Trending Issues in State AI Regulation as Seen Through Connecticut’s Omnibus AI Law (SB5)
Earlier this year, Connecticut enacted its Online Safety Act (“SB5”), now retitled the Connecticut Artificial Intelligence Responsibility and Transparency Act (the “CART Act”), which represents one of the most wide-ranging omnibus state artificial intelligence (“AI”) and online-safety laws enacted to date. The broad multi-topic nature of the law contrasts with the recent state legislative trend of more targeted laws and regulations focusing on a particular context, specific digital risk, or broadly impactful player within the AI or online ecosystem. For example, Colorado’s revised AI Act now focuses exclusively on automated decision-making technologies, a number of states (e.g., Georgia, Iowa, Nebraska) have enacted laws focused on AI chatbots, and New York and California have been engaged in rulemaking to operationalize those states’ social media focused law.
Instead, Connecticut’s legislature opted to address numerous hot topics in digital risk at the same time, including foundation model catastrophic risk, frontier lab whistleblowers, chatbot safety, engagement-optimizing algorithms, AI in employment decisions, synthetic content labeling, subscription opacity, workforce AI training, and more. The new law also includes directives to support an AI-accelerated economy. It will create a working group to study proposed legislation around various AI topics and use cases, and establish other initiatives to support the Connecticut government and economy adjusting to new realities in 2026, Anno Machinae.
The law breaks new ground with requirements such as extensive whistleblower requirements for frontier AI developers and disclosure requirements for businesses that offer subscriptions to AI tools. Significantly, SB5 reaches beyond AI regulation, such as by imposing non AI-related youth online safety requirements governing personalized social media feeds. Many of the AI companion rules may lead to age gating, or significant redesigns impacting not just specific AI companion bots but for many market LLMs as well. The law is effective October 1, 2026, but key compliance dates vary by provision, with the bulk of business-related obligations beginning in 2027. The law provides for enforcement by the Attorney General; it does not provide for a private right of action.
SB5 passed alongside Connecticut’s SB4 (“An Act Concerning Consumer Privacy and Protection”), which amends and extends the Connecticut Data Privacy Act (“CTDPA”) to include, among other things, data broker and surveillance pricing provisions. However, the Online Safety Act (SB5) covers more ground than CTDPA, as it applies to all entities doing business in Connecticut, without regard to CTDPA’s thresholds.
Key Features
AI Companions – Labeling, Mental Distress Protections and Minor-Specific Requirements
Driven by growing concerns over human-like interactions between AI tools and users, especially minors, AI companions and conversational chatbots have emerged as one of the most active areas in AI policymaking. With the passage of SB5, Connecticut joined the growing ranks of states that regulate AI companions or chatbots, with similar controls as those seen in other state laws, including New York and California. Effective January 1, 2027, SB5 requires “AI companions” that leverage AI and provide adaptive, human-like responses to user inputs and that can “sustain a relationship across multiple interactions” to notify consumers that they are interacting with an AI (if not obvious to the user) and monitor for user expressions involving suicide, self-harm, or imminent violence and, if detected, respond with references to mental health resources (e.g., 9-8-8 suicide prevention hotline). As with other similar laws, the requirements generally do not apply to AI companions used for operational purposes, customer support, for providing information about specific products or services sold by the company, or used solely for internal purposes.
SB5 imposes additional compliance obligations on operators that know, or have reason to believe, the user of an AI companion is under the age of 18. In particular, the law prohibits providing such companions to minors “if it is reasonably foreseeable that the artificial intelligence companion is capable of” a list of potentially risky or harmful activity, including “encouraging” minors to harm themselves or others or engage in illegal activity, engaging in romantic or sexually explicit interactions, providing mental health services unless specifically designed to do so and with other compliance requirements met, discouraging the user from obtaining assistance from mental health professionals or an appropriate adult, or prioritizing validation of the user’s beliefs, preferences, or desires over factual accuracy or safety. It would also prohibit youth-focused chatbots from using certain techniques to prolong extended interactions between the user and the AI companion. While there is no age verification requirement, the law provides a safe harbor for minor-specific requirements if a business “reasonably determined” that the user was at least 18 years of age. These and other requirements reflect current concerns and hot-button issues at the intersection of children’s privacy and AI.
Automated Employment-Related Decision Technologies
SB5 also imposes requirements on employers and others using automated employment-related decision technologies (“AEDT”) or “any technology that processes personal data and uses computation to generate any output … that is a substantial factor used to make or materially influence an employment-related decision” in employment contexts. Unlike similar laws in California and Colorado, SB5 does not limit the applicability of AEDT requirements to instances where a human is in the loop.
Beginning October 1, 2027, covered entities using AEDT in employment decisions must provide pre-use notices, including the trade name of the AEDT being deployed. Following California’s lead, the Act also codifies in the state’s anti-discrimination laws prohibitions on the use of AEDT in ways that unlawfully discriminate on the basis of protected characteristics, including race, religion, sex, gender identity, and disability. It expressly allows the state’s employment commission and courts to consider anti-bias testing as a potential defense to a discrimination claim premised on the use of AEDT.
The framework resembles other emerging employment-related AI laws and regulations by emphasizing transparency in use and decisions, bias mitigation, and accountability. While SB5 does not expressly mandate algorithmic impact assessments, it strongly incentivizes organizations to evaluate discriminatory impacts and maintain defensible governance controls around employment-related AI.
Provenance Data and Deep Fakes
SB5 also addresses the proliferation of deep fakes and related concerns about misinformation and fraud by requiring producers of generative AI systems with more than one million users per month (“covered providers”) to include provenance data capable of verifying the authenticity or origin of digital content in any content that is created or materially altered by such covered provider’s generative AI system, and make such data accessible to consumers, beginning October 1, 2026. In addition, the law requires covered providers to use commercially and technically reasonable methods, such as those established by the Coalition for Content Provenance and Authenticity, to make the provenance data difficult to tamper with. This will help ensure that developers of artificial intelligence systems or general-purpose artificial intelligence models capable of generating synthetic digital content ensure such outputs are marked and detectable as synthetic digital content.
Social Media Restrictions
SB5 also covers another hot topic in children’s privacy and contains restrictions on minors’ use of “covered platforms,” effectively social media platforms or a platform that “as a significant part of the services offered, recommends, selects, or prioritizes for display … media items generated or shared on a platform by users,” excluding platforms primarily facilitating sales and certain contract-based educational services. This topic is also addressed in regulations recently issued under New York’s SAFE for Kids Act and the rulemaking currently being undertaken by the California Attorney General pursuant to California’s Protecting Our Kids from Social Media Addiction Act (which a federal district court recently refused to enjoin).
Beginning January 1, 2028, Connecticut’s law will require operators of covered platforms to take certain steps before allowing a user to access any portion of a covered platform that relies on a personalized algorithm. Operators must: (i) verify, using commercially reasonable and technically feasible methods, whether the user is at least 18 years old; and (ii) for users under 18, obtain consent from the user’s parent or legal guardian and comply with additional safety requirements. Among other provisions, SB5 requires that when minor users are using the covered platforms’ services, operators display a “clear and conspicuous warning, in black lettering appearing against a white background…” that states “The Surgeon General has warned that while social media may have benefits for some young users, social media is associated with significant mental health harms and has not been proven safe for young users.”
Unless a minor’s parent or legal guardian provides consent, covered platforms must also by default limit recommendation-related notifications to the hours of 8:00 a.m. through 9:00 p.m. Eastern Time, restrict access to personalized feeds to one hour a day, and block “sensitive content,” defined broadly as “any content that … a covered platform deems to be in violation of the community standards, or any similar guidelines or standards[.]” Notably, several of these requirements resemble provisions in other state laws that have faced constitutional challenges and, in some cases, have been enjoined. Whether SB5’s provisions will be subject to similar litigation challenges remains to be seen.
AI Subscription Terms
Beginning on October 1, 2026, any person doing business in Connecticut that offers AI technology to a Connecticut consumer for a fee pursuant to a subscription must provide written notice to the consumer disclosing the key terms and conditions, and the consumer must accept in writing before entering into or renewing a subscription.
The written notice must include, at a minimum, any restrictions the provider may impose under the terms of the subscription, including any restrictions triggered by the consumer’s conduct, as well as whether the provider has discretion to limit or eliminate the consumer’s access to, or reduce the quantity or quality of, any functionality of the artificial intelligence technology offered under such subscription. In the case of a renewal, providers must disclose any limitations or provider restrictions that are new or modified from the preceding term.
Reporting and Enforcement
SB5 grants enforcement authority to the Connecticut Attorney General for several consumer-protection provisions, including AI companion requirements. The law also establishes multiple working groups, advisory bodies, and reporting obligations intended to monitor AI’s economic and societal impacts. The law does not include private right of action.
Takeaways for Organizations
With several business-facing requirements taking effect as early as October 1, 2026, organizations that deploy AI systems in Connecticut should evaluate their existing AI compliance programs against SB5’s requirements. While many of the provisions will apply only to certain players in the online and AI ecosystem, such as frontier labs, chatbot providers, social media providers, or providers of subscription-based AI technologies, there are provisions that may be relevant across the economy, depending on a business’s AI use cases. As other states weigh their own omnibus approaches, SB5 offers an example for what state AI regulation may look like, and what organizations may see more of in the future as they continue to evolve their digital risk and AI compliance programs.
This post is as of the posting date stated above. Sidley Austin LLP assumes no duty to update this post or post about any subsequent developments having a bearing on this post.

