Companies using AI tools to screen resumes, rank candidates, or evaluate employee performance are operating in a regulatory environment that is expanding faster than most compliance teams can track. On May 29, 2026, Connecticut Governor Ned Lamont signed the Connecticut Artificial Intelligence Responsibility and Transparency Act (SB 5) into law, making Connecticut one of a growing number of states requiring employers to disclose how they use automated tools in employment decisions. The law applies not only to companies headquartered in Connecticut but to any employer deploying these tools on employees or applicants within the state.
For organizations already familiar with New York City’s Local Law 144, which was enacted in 2021 and has been actively enforced since July 2023, much of what Connecticut requires will feel recognizable. But familiarity should not lead to inaction. The compliance obligations are specific, the timelines are compressed, and the consequences of noncompliance include enforcement by the Connecticut attorney general under the state’s unfair trade practices framework.
What the Connecticut Law Requires
The law defines “automated employment-related decision technology” broadly. It covers any technology that processes personal data and uses computation to generate outputs such as predictions, recommendations, rankings, classifications, or scores that serve as a “substantial factor” in making or materially influencing employment decisions. That definition reaches well beyond fully autonomous hiring systems. It captures resume screening software, candidate ranking tools, chatbot recruiting workflows, automated interview analysis platforms, and performance analytics systems that shape outcomes even when a human reviewer remains in the loop.
Beginning October 1, 2027, employers using these tools must provide written notice to affected employees and applicants before any employment decision is made. The notice must disclose, in plain language, that the employer is using the technology, the purpose and nature of the decision, the trade name of the tool, the categories and sources of personal data being analyzed, and the employer’s contact information. Employers must also inform individuals when they are interacting with automated technology, unless a reasonable person would find that fact obvious.
Starting even sooner, on October 1, 2026, employers filing WARN Act notices must disclose whether layoffs are related to the adoption of AI or other technological changes. And the law amends Connecticut’s anti-discrimination statute to make clear that using an AI tool is not a defense to a discrimination complaint. Courts may, however, consider evidence of proactive bias testing as a mitigating factor when evaluating whether an employer took steps to prevent discrimination.
The NYC Parallel: Local Law 144 as a Compliance Blueprint
New York City’s Local Law 144 established the first enforceable AI hiring regulation in the United States. It requires employers using automated employment decision tools to commission an independent annual bias audit, publicly post a summary of the results, and provide at least ten business days’ notice to candidates before the tool is used.
The bias audit examines whether the tool’s outputs create disparate outcomes across protected and intersectional demographic groups, using a methodology defined by the law and related guidance. Penalties for noncompliance range from $500 for a first violation to $1,500 per day for ongoing violations. A December 2025 audit by the New York State Comptroller found significant gaps in enforcement, suggesting that tighter scrutiny is likely ahead.
Connecticut’s law shares the same underlying logic. Both focus on transparency, notice, and accountability for employers using automated tools in consequential employment decisions. Both apply beyond their geographic borders, meaning your company does not need to be headquartered in the jurisdiction to fall within scope. If you are making employment decisions about people in Connecticut or evaluating candidates who reside in New York City, these requirements apply to you.
The practical takeaway is straightforward: if your organization has not built a compliance framework around its use of AI in hiring and employment decisions, the window for getting ahead of enforcement is narrowing.
What a Defensible Compliance Program Should Address Organizations that are taking this issue seriously are approaching it as a governance and risk management question. A defensible compliance program should account for how covered tools are identified, how decisions about their use are documented, how required notices and disclosures are managed, and how oversight is maintained as laws continue to evolve.
In practice, that means employers need a framework that addresses transparency, documentation, accountability, and vendor oversight in a way that aligns with the role the tool plays in employment decisions. The right approach will vary based on the organization’s footprint, the functions the tool performs, and the jurisdictions that may apply. What matters most is having a structure that is credible, current, and capable of withstanding scrutiny from regulators, litigants, and other stakeholders.
Why Independent Expertise Matters Here
The Guidepost team brings a practitioner’s perspective to this work. Our experience across compliance, monitoring, and investigations has shown us that the organizations best positioned to meet these requirements are the ones that engage independent expertise early, before enforcement activity or litigation forces the conversation.
Bias audits, in particular, require specialized analytical capabilities. Assessing selection rates, calculating impact ratios across intersectional demographic categories, and evaluating whether a tool’s outputs are producing discriminatory effects are not tasks that a general compliance function can absorb alongside its existing responsibilities. They require subject matter expertise in data analysis, employment regulation, and algorithmic accountability.
The regulatory direction is clear. New York City led with Local Law 144. Connecticut has now followed with a comprehensive framework of its own. Colorado, Illinois, and California have enacted or are advancing similar requirements. Companies operating across multiple states face a growing patchwork of obligations, and building a defensible compliance posture now will be far more efficient than responding to each new law as it arrives.
Getting Started
Connecticut’s law creates a near-term decision point for employers using AI-enabled tools in hiring, promotion, performance evaluation, or other employment decisions. Some provisions take effect as early as October 2026, with broader notice and disclosure requirements following in October 2027. Organizations that have already done work in response to Local Law 144 may have a head start, but they should not assume that existing measures fully address Connecticut’s requirements or the broader direction of state-level regulation.
For organizations that have not yet addressed this area, the immediate priority is understanding where AI-enabled employment tools may be creating legal, operational, and reputational exposure. From there, companies can determine what level of governance, audit support, and cross-functional coordination will be necessary to respond in a way that is both compliant and sustainable. Because scope questions, vendor representations, and jurisdictional triggers are not always straightforward, many employers benefit from independent guidance rather than relying on assumptions or generic templates.
Our team works with companies to conduct these assessments, develop the governance and policy documentation required for compliance, perform independent bias audits, and build programs designed to adapt as additional states enact their own requirements. Reaching out before the compliance deadlines arrive allows your organization to set the pace and scope of this work on its own terms.