Skip to content

Connecticut's AI Bill: What Passed, and What Did Not

9 min read · updated August 11, 2026

Connecticut is regularly listed among the states with a comprehensive AI act. It is not one. A bill has passed the Senate more than once and has never been enacted, and the law that does bind in Connecticut comes from three other places.

The legislative record, with dates

The bill in question is Senate Bill 2, sponsored across sessions by Senator James Maroney, in a form closely related to what became Colorado’s AI Act. The record:

  • 2024 session. SB 2 passed the Connecticut Senate in April 2024. It did not receive a vote in the House before the session adjourned on 8 May 2024, and so died. Governor Lamont had publicly indicated he would veto it.
  • 2025 session. A revised SB 2 again passed the Senate. It again failed to receive a House vote before adjournment on 4 June 2025. The Governor’s position was unchanged.

Twice passing one chamber and never the other is a specific fact about a specific bill, and it is different from “Connecticut is considering AI legislation”. Bill histories, including committee action and vote records, are available at the Connecticut General Assembly.

This page states a legislative record as at its date and is not legal advice. Connecticut’s regular sessions run each year, and a bill that failed in one session can be reintroduced in the next. Confirm the current session’s outcome directly at cga.ct.gov before relying on the position described here.

Why it has not passed

The stated objections are worth recording because they are the same objections that shaped Texas’s and Virginia’s outcomes, and they explain the pattern rather than the instance.

The Governor’s public position has been that a state-level comprehensive framework risks constraining a growing sector before the federal position is settled, and that Connecticut should not be first in a way that puts it out of step with neighbouring states. Industry opposition centred on the duty of reasonable care and the impact assessment obligation — the same two provisions that generated Colorado’s post-enactment amendment process. Supporters argued that the consumer-protection gap is real and that waiting for Congress has no end date.

The result is that the Colorado model has been introduced in many states and enacted in very few, while narrower instruments — disclosure duties, sector rules, government-use rules, deepfake statutes — have passed widely. That distinction is the single most useful thing to carry away from Connecticut’s record, and it is visible across the American state law picture as a whole.

What is actually in force

Connecticut is not without AI law. Three instruments bind now.

Public Act 23-16, on state agency use. Enacted in 2023, it requires an inventory of state systems that use artificial intelligence, requires ongoing assessment of those systems for discriminatory impact, directs the development of policies for state procurement and use of AI, and established an advisory body on AI policy along with a public AI education programme. The act is published at the Connecticut General Assembly. Like California SB 896, it binds agencies and reaches vendors through procurement.

Synthetic media provisions. Connecticut has enacted criminal and civil provisions addressing non-consensual synthetic intimate imagery and deceptive synthetic media in elections, the latter operating within a defined window before an election. These are part of the broader American pattern covered in the state deepfake election law snapshot.

The Connecticut Data Privacy Act. The most consequential of the three for ordinary product work, and the subject of the next section.

The CTDPA profiling opt-out

The Connecticut Data Privacy Act, in force since 1 July 2023, gives consumers a right to opt out of the processing of personal data for purposes of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer. It also requires a data protection assessment for processing that presents a heightened risk of harm, which expressly includes profiling where it presents a reasonably foreseeable risk of unfair or deceptive treatment, disparate impact, financial or physical injury, or intrusion upon solitude.

For most companies this is the Connecticut AI obligation that actually applies. An automated credit, housing, insurance or employment decision made about a Connecticut consumer engages it, and the assessment duty engages before the decision is ever made. The mechanism is the same one used across the American state privacy statutes and is discussed in the automated decision laws page; the parallel European provision, which is a prohibition with exceptions rather than an opt-out, is in GDPR Article 22.

The word doing the work is solely. A decision with genuine human involvement is outside the opt-out, and what counts as genuine involvement is the same contested question it is under Article 22 — a reviewer who rubber-stamps a model output has not made the decision a human one. Connecticut has produced no authoritative construction of the term, so the European guidance on the equivalent phrase is the nearest available reasoning, and it is persuasive at best.

How to check the current position

Because this page describes a status rather than a mechanism, it is written to be checkable rather than relied on. Three sources answer the question directly, and none of them is a news article:

  • The bill status page at cga.ct.gov for the current session’s SB 2 or its successor — chamber votes, committee action, and whether it was transmitted to the Governor.
  • The Public Acts list for the session, which is the authoritative record of what was actually enacted; a bill that is not in it did not become law, whatever was reported about it.
  • The Connecticut Attorney General’s office for enforcement guidance under the CTDPA, which is where the practical expectations around profiling and assessments are expressed.

The general lesson generalises past Connecticut. A very large share of published writing about American AI regulation describes bills rather than statutes, and does not distinguish clearly between the two. The question to ask of any claim that a state “has an AI law” is which public act number, from which session, effective when — and if that cannot be answered, the claim is about a proposal.