Connecticut's CART Act: The State AI Obligations to Prepare for Now
Back to Signal
State & LocalAIGovernmentComplianceGovtech

Connecticut's CART Act: The State AI Obligations to Prepare for Now

September 16, 2026Jess Loban

Put the dates beside the duties

Governor Lamont approved Public Act 26-15 on May 27, 2026 and announced the legislation on June 2. Commonly called the CART Act, it covers employment technology, state AI use, workforce development, companion chatbots, and other subjects. The enacted text distinguishes a section's effective date from the date that a particular operational duty attaches.

For state technology planning, the key milestones are:

  • October 1, 2026: state AI rules. Sections 37 and 38 take effect. Section 37 expands inventory information and reporting standards. Section 38 ties covered state uses and AI procurement to Office of Policy and Management and Department of Administrative Services policies and standards, with assessment and publication requirements for authorized acquisitions.
  • December 31, 2026: expanded annual inventory. DAS must inventory AI systems in use by covered state agencies and publish the inventory on the state's open data portal. The statutory fields apply to the extent practicable based on available data.
  • October 1, 2026: employment discrimination amendments. Sections 13 and 14 clarify that using automated employment-related decision technology is not a defense to the specified discrimination complaints. A commission or court may consider anti-bias testing and other preventive efforts; these provisions do not create a universal mandatory pre-deployment bias audit.
  • October 1, 2027: covered employment deployments. Although sections 8–10 have October 2026 effective clauses, their developer-information and deployer-disclosure duties use October 2027 deployment triggers.

The act also requires the Connecticut AI Academy to be established by December 31, 2026 under section 17, effective July 1, 2026. Companion-chatbot provisions have a separate January 1, 2027 effective date. Neither date should be substituted for the agency inventory or procurement requirements.

Connecticut already had an AI governance foundation

The 2026 legislation builds on earlier requirements. Section 37 retains DAS's ongoing assessment duty dating from February 1, 2024. The legislature's September 2026 review of state AI law describes existing executive and judicial branch inventory, policy, and impact-assessment responsibilities.

The immediate management task is to update that foundation. A useful gap review compares existing records, approvals, contracts, and operating practices with the amended requirements. It should distinguish a missing record from an obsolete record and an unassessed system from a system whose assessment needs updating.

Scope needs equal care. Section 37 uses the state-agency definition in section 4d-1; section 38 uses section 1-79 and defines the AI technology it covers. That latter definition excludes cybersecurity tools, data analytics tools, or systems where AI is incidental and not determinative. Legal and program teams should apply those definitions to the actual function before assigning obligations.

Build the inventory around decisions and uses

A software asset list is a starting point. It may not reveal which feature ranks applicants, recommends a fraud review, prioritizes a case, or informs a benefits decision. Products sold as analytics or case management can contain AI functions, and in-house systems need the same examination of what they do.

Section 37's inventory calls for the system and vendor, capabilities and uses, decision-making role, whether it received an assessment before implementation, the last assessment date, access to personally identifiable information, and known risks to individuals, communities, and state employees. DAS must establish definitions, reporting standards, and submission formats.

To collect that information reliably, agencies should pair technology records with interviews of the program staff who use the system. For each candidate use case, establish:

  1. The business function: what decision or service the system supports and who is affected.
  2. The actual role of automation: whether the output determines, informs, or materially supports a decision, and what staff do with it.
  3. The evidence owner: who can supply configuration, data-source, assessment, and change records.
  4. The operating boundary: who has access, which data is used, and how errors or unexpected behavior are escalated.
  5. The refresh trigger: what changes require the inventory entry and assessment record to be revisited.

These additional operating details help make the statutory inventory useful after its first publication. They also expose questions that cannot be answered by the vendor name alone.

Put assessments into procurement and deployment schedules

Section 38 restricts covered uses connected with public-assistance benefits or material impacts on residents' rights, civil liberties, safety, or welfare unless they comply with OPM and DAS policies and standards. It separately addresses authorization of AI procurement, purchase, or acquisition. For authorized acquisitions, the agency must complete an impact assessment consistent with those policies and standards, submit it to DAS, and post it on the agency website at least sixty days before deployment. Personally identifiable information may be redacted.

That publication interval belongs in the implementation schedule. Procurement approval, technical acceptance, assessment preparation, redaction review, and public posting need named owners and realistic lead times. An intended go-live date should not become a reason to rush the assessment at the end of a project.

The detailed assessment method must follow the applicable OPM/DAS requirements. As a practical review, program teams should also ask how a system's performance varies across affected populations, how staff recognize and correct errors, and how existing appeal or review procedures handle AI-influenced decisions. Those questions help examine operational consequences; the applicable OPM/DAS requirements remain the basis for the assessment.

For existing systems, establish what earlier and amended rules require, which evidence already exists, and where remediation is necessary. Existing inventory and ongoing assessment duties make this more than a review of new purchases.

Employment technology needs its own scope review

Under section 7, automated employment-related decision technology processes personal data and generates outputs that are a substantial factor in making or materially influencing an employment decision. The definition includes important exclusions, including certain incidental uses and decisions involving scheduling, planning, workplace health and safety, or productivity monitoring. A label such as workforce analytics does not resolve coverage either way.

The employment discrimination law's definition of employer includes the state and its political subdivisions. That makes the October 2026 discrimination amendments relevant to public employers. The separate developer/deployer rules use their own definitions, including a person doing business in the state; counsel should confirm the applicable role and deployment trigger rather than assume every provision has identical public-sector coverage. Connecticut employment-law definitions

For covered October 2027 deployments, section 9 addresses plain-language disclosure when the technology interacts with an employee or applicant, subject to its obvious-interaction exception. Section 10 requires pre-decision written notice covering the technology's purpose and trade name, the decision, personal-data categories and sources, how the data is assessed, and deployer contact information. Section 8 addresses developer information and permits a binding contract to assign specified notice duties to the developer. Protected information may be withheld under section 11, with notice of the withholding and its basis.

HR, procurement, and legal teams should identify who will deliver those notices and obtain the information needed to do so. Testing evidence remains valuable for detecting and addressing discriminatory outcomes even where the law does not prescribe a universal audit.

Vendor assurance and agency accountability belong together

Other states illustrate different approaches. California's March 2026 Executive Order N-5-26 directs recommendations for certifications that may enter procurement processes; it does not itself impose an immediate universal vendor attestation. The order also addresses internal state adoption and safeguards. Illinois's Public Act 104-0538 establishes independent audit duties for covered large frontier developers, a different role and scope from an agency's deployment assessment.

The procurement lesson is to connect supplier evidence with the agency's actual use. A developer's evaluation may inform an assessment, but the agency still needs to understand its data, configuration, decision process, and operating controls.

Fund a continuing function

Inventory maintenance, assessment review, vendor coordination, staff training, and public-record preparation require capacity. Leaders should estimate that workload against existing staff and contract support, identify the applicable budget authority, and document any resource gap. A statutory deadline alone does not establish whether an agency's current appropriation is sufficient.

Start with the systems and decisions that fall within the law, then prioritize the evidence gaps that threaten a required approval or deployment date. Build the resulting tasks into procurement and operating budgets, with responsibilities that survive personnel changes. Other states can use this approach to improve AI oversight while applying their own laws and organizational arrangements.

Sources and further reading

Spartan X's AI and cybersecurity practices connect governance requirements with the inventory, assessment, procurement, and operating decisions that make responsible deployment sustainable.

Share this article
LinkedIn

BUILD WITH US

Ready to Solve Hard Problems?

Spartan X builds AI systems, autonomous platforms, and cybersecurity solutions for defense and national security.