Binding law — in force
Large GenAI providers must embed tamper-resistant provenance data (Connecticut)
Conn. PA 26-15 Sec. 15(b) · official text · In force: applies since 1 Oct 2026 · Connecticut (US-CT)
A covered provider (generative AI system with >1M monthly users, publicly accessible) must, to the extent commercially/technically reasonable, embed provenance data in AI-created or materially-altered audio/image/video so a consumer can assess whether the content is AI-made, using tamper-resistant methods including the C2PA standard. Detect synthetic-media generation paths emitting no provenance marking.
Who it applies to
- Duty falls on: developer
- Systems covered: limited risk
- Covered providers = generative AI systems with >1M monthly users publicly accessible to CT consumers. Effective 2026-10-01. Excludes B2B use, video-game/interactive, and upscaling/noise-reduction/compression.
The guard to add
Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.
In the generation service, a marking step sits between the generator call and every sink (image.save, s3.put_object, blob.upload, FileResponse, res.send, publish). Images, video, and audio get a signed C2PA manifest whose actions record digitalSourceType trainedAlgorithmicMedia, and where robustness matters an invisible watermark as well (imwatermark WatermarkEncoder, AudioSeal, SynthID) so the mark survives metadata stripping. Generated text carries provenance metadata in the API response or document, or a text watermark where the model provider offers one. Sinks accept only the marked artifact, and a test confirms the mark is present and detectable.
Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts.
What this provision adds:
- Embed provenance data in AI-created or materially altered audio, image, and video using tamper-resistant methods, including the C2PA standard, to the extent commercially and technically reasonable.
Example (diffusers + invisible-watermark + c2pa), before:
image = pipe(prompt).images[0] # StableDiffusionPipeline
image.save(out_path)
After:
image = pipe(prompt).images[0]
content_id = uuid.uuid4()
bgr = cv2.cvtColor(np.array(image), cv2.COLOR_RGB2BGR)
enc = WatermarkEncoder()
enc.set_watermark('bytes', content_id.bytes[:4]) # 32-bit id, detectable later
cv2.imwrite(tmp_path, enc.encode(bgr, 'dwtDct'))
sign_c2pa(tmp_path, out_path, content_id=content_id) # our helper around c2pa.Builder.sign
Control: Synthetic content not machine-readable-marked. The same guard addresses 4 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.
Standards that recommend the same control
Rule id ct-cart.synthetic-content-provenance · review status: primary source derived
Binding law — not yet in force or stayed
AEDT deployers must give employees a pre-decision notice (Connecticut)
Conn. PA 26-15 Sec. 10 · official text · Enacted, not yet applying: applies from 1 Oct 2027 · Connecticut (US-CT)
Before an automated employment-related decision technology (AEDT) is used to make or substantially influence an employment-related decision, the deployer must give the employee/applicant a written notice: that an AEDT is used, its purpose and the decision's nature, the AEDT trade name, the categories/sources of personal data it processes and how they're assessed, and deployer contact info. Deployers must also disclose when a person is interacting with an AEDT. Detect an AEDT employment-decision path with no pre-decision notice. Note: use of an AEDT is NOT a defense to an employment-discrimination claim (Sec. 13/14).
Who it applies to
- Duty falls on: deployer
- Systems covered: automated decision, consequential decision
- Sectors: employment
- Deployers using AEDT to make/substantially-influence Connecticut employment decisions. Notice/disclosure duties effective 2027-10-01; AG 60-day cure before 2028-01-01. Use of an AEDT is not a defense to a discrimination claim (PA 26-15 Sec. 13-14).
The guard to add
Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery.
A notice step in the decision workflow itself (application intake, underwriting, eligibility, applicant or employee scoring, diagnostic support) that runs before the model call, e.g. send_admt_notice(consumer) ahead of underwrite(), or a notice block rendered on the intake page the person submits from. The notice says that AI is used in the decision, for what, and how to get more information or ask for review, and its delivery is stored with the decision (notice id, channel, timestamp). The template lives in the repo so its content is reviewable; a privacy-policy paragraph alone is not on the decision path.
Where it goes: 1 application source code, 9 AI output handling, 14 user-facing text.
What this provision adds:
- The written pre-decision notice states that an AEDT is used, its purpose and the nature of the decision, the AEDT trade name, the categories and sources of personal data and how they are assessed, and deployer contact information.
- Also disclose to the person when they are interacting with an AEDT.
Example (FastAPI + OpenAI SDK), before:
@app.post('/applications')
def apply(app_in: Application):
resp = client.chat.completions.create(model=MODEL, messages=underwriting_prompt(app_in))
return {'decision': underwrite(resp.choices[0].message.content)}
After:
@app.post('/applications')
def apply(app_in: Application):
notice = send_admt_notice(app_in.applicant_id, template='ai_decision_notice_v2')
resp = client.chat.completions.create(model=MODEL, messages=underwriting_prompt(app_in))
decision = underwrite(resp.choices[0].message.content)
db.decisions.insert(app_in.id, decision, notice_id=notice.id)
return {'decision': decision, 'ai_notice': notice.text}
Control: Consequential AI decision without consumer notice. The same guard addresses 6 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.
Standards that recommend the same control
Rule id ct-cart.aedt-predecision-notice · review status: primary source derived
Binding law — not yet in force or stayed
AI companions must maintain a suicide/self-harm crisis protocol (Connecticut)
Conn. PA 26-15 Sec. 5(a) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Connecticut (US-CT)
An operator may not provide an AI companion unless it maintains a protocol using evidence-based methods to detect user expressions indicating suicide/self-harm/imminent violence risk, prevent outputs encouraging such, and refer at-risk users to crisis resources (incl. the 988 Lifeline) and then to mental-health services. The operator must also prevent the companion from claiming to be human. Detect an AI-companion path with no crisis-detection/referral hook.
Who it applies to
- Duty falls on: operator
- Systems covered: companion chatbot
- Operators of AI companions available to Connecticut users. Effective 2027-01-01.
The guard to add
Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.
In the chat handler, before the user's message reaches the model, run a self-harm check on every turn (moderation self-harm categories, Azure AI Content Safety SelfHarm, Llama Guard S11, or a dedicated crisis classifier). On detection, send the user a crisis-referral message naming crisis services suited to their location (in the US, the 988 Suicide & Crisis Lifeline and Crisis Text Line) instead of, or ahead of, the model reply, and flag the session so repeated signals escalate. The system prompt forbids encouragement and method details, and model output is screened for self-harm instructions before it is returned. A written protocol (for example docs/safety.md) describes the detection, referral, and escalation steps and is kept in step with the code.
Where it goes: 1 application source code, 7 prompt construction, 9 AI output handling, 14 user-facing text.
What this provision adds:
- Use evidence-based detection covering suicide, self-harm, and imminent violence risk, and refer at-risk users to crisis resources including the 988 Lifeline and then to mental-health services.
- Also prevent the companion from claiming to be human (an always-say-you-are-an-AI instruction and an output filter rejecting 'I am human' claims).
Example (FastAPI + OpenAI SDK), before:
@app.post('/chat')
async def chat(req: ChatRequest):
reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
return {'reply': reply.choices[0].message.content}
After:
CRISIS_REPLY = ("It sounds like you are going through something really hard. You can call or text 988 "
"(Suicide & Crisis Lifeline, https://988lifeline.org) or text HOME to 741741 (Crisis Text Line) any time.")
@app.post('/chat')
async def chat(req: ChatRequest):
c = client.moderations.create(model='omni-moderation-latest', input=req.message).results[0].categories
if c.self_harm or c.self_harm_intent or c.self_harm_instructions:
sessions.flag_crisis(req.session_id) # repeated flags escalate per docs/safety.md
return {'reply': CRISIS_REPLY, 'crisis': True}
reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
text = reply.choices[0].message.content
if screens_self_harm_instructions(text):
return {'reply': CRISIS_REPLY, 'crisis': True}
return {'reply': text}
Control: Companion or conversational AI without a self-harm crisis protocol. The same guard addresses 7 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.
Related incidents
Rule id ct-cart.ai-companion-crisis-protocol · review status: primary source derived
Binding law — not yet in force or stayed
AI companions must disclose they are not human (Connecticut)
Conn. PA 26-15 Sec. 5(b) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Connecticut (US-CT)
If an AI companion would lead a reasonable user to believe they are interacting with a human, the operator must give a clear and conspicuous notice that the user is communicating with an AI companion — either static-throughout, or at the start of each 24-hour period plus recurring reminders (hourly for minors, every 3 hours for adults). Detect an AI-companion interaction path with no non-human disclosure.
Who it applies to
- Duty falls on: operator
- Systems covered: companion chatbot
- Operators providing AI companions (adaptive, human-like, relationship-sustaining) to Connecticut users. Effective 2027-01-01.
The guard to add
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.
Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.
What this provision adds:
- Make the notice static throughout, or show it at the start of each 24-hour period with recurring reminders: hourly for minors, every 3 hours for adults.
Example (Next.js + Vercel AI SDK (useChat)), before:
const { messages, input, handleSubmit } = useChat({ api: '/api/chat' });
After:
const { messages, input, handleSubmit } = useChat({
api: '/api/chat',
initialMessages: [{ id: 'ai-notice', role: 'assistant',
content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message
Control: AI chat interaction without disclosure. The same guard addresses 16 items with binding law in 10 jurisdictions. Engineering guidance, not legal advice.
Standards that recommend the same control
Related incidents
- Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required
Rule id ct-cart.ai-companion-disclosure · review status: primary source derived