On October 1, 2026, the first provisions of Connecticut's CART Act (Public Act 26-15, Senate Bill 5) and its companion privacy expansion (Public Act 26-64, Senate Bill 4) became enforceable. The CT Mirror reports that they cover whistleblower protections for people working on large frontier AI models, disclosure rules for AI subscriptions, and limits on facial recognition and surveillance pricing. Chatbot rules follow on January 1, 2027, and youth social-media rules on January 1, 2028. Sen. James Maroney called the package "the floor," not a ceiling.
That framing matters, because Connecticut is legislating in the middle of a federal fight over who gets to regulate AI.
The case for Connecticut acting
The strongest argument for the state is that Washington has not acted. Gov. Ned Lamont said when signing Public Act 26-15: "We can no longer wait for Washington, D.C. to do the right thing and enact protections over these digital tools." Congress has passed no comprehensive AI statute, and people inside AI labs have few legal channels for raising safety concerns. Surveillance pricing, where personal data is used to set individualized prices, is hard for consumers to detect and so is a plausible market failure. Pro-innovation does not mean pro-opacity.
That case is strongest for the narrowest part of the law: frontier-developer whistleblower protections.
What the law actually requires
According to Faegre Drinker's summary, the whistleblower provisions apply to developers training models above 10^26 operations. They protect employees who report "catastrophic risks," defined as 50 or more deaths or serious injuries, or $1 billion or more in property damage. The Attorney General is the exclusive enforcer. The statute creates a rebuttable presumption of reasonable care for compliant entities. It also gives an affirmative defense to organizations that follow recognized frameworks such as NIST or ISO/IEC 42001, conduct red-teaming, and cure violations within 60 days.
This is close to the right design. The compute threshold limits the law to a handful of firms. The harm definition is specific. The safe harbor rewards firms that adopt voluntary standards instead of punishing them for it. Vorp Labs' analysis reports civil penalties of up to $1,000 per violation, which is modest, and no private right of action. Internal anonymous reporting channels for large developers are not due until January 1, 2027. Protecting employees who speak up costs little and raises the odds that a real hazard is caught early, without dictating how anyone builds a model.
Where the design is weaker
The privacy side is broader. Carmody Law's summary says Public Act 26-64 adds consumer rights to access, correct, delete and opt out, and restricts "surveillance pricing." It also requires the disclosure "THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA" on affected prices. Data-broker registration begins January 1, 2027.
The label has three problems.
- It is aimed at a harm that is hard to define. Personalized pricing includes loyalty discounts, coupons and student rates, which consumers like. A warning triggered by an "increase" invites fights over what the baseline price was.
- It may overwarn. Legally mandated warnings that appear everywhere teach people to ignore them. California's Proposition 65 is the standard example.
- It falls on small sellers. Large retailers have compliance teams. A small Connecticut online shop running an off-the-shelf pricing tool does not.
The subscription rule shows a similar drift. Vorp Labs reports that Public Act 26-100, enacted June 2, 2026, narrowed it to generative systems that produce images, audio or video, exceed one million monthly users, and are sold by subscription. That is a better rule than the original. But it is still a billing-disclosure requirement that existing consumer-protection law already arguably covers.
The act also creates an AI regulatory sandbox, per the governor's office. That is the right instinct, and its value will depend on whether regulators actually use it to grant relief.
The federal shadow
The larger risk is fragmentation. On December 11, 2025, the White House issued Executive Order 14365. It calls for a "minimally burdensome national standard" and directs the Attorney General to set up a task force to challenge state AI laws. It also directs Commerce to identify "onerous" state laws and ties some broadband funding to state compliance. The order's carve-outs include child safety, data center infrastructure and state procurement. An executive order cannot itself preempt state law, so Connecticut's statute stands unless Congress or a court says otherwise.
That gives Connecticut's design some defensibility. The pieces most likely to survive a preemption challenge are the narrow, harm-specific ones: whistleblower protection, the minors' provisions and the sandbox. The pieces most exposed to legal and compliance friction are the broad pricing and subscription mandates, which a company operating nationally must reconcile with other states' rules.
What to watch
Three tests will show whether this is proportionate regulation or a template for overreach:
- Enforcement restraint. The Attorney General holds sole enforcement power. Early actions should target actual concealment of catastrophic risk, not technical label violations.
- Whether the cure period and safe harbor are honored. If recognized frameworks count in practice, firms have a reason to adopt them.
- Whether other states copy the narrow or the broad provisions. Copying the whistleblower rule would add a safety net. Copying a patchwork of conflicting price labels would add cost with little benefit.
Connecticut has done the most defensible thing first. The sensible next step is to leave the broader rules open to revision once the first year of enforcement shows what they cost and what they protect.