Law / United States / Connecticut

Frontier Developer Catastrophic-Risk Whistleblower Protections

2026 Conn. Pub. Acts 26-15, Sec. 2

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force in 8 days, effective 1 October 2026.

An AI governance rule binding private bodies.

As of 6 September 2026.

What it requires

  • This duty takes effect October 1, 2026.
  • If you are a frontier developer, do not retaliate against a covered employee for reporting a reasonable, good-faith belief that your activity poses a specific and substantial danger to public health or safety through a catastrophic risk.
  • If you are a large frontier developer with annual gross revenue over five hundred million dollars, establish by January 1, 2027 an internal process letting a covered employee anonymously report such a concern.
  • Share each report and update with your officers and directors at least quarterly, withholding it from any officer or director the report accuses of wrongdoing.
  • Give covered employees notice of their rights under this section, at hiring and periodically afterward.

What it reaches

How the hook was established

express

What makes it apply

Operator establishment

What it makes you log

Logging duty

Section 2 never uses the words logs, records or audit trail. It requires a large frontier developer to maintain a process for a covered employee to submit a report and to receive reasonable updates on the status of the investigation and the actions taken, and requires each report and update to be shared with officers and directors at least quarterly. That is documentation created and periodically produced to a named internal audience, which cannot happen without the report and update being written down, so the duty is implicit. The report is triggered by a specific and substantial danger to public health or safety through a catastrophic risk, which the section defines to include a cyberattack, expert assistance in a chemical, biological, radiological or nuclear weapon, and loss of control over the model.

Kind
Implicit
As of
21 September 2026
Provision
Sec. 2(c) and (d)
Trigger
security_incident

Who checks it

Audit expectation

periodic

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Takes effect October 1, 2026.

A frontier developer, defined as anyone who trains or intends to train a foundation model using more than ten to the twenty-sixth power of computing operations, may not retaliate against a covered employee for reporting a reasonable belief that the developer's activity poses a specific and substantial danger to public health or safety through a catastrophic risk, defined to include contributing to more than fifty deaths or serious injuries or more than one billion dollars of property damage or loss from a single incident.

A large frontier developer, one with annual gross revenues over five hundred million dollars, must by January 1, 2027 establish an internal process for a covered employee to anonymously report such concerns, share reports with officers and directors at least quarterly, and give employees notice of their rights under the section.

A frontier developer that violates the notice or anti-retaliation provisions is liable to the state for a civil penalty of up to one thousand dollars per violation, recoverable by the Attorney General in Superior Court for the judicial district of Hartford.

When LexLint raises it

  • trains_models

Read the law

official session Public Act text, Connecticut General Assembly

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app