Connecticut's AI law binds Thursday — and not with the duties you prepared
Twelve developments across eight jurisdictions this week, and the through-line is staging: the gap between what a regulator's press release says commences, and what the enacted text actually does. We read Connecticut's CART Act section by section, and four duties bind on 1 October that were on no watch list — while the two everyone is preparing for do not commence at all.
Correction to #36: our Deadline Watch listed Connecticut's AEDT notice duties as commencing 1 October 2026. They do not. Read against the enacted text of Public Act 26-15, the developer-to-deployer disclosure, the AI-interaction disclosure and the written pre-decision notice (Secs 8–10) attach only where a deployer deploys the technology on or after 1 October 2027; the WARN-AI disclosure (Sec. 26) and the frontier-developer whistleblower provisions (Sec. 2) were correctly dated. (enacted text)
At a Glance
Connecticut AI Act binds Thursday — four duties commence 1 October that were on no watch list, while the two everyone is preparing for do not commence at all.
IVDR class C cliff Saturday — self-declared legacy in-vitro diagnostics need a signed notified-body agreement by 26 September or they leave the transition regime.
Italy's AI liability decree lands — a legislative decree adapting Italian policing and civil/criminal liability law to the EU AI Act enters into force 30 September.
Ireland fines Google €403 million — the DPC's location-data decision also orders Google to bring processing into compliance within six months.
DOJ bills contractor $2 million — a False Claims Act settlement over NIST SP 800-171 non-compliance on a Department of Defense network.
Ofcom probes Pornhub age checks — the first UK investigation into age assurance built on a third party's signals, in this case Apple's.
Critical Actions
Connecticut — CART Act first tranche commences 1 October (7 days). Public Act 26-15 is staged section by section. Four duties bind on 1 October: generative-AI providers with more than one million users per month must embed tamper-resistant provenance data in AI-created or materially altered audio, image and video (Sec. 15, naming the Coalition for Content Provenance and Authenticity by name); any AI product sold to Connecticut consumers on a subscription needs a written key-terms notice and the consumer's written acceptance before signup, renewal and fee collection (Sec. 1); employers filing a federal WARN notice must tell the Labor Department whether the layoffs relate to their use of AI (Sec. 26); and under the amended state discrimination statutes, using an automated employment-related decision technology “shall not be a defense against a complaint” (Secs 13–14). The chatbot and companion duties are 1 January 2027; the AEDT disclosure package is 1 October 2027. Action: Before 30 September, confirm provenance marking on any consumer genAI system above one million monthly users, gate subscription signup and renewal on written acceptance, brief HR on the WARN disclosure field, and assemble the anti-bias testing record for every employment tool touching Connecticut. Connecticut Public Act 26-15 — enacted text
EU — IVDR class C legacy transition closes without a signed notified-body agreement (26 September, 2 days). Under Article 110(3c) of the IVDR as inserted by Regulation (EU) 2024/1860 — not, as widely reported, Regulation (EU) 2022/112 — a class C in-vitro diagnostic self-declared under the old IVDD keeps the extended transitional period to 31 December 2028 only if the manufacturer and a notified body “have signed a written agreement” no later than 26 September 2026. The agreement is one of six cumulative conditions: a formal application had to be lodged by 26 May 2026 and a quality management system had to be in place by 26 May 2025, both of which have passed. A signature this week therefore preserves the transition only for manufacturers who already applied in time. Action: Confirm by Saturday that every self-declared class C device has a countersigned notified-body agreement on file, and check it back against the 26 May 2026 application record. Regulation (EU) 2024/1860
Italy — AI Act adaptation decree enters into force 30 September (6 days). Decreto Legislativo 9 settembre 2026, n. 160 was published in Gazzetta Ufficiale Serie Generale n. 214 of 15 September and enters into force on 30 September. Issued under Article 24 of Legge 132/2025, its stated subject is adapting Italian national law to Regulation (EU) 2024/1689 in two areas: the use of AI systems in policing activity, and civil and criminal liability. Clause-level accounts circulating in Italian professional commentary have not been confirmed against the decree's own articles and should not be relied on until they are. Action: Have Italian counsel read the decree's articles before 30 September and map any criminal-liability exposure onto your high-risk AI inventory. Normattiva — D.Lgs. 160/2026
Enforcement Watch
Ireland / Google — €403 million. On 21 September the Data Protection Commission closed an own-volition inquiry opened in February 2020 into Google Ireland Limited's handling of Web & App Activity, Location History and Location Accuracy between 25 May 2018 and 4 February 2020. It found infringements of lawfulness and fairness, accountability, transparency and retention, and ordered Google to bring processing into compliance within six months. The full decision has not yet been published. DPC announcement
DOJ / Honeywell — $2,042,518. Honeywell Aerospace Inc. agreed to resolve False Claims Act allegations that a business unit of Honeywell International Inc. submitted claims for payment between April 2020 and December 2023 while failing to meet NIST SP 800-171 requirements on a network used for a Department of Defense contract. The whistleblower receives $375,823. The claims are allegations only, with no determination of liability — but the Civil Cyber-Fraud Initiative continues to treat a self-assessed SPRS score as a representation you can be sued on, independently of the CMMC timetable. DOJ announcement
Massachusetts / TradeZero America — $750,000. The Securities Division's 17 September consent order turns on a third-party web-chat service breached in July 2024, exposing personal information and uploaded documents belonging to thousands of customers. The Division found failures to vet the vendor before and after engagement and to confirm the exposed data was deleted despite a ransom payment. An independent compliance consultant is also imposed. Every firm that bolted a chatbot or support widget onto a client-facing surface this year should read this as the template. Massachusetts Securities Division
HHS OCR / Ambry Genetics — $700,000. Ambry paid $700,000 and accepted a two-year corrective action plan over a January 2020 phishing compromise that potentially exfiltrated the protected health information of 225,370 individuals. OCR's cited failures are the familiar three: no accurate and thorough risk analysis, no termination-of-access procedures, and no unique user identification across systems holding ePHI. OCR announcement
Ofcom / Aylo — investigation opened, exposure £18m or 10% of turnover. On 23 September Ofcom began a formal investigation into Aylo, the service provider of Pornhub, over an age-assurance process deployed in May 2026 that relies on signals from Apple indicating a UK user may have completed Apple's own age checks. Two duties are in scope: highly effective age assurance, and whether Aylo completed a suitable and sufficient children's access assessment. Ofcom states it will not determine how Apple operates its age checks. Ofcom announcement
China / CAC — ten typical enforcement cases. The 15 September roundup spans the Cybersecurity Law, Data Security Law, PIPL and the Network Data Security Management Regulation, and includes collection of facial-recognition records without separate consent, cross-border export of personal information without a security assessment, and an AI mini-program ordered offline for failing to label AI-generated content and skipping its security assessment. Penalties ran from warnings to fines with personal liability for responsible managers; amounts were not disclosed. CAC roundup
Deadline Watch
26 Sep — IVDR signed notified-body agreement for self-declared class C legacy devices (EU, 2 days).
28 Sep — CISA discontinues the weekly Vulnerability Summary Bulletin under BOD 26-04 (US, 4 days).
30 Sep — Italy D.Lgs. 160/2026 in force; FedRAMP machine-readable (OSCAL) format required for new Rev5 packages; California's window closes on eleven enrolled AI bills (Italy / US / US-CA, 6 days).
1 Oct — Connecticut CART Act first tranche; Austria NISG 2026 in full force; China MPS Order No. 176 inspection measures (US-CT / Austria / China, 7 days).
2–3 Oct — TC260 agent-system security practice guide comments close; Poland NIS2 entity registration closes (China / Poland).
17 Oct — China State Council draft regulation on minors' internet use — comments close (China).
20–21 Oct — Australia FWC generative-AI guidance note effective; DEA placement of diphenidine in Schedule I effective (Australia / US).
26–31 Oct — UK Cyber Security and Resilience Bill Lords Report stage; Italy NIS2 ACN baseline measures for listed entities (UK / Italy).
13 Nov — EDPB Guidelines 04/2026 consultation closes; India DPDP Rule 4 commences (EU / India).
16–17 Nov — California EO N-9-26 GovOps recommendations due; DOJ/Pinnacle Tunney Act comments close (US-CA / US).
23 Nov — CMS Part D pharmacy contracting RFI comments close (US).
11 Dec — Cybersecurity Information Sharing Act 2015 protections lapse (US).
Around the World
United States — The Antitrust Division's proposed consent decree with landlord Pinnacle Property Management Services, noticed at 91 FR 59304 on 18 September in United States v. RealPage, bars Pinnacle from using any revenue-management product that ingests external non-public competitor data at runtime, pools or discloses it, or that was trained on it. The reach into the training corpus is the part to read twice: it is the clearest federal statement yet that an algorithm's provenance, not just its live inputs, can be the remedy's target. Tunney Act comments close on or about 17 November. 91 FR 59304
China — On 18 September the CAC released a State Council-level draft Regulation on Ensuring Minors' Healthy and Safe Use of the Internet for comment to 17 October. The 25-article draft binds network-service providers, smart-terminal makers and app-distribution platforms, and carries penalties of one to ten times illegal gains where those gains reach RMB 1 million, or RMB 100,000–1,000,000 otherwise, plus RMB 10,000–100,000 on responsible individuals, with suspension, site or app closure and licence revocation in serious cases. The effective date is left blank pending finalisation. CAC draft for comment
European Union — Two supervisory instruments landed within four days. The EBA published final Guidelines on the management of third-party risk on 18 September, replacing the fragmented outsourcing regime with a single lifecycle framework covering ICT and non-ICT arrangements that support critical or important functions, aligned with DORA; a two-year transitional period applies, though the EBA has not published the date it runs from and the text awaits translation. On 21 September the EDPB adopted Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR — a five-step method with 14 worked examples, replacing the legacy WP29 guidance and complementing (not replacing) Guidelines 04/2022 on fine calculation. Consultation closes 13 November. EBA Guidelines · EDPB plenary
California — Governor Newsom issued Executive Order N-9-26 on 18 September, directing GovOps to report no later than 16 November on the technical feasibility of four amendments to state AI law: embedding independent verification organisations inside large frontier labs, independent verification of the safety frameworks already filed under state law, a kill switch for frontier models with ongoing efficacy verification, and a widened definition of reportable critical safety incidents to cover loss-of-control events. The order creates no rights enforceable at law and no duty on any company today. Separately, eleven enrolled AI bills remain unsigned with the constitutional window closing 30 September — and SB 1000 carries an urgency clause, so a signature on the 30th is an obligation on the 30th. Executive Order N-9-26
Deep Dive
United States (Connecticut) · AI Governance / Employment / Consumer Protection
Connecticut's CART Act: the duties that actually bind on 1 October
Connecticut's Attorney General published business-and-consumer guidance on 16 September. It opens by telling consumers that “beginning October 1, 2026” they gain rights under new AI laws, and then lists the CART Act's chatbot-and-children provisions and its AI-and-employment provisions underneath that sentence. Read as a compliance calendar, that ordering is wrong, and it is wrong in the direction that wastes the most money: it points teams at two packages that do not commence on 1 October while saying nothing about four that do.
Public Act 26-15 is staged section by section, and every section carries its own effective-date parenthetical in the enacted text. The AI companion provisions — the self-harm detection protocol with its 9-8-8 referral, the “do not claim to be a human being” safeguard, the prohibition on romantic or sexually explicit interaction with minors, the screen-time and parental tooling — sit in Secs 4 to 6, each of which reads “(Effective January 1, 2027)”. The AEDT disclosure package sits in Secs 8 to 10; those sections are themselves effective 1 October 2026, but each duty is conditioned on a deployer deploying the technology “on or after October 1, 2027”. The written pre-decision notice that most employment counsel have been briefing as a seven-day problem is a twelve-month-and-seven-day problem.
What does bind next Thursday is a different list, and in two cases a broader one. Section 15 makes any producer of a generative AI system with more than one million users per month that is publicly accessible to consumers for personal use embed provenance data in AI-created or materially altered audio, image and video, and use commercially and technically reasonable methods — the statute naming the Coalition for Content Provenance and Authenticity expressly — to make that data difficult to tamper with, remove or disassociate. Business-to-business distribution, video games and interactive experiences, and systems used solely for upscaling, noise reduction or compression are carved out. Section 1 reaches further down the market: any provider selling an AI technology to Connecticut consumers on a subscription must give written notice of key terms — expressly including any usage limits — and obtain the consumer's written acceptance before initial subscription, before renewal, and before collecting any fee. Section 26 adds a line to every federal WARN notice filed with the Connecticut Labor Department: whether the layoffs relate to the employer's use of artificial intelligence or another technological change. And Secs 13 and 14 amend the state's discrimination statutes so that the use of an automated employment-related decision technology “shall not be a defense against a complaint” — while the commission or court “may consider evidence of anti-bias testing or similar proactive efforts”, expressly including the quality, efficacy, recency and scope of that testing.
That last pair is the provision with the shortest fuse, because it is evidentiary rather than procedural. It does not ask you to publish anything or notify anyone. It removes a defence on 1 October and names exactly one thing that can be weighed in mitigation — a testing record whose recency is on the statutory list. A record assembled in November is a record that was not current when the defence disappeared…
The analysis continues for CyberEyeQ Pro subscribers. Unlock the full deep-dive recommendations, all five weekly action items, source documents, and jurisdiction-specific compliance checklists.
Subscribe to Pro to read the rest.
Become a paying subscriber of Pro to get access to this post and other subscriber-only content.
UpgradeA subscription gets you:
- Deep dives of each updated regulation
- Source verification documents
- Extended jurisdiction-specific analysis
- Compliance deadline tracker
- Regulation crosswalk