Connecticut’s AI law is no longer a bill to watch.
SB 5 was signed on May 27 as Public Act 26-15, and that enacted status matters because the law does not read like one abstract AI-principles document. It reads like a stack of operational rules with different effective dates, different targets, and different compliance owners.
That is probably the most useful thing about it.
Public Act 26-15 does not try to settle every AI policy fight at once. It puts real duties into places companies already understand: companion-chatbot safety, workplace decision tools, synthetic-content provenance, workforce programs, and youth-platform design. That is much closer to how AI compliance is likely to arrive in practice.
The Short Answer
- Connecticut's SB 5 is enacted as Public Act 26-15.
- The law includes staggered requirements touching AI companions, employment-related automated decision tools, provenance for certain public generative-AI systems, frontier-developer whistleblower protections, and youth-platform safeguards.
- For many businesses, the most practical near-term items are the October 1, 2026 provenance and employment provisions, the January 1, 2027 companion-chatbot safeguards, and the October 1, 2027 trigger for certain employment-tool deployment duties.
Why The Enacted Version Matters More Than The Bill Debate
A lot of AI-law coverage treats passage as the interesting moment and implementation as the footnote.
With Connecticut, the implementation is the story.
The enacted law is broad, but it is not one uniform compliance event. It is a phased package. Some parts are effective in mid-2026, some in October 2026, some in January 2027, some in October 2027, and some youth-platform provisions arrive in 2028.
That means legal teams should stop asking whether Connecticut passed "an AI law" and start asking which business function owns which date.
The Employment Piece Is One Of The Most Concrete
The workplace provisions are likely to be the most immediate operational issue for many companies.
Public Act 26-15 defines automated employment-related decision technology and sets up a developer-deployer structure for related obligations. Starting October 1, 2026, the statutory framework is in place. For deployers using covered tools on or after October 1, 2027, the law requires disclosure when an employee or applicant is interacting with such technology unless a reasonable person would think that is obvious.
Before an employment-related decision is made, the deployer must also provide written notice describing:
- that the technology has been deployed,
- the purpose of the technology and the nature of the decision,
- the trade name of the technology,
- the categories of personal data it will analyze or process and how that data will be assessed,
- the source of that data, and
- contact information for the deployer.
The law also says use of automated employment-related decision technology is not a defense to a discrimination complaint. That is a clean point legal teams should not miss.
In other words, Connecticut is not treating workplace AI as a novelty. It is treating it as another decision system that can create notice, documentation, and discrimination exposure.
The Companion-Chatbot Rules Are Not Cosmetic
Starting January 1, 2027, Connecticut adds another enacted state model for companion-style AI.
The law defines an artificial intelligence companion in a way that turns on sustained, anthropomorphic, relationship-like interaction while carving out a range of ordinary business and operational chat uses. That definitional line matters because it tries to separate companion-style consumer products from ordinary support and productivity tooling.
For covered companions, the law requires operators to use evidence-based methods to detect user expressions clearly indicating risk of suicide, self-harm, or imminent physical violence and to institute measures to prevent the system from generating outputs that encourage those harms. If such a signal is detected, the operator must refer the user to appropriate crisis resources.
The law also requires clear and conspicuous notice when a reasonable user might think they are interacting with a human rather than an AI companion. And for minor users, the law adds additional safeguards around self-harm, suicidal ideation, violence, disordered eating, alcohol, drugs, sexual exploitation, and parental management tools.
This is not just a disclosure rule. It is a product-safety and response-protocol rule.
Connecticut Also Moves On Provenance
Another part of the law, effective October 1, 2026, applies to certain publicly accessible generative-AI providers with more than one million monthly users.
That section requires covered providers, to the extent commercially and technically reasonable, to include provenance data in covered audio, image, or video content created or materially altered by the provider's generative-AI system, and to use reasonable methods to make that provenance data difficult to tamper with, remove, or separate from the content.
That matters for two reasons.
First, it shows Connecticut is willing to move beyond general transparency rhetoric into implementation detail around synthetic-content authenticity. Second, it uses a familiar enforcement model: unfair or deceptive trade practice treatment, enforced solely by the Attorney General, with no private right of action.
Frontier Developers And Internal Reporting Are In The Mix Too
The law also includes a frontier-developer section effective January 1, 2027.
Large frontier developers must maintain a reasonable internal process for anonymous reporting by covered employees who in good faith identify activity posing a specific and substantial public-health or public-safety danger tied to catastrophic risk. The law also requires updates, board-level sharing in most cases, and notice of employee rights.
That does not affect every company. It still matters as a signal.
Connecticut is treating frontier-model governance not just as a public-policy debate, but as an internal reporting, employee-protection, and documentation issue.
The Effective-Date Map Matters
The biggest practical mistake would be treating Public Act 26-15 as one single compliance date.
The rough timing looks more like this:
July 1, 2026: the Connecticut AI Academy provision takes effect.October 1, 2026: provenance rules for certain public generative-AI providers, employment-tool framework provisions, anti-discrimination clarifications, and WARN-related AI/technology layoff disclosure provisions take effect.January 1, 2027: companion-chatbot safeguards and frontier-developer reporting provisions take effect.October 1, 2027: certain automated employment-related decision technology deployment duties apply when covered tools are deployed on or after that date.January 1, 2028: certain youth-platform algorithmic and warning provisions take effect.
That timeline is why this should be treated as an inventory problem, not a headline problem.
What Companies Should Review Now
If Connecticut matters to the business, the review should be practical:
- identify whether any consumer product could fit the law's companion definition;
- identify whether any hiring or employment workflow uses tools that could materially influence a decision;
- determine whether any public generative-AI product crosses the monthly-user threshold for the provenance section;
- review vendor and internal documentation needed to support employment notices;
- map who owns self-harm response, crisis referral, and notice design for companion-style systems; and
- track which dates matter for which products, functions, and contracts.
The legal burden here is not only about whether AI is used. It is about whether the company can show where the law attaches and who owns the response.
Bottom Line
Connecticut's Public Act 26-15 is a good picture of how state AI compliance actually arrives.
Not through one giant theory of artificial intelligence, but through layered rules touching employment, companion products, provenance, internal governance, and youth-facing design. The law is enacted, the dates are staggered, and several of the duties are concrete enough that companies should already know which teams will own them.
For legal and compliance teams, that is the real lesson. State AI law is getting less theoretical and more operational.
