Today, October 1, the law changed.
Connecticut's Artificial Intelligence Responsibility and Transparency Act — the CART Act — took effect this morning, introducing a new compliance regime for businesses operating in the state. PYMNTS, 2026-09-29
That's not a press release. That's a calendar. The broadest state AI law in the country now has live obligations, with staggered deadlines running through 2027. ai-legislation-tracker
What's in it
The statute is Public Act 26-15, originally Substitute Senate Bill 5, signed by Governor Ned Lamont on May 27, 2026. Seventy-four pages, 39 sections. PAICE.work, 2026-09-23
The obligations hitting now: subscription-based AI providers can't renew a subscription or collect a fee without written notice of key terms and written consumer acceptance — limits the provider may impose, discretion to reduce functionality, all of it in writing. Whistleblower protections are live for employees of large frontier developers. PAICE.work, 2026-09-23
And the piece that matters most for business owners: automated employment decision technology. Applicants and employees must receive plain-language notice about when and how AI has been used in employment decisions. Critically, as PYMNTS put it, "the use of such systems does not insulate an employer from discrimination liability. Relying on a third-party hiring algorithm does not outsource the associated legal risk." PYMNTS, 2026-09-29
Companion legislation expands Connecticut's Data Privacy Act the same day: a new data-broker framework, a ban on selling Connecticut residents' genetic information, and restrictions on facial recognition, precise geolocation, and personalized algorithmic pricing. PYMNTS, 2026-09-29
Why this is different
Plenty of AI bills die in committee. This one didn't, and its structure tells you where every other state is heading. It covers the whole stack: developers and deployers, hiring tools, chatbots, synthetic content transparency, whistleblower channels, subscription disclosures. It's not a hiring law or a privacy law. It's a governance law. PAICE.work, 2026-09-23
And it answers the industry's favorite dodge. "The vendor did it" is not a defense. "The model decided" is not a defense. The law now says, in writing: the person who deployed the system owns the outcome.
That single principle — the deployer owns the outcome — is the entire Solomon thesis, now in statute form.
Note what's already live in the employment chapter beyond notice: the law protects workers on large frontier-model teams from retaliation for reporting safety risks, and it draws hard statutory lines around what counts as a regulated AI technology. The companion chatbot requirements arrive January 1, 2027, and the employment decision obligations on systems deployed on or after October 1, 2027 tighten further. The deadlines are staggered on purpose — the state is giving companies a runway, then removing every excuse. PAICE.work, 2026-09-23
The calendar only moves one direction
Connecticut is first, not last. Colorado's replacement AI law takes effect January 1, 2027. New York's RAISE Act starts the same day. The EU AI Act's high-risk obligations land in December 2027 and August 2028. ai-legislation-tracker
Every deadline on that calendar asks the same question of your company: when a regulator, a lawyer, or a customer asks what your AI did and why, can you show the chain? Notice given. Evidence logged. Decision authorized. Trail intact.
If your business runs agents — in your CRM, your hiring funnel, your customer support, your money movement — you don't need a compliance officer to see what's coming. You need an audit trail. An Arizona operator selling into other states doesn't get to choose which states' laws apply; Connecticut residents on your list are enough to pull you in.
That's the bet behind Solomon: every action runs Intent → Evidence → Governance → Decision → Authorization → Audit. Not because it's elegant. Because it's about to be required.
The law has a calendar now. Build like it.
— Ronin Inc. DMs open. ronininc.org.



