Illustration by tuput
English
Parts of Public Act 26-15 started applying on 1 October 2026, with fines of up to $1,000 per violation for AI labs that punish whistleblowers and Attorney General enforcement of the other duties. Several sections do not start until 2027 and 2028, and a Justice Department task force exists to challenge state AI laws.
Connecticut’s AI law, Public Act 26-15, began binding companies on 1 October 2026. From that date a developer of a very large AI model may not adopt a rule or contract that lets it punish an employee who reports a catastrophic risk, and a popular image, audio or video generator must embed provenance data in what it produces, to the extent that is commercially and technically reasonable.
The act was approved on 27 May 2026, and its sections start on different dates, from the day it passed to 1 January 2028. The CT Mirror reported on 28 September that “the bulk of enforcement power will rest with the Attorney General’s Office.”
What changed for AI labs on 1 October
The act defines a frontier developer as a business operating in Connecticut that trains, or plans to train, a foundation model using more than 10 to the power of 26 integer or floating-point operations, counting later fine-tuning. A large frontier developer is one with more than $500 million in annual revenue, counting affiliates. Our explainer on how large language models work covers the technology.
Section 2 bars a frontier developer from adopting any rule, policy or contract that lets it retaliate against an employee with reasonable cause to believe the company is engaged in activity posing a “specific and substantial danger to the public health or safety due to a catastrophic risk.” The act defines catastrophic risk as a foreseeable risk that a model will contribute to the death or serious injury of more than 50 people, or more than $1 billion in property damage, in a single incident, such as by giving expert-level help with a chemical, biological, radiological or nuclear weapon.
By 1 January 2027, each large frontier developer must run an anonymous internal reporting process, give the reporter updates, and share reports with its officers and directors at least quarterly.
The penalty is up to $1,000 per violation, collected by the Attorney General in the superior court in Hartford, which can also order injunctions.
DLA Piper’s Danny Tobey, Ashley Carr and Michael Atleson wrote on 7 May that Connecticut’s provision is “stand-alone and is not paired with a broad transparency law.” The Future of Privacy Forum’s Justine Gluck and Daniel Hales wrote that the act requires no governance frameworks, transparency reports or critical safety incident reporting, and that it borrows key definitions from California’s SB 53 and New York’s RAISE Act.
Image, audio and video generators must label their output
Section 15 covers a provider whose generative AI system has more than one million users a month and is open to consumers for personal use. Government agencies are excluded, and the definition turns on generating images, audio or video.
Such a provider must, to the extent commercially and technically reasonable, include provenance data in audio, image or video content its system creates or materially alters, and use reasonable methods, including the Coalition for Content Provenance and Authenticity standard, to make it hard to remove. The act exempts business-to-business sales, video games and systems used only for upscaling, noise reduction or compression.
Only the Attorney General can enforce it, as an unfair trade practice, and the section sets no dollar figure.
Summaries disagree on timing. DLA Piper’s 7 May alert said “By October 1, 2027, such developers must ensure that such content is marked and detectable as such.” The signed act labels Section 15 as effective 1 October 2026, and the Future of Privacy Forum and Morrison Foerster both list provenance among the October 2026 duties.
The subscription rule moved to a second law
Section 1 of the act first required notice and written acceptance before an AI subscription began or renewed. Public Act 26-100, approved on 2 June 2026, repealed it and set a narrower rule in its own Section 46, also effective 1 October 2026.
The new rule applies to a provider whose generative AI system has more than one million monthly users and is open to consumers. Before it starts or renews a subscription, it must give written notice of the key terms and the consumer must send written notice of acceptance. The notice must cover usage limits and whether the provider can cut access or reduce quality. The Attorney General alone enforces it.
The Daily Campus reported on 30 September that the rule covers AI companies “such as ChatGPT or Google AI.” The statute’s definition refers to systems that generate images, audio or video, and tuput found no Attorney General guidance on how it applies to a text chatbot that also makes images.
Hiring tools and layoff notices
Sections 7 to 12 cover software that processes personal data and produces a score, ranking or recommendation that is a substantial factor in hiring, promotion, discipline or firing. They are labelled effective 1 October 2026, but the duties apply to tools deployed on or after 1 October 2027. Employers must then tell applicants in plain language when they are dealing with such a tool, and give written notice before a decision naming the tool, its purpose and the personal data it uses. The Attorney General alone enforces these sections and, for violations through 31 December 2027, may first allow 60 days to cure. The Future of Privacy Forum notes that the act requires no bias audits.
Two employment rules did start on 1 October 2026. Under amendments to the state’s anti-discrimination statutes, using such a tool “shall not be a defense against a complaint,” though a court or the commission may weigh evidence of anti-bias testing. And an employer that files a federal WARN layoff notice with the Connecticut Labor Department must now disclose whether the layoffs relate to its use of AI or another technological change.
What waits for 2027 and 2028
AI companion chatbot rules begin on 1 January 2027. The CT Mirror reports that they require chatbots to disclose that they are not human. Protections for minors on covered social platforms begin on 1 January 2028. State Sen. James Maroney, a lead architect of the act, said at a press conference, per the CT Mirror: “This is a start. This is not a finish; this is not a ceiling. This is the floor.”
The federal task force and the one case so far
Executive Order 14365, signed on 11 December 2025, told the Attorney General to set up a task force “whose sole responsibility shall be to challenge State AI laws” inconsistent with federal policy. The Justice Department created it by memorandum on 9 January 2026. The order says its call for federal legislation should not propose preempting otherwise lawful state laws on child safety, AI data centres, or state government use of AI.
The one court action in the sources is in Colorado. On 27 April 2026 a federal magistrate judge granted a joint motion in X.AI LLC v. Weiser, a suit in which the United States is a plaintiff-intervenor. The order bars the defendant, Philip J. Weiser, from starting enforcement of Colorado’s SB24-205, for violations through 14 days after the court rules on xAI’s coming motion for a preliminary injunction. The parties agreed to the stay, and the order does not rule on the law’s validity.
None of the sources tuput reviewed through 8 October reports a federal or private challenge to Connecticut’s act. DLA Piper wrote in May that Connecticut acted “even as the federal preemption debate continues.”
The latest steps in Brussels and Delhi
The European Union’s latest binding step is Regulation (EU) 2026/1744, the Digital Omnibus on AI, dated 8 July 2026 and published in the Official Journal on 24 July. It entered into force on 27 July and moved the AI Act’s high-risk obligations to 2 December 2027 for systems listed in Annex III and 2 August 2028 for those in Annex I. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) marking duty. Gibson Dunn’s lawyers called the package “a deferral rather than a dismantling” in a 27 May alert on the political deal.
India’s most recent rule is notification G.S.R. 120(E) of 10 February 2026, amending the IT Rules, 2021, which AZB & Partners says took effect on 20 February. It defines “synthetically generated information” as audio, visual or audio-visual material made or altered by computer that appears real. Under new Rule 3(3), a platform that offers tools to create such material must block unlawful output, label the rest prominently and embed permanent metadata or another provenance mechanism, to the extent technically feasible. The takedown window for court or government orders fell from 36 hours to three. The ministry behind the rules, MeitY, also runs the Bhashini translation platform covered in India Is Building AI in Its Own Languages.
MediaNama reports a further MeitY advisory dated 8 October 2026, signed by Joint Secretary Ajit Kumar, asking social media platforms to apply “enhanced diligence” to false or manipulated content and to label or contextualise it. MediaNama notes that it lists no penalties and does not refer to the February amendment, and does not say whether it binds.
Dates still ahead
- 2 December 2026: the EU’s Article 50(2) marking duty for older generative systems, and its new ban on systems that generate non-consensual intimate imagery or child sexual abuse material, both apply.
- 1 January 2027: Connecticut’s large-developer reporting channels and companion chatbot rules start.
- 1 October 2027: Connecticut’s hiring-tool duties apply to tools deployed from then.
- 2 December 2027: the EU’s Annex III high-risk obligations start to apply.
- 1 January 2028: Connecticut’s social media rules for minors start.
Sources & further reading
- Connecticut General Assembly: Substitute Senate Bill No. 5, Public Act No. 26-15, An Act Concerning Online Safety (approved 27 May 2026)
- Connecticut General Assembly: Substitute House Bill No. 5222, Public Act No. 26-100 (approved 2 June 2026)
- The White House: Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence (11 December 2025)
- US Department of Justice: Memorandum from the Attorney General, Artificial Intelligence Litigation Task Force (9 January 2026)
- US District Court for the District of Colorado: Minute Order, X.AI LLC v. Weiser, Civil Action No. 26-cv-01515 (27 April 2026)
- EUR-Lex: Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI (Official Journal, 24 July 2026)
- Ministry of Electronics and Information Technology: IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, updated as on 10.02.2026
- Future of Privacy Forum: SB 5 in Five, What to Know About Connecticut's New AI Law (27 May 2026)
- DLA Piper: Unpacking SB5, Connecticut's new AI law (7 May 2026)
- Morrison Foerster: Connecticut Enacts Sweeping AI Law Covering Online Safety, AI Companions, and Employment AI (June 2026)
- CT Mirror: New CT AI, data privacy laws go into effect Oct. 1 (28 September 2026)
- The Daily Campus: New AI regulation law goes into effect Oct. 1 (30 September 2026)
- Gibson Dunn: EU AI Act Omnibus Agreement, Postponed High-Risk Deadlines and Other Key Changes (27 May 2026)
- AZB & Partners: India's New Law Governing Synthetic Media
- MediaNama: MeitY widens labelling for social media beyond synthetic content (October 2026)
Researched and written with the help of AI tools and edited for accuracy. Provided for general information and discussion only, not professional advice. See our editorial standards and disclaimer. Spotted an error? Tell us.
Enjoyed this? Get the next one.
One good read at a time, straight to your inbox. No spam, unsubscribe anytime.