Insights

Colorado Rewrote Its AI Act: What Deployers Do Now

Colorado Replaced Its AI Act With a Narrower One

If you last read about the Colorado AI Act in 2024 or 2025, most of what you learned is out of date. The original law, SB 24-205, was built around “high-risk AI systems,” algorithmic discrimination, impact assessments, and risk management programs. In May 2026 lawmakers repealed and reenacted it as SB 26-189, a narrower law built around automated decision-making technology (ADMT). The new obligations start January 1, 2027.

Colorado AI Act legislative framework restructuring into narrower ADMT compliance requirements

For mid-market IT teams, the compliance burden dropped in some places and stayed put in others. The law now centers on transparency: telling people when software helped decide something important about them, explaining bad outcomes, and giving them a way to get a human to look again.

What Was Removed and What Stayed

Based on law firm summaries of the enacted bill, here is the practical difference for a deployer.

No longer required:

  • Impact assessments before deploying a high-risk system
  • A documented risk management policy and program
  • Reporting algorithmic discrimination risks to the Attorney General

Now required:

  • Clear and conspicuous notice before you use covered ADMT to materially influence a consequential decision
  • A plain-language description of the decision within 30 days after an adverse outcome
  • A way for the person to correct factually inaccurate personal data and to request meaningful human review, to the extent commercially reasonable
  • Compliance records kept for three years

Don’t read “no impact assessment” as “no bias testing.” Anti-discrimination laws such as Title VII for hiring still apply, and a screening tool that treats candidates unequally is a problem no matter what Colorado asks you to file.

Are You a Deployer Under the New Law?

A deployer is a person doing business in Colorado that deploys a covered ADMT. What triggers the law is a “consequential decision”: one that affects a person’s access to, eligibility for, selection for, or compensation in seven areas — education, employment, housing, financial or lending services, insurance, healthcare, and essential government services. Low-stakes decisions, advertising, content moderation, and routine procedural tasks are excluded.

If your HR team uses an AI resume screener, that is almost certainly in scope. If a lending or insurance workflow includes an AI scoring component, that is in scope too. A general-purpose writing assistant or code completion tool will not make you a deployer on its own, but the analysis changes once that tool starts materially influencing a decision about a person.

The practical problem is that most IT managers don’t have a clean map of which tools do what. An AI lead-scoring tool tied to credit or insurance decisions, or an AI add-on layered onto an applicant tracking system, may have pulled a team into scope without IT knowing. That is the shadow AI problem showing up as a compliance problem.

Two caveats. First, the trigger is ADMT that “materially influences” a decision, and the Attorney General is required to adopt rules on post-adverse-outcome disclosures by January 1, 2027, so borderline decision-support tools stay gray until then. Second, law firm summaries report carve-outs for certain insurers, financial institutions under prudential regulator guidance, HIPAA-covered entities (partially), and deployers whose existing FCRA or FERPA notices already meet the requirements. If you might fall into one of those, ask counsel which parts apply to you.

Your Vendors Now Owe You Documentation

Developers of covered ADMT must give deployers documentation covering intended uses, harmful or inappropriate uses, training data, and known risks. They must also notify deployers of material updates and keep compliance records for three years. That documentation is what makes your own obligations workable: you can’t explain a decision in plain language if you can’t see how the tool contributed to it.

When a new or existing tool could touch a consequential decision, add these questions to your vendor review:

  • Does the tool make or materially influence decisions in any of the seven areas, and how does your documentation describe its intended and inappropriate uses?
  • What does the tool record so we can explain an adverse decision in plain language within 30 days?
  • Can a person’s data be corrected in the system, and can a human review and override the output?
  • How and when will you tell us about material changes to the model?
  • What training data and known-risk information can you share?

Our guides to AI tool risk assessment and a defensible AI vendor risk assessment cover how to run that review without enterprise software.

Enforcement: Attorney General Only, With a Cure Window

The Colorado Attorney General has exclusive enforcement authority, and the law creates no private right of action. Violations are treated as deceptive trade practices under the Colorado Consumer Protection Act. According to the bill’s official summary, the Attorney General must give a developer or deployer 60 days’ notice and a chance to cure the alleged violation, where a cure is possible, before starting an enforcement action.

Colorado Is Moving Away From the EU Model

Colorado’s original law shared its structure with the EU AI Act: risk tiers, impact assessments, and disclosure to affected people. The replacement drops most of that in favor of notice and review. Meanwhile, the EU has agreed to push most stand-alone high-risk obligations out to December 2027. Neither is a reason to pause. The work that carries across both is the same: inventory your systems, collect vendor documentation, build notice and human-review paths, and keep records. If you also sell into the EU, our EU AI Act compliance checklist covers the other side.

What to Do This Week: Find Your Consequential-Decision Tools

You can’t notify people about tools you don’t know you have. Most mid-market teams lack this list, not because they’re careless, but because AI adoption moved faster than governance. Start here:

  1. Send a short survey to department heads in HR, finance, sales, and customer-facing operations. Ask three questions: What AI tools does your team use regularly? What decisions does each tool inform or automate? Who approved each one?
  2. Flag every tool that touches one of the seven areas and log it in an AI tool register. The free AI tool register template tracks owner, data types, and approval status and scores risk for each tool. Request it and use it as the basis for your survey.
  3. For each flagged tool, write down who makes the decision, what the tool contributes, and whether a human can review and override it.
  4. Draft two documents you will need before January 1: a plain-language notice and a template for explaining an adverse decision.
  5. Send your vendors the documentation questions above and note who has not answered.

To see where your governance program stands overall, the free AI governance maturity assessment benchmarks you across four phases (React, Assess, Govern, and Prove) with ten questions and an instant score.

The Longer View for Mid-Market IT

Colorado just rewrote its own law within two years of passing it, which is a good reminder that state AI rules will keep shifting. Governance built around one statute’s checklist ages quickly. Governance built around durable pieces — an inventory, vendor documentation standards, notice and review paths, and records — carries over when the next rule changes.

That doesn’t require an enterprise GRC platform you don’t need. It starts with knowing what you have, understanding which obligations attach to it, and creating a repeatable process for new deployments. Our AI governance checklist for IT managers walks through that sequence for teams without a dedicated compliance function.

Sources

This post reflects sources as of September 18, 2026 and is general information, not legal advice. Attorney General rules due by January 1, 2027 may change details.