39 Sections, One Signature: Connecticut's Sweeping AI Law Goes Live October 1
Public Act 26-15 takes effect today, imposing AI disclosure duties on layoffs, provenance watermarking on big generative AI providers, and frontier-lab whistleblower protections — with chatbot and employment rules phasing in through 2028.
For most of 2026, the loudest AI policy fights played out in California and Washington, D.C. But on October 1, 2026, a 39-section bill signed quietly in Hartford in May becomes binding law — and the first concrete obligations inside Connecticut’s Public Act 26-15, better known as SB 5, start attaching to companies that operate in the state. If your business uses AI to screen job candidates, generate content for more than a million monthly users, or run mass layoffs connected to automation, today is the day the grace period ends.
What actually takes effect today
SB 5 phases in over roughly two years, and the October 1, 2026 tranche is a mixed bag of obligations spanning four different areas of AI activity.
AI-linked layoff disclosures. Any employer issuing a plant-closing or mass-layoff notice under the federal WARN Act in Connecticut must now disclose to the state Department of Labor whether the workforce reduction is connected to the employer’s use of AI or other technological displacement. It is a narrow requirement — it compels disclosure, not restraint — but it creates the first systematic state-level data trail connecting AI adoption to job losses. Economists and legislators elsewhere will be watching that dataset closely.
AI content provenance for large providers. Covered providers that operate publicly accessible generative AI systems with more than one million monthly users must now embed provenance data in content that is created or materially altered by their systems. The requirement excludes minor edits like resizing or color adjustments, and providers do not have to embed data tied to identifiable individuals, trade secrets, or confidential information. But the provenance data that is embedded must be, in the law’s words, difficult to tamper with or remove. Connecticut thus joins California, Utah, and Washington in the small but growing club of states mandating machine-readable AI content labeling.
Frontier-lab whistleblower protections. SB 5 borrows vocabulary from frontier AI statutes like California’s SB 53 and New York’s RAISE Act — defining “frontier developer,” “large frontier developer,” and “catastrophic risk” — but stops short of those laws’ fuller architecture. There is no mandate to publish governance frameworks or transparency reports. Instead, the law prohibits frontier developers from retaliating against employees who report, with reasonable cause, conduct they believe poses a specific and substantial danger to public health or safety due to a catastrophic risk. Large frontier developers face an additional deadline: by January 1, 2027, they must stand up an internal anonymous reporting process, provide updates to reporting employees, share reports with their boards quarterly, and notify staff of their rights.
A key employment milestone. October 1 also marks the start of the law’s employment-AI clock: the transparency obligations for automated employment decision technologies (AEDTs) apply to systems deployed on or after today, with developer and deployer notice duties for those tools taking effect October 1, 2027.
The chatbot rules arrive January 1, 2027
The provisions drawing the most public attention — companion chatbot safeguards — are not among the items going live today. They arrive on January 1, 2027, alongside the framework’s core design rules.
For all users, operators of AI companion systems will need to publicly post safety protocols that use “evidence-based methods” to detect and “clinical best practices” to respond to expressions of suicidal ideation, self-harm, or violence. Operators must also clearly disclose non-human identity when a chatbot could reasonably be mistaken for a person — with a one-hour disclosure interval for minors and a three-hour interval for adults, an approach drawn from Washington’s and Georgia’s statutes.
For minors, the obligations go deeper into product design. Operators that know or have reason to believe a user is under 18 must prevent companion chatbots from encouraging disordered eating or physical violence, from romantic interactions, and from manipulative engagement-extending techniques such as encouraging isolation from family or fostering “inappropriate emotional dependence.” A broader catch-all prohibits optimizing engagement in any manner that disregards those safeguards. Parents and minors must get tools to manage screen time and account settings. Violations are enforced by the Attorney General as unfair or deceptive trade practices — no private right of action.
Connecticut is the ninth state to regulate companion chatbots in some form, following New York, California, Washington, Oregon, Nebraska, Idaho, Iowa, and Georgia, according to the Future of Privacy Forum’s tracking.
Employment AI: notice-first, not audit-first
The employment section is deliberately lighter than New York City’s Local Law 144 or the original 2024 Colorado AI Act. Connecticut does not require bias audits or impact assessments of AEDTs. What it requires is disclosure, allocated across the AI value chain: from October 1, 2027, developers marketing AEDTs for hiring, promotion, discipline, or discharge must give deployers information about the tool, and deployers must tell applicants and employees that the tool is in use, its purpose, its trade name, the categories of personal data it consumes, and a contact point.
But notice-first is not notice-only. SB 5 also amends Connecticut’s fair employment statute to make clear that using an AEDT is not a defense to a discrimination claim — while allowing courts to weigh evidence of anti-bias testing when evaluating those claims. The practical read: testing is not mandated, but skipping it now carries real litigation risk. Enforcement sits with the Attorney General, with a 60-day cure period available through the end of 2027.
Why it matters beyond Connecticut
Connecticut is a small state, but SB 5 is one of the broadest single AI packages any state has enacted — companion chatbots, employment AI, AI provenance, frontier-lab whistleblowing, and social media safety for minors, all stitched into one act. Its staggered effective dates (October 2026 through January 2028) also make it a live experiment in whether phased, issue-specific regulation works better than the comprehensive-framework approach that collapsed in Connecticut’s own legislature a year earlier, when Governor Ned Lamont threatened to veto SB 2 over innovation concerns.
Two design choices deserve particular attention. First, the layoff-disclosure requirement creates something the federal government has never produced: a state-level ledger explicitly attributing job cuts to AI deployment. Second, the whistleblower provisions, though narrower than California’s, extend the reach of frontier-lab safety reporting obligations to employees of any developer meeting the definition — a population that includes contractors and researchers embedded in the largest training runs.
For companies, the compliance calculus is now genuinely multistate. A generative AI provider with a million monthly users faces provenance rules in four states with four different technical expectations. An employer using algorithmic hiring tools faces a patchwork where New York City demands audits, Colorado demands impact assessments, and Connecticut demands disclosure layered on top of its existing discrimination jurisprudence. That divergence is precisely the compliance friction that industry groups cite when arguing for a single federal standard — and precisely the experimentation that state legislators defend as the point of federalism.
The remaining tranches are already scheduled: chatbot safeguards and large-frontier-developer internal reporting processes on January 1, 2027; AEDT developer and deployer notices on October 1, 2027; and the social media minor-safety provisions, including a default one-hour daily cap on personalized recommender systems for minors, on January 1, 2028. A plan for an AI regulatory sandbox — potentially reciprocal with other states — is due from the Commissioner of Economic and Community Development by January 1, 2028.
SB 5 will not settle the national argument over AI regulation. But as of today, it is on the books, and its first obligations are enforceable.
Sources
- [1] https://fpf.org/blog/sb-5-in-five-what-to-know-about-connecticuts-new-ai-law/
- [2] https://www.cga.ct.gov/2026/act/Pa/pdf/2026PA-00015-R00SB-00005-PA.PDF
- [3] https://www.ropesgray.com/en/insights/alerts/2026/06/connecticut-enacts-sweeping-ai-law-covering-employment-healthcare-and-online-safety
- [4] https://ctnewsjunkie.com/2026/09/17/new-laws-go-into-effect-oct-1-regulating-ai-chatbots-protecting-whistleblowers/
- [5] https://www.ogletree.com/insights-resources/blog-posts/new-connecticut-law-restricts-employer-ai-use-mandates-notice-for-ai-caused-rifs/