Connecticut's new rules took effect on October 1, this time targeting the consumer side and the data side. Two bills passed during the state legislature's 2026 session — the Connecticut Artificial Intelligence Responsibility and Transparency (CART) Act (Public Act 26-15, officially titled the Act Concerning Online Safety) and the Act Concerning Consumer Privacy and Protection (Public Act 26-64, an expansion of the Connecticut Data Privacy Act, or CTDPA) — became legally binding on businesses operating in the state on October 1, 2026. Both were signed by the governor on May 11, 2026. The employer AI disclosure duties that took effect yesterday came from the same legislative package; today's batch applies to AI subscription providers, data brokers, and every business handling the consumer data of Connecticut residents.
AI subscription providers: written notice before signing, written acceptance required
Section 1 of the CART Act is the most direct provision for AI product companies among the provisions taking effect October 1: subscription-based providers of AI technology must give consumers written notice of key subscription terms before entering into or renewing a contract, and obtain the consumer's written acceptance. In practice, monthly AI subscriptions like ChatGPT Plus can no longer rely on a pre-checked box buried in a checkout flow for Connecticut users — the terms must be presented as a standalone, clear disclosure, and consent must be an affirmative written act by the consumer. This applies regardless of where the company is headquartered; what matters is whether the user is a Connecticut resident.
Data brokers: annual registration from 2027, plus the nation's first centralized deletion mechanism
Public Act 26-64 imposes new registration requirements on businesses that sell or license consumer data: starting January 1, 2027, they must register annually with the Connecticut Department of Consumer Protection, pay annual fees, maintain compliant privacy policies, and publicly explain their data collection practices and how consumers can exercise their privacy rights. More significantly, Connecticut will build the first statewide centralized deletion system in the United States: a single consumer request will require all registered data brokers to delete that person's data, and brokers must establish processes to review requests, on a 45-day review cycle under the law's standards. The business of hoarding and reselling personal data is about to get materially more expensive in Connecticut.
Sale of precise geolocation data is banned; "surveillance pricing" is in the crosshairs
The new rules prohibit businesses and third parties from selling Connecticut residents' precise geolocation data — no grace period, effective October 1. Also notable are restrictions on "surveillance pricing": personalizing or raising prices based on consumer tracking or behavioral data is restricted, and some AI-driven pricing tools must disclose their use. The statute even supplies sample disclosure language: "THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA." E-commerce, ride-hailing, and food-delivery platforms that show different prices to different users in Connecticut should audit their pricing logic now. Connecticut is moving in the same direction as California, New York, and Maryland — Maryland's HB 895 takes effect the same day, prohibiting food retailers and delivery services from using personal data for dynamic pricing, at up to $10,000 per violation.
AI companions: identity disclosure, minor protections, and suicide intervention are all mandatory
The CART Act also creates dedicated obligations for "AI companions" — AI with a natural-language interface that provides adaptive, human-like responses and can sustain a relationship across multiple interactions. Operators must disclose to users at set intervals that they are interacting with AI; implement safeguards for minors; detect and respond to suicide and self-harm indicators; and restrict manipulative or harmful interactions. Operators who know or have reason to believe a user is a minor face heavier obligations — "deliberately not knowing the user's age" is not a viable compliance strategy, and age-verification processes need to be on the roadmap.
What businesses should do now
First, update subscription contracts and checkout flows so written notice of key terms and written acceptance become standalone steps. Second, map the data buying-and-sharing chain to determine whether you qualify as a "data broker" under the act, and prepare for 2027 registration. Third, immediately stop selling or sharing precise geolocation data. Fourth, review the logic and disclosure copy behind dynamic and personalized pricing. Fifth, add identity disclosure, minor protections, and crisis-intervention mechanisms to AI companion products. Sixth, update privacy notices, data retention and deletion processes, and complete impact assessments for profiling and automated decision-making.
Where the risks lie
First, enforcement: the new rules are enforced by the state attorney general and the Department of Consumer Protection, and Connecticut has a track record of active privacy enforcement. Second, multi-state complexity: businesses operating in several states will have to reconcile obligations state by state; a single national template no longer works. Third, operating costs: the centralized deletion mechanism, the 45-day review cycle, and annual registration fees are real, ongoing investments. One timing note: most of the CART Act's employer-facing AI disclosure duties don't take effect until October 1, 2027 — don't confuse the consumer-side and employer-side timelines.