AAI Compliance Atlas
FrameworksState lawsIndustriesToolsNews
GuidesMap my obligations →
AAI Compliance Atlas

Structured, continuously verified reference for US AI compliance — federal frameworks, state laws, and the obligations that connect them.

Atlas

  • Frameworks
  • State laws
  • Industries
  • By role
  • Comparisons

Tools

  • Compliance Checker
  • Penalty Calculator
  • Impact Assessment
  • Vendor Questionnaire

Resources

  • Guides
  • News
  • Blog
  • Methodology

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 AI Compliance Atlas. Informational only — not legal advice. Consult qualified counsel before making compliance decisions.Verified Sep 7, 2026
  1. Home/
  2. Connecticut AI laws/
  3. Connecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions)/
  4. Compliance Checklist
In effectSB 5 (2026); predecessor SB 2 (2025)

Connecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions): Compliance Checklist

A practical checklist of the main obligations to satisfy under this law.

Compliance checklist

Run through these items to scope your obligations under Connecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions). Not legal advice; verify with counsel before acting.

  1. Confirm scope: does the law apply to your operations? See Who Must Comply or use the Compliance Checker.
  2. Inventory in-scope AI systems and classify them by role (developer/deployer) and decision type.
  3. Address each obligation:
    • transparency — On and after October 1, 2026, a subscription-based provider that creates, codes, or otherwise produces a generative AI system with more than 1,000,000 monthly users and public accessibility to consumers for personal use must provide the generative-AI subscription disclosure required by Public Act 26-100 Section 46 (which replaced the original Public Act 26-15 subscription provisions). The duty is enforced solely by the Attorney General as a Connecticut Unfair Trade Practices Act (CUTPA) violation, with no private right of action.Public Act 26-100 § 46 (revising Public Act 26-15 / Sub. SB 5)
    • disclosure — On and after October 1, 2026, an employer that conducts a layoff substantially caused or contributed to by an artificial intelligence system must provide the AI-related layoff notice required by Public Act 26-15. This is one of the earliest-effective private-sector duties in the Connecticut package and applies alongside the state's existing separation and mass-layoff notice obligations.Public Act 26-15 (Sub. SB 5, An Act Concerning Online Safety)
    • governance — On and after January 1, 2027, a large frontier-model developer must establish an anonymous whistleblower reporting channel through which employees and contractors can report critical AI risks. Violations of the frontier-developer whistleblower provisions carry a civil penalty of up to $1,000 per violation plus injunctive and equitable remedies, distinct from the CUTPA/Attorney-General model that governs most other provisions of the Act.Public Act 26-15 (Sub. SB 5) — frontier-developer provisions
    • consumer right — On and after January 1, 2027, an operator of an AI companion (a system designed to simulate sustained human-like relationships with a user) must implement the Act's chatbot safety provisions, including protections for minors. These operator duties sit within the Act's broader youth online-safety framework and are enforced by the Attorney General as CUTPA violations.Public Act 26-15 (Sub. SB 5) — AI companion provisions
    • disclosure — For deployments of automated employment-related decision technology (AEDT) on or after October 1, 2027, a deployer must provide the Act's interactive disclosures and pre-decision written notice to affected individuals. The Attorney General may issue a 60-day cure notice for AEDT violations occurring through December 31, 2027, so the earliest AEDT-specific compliance work is a 2027 program task rather than a 2026 one.Public Act 26-15 (Sub. SB 5) — AEDT provisions
  4. Adopt a federal control framework: NIST AI RMF or ISO/IEC 42001 to demonstrate due care.
  5. Document evidence of compliance for each obligation, refreshed at the cadence the law requires.
  6. Build the AG-notification path if the law requires it (Colorado, California SB 53).
  7. Set the refresh cadence — annual for most impact-assessment regimes; continuous for monitoring.

Automate AI governance with OneTrust

partner link

Manage AI inventory, risk assessments, and policy enforcement across your organization. Used by hundreds of regulated enterprises.

See OneTrust AI Governance →
More on this law
  • Full law detail
  • Who Must Comply
  • Penalties
  • Disclosure Requirements
  • Impact Assessment Requirements
  • Consumer Rights
  • Enforcement Actions
Legal disclaimer

This content is informational only and does not constitute legal advice. Laws change frequently and vary by jurisdiction. Consult qualified legal counsel before making compliance decisions. Information accuracy not guaranteed as of any specific date.

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.