惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
Recent Announcements
Recent Announcements
雷峰网
雷峰网
The GitHub Blog
The GitHub Blog
罗磊的独立博客
月光博客
月光博客
J
Java Code Geeks
A
About on SuperTechFans
Microsoft Security Blog
Microsoft Security Blog
D
Docker
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
F
Fortinet All Blogs
U
Unit 42
C
Check Point Blog
Martin Fowler
Martin Fowler
有赞技术团队
有赞技术团队
博客园 - 叶小钗
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
酷 壳 – CoolShell
酷 壳 – CoolShell
Blog — PlanetScale
Blog — PlanetScale
大猫的无限游戏
大猫的无限游戏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
阮一峰的网络日志
阮一峰的网络日志
MyScale Blog
MyScale Blog

Privacy & Cybersecurity Law Blog

FTC Rescinds 2021 Policy Statement on Health App Data Breaches EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays
Connecticut Signs Comprehensive AI Bill into Law
2026-06-11 · via Privacy & Cybersecurity Law Blog

On May 27, 2026, Connecticut enacted a comprehensive state artificial intelligence law, Substitute Senate Bill No. 5 (Public Act No. 26-15) (the “Act”), establishing several regulatory frameworks that address companion chatbots, frontier model governance, and AI use in employment decisions, among other topics. The effective dates are staggered beginning in October 2026. Key provisions of the Act are described below.

AI Companion Safeguards

Operators must implement protocols to detect and respond to user expressions of self-harm, prevent outputs that encourage harm, and avoid anthropomorphic deception. Operators of AI companions that could reasonably be mistaken for human users must clearly disclose that the user is interacting with AI. This disclosure must be either continuously visible throughout the interaction or provided at defined intervals: at the start of the first interaction during any twenty-four hour period and, during a continuous interaction, at least hourly for minors and every three hours for adults.

The Act also requires operators to implement additional safeguards for users the operator knows or has reason to believe are minors, including preventing certain types of interactions with the AI companion and providing minor users and their parents or legal guardians tools to manage the minor users’ screen time and account settings.

Frontier Model Governance

The Act defines “frontier developer” using a compute-based threshold broadly similar to California’s and covers persons who train or intend to train foundation models using computing power greater than 10^26 integer or floating-point operations. Unlike California’s law, the compute-based threshold is included in the definition of “frontier developer” rather than in a standalone definition of a “frontier model.”

The Act distinguishes between “frontier developers” and “large frontier developers,” imposing baseline whistleblower protections on all frontier developers while reserving more robust governance obligations for large frontier developers (defined as those with more than $500 million in annual gross revenue).

Specifically, all frontier developers are prohibited from retaliating against employees who report risks associated with catastrophic outcomes and must provide clear notice of employee rights under the statute. Large frontier developers must establish formal internal reporting systems by January 1, 2027, including anonymous reporting channels for covered employees, obligations to provide updates on investigations and mitigation actions, and quarterly reporting of such matters to officers and directors.

AI in Employment Decisions

The Act requires employers to disclose when employers or applicants are interacting with automated employment-related decision technologies, unless that fact would be obvious to the reasonable person. In addition, before any such technology may be used to generate any output for the purpose of making (or as a substantial factor in making) an employment-related decision concerning an employee or applicant, employers must provide the employee or applicant with a notice that lets the employee or applicant know that the employer has deployed such technology and includes information about the technology, including the technology’s name and purpose, the nature of the decision, the categories of personal data the technology will process, how such data will be assessed in reaching a decision, the sources of such data, and the employer’s contact information.

Generative AI Provenance

Covered providers (defined as any person who produces a generative AI system with more than 1 million users per month that is publicly accessible to consumers for personal use) must, where commercially and technically feasible, embed metadata or similar signals to allow users to identify AI-generated or materially altered content.

Disclosures for AI Subscriptions

Subscription-based providers are prohibited from entering into or renewing subscriptions for AI technology without first providing consumers with written notice disclosing the key terms and conditions of the subscription and receiving written notice from the consumer that such consumer has accepted the key terms and conditions of the subscription.

Regulatory Sandbox Program and Enforcement

The Act directs the Connecticut Commissioner of Economic and Community Development to develop a plan to establish an AI regulatory sandbox program to allow testing of innovative products or services on a limited basis under reduced regulatory and other legal requirements under Connecticut law.

Enforcement authority rests primarily with the Connecticut Attorney General.