United States - Connecticut - AI Regulation (SB 2)

An Act Concerning Artificial Intelligence (Connecticut SB 2)

United States

RAI-US-CT-CAICSXX-2024
Withdrawn(Withdrawn)
BillGovernance and OversightRisk ManagementFundamental Rights
Export PDF

Connecticut Senate Bill 2 (2024) aimed to establish a comprehensive state-level regulatory framework for AI, focusing on high-risk systems and consumer protection, but ultimately stalled in the House.

Overview

Connecticut Senate Bill 2 (2024), formally titled 'An Act Concerning Artificial Intelligence,' represented a pioneering legislative effort within the United States to establish a comprehensive regulatory framework for artificial intelligence (AI) systems at the state level. Introduced in February 2024, the bill aimed to address the multifaceted challenges and opportunities presented by AI, with a particular focus on mitigating potential harms while fostering responsible innovation. Its scope was notably broad, encompassing various types of AI systems, including generative AI, and targeting their development and deployment across critical sectors such as education, employment, financial services, and healthcare. The legislation adopted a risk-based approach, distinguishing between general AI systems and 'high-risk' systems that could significantly impact individuals' lives through 'consequential decisions.' This strategic focus underscored Connecticut's intent to proactively shape AI governance, positioning itself as a leader in state-level AI regulation.

Despite its ambitious goals and significant progress, including passage by the Connecticut Senate on April 24, 2024, the bill ultimately did not become law. It stalled in the House of Representatives and reportedly faced a veto threat from Governor Ned Lamont, who expressed concerns that excessive regulation might stifle technological innovation and deter businesses. Consequently, the 2024 iteration of SB 2 was withdrawn, with expectations for a revised version to be introduced in the 2025 legislative session. Nevertheless, the detailed provisions of SB 2 provide valuable insight into a leading state's approach to AI regulation, particularly concerning consumer protection against algorithmic discrimination, transparency requirements, and the establishment of robust risk management systems for AI developers and deployers. Its emphasis on generative AI in education, workforce development, and public sector applications highlights a forward-thinking perspective on integrating AI responsibly into societal structures.

Definitions

The bill established several crucial definitions to delineate its scope and applicability. An 'Artificial Intelligence System' was broadly defined as any machine-based system that, for a defined set of objectives, infers from input to generate outputs such as predictions, content, recommendations, or decisions capable of influencing physical or virtual environments. This comprehensive definition explicitly included 'generative artificial intelligence systems,' recognizing the distinct characteristics and implications of AI models capable of producing synthetic digital content across various modalities like audio, visual, and text. The inclusion of generative AI underscored the legislature's intent to regulate not just decision-making AI but also content-generating AI, which presents unique challenges related to authenticity, misinformation, and intellectual property.

Central to the bill's risk-based framework was the definition of a 'High-Risk Artificial Intelligence System.' Such a system was characterized as one that, when deployed, either makes or is a substantial factor in making a 'consequential decision.' These consequential decisions were specifically enumerated to include critical life opportunities, such as access to or the terms of education, employment, financial or lending services, healthcare services, housing, and insurance. This classification mechanism was designed to focus regulatory efforts on AI applications with the highest potential for societal impact and individual harm. Furthermore, 'Algorithmic Discrimination' was precisely defined as any condition where an AI system's use results in unlawful differential treatment or impact disfavoring an individual or group based on protected characteristics like age, race, disability, or gender identity. The bill also clearly distinguished between 'Developers,' those who create or substantially modify AI systems, and 'Deployers,' those who implement them in the state, assigning specific obligations to each category.

Governance and Institutional Framework

The proposed legislation outlined a multi-faceted approach to AI governance within Connecticut, aiming to establish both advisory and enforcement mechanisms. A significant component was the planned establishment of an 'Artificial Intelligence Advisory Council.' This council was intended to provide expert guidance and recommendations on AI policy, technological advancements, and regulatory strategies, ensuring that legislative efforts remained informed by current developments in the rapidly evolving AI landscape. However, later amendments to the bill saw the deletion of provisions creating this specific council, indicating a fluidity in the proposed governance structure as the legislative process progressed. Despite this, the bill still mandated the establishment of a Connecticut Technology Advisory Board, which would play a crucial role in broader technology policy, including AI.

Beyond advisory bodies, the bill also stipulated the creation of an artificial intelligence task force. This task force was specifically charged with developing recommendations for the regulation of generative and general-purpose AI, highlighting a proactive stance on emerging AI capabilities and their societal implications. In terms of enforcement, the Connecticut Attorney General was designated as having the sole authority to enforce the provisions of the bill. However, this authority was explicitly stated not to supersede the existing powers of other state agencies, such as the Connecticut Commission on Human Rights and Opportunities (CHRO), to enforce against discrimination. This division of labor aimed to leverage existing legal frameworks while centralizing AI-specific enforcement, providing a clear pathway for addressing violations related to AI system deployment. The bill also included provisions for a 60-day right to cure for alleged violations until June 30, 2026, offering businesses an opportunity to rectify non-compliance before facing penalties.

Key Focus Areas

Connecticut SB 2 addressed several critical areas of AI regulation, demonstrating a comprehensive approach to managing the technology's impact. A primary focus was consumer protection, particularly safeguarding individuals from 'algorithmic discrimination.' The bill mandated that developers of high-risk AI systems exercise 'reasonable care' to protect consumers from known or foreseeable risks of such discrimination. This included ensuring that AI systems do not result in unlawful differential treatment based on protected characteristics. Individuals were granted significant rights, including the right to receive notice before a high-risk AI system is used to make a consequential decision, the right to an explanation of how an adverse decision was reached (including the personal data used), the right to correct inaccurate personal data, and the right to appeal adverse decisions for human review. These provisions aimed to empower individuals and provide avenues for redress in an increasingly AI-driven world.

Another significant area of focus was the regulation of generative AI and its potential for misuse. The bill included explicit prohibitions against the dissemination of certain synthetic images, particularly those created without consent, addressing concerns around deepfakes and non-consensual intimate imagery. Furthermore, it aimed to prohibit the distribution of deceptive media concerning elections, recognizing the critical threat AI-generated content poses to democratic processes. Beyond these prohibitions, the bill also placed a strong emphasis on integrating AI responsibly into the education sector and workforce development. It required the Board of Regents for Higher Education to establish a 'Connecticut Citizens AI Academy' and develop certificate programs in AI-related fields, aiming to enhance public AI literacy and prepare the workforce for an AI-driven economy. State agencies were also tasked with studying the potential uses of generative AI and proposing pilot projects, alongside requiring the Commissioner of Administrative Services to provide training on generative AI to state employees, underscoring a commitment to public sector AI adoption and education.

Implementation Framework

The proposed implementation framework of Connecticut SB 2 established distinct, yet interconnected, obligations for both developers and deployers of artificial intelligence systems, particularly those classified as high-risk. For developers, the bill mandated the exercise of 'reasonable care' to protect consumers from the known or reasonably foreseeable risks of algorithmic discrimination. This overarching duty of care required developers to proactively identify and mitigate biases in their AI systems throughout the development lifecycle. Furthermore, developers were required to provide deployers with comprehensive documentation. This documentation included statements detailing the intended use, purpose, outputs, and benefits of the AI system, as well as summaries of the training data used, known model limitations, and foreseeable risks of algorithmic discrimination. This provision aimed to ensure transparency and enable deployers to make informed decisions about the AI systems they integrate.

Deployers, in turn, were tasked with establishing, implementing, and documenting a robust risk management system specifically designed to address preventable algorithmic discrimination risks in high-risk AI systems. These risk management systems were expected to be regularly assessed, reviewed, and updated throughout the AI lifecycle and were encouraged to align with nationally and internationally recognized frameworks, such as the NIST AI Risk Management Framework and ISO 42001. Deployers were also required to administer and document impact assessments for high-risk AI systems, which included components like identifying the system's purpose, assessing its potential impacts on consumers, and evaluating its data governance practices. In the event of substantial modifications to a high-risk AI system, deployers were obligated to conduct new impact assessments and explain how the system's use corresponded with the developer's intended use description. Additionally, the bill included requirements for any person or entity deploying an AI system that interacts with individuals to disclose that they are engaging with an AI system and to watermark AI-generated content, promoting transparency at the point of interaction. Small business exceptions for deployers were also considered in certain circumstances.

Monitoring and Evaluation

While Connecticut SB 2 did not explicitly detail a continuous, centralized monitoring and evaluation framework for all AI systems post-enactment, it embedded several mechanisms within its provisions that would have contributed to ongoing assessment and oversight. A key element was the requirement for deployers of high-risk AI systems to regularly assess, review, and update their comprehensive risk management systems throughout the AI lifecycle. This internal, continuous evaluation by deployers would have served as a primary mechanism for monitoring the performance and safety of AI systems in real-world applications, ensuring that risks of algorithmic discrimination were continually identified and mitigated. The mandate for periodic impact assessments, particularly in response to substantial modifications to an AI system, further underscored this emphasis on ongoing evaluation at the operational level, requiring deployers to document and review the system's alignment with its intended use and its potential impacts.

Beyond internal corporate governance, the bill also proposed mechanisms for broader governmental monitoring and evaluation, albeit indirectly. The establishment of an artificial intelligence task force, charged with recommending legislation for the regulation of generative and general-purpose AI, implies an ongoing process of legislative review and adaptation based on evolving AI capabilities and societal needs. Furthermore, the bill required state agencies to undertake studies on the potential uses of generative AI and to propose pilot projects. These initiatives would have naturally involved a degree of monitoring and evaluation of AI's effectiveness, efficiency, and ethical implications within public sector applications. The proposed 'Connecticut Citizens AI Academy' and related certificate programs, while primarily educational, would also contribute to a more AI-literate populace capable of critically evaluating AI systems and advocating for responsible deployment. Although the bill did not pass, these provisions illustrate an intention to foster a dynamic environment where AI's impact is continuously observed and regulatory responses can evolve.

Penalties, Liability, and Appeals

Connecticut SB 2 outlined a clear framework for enforcement, penalties, and individual redress concerning violations of its provisions. The Attorney General was designated as the sole authority for enforcing the bill's requirements. This centralization of enforcement aimed to provide a consistent and dedicated legal channel for addressing non-compliance within the state. However, the bill explicitly stated that this authority would not supersede any existing legal authority of other state agencies to enforce against discrimination, such as the Connecticut Commission on Human Rights and Opportunities (CHRO). This ensured that individuals could still pursue claims under broader anti-discrimination laws, while the Attorney General focused on the specific AI-related provisions. The bill also specified that the Attorney General could not initiate an action for claims already being pursued by the CHRO for the same conduct, preventing duplicative enforcement efforts.

A notable aspect of the enforcement mechanism was the inclusion of a 'right to cure' provision. Until June 30, 2026, developers and deployers accused of violations would have a 60-day period to rectify any alleged non-compliance. This grace period aimed to encourage voluntary compliance and allow businesses to adapt to the new regulatory landscape without immediate punitive measures, particularly during the initial phase of the law's implementation. For individuals, the bill established crucial rights regarding adverse consequential decisions made by high-risk AI systems. These rights included the ability to receive an explanation for the decision, encompassing the personal data used, the right to correct inaccurate personal data that influenced the decision, and importantly, the right to appeal the decision for human review. These appeal mechanisms were designed to provide a safeguard against purely algorithmic determinations and ensure human oversight in critical contexts, offering a pathway for individuals to challenge and potentially overturn decisions perceived as unfair or discriminatory.

Relationship to Other Instruments

Connecticut SB 2 was designed to operate within the existing legal landscape of the state, aiming to complement rather than entirely replace established statutes, particularly those related to civil rights and consumer protection. The bill explicitly stated that the enforcement authority granted to the Attorney General for AI-related violations would not supersede the existing powers of other state agencies, such as the Connecticut Commission on Human Rights and Opportunities (CHRO), to enforce against discrimination. This provision indicated an intention to integrate AI regulation into a broader framework of protections, ensuring that individuals could still leverage established legal avenues for redress while also benefiting from AI-specific safeguards. The bill's focus on preventing 'algorithmic discrimination' directly aligned with existing anti-discrimination laws, extending their principles to the context of automated decision-making.

Furthermore, SB 2 was recognized as a potential foundational framework for AI governance across the United States, given the fragmented nature of AI regulation at the state level and the absence of comprehensive federal legislation. Commentators noted its comprehensive, risk-based approach as a leading model, with the potential to influence national AI regulatory strategy through 'trickle-up' effects. While not directly referencing international instruments, the bill's emphasis on risk management systems aligning with frameworks like the NIST AI Risk Management Framework and ISO 42001 demonstrated an awareness of global best practices and a desire for interoperability with broader standards. The bill's scope and ambition were often compared to the EU AI Act, suggesting an aspiration to establish a comparable scale of private-sector AI regulation. This positioning indicated Connecticut's intent to contribute significantly to the evolving discourse on AI regulation, both domestically and internationally, by setting a precedent for robust state-level oversight.

International Alignment

Connecticut SB 2, while a state-level initiative in the United States, demonstrated an implicit awareness of and aspiration towards alignment with international best practices in artificial intelligence regulation. The bill's emphasis on a risk-based approach, distinguishing between general AI systems and 'high-risk' applications based on their potential for societal impact, echoed the foundational principles seen in leading global regulatory frameworks, most notably the European Union's AI Act. This common philosophical underpinning suggests a convergence in understanding the need to calibrate regulatory intensity with the potential for harm, a concept widely adopted in international discussions on AI governance.

Moreover, the bill explicitly referenced and encouraged alignment with internationally recognized risk management frameworks. Specifically, it mandated that deployers establish risk management systems that adhere to standards such as the NIST AI Risk Management Framework and ISO 42001. The National Institute of Standards and Technology (NIST) AI RMF is a globally influential framework developed in the U.S. that provides a flexible, voluntary approach to managing AI risks, while ISO 42001 is an international standard for AI management systems. By incorporating these benchmarks, Connecticut SB 2 aimed to ensure that its regulatory requirements were not insular but rather harmonized with broader global efforts to promote responsible AI development and deployment. This strategic choice would have facilitated cross-border collaboration and reduced compliance burdens for entities operating in multiple jurisdictions, demonstrating a forward-looking perspective on the interconnected nature of the global AI ecosystem.

Implementation Timeline

MilestoneDate (Proposed)Notes
Bill Introduction2024-02-01Bill introduced in the Connecticut Senate.
Senate Passage2024-04-24Connecticut Senate passed SB 2.
House Action (Stalled)2024-04-25Bill moved to House Calendar but ultimately stalled/died in chamber.
Initial Effective Date for Some Provisions (Proposed)2024-10-01Original proposed effective date for certain aspects of the bill.
Developer/Deployer Obligations Begin (Revised Proposed)2025-07-01Revised proposed date for some developer and deployer obligations to commence.
Full Compliance for Developers/Deployers (Revised Proposed)2026-02-01Revised proposed date for full compliance requirements, including risk management systems.
Right to Cure Period Ends (Proposed)2026-06-30Proposed end date for the 60-day right to cure alleged violations.
Anticipated Reintroduction2025-01-XXA revised version of SB 2 is anticipated in the 2025 legislative session.

Compliance Checklist

CheckRequired Action (Proposed for Developers/Deployers)
Algorithmic Discrimination PreventionDevelopers must use reasonable care to protect consumers from known or foreseeable risks of algorithmic discrimination.
Documentation for DeployersDevelopers must provide deployers with documentation including intended use, purpose, outputs, benefits, training data summaries, model limitations, and foreseeable risks of algorithmic discrimination.
Risk Management SystemDeployers must establish, implement, and document a comprehensive risk management system for high-risk AI systems, targeting preventable algorithmic discrimination risks. This system should be regularly assessed, reviewed, and updated.
Alignment with StandardsRisk management systems should adhere to standards like the NIST AI Risk Management Framework and ISO 42001.
Impact AssessmentsDeployers must administer and document impact assessments for high-risk AI systems, including purpose, potential impacts, and data governance. New assessments required for substantial modifications.
Record KeepingDeployers must maintain records of impact assessments for three years following initial system deployment.
Disclosure of AI InteractionAny person or entity deploying an AI system that interacts with individuals must disclose that they are engaging with an AI system.
Watermarking AI-Generated ContentEntities deploying AI systems must watermark AI-generated content.
Individual Rights ImplementationDeployers must ensure individuals have notice before high-risk AI use, explanation of adverse decisions, right to correct data, and right to appeal for human review.
Prohibition on Synthetic Images/Deceptive MediaCompliance with prohibitions on disseminating certain synthetic images and deceptive media concerning elections.

Sources and References

SourceType
Substitute for SB No. 2 - An Act Concerning Artificial IntelligenceOfficial Legislative Document
Bill Summary for SB No. 2Official Legislative Summary
Bill Status and Actions for SB No. 2Official Legislative Status
Plain English

Connecticut's proposed Senate Bill 2 aimed to create a comprehensive state-level framework for artificial intelligence, primarily targeting developers and deployers of "high-risk" AI systems to protect consumers from algorithmic discrimination.

The bill defined "high-risk" AI systems as those making or substantially influencing "consequential decisions" in critical areas like education, employment, financial services, healthcare, housing, and insurance. This means any company developing or using AI in Connecticut that impacts these areas would have been in scope. Developers of high-risk AI would have been required to exercise "reasonable care" to prevent known or foreseeable risks of algorithmic discrimination and provide detailed documentation to deployers about the system's purpose, limitations, and potential biases. Deployers, in turn, would have needed to establish robust risk management systems, conduct impact assessments for high-risk AI, and regularly review them. They would also have to disclose when an individual is interacting with an AI system and watermark AI-generated content. Individuals would gain rights to notice before high-risk AI is used, an explanation for adverse decisions, the ability to correct inaccurate data, and the right to appeal for human review. The bill also prohibited disseminating certain synthetic images (like deepfakes) and deceptive AI-generated media related to elections.

While the bill passed the Senate, it stalled in the House in April 2024 and did not become law. Proposed effective dates for various provisions ranged from October 2024 to February 2026, with a revised version anticipated for reintroduction in 2025. The Connecticut Attorney General would have been the sole authority to enforce the bill, though existing anti-discrimination agencies would retain their powers. A key feature was a "right to cure" period until June 30, 2026, allowing businesses 60 days to fix alleged violations before facing penalties. The most significant practical takeaway is that while this specific bill failed, its detailed provisions offer a strong indication of the types of AI regulations likely to emerge in Connecticut and potentially other states. Companies should view this as a blueprint for future compliance, particularly regarding risk management, transparency, and consumer rights in high-stakes AI applications.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under United States - Connecticut - AI Regulation (SB 2). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalJul 1, 2025

    Applies to: Developers of high-risk AI systems.

    Developers must use reasonable care to protect consumers from known or foreseeable risks of algorithmic discrimination.
  2. #2CriticalFeb 1, 2026

    Applies to: Deployers of high-risk AI systems.

    Deployers were tasked with establishing, implementing, and documenting a robust risk management system specifically designed to address preventable algorithmic discrimination risks in high-risk AI systems.
  3. #3CriticalFeb 1, 2026

    Applies to: Deployers of high-risk AI systems.

    it mandated that deployers establish risk management systems that adhere to standards such as the NIST AI Risk Management Framework and ISO 42001.
  4. #4CriticalFeb 1, 2026

    Applies to: Deployers of high-risk AI systems.

    Deployers were also required to administer and document impact assessments for high-risk AI systems, which included components like identifying the system's purpose, assessing its potential impacts on consumers.
  5. #5CriticalFeb 1, 2026

    Applies to: Deployers of high-risk AI systems.

    Individuals were granted rights: notice before high-risk AI use, explanation of adverse decisions, right to correct data, and right to appeal for human review.
  6. #6CriticalJul 1, 2025

    Applies to: Any person or entity.

    explicit prohibitions against the dissemination of certain synthetic images... and to prohibit the distribution of deceptive media concerning elections.
  7. #7ImportantJul 1, 2025

    Applies to: Developers of high-risk AI systems.

    Developers were required to provide deployers with comprehensive documentation including intended use, purpose, outputs, benefits, training data summaries, model limitations, and foreseeable risks.
  8. #8ImportantFeb 1, 2026

    Applies to: Deployers of high-risk AI systems.

    Deployers must maintain records of impact assessments for three years following initial system deployment.
  9. #9ImportantJul 1, 2025

    Applies to: Any person or entity deploying an AI system.

    any person or entity deploying an AI system that interacts with individuals to disclose that they are engaging with an AI system.
  10. #10ImportantJul 1, 2025

    Applies to: Entities deploying AI systems.

    to watermark AI-generated content, promoting transparency at the point of interaction.

© Regulations.AI — created on 12-Jun-2026 using Gemini 2.5 Flash