US AI regulation

Connecticut's CART Act Gets the Whistleblower Rules Right, but Its Surveillance-Pricing Label Is a Blunt Tool

Connecticut's first AI and privacy provisions took effect Oct. 1. The narrow, enforceable ones are defensible; the broad pricing and subscription mandates deserve scrutiny.

Connecticut's CART Act by the numbers People of Internet Research · US 10^26 ops Frontier compute threshold Whistleblower duties apply only to… 60 days Cure period for violations Affirmative defense for firms usin… $1,000 Civil penalty per violation Maximum for frontier-duty violatio… 1M users Subscription rule user threshold Narrowed rule covers generative me… peopleofinternet.com
Connecticut's CART Act by the numbers People of Internet Research · US 10^26 ops Frontier compute threshold 60 days Cure period for violations $1,000 Civil penalty per violation 1M users Subscription rule user threshold peopleofinternet.com

Key Takeaways

On October 1, 2026, the first provisions of Connecticut's CART Act (Public Act 26-15, Senate Bill 5) and its companion privacy expansion (Public Act 26-64, Senate Bill 4) became enforceable. The CT Mirror reports that they cover whistleblower protections for people working on large frontier AI models, disclosure rules for AI subscriptions, and limits on facial recognition and surveillance pricing. Chatbot rules follow on January 1, 2027, and youth social-media rules on January 1, 2028. Sen. James Maroney called the package "the floor," not a ceiling.

That framing matters, because Connecticut is legislating in the middle of a federal fight over who gets to regulate AI.

The case for Connecticut acting

The strongest argument for the state is that Washington has not acted. Gov. Ned Lamont said when signing Public Act 26-15: "We can no longer wait for Washington, D.C. to do the right thing and enact protections over these digital tools." Congress has passed no comprehensive AI statute, and people inside AI labs have few legal channels for raising safety concerns. Surveillance pricing, where personal data is used to set individualized prices, is hard for consumers to detect and so is a plausible market failure. Pro-innovation does not mean pro-opacity.

That case is strongest for the narrowest part of the law: frontier-developer whistleblower protections.

What the law actually requires

According to Faegre Drinker's summary, the whistleblower provisions apply to developers training models above 10^26 operations. They protect employees who report "catastrophic risks," defined as 50 or more deaths or serious injuries, or $1 billion or more in property damage. The Attorney General is the exclusive enforcer. The statute creates a rebuttable presumption of reasonable care for compliant entities. It also gives an affirmative defense to organizations that follow recognized frameworks such as NIST or ISO/IEC 42001, conduct red-teaming, and cure violations within 60 days.

This is close to the right design. The compute threshold limits the law to a handful of firms. The harm definition is specific. The safe harbor rewards firms that adopt voluntary standards instead of punishing them for it. Vorp Labs' analysis reports civil penalties of up to $1,000 per violation, which is modest, and no private right of action. Internal anonymous reporting channels for large developers are not due until January 1, 2027. Protecting employees who speak up costs little and raises the odds that a real hazard is caught early, without dictating how anyone builds a model.

Where the design is weaker

The privacy side is broader. Carmody Law's summary says Public Act 26-64 adds consumer rights to access, correct, delete and opt out, and restricts "surveillance pricing." It also requires the disclosure "THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA" on affected prices. Data-broker registration begins January 1, 2027.

The label has three problems.

The subscription rule shows a similar drift. Vorp Labs reports that Public Act 26-100, enacted June 2, 2026, narrowed it to generative systems that produce images, audio or video, exceed one million monthly users, and are sold by subscription. That is a better rule than the original. But it is still a billing-disclosure requirement that existing consumer-protection law already arguably covers.

The act also creates an AI regulatory sandbox, per the governor's office. That is the right instinct, and its value will depend on whether regulators actually use it to grant relief.

The federal shadow

The larger risk is fragmentation. On December 11, 2025, the White House issued Executive Order 14365. It calls for a "minimally burdensome national standard" and directs the Attorney General to set up a task force to challenge state AI laws. It also directs Commerce to identify "onerous" state laws and ties some broadband funding to state compliance. The order's carve-outs include child safety, data center infrastructure and state procurement. An executive order cannot itself preempt state law, so Connecticut's statute stands unless Congress or a court says otherwise.

That gives Connecticut's design some defensibility. The pieces most likely to survive a preemption challenge are the narrow, harm-specific ones: whistleblower protection, the minors' provisions and the sandbox. The pieces most exposed to legal and compliance friction are the broad pricing and subscription mandates, which a company operating nationally must reconcile with other states' rules.

What to watch

Three tests will show whether this is proportionate regulation or a template for overreach:

  1. Enforcement restraint. The Attorney General holds sole enforcement power. Early actions should target actual concealment of catastrophic risk, not technical label violations.
  2. Whether the cure period and safe harbor are honored. If recognized frameworks count in practice, firms have a reason to adopt them.
  3. Whether other states copy the narrow or the broad provisions. Copying the whistleblower rule would add a safety net. Copying a patchwork of conflicting price labels would add cost with little benefit.

Connecticut has done the most defensible thing first. The sensible next step is to leave the broader rules open to revision once the first year of enforcement shows what they cost and what they protect.

Sources & Citations

  1. CT Mirror: New CT AI, data privacy laws go into effect Oct. 1
  2. Governor Lamont signs Public Act 26-15 (ct.gov)
  3. White House: Executive Order 14365 on national AI policy
  4. Faegre Drinker: Connecticut enacts comprehensive AI regulation
  5. Carmody Law: Effective October 1, 2026 data privacy and AI laws
  6. Vorp Labs: Connecticut CART Act analysis