Policy

Connecticut's Omnibus AI Law Tackles Chatbots, Employment, and Social Media

The CART Act addresses frontier model risks, AI companions for minors, automated hiring tools, and personalized feeds in one sweeping statute.

Omega Editorial· August 21, 2026· 4 min read

Connecticut has enacted one of the broadest state artificial intelligence laws to date, addressing multiple digital risks in a single omnibus statute rather than the targeted approach most states have taken.

The Connecticut Artificial Intelligence Responsibility and Transparency Act (CART Act), originally titled SB5, takes effect October 1, 2026, with most business obligations beginning in 2027. The law applies to all entities doing business in Connecticut, without the revenue or data-processing thresholds found in the state's existing data privacy act. Enforcement rests with the Attorney General; no private right of action exists.

Why it matters

While states like Colorado have narrowed AI legislation to automated decision-making and others focus on specific use cases like chatbots, Connecticut's comprehensive approach may signal a new legislative trend. Organizations operating across multiple states will need to track whether other jurisdictions follow Connecticut's model of bundling AI companion rules, employment automation requirements, deepfake provisions, and social media restrictions into single statutes—potentially creating more complex compliance landscapes than sector-specific laws.

AI companion and chatbot requirements

Starting January 1, 2027, AI companions that provide adaptive, human-like responses and sustain relationships across interactions must disclose their non-human nature when not obvious. These systems must monitor for expressions of suicide, self-harm, or imminent violence and respond with mental health resources including the 988 hotline.

For users under 18, the law prohibits AI companions reasonably foreseeable to encourage self-harm or illegal activity, engage in romantic or sexually explicit interactions, provide mental health services without proper design, discourage professional help-seeking, or prioritize validation over accuracy. Businesses receive safe harbor protection if they reasonably determined a user was at least 18. Exemptions apply for operational tools, customer support, and internal-use systems.

Automated employment decision technologies

Beginning October 1, 2027, employers using automated employment-related decision technologies (AEDT) must provide pre-use notices including the trade name of the system. Unlike similar laws in California and Colorado, Connecticut's definition does not require human involvement in the loop.

The law codifies anti-discrimination prohibitions for AEDT use based on protected characteristics including race, religion, sex, gender identity, and disability. Courts and the state employment commission may consider anti-bias testing as a defense to discrimination claims. While algorithmic impact assessments are not mandated, the framework strongly incentivizes bias evaluation and governance controls.

Provenance data and synthetic content

Generative AI systems with over one million monthly users must embed provenance data in created or materially altered content starting October 1, 2026. Providers must use commercially reasonable methods—such as Coalition for Content Provenance and Authenticity standards—to make this data tamper-resistant and accessible to consumers.

Social media platform restrictions

Effective January 1, 2028, covered platforms using personalized algorithms must verify user age and obtain parental consent for users under 18. For minors, platforms must display a Surgeon General warning about mental health harms in black text on white background.

Without parental consent, platforms must limit recommendation notifications to 8 a.m.–9 p.m. Eastern Time, restrict personalized feed access to one hour daily, and block "sensitive content" defined as anything violating community standards. These provisions resemble requirements in other state laws that have faced constitutional challenges.

Subscription disclosure requirements

Any business offering AI technology subscriptions to Connecticut consumers must provide written notice of key terms before purchase or renewal, starting October 1, 2026. Disclosures must include usage restrictions, provider discretion to limit access or reduce functionality, and any new or modified limitations for renewals.

Additional provisions

The law establishes working groups to study AI topics and initiatives supporting Connecticut's government and economy. It also includes extensive whistleblower protections for frontier AI developers and creates frameworks for workforce AI training.

These details were first reported by Sidley Austin LLP in their Data Matters blog.

#state ai regulation#connecticut cart act#ai chatbots#automated employment decisions#social media regulation#synthetic content

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Policy

Policy· 3 min read

Minnesota Attorney Suspended for AI-Generated Fake Case Citations

Faisal Ahmed cited nonexistent lawsuits in court filings, drawing a 30-day license suspension and highlighting growing judicial concerns over AI hallucinations.

Via AI Watch · Aug 21, 2026
Policy· 3 min read

PJM Grid Operator Puts AI Data Centers Last in Line for Power

New rules require facilities over 50 megawatts to prove dedicated power supply by March 2027 or face first cuts during shortages.

Via AI Watch · Aug 21, 2026
Policy· 3 min read

Southeast Asia's AI Boom May Be Short-Lived, Economists Warn

While Taiwan and Korea ride surging chip exports to record growth, regional experts say Southeast Asian nations risk getting trapped at the bottom of the value chain.

Via AI Watch · Aug 21, 2026