In May 2026, the state of Connecticut passed a law called SB 5, on the books as Public Act 26-15.
It is the widest AI law any US state has passed so far. One law, five types of AI products. First deadline: 1 October 2026, about ten weeks away.
Here is the trap: you don't need an office in Connecticut for this law to apply to you. You just need users there. And if your product is on the internet in the US, you have users there.
Why one state's law becomes everyone's law
America has no single national AI law. Each state writes its own. Since you can't ship a different app for each state, you end up building for the toughest state your users live in.
California wrote the rules for AI companion apps. New York City wrote the rules for AI hiring tools. Connecticut just wrote rules for five categories at once, and gave its Attorney General, the state's chief legal officer, the power to act against companies that break them.
That is not an empty threat. State enforcers and private lawsuits are already reshaping AI companies. You will see real cases under each section below.
Five categories. Find yours.
1. AI hiring tools
Building in one of these categories? Send me one message about what you're building and I'll name the laws you're inside — which documents they demand, and what covers you. Free, usually within a day or two. Start here.
— Santosh
Who this describes. Products that screen resumes, rank candidates, score video interviews, or recommend promotions. Think of the space HireVue, Eightfold AI, Paradox, and Sapia.ai operate in, and every early-stage startup building "AI recruiter" or "AI interviewer" products.
The rule. From 1 October 2027, any Connecticut employer using AI to help hire, promote, discipline, or fire someone must tell that person first, in writing, before the decision. The notice must include four things: what the tool is for, the tool's trade name, the categories of data it analyzes, and where that data comes from. Earlier deadline: from 1 October 2026, an employer filing a mass-layoff notice must declare whether the layoff is connected to AI.
How it affects you. Your customer cannot write that notice without you. It must name your product and your data sources. So every enterprise deal will now include the question: "Give us the disclosure pack." The vendor who has it ready closes. The vendor who says "let me check with legal" loses a quarter. Two traps inside the law: "the AI did it" is not a defense to a discrimination complaint, and if your tool was tested for bias, that test can be shown as evidence in court. Testing is not compulsory, but "no, we never tested it" is the other side's best exhibit.
Mobley v. Workday. A job applicant over 40 sued Workday, claiming its AI screening rejected him and others like him. A federal court let the case proceed as a collective action, meaning applicants across the country can join, and in January 2026 the court authorized notice to potentially millions of rejected applicants. The critical legal point: the court accepted that the AI vendor itself, not just the employer, can be sued as if it were making the hiring decision. That is the exposure model every hiring-AI founder now lives with.
2. AI companions and chatbots
Who this describes. Companion apps, AI friends, roleplay chat, AI therapy-adjacent products, and any assistant that builds an ongoing emotional relationship with the user. The space Character.AI and Replika defined, plus mental-health chat products like the one Woebot built.
The rule. From 1 January 2027, a companion AI serving Connecticut users must: (1) detect talk of suicide or self-harm and respond with a protocol built on evidence-based methods, a real crisis flow rather than a generic helpline line; (2) tell users they are talking to a machine, within 1 hour of use for children and 3 hours for adults; (3) drop engagement features designed to make users emotionally dependent or isolated.
How it affects you. Rule three regulates your growth mechanics. The streak counter. The "your companion misses you" notification. The guilt message when a user leaves. The features that moved your day-2 retention from 18% to 31% are now, in Connecticut, something a regulator can act against. Your retention dashboard and your legal exposure have become the same document. And Connecticut is the fourth-plus state on this path. California's SB 243 (in force since January 2026) demands crisis protocols and disclosure, New York and Utah have chatbot laws, Illinois banned AI "therapy" outright. Build the safety flow once, properly, and it covers all of them.
In January 2026, Character.AI and Google agreed to settle five lawsuits from families who said the chatbot contributed to teen suicides and mental-health harm, after a court refused to throw the first case out. Terms are confidential; more family suits are still being filed. Separately, the Texas Attorney General has an open investigation into companion apps' marketing to minors, and Pennsylvania's AG has acted against a chatbot persona that presented itself as practicing medicine. The lesson: this exposure existed before any AI statute. The new laws only add to it.
3. Synthetic media platforms
Who this describes. Products that generate or heavily edit images, video, voice, or text. The space Midjourney, Runway, ElevenLabs, Synthesia, and HeyGen operate in, plus every consumer app with an "AI avatar" or "AI edit" feature.
The rule. From 1 October 2026, if your product has more than one million monthly users, AI-generated or substantially altered content must be disclosed as AI-made.
How it affects you. One million monthly users is not "later-stage problem" territory for a consumer AI product. One viral week can take you across the line, and the deadline is this October. If you are at 600K users and growing, the labeling system belongs on your roadmap now. This is a pattern, not a one-off: California's AB 3211 already requires content labeling, and the federal TAKE IT DOWN Act forces platforms to remove fake intimate images within 48 hours of a report. That duty went live in May 2026. Watermarking standards like C2PA were optional polish in 2024. In 2026 they are a compliance deadline.
The money fights in this category are the training-data lawsuits: The New York Times v. OpenAI and Microsoft (the marquee test of whether training on copyrighted work is fair use) and Getty Images v. Stability AI (trial expected 2028). Neither is decided, which means every synthetic-media startup is building on legally unsettled ground, and the disclosure rules above are the part you can control today.
4. Products used by teenagers
Who this describes. Any consumer product with users under 18: social apps, study tools, games with chat, companion apps, content platforms. If teenagers are anywhere in your funnel, this section is yours even if your marketing says 18+.
The rule. From 1 January 2028, platforms serving Connecticut minors must: verify age; get a parent's permission before showing a personalized recommendation feed; cap algorithmic feeds at one hour per day by default for minors; give parents real control tools; and display health warnings about social media use.
How it affects you. The enforcement model is the difference. For most of SB 5, only the Attorney General can act: one office, one docket. For some of the minors' provisions, parents can sue your company directly. Your risk shifts from "one regulator might notice us" to "any parent with a lawyer is a potential case", and insurers, investors, and acquirers all read that difference loudly. You also cannot wait for 2028: age verification and parental consent touch signup, data storage, and feed architecture. Nebraska's and South Carolina's kids' codes are in force now; the federal children's privacy rule (COPPA) already requires separate parental opt-in before children's data can train AI models, with full compliance since April 2026.
FTC v. NGL Labs. NGL ran an anonymous messaging app popular with teens, sent fake AI-generated messages to keep users engaged, and claimed AI moderation kept kids safe. The FTC and the Los Angeles DA shut that down in 2024: a monetary settlement and, the historic part, a ban on offering the app to anyone under 18 at all. First order of its kind. Claiming AI safety features you can't prove is itself the violation.
5. Developers training large AI models
Who this describes. Frontier labs and large model developers (the OpenAI, Anthropic, Google DeepMind, Meta, and Mistral tier) and the next tier of startups training large models on serious compute. The thresholds target the biggest systems; if you are fine-tuning open models, read this as where your suppliers' obligations are heading.
The rule. Connecticut, from 1 January 2027: large frontier developers must run a safe, anonymous channel for employees to report AI safety concerns, and cannot punish whistleblowers who use it. Up to $1,000 per violation, each violation counted separately. Illinois, signed 6 July 2026 and effective January 2027: SB 315 requires large model developers to undergo independent third-party safety audits, publish their safety practices, and report serious safety incidents. It is the first US law to demand outside audits of how models are built.
How it affects you. The fine is small; the shift is not. For the first time, US states regulate the lab itself: internal processes, employee channels, HR practices, not just the shipped product. Your employee handbook is now a compliance surface. And if you are raising a round on a frontier training run, expect investors to ask about audit-readiness the way they already ask about SOC 2. There is no enforcement case yet because neither law is in force. The founders who set up reporting channels and an audit relationship in 2026 will watch everyone else scramble for auditors in December.
The one-line summary for each founder
Hiring AI: your disclosure pack is now part of your product, and Mobley says the vendor can be sued directly.
Companion AI: your retention tricks are now a legal question, and the Character.AI settlements show the exposure predates the statute.
Synthetic media: labeling is a feature with an October deadline. Build it before your viral week, not after.
Teen products: parents can sue you directly, and NGL shows regulators will ban you from the under-18 market entirely.
Model labs: the lab itself is now regulated, in two states and counting.
None of this kills a roadmap. But it decides who wins the regulated customer, and the best model rarely does. The product with its paperwork ready does.
Building in one of these five categories? Send me one message about what you're building, and I'll name the rules you're inside.