| Jurisdiction | Connecticut |
| Bill ID | SB 5 (2026 session) — Public Act 2026-PA-00015 |
| Sponsor (lead) | Sen. James Maroney (D), author of the original CTDPA |
| Signed by | Gov. Ned Lamont (D), 2026-05-28 |
| Status | Enacted |
Connecticut SB 5 is a 2026 state law that bundles four distinct AI regimes — frontier-model anonymous risk reporting, automated-decision disclosure for employment, AI-companion transparency, and a regulatory sandbox — into a single act. It was signed by Gov. Ned Lamont on May 28, 2026 as the broad-AI half of the 2026 Connecticut "AI + privacy" package, alongside Connecticut SB 4 — Data-broker registration + geolocation-sales ban + facial recognition (CTDPA amendment) (the data-broker / Delete-Act-style half). It contrasts with the single-purpose framing of Illinois SB 315 (frontier safety framework with mandatory third-party audits), New York RAISE Act, and California SB 53.
Status and legislative history
SB 5 is enacted as Public Act 2026-PA-00015 (Source: cga.ct.gov). Lead sponsor Sen. James Maroney (D) authored the original Connecticut Data Privacy Act (CTDPA). The 2026 act followed an earlier Maroney AI framework that nearly passed in 2024 but was killed by a veto threat from Lamont. Maroney describes SB 5 as a three-year compromise negotiated with the governor.
According to Pluribus reporting of an interview with Maroney, the 2026 version was enacted where the prior framework was not because it is paired with workforce-development and training programs, because the sandbox provision reduced developer-side opposition, and because the frontier provisions are scoped to large model developers rather than reaching small AI deployers. Maroney's own framing: "It is a start, it's not an end point. There's additional work I'd like to do, but I think this bill positions us well — particularly with the workforce development and training programs that we're building in here — to make sure our residents are prepared to compete in the AI economy."
Key provisions
Frontier-model anonymous risk reporting
SB 5 carries frontier-model reporting requirements with coverage thresholds similar to Illinois SB 315 (frontier safety framework with mandatory third-party audits). Covered developers must create reporting systems that let employees anonymously disclose risks or malfunctions discovered during model development, and must draft regular updates to company leadership on the handling of those potential risks, an internal-governance disclosure.
Where Illinois SB 315, described as the strictest U.S. state-level frontier framework as of May 2026, imposes external mandatory third-party audits, CT SB 5 imposes internal whistleblower channels and management-reporting duties, presenting two state-level approaches to surfacing frontier-model risk.
ADMT disclosure for consequential employment decisions
SB 5 requires disclosure when automated decisions play a prominent role in consequential decisions related to employment, and makes clear that anti-discrimination laws apply to those technologies. The framing aligns with the broader Automated Decision-Making Technology regulatory thread, including California's CCPA/CPRA ADMT regulations, and uses a "consequential" trigger drawn from EU AI Act high-risk classification logic.
AI-companion regulation, including a flat under-18 ban
The companion provisions impose disclosure and transparency requirements regarding nonhuman interactions, together with a flat prohibition on use by minors under age 18.
The under-18 ban is structurally similar to the minor-protection provisions in California SB 243 — Companion Chatbots for companion AI and to the AI-companion provision in New York Safe By Design Act (FY27 budget, May 28, 2026) (part of Hochul's FY27 budget agreement, also dated May 28, 2026), except that Connecticut applies a flat prohibition rather than a default-off setting. The Connecticut, New York, and California measures together form the first wave of U.S. state-level legislation treating AI companions as a regulated product category.
Regulatory sandbox by January 1, 2028
SB 5 mandates the creation of a state AI regulatory sandbox by January 1, 2028, pairing the act's restrictive duties with an innovation-side opening. The sandbox aligns Connecticut with the AI Regulatory Sandbox approach being explored in the UK and EU.
Reactions and context
Across California, Colorado, New York, Illinois, and Connecticut, states have chosen different combinations of the same building blocks: frontier audits, ADMT disclosure, companion-AI rules, sandboxes, and minor protections. SB 5 is described as the first to bundle all four regimes into a single act. Its anonymous whistleblower channel functions as a structural complement, rather than an alternative, to the external-audit approach of Illinois SB 315 (frontier safety framework with mandatory third-party audits).
The flat under-18 ban on AI companions is more restrictive than New York's default-off and California's age-gated approaches. How the bill defines "AI companion" will determine whether general-purpose assistants such as ChatGPT, Claude, and Gemini are captured. The Maroney–Lamont compromise has been characterized as a possible template for other Democratic-trifecta states (NJ, MA, OR, WA) that have stalled on AI bills over veto-side disagreements.
This material is drawn from the IAPP report on the package (Source: iapp.org) and the Pluribus interview (Source: pluribusnews.com).
Relationships
- paired-with: Connecticut SB 4 — Data-broker registration + geolocation-sales ban + facial recognition (CTDPA amendment) (companion bill on data brokers, signed same day)
- modeled-on: Illinois SB 315 (frontier safety framework with mandatory third-party audits) (frontier-reporting thresholds), California SB 243 — Companion Chatbots (companion-AI restrictions)
- related: California SB 53, New York RAISE Act, New York Safe By Design Act (FY27 budget, May 28, 2026) (parallel May 28 NY action), Automated Decision-Making Technology (ADMT), AI Regulatory Sandbox, State-Level AI Regulation, California Effect, Character.AI
- contradicts: EO — Trump Federal Preemption of State AI Laws (Dec 11, 2025) (federal preemption posture)
- regulated-by: Ai Companion Regulation (this bill establishes one of the strictest state regimes)
Sources
- IAPP — "Notable AI, privacy bills hit finish line in Illinois, Connecticut and New York" (May 28, 2026) (Source: iapp.org)
- Connecticut General Assembly — SB 5 / Public Act 2026-PA-00015 primary text (Source: cga.ct.gov)