Connecticut businesses and employers should be reminded that as of October 1, 2026, many Public Acts from the Connecticut 2026 legislative session take effect, altering obligations around data privacy and AI. 

Key Takeaways for Businesses

  • Businesses face increased compliance demands regarding consumer data privacy rights and surveillance pricing protections: Businesses must comply with expanded consumer privacy protections under Connecticut law, including broader rights to access, delete, and opt out of certain uses of personal data, as well as new protections against “surveillance pricing” practices that use consumer data to personalize or increase prices.
  • Determine if consumer-facing AI solutions meet “AI companion” definition and build in age verification processes: Companies with “AI companions” should review their disclosures and safeguards for users (particularly minors). Create an age verification process, as operators who know or have reason to believe a user is a minor face more obligations.
  • Employers face increased scrutiny over workplace AI systems: Employers using AI in hiring, promotion, discipline, productivity monitoring, or workforce management should determine if they bear a disclosure duty and implement notice procedures, bias assessments, documentation practices, and internal AI governance programs.
  • Employee monitoring requirements are changing: Public Act 26-73 expands Connecticut’s electronic monitoring law requiring employers to identify monitored workplace locations, post notices in monitored areas, and provide written notices to certain prospective employees.

Public Act 26-64 Signals Major Changes for Businesses Handling Consumer Data in Connecticut

Connecticut Public Act 26-64, “An Act Concerning Consumer Privacy and Protection” amends and expands upon the Connecticut Data Privacy Act (CTDPA) with an effective date of October 1, 2026.

Key Takeaways for Businesses

  • New Data Broker Registration Requirements: Businesses that sell or license consumer data may need to register annually with the Connecticut Department of Consumer Protection beginning January 1, 2027. Registered data brokers must pay annual registration fees, maintain compliant privacy policies, disclose data collection practices and publicly explain how consumers can exercise privacy rights.
  • Statewide Consumer Deletion Mechanism: Connecticut will create a first-of-its-kind centralized system allowing consumers to request deletion of their data from registered data brokers. Businesses will need processes to review and comply with deletion requests according to the law’s standards, which include reviewing deletion requests every 45 days.
  • Expanded Consumer Privacy Rights: Businesses must comply with consumer data privacy rights such as broader rights to access, correct, delete, and opt out of certain uses of their personal data, including profiling and targeted advertising.
  • Increased Scrutiny on AI and Profiling: Businesses using AI or automated decision-making tools for hiring, lending, housing, insurance, education, or health care decisions should review profiling practices, disclosures, governance controls, and impact assessment procedures.
  • Ban on Sale of Precise Geolocation Data: Businesses and third parties are prohibited from selling consumers’ precise geolocation data.
  • New Restrictions on Surveillance Pricing: The public act restricts certain personalized pricing practices based on consumer tracking or behavioral data and imposes disclosure requirements for some AI-driven pricing tools. A business using dynamic pricing may need to provide a disclosure such as, “THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA.” Marketing teams will not find this language ideal, but it is an express requirement. Moreover, forms of “surveillance pricing” based on specific consumer data are restricted or prohibited.
  • Heightened Compliance Expectations: Because the public act creates more data privacy requirements, businesses should review privacy notices, consent mechanisms, AI governance programs, vendor agreements, data retention and deletion practices, and pre-deployment risk assessments and post-deployment anti-bias monitoring to ensure compliance.

New AI Obligations for Connecticut Businesses and Employers in Public Act 26-15

Connecticut Public Act 26-15, “An Act Concerning Online Safety” covers the use of AI and automated decision-making tools for covered businesses and employers with many provisions taking effect on October 1, 2026.

AI Obligations for Connecticut Businesses

1. “AI Companions” Face New Restrictions
Businesses operating “AI companions” (AI with a natural language interface that provides adaptive, human-like responses and can sustain a relationship across multiple interactions) may need to:

  • Disclose that users are interacting with AI at set intervals
  • Implement safeguards for minors
  • Detect and respond to suicide or self-harm indicators
  • Restrict manipulative or harmful interactions

2. Stronger Protections for Minors Online
The public act creates some of the nation’s stricter protections involving minors and algorithmic systems. When an operator knows or has reason to believe that users are minors, requirements include:

  • Parental consent for certain algorithmic feeds
  • Prohibitions on manipulating minors into purchases or continued engagement
  • Prohibitions on romantic or sexually explicit interactions
  • Limits on notifications to minors

AI developers and providers of generative AI systems may also have additional requirements related to whistleblower protections and synthetic content provenance.  

Next Steps for Businesses

Updating disclosures, internal policies and operational governance is critical for many of the new AI and data privacy requirements. Creating an age verification process for “AI companion” users will also help with liability, as operators who know or have reason to believe a user is a minor face greater obligations. Willful blindness is not a reasonable compliance or risk management approach. Assemble a team comprised of leadership, HR, marketing, IT, and legal counsel to create new language and systems to deploy.  

AI Obligations for Connecticut Employers (Most obligations effective October 1, 2027)

For employers using AI in recruiting, hiring, promotion, discipline, compensation, or termination decisions, the Public Act 26-15 signals a significant shift toward transparency, accountability, and anti-discrimination compliance.

Public Act 26-15 is especially relevant for employers using:

  • Resume-screening software
  • AI interview analysis tools
  • Productivity-monitoring software
  • Employee profiling and scoring systems
  • Predictive analytics for promotion or retention
  • Automated scheduling or workforce management systems
  • AI-assisted disciplinary or termination recommendations

Key Takeaways for Employers

New obligations and considerations include:

  • Advance notice to applicants and employees: Employers using AI or automated decision-making tools for employment-related decisions should provide clear notice that AI is being used in the decision-making process. Before making an employment decision, deployers must provide written notice of the tool’s purpose, trade name, and the categories and sources of personal data it analyzes.
  • Anti-discrimination requirements: Like with any other tool, employers cannot use AI systems in ways that unlawfully discriminate against protected classes under Connecticut employment law. Conduct pre-deployment risk assessments and post-deployment bias monitoring for AI tools to protect organizations against AI-specific discrimination claims.
  • Recordkeeping and documentation: Employers should maintain records concerning how AI tools are used, what decisions they influence, and what steps were taken to evaluate fairness and compliance. Additionally, keep all vendor contracts on file and make sure the Data Processing Agreements (DPAs) are in order.
  • Collective bargaining considerations: Employers subject to union agreements may face restrictions on implementing AI systems in ways that conflict with collective bargaining rights or negotiated labor protections. 

Next Steps for Employers

  1. Inventory all AI and automated decision-making tools used by HR or management.
  2. Identify where AI influences employment decisions.
  3. Maintain internal documentation and review vendor documentation regarding bias testing, data processing and governance.
  4. Develop AI-use disclosure language for applicants and employees.
  5. Create internal AI governance and review procedures.
  6. Coordinate HR, legal, IT, and compliance teams on implementation.
  7. Explain and implement new procedures with employees.

To read more about how these AI obligations impact employers and HR teams, click here.  

Rules Surrounding Electronic Monitoring of Employees

Connecticut Public Act 26-73, “An Act Concerning the Electronic Surveillance of Employees” amends Connecticut’s current law, coming into effect October 1, 2026. In addition to requiring employers to provide employees with notice of the type of electronic monitoring that may occur, the new law also requires employers to:

  1. Include the specific workplace locations that may be monitored;
  2. Post a notice in the locations where monitoring may occur; and
  3. Give prospective employees hired on or after October 1, 2026, a written statement advising which activities are prohibited and may be monitored without prior written notice.

To read more about employee electronic monitoring, click here.  

Concluding Considerations

The 2026 legislative session signals the importance of data privacy and AI regulations in the state. Connecticut stands out nationwide for several of its stricter requirements and advancing its first-of-its-kind centralized data broker deletion system. With many new obligations taking effect October 1, 2026, and others a year later, businesses have reason to prepare now. As AI and data-driven technologies reshape business operations, organizations should act to establish clear policies and procedures that reduce compliance risk.

For guidance on how the new data privacy and AI laws may impact your business, please contact:

Sherwin M. Yoder, CIPP/US, CIPP/E and CIPM
Partner
203.784.3107
[email protected]

Carmody’s Technology & Data Privacy lawyers advise companies on the strategic adoption of emerging technologies, including artificial intelligence, social media, cloud platforms, IoT, and data analytics, while guiding cybersecurity risk management and the responsible collection, use, and protection of corporate and personal data.

This information is for educational purposes only to provide general information and a general understanding of the law. It does not constitute legal advice and does not establish any attorney-client relationship.