July 1, 2026 State Privacy Deadlines: Connecticut's LLM-Training Disclosure, Neural Data, and New Rules in Arkansas and Utah
Summary
On July 1, 2026, three state privacy laws take effect, marking a significant compliance milestone. Connecticut's SB 1295 substantially amends its Data Privacy Act, lowering the consumer threshold to 35,000 and expanding sensitive data categories to include neural data, government IDs, and financial account information. Crucially, it mandates that companies disclose in privacy notices whether personal data is used for large language model (LLM) training, a novel requirement in US privacy law. Arkansas's HB 1717, the Children and Teens' Online Privacy Protection Act, introduces two-tiered consent for minors (parental for 12 and under; teen or parent for 13-16) and prohibits targeted advertising to minors. Utah's HB 418 amends the Utah Consumer Privacy Act, adding a consumer right to correct inaccurate personal data and imposing new data portability and interoperability obligations on social media platforms. These updates highlight a trend of increasing state-specific privacy innovations beyond a converging baseline.
Key takeaway
For legal professionals overseeing privacy compliance, particularly with AI initiatives, you must now conduct a thorough data inventory to identify all personal data flows feeding large language model training, both internally and via vendors. Connecticut's unique disclosure requirement means a vague privacy notice is insufficient and carries FTC deception risk. Proactively verify your data governance now to ensure accurate public statements and prepare for similar future state-level inquiries.
Key insights
Connecticut's new LLM-training disclosure mandates unprecedented transparency into AI data supply chains, forcing companies to inventory data flows.
Principles
- Privacy law scope increasingly keys to conduct, not just scale.
- Sensitive data definitions are expanding to include neurotech.
- State privacy laws are diverging beyond a common baseline.
Method
To comply with Connecticut's LLM-training disclosure, controllers must extend data inventories to include "AI/LLM training" as a processing purpose, interrogate vendor agreements for model-improvement clauses, and draft accurate, maintainable disclosures.
In practice
- Re-run applicability analysis for CTDPA's 35,000-consumer threshold.
- Re-map sensitive data for expanded categories like neural data.
- Implement two-tier consent for minors in Arkansas.
Topics
- US State Privacy Laws
- Connecticut SB 1295
- LLM Training Disclosure
- Children's Online Privacy
- Neural Data
- Data Portability
Best for: Legal Professional, Director of AI/ML, Consultant
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by Global Privacy Laws & Compliance Frameworks | ComplianceHub.Wiki.