United States - Connecticut - AI and Data Privacy Act (SB 1103)
An Act Concerning Artificial Intelligence, Automated Decision-Making and Personal Data Privacy
United States
RAI-US-CT-CAIADXX-2023Connecticut's SB 1103 establishes a framework for responsible AI use by state agencies, mandates impact assessments, and strengthens data privacy protections, including for minors.
Summary
Read full text ↗Plain English
Overview
Connecticut Senate Bill 1103, officially enacted as "An Act Concerning Artificial Intelligence, Automated Decision-Making and Personal Data Privacy," represents a pioneering legislative effort by the State of Connecticut to establish a robust regulatory framework for the use of artificial intelligence (AI) and automated decision-making systems within its state government operations. Signed into law by Governor Ned Lamont on June 7, 2023, this Act is a direct response to the increasing integration of AI technologies in public sector functions and the growing recognition of the need for ethical guidelines, transparency, and accountability. The legislation aims to mitigate potential risks such as bias, discrimination, and privacy infringements that can arise from the deployment of AI in critical governmental processes, including those impacting citizens' rights and access to services. Its comprehensive scope underscores a commitment to ensuring that technological advancements serve the public interest without compromising fundamental rights or exacerbating societal inequalities.
The Act's primary focus is on regulating how state agencies develop, procure, and utilize AI systems, particularly those involved in making "critical decisions." It mandates a series of proactive measures designed to foster responsible AI governance, including the requirement for impact assessments to identify and prevent discriminatory outcomes, the creation of public inventories of AI systems in use, and the establishment of dedicated oversight bodies. Furthermore, the legislation extends its reach to enhance personal data privacy protections by amending the Connecticut Data Privacy Act (CTDPA), specifically addressing concerns related to targeted advertising and the sale of minors' data. By establishing an Office of Artificial Intelligence and a task force charged with developing an AI Bill of Rights, Connecticut positions itself at the forefront of state-level AI regulation, laying groundwork for future policy developments and setting a precedent for other jurisdictions grappling with the complex challenges posed by emerging AI technologies.
Definitions
The Act provides crucial definitions to delineate the scope of its application, ensuring clarity for state agencies and other stakeholders. Central to the legislation is the definition of "Artificial Intelligence (AI)," which encompasses a broad range of artificial systems. Specifically, AI is defined as an artificial system that performs tasks under varying and unpredictable circumstances without significant human oversight, or one that can learn from experience and improve its performance when exposed to data sets. This definition further clarifies that AI can be developed in any context, including software or physical hardware, and is designed to solve tasks requiring human-like perception, cognition, planning, learning, communication, or physical action. It also includes systems designed to think or act like a human, such as cognitive architectures or neural networks, or to act rationally, like intelligent software agents or embodied robots that achieve goals using perception, planning, reasoning, learning, communication, decision-making, or action. Additionally, the definition extends to a set of techniques, including machine learning, designed to approximate a cognitive task. This comprehensive definition ensures that a wide array of AI technologies used by state agencies falls under the purview of the Act's regulatory requirements.
Another critical term defined within the Act is "State Agency." This definition is expansive, covering each department, board, council, commission, institution, or other agency of the Executive Department of the state government. It specifies that any board, council, commission, institution, or other agency included by law within a given department is considered a division of that department. Furthermore, the term explicitly includes the offices of the Governor, Lieutenant Governor, Treasurer, Attorney General, Secretary of the State, and Comptroller, as well as all operations of an Executive Department agency that are funded by the state. This broad definition ensures that virtually all governmental entities at the state level are subject to the Act's provisions regarding AI governance and data privacy. The meticulous outlining of these terms is fundamental to the effective implementation and enforcement of the Act, providing a clear understanding of what constitutes an AI system and which governmental bodies are responsible for adhering to the established regulations.
Governance and Institutional Framework
The Act establishes a multi-faceted governance and institutional framework designed to oversee and regulate the use of AI within Connecticut's state government. A cornerstone of this framework is the establishment of an Office of Artificial Intelligence, which is tasked with developing and implementing automated system procedures for state agencies. This office plays a pivotal role in shaping the state's approach to AI, ensuring consistency and adherence to ethical principles across various governmental functions. Complementing this, the Act mandates the designation of an Artificial Intelligence Officer within the Office of Policy and Management (OPM). This officer is specifically charged with developing and adopting comprehensive policies and procedures for state agencies concerning the design, utilization, and procurement of automated systems. Their responsibilities include ensuring that these procedures are publicly accessible and regularly updated to reflect evolving best practices and technological advancements.
Further strengthening the governance structure, the Department of Administrative Services (DAS) Commissioner is required to designate an AI implementation officer. This role focuses on the practical application and oversight of AI systems within state agencies, working in conjunction with the OPM's AI Officer to translate policy into actionable implementation strategies. Additionally, the Act establishes a working group or task force dedicated to studying artificial intelligence and developing a Connecticut AI Bill of Rights. This task force is crucial for engaging diverse stakeholders and experts to make recommendations on the ethical and equitable use of AI in state government, assess national AI blueprints like the White House Office of Science and Technology Policy's "Blueprint for an AI Bill of Rights," and propose regulations for AI use in the private sector. This collaborative and multi-tiered approach ensures that AI governance is not only centralized but also informed by broad expertise and public input, fostering a responsible and adaptive regulatory environment for AI in Connecticut.
Key Focus Areas
The Act addresses several critical areas to ensure responsible AI governance within Connecticut's state agencies. A primary focus is on mandating impact assessments for AI systems, particularly those used for "critical decisions." State agencies are prohibited from implementing any AI system unless an impact assessment has been conducted to ensure that such a system will not result in adverse impacts or unlawful discrimination. This proactive measure is designed to identify and mitigate potential biases or disparate impacts before AI systems are deployed, safeguarding against outcomes that could violate state or federal laws. The Department of Administrative Services (DAS) and the Judicial Department are also required to perform ongoing assessments of AI systems to ensure continuous compliance with non-discrimination principles. These assessments are crucial for maintaining the ethical integrity and fairness of AI applications in government.
Another significant focus area is transparency through inventory requirements and data privacy enhancements. The Act mandates that state agencies, including the DAS and the Judicial Department, conduct annual inventories of all AI systems they develop, use, or procure. These inventories must include detailed information such as the system's name, capabilities, data used, purpose, intended use, data processing and storage methods, and any financial impact. Crucially, these completed inventories must be made publicly accessible on the state's open data site or the department's website, fostering transparency and allowing public scrutiny of government AI use. In terms of data privacy, the Act amends the Connecticut Data Privacy Act (CTDPA) by requiring state contracting agencies to include provisions in their contracts ensuring third-party businesses comply with the CTDPA. It also strengthens consumer protections by prohibiting controllers from processing personal data for targeted advertising or selling personal data without consent, especially when they have actual knowledge or willfully disregard that the consumer is between 13 and 16 years of age. These provisions collectively aim to enhance data subject rights and prevent misuse of personal information in the context of AI-driven applications.
Implementation Framework
The implementation framework of the Act is structured to ensure a phased and coordinated approach to AI governance across Connecticut's state government. A central component involves the Office of Policy and Management (OPM), which is tasked with developing and establishing comprehensive policies and procedures for state agencies concerning the responsible use of AI. These policies must cover the entire lifecycle of AI systems, from their development and procurement to their implementation, utilization, and ongoing assessment. The OPM is also responsible for posting these policies and any subsequent revisions on its official website, ensuring public access and transparency. This foundational work by the OPM sets the statewide standards that all other agencies must adhere to, creating a unified approach to AI ethics and compliance.
Furthermore, specific responsibilities are delegated to key state departments to operationalize the Act's requirements. The Department of Administrative Services (DAS) is mandated to inventory all AI systems used by state agencies annually, with the first inventory due by December 31, 2023, and subsequent inventories annually thereafter. The DAS must also make these inventories publicly available on the state's open data portal. Beginning February 1, 2024, the DAS commenced performing ongoing assessments of AI systems to ensure they do not result in unlawful discrimination. Similarly, the Judicial Department (JD) is required to conduct its own inventory of AI systems by December 31, 2023, and make it publicly accessible. The JD also had to establish its own policies and practices for responsible AI use by February 1, 2024, and conduct ongoing assessments. These departmental mandates ensure that the Act's provisions are integrated into the daily operations and long-term planning of state entities, fostering a culture of accountability and responsible AI deployment.
Monitoring and Evaluation
The Act incorporates robust mechanisms for monitoring and evaluating the implementation and impact of AI systems within state agencies, emphasizing continuous oversight and public accountability. A core aspect of this is the requirement for ongoing assessments of AI systems. Beginning February 1, 2024, both the Department of Administrative Services (DAS) and the Judicial Department were mandated to perform continuous assessments of systems employing AI to ensure that they do not result in any unlawful discrimination or disparate impact against individuals or groups. These assessments are critical for identifying and rectifying issues that may arise post-implementation, ensuring that AI systems remain fair, equitable, and compliant with state and federal laws throughout their operational lifespan. This proactive monitoring approach helps to maintain the integrity of governmental decision-making processes that increasingly rely on AI.
Transparency forms another pillar of the monitoring and evaluation framework. All inventory reports required under the Act, detailing the AI systems used by state agencies and the Judicial Department, must be made publicly accessible online. The DAS is specifically tasked with making its completed inventories available on the state's open data site, while the Judicial Department must post its inventory on its own website. This public disclosure allows for external scrutiny and fosters greater trust in government AI use. Additionally, the Act requires the Artificial Intelligence Officer to prepare and submit an annual report to the joint standing committee of the General Assembly relating to consumer protection. This report, due by February 15, 2025, and annually thereafter, must include details on automated system procedures and updates, legislative recommendations, information on automated systems used by state agencies, and any other relevant information deemed necessary by the officer. These reporting obligations ensure that the General Assembly is kept informed of AI implementation progress, challenges, and potential areas for further legislative action, facilitating ongoing legislative oversight and adaptation of the regulatory framework.
Penalties, Liability, and Appeals
While the Act primarily focuses on establishing a framework for responsible AI governance through proactive measures like impact assessments, inventories, and policy development, it also implicitly addresses penalties and liability through its prohibitions and amendments to existing data privacy law. The Act explicitly restricts state agencies from implementing any AI system that has not undergone required impact assessments or that has been determined to result in unlawful discrimination or disparate impact against individuals or groups. This prohibition serves as a primary enforcement mechanism, preventing the deployment of non-compliant or harmful AI systems. Although the Act does not detail specific monetary penalties or criminal sanctions directly for state agencies violating these AI governance provisions, non-compliance could lead to internal disciplinary actions, public censure, and legal challenges based on the discriminatory outcomes of such systems. The emphasis is on prevention and adherence to established procedures to avoid such adverse impacts in the first place.
Furthermore, the Act's amendments to the Connecticut Data Privacy Act (CTDPA) introduce avenues for liability and potential penalties related to personal data handling in the context of AI. By strengthening consumer consent requirements for targeted advertising and the sale of personal data, especially concerning minors, the Act brings AI-related data processing activities under the existing enforcement mechanisms of the CTDPA. Violations of the CTDPA can result in civil penalties, including fines, and consumers may have rights to seek redress for damages caused by non-compliant data practices. For third-party businesses contracting with state agencies, the requirement to comply with the CTDPA means they are subject to its full range of enforcement provisions. While the Act does not outline a specific appeals process for decisions related to AI system deployment or assessment, individuals affected by discriminatory or adverse outcomes from state agency AI systems would likely have recourse through existing administrative review processes or judicial channels, challenging the agency's decision or the system's impact based on violations of state or federal anti-discrimination laws or data privacy rights.
Relationship to Other Instruments
The Act demonstrates a clear relationship with other significant legal and policy instruments, both at the state and national levels, integrating its provisions within a broader regulatory landscape. Most notably, the Act directly amends and interacts with the Connecticut Data Privacy Act (CTDPA). By incorporating new requirements related to consumer consent for targeted advertising and the sale of personal data, particularly for individuals between 13 and 16 years of age, the Act strengthens and expands the protections offered by the CTDPA in the context of AI-driven data processing. This integration ensures that AI applications developed or procured by state agencies, as well as those used by third-party contractors, adhere to robust privacy standards, aligning AI governance with established data protection principles. The requirement for state contracting agencies to include CTDPA compliance provisions in their contracts further solidifies this relationship, creating a cohesive legal framework for data handling.
Beyond state-level legislation, the Act explicitly acknowledges and seeks alignment with national AI policy initiatives. The task force established by the Act is specifically mandated to assess the White House Office of Science and Technology Policy's "Blueprint for an AI Bill of Rights" and similar materials. This assessment is intended to inform recommendations concerning the regulation of AI use in the private sector and the potential adoption of a Connecticut AI Bill of Rights, based on the principles outlined in the federal blueprint. This forward-looking approach indicates an intent to harmonize Connecticut's AI governance efforts with national best practices and emerging federal guidance, ensuring that the state's policies are not developed in isolation but are informed by a broader national dialogue on AI ethics and regulation. While not an international alignment, this national alignment signifies a commitment to comprehensive and well-informed AI policy development.
International Alignment
Given that Connecticut Senate Bill 1103 is a state-level legislative act within the United States, its primary focus is on establishing a regulatory framework for AI within the state's jurisdiction and its government agencies. Consequently, the Act does not explicitly address or seek direct alignment with international AI governance instruments or standards. State legislation typically concentrates on domestic concerns and the specific needs of its constituents, and direct engagement with international treaties, frameworks, or bodies like the European Union's AI Act or OECD AI Principles is generally beyond its immediate scope. The legislative intent is rooted in addressing the ethical, privacy, and accountability challenges posed by AI within the operational context of Connecticut's public sector.
However, the Act does demonstrate an awareness of broader discussions on AI ethics by mandating its established task force to assess the White House Office of Science and Technology Policy's "Blueprint for an AI Bill of Rights." While this "Blueprint" is a national policy document rather than an international one, it itself draws upon global discussions and emerging best practices in AI ethics, fairness, and accountability. Therefore, by considering and potentially integrating principles from a nationally recognized framework that is, in turn, influenced by international discourse, the Act indirectly reflects a general alignment with global trends towards responsible AI development and deployment. This indirect influence, rather than direct international alignment, is characteristic of how sub-national jurisdictions often engage with broader technological governance challenges.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Bill Introduced | 2023-03-10 | Introduced by State Senator James Maroney. |
| Senate Passage | 2023-05-11 | Passed the Senate with a unanimous vote. |
| Signed by Governor | 2023-06-07 | Signed into law by Governor Ned Lamont. |
| Sections 1-3 Effective | 2023-07-01 | Provisions related to the Office of AI, AI Officer, and certain data privacy amendments. |
| State Contracting Agencies CTDPA Compliance | 2023-07-01 | Prohibition on entering contracts without CTDPA compliance provision. |
| Section 4 Effective | 2023-10-01 | Specific provisions related to data privacy. |
| Judicial Department AI Inventory Due | 2023-12-31 | Annual inventory of AI systems in use by the Judicial Department. |
| DAS AI Inventory Due | 2023-12-31 | Annual inventory of AI systems in use by state agencies, made publicly available. |
| OPM Policies and Procedures Established | 2024-02-01 | Office of Policy and Management to develop and adopt AI use procedures. |
| Judicial Department Policies and Procedures Established | 2024-02-01 | Judicial Department to create policies and practices for AI use. |
| Prohibition on Discriminatory AI Implementation | 2024-02-01 | No state agency or Judicial Department to implement AI systems resulting in unlawful discrimination. |
| DAS Ongoing AI Assessments Begin | 2024-02-01 | Department of Administrative Services to perform ongoing assessments of AI systems. |
| Judicial Department Ongoing AI Assessments Begin | 2024-02-01 | Judicial Department to perform ongoing assessments of AI systems. |
| Artificial Intelligence Officer Report Due | 2025-02-15 | Annual report to the General Assembly on automated system procedures and updates. |
Compliance Checklist
| Check | Required Action |
|---|---|
| AI Officer Designation | Office of Policy and Management (OPM) must designate an Artificial Intelligence Officer. |
| AI Implementation Officer Designation | Department of Administrative Services (DAS) Commissioner must designate an AI Implementation Officer. |
| Develop AI Policies & Procedures | OPM must develop and adopt procedures for state agencies' use of automated systems (AI), and post them publicly. |
| Conduct Annual AI Inventory (DAS) | DAS must annually inventory all AI systems used by state agencies and make the inventory publicly accessible. |
| Conduct Annual AI Inventory (Judicial Dept.) | Judicial Department must annually inventory its AI systems and make the inventory publicly accessible. |
| Perform Impact Assessments | State agencies must conduct impact assessments before implementing new AI systems to ensure no unlawful discrimination or disparate impact. |
| Ongoing AI System Assessments | DAS and Judicial Department must perform ongoing assessments of AI systems to ensure continuous compliance with non-discrimination. |
| Prohibit Discriminatory AI | State agencies and the Judicial Department are prohibited from implementing AI systems that result in unlawful discrimination or disparate impact. |
| CTDPA Compliance in Contracts | State contracting agencies must include provisions in contracts with third-party businesses requiring compliance with the Connecticut Data Privacy Act (CTDPA). |
| Consumer Data Consent | Controllers must not process personal data for targeted advertising or sell personal data without consumer consent, especially for individuals 13-16 years old. |
| Annual Report to General Assembly | The Artificial Intelligence Officer must prepare and submit an annual report to the General Assembly on automated system procedures and recommendations. |
| Task Force Engagement | Participate in or monitor the AI task force's work on ethical AI use and the development of a Connecticut AI Bill of Rights. |
Sources and References
| Source | Type |
|---|---|
| Connecticut General Assembly - Public Act No. 23-15 (SB 1103) | official |
| Connecticut General Assembly - SB 1103 Bill Text (Original) | official |
| LegiScan - CT SB01103 | 2023 | General Assembly | legal |
Connecticut's new law, effective in phases starting July 1, 2023, establishes a framework for state agencies to responsibly use artificial intelligence and strengthens data privacy protections for consumers. This legislation broadly applies to nearly all state government entities, including departments, boards, commissions, and the offices of the Governor, Attorney General, and others, as well as the Judicial Department. It also impacts third-party businesses that contract with state agencies, requiring them to comply with the Connecticut Data Privacy Act (CTDPA).
The law introduces several key requirements. State agencies and the Judicial Department are prohibited from implementing any artificial intelligence (AI) system that results in unlawful discrimination or disparate impact, a rule that took effect on February 1, 2024. Before deploying AI systems, especially those involved in "critical decisions," agencies must conduct impact assessments to identify and prevent potential biases or discriminatory outcomes. To ensure transparency, state agencies and the Judicial Department must conduct annual inventories of all AI systems they use, develop, or procure. These detailed inventories, including system capabilities, data used, and purpose, must be made publicly accessible online, with the first reports due by December 31, 2023. The law also enhances data privacy by amending the CTDPA, requiring state contracting agencies to ensure their third-party business partners comply. Furthermore, it prohibits companies from processing personal data for targeted advertising or selling personal data without consent, particularly when they know or should know the consumer is between 13 and 16 years old.
While the law doesn't specify direct monetary penalties for state agencies violating AI governance rules, non-compliance could lead to internal actions, public criticism, or legal challenges based on discriminatory outcomes. For data privacy violations, the existing CTDPA framework applies, which includes civil penalties and fines, and consumers may seek redress. A notable practical aspect is the requirement for public inventories of AI systems. This means the public can scrutinize how state government uses AI, fostering transparency but also potentially leading to increased public debate and oversight regarding specific AI deployments.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under United States - Connecticut - AI and Data Privacy Act (SB 1103). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Feb 1, 2024
Applies to: State agencies and the Judicial Department
“State agencies are prohibited from implementing any AI system... that has been determined to result in unlawful discrimination or disparate impact.”
- #2Critical⏰ Before placing on market
Applies to: State agencies
“State agencies are prohibited from implementing any AI system unless an impact assessment has been conducted to ensure that such a system will not result in adverse impacts or unlawful discrimination.”
- #3Critical⏰ Feb 1, 2024
Applies to: Department of Administrative Services (DAS) and Judicial Department
“The Department of Administrative Services (DAS) and the Judicial Department are also required to perform ongoing assessments of AI systems.”
- #4Critical⏰ Jul 1, 2023
Applies to: State contracting agencies
“The Act amends the Connecticut Data Privacy Act (CTDPA) by requiring state contracting agencies to include provisions in their contracts ensuring third-party businesses comply with the CTDPA.”
- #5Critical⏰ Oct 1, 2023
Applies to: Controllers
“prohibiting controllers from processing personal data for targeted advertising or selling personal data without consent, especially when they have actual knowledge or willfully disregard that the consumer is between 13 and 16 years of age.”
- #6Important⏰ Jul 1, 2023
Applies to: Office of Policy and Management (OPM)
“the Act mandates the designation of an Artificial Intelligence Officer within the Office of Policy and Management (OPM).”
- #7Important
Applies to: Department of Administrative Services (DAS) Commissioner
“the Department of Administrative Services (DAS) Commissioner is required to designate an AI implementation officer.”
- #8Important⏰ Feb 1, 2024
Applies to: Office of Policy and Management (OPM)
“The OPM is tasked with developing and establishing comprehensive policies and procedures for state agencies concerning the responsible use of AI.”
- #9Important⏰ Dec 31, 2023
Applies to: Department of Administrative Services (DAS)
“The Department of Administrative Services (DAS) is mandated to inventory all AI systems used by state agencies annually.”
- #10Important⏰ Dec 31, 2023
Applies to: Judicial Department
“the Judicial Department (JD) is required to conduct its own inventory of AI systems by December 31, 2023.”
- #11Important⏰ Feb 1, 2024
Applies to: Judicial Department
“The JD also had to establish its own policies and practices for responsible AI use by February 1, 2024.”
- #12Important⏰ Feb 15, 2025
Applies to: Artificial Intelligence Officer
“the Artificial Intelligence Officer to prepare and submit an annual report to the joint standing committee of the General Assembly relating to consumer protection.”
Related Regulations
Connecticut AI Impact Assessment Requirements
United States95% similar
Connecticut Artificial Intelligence Responsibility and Transparency Act
Connecticut, United States95% similar
An Act Concerning Online Safety
Connecticut, United States95% similar
An Act Concerning Artificial Intelligence (Connecticut SB 2)
United States92% similar
An act relating to creating oversight and liability standards for developers and deployers of inherently dangerous artificial intelligence systems
United States90% similar
© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash