A pair of laws governing artificial intelligence and data privacy will take effect in Connecticut Thursday (Oct. 1), introducing a new compliance regime for businesses operating in the state.
The Connecticut Artificial Intelligence Responsibility and Transparency, or CART, Act requires new AI subscription disclosures, protections for whistleblowers working on large frontier models and introduces new statutory definitions establishing what technologies fall within the regulatory framework. Connecticut’s consumer protection legislation also requires generative AI subscription providers to give consumers written notice of key subscription terms and obtain written acceptance.
Companion legislation expands the Connecticut Data Privacy Act, adding a new data broker regulatory framework, prohibiting the sale of Connecticut residents’ genetic information and places restrictions on facial recognition, precise geolocation and personalized algorithmic pricing. The pricing provision aligns Connecticut with California, New York and Maryland, each of which have also enacted restrictions on the use of personal data to set prices on goods, rent and other transactions.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
Among the biggest changes affecting businesses are new rules regarding the use of automated employment decision processes. Applicants and employees must receive plain-language notice about when and how AI has been used in employment decisions. Critically under the law, the use of such systems does not insulate an employer from discrimination liability. Reyling on a third-party hiring algorithm does not outsource the associated legal risk.
While those provisions take effect this week, additional AI-related requirements are scheduled to take effect in 2027 and 2028. Beginning Jan. 1, 2027, companies must alert chatbot users that they are not interacting with a human, and must implement new safeguards concerning suicide, self-harm and interactions with minors. Additional youth-related social media provisions follow on Jan. 1, 2028, including parental controls and new default setting requirements that will limit when minors receive notifications, as well as limits on what information platforms can display to younger users.
Although a number of state agencies are responsible for different portions of the laws, the bulk of the enforcement power will rest with the Attorney General’s Office.
According to CT Mirror, the legislature is already considering new regulations to address other uses of artificial intelligence and those that may develop in the future.
“This is a start. This is not a finish; this is not a ceiling. This is the floor,” Sen. James Maroney, D-Milford, co-chairman of the legislature’s General Law Committee and lead architect of the new AI and data privacy regulations, said during a recent press conference, per CT Mirror. “It’s just a start and we know we have a lot more to do.”
That means companies operating in Connecticut will need to conduct an artificial intelligence use case inventory rather than simply an inventory of AI systems. They’ll need to identify where AI or personal data they collect touches hiring, pricing, facial recognition, consumer subscriptions, geolocation, genetic information and interactions with minors.
In addition, they should map each use case to the effective date of the relevant regulation, review consumer and employee notices, review AI/data vendors and contractual allocations of responsibility, and document human oversight of automated employment decisions.