Connecticut's CART Act: Inside SB5, One of the Nation's Most Comprehensive State AI Laws

· Source: Global Privacy Laws & Compliance Frameworks | ComplianceHub.Wiki · Field: Legal & Regulatory — Compliance & Risk Management, Regulatory Affairs & Government Relations · Depth: Intermediate, long

Summary

Connecticut Governor Ned Lamont signed Senate Bill 5, the Artificial Intelligence Responsibility and Transparency Act (CART Act), into law on June 2, 2026, as Public Act 26-15. This comprehensive 39-section omnibus regulates AI across employment, consumer chatbots, frontier model safety, synthetic-content provenance, and online experiences for minors. Unlike earlier proposals, CART deliberately avoids Colorado's "algorithmic discrimination" framework, focusing instead on transparency and supply-chain responsibility. The law establishes a bundle of discrete obligations with staggered compliance deadlines, beginning October 1, 2026, and extending through January 1, 2028. Key provisions include employment-related AEDT notices by October 1, 2027, "AI companion" rules by January 1, 2027, and frontier model whistleblower duties by October 1, 2026. It also mandates synthetic media marking and social media platform requirements for minors by January 1, 2028.

Key takeaway

For compliance teams navigating the expanding landscape of state AI regulations, Connecticut's CART Act demands immediate, segmented action. You must map the act's various regimes to your business and prioritize obligations with earliest effective dates, starting October 1, 2026. Rework AEDT procurement contracts for October 2027 and audit chatbots for January 2027 rules. Do not wait for the latest 2028 deadlines; your compliance work needs to begin against the earliest applicable date.

Key insights

Connecticut's CART Act establishes a broad, multi-faceted AI regulatory framework emphasizing transparency and supply-chain responsibility over algorithmic discrimination.

Principles

Method

CART allocates AI responsibility along the supply chain, requiring developers to provide deployers with compliance information or contractually assume obligations.

In practice

Topics

Best for: CTO, VP of Engineering/Data, Executive, Legal Professional, Policy Maker, Director of AI/ML

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by Global Privacy Laws & Compliance Frameworks | ComplianceHub.Wiki.