Connecticut AG Sets AI Compliance Rules Under State Privacy Law

    Hunton Andrews Kurth LLP30 Mar 2026

    Why it matters

    Why it matters: State-level AI enforcement is accelerating, and Connecticut's guidance creates concrete legal obligations that could expose companies to AG investigations and penalties.

    The brief

    Summary

    Connecticut's Attorney General issued clarifying guidance on how the Connecticut Data Privacy Act (CTDPA) applies to AI systems, signaling active enforcement intent. Companies using AI to process Connecticut residents' data must now align automated decision-making practices with state privacy requirements. This adds to a growing patchwork of state AI regulations that compliance teams must track independently of federal action.

    Key takeaways

    • 01**Audit** AI systems that process Connecticut residents' data for CTDPA compliance gaps immediately.
    • 02**Review** automated decision-making workflows — consent, opt-out rights, and transparency obligations likely apply.
    • 03**Prioritize** this alongside similar laws in Texas, Colorado, and Virginia to manage multi-state exposure.
    • 04**Engage** legal counsel to assess whether current AI vendor contracts satisfy new compliance requirements.

    Bottom line

    The bottom line: State AGs are filling the federal AI regulation vacuum — Connecticut just raised the compliance bar, and enforcement will follow.

    Read the full article at Hunton Andrews Kurth LLP

    Original reporting © Hunton Andrews Kurth LLP. This page carries Matthew Carr's editorial summary.

    Related AI Compliance