Effective soonSB 5 (2026); predecessor SB 2 (2025)

Connecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions): Compliance Checklist

A practical checklist of the main obligations to satisfy under this law.

Compliance checklist

Run through these items to scope your obligations under Connecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions). Not legal advice; verify with counsel before acting.

  1. Confirm scope: does the law apply to your operations? See Who Must Comply or use the Compliance Checker.
  2. Inventory in-scope AI systems and classify them by role (developer/deployer) and decision type.
  3. Address each obligation:
    • transparencyOn and after October 1, 2026, a subscription-based provider that creates, codes, or otherwise produces a generative AI system with more than 1,000,000 monthly users and public accessibility to consumers for personal use must provide the generative-AI subscription disclosure required by Public Act 26-100 Section 46 (which replaced the original Public Act 26-15 subscription provisions). The duty is enforced solely by the Attorney General as a Connecticut Unfair Trade Practices Act (CUTPA) violation, with no private right of action.Public Act 26-100 § 46 (revising Public Act 26-15 / Sub. SB 5)
    • disclosureOn and after October 1, 2026, an employer that conducts a layoff substantially caused or contributed to by an artificial intelligence system must provide the AI-related layoff notice required by Public Act 26-15. This is one of the earliest-effective private-sector duties in the Connecticut package and applies alongside the state's existing separation and mass-layoff notice obligations.Public Act 26-15 (Sub. SB 5, An Act Concerning Online Safety)
    • governanceOn and after January 1, 2027, a large frontier-model developer must establish an anonymous whistleblower reporting channel through which employees and contractors can report critical AI risks. Violations of the frontier-developer whistleblower provisions carry a civil penalty of up to $1,000 per violation plus injunctive and equitable remedies, distinct from the CUTPA/Attorney-General model that governs most other provisions of the Act.Public Act 26-15 (Sub. SB 5) — frontier-developer provisions
    • consumer rightOn and after January 1, 2027, an operator of an AI companion (a system designed to simulate sustained human-like relationships with a user) must implement the Act's chatbot safety provisions, including protections for minors. These operator duties sit within the Act's broader youth online-safety framework and are enforced by the Attorney General as CUTPA violations.Public Act 26-15 (Sub. SB 5) — AI companion provisions
    • disclosureFor deployments of automated employment-related decision technology (AEDT) on or after October 1, 2027, a deployer must provide the Act's interactive disclosures and pre-decision written notice to affected individuals. The Attorney General may issue a 60-day cure notice for AEDT violations occurring through December 31, 2027, so the earliest AEDT-specific compliance work is a 2027 program task rather than a 2026 one.Public Act 26-15 (Sub. SB 5) — AEDT provisions
  4. Adopt a federal control framework: NIST AI RMF or ISO/IEC 42001 to demonstrate due care.
  5. Document evidence of compliance for each obligation, refreshed at the cadence the law requires.
  6. Build the AG-notification path if the law requires it (Colorado, California SB 53).
  7. Set the refresh cadence — annual for most impact-assessment regimes; continuous for monitoring.
More on this law

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.