be given either in static written form visible throughout the entire interaction, or in audible or written form at the beginning of the first interaction and at intervals thereafter (§ 5(b)(1)-(2))

Penalties

ViolationFine
Unfair trade practiceA violation of § 1(b) is an unfair or deceptive trade practice under Conn. Gen. Stat. § 42-110b(a); the private right of action in § 42-110g does not apply and the section provides no basis for a private claim (§ 1(c))
Cite this regulation

Permalink: https://everyailaw.com/regulation/connecticut-pa26-15/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Connecticut AI Responsibility Act (PA 26-15)”, EveryAILaw.com, Aug 2, 2026. https://everyailaw.com/regulation/connecticut-pa26-15/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.