Large parts of Connecticut’s new AI law took effect on October 1. Employers that file mass-layoff notices must now tell the state whether the layoffs relate to their use of AI. Developers of the biggest AI models may not retaliate against staff who report catastrophic risks, and AI subscription services must spell out their limits before customers pay.
New to this? Read it in simple words
- Parts of a new AI law in the US state of Connecticut started on October 1.
- Big employers must say if AI was part of the reason for mass layoffs.
- Makers of the biggest AI models may not punish workers who warn about serious dangers.
- Companies that sell AI subscriptions must explain the limits before people pay.
- Whistleblower
- A worker who reports wrongdoing or danger inside their company.
- Mass layoff
- When a company lets many workers go at the same time.
- Provenance data
- Hidden information in a file that shows where it came from and how it changed.
Layoffs and AI
Employers that file a federal mass-layoff notice must now also tell Connecticut’s Labor Department whether the layoffs are related to their use of AI or another technological change. The Labor Commissioner decides the form.
The rule does not ban layoffs linked to AI. It makes Connecticut one of the first states to ask employers to say when AI is part of the reason, the law firm Nixon Peabody notes.
A change to the state’s anti-discrimination law also took effect: using an automated decision tool is no defence against a discrimination complaint. Regulators and courts may weigh evidence of anti-bias testing.
From the signed text of Public Act 26-15.
Protection for AI insiders
The law covers “frontier developers”: companies doing business in the state that train a foundation model with huge amounts of computing power, more than 10^26 operations. They may not punish employees who report activity that poses a specific and substantial danger from a catastrophic risk.
The law defines a catastrophic risk as one that could kill or seriously injure more than 50 people, or cause more than $1 billion in damage, in a single incident. Examples include expert help with chemical, biological, radiological or nuclear weapons, or a cyberattack carried out without human oversight.
By January 1, 2027, developers with more than $500 million in yearly revenue must offer an anonymous internal channel for such reports and share them with officers and directors every quarter. Breaking these rules can cost up to $1,000 per violation.
Sources1
Subscriptions and AI-made media
Companies that sell AI subscriptions to Connecticut residents must now give written notice of the key terms, including usage limits and any right to cut features, and get written acceptance before charging.
Generative AI services with more than one million monthly users that make images, audio or video must add provenance data to that content, where this is commercially and technically reasonable.
The Attorney General enforces both rules, and residents cannot sue under them. “This is the floor,” State Senator James Maroney, the law’s lead author, said of it, CT Mirror reports.
Sources
Every fact in this story comes from the sources below. Open them to check our work.
- 1Primary source · Approved May 27, 2026Public Act No. 26-15 (Substitute Senate Bill No. 5): An Act Concerning Online Safety Connecticut General Assembly
- 2
- 3Research · September 28, 2026New CT AI, data privacy laws go into effect Oct. 1. What to know CT Mirror
We read the act itself, which gives the start date of each section, and compared CT Mirror’s guide and a law firm’s summary. Some summaries written before the governor signed give other dates; where they differ, we follow the signed text.