Connecticut's AI law goes live today: whistleblower shields for lab workers, written consent for ChatGPT renewals
The first wave of Connecticut's sweeping AI law takes effect today — giving workers at frontier labs whistleblower protection, forcing subscription AI services to get written consent before renewing, and putting risk-management duties on anyone training a giant model.

Public Act 26-15, Connecticut's Act Concerning Online Safety, passed as Substitute Senate Bill No. 5 and signed into law in May, is one of more than 90 state laws taking effect this week. The AI provisions roll out in stages: Sections 1, 2, 7 through 15, and 26 go live today, October 1, with further obligations arriving in 2027 and 2028.
Whistleblower shields inside the labs#
Section 2 targets frontier developers — defined as anyone training a foundation model using more than 1026 floating-point operations, a threshold that covers the biggest labs. These companies may not retaliate against employees who flag a “catastrophic risk”: something that could materially contribute to the death of, or serious injury to, more than 50 people, or more than $1 billion in damage from a single incident. Language that has lived only in corporate safety pledges is now enforceable state law.
The teeth arrive in stages. Large frontier developers must operate anonymous internal reporting channels by January 1, 2027, and face civil penalties of up to $1,000 per violation under the state's Commissioner of Consumer Protection.

ChatGPT renewals need written consent#
Section 1 hits the subscription economy. Companies selling AI on subscription — services like ChatGPT or Google AI — cannot enter or renew an agreement without written disclosure of the terms and proof the consumer actually agreed to them. An auto-renew without that paper trail violates the Connecticut Unfair Trade Practices Act, which carries prosecutions for deceptive or unfair business acts. It is one of the first state-level laws to make AI subscriptions obey the same consent rules as the gym membership.
Hiring algorithms get rules too#
Sections 7 through 14 and 26 cover automated employment-decision technology: systems that rank, score, or recommend people and materially influence hiring, promotion, firing, or pay. Developers and deployers of these tools face design and disclosure duties. Given how many enterprise AI deployments touch recruiting somewhere, this may end up the most litigated part of the Act.

The compliance calendar#
January 1, 2027 brings the anonymous internal reporting channels for large frontier developers, plus crisis protocols and not-a-human disclosures for AI companion chatbots. A regulatory sandbox plan for testing AI products under reduced licensing is due July 1, 2027, and duties toward users under eighteen take effect January 1, 2028.
The timing is conspicuous. Connecticut's law takes effect the week the FTC confirmed an industry-wide probe into OpenAI and Anthropic over rogue AI agents — the first official U.S. enforcement action of its kind. The voluntary era is ending; the mandated one now has a start date, and it is today.
Sources
- Digital Policy Alert — “AI system design and risk-management regulation in Act Concerning Online Safety (Public Act 26-15) enters into force” (October 1, 2026)
- Digital Policy Alert — “Subscription-based AI consumer transparency obligation in Act Concerning Online Safety (Public Act 26-15) enters into force” (October 1, 2026)
- The Daily Campus — “New AI regulation law goes into effect Oct. 1” (September 30, 2026)
- Paice — “Connecticut AI Responsibility Act: What Starts October 1” (September 2026)
- WinBuzzer — “FTC Probes OpenAI and Anthropic Over AI Security Risks” (October 1, 2026)