Three US state privacy changes take effect on 1 July 2026: Connecticut's substantial amendments to its Data Privacy Act under SB 1295 (enacted as Public Act 25-113), Utah's amendments to the Utah Consumer Privacy Act under HB 418, and Arkansas's Children and Teens' Online Privacy Protection Act, HB 1717. They are not three of a kind — Connecticut's is an amendment to a comprehensive law, Utah's amends a comprehensive law and adds social-media portability rules, and Arkansas's is a narrower, minors-focused statute. Together they deepen a US privacy landscape that spans roughly 20 states with comprehensive laws, depending on how narrower statutes like Florida's are counted, and that still has no federal law to unify them. The most consequential of the three, Connecticut's, is notable beyond its own borders because it pushes state privacy law into the governance of AI.

Connecticut: the widest reach, and an AI-governance signal

Connecticut's Data Privacy Act has been in force since 2023, but SB 1295 changes both who is covered and what coverage requires. The applicability threshold drops from 100,000 to 35,000 consumers, and — more significantly — two triggers lose any volume threshold at all: a business is now covered if it processes any sensitive data, or if it offers any personal data for sale in trade or commerce, regardless of how few residents it touches. That is a shift from scale-based to conduct-based coverage, and it pulls a large tranche of mid-size and niche businesses into scope for the first time. The amendments also narrow the entity-level exemption that many financial institutions had relied on under the Gramm-Leach-Bliley Act.

The substance expands in step with the scope. The definition of sensitive data grows to include neural data, along with additional health, gender-related, financial-account and government-identifier categories. Data-minimisation duties tighten: collection must now be not only reasonably necessary but also proportionate to the disclosed purposes. On automated decision-making, the amendments broaden the profiling opt-out — where it previously reached only solely-automated decisions, it now covers profiling in furtherance of decisions that produce a legal or similarly significant effect — and add a requirement to conduct impact assessments for such profiling, which applies to activities created or generated on or after 1 August 2026.

The provision that stands out most is a disclosure requirement: Connecticut controllers must now state in their privacy notice whether they use or sell personal data to train large language models. It is a small sentence with large implications, because it forces a company to answer a question many have never formally posed internally — which of its data flows feed AI-training pipelines — and it places that answer in a public notice, where an inaccurate statement becomes an enforcement risk. Privacy practitioners have described it as genuinely novel in US privacy law, and as one of the clearest early examples of a state data-protection statute regulating AI training directly. The amendments also impose a blanket prohibition on targeted advertising to, and the sale of personal data of, consumers under 18.

Utah and Arkansas: narrower, but pointed

Utah's HB 418 is a quieter change with a practical edge. It adds a right to correct inaccurate personal data — a gap in the prior Utah Consumer Privacy Act, which had been the most business-friendly of the early state laws — bringing Utah in line with other comprehensive state regimes. It pairs that with the Digital Choice Act, which imposes data portability and interoperability obligations on social-media platforms, requiring them to let users export their data in a machine-readable format and move it elsewhere.

Arkansas's contribution needs to be characterised precisely, because early commentary sometimes overstated it. HB 1717, the Children and Teens' Online Privacy Protection Act, is not a comprehensive consumer privacy statute in the mould of Connecticut's or Utah's. It is a minors-focused law, closer to an expanded COPPA: it applies to operators of online services directed at children or teens, or with actual knowledge that they collect minors' data, and it restricts using the data of the children and teens it covers for targeted advertising, embeds data-minimisation and retention limits, and grants those minors and their parents rights to access, delete and correct information. Enforcement sits exclusively with the Arkansas Attorney General.

The dates around the 1 July wave

It is worth placing these three changes on the calendar accurately, because 2026 is a year of rolling effective dates rather than a single deadline. The comprehensive privacy laws of Indiana, Kentucky and Rhode Island took effect earlier, on 1 January 2026, not in July. Looking just past the July wave, California's expanded data-broker requirements — more detailed registration disclosures under SB 361 and the centralised deletion mechanism associated with the Delete Act — take effect on 1 August 2026, the same date Connecticut's profiling impact-assessment duty begins to apply. The mid-year picture, in other words, is a sequence: comprehensive laws in January, three more changes in July, and data-broker and assessment duties in August.

What it adds up to

Two themes run through the July changes. The first is fragmentation: without a federal privacy statute, each state keeps legislating on its own schedule and its own terms, and while many still follow the Virginia-style template, the recent amendments are causing them to diverge — different thresholds, different sensitive-data lists, different rights. In practice, most national organisations manage this by building a baseline programme and layering state-specific requirements on top, but the layering is getting deeper and more jurisdiction-specific with each amendment cycle. It is a sharp contrast with omnibus regimes such as the EU's GDPR, and it is the environment that global and regional companies serving US consumers have to navigate.

The second theme is that privacy law is quietly becoming a vehicle for AI governance. Connecticut's LLM-training disclosure, its broadened opt-out around automated decisions, its impact-assessment requirement and its treatment of neural data as sensitive all point the same way: in the absence of dedicated AI legislation at the federal level, state data-protection statutes are where obligations on automated decision-making and AI training are actually landing.

Key Takeaways

  • Three US state privacy changes take effect on 1 July 2026: Connecticut's CTDPA amendments (SB 1295 / Public Act 25-113), Utah's HB 418, and Arkansas's Children and Teens' Online Privacy Protection Act (HB 1717) — added to a patchwork of roughly 20 states with comprehensive privacy laws and no federal equivalent.

  • Connecticut's is the widest-reaching: it cuts the coverage threshold from 100,000 to 35,000 consumers (with no threshold at all for processing sensitive data or offering personal data for sale), adds neural data and other categories to the sensitive-data list, tightens data minimisation, broadens the opt-out around profiling for significant automated decisions, prohibits targeted advertising to and sale of the data of consumers under 18, and requires companies to disclose whether they use personal data to train large language models — a step described as novel for US privacy law.

  • Utah's HB 418 adds a right to correct inaccurate data plus social-media portability under the Digital Choice Act; Arkansas's HB 1717 is a minors-focused law (not a comprehensive statute) that restricts targeted advertising to the children and teens it covers and grants those minors and their parents access, deletion and correction rights.

  • The July changes sit within a year of rolling dates: Indiana, Kentucky and Rhode Island's comprehensive laws took effect 1 January 2026; California's expanded data-broker rules and Connecticut's profiling impact-assessment duty begin 1 August 2026. The structural story is fragmentation — and privacy law increasingly carrying AI-governance obligations in the absence of a federal framework.