United States - Connecticut - AI Impact Assessment (Public Act 23-16)
Connecticut AI Impact Assessment Requirements
United States
RAI-US-CT-CAIARXX-2023Connecticut's Public Act 23-16 mandates AI impact assessments, annual inventories, and transparent policies for state agencies to prevent discrimination and ensure ethical AI use.
Summary
Read full text ↗Plain English
Overview
Connecticut's Public Act 23-16, formally titled "An Act Concerning Artificial Intelligence, Automated Decision-Making and Personal Data Privacy," represents a pioneering legislative effort to establish a structured regulatory environment for the use of artificial intelligence within state government. Signed into law on June 7, 2023, this Act primarily targets the executive and judicial branches of Connecticut's state government, mandating a series of proactive measures to ensure the ethical, equitable, and transparent deployment of AI systems. The core objective of P.A. 23-16 is to mitigate the potential risks associated with AI, particularly concerning algorithmic discrimination and disparate impact on individuals and groups. It achieves this by imposing strict requirements for inventorying AI systems, developing comprehensive policies and procedures for their lifecycle management, and critically, by requiring thorough impact assessments before any AI system is implemented. These assessments are designed to proactively identify and address biases or discriminatory outcomes, thereby safeguarding fundamental rights and promoting public trust in government-deployed AI technologies.
The legislation's phased implementation, with key provisions taking effect from July 1, 2023, and extending to February 1, 2024, underscores a deliberate approach to integrating AI governance into existing governmental operations. Beyond direct regulatory mandates, P.A. 23-16 also established a dedicated working group comprising experts and stakeholders. This group was tasked with formulating recommendations for best practices in ethical and equitable AI use, reflecting a commitment to ongoing adaptation and refinement of the state's AI strategy. By focusing on internal government use, Connecticut aims to set a precedent for responsible AI adoption, ensuring that technological advancements serve the public good without inadvertently perpetuating or creating new forms of inequality. This Act positions Connecticut as a leader in state-level AI regulation, laying foundational principles for accountability and transparency in the rapidly evolving landscape of artificial intelligence.
Definitions
Public Act 23-16 provides specific definitions to delineate the scope and application of its provisions. Central to the Act is the definition of "Artificial Intelligence (AI)," which is characterized in two primary ways. Firstly, it refers to a collection of techniques, prominently including machine learning, that are designed to emulate or approximate a human cognitive task. Secondly, AI is defined as an artificial system that fulfills certain operational criteria: it can perform tasks under varying and unpredictable circumstances without requiring significant human oversight, or it possesses the capability to learn from experience and enhance its performance when exposed to diverse datasets. Additionally, this definition encompasses systems developed in any context, whether software or physical hardware, that are designed to solve tasks traditionally requiring human-like perception, cognition, planning, learning, communication, or physical action. This broad definition ensures that a wide array of AI technologies used by state agencies falls under the purview of the Act, from simple machine learning algorithms to more complex autonomous systems.
Another crucial term, though not explicitly defined within P.A. 23-16 but inferred from its requirements, is "Automated Decision System." This refers to any machine-based system or application that is utilized to make, inform, or materially support a critical decision within the operational context of state agencies. The Act's emphasis on preventing "unlawful discrimination or disparate impact" through impact assessments directly addresses the potential negative consequences of such systems. An "Impact Assessment" itself is defined as a mandatory, systematic evaluation that state agencies must conduct before implementing an AI system, and subsequently on an ongoing basis. The explicit purpose of this assessment is to proactively identify and ensure that the AI system will not lead to any unlawful discrimination or disparate impact against individuals or groups. This includes scrutiny based on actual or perceived differentiating characteristics such as age, race, gender, religion, disability, or sexual orientation. The term "State Agency" is also explicitly defined to include any department, board, commission, council, institution, office, or constituent unit within the executive, legislative, or judicial branches of state government, clearly outlining the entities subject to the Act's mandates.
Governance and Institutional Framework
The governance structure established by Public Act 23-16 for overseeing AI use within Connecticut's state government is distributed across several key entities, each with distinct responsibilities. The Department of Administrative Services (DAS) and the Judicial Department are central to the implementation of the Act. Both are mandated to conduct annual inventories of all AI systems utilized within their respective domains. These inventories are not merely internal records; they must be made publicly available, fostering a critical layer of transparency regarding government AI deployment. Beyond inventorying, DAS is also responsible for performing ongoing assessments of AI systems in accordance with policies and procedures developed by the Office of Policy and Management (OPM). Similarly, the Judicial Department is tasked with developing its own policies and procedures, ensuring that AI use within the judiciary aligns with the Act's principles. This dual-pronged approach ensures that both the executive and judicial branches are held accountable for their AI practices, with specific agencies designated to manage the operational aspects of compliance.
The Office of Policy and Management (OPM) plays a pivotal role in setting the overarching policy direction for the executive branch. OPM is specifically required to develop and establish comprehensive policies and procedures for the development, procurement, implementation, utilization, and ongoing assessment of AI systems by state executive branch agencies. These policies are foundational, guiding agencies on how to ethically and equitably integrate AI into their operations, with a particular focus on preventing unlawful discrimination or disparate impact. The Act also established a 21-member Artificial Intelligence Working Group. This multidisciplinary group, comprising computer and public policy experts, as well as state agency heads, was charged with engaging stakeholders and developing recommendations for best practices concerning the ethical and equitable use of AI in state government. While the working group's initial report was due by February 1, 2024, its establishment signifies a commitment to continuous learning and adaptation in AI governance, ensuring that the state's regulatory framework remains responsive to technological advancements and societal needs. This collaborative framework, involving legislative mandates, executive policy-making, and expert advisory input, underpins Connecticut's strategic approach to responsible AI governance.
Key Focus Areas
Public Act 23-16 primarily focuses on three interdependent areas to ensure responsible AI deployment within Connecticut's state government: the prevention of unlawful discrimination and disparate impact, the promotion of transparency and public accountability, and the establishment of robust risk management practices through impact assessments. At its core, the Act is driven by the imperative to safeguard fundamental rights. It explicitly prohibits state executive and judicial branches from implementing any AI system that has not undergone an impact assessment to confirm it will not result in unlawful discrimination or create a disparate impact against individuals or groups based on protected characteristics such as age, race, gender, religion, or disability. This proactive stance aims to address inherent biases that can be embedded in AI systems, ensuring that government services and decisions are fair and equitable for all Connecticut residents. The emphasis here is not just on avoiding intentional discrimination but also on mitigating unintended disparate impacts that may arise from algorithmic processes, reflecting a deep commitment to social justice in the digital age.
Transparency and disclosure form another critical pillar of the Act. To foster public trust and accountability, P.A. 23-16 mandates that all inventories of AI systems used by state agencies, along with the policies and procedures governing their use, must be made publicly available online. This requirement allows citizens, oversight bodies, and other stakeholders to understand where and how AI is being deployed by the state, promoting informed public discourse and enabling external scrutiny. Such transparency is vital for identifying potential issues early and for holding agencies accountable for their AI governance practices. Furthermore, the Act establishes a comprehensive risk management framework centered around mandatory impact assessments. These assessments are not one-time events but are required both before implementation and on an ongoing basis, particularly after any substantial modifications to an AI system. This continuous assessment model ensures that potential risks, especially those related to discrimination, are systematically identified, evaluated, and mitigated throughout the AI system's lifecycle, thereby embedding a culture of responsible innovation within state government.
Implementation Framework
The implementation framework for Public Act 23-16 is structured around a series of phased requirements and responsibilities designed to integrate AI governance into the operational fabric of Connecticut's state executive and judicial branches. A foundational element is the mandatory annual inventory of all AI systems. By December 31, 2023, both the Department of Administrative Services (DAS) for the executive branch and the Judicial Department were required to complete an initial inventory of all AI systems they employ. This inventory must be publicly posted, providing a baseline of AI usage across state government and enhancing transparency. This initial step is crucial for understanding the landscape of AI tools currently in use and for identifying areas that require immediate policy attention or impact assessment. The ongoing nature of this requirement ensures that the state maintains an up-to-date record of its AI footprint, adapting to new procurements and deployments.
Following the inventory, a critical component of the framework involves the development and establishment of comprehensive policies and procedures. By February 1, 2024, the Office of Policy and Management (OPM) for the executive branch and the Judicial Department were mandated to develop and make publicly available detailed policies and procedures. These guidelines cover the entire lifecycle of AI systems, from their initial development and procurement to their implementation, utilization, and ongoing assessment. The policies are explicitly designed to guide state agencies in developing, using, and consistently assessing AI systems to ensure they do not result in unlawful discrimination or disparate impact. This includes providing guidance on integrating ethical considerations, data privacy principles, and robust testing methodologies into AI development and deployment. The requirement for impact assessments before implementation and on an ongoing basis, as detailed in these policies, forms the bedrock of the Act's risk mitigation strategy, compelling agencies to proactively evaluate and address potential harms throughout the operational lifespan of their AI systems.
Monitoring and Evaluation
Public Act 23-16 establishes a robust framework for the continuous monitoring and evaluation of AI systems deployed by Connecticut's state executive and judicial branches, moving beyond one-time compliance checks to ensure sustained adherence to ethical and equitable principles. A central tenet of this framework is the requirement for ongoing assessments. Beginning February 1, 2024, the Department of Administrative Services (DAS) and the Judicial Department became responsible for performing continuous assessments of AI systems under their purview. These assessments are critical for verifying that AI systems continue to operate without resulting in unlawful discrimination or disparate impact, particularly as data inputs, operational contexts, and user interactions evolve over time. The dynamic nature of AI mandates such continuous scrutiny, recognizing that systems that perform equitably at one point may develop biases or unintended consequences under different conditions. This ongoing evaluation mechanism is integral to maintaining the integrity and fairness of AI-driven government services.
The policies and procedures developed by the Office of Policy and Management (OPM) and the Judicial Department, effective February 1, 2024, explicitly provide for these ongoing assessments. These guidelines outline the methodologies, metrics, and reporting mechanisms necessary to effectively monitor AI system performance, identify deviations from expected outcomes, and promptly address any emerging risks. For instance, the Judicial Branch's Responsible AI Framework details procedures for AI Impact Assessment (Procedure AI-03), which includes provisions for ongoing monitoring. Furthermore, state agencies are required to conduct new impact assessments within 90 days after any intentional and substantial modification is made to a high-risk AI system, ensuring that changes do not introduce new forms of bias or discrimination. This adaptive approach to monitoring and evaluation underscores Connecticut's commitment to a living governance model for AI, where oversight is continuous, responsive, and integrated into the operational lifecycle of all AI systems used by the state.
Penalties, Liability, and Appeals
Public Act 23-16 primarily focuses on establishing a preventative and proactive compliance framework for state agencies concerning their use of AI, rather than outlining specific penalties or liability provisions for non-compliance by external entities or individuals. The Act's core mechanism for enforcement lies in its explicit prohibition: beginning February 1, 2024, the executive and judicial branches are prohibited from implementing any AI system unless an impact assessment has been completed, demonstrating that the system will not result in any unlawful discrimination or disparate impact. This means that the primary consequence of failing to meet the impact assessment requirements or deploying a discriminatory AI system is the inability to implement or continue using that system. While the Act does not detail fines or criminal charges directly against state agencies for such failures, the mandate carries significant administrative and reputational implications. Agencies found to be non-compliant would face directives to cease use of the problematic system, undertake corrective actions, and revise their policies and procedures, potentially leading to delays in service delivery, increased scrutiny, and a loss of public trust.
The Act's emphasis is on internal governmental accountability and risk mitigation. It places the onus on state agencies, the Department of Administrative Services (DAS), and the Office of Policy and Management (OPM), as well as the Judicial Department, to develop and adhere to robust policies and procedures. These internal governance mechanisms are designed to prevent discriminatory outcomes from occurring in the first place, rather than solely punishing them after the fact. While the Act does not explicitly detail an appeals process for individuals adversely affected by a state agency's AI system, the underlying principles of preventing unlawful discrimination imply that existing legal avenues for challenging discriminatory government actions would apply. This could include administrative appeals within the relevant agency, judicial review, or civil rights complaints, depending on the nature of the harm. The Act's provisions requiring compliance with applicable data privacy laws in state contracts also introduce a contractual layer of accountability for third-party vendors, where breaches could lead to contractual remedies. Ultimately, the Act's strength lies in its preventative requirements, leveraging administrative oversight and the threat of non-implementation to ensure responsible AI practices within state government.
Relationship to Other Instruments
Public Act 23-16 operates within a broader legal and policy landscape, both within Connecticut and at the federal level, demonstrating a conscious effort to align with existing protections and emerging best practices. A significant connection is made to the Connecticut Data Privacy Act (CTDPA). P.A. 23-16 mandates that, on or after October 1, 2023, state contracting agencies are prohibited from entering into any contract with a business unless that contract includes a provision requiring the business to comply with all applicable provisions of the consumer data privacy law. This integration ensures that as state agencies procure or develop AI systems, the underlying data practices of their vendors also adhere to Connecticut's robust privacy standards, thereby reinforcing data subject rights and data protection principles across the AI ecosystem. This cross-referencing highlights the understanding that AI systems are often data-intensive and that responsible AI governance cannot be separated from sound data privacy practices.
Furthermore, while P.A. 23-16 is a state-specific initiative, its development was informed by and seeks alignment with broader national and international discussions on AI ethics and regulation. The Artificial Intelligence Working Group established by the Act was, in its initial aims, tasked with developing recommendations for an AI Bill of Rights, potentially in alignment with the White House's "Blueprint for an AI Bill of Rights." This indicates an awareness and consideration of federal guidance and principles, even as Connecticut forges its own path in state-level regulation. Although the working group's final report focuses on a legislative framework for ethical and equitable AI use within the state, the initial reference to a national blueprint demonstrates a desire for consistency and shared values in AI governance. Additionally, the ongoing legislative discussions in Connecticut, such as those surrounding Senate Bill 2 (2024) concerning private sector AI, suggest that P.A. 23-16 serves as a foundational step, laying the groundwork for potentially more expansive AI regulations in the future that could further interact with and build upon its principles.
International Alignment
While Public Act 23-16 is a state-level legislative instrument focused on the internal use of AI by Connecticut's executive and judicial branches, its development and the ongoing discussions surrounding AI governance in the state reflect an awareness of broader international efforts and standards. The Artificial Intelligence Working Group, established by P.A. 23-16, was tasked with formulating recommendations for best practices in ethical and equitable AI use within state government. In its deliberations, the working group considered various models and principles, including the potential for alignment with relevant global standards for AI. Although the Act itself does not explicitly mandate adherence to specific international standards, the working group's report and discussions have acknowledged the significance of global benchmarks, such as the European Union's AI Act. This recognition underscores a forward-looking perspective, acknowledging that while state-level regulation addresses immediate local needs, the interconnected nature of AI development and deployment necessitates an understanding of international regulatory trends and best practices.
The consideration of international frameworks, such as the EU AI Act, by Connecticut's AI Working Group, even if not directly incorporated into P.A. 23-16, signals a strategic intent to ensure that Connecticut's approach to AI governance is not isolated but rather contributes to and learns from a global dialogue on responsible AI. The EU AI Act, for instance, categorizes AI systems by risk level and imposes stringent requirements for high-risk applications, including conformity assessments, risk management systems, and human oversight. While P.A. 23-16 applies broadly to AI systems used by state agencies with a focus on impact assessments to prevent discrimination, the underlying principles of risk mitigation, transparency, and fundamental rights protection resonate across these different regulatory landscapes. This informal alignment through expert consideration and best practice recommendations helps to ensure that Connecticut's AI policies are robust, comprehensive, and adaptable to the evolving global standards for AI ethics and safety, positioning the state as a thoughtful participant in the international conversation on AI governance.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Public Act 23-16 Signed into Law | 2023-06-07 | Governor signed the bill, making it law. |
| General Effective Date of Act | 2023-07-01 | Most provisions of P.A. 23-16 became effective. |
| Working Group Provision Effective | 2023-06-07 | The establishment of the Artificial Intelligence Working Group was effective upon passage. |
| State Contracts Data Privacy Compliance Requirement | 2023-10-01 | State contracting agencies must include provisions requiring businesses to comply with the Connecticut Data Privacy Act. |
| DAS & Judicial Department AI System Inventory Due | 2023-12-31 | Initial inventory of AI systems used by state executive and judicial branches required to be completed and publicly available. |
| OPM & Judicial Department Policies/Procedures Establishment | 2024-02-01 | Policies and procedures for AI development, procurement, implementation, utilization, and ongoing assessment must be established and publicly available. |
| Prohibition on AI System Implementation Without Impact Assessment | 2024-02-01 | State agencies are prohibited from implementing any AI system without a completed impact assessment ensuring no unlawful discrimination or disparate impact. |
| Ongoing Assessments Begin | 2024-02-01 | Department of Administrative Services and Judicial Department begin performing ongoing assessments of AI systems. |
| AI Working Group Report Due | 2024-02-01 | The Artificial Intelligence Working Group's report on best practices for ethical and equitable AI use in state government was due. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Annual AI System Inventory | State executive and judicial branches must annually inventory all systems employing AI, including details like name, description, training data (if applicable), output, and any known instances of discrimination. This inventory must be made publicly available. |
| Policies and Procedures Development | The Office of Policy and Management (for executive agencies) and the Judicial Department must develop and establish comprehensive policies and procedures for the development, procurement, implementation, utilization, and ongoing assessment of AI systems. These must be publicly available. |
| Pre-Implementation Impact Assessment | Before implementing any AI system, state agencies must complete a thorough impact assessment to ensure the system will not result in any unlawful discrimination or disparate impact against individuals or groups based on protected characteristics. |
| Ongoing Impact Assessments | State agencies, through DAS and the Judicial Department, must perform ongoing assessments of deployed AI systems to continuously ensure compliance and prevent unlawful discrimination or disparate impact. New assessments are required within 90 days of substantial modifications. |
| Non-Discrimination Assurance | Ensure that no AI system actively utilized by state agencies results in unlawful discrimination or disparate impact, aligned with federal and state data privacy and discrimination laws. |
| Data Privacy in Contracts | State contracting agencies must include a provision in every contract with a business, on or after October 1, 2023, requiring compliance with all applicable provisions of the Connecticut Data Privacy Act. |
| Public Disclosure | All required inventories, policies, and procedures related to AI systems must be publicly posted online to ensure transparency. |
| Training and Safeguards | Implement safeguards to ensure AI systems are properly applied, utilized, and functioning, and provide appropriate training to personnel responsible for designing, utilizing, or procuring such systems. |
Sources and References
| Source | Type |
|---|---|
| Public Act No. 23-16: An Act Concerning Artificial Intelligence, Automated Decision-Making and Personal Data Privacy | official |
| Responsible AI Framework February 1, 2024 - Connecticut Judicial Branch | government |
| Artificial Intelligence Working Group - CT Office of Policy and Management | government |
Connecticut's Public Act 23-16 requires state government agencies in the executive and judicial branches to conduct impact assessments and maintain transparency for their artificial intelligence (AI) systems, aiming to prevent discrimination and ensure ethical use.
This law applies directly to all departments, boards, commissions, and offices within Connecticut's executive and judicial branches. It covers any system that uses AI, broadly defined to include machine learning and other artificial systems that perform human-like cognitive tasks, learn from experience, or operate without significant human oversight.
The Act imposes several key requirements, most of which took effect by February 1, 2024: - Agencies must complete a thorough impact assessment before implementing any new AI system, ensuring it will not lead to unlawful discrimination or disparate impact based on characteristics like age, race, or gender. - They must also perform ongoing assessments of existing AI systems to continuously monitor for and prevent such harms. - An annual public inventory of all AI systems in use is mandatory, detailing their function and any known instances of discrimination. - The Office of Policy and Management (for executive agencies) and the Judicial Department must establish and publicly share comprehensive policies for how AI systems are developed, procured, used, and assessed.
While the Act generally became effective on July 1, 2023, the most significant obligations, including the prohibition on implementing AI without an assessment and the start of ongoing reviews, began on February 1, 2024. The law does not impose direct fines or criminal charges on agencies for non-compliance. Instead, its teeth lie in the prohibition against implementing or continuing to use an AI system that has not undergone the required impact assessment or is found to cause discrimination. Non-compliant agencies would face directives to cease use, undertake corrective actions, and revise procedures, leading to administrative hurdles and reputational damage.
A practical surprise for many is the broad definition of "Artificial Intelligence," which could encompass more systems than agencies initially realize, requiring a wider scope of assessment and inventory. Additionally, the Act mandates that state contracts with businesses must include provisions requiring compliance with Connecticut's consumer data privacy law, extending privacy obligations to third-party AI vendors.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 8 marked completePlain-English obligations under United States - Connecticut - AI Impact Assessment (Public Act 23-16). Not legal advice — verify against the official text before relying on it.
- #1CriticalKey Focus Areas⏰ Before implementing any AI system
Applies to: Connecticut state agencies.
“Prohibits state executive and judicial branches from implementing any AI system that has not undergone an impact assessment.”
- #2CriticalKey Focus Areas⏰ Ongoing
Applies to: Connecticut state agencies.
“Explicitly prohibits state executive and judicial branches from implementing any AI system that... will not result in unlawful discrimination or create a disparate impact.”
- #3CriticalImplementation Framework⏰ Annually by December 31
Applies to: Connecticut state executive and judicial branches.
“State executive and judicial branches must annually inventory all systems employing AI... This inventory must be made publicly available.”
- #4CriticalImplementation Framework⏰ Feb 1, 2024
Applies to: Office of Policy and Management and Judicial Department.
“OPM... and the Judicial Department were mandated to develop and make publicly available detailed policies and procedures.”
- #5CriticalMonitoring and Evaluation⏰ Ongoing, starting 2024-02-01
Applies to: Department of Administrative Services and Judicial Department.
“DAS and the Judicial Department became responsible for performing continuous assessments of AI systems under their purview.”
- #6CriticalRelationship to Other Instruments⏰ On or after 2023-10-01
Applies to: Connecticut state contracting agencies.
“State contracting agencies are prohibited from entering into any contract with a business unless that contract includes a provision requiring the business to comply with all applicable provisions of the consumer data privacy law.”
- #7ImportantGovernance and Institutional Framework⏰ By 2024-02-01
Applies to: Connecticut state agencies, DAS, OPM, Judicial Department.
“These inventories are not merely internal records; they must be made publicly available.”
- #8ImportantCompliance Checklist⏰ Ongoing
Applies to: Connecticut state agencies.
“Implement safeguards to ensure AI systems are properly applied... and provide appropriate training to personnel.”
Related Regulations
Connecticut Artificial Intelligence Responsibility and Transparency Act
Connecticut, United States95% similar
An Act Concerning Artificial Intelligence, Automated Decision-Making and Personal Data Privacy
United States95% similar
An Act Concerning Online Safety
Connecticut, United States93% similar
An Act Concerning Artificial Intelligence (Connecticut SB 2)
United States92% similar
Georgia State AI Governance and Use Guidance
United States90% similar
© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash