Connecticut AI Responsibility Act: What Starts October 1

Sections 1, 2, and 7 Through 15 of Public Act 26-15 Take Effect October 1, 2026

by Sam Rogers
11 min read
guide
governance
policy
regulated-industries
legal
Connecticut AI Responsibility Act: What Starts October 1

This article is for educational purposes and does not constitute legal advice. Organizations subject to Connecticut Public Act 26-15 should consult qualified counsel about their specific obligations.

On October 1, Connecticut takes the tool away as a defense and leaves the person who used it holding the decision.

What's Live on October 1

Connecticut's Public Act 26-15 is Substitute Senate Bill 5, titled An Act Concerning Online Safety, 74 pages and 39 sections. EveryAILaw tracks it as the Connecticut AI Responsibility Act and records the Governor's signature on May 27, 2026, the same date the General Assembly's bill history shows. Its first operative date is October 1, 2026. This is a guide to the statute text.

Section 1, subscription disclosure. A subscription-based provider of an artificial intelligence technology may not enter into or renew a subscription with a Connecticut consumer, or collect a fee for one, unless it has given written notice of the key terms and the consumer has accepted them in writing. The notice must cover any quantitative or qualitative limits the provider may impose, including limits triggered by the consumer's own conduct, and whether the provider has discretion to reduce or eliminate functionality. Violations are unfair or deceptive trade practices, enforced solely by the Attorney General, with no private right of action.

Section 2, frontier developer whistleblowing. A frontier developer is anyone doing business in the state who trains, initiates training of, or intends to train a foundation model using more than ten to the twenty-sixth power integer or floating-point operations, counting fine-tuning and other material modifications. From October 1 no frontier developer may adopt a rule, policy or contract that penalizes a covered employee for reporting a specific and substantial danger to public health or safety arising from a catastrophic risk.

The casualty threshold is the part that travels, so it's worth stating the whole definition. A catastrophic risk is a foreseeable and material risk of more than fifty deaths or serious injuries, or more than one billion dollars in damage to or loss of covered property, from a single incident, and the incident has to be of a particular kind: expert-level assistance in creating or releasing a chemical, biological, radiological or nuclear weapon, or conduct occurring without meaningful human oversight that constitutes a cyberattack or would be murder, assault, extortion or theft if a person did it. Risks traceable to information already publicly available, lawful federal activity, and model-plus-software combinations where the model doesn't materially increase the risk are all carved out. Read only the casualty number and the section looks far broader than it is.

"Covered employee" is narrow too. It means someone responsible for assessing, managing or addressing the model-weight security, catastrophic-risk, loss-of-control or deceptive-technique risks the section lists, not everyone on the payroll. Those employees get notice of their rights through continuous workplace posting plus equivalent notice to new hires. The civil penalty is up to one thousand dollars per violation, recoverable by the Attorney General.

One thing does not start on October 1. The anonymous internal reporting channel, with its quarterly board sharing and the carve-out preventing a report reaching an officer it accuses, is due from large frontier developers by January 1, 2027. October brings the anti-retaliation rules and the notice duty; the machinery comes later.

Sections 7 through 12, automated employment-related decision technology. These take effect October 1, 2026, but the developer and deployer duties in sections 8 through 10 attach only to technology deployed on or after October 1, 2027. More on that split below.

Sections 13 and 14, no AI defense to discrimination. The act amends the state's employment discrimination statutes so that using an automated employment-related decision technology is not a defense against a complaint. The commission or court may consider evidence of anti-bias testing or similar proactive efforts, including the quality, efficacy, recency, and scope of the testing, its results, and the response to them.

Section 15, provenance. A covered provider, meaning anyone producing a generative AI system with more than one million users per month that's publicly accessible to consumers, must include provenance data in audio, image, or video content its system creates or materially alters, to the extent commercially and technically reasonable, and must use methods such as the Coalition for Content Provenance and Authenticity standard to make that data hard to remove. Business-to-business distribution is excluded.

Two more October 1 sections are easy to miss. Section 26 requires any employer filing a federal WARN notice to tell the Labor Department whether the layoffs relate to its use of artificial intelligence. Section 38 bars state agencies from using AI in functions that affect public benefits or materially affect rights, safety, or welfare unless the use complies with state policies and standards, and requires an impact assessment posted sixty days before deployment.

What Waits

The act phases in over fifteen months. The dates below come from the chaptered text and match the EveryAILaw milestone record.

DateSectionsWhat attaches
October 1, 20261, 2, 7-15Subscription disclosure, frontier whistleblower protections, AI is no defense to discrimination, provenance, employment-technology definitions
January 1, 20272(c)(1), 4-6Large frontier developers must operate an anonymous internal reporting process; AI companion crisis protocols and not-a-human disclosures
October 1, 20278-10Developer-to-deployer information, interaction disclosure, and pre-decision written notice apply to employment technology deployed on or after this date
January 1, 202839Covered platform duties toward users under eighteen

The 2027 companion sections are aimed at consumer products. Section 4 excludes chatbots used only for a business's operational purposes, customer service, technical assistance, or internal research that aren't marketed as companions, so most enterprise deployments fall outside them. Section 5(b) still tells us where the legislature's mind is: if a reasonable user would believe they're talking to a human, the operator must say otherwise, either in a static notice that stays visible throughout the interaction or in a notice repeated at set intervals.

Who Counts as a Deployer

Section 7 does the definitional work, and it's narrower than the word "AI" suggests. An automated employment-related decision technology is any technology that processes personal data and uses computation to produce a prediction, recommendation, classification, ranking, score, or other output that's a substantial factor in an employment-related decision. Spreadsheets, word processors, and similar tools are excluded unless they make or materially influence the decision, and so is purely descriptive or statistical information not relied on to decide.

An employment-related decision means hiring, promotion, discipline, discharge, renewal, selection for training or apprenticeship, or a change to tenure, terms, privileges, or conditions of employment. Nonmaterial changes to tasks, hours, or assignments are out, and so are decisions about workplace health and safety, scheduling, and productivity monitoring.

A deployer is a person doing business in the state who puts such a technology into use there. For technology deployed on or after October 1, 2027, the deployer must tell applicants and employees who interact with it so in plain language (section 9), and before any decision it must give the individual a written notice stating that the technology was deployed, its purpose and the nature of the decision, its trade name, the categories and sources of personal data it analyzes and how they'll be assessed, and the deployer's contact information (section 10). The developer must supply the deployer with everything it needs to meet those duties (section 8), and may contract to assume them. Trade secrets may be withheld, but the withholding itself must be disclosed with a reason (section 11). Enforcement is by the Attorney General alone, with a sixty-day cure window for curable violations through December 31, 2027 (section 12).

What the Statute Assumes About People

Read sections 13 and 14 slowly. They don't regulate the technology. They regulate the defense. After October 1, an employer answering a discrimination complaint can't point at the ranking tool. The complaint proceeds against the employer and the employer's agent, which in practice means the recruiter, the hiring manager, or the HR analyst who accepted the score.

What the tribunal may weigh instead is evidence of anti-bias testing and the response to it. Every element on that list is a human act. Someone chose the test and its scope, read the results, and decided what to do. Section 10 assumes a person can explain how the personal data will be assessed. Section 2 assumes a covered employee will recognize a catastrophic risk and report it. Section 38 assumes an agency officer will complete an honest impact assessment before deployment.

So the obligation lands on a person, and nobody's measuring how that person behaves. We audit whether the notice template exists and whether the testing vendor was engaged. When new systems are introduced, execution is audited. Behavior is not. Whether the analyst noticed the score was wrong for this applicant, whether the manager overrode a recommendation they couldn't explain, whether anyone escalated when the testing results looked odd: none of that is in the compliance file, and all of it is what the statute now puts in front of a commission or court.

ObligationFirst is the shared schema for modeling obligations like these as structured objects, so "no defense" and "may consider anti-bias testing" become explicit fields with a subject, a trigger, and an evidence expectation instead of a paragraph we hope a model reads correctly. EveryAILaw carries the tracked record, each milestone date and verified-on date included, as statutory reference and obligation categories rather than a determination of what applies to any one employer. Both belong to the Regulation vector. This post stays on the People vector.

What to Do With the Next Ninety Days

Operational, not legal. Confirm each item with counsel.

  1. Inventory. List every tool that scores, ranks, classifies, or recommends people in hiring, promotion, discipline, discharge, or training selection. Apply the section 7 substantial-factor test, not the vendor's marketing label. Note each tool's deployment date, because October 1, 2027 turns on it.
  2. Subscription paper. If you sell AI technology by subscription to Connecticut residents, draft the section 1 key-terms notice and the written acceptance flow before you next renew anyone.
  3. Testing record. Sections 13 and 14 make anti-bias testing evidence admissible in your favor. Record the test, its scope, its date, the results, and what you did about them. An untested tool is now an unexplained one.
  4. Oversight roles. Name the person who reviews each tool's output before a decision, the person who can override it, and the person who receives an escalation. Write down what each is expected to catch.
  5. Evidence of review. The gap between a named reviewer and an effective one is behavioral. PAICE (People + AI Collaboration Effectiveness) measures how a professional behaves when AI output is uncertain, incomplete, or wrong: whether they catch a seeded error, verify the claim that carries the decision, escalate when a source can't be confirmed, and correct rather than defend. Results attach to hashed identifiers, no conversation text is retained, and individual scores are structurally unavailable to the organization. A cohort reliability reading tells you whether the people your section 13 defense depends on can actually tell when the tool is wrong. Not what they report, what they do.
  6. Calendar. January 1, 2027 for the section 2(c)(1) reporting process if you're a large frontier developer. October 1, 2027 for sections 8 through 10. December 31, 2027 for the end of the cure window.

There's enough time before October 1 for items one through four. Item five is the one we skip, because the certificate of completion looks like the same thing. It isn't. From October 1, Connecticut makes the difference between them evidence.


Want to know whether the people behind your employment decisions can catch a wrong score before a complaint does? Contact us about PAICE for organizations.


Curious but short on time?

Take the 3-minute PAICE Pulse — a quick confidence check that maps how you see your own AI collaboration posture. No login required.