Connecticut's AI compliance clock has officially moved into the enforcement phase. Effective October 1, 2026, the state's Artificial Intelligence Responsibility and Transparency Act (the CART Act, Public Act 26-15, i.e. SB 5) and the omnibus privacy amendment bill (Public Act 26-64, i.e. SB 4, amending the Connecticut Data Privacy Act, or CTDPA) take effect together. Both laws were signed by Governor Ned Lamont in May 2026, and on September 16 Attorney General William Tong held a dedicated press conference to brief businesses and consumers on the new rights and obligations.
What happened: two state laws landing back to back
The CART Act is one of the most comprehensive state-level AI statutes enacted in the United States this year, covering automated employment decision-making, AI subscription terms, whistleblower protections at frontier model developers, synthetic content provenance, and AI companion bots used by minors, among other topics. The first tranche of provisions takes effect on October 1: the automated employment decision technology rules, anti-retaliation duties for large frontier model developers, and generative content transparency obligations. The provisions on companion bots and minor protection are deferred to January 1, 2027.
SB 4, taking effect in parallel, substantially expands the CTDPA's reach: it limits and mandates disclosure for algorithmic pricing based on personal data ("surveillance pricing"), requires businesses using facial recognition technology to post clearly legible signage on their premises along with a link to their facial recognition policy, prohibits the sale of Connecticut residents' precise geolocation data and genetic information, and requires data brokers to register with the Department of Consumer Protection (DCP) by January 1, 2027.
Who is affected: not just tech companies
First in line are employers operating in Connecticut. Any company that uses AI tools in employment decisions—hiring, promotion, discipline, or termination, including resume-screening software, automated interview scoring, and performance evaluation platforms—must provide written notice to applicants and employees starting October 1, explaining when and how AI is used in those decisions. Crucially, the law makes clear that using an AI decision tool does not insulate a company from anti-discrimination liability: an employer cannot outsource legal risk by claiming "it was the vendor's algorithm"—the employer itself is the regulated "deployer."
Second are generative AI subscription products offered to Connecticut consumers. Providers must give consumers written notice of key subscription terms and obtain written acceptance—subscription transparency is now written into consumer protection law.
Third are parties holding Connecticut residents' data: data brokers, direct-to-consumer genetic testing companies, businesses using facial recognition or precise geolocation data, and any merchant using personal data for differential pricing.
What to do: an action checklist
- Inventory your hiring toolchain: list every AI tool involved in employment decisions (built in-house or procured), and prepare written notice text for each before October 1.
- Rewrite vendor contracts: write transparency and cooperation duties into procurement terms—"the vendor promised compliance" cannot replace the employer's own notice obligation.
- Review subscription pages: check whether pricing, renewal, and cancellation terms for AI subscription products are disclosed in writing, and whether written acceptance has been obtained.
- Privacy-side audit: check whether you use personal data for price discrimination, sell precise geolocation or genetic data, or operate premises with facial recognition without signage.
- Separate timeline for data brokers: the registration duty is due January 1, 2027—don't confuse it with October 1.
Where the risks are: three common traps
First, "state law" is not "federal law," let alone global law—the CART Act applies only in Connecticut. But it shares DNA with the algorithmic pricing restrictions moving through California, New York, and Maryland, and Attorney General Tong stated at the press conference that state-level enforcement is stepping in to fill the gap. Companies should treat this state-by-state convergence as a long-term trend, not a series of one-off fires. New York's RAISE Act implementation timeline, in its intensive rollout phase, is worth reading alongside—see New York RAISE Act implementation timeline.
Second, the effective dates are staggered. October 1 is only the first tranche: companion bot provisions on January 1, 2027, data broker registration on January 1, 2027, and some requirements phasing in through 2027–2031. Preparing as if "everything takes effect on October 1," or dragging your feet because "none of it applies yet," are both mistakes.
Third, the enforcement signal is unmistakable. Tong declined to detail Connecticut's lead role in the multistate investigation of OpenAI but stressed that enforcement agencies are racing to catch up. The EU AI Act has already entered its operational enforcement phase—see EU AI Act enforcement enters operational phase—so enforcement momentum is accelerating on both sides of the Atlantic. Compliance budgets not spent now will be spent as fines later.
Placed in the context of the U.S. state-by-state legislative race: the moment Connecticut wrote "the employer is the AI deployer, and risk cannot be outsourced" into law, any company operating across states and using AI in personnel decisions must bring compliance to the deployer side rather than pushing responsibility onto vendors. Next year will bring more such state laws, not fewer.