Skip to content
هذه ترجمة للتسهيل فقط. النسخة الإنجليزية هي النسخة الرسمية والملزمة قانونيا. عرض النسخة الإنجليزية
US-CTEnforcement: October 1, 2026MEDIUM coverage1 enforcement action

Connecticut AI & Data Privacy Stack — PA 26-15 (AI/Online Safety), PA 26-64 (Privacy/Surveillance Pricing), CTDPA as amended by PA 25-113, CID Bulletin MC-25: AI Compliance Requirements

Connecticut regulates AI through four stacked instruments, three of which are already in force and one of which lands on 1 October 2026. (1) PUBLIC ACT 26-15 (Substitute SB 5, "An Act Concerning Online Safety", Approved 27 May 2026) is Connecticut's AI act. Effective 1 October 2026 it: requires a written key-terms notice and written consumer acceptance before any AI-technology SUBSCRIPTION is entered or renewed (§ 1); protects frontier-model whistleblowers and, from 1 January 2027, requires every LARGE frontier developer (>$500M group revenue; frontier developer = training a foundation model with more than 10^26 integer or floating-point operations) to run an anonymous internal catastrophic-risk reporting channel with quarterly board reporting (§ 2); builds an AUTOMATED EMPLOYMENT-RELATED DECISION TECHNOLOGY (AEDT) regime in §§ 7-12 whose duties attach to technologies deployed on or after 1 OCTOBER 2027 — developer-to-deployer information supply (§ 8), plain-language disclosure that an applicant or employee is interacting with the technology (§ 9), and a pre-decision written notice naming the technology, its purpose, the personal-data categories and sources analysed and the deployer's contact details (§ 10); makes the use of an AEDT NOT A DEFENCE to a discrimination complaint under Conn. Gen. Stat. §§ 46a-60(b) and 46a-81c, while letting the commission or court weigh evidence of anti-bias testing (§§ 13-14); and requires providers of publicly accessible generative-AI systems with more than one million monthly users to embed tamper-resistant C2PA-style PROVENANCE DATA in AI-created or materially altered audio, image and video (§ 15). From 1 January 2027 §§ 4-6 require AI COMPANION operators to run an evidence-based suicide/self-harm/violence detection protocol with 988 referral (posted publicly on the operator's web site), to prevent the companion from claiming to be human, to disclose the non-human nature of the interaction on a fixed cadence, and to apply age-appropriate safeguards for users under 18. (2) The CTDPA as amended by PUBLIC ACT 25-113 (Substitute SB 1295, Approved 24 June 2025) has applied since 1 JULY 2026 to any business that in a calendar year controls or processes the personal data of 35,000+ Connecticut consumers (down from 100,000, excluding payment-transaction-only data), OR processes consumers' sensitive data at any volume, OR offers consumers' personal data for sale — and the entity-level GLBA financial-institution exemption was REPLACED by a narrower bank/credit-union exemption. Its privacy notice must now disclose, among other items, whether the controller collects, uses or sells personal data to train LARGE LANGUAGE MODELS, and must carry the month and year it was last updated. Consumers may opt out of profiling in furtherance of ANY automated decision (the word "solely" was deleted) producing a legal or similarly significant effect and, where feasible, may question the result, be told the reason for it, review the data used and — for housing decisions — correct that data and have the decision re-evaluated. Since 1 AUGUST 2026 controllers that profile for such decisions must also complete a seven-element PROFILING IMPACT ASSESSMENT, which the Attorney General may demand in an investigation. (3) PUBLIC ACT 26-64 (Substitute SB 4, "An Act Concerning Consumer Privacy and Protection", Approved 27 May 2026) takes effect 1 OCTOBER 2026: online prices set by an automated "price setting device" using a consumer's personal data must carry the literal legend "THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA"; retail sellers and third-party delivery services may not engage in surveillance pricing at all; a controller using facial-recognition technology on its premises for security may match only against its own database and must post entrance signage linking to a facial-recognition policy that carries the Attorney General's contact details; no controller or third party may sell precise geolocation data; and data brokers must register with the Department of Consumer Protection (a $2,500 fee) before selling or licensing brokered personal data on or after 1 January 2027. (4) INSURANCE — Connecticut Insurance Department Bulletin No. MC-25 (26 February 2024) adopted the NAIC Model Bulletin on the Use of AI Systems by Insurers for all insurers licensed in Connecticut, replacing the Department's 20 April 2022 big-data notice, and requires every Connecticut DOMESTIC insurer to file an AI Certification by 1 September each year. Enforcement across the whole non-insurance stack runs through CUTPA § 42-110b(a) and is EXCLUSIVE to the Attorney General — § 42-110g is switched off and there is no private right of action — except that PA 26-55 (HB 5312, signed 26 May 2026) creates both an AG civil action and a PRIVATE right of action against platform operators that fail to take down synthetically created intimate images. VERIFY-THE-NEGATIVE: SB 2 (2025), the Colorado-style high-risk-AI duty-of-care bill, never became law, so Connecticut imposes NO algorithmic-discrimination duty of care and NO high-risk-AI impact assessment on private developers or deployers; HB 5342 (2026), the election-deepfake bill, died on the House calendar (last action 20 April 2026, session adjourned sine die 6 May 2026), so Connecticut has NO election-synthetic-media statute; and Connecticut has no BIPA-style biometric statute — biometric data is regulated as CTDPA sensitive data requiring consent.

Summary of publicly-available regulatory text as of 2026-08-25. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

July 1, 2023

Enforcement Begins

October 1, 2026

Maximum Penalty

CUTPA (the enforcement route for the CTDPA, PA 26-15 §§ 1, 8-11, 15 and PA 26-64): up to $5,000 per willful violation of § 42-110b and up to $25,000 for violating an injunction (Conn. Gen. Stat. § 42-110o, findlaw text "Current as of January 01, 2025"); AG-exclusive, no private right of action. PA 26-15 § 2 (frontier-developer whistleblower duties) carries its own civil penalty of up to $1,000 per violation recoverable by the AG in Hartford Superior Court, plus investigation costs, expert fees and attorney's fees. Insurance: CUIPA penalties of up to $5,000 per act ($50,000 aggregate) for non-willful and up to $25,000 per act ($250,000 per six months) for willful violations, plus licence suspension or revocation (Conn. Gen. Stat. § 38a-817, same findlaw stamp).

What Your Business Must Do

15 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

CTDPA Privacy Notice — LLM Training Disclosure and Mandatory Notice Contents

High Priority

IN FORCE SINCE 1 JULY 2026. Conn. Gen. Stat. § 42-520(b)(1), as substituted by PA 25-113 § 9, fixes what a controller's privacy notice must contain, and subparagraph (H) is the AI item: "a statement disclosing whether the controller collects, uses or sells personal data for the purpose of training large language models". Read the whole list, because the AI line is one of nine mandatory items and the others changed in the same amendment: (A) categories of personal data processed; (B) purpose of processing; (C) a description of the means for consumers to submit rights requests, including how to exercise § 42-518(a) rights and how to appeal a controller's decision on such a request; (D) the categories of personal data the controller SELLS to third parties (the amendment replaced "shares with"); (E) the categories of third parties to which it sells personal data; (F) a clear-and-conspicuous disclosure of any processing for targeted advertising or any sale for targeted advertising; (G) an active e-mail address or other online mechanism for contacting the controller; (H) the large-language-model training statement; and (I) THE MONTH AND YEAR THE NOTICE WAS LAST UPDATED. § 42-520(b)(2) then dictates publication: a conspicuous hyperlink containing the word "privacy" on the web-site home page, on the app store or download page, and in the app settings menu; a regularly used medium such as mail if there is no web site; every language in which the controller offers the product or service; and in a form reasonably accessible to and usable by people with disabilities. Note that (H) is a disclosure duty about LLM training — it does not by itself permit or forbid the training.

Deadline: July 1, 2026

Conn. Gen. Stat. § 42-520(b)(1)(H) and § 42-520(b)(2), as substituted by Public Act 25-113 § 9 (Substitute SB 1295, Approved 24 June 2025, Effective 1 July 2026); applicability § 42-516 as substituted by PA 25-113 § 6

CTDPA Profiling — Opt-Out plus the New Explanation and Re-Evaluation Rights

High Priority

The opt-out has existed since 1 July 2023, but PA 25-113 § 8 rewrote it and bolted four new rights on top, all in force since 1 JULY 2026. (1) SCOPE WIDENED: the opt-out now covers "profiling in furtherance of ANY automated decision that produces any legal or similarly significant effect" — the word "solely" was struck, so keeping a human in the loop no longer takes the decision out of scope. (2) ACCESS: on a § 42-518(a)(1) request the controller must confirm whether it is processing the consumer's personal data for profiling to make such a decision, and disclose inferences derived about the consumer, subject to the trade-secret carve-out. (3) EXPLANATION: where personal data were processed for profiling in furtherance of such a decision, the consumer may, IF FEASIBLE, (a) question the result of the profiling, (b) be informed of the reason the profiling produced that decision, and (c) review the personal data that were processed. (4) HOUSING RE-EVALUATION: if the profiling decision concerned housing, the consumer may correct incorrect personal data used in the profiling and have the decision RE-EVALUATED on the corrected data. (5) SALE TRANSPARENCY: the consumer may demand a list of the third parties to which the controller has sold that consumer's personal data, or, if the controller keeps no such per-consumer list, a list of all third parties to which it has sold personal data. Build the rights-request workflow so the profiling questions can actually be answered — an opt-out toggle alone no longer satisfies § 42-518.

Deadline: July 1, 2026

Conn. Gen. Stat. § 42-518(a)(1), (a)(5)(C), (a)(6) and (a)(7), as substituted by Public Act 25-113 § 8 (Effective 1 July 2026); original opt-out in force since 1 July 2023

CTDPA Profiling Impact Assessment (Seven Mandatory Elements)

High Priority

IN FORCE SINCE 1 AUGUST 2026 — this is a SECOND, SEPARATE assessment from the data protection assessment, and Connecticut is explicit that it is not retroactive: it applies to processing activities created or generated ON OR AFTER 1 August 2026 (the DPA duty continues to apply to activities created after 1 July 2023). Any controller that engages in profiling to make a decision producing a legal or similarly significant effect concerning a consumer must conduct an impact assessment containing, to the extent reasonably known or available: (1) a statement of the purpose, intended use cases, deployment context and benefits of the profiling; (2) an analysis of whether the profiling poses a known or reasonably foreseeable heightened risk of harm and, if so, the nature of that risk and the mitigation steps taken; (3) a description of the main categories of personal data used as INPUTS and of the OUTPUTS produced; (4) an overview of the main categories of personal data used to CUSTOMISE the profiling, if any; (5) the metrics used to evaluate performance and the known limitations; (6) a description of transparency measures, including how consumers are told profiling is happening while it is happening; and (7) a description of post-deployment MONITORING and user safeguards, including the oversight, use and learning processes established to address issues arising from the profiling. Separately, the four heightened-risk triggers for the data protection assessment are now set out up front in § 42-522(a): targeted advertising, sale of personal data, profiling carrying a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact, financial/physical/reputational injury, offensive intrusion on solitude, or other substantial injury, and the processing of sensitive data. The Attorney General may demand either assessment in an investigation; both are confidential and exempt from the Freedom of Information Act, and disclosing them to the AG does not waive attorney-client privilege or work-product protection. An assessment prepared for another law counts if it is reasonably similar in scope and effect, and one assessment may cover a comparable set of processing operations.

Deadline: August 1, 2026

Conn. Gen. Stat. § 42-522(c) (impact assessment contents) and § 42-522(g)(2) (applies to processing activities created or generated on or after 1 August 2026), with heightened-risk triggers in § 42-522(a) and AG access in § 42-522(d) — all as substituted by Public Act 25-113 § 11 (Effective 1 July 2026)

PA 26-15 §§ 9-10 — Automated Employment Decision Technology: Interaction Disclosure and Pre-Decision Notice

High Priority

Sections 7 to 12 of Public Act 26-15 take effect 1 OCTOBER 2026, but read the trigger carefully: the deployer duties attach to automated employment-related decision technologies DEPLOYED ON OR AFTER 1 OCTOBER 2027. An AEDT is any technology that processes personal data and uses computation to generate an output — prediction, recommendation, classification, ranking, score or other information — that is a SUBSTANTIAL FACTOR used to make or materially influence an employment-related decision, meaning a factor that meaningfully alters the outcome. Ordinary word processing, spreadsheets, navigation, hosting, storage, security and similar tooling is excluded so long as it does not make or materially influence the decision, as is anything purely descriptive, diagnostic or statistical and not relied upon. "Employment-related decision" covers hiring, promotion, discipline, discharge, renewal, selection for training or apprenticeship, and tenure or terms, privileges and conditions of employment — but NOT decisions producing only a non-material change in job tasks, responsibilities, hours or assignments, and not decisions about workplace health and safety, scheduling and planning, or productivity monitoring. TWO DUTIES: (§ 9) where the AEDT is intended to interact with an employee or applicant in Connecticut, disclose in PLAIN LANGUAGE to each person who interacts with it that they are interacting with the technology — unless a reasonable person would find it obvious; and (§ 10) before the employment-related decision is made, give the employee or applicant a WRITTEN NOTICE stating (1) that the deployer has deployed an AEDT, (2) the purpose of the AEDT and the nature of the decision, (3) the TRADE NAME of the AEDT, (4) the categories of the person's personal data the AEDT will analyse or process and how that data will be assessed in reaching a decision, (5) the sources of that personal data, and (6) contact information for the deployer. Section 11 lets you withhold trade-secret or otherwise legally protected information, but then you must notify the person that information is being withheld AND the basis for withholding it. If a developer has contracted under § 8(c) to assume these duties, the contract must be binding and set out exactly which duties it takes over. NOTE THE HONEST LIMIT: Connecticut requires notice, not a bias audit — there is no impact-assessment, disparate-impact-testing or filing duty in §§ 7-12.

Deadline: October 1, 2027

Public Act 26-15 §§ 7 (definitions), 9 (interaction disclosure), 10 (pre-decision written notice) and 11 (trade-secret withholding notice) (Substitute SB 5, Approved 27 May 2026; sections effective 1 October 2026; duties attach to AEDTs deployed on or after 1 October 2027)

PA 26-15 § 8 — AEDT Developer Duty to Equip the Deployer

High Priority

The developer of an automated employment-related decision technology deployed in Connecticut on or after 1 OCTOBER 2027 must provide to the deployer ALL information the deployer needs to perform its § 9 and § 10 duties — that is, everything required to disclose the interaction and to issue the pre-decision notice naming the technology, its purpose, the personal-data categories and their sources, and how that data is assessed. "Developer" means a person doing business in Connecticut who develops, or intentionally and substantially modifies, an AEDT, so a substantial modifier inherits developer duties. The duty is switched off unless the technology was advertised, marketed, configured, contracted for, sold or licensed to be USED TO MATERIALLY INFLUENCE an employment-related decision — a general-purpose model a customer repurposes for hiring on its own initiative does not by itself pull the developer in. Alternatively the developer may contract to ASSUME the deployer's § 9 and § 10 duties; that contract must be binding and clearly set out which duties it has taken over. Practical build: ship a Connecticut disclosure pack with the product (trade name, purpose, input-data categories and sources, assessment logic summary at a level that survives the § 11 trade-secret carve-out) rather than answering customer-by-customer.

Deadline: October 1, 2027

Public Act 26-15 § 8 (developer information-supply duty; § 8(b) marketing-purpose limit; § 8(c) duty-assumption contract), with § 7(4) definition of "developer" (Effective 1 October 2026; duties attach on or after 1 October 2027)

PA 26-15 §§ 13-14 — Using an AEDT Is No Defence to a Discrimination Complaint

High Priority

EFFECTIVE 1 OCTOBER 2026 — five weeks after this entry was verified, and years ahead of the AEDT notice duties. Public Act 26-15 § 13 rewrites Conn. Gen. Stat. § 46a-60(b)(1) and § 14 rewrites § 46a-81c(1) to add the same sentence: the use of an automated employment-related decision technology, as defined in § 7 of the act, SHALL NOT BE A DEFENCE against a complaint alleging a discriminatory practice. The Commission on Human Rights and Opportunities or the court "may consider evidence of anti-bias testing or similar proactive efforts to avoid such discriminatory practice, including, but not limited to, the quality, efficacy, recency and scope of such testing or efforts, the results of such testing or efforts and the response thereto." Two consequences. First, "the vendor's model did it" is dead as a liability shield for hiring, promotion, discipline, discharge, terms and conditions across every protected characteristic in § 46a-60(b)(1) and for sexual orientation and civil union status under § 46a-81c. Second, anti-bias testing is now MITIGATION EVIDENCE with named quality criteria — quality, efficacy, RECENCY, scope, results and the response to those results — so testing that is stale, narrow or ignored after a bad result is worth little. Connecticut does not mandate the testing; it rewards being able to produce it. Keep dated test reports, the population and outcome measures used, and a record of what changed after each result.

Deadline: October 1, 2026

Public Act 26-15 §§ 13-14, amending Conn. Gen. Stat. § 46a-60(b)(1) (2026 supplement) and § 46a-81c (Effective 1 October 2026); AEDT definition in § 7 of the same act

PA 26-15 § 15 — Generative-AI Provenance Data (C2PA) for Large Consumer Providers

High Priority

EFFECTIVE 1 OCTOBER 2026. A "covered provider" — any person who creates, codes or otherwise produces a generative AI system that has MORE THAN ONE MILLION USERS PER MONTH and is publicly accessible to consumers for personal use (government agencies excluded) — must, to the extent commercially and technically reasonable, embed PROVENANCE DATA in any audio, image or video content, or combination of them, that its system creates or MATERIALLY ALTERS, in a way that lets a consumer assess whether the content was created or materially altered by that system. The provenance data must be made difficult to tamper with, remove or disassociate using commercially and technically reasonable methods, "including, but not limited to, the relevant standard established by the COALITION FOR CONTENT PROVENANCE AND AUTHENTICITY" — the statute names C2PA on its face. "Generative artificial intelligence system" is defined as technology using machine learning to generate images, audio or video, including deep learning, natural language processing or comparable techniques; "provenance data" is data embedded in the content or its metadata for verifying authenticity, origin or modification history. "Materially alter" excludes minor modifications that do not significantly change perceived content or meaning — brightness, contrast, colour, sharpening, saturation, filters, resizing, scaling, cropping, format conversion, resampling, denoising and background-noise removal. CARVE-OUTS: the duty never requires embedding information about an identified or identifiable individual, nor disclosure of trade secrets or confidential design information; and it does not apply to business-to-business use, sale, licensing or distribution of a generative AI system, to products or services solely providing video game or interactive experiences (including in-experience commerce), or to systems used solely for upscaling, noise reduction or compression. Note the scope limit honestly: § 15 covers audio, image and video — TEXT output is not within the provenance duty.

Deadline: October 1, 2026

Public Act 26-15 § 15 (covered provider, provenance data, C2PA reference, exclusions, and § 15(c) enforcement) (Substitute SB 5, Effective 1 October 2026)

PA 26-15 §§ 5-6 — AI Companion Crisis Protocol, Non-Human Disclosure Cadence and Minor Safeguards

High Priority

EFFECTIVE 1 JANUARY 2027. An operator — any individual or business entity (or its affiliate, member, subsidiary or beneficial owner) that provides or operates an AI companion for a user — may not provide or operate one unless BOTH conditions in § 5(a)(1) are met. (A) The companion includes a protocol that uses evidence-based methods to detect user expressions clearly indicating a risk of suicide, self-harm or imminent physical violence AND institutes measures preventing the companion from generating output that encourages suicide, self-harm or physical violence; on detection it must refer the user to appropriate mental-health evaluation and treatment resources INCLUDING the 9-8-8 National Suicide Prevention Lifeline; and on a repeat detection after such a referral it must refer the user to mental-health services consistent with clinical best practices and expertise. (B) The operator has implemented reasonable measures preventing the companion from claiming to be a human being — including when asked directly — and from generating output that refutes or conflicts with any disclosure that it is not human. § 5(a)(2) then requires the PROTOCOL ITSELF to be posted in a prominent, publicly accessible location on the operator's web site. § 5(b) sets the disclosure CADENCE where the companion would cause a reasonable user to believe they are talking to a human: either a static written notice visible throughout the entire interaction, or an audible or written notice at the start of the first interaction in any 24-hour period AND at least ONCE PER HOUR for users under 18, or at least once every THREE HOURS for users 18 and over, during continuous interaction. § 6 adds minor-specific duties where the operator knows or has reason to believe the user is under 18: safeguards meeting or exceeding the measures the section specifies, plus tools made available to minor users and their parents or guardians to manage the minor's use — with a safe harbour where the operator knew or had reason to believe, before providing the companion, that the user was 18 or older.

Deadline: January 1, 2027

Public Act 26-15 §§ 4 (definitions of "artificial intelligence companion", "operator", "self-harm"), 5 (protocol, publication, non-human disclosure cadence) and 6 (minor users) (Effective 1 January 2027)

PA 26-15 § 1 — AI Subscription Key-Terms Notice and Written Acceptance

High Priority

EFFECTIVE 1 OCTOBER 2026 — an unusual duty that catches every AI vendor selling to Connecticut consumers on a subscription. A "subscription-based provider" (a person doing business in Connecticut who provides or offers an AI technology to a consumer under a subscription for any fee or other compensation) may not enter into or renew a subscription, or collect any fee for an initial subscription or renewal, unless (A) it has given the consumer a WRITTEN NOTICE disclosing the key terms and conditions and (B) the consumer has given the provider a written notice ACCEPTING those key terms. For an INITIAL subscription the notice must set out material information sufficient for a reasonable consumer to decide whether to buy or keep the subscription, including at minimum (i) any quantitative or qualitative LIMITATIONS the provider may impose under the terms — expressly including limits it may impose in response to the consumer's own conduct — and (ii) whether the provider has DISCRETION to limit or eliminate access to, or reduce the quantity or quality of, any functionality of the AI technology. For a RENEWAL the notice must set out any such limitation or discretion that will apply for the first time in the renewal term, or that applied in the immediately preceding term but has been MODIFIED for the renewal term. In plain terms: rate limits, usage caps, throttling, model downgrades, feature removal and conduct-based restrictions have to be disclosed up front and re-disclosed when they change, and a click-through that never surfaces them will not do — the statute requires the consumer's written acceptance of the key terms.

Deadline: October 1, 2026

Public Act 26-15 § 1 (definitions in § 1(a); notice and acceptance duty in § 1(b); enforcement in § 1(c)) (Effective 1 October 2026)

PA 26-64 § 11 — Algorithmic Pricing Legend and Surveillance-Pricing Ban

High Priority

EFFECTIVE 1 OCTOBER 2026. A "price setting device" is defined broadly as ANY automated or programmed process that uses a consumer's personal data to establish a price for a consumer good or service — algorithmic and AI pricing squarely included. TWO DUTIES. (1) DISCLOSURE: any person doing business in Connecticut who uses a price setting device for any purpose other than establishing a DISCOUNTED price for an online transaction, and who advertises, promotes, labels, publishes or displays that price online, must include the following disclosure or one substantially similar, readily visible to the average consumer: "THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA". A "discounted price" means one verifiably lower than the generally available, publicly disclosed, bona fide market price. (2) PROHIBITION: no RETAIL SELLER (a retailer as defined in Conn. Gen. Stat. § 12-407 making retail sales of tangible personal property, including a retail food establishment) and no THIRD-PARTY DELIVERY SERVICE doing business in Connecticut may engage in SURVEILLANCE PRICING at all. Surveillance pricing means establishing a customised price for a consumer good or service that is specific to a consumer based in whole or in part on the consumer's personal data collected through any technology, method, system or tool — expressly including biometric monitoring, cameras, device tracking or sensors — capable of gathering personal data about the consumer's behaviour, characteristics, location or other attributes in a physical or digital environment, whether the person setting the price gathered that data directly or acquired it from a third party. The act carves out retention discounts and price differences that reflect justifiable differences in the cost of providing the good or service.

Deadline: October 1, 2026

Public Act 26-64 § 11 (definitions of "price setting device", "surveillance pricing", "retail seller", "third-party delivery service" and "discounted price"; disclosure duty § 11(b); prohibition § 11(c); enforcement § 11(e)) (Substitute SB 4, Approved 27 May 2026, Effective 1 October 2026)

PA 26-64 § 16 — On-Premises Facial Recognition: Own-Database Limit, Entrance Signage and Published Policy

High Priority

EFFECTIVE 1 OCTOBER 2026, added to Conn. Gen. Stat. § 42-524. A controller or consumer health data controller that uses ANY facial recognition technology on its premises to prevent, detect, protect against or respond to security incidents, identity theft, fraud, harassment, malicious or deceptive activity or illegal activity, to preserve system integrity or security, or to investigate, report or prosecute those responsible, must do BOTH of the following. (i) Use the technology EXCLUSIVELY to match still images or video against a database maintained exclusively by that controller — matching against third-party watchlists, purchased face databases or shared retail-crime databases is out. (ii) Post CLEARLY LEGIBLE SIGNAGE at each entrance to the premises where the technology is in use — other than entrances to areas restricted to authorised employees — that both alerts consumers entering that facial recognition technology is in use AND includes a conspicuous hyperlink or QR CODE directing them to the controller's facial-recognition technology policy. That policy must include CONTACT INFORMATION FOR THE OFFICE OF THE ATTORNEY GENERAL, and may disclose the controller's policies on interactions between its loss-prevention officers and consumers. This is the security-purpose branch of the sensitive-data rules: biometric data processed to uniquely identify an individual remains CTDPA sensitive data requiring consent outside these security uses, and the same section preserves the narrow processing allowance only where safeguards protect the consumer and a professional under confidentiality obligations is responsible.

Deadline: October 1, 2026

Public Act 26-64 § 16, adding subdivision (2) to Conn. Gen. Stat. § 42-524(a) (2026 supplement) (Effective 1 October 2026)

CID Bulletin MC-25 — Insurer AI Systems Programme and the Annual AI Certification (Due 1 September)

High Priority

IN FORCE SINCE 26 FEBRUARY 2024, with a RECURRING ANNUAL DEADLINE — the next falls on 1 SEPTEMBER 2026. Connecticut Insurance Department Bulletin No. MC-25, addressed to all insurers licensed to do business in Connecticut, adopts the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers and expressly "updates and replaces the Department's Notice issued on April 20, 2022, concerning the usage of big data and avoidance of discriminatory practices" — so the 2022 big-data notice is superseded, not cumulative. The bulletin reminds insurers that decisions or actions affecting consumers made or supported by advanced analytical and computational technologies, including AI systems, must comply with all applicable insurance laws, including unfair trade practice and unfair discrimination law, and it sets out the Department's expectations for governance of the development, acquisition and use of AI, plus the information and documentation the Department may request in an investigation or market conduct examination. THE CONNECTICUT-SPECIFIC DUTY: "Connecticut domestic Insurers must complete the Artificial Intelligence Certification ('Certification'), which is due on or before September 1, 2024, and annually thereafter", filed through the Department's data-certification application; an insurer certifying that it demonstrates compliance through ALTERNATIVE MEANS must describe those alternative means as part of the Certification. The bulletin names its own legal footing: the Connecticut Unfair Insurance Practices Act (Conn. Gen. Stat. §§ 38a-815 to 38a-819, including the unfair claim settlement standards in § 38a-816(6)); the Corporate Governance Annual Disclosure report under § 38a-142a, whose § 38a-142a(c)(5) description of board and senior-management oversight of critical risk areas the Department reads as covering the insurer's use of AI systems; the Rating Laws (property and casualty §§ 38a-663 to 38a-696, health §§ 38a-481, 38a-501a, 38a-528a and 38a-556, life §§ 38a-446 and 38a-447), which apply regardless of the methodology used to develop rates so an AI- or predictive-model-derived rate is judged by the same standard; and the market conduct examination and investigation framework in §§ 38a-15 and 38a-16.

Deadline: September 1, 2026

Connecticut Insurance Department Bulletin No. MC-25, "Use of Artificial Intelligence Systems by Insurers" (26 February 2024), adopting the NAIC Model Bulletin (NAIC-adopted 4 December 2023); legal authority as cited in the bulletin: Conn. Gen. Stat. §§ 38a-815 to 38a-819 (CUIPA), § 38a-816(6), § 38a-142a(c)(5) (CGAD), §§ 38a-663 to 38a-696, §§ 38a-481, 38a-501a, 38a-528a, 38a-556, §§ 38a-446, 38a-447 (Rating Laws), §§ 38a-15 and 38a-16 (market conduct)

Conn. Gen. Stat. § 36a-701b — 60-Day Breach Notice, Simultaneous AG Notice and Two Years of Identity-Theft Services

High Priority

Connecticut's breach statute is the backstop when an AI system, vendor or training pipeline leaks personal information. Notice to each affected Connecticut resident must go out "without unreasonable delay but not later than SIXTY DAYS after the discovery of such breach". Notice to the ATTORNEY GENERAL is required "not later than the time when notice is provided to the resident" — simultaneous, not a follow-up filing, which is stricter in sequencing than several neighbouring states. Where the breach exposes personal information, the person who owns or licenses the data must OFFER appropriate identity-theft prevention services and, where applicable, identity-theft mitigation services, at NO COST to the resident, for a period of NOT LESS THAN TWO YEARS. Failure to comply is an unfair trade practice, enforceable by the Attorney General, with penalties directed to the state privacy protection account. Practical note for AI deployments: a compromise of model training data, embeddings stores or vendor-side logs containing Connecticut residents' personal information starts the same 60-day clock as any other breach, and the AG-notice timing means the regulator learns of it on the same day the consumers do.

Conn. Gen. Stat. § 36a-701b (breach of security regarding computerized data; 60-day consumer notice; simultaneous Attorney General notice; not less than two years of identity-theft prevention and mitigation services; unfair-trade-practice enforcement) — text verified via codes.findlaw.com, stamped "Current as of January 01, 2025"

PA 26-15 § 2 — Frontier Developer Catastrophic-Risk Whistleblower Duties

Medium Priority

EFFECTIVE 1 OCTOBER 2026, with the internal-channel build due 1 JANUARY 2027. A "frontier developer" is any person doing business in Connecticut who intends to train, initiates the training of, or trains a foundation model using more than 10^26 integer or floating-point operations, counting original training plus any fine-tuning, reinforcement learning or other material modification applied to a preceding model. A "large frontier developer" is one whose group (including entities under common control) had annual gross revenues above $500,000,000 in the most recently completed calendar year. DUTIES. (§ 2(b)) No frontier developer may make, adopt, enforce or enter into any rule, policy or contract providing that it may discharge, discipline or penalise an employee for activity protected by Conn. Gen. Stat. § 31-51m(b), or that anyone with authority over a covered employee may retaliate against that covered employee for reporting an issue they have reasonable cause to believe indicates activity posing a specific and substantial danger to public health or safety due to a CATASTROPHIC RISK. (§ 2(c)) Every LARGE frontier developer must, by 1 January 2027, establish and maintain a reasonable internal process for a covered employee to submit an ANONYMOUS report of such activity and to receive reasonable updates on the investigation and the actions taken; reports and updates must be shared with the officers and directors at least QUARTERLY, except that a report alleging wrongdoing by an officer or director must not be shared with that person. (§ 2(d)) Every frontier developer must give covered employees clear notice of their rights either by posting a notice at all times in every workplace, giving an equivalent notice to each new covered employee and periodically to remote covered employees, or by providing a written notice at least ANNUALLY to each covered employee and obtaining their acknowledgement of receipt. "Catastrophic risk" is defined against a threshold of death or serious injury to more than fifty people or more than one billion dollars in damage or loss of covered property from a single incident involving expert-level CBRN uplift or unsupervised model conduct constituting a cyberattack or, if done by a person, murder, assault, extortion or theft. HONEST LIMIT: Connecticut stops at whistleblower protection — unlike some other states there is NO published-safety-framework duty and NO safety-incident reporting duty to a regulator in § 2.

Deadline: January 1, 2027

Public Act 26-15 § 2 (definitions in § 2(a) including "catastrophic risk", "covered employee", "foundation model", "frontier developer", "large frontier developer"; duties in § 2(b)-(d); penalty in § 2(e)) (Effective 1 October 2026)

PA 26-55 — Platform Takedown Exposure for Synthetically Created Intimate Images (AG Civil Action plus PRIVATE Right of Action)

Medium Priority

THE ONE CONNECTICUT AI-ADJACENT STATUTE THAT IS NOT AG-EXCLUSIVE. House Bill 5312 of the 2026 session — "AN ACT ESTABLISHING A CIVIL ACTION FOR THE OFFICE OF THE ATTORNEY GENERAL AND A PRIVATE RIGHT OF ACTION FOR VICTIMS OF UNLAWFUL DISSEMINATION OF A SYNTHETICALLY CREATED INTIMATE IMAGE" — passed the House on 1 May 2026 and the Senate on 5 May 2026, was designated PUBLIC ACT 26-55 on 14 May 2026 and was SIGNED BY THE GOVERNOR ON 26 MAY 2026. Per the General Assembly's own statement of purpose, the act establishes a private right of action and a civil action for the Office of the Attorney General to pursue damages from an OPERATOR OF AN ELECTRONIC DIGITAL PLATFORM that fails to take down a synthetically created intimate image. Any platform that hosts user-generated imagery and serves Connecticut users should therefore run a notice-and-takedown path for synthetic intimate imagery and be able to evidence its response times. HONEST LIMIT ON THIS ENTRY, RECORDED DELIBERATELY: the enrolled text of PA 26-55 could NOT be retrieved this session — cga.ct.gov was unreachable from this toolchain and the Wayback Machine holds no capture of 2026PA-00055-R00HB-05312-PA.PDF — so the takedown deadline, the damages figures, the definition of "operator of an electronic digital platform" and the effective date are NOT stated here rather than guessed. The facts above come from the CGA's own bill-status record for HB-5312 (bill title, statement of purpose, and the history lines "5/14/2026 (LCO) Public Act 26-55" and "5/26/2026 Signed by the Governor"). NEXT VERIFIER: pull 2026PA-00055-R00HB-05312-PA.PDF and fill in the operative detail, then set a real deadline and penaltyAmount.

Public Act 26-55 (Substitute for Raised H.B. No. 5312, 2026 session; Public Act designation 14 May 2026; signed by the Governor 26 May 2026) — bill title and history verified from the Connecticut General Assembly bill-status record; enrolled act text not retrievable this session

Who Does This Apply To?

CONNECTICUT AI SCOPE IN ONE PLACE — four instruments, four different scope tests, so check each separately rather than assuming one threshold governs. (1) PA 26-15 has NO general size threshold: § 1 catches any subscription-based AI provider selling to Connecticut consumers; §§ 7-12 catch any person doing business in the state who develops or deploys an automated employment-related decision technology (duties attaching to technologies deployed on or after 1 October 2027); §§ 13-14 catch any employer subject to Conn. Gen. Stat. § 46a-60 or § 46a-81c using such technology, with NO deployment-date carve-out and effect from 1 October 2026; §§ 4-6 catch any operator of an AI companion; § 15 catches only generative-AI providers with more than one million monthly users whose systems are publicly accessible for personal use; and § 2 catches frontier developers above 10^26 training operations, with the internal anonymous-reporting channel reserved for large frontier developers above $500M group revenue. (2) THE CTDPA, as amended by PA 25-113 and in force since 1 July 2026, catches a person conducting business in Connecticut or targeting Connecticut residents that in the preceding calendar year controlled or processed the personal data of 35,000+ consumers (excluding payment-transaction-only data), OR controls or processes consumers' sensitive data at any volume, OR offers consumers' personal data for sale. Entity-level exemptions were re-cut in the same amendment: state and local government bodies and their consumer-health-data contractors, nonprofits, candidate and political committees, institutions of higher education, registered national securities associations, HIPAA covered entities and business associates, tribal nation government organisations, air carriers, insurers and their affiliates (including fraternal benefit societies, health carriers, insurance-support organisations, agents and producers), and banks and credit unions meeting the three conditions in § 42-517(a)(11) — critically, the OLD blanket exemption for GLBA financial institutions and GLBA-covered DATA was REMOVED, so a non-bank lender or fintech that relied on it is now in scope. (3) PA 26-64, from 1 October 2026, applies its algorithmic-pricing legend to any person doing business in Connecticut who prices online using a price setting device, bans surveillance pricing outright for retail sellers of tangible personal property and third-party delivery services, applies the facial-recognition duties to any controller using the technology on premises, bans the sale of precise geolocation data by controllers and third parties, and requires data-broker registration with the Department of Consumer Protection (a $2,500 fee) to sell or license brokered personal data on or after 1 January 2027. (4) CID BULLETIN MC-25 applies its AI Systems Programme expectations to ALL insurers licensed in Connecticut, and its annual 1 September AI Certification to Connecticut DOMESTIC insurers. Enforcement across the CTDPA, PA 26-15 and PA 26-64 is EXCLUSIVE to the Attorney General through CUTPA § 42-110b(a) with § 42-110g switched off and no private right of action, and since 1 January 2025 the CTDPA cure notice is discretionary (PA 26-15 §§ 8-11 keep a 60-day cure for violations occurring on or before 31 December 2027); the exception is PA 26-55, which gives victims of synthetically created intimate images a private right of action against platform operators. Legacy scope note retained for continuity: the pre-amendment CTDPA test was 100,000 consumers, or 25,000 consumers with more than 25% of gross revenue from selling personal data — that test governed conduct before 1 July 2026 and still frames older enforcement. ORIGINAL ENTRY TEXT (kept because it remains accurate for the LLM-training duty specifically): any business already subject to the Connecticut Data Privacy Act — one that, in a calendar year, (a) controls or processes the personal data of 35,000+ Connecticut consumers (LOWERED from 100,000 by PA 25-113, effective July 1, 2026; excluding data processed solely to complete a payment transaction), OR (b) controls or processes consumers' sensitive data (no volume threshold), OR (c) offers consumers' personal data for sale (no volume threshold) — that uses personal data to train AI systems (specifically large language models). In scope means two duties: (1) under PA 25-113 (effective July 1, 2026) a clear-and-conspicuous, consumer-facing privacy-notice disclosure of whether personal data is collected, used, or sold for LLM-training purposes; and (2) under the existing CTDPA (effective July 2023) an opt-out of profiling / automated decision-making that produces legal or similarly significant effects, plus a data-protection assessment for such high-risk processing. Enforced by the Connecticut Attorney General (no private right of action); up to $5,000 per willful violation under CUTPA. Scope turns on the CTDPA processing thresholds, not on whether the business is AI-focused.

Recent Enforcement Actions

2025-07Source verified· as of 2026-08-25

Against:

Recent Regulatory Guidance

guidance2026-08

NAIC Big Data & AI (H) Working Group — implementation map for the Model Bulletin on the Use of AI Systems by Insurers

Read this round from the NAIC's own PDF, "Implementation of NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers", stamped "[Status as of August 6, 2026]". Connecticut appears in the ADOPTED set and its reference line reads exactly: "Connecticut: Bulletin No. MC-25 - Adopted February 26, 2024". Twenty-five jurisdictions are listed as adopting; California, Colorado, New York and Texas appear separately under "Insurance Specific Regulation/Guidance" rather than as model-bulletin adopters. TOOLING WARNING FOR THE NEXT VERIFIER: two NAIC map PDFs are live at once and they disagree in age — content.naic.org/sites/default/files/cmte-h-big-data-artificial-intelligence-wg-map-ai-model-bulletin.pdf is STALE ("Status as of April 1, 2026"), while content.naic.org/sites/default/files/legal-adoption-map-ai-model-bulletin.pdf carried the current 6 August 2026 status this round. Check the status line before quoting either.

guidance2026-05

Connecticut General Assembly — 2026 session outcome for AI legislation (enacted and failed)

Verified from the CGA bill-status records this round. ENACTED: SB 5 became Public Act 26-15 ("An Act Concerning Online Safety", Approved 27 May 2026, 39 sections, 74 pages); SB 4 became Public Act 26-64 ("An Act Concerning Consumer Privacy and Protection", Approved 27 May 2026); HB 5312 became Public Act 26-55 (Public Act designation 14 May 2026, signed 26 May 2026). FAILED: HB 5342, the election-deepfake bill restricting distribution of manipulated images, audio or video within 90 days of an election, reached "Tabled for the Calendar, House" on 20 April 2026 after a Judiciary joint favorable report and went no further before the session adjourned sine die on 6 May 2026 — Connecticut therefore has NO election-synthetic-media statute. Also still not law: SB 2 (2025), the Colorado-style high-risk-AI bill, which passed the Senate in 2025 and died in the House; its "duty of care against algorithmic discrimination" and developer/deployer impact-assessment architecture exists nowhere in Connecticut law. Monitoring lesson consistent with other states: Connecticut's AI duties arrived inside acts titled "Online Safety" and "Consumer Privacy and Protection", so a title or keyword scan of enacted bills would have missed all of them — only enrolled text settles it.

guidance2024-02

Connecticut Insurance Department — Bulletin MC-25 supersedes the April 2022 big-data notice

Read from the bulletin PDF itself this round. MC-25 opens: "This Bulletin updates and replaces the Department's Notice issued on April 20, 2022, concerning the usage of big data and avoidance of discriminatory practices." So the 2022 notice is NOT a separate live obligation to track — it is superseded. The bulletin is addressed to all insurers licensed to do business in Connecticut, adopts the NAIC model expectations for an AI Systems Programme, and carries the Connecticut-specific addition that domestic insurers must complete the Artificial Intelligence Certification "due on or before September 1, 2024, and annually thereafter", filed through the Department's catalog.state.ct.us data-certification application, with a written description required where an insurer certifies compliance by alternative means.

guidance2024-12

Connecticut AG — CTDPA Year-One Enforcement Report (2024)

Connecticut AG published its first annual enforcement report under the CTDPA. The report identified the most common deficiencies as: (1) missing or inadequate privacy policy disclosures of profiling and ADM, (2) failure to honor opt-out requests for sale and targeted advertising, (3) failure to obtain consent for sensitive-data processing including biometric and inferred-health data. The AG signaled that profiling-and-ADM enforcement will be a 2025-2026 priority.

Key Case Law & Precedent

California AG — Sephora CCPA enforcement (2022)

California Department of Justice · 2022

$1.2M settlement against Sephora for selling consumer data without disclosure and failing to honor Global Privacy Control signals. Connecticut AG's CTDPA enforcement framework explicitly cites Sephora as the model for Connecticut's profiling-disclosure and opt-out-honoring expectations under CTDPA §10. Connecticut is among the states that has accepted GPC as a valid universal opt-out signal.

Outcome: $1.2M settlement, restitution, injunctive relief

Case reference

Industry Playbooks covering Connecticut AI & Data Privacy Stack — PA 26-15 (AI/Online Safety), PA 26-64 (Privacy/Surveillance Pricing), CTDPA as amended by PA 25-113, CID Bulletin MC-25

These industry playbooks include jurisdiction-specific checklist items and guidance for Connecticut AI & Data Privacy Stack — PA 26-15 (AI/Online Safety), PA 26-64 (Privacy/Surveillance Pricing), CTDPA as amended by PA 25-113, CID Bulletin MC-25.

Frequently Asked Questions

Does Connecticut AI & Data Privacy Stack — PA 26-15 (AI/Online Safety), PA 26-64 (Privacy/Surveillance Pricing), CTDPA as amended by PA 25-113, CID Bulletin MC-25 apply to my business?

Connecticut regulates AI through four stacked instruments, three of which are already in force and one of which lands on 1 October 2026. (1) PUBLIC ACT 26-15 (Substitute SB 5, "An Act Concerning Online Safety", Approved 27 May 2026) is Connecticut's… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Connecticut AI & Data Privacy Stack — PA 26-15 (AI/Online Safety), PA 26-64 (Privacy/Surveillance Pricing), CTDPA as amended by PA 25-113, CID Bulletin MC-25 is: CUTPA (the enforcement route for the CTDPA, PA 26-15 §§ 1, 8-11, 15 and PA 26-64): up to $5,000 per willful violation of § 42-110b and up to $25,000 for violating an injunction (Conn. Gen. Stat. § 42-110o, findlaw text "Current as of January 01, 2025"); AG-exclusive, no private right of action. PA 26-15 § 2 (frontier-developer whistleblower duties) carries its own civil penalty of up to $1,000 per violation recoverable by the AG in Hartford Superior Court, plus investigation costs, expert fees and attorney's fees. Insurance: CUIPA penalties of up to $5,000 per act ($50,000 aggregate) for non-willful and up to $25,000 per act ($250,000 per six months) for willful violations, plus licence suspension or revocation (Conn. Gen. Stat. § 38a-817, same findlaw stamp).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Connecticut AI & Data Privacy Stack — PA 26-15 (AI/Online Safety), PA 26-64 (Privacy/Surveillance Pricing), CTDPA as amended by PA 25-113, CID Bulletin MC-25?

The 15 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00015-R00SB-00005-PA.PDF

Last updated: 2026-08-25 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan