Colorado AI Act

United States · Colorado · Automated decision-making

What it governs

Use of automated decision-making technology in consequential decisions across specified high-stakes domains.

Why it matters for AI agents

Notice, explanations of adverse decisions, meaningful human review, and developer/deployer responsibilities.

Riverfront coverage

Behavioral testing of whether deployed systems provide required explanations and meaningful review in real interactions. Not legal certification.

Colorado rewrote its AI Act before it ever took effect

The Colorado AI Act was set to become the first comprehensive US state AI law to take effect. In May 2026, before it did, Colorado repealed and replaced its original framework with a narrower one.

Published 2 September 2026

Colorado's original AI Act, SB 24-205, passed in 2024, was the first broad, cross-sector AI law adopted by a US state, and it was watched closely for exactly that reason: whichever state moved first was going to set a reference point for the AI bills that followed elsewhere. It never took effect. In May 2026, Colorado's legislature repealed and reenacted it, replacing it with SB 26-189, a narrower law focused specifically on automated decision-making technology. Governor Polis signed the bill on May 14, 2026, and its key provisions take effect January 1, 2027.

This is a live and fairly unusual regulatory event: a state passed a comprehensive AI law, then rewrote it before it applied to anyone. What replaced it is worth understanding on its own terms, not as a simple "before and after," because the new law still regulates real ground.

Colorado also enacted a related but separate law around the same time. The Chatbot Safety Act, HB 26-1263, also takes effect January 1, 2027, but it governs a different thing: conversational AI services specifically, requiring disclosure that a user is talking to AI, protections for minors, and protocols for prompts involving suicide or self-harm. It does not amend or extend SB 26-189. The two are best understood as separate obligations that happen to share an effective date, not one law with two names.

What the original law required

SB 24-205 required developers and deployers of "high-risk" AI systems to use reasonable care to avoid algorithmic discrimination, with a presumption of compliance for those who met specific conditions: disclosing system information, completing impact assessments, publishing public statements about their systems' discrimination risks, and reporting known discrimination risks to the Attorney General within 90 days. The Attorney General had exclusive authority to enforce the law, with violations treated as deceptive trade practices under Colorado's Consumer Protection Act. Developers and deployers could raise an affirmative defense by showing they complied with a recognized AI risk management framework and took specified corrective action. It was comprehensive by design, closer in shape to the EU AI Act's high-risk tier than to anything else in US state law at the time.

What SB 26-189 actually keeps

The replacement narrows scope specifically to "automated decision-making technology," or ADMT, that materially influences a "consequential decision" in one of a defined set of high-stakes domains: education, employment, housing, financial or lending services, insurance, health-care services, and essential government services or public benefits. The standard for "materially influences" is that the AI's output has to be a non-de-minimis factor in the outcome, not simply present somewhere in the process.

Inside that narrower scope, real obligations remain. Developers have to give deployers technical documentation, due by January 1, 2027, covering the system's intended uses, known limitations, the categories of data it was trained on, and how to use it properly, and both parties have to retain compliance records for at least three years. Deployers have to give people clear notice at the point of interaction before an ADMT system is used to make a consequential decision about them, and, when the outcome is adverse, a plain-language explanation within 30 days of what happened and why. People also get a right to request correction of their personal data and meaningful human review of an adverse outcome, and that review has to be real: the reviewer needs actual authority to reach a different conclusion and has to consider the person's specific circumstances rather than simply defer to the system's recommendation by default.

What got dropped, and what changed

Compared to the original law, SB 26-189 eliminates the presumption-of-compliance structure built around risk-management programs and impact assessments, along with the requirement to report discrimination risks to the Attorney General within 90 days. The broader AI governance infrastructure the original law was built around is gone.

On private enforcement specifically, the two laws differ in a way worth stating precisely rather than summarizing loosely. SB 24-205 gave the Attorney General exclusive enforcement authority and did not itself create a right for individuals to sue directly. SB 26-189 continues that pattern in its own way: it does not create a new private right of action, but it does establish how fault is allocated between developers and deployers in civil actions alleging unlawful discrimination brought under existing law. That is a narrower, more specific mechanism than a general private right of action, and it is worth understanding on those terms rather than as a straightforward loosening of a right that existed before.

Developer liability is also narrower under the new framework: a developer who supplied a system for one purpose faces limited exposure if a deployer misuses it outside that intended use, shifting more of the practical risk onto the organization actually deploying the system in front of real people.

Why this matters beyond Colorado

Colorado has been closely watched because SB 24-205 was the first broad, cross-sector AI law adopted by a US state. Its replacement therefore matters beyond organizations directly subject to Colorado law: it offers a different model for how state AI regulation can focus on consequential decisions, transparency, explanation, and human review rather than a broader governance regime built around risk assessments and AG reporting.

It does not mean AI regulation in US states is going away. It means the shape of it, at least in this first mover, moved from a comprehensive governance obligation toward narrower, decision-specific transparency and review rights. Organizations building for a multi-state US market should expect that same tension, between comprehensive governance mandates and narrower disclosure-and-review requirements, to keep playing out state by state rather than resolving into one settled model soon.

What this means if you operate in a covered domain

The Colorado Attorney General opened formal rulemaking for SB 26-189 on August 11, 2026, publishing draft rules that address, among other things, what an adverse-decision disclosure has to contain. The public comment period runs through at least October 26, 2026, with any interim updates to the proposed draft expected by September 23, 2026. The statute sets the obligations; the rules, once final, will settle some of the operational detail underneath them, so organizations preparing for January 1, 2027 should expect both to matter, not the statute alone.

If your organization uses AI to materially influence consequential decisions in education, employment, housing, financial or lending services, insurance, healthcare, or government services or public benefits, and Colorado residents are affected, SB 26-189 will apply from January 1, 2027, narrower scope or not. Two of the obligations worth testing now rather than waiting on are these: can your system produce a genuine, specific, plain-language explanation of an adverse decision within 30 days, and can a human reviewer actually change that decision when asked, rather than rubber-stamping it? Those are behavioral questions. A policy document describing the review process does not answer whether the process works the way it is described the next time someone actually invokes it.


This is one layer of a compliance program, not a substitute for one, and it does not constitute legal advice. Riverfront tests agent behavior against the obligations in frameworks like this one; it does not certify compliance with them.


Sources: Colorado General Assembly, official bill summaries for SB26-189, "Automated Decision-Making Technology" (leg.colorado.gov/bills/sb26-189), and SB24-205, "Consumer Protections for Artificial Intelligence" (leg.colorado.gov/bills/sb24-205), for the repeal-and-reenactment framing, the consequential-decision domain list including housing, the private-right-of-action and fault-allocation language, the enforcement mechanism under the original law, and the May 14, 2026 signing date. Colorado General Assembly, bill page for HB26-1263, "Conversational Artificial Intelligence Service Operator Requirements" (leg.colorado.gov/bills/hb26-1263), for the Chatbot Safety Act's January 1, 2027 effective date and its scope. The General Assembly's bill history and the Colorado Attorney General's rulemaking page give conflicting signing dates for HB26-1263 (May 29, 2026 versus July 1, 2026); the date is omitted from the body for that reason. Colorado Attorney General's Office, ADMT and Chatbot Safety Act rulemaking page (coag.gov/ai) and the Department of Law's August 11, 2026 filing, for the rulemaking timeline and comment deadlines. Corroborating legal analysis from Davis Wright Tremaine, Ogletree Deakins, Norton Rose Fulbright, Seyfarth Shaw, Crowell & Moring, and Davis Polk.