Connecticut’s AI Responsibility and Transparency Act (better known as the “CAIA”) takes effect on October 1, 2026. If your company uses artificial intelligence in any aspect of employment decision-making, the time to prepare is now.
We wrote about the CAIA earlier this year, identifying the law’s key provisions and what they mean for employers. This post builds on that earlier discussion with a practical focus: what employers should do now to be ready by October 1.
A Quick Refresher: What the CAIA Requires
The CAIA regulates the use of “high-risk” artificial intelligence (“AI”) systems, meaning those used to make or substantially inform consequential decisions about people. For employers, it applies to AI tools used in hiring, promotion, discipline, termination, and other significant employment decisions.
The law draws a distinction between developers (the companies that build AI systems) and deployers (the companies that use them). Most employers fall into the deployer category. If you use any AI-powered tool that makes or substantially informs employment decisions, you may be covered as a deployer. Common examples include resume-screening software, automated candidate interview tools, and performance evaluation platforms.
If you are a deployer of a high-risk AI system, the CAIA requires you to:
- Implement a risk management policy that governs your use of AI in employment decisions.
- Conduct impact assessments of your high-risk AI systems, evaluating the system’s purpose, intended benefits, potential risks of algorithmic discrimination, and the categories of data processed.
- Provide transparency notices to employees and applicants, informing them when AI is being used in decisions that affect them, including a description of the system’s purpose and the type of decision being made.
- Offer a right to appeal, allowing individuals to request human review of an AI-assisted decision where feasible.
Importantly, using a vendor’s tool does not insulate you from liability. Even if you purchased or licensed an AI system from a third-party provider, the CAIA places the compliance burden on the deployer, not the vendor that built the technology.
What Employers Should Be Doing Right Now
With about two weeks until October 1, here is a practical compliance checklist:
1. Conduct an AI inventory. Start by identifying every AI-powered tool your company uses in the employment context. Look beyond hiring: performance management platforms, scheduling tools, and workforce analytics systems may also be covered. Companies are often surprised to discover how many AI tools are already embedded in their workflows.
2. Classify your systems. Determine which systems qualify as “high-risk” under the CAIA. If a system makes or substantially informs a consequential employment decision, it is likely covered.
3. Draft and adopt a risk management policy. Your risk management policy should be tailored to your organization and the specific AI tools you use. It should address governance and oversight responsibilities, the steps you take to test for bias and ensure fairness, how you monitor system performance over time, and protocols for responding to issues when they arise.
4. Complete your impact assessments. For each high-risk system, document the system’s purpose and intended use, the types of data it processes, the potential risks of algorithmic discrimination, and the safeguards you have implemented. This should not be a one-time exercise: plan to update your assessments periodically and as your AI tools change.
5. Update your notices. Review your job postings, application materials, employee handbooks, personnel policies, and any communications associated with performance reviews or disciplinary processes. Make sure that appropriate disclosures are in place wherever AI plays a role.
6. Establish a human review process. Determine how individuals can appeal AI-assisted decisions and ensure the process is clearly communicated. This may require training managers on how to conduct meaningful human review.
7. Review your vendor contracts. If you rely on third-party AI tools, review your contracts now and consider whether your vendor is obligated to provide bias audit results, technical documentation, or cooperation with your impact assessment. If those provisions are missing, this is the time to negotiate them.
8. Train your team. Make sure your HR professionals, hiring managers, and in-house counsel understand the new requirements. An employer’s best defense is a workforce that understands the rules.
Enforcement and Penalties
Employers who fail to comply risk enforcement actions that may include civil penalties. The law includes provisions designed to encourage good-faith compliance, but the potential for reputational harm and legal exposure makes delay a risky strategy.
Additionally, employers should keep in mind that the CAIA is not their only source of AI-related risk. AI tools that produce discriminatory outcomes may also expose employers to liability under existing federal and state anti-discrimination laws, including Title VII and the Connecticut Fair Employment Practices Act. The CAIA’s requirements are best understood as an additional layer of compliance, not a replacement for the obligations employers already have.
Bottom Line
October 1 is only weeks away. If your organization uses AI in any aspect of employment decision-making, act now. Compliance with the CAIA protects your organization from penalties and, just as important, ensures that your use of AI in the workplace is fair, transparent, and defensible.
For more background on the CAIA’s key provisions, be sure to read our earlier post on the law.
If you have questions about the CAIA or need assistance preparing for compliance, please reach out to Claire Pariano.
