As of October 1, 2026, Connecticut employers filing WARN Act layoff notices must tell the state's Department of Labor whether artificial intelligence played a role in the decision, and the same law puts every employer using AI in hiring, promotion, or discipline on a compliance clock that runs through October 2027.
Connecticut is now the first state to link an AI disclosure duty to WARN Act mass-layoff filings.
Governor Ned Lamont signed the Connecticut Artificial Intelligence Responsibility and Transparency Act on May 27, 2026, as Public Act 26-15 (enacted as Substitute Senate Bill No. 5, "An Act Concerning Online Safety"). The law is best known for its provisions on frontier AI models and minors' use of chatbots, but its employment section is what will land on an HR or compliance team's desk first. Connecticut becomes the fourth state, after Illinois, California, and Colorado, to write AI-specific obligations directly into its employment statute, and the first to link an AI disclosure requirement to the state's WARN Act mass-layoff process (Ropes & Gray, Fisher Phillips, Morrison Foerster, June 2026 client alerts).
Key Takeaways
➤ Two employment-related deadlines apply, not one: the WARN Act AI disclosure and the antidiscrimination/whistleblower provisions take effect October 1, 2026, while the written pre-decision notice requirement for automated employment tools does not become operative until October 1, 2027.
➤ Using automated employment-related decision technology is explicitly not a legal defense to a discrimination claim under the amended Connecticut Fair Employment Practices Act.
➤ Employees of large frontier AI developers gain whistleblower protection against retaliation for reporting "catastrophic risk" concerns, with anonymous internal reporting channels required by January 1, 2027.
➤ Connecticut's approach differs sharply from Colorado's newly rewritten SB 26-189: Colorado leans on pre-use notice and post-adverse-outcome disclosure to workers as consumers, while Connecticut ties its most novel obligation to the WARN Act's mass-layoff reporting process.
What Connecticut's AI Employment Law Actually Requires
Automated employment-related decision technology (AEDT): the statute's term for any computational process, including one derived from machine learning or AI, that is used to substantially assist or replace human decision-making in an employment decision. The definition covers resume-screening tools, algorithmic scheduling and scoring systems, and AI-assisted performance review software, not just dedicated "hiring AI" products. The distinction between a governance framework that describes what to do and the governance controls that actually implement it matters here, since Connecticut's notice obligation is itself a control an employer has to operationalize, not just a policy to write down.
Two obligations sit at the center of the law's workplace provisions. First, an employer or vendor that deploys AEDT such that its output is a substantial factor in an employment decision must give affected employees and applicants written notice: the trade name and purpose of the tool, the categories of personal data it analyzes, where that data comes from, and the type of decision involved. This notice obligation is effective October 1, 2026, but does not become operative in practice until October 1, 2027, giving deployers roughly a year of lead time to build the disclosure into hiring and review workflows.
Second, and effective immediately from October 1, 2026, any employer that files a WARN Act notice with the Connecticut Department of Labor for a covered layoff must state whether the reduction is related to the employer's use of AI or another technological change. Connecticut is the first state to fold an AI-specific question into its mini-WARN reporting regime, which means the disclosure obligation arrives well before the pre-decision notice requirement does.
The Antidiscrimination Clarification
The law amends the Connecticut Fair Employment Practices Act to state plainly that deploying AEDT is not a defense to a complaint alleging discriminatory employment practice. In practice, an employer cannot argue that a hiring decision was fair because "the algorithm made it." Courts and the Commission on Human Rights and Opportunities may still weigh evidence of bias testing, audit documentation, or corrective steps taken before or after deployment, so the incentive to run and document that testing has not disappeared. It has simply stopped functioning as a liability shield.
Whistleblower Protections for AI Developer Employees
A separate section of the Act protects employees of "large frontier developers," AI developers whose models are trained using more than 10^26 floating-point operations and whose annual revenue exceeds $500 million, from retaliation for reporting a reasonable belief that the developer's activities pose a specific and substantial danger tied to a catastrophic risk. Catastrophic risk is defined as a foreseeable material risk that a frontier model contributes to 50 or more deaths or serious injuries, or more than $1 billion in property damage. Covered developers must stand up an anonymous internal reporting channel by January 1, 2027, and violations of the anti-retaliation provisions can carry civil penalties.
This is not a general workplace whistleblower statute; it applies narrowly to a small population of frontier-model builders. For most employers reading this piece, it matters chiefly because a multi-state AI governance program has to track it as a distinct compliance line, separate from the AEDT notice and WARN obligations that apply to any employer, not just AI developers. California took a similar staggered approach with its own frontier-model transparency law, which suggests this pairing of employment rules with frontier-developer safety rules in a single bill is becoming a template other states will copy rather than a one-off.
Penalties and Enforcement
There is no private right of action for the AEDT notice or WARN disclosure provisions. The Connecticut Attorney General enforces both exclusively as unfair or deceptive trade practices under the Connecticut Unfair Trade Practices Act, with civil penalties of up to $1,000 per violation, plus injunctive relief. The statute also builds in a notice-and-cure period: for violations occurring on or before December 31, 2027, the Attorney General must give the employer 60 days to cure before bringing an action, where a cure is possible. That cure window narrows the immediate litigation risk, but it does not extend the underlying compliance deadlines, and $1,000 per violation adds up quickly across a workforce where the same uncured notice gap applies to every affected applicant or employee.
Connecticut vs. Colorado vs. Texas: How the Employment AI Rules Compare
| Requirement | Connecticut (PA 26-15) | Colorado (SB 26-189) | Texas (TRAIGA) |
|---|---|---|---|
| Employee/applicant pre-decision notice | Required for AEDT that is a substantial factor in an employment decision; operative October 1, 2027 | Required pre-use notice plus post-adverse-outcome disclosure for "covered ADMT" affecting consequential decisions; effective January 1, 2027 | No general employee notice mandate; TRAIGA governs state-agency AI use and unlawful discrimination intent, not private-employer disclosure |
| Mass-layoff AI disclosure | Yes, tied to WARN Act filings with the Department of Labor; effective October 1, 2026 | Not addressed | Not addressed |
| AI as discrimination defense | Explicitly barred by statute | Contractual indemnification for a deployer's own discrimination liability is void as against public policy | AI systems may not be intentionally developed or deployed to unlawfully discriminate |
| Governing standard for liability | Substantial factor in the decision | Consequential decision materially influenced by the technology | Intentional discriminatory purpose |
| Compliance lead time from enactment to first deadline | About 4 months (WARN disclosure) | About 8 months (rewritten law effective 2027) | About 6 months (effective January 1, 2026) |
| Civil penalty per violation | Up to $1,000, under CUTPA | Up to $20,000 (up to $50,000 if the affected individual is elderly), under the Colorado Consumer Protection Act | $10,000-$12,000 for a curable violation; $80,000-$200,000 if a court finds it uncurable |
| Cure period before enforcement | 60 days, for violations through December 31, 2027 | 60 days, unless the violation was knowing or repeated | 60 days, with the cure documented to the Attorney General |
Colorado's rewrite is instructive precisely because it moved away from the original 2024 Colorado AI Act's duty-of-care and impact-assessment model toward a leaner notice-and-disclosure structure, the same direction Connecticut has taken with AEDT, but Colorado still frames the worker as a "consumer" under its consumer-protection statute, while Connecticut regulates the employment relationship directly through its Fair Employment Practices Act. That distinction matters for a multi-entity employer building one governance framework to cover both states: the trigger for notice (substantial factor vs. material influence on a consequential decision) is worded differently enough that a single internal threshold test will not satisfy both without a joint mapping exercise. Chasing that mapping by hand across two statutes, and soon a third or fourth, is exactly the gap a multi-jurisdiction AI governance framework is built to close, rather than one built around a single federal standard: Secure Privacy's Governance Maturity module benchmarks each entity against the specific state triggers that apply to it, not a generic checklist.
Compliance Checklist Before October 2026 and October 2027
- Inventory every automated tool touching an employment decision. Include resume screening, algorithmic scheduling, performance-scoring software, and any AI feature bundled into an existing HR platform, not only tools marketed as "AI hiring" products.
- Classify each tool against the "substantial factor" test. Document, in writing, why a tool does or does not meet that threshold; this is the same documentation regulators and plaintiffs' counsel will ask for first.
- Update WARN Act filing templates now, ahead of the October 1, 2026 deadline, so the AI-relatedness question is answered accurately rather than defaulted to "no" under time pressure during an actual reduction in force.
- Draft the AEDT notice template required for October 2027: trade name, categories and sources of personal data, purpose, and the type of decision involved, and test it against a real workflow before the operative date arrives.
- Obtain and retain bias-testing documentation from AEDT vendors. It will not immunize a discrimination claim, but the record still functions as mitigating evidence.
- Confirm whether your organization meets the "large frontier developer" threshold (10^26 FLOPs, $500 million-plus revenue). Most employers will not, but any organization building or fine-tuning foundation models internally should check.
Manually tracking two different effective dates, three different jurisdictional triggers, and a WARN Act carve-out inside a spreadsheet stops being reliable the moment a second state adds a similar rule, which Illinois and New York have already signaled they intend to do. Secure Privacy's AI Governance module registers each automated employment tool with its risk tier, maps it against the specific state triggers that apply, and flags a gap before an audit or a WARN filing does.
Frequently Asked Questions
Does Connecticut's AI law apply to every employer that uses AI-assisted hiring software?
It applies to any employer or vendor whose automated employment-related decision technology output is a substantial factor in an employment decision concerning a Connecticut employee or applicant, regardless of company size. The law does not carve out an employee-count threshold the way some other state privacy statutes do.
When do Connecticut employers actually have to start giving employees written notice about AI tools?
The written pre-decision notice requirement is effective October 1, 2026, but is not operative until October 1, 2027. The WARN Act AI-disclosure requirement, by contrast, applies starting October 1, 2026.
Can an employer still defend a discrimination claim by pointing to its AI vendor's bias testing?
Not as a defense in itself. The law states that deploying AEDT is not a defense to a discrimination complaint, though courts and the Commission on Human Rights and Opportunities may weigh anti-bias testing and mitigation evidence when assessing the underlying claim.
How is Connecticut's approach different from Colorado's AI employment rules?
Connecticut regulates the employment relationship directly through its Fair Employment Practices Act and ties a novel disclosure obligation to WARN Act mass-layoff filings. Colorado's rewritten SB 26-189 instead treats workers as consumers under a broader automated-decision-technology statute, with pre-use notice and post-adverse-outcome disclosure obligations effective January 1, 2027.
What counts as a "large frontier developer" under the whistleblower provisions?
The law defines it as a developer whose AI models are trained using more than 10^26 floating-point operations and whose annual revenue exceeds $500 million. This provision is narrow by design and will not apply to most employers, only to a small set of foundation-model builders.
Connecticut's law is one data point in a pattern, not an isolated event: a multi-state employer now has to reconcile Connecticut's WARN-linked disclosure, Colorado's consumer-framed notice regime, and Texas's discrimination-intent standard inside a single governance program, on three different clocks. Secure Privacy's Privacy & AI Governance Platform maps each state's AEDT trigger against your actual system inventory, tracks the October 2026 and October 2027 deadlines on one compliance calendar, and gives multi-entity organizations one dashboard instead of three separate trackers. Book a demo to see how it maps to your specific footprint.




