The Colorado AI Act you planned for does not exist.
SB 24-205 was repealed on 14 May 2026, before it ever took effect. What replaces it is SB 26-189, and it is a different animal: no duty of care, no risk-management programme, no impact assessments. Instead — tell people before you use the technology, explain an adverse outcome within 30 days, let a human look again, and keep the records three years. Narrower than the law it replaces. Closer than it looks.
If you read nothing else
Signed 17 May 2024, deferred twice, repealed 14 May 2026. Never took effect for a single day.
Signed 14 May 2026. Bites on consequential decisions made on or after 1 January 2027.
Automated decision-making technology that materially influences a consequential decision about a Colorado consumer.
Notice before use. Plain-language disclosure within 30 days of an adverse outcome. Correction and human review on request. Three years of records.
A violation is a deceptive trade practice. A 60-day cure period applies. There is no private right of action.
Duty of care. Risk-management programme. Annual impact assessments. All three left with the 2024 Act.
Work scoped against Colorado in 2025 needs re-pointing, not finishing.
Five questions. All five are yes, or you are out.
Colorado’s scope is narrow and specific. Run a system down this list before you budget anything against it.
-
Does it process personal data by computation?
And produce a prediction, recommendation, classification, ranking or score. If it does none of that it is not ADMT. Anti-malware, calculators, databases and spreadsheets without machine learning are out on this question alone.
-
Does that output materially influence a decision?
The test is whether the output is a non-trivial factor in the outcome. A system that formats, routes or schedules does not clear it. A system whose score decides who progresses does.
-
Is the decision one of the eight?
Education, employment, housing, financial or lending services, insurance, health care, essential government services, or differentiated pricing that materially limits access. Nothing else is a consequential decision.
-
Is the person a Colorado consumer?
That is the only geography in the test. Your head office, your servers and your place of incorporation do not come into it.
-
Does a carve-out actually reach you?
Insurance, HIPAA, FDA and ECOA/FCRA carve-outs exist, and every one of them stops somewhere. None of them reach employment decisions.
Five yeses and you are a deployer, with duties from 1 January 2027. Built the system yourself, or substantially and intentionally modified it? You are also a developer, and the documentation duty is yours as well.
Two statutes. One of them never happened.
Here is which one binds you, what it is actually about, and who it reaches.
SB 26-189 is the law. Passed on 9 May 2026, signed on 14 May 2026, and applies to consequential decisions made on or after 1 January 2027. It repeals SB 24-205 — the 2024 Colorado AI Act — which was deferred twice and never took effect at all.
The subject is ADMT. Technology that processes personal data by computation to produce a prediction, recommendation, classification, ranking or score used to make or guide a decision about a person. Where that output materially influences a consequential decision — it is a non-trivial factor in the outcome — the system is covered ADMT and the duties attach.
The duties are disclosure duties, not risk duties. A deployer gives clear and conspicuous notice before the technology is used. Discloses in plain language within 30 days of an adverse outcome. Offers a route to correct inaccurate personal data and to request meaningful human review. Keeps the records three years. A developer supplies the documentation that makes all of that possible.
Enforcement is narrow and sharp. The Attorney General alone. A violation is a deceptive trade practice under the Colorado Consumer Protection Act. A 60-day cure period applies and falls away for knowing or repeated violations. There is no private right of action.
Who this reaches
-
Deployers
You use covered ADMT to make or materially influence a consequential decision about a Colorado consumer. Most readers of this page are here.
-
Developers
You build, or substantially and intentionally modify, ADMT made available for use in Colorado. Sold, licensed or handed to a sister company: same answer.
-
Employers and HR platforms
Employment is a named domain, and it is the one domain the insurance and HIPAA carve-outs do not reach.
-
Lenders and financial services
In scope by domain — though a creditor meeting the ECOA and FCRA notice requirements is treated as compliant for those disclosures.
-
Housing, education and government services
Tenant screening, admissions and eligibility for an essential government service are consequential decisions on the face of the statute.
-
Businesses outside Colorado
The trigger is a consequential decision about a Colorado consumer. Your head office, your servers and your place of incorporation are not the test.
Gone. Kept. New.
If you built towards Colorado in 2024 or 2025, this is the section that matters. Three buckets, then the row-by-row for anyone who needs it.
Stop building these
Left with SB 24-205, and not required by anything now.
- Duty of reasonable care on developers and deployers
- Risk-management programme, with NIST AI RMF or ISO 42001 as safe harbour
- Annual impact assessments, and assessments on substantial modification
- The "high-risk AI system" framing entirely
The shape survived
Carried across the repeal essentially unchanged.
- Attorney General as sole enforcer
- A violation is a deceptive trade practice under the CCPA
- No private right of action
- The consequential-decision domain list, close to unchanged
Build these by 1 Jan 2027
What the replacement statute asks for instead.
- "Automated decision-making technology" replaces "AI system" as the operative term
- Clear and conspicuous notice at the point of interaction, before use
- Plain-language disclosure within 30 days of an adverse outcome
- Meaningful human review on request, to the extent commercially reasonable
- Compliance records kept three years from each consequential decision
- Mandatory Attorney General rulemaking by 1 January 2027
Show the full 15-row comparison Hide the full comparison
| Attribute | SB 24-205 The 2024 Colorado AI Act — repealed | SB 26-189 In force 1 January 2027 |
|---|---|---|
| Short title | Colorado AI Act — "Consumer Protections for Artificial Intelligence" | Automated Decision-Making Technology |
| Enacted | Signed 17 May 2024 | Passed 9 May 2026, signed 14 May 2026 |
| Status | Repealed It never took effect | In force From 1 January 2027 |
| Effective date | 1 February 2026, deferred to 30 June 2026 by SB 25B-004 | Consequential decisions made on or after 1 January 2027 |
| Core framing | Risk management and a duty of care against algorithmic discrimination | Disclosure, transparency and targeted consumer rights |
| Terminology | "Artificial intelligence system", "high-risk AI system" | "Automated decision-making technology" (ADMT), "covered ADMT" |
| Duty of reasonable care | Required of developers and deployers | Removed |
| Risk-management programme | Required — NIST AI RMF or ISO 42001 named as a safe harbour | Removed Not required by the statute |
| Impact assessments | Annual, plus on substantial modification | Removed |
| Consumer notice | Notice before a consequential decision | Clear and conspicuous notice at the point of interaction, before use |
| After an adverse outcome | Statement of reasons and an opportunity to appeal | Plain-language disclosure within 30 days, plus a route to the system details |
| Human review | Appeal with human review where technically feasible | Meaningful human review on request, to the extent commercially reasonable |
| Record retention | Impact assessments kept three years | Compliance records kept three years from each consequential decision |
| Enforcement | Attorney General only; deceptive trade practice; no private right of action | Unchanged in shape — AG only, deceptive trade practice, 60-day cure, no private right of action |
| Rulemaking | Discretionary | The Attorney General must adopt rules by 1 January 2027 |
What survives is the enforcement shape. Attorney General only, a violation as a deceptive trade practice, no private right of action, and a list of consequential-decision domains that is close to unchanged. What does not survive is everything that made SB 24-205 a risk-management statute. Insurers should also read Colorado SB 21-169, which is a separate regime and was not touched by either bill.
Eight domains. Yours is probably in three of them.
The domains are the statute’s. The examples are ours — because “education” does not tell an admissions team whether their scoring model is in scope, and “admissions and enrolment” does.
Employment
- CV screening and ranking
- Interview or assessment scoring
- Promotion and termination support
Financial & lending
- Credit decisioning and limits
- Risk-based pricing
- Collections and closure triage
Insurance
- Underwriting and eligibility
- Rating and tiering
- Claims triage and fraud scoring
Health care
- Coverage and prior authorisation
- Triage and care-pathway ranking
- Financial-assistance eligibility
Housing
- Tenant screening and scoring
- Rent and deposit setting
- Waiting-list prioritisation
Education
- Admissions and enrolment
- Scholarship and aid allocation
- Programme placement
Government services
- Benefit eligibility screening
- Licence and permit decisions
- Case prioritisation
Differentiated pricing
- Personalised pricing that limits access
- Tiering that gates a product
- Materially less favourable terms
Clean exclusions
Out of scope on the face of the statute.
- Tools that neither rank nor score — anti-malware, calculators, databases, spreadsheets without machine learning
- Chatbots whose acceptable-use policy prohibits use in consequential decisions
- Advertising, recommendations, search and content moderation
- Low-stakes and purely procedural tasks — scheduling, routing, formatting
- Medical devices and research activities under FDA oversight
Partial — read the second half
Subject-matter carve-outs, not blanket exemptions. Every one of them stops somewhere.
- Insurers Outside for insurance practices under §10-3-1104.9. Not outside for employment decisions.
- HIPAA entities Outside the principal duties. Not outside for employment. General technology notice still applies, and extra disclosure is owed on financial-assistance eligibility.
- Creditors Meeting the ECOA and FCRA notice requirements deems you compliant for those disclosures. Not for the rest of the statute.
Two years, three bills, zero days in force.
The first three rows are history rather than deadlines. They are here because they are the answer to “we were told February 2026”.
-
17 May 2024 Superseded
SB 24-205 signed
The original Colorado AI Act: a duty of reasonable care, risk-management programmes and annual impact assessments, due to take effect on 1 February 2026.
-
28 August 2025 Superseded
SB 25B-004 defers the start date
A special session ends without a compromise on amendments, and the effective date moves from 1 February 2026 to 30 June 2026.
-
14 May 2026 Enacted
SB 26-189 signed, SB 24-205 repealed
Passed 9 May, signed 14 May. The 2024 Act is repealed outright, having never taken effect, and is replaced by a disclosure-and-transparency framework.
-
Now to 31 Dec 2026 Window open
Your build window
Inventory the ADMT in your decision paths, classify what materially influences a consequential decision, and draft the notices, the review route and the retention rule.
-
By 1 January 2027 Rulemaking
Attorney General rules adopted
The statute leaves the shape of the post-adverse-outcome disclosure to rulemaking. Draft to the statute now and reconcile to the rules when they land.
-
1 January 2027 In force
SB 26-189 applies
It bites on consequential decisions made on or after this date. A decision made on 31 December 2026 is not covered; the same decision a day later is.
-
From January 2028 Reporting
Annual enforcement reporting begins
The Attorney General reports annually on enforcement actions. The reporting requirement itself sunsets on 1 January 2030.
Three years of records, counted from each decision — not from year end.
Four things you have to be able to show
Not the old four. Governance, risk management and discrimination testing were SB 24-205’s, and three of those four are not required by anything now.
Inventory & classification
You cannot give notice about what you have not found.
- A register of every ADMT in a decision path, vendor tools included
- The consequential-decision domain each one touches
- A recorded "materially influences" call, with its reasoning
- Developer documentation on file for each third-party system
Notice & disclosure
Two moments, two different documents.
- Point-of-interaction notice, with a route to more information
- Post-adverse-outcome disclosure inside 30 days
- A request path for system name, version, developer and data sources
- Accessible for disability and limited English proficiency
Human review & correction
“Meaningful” is doing all the work in that phrase.
- A designated reviewer with genuine override authority
- Enough system information to review without exposing trade secrets
- A correction route for factually inaccurate personal data
- A recorded reconsideration outcome, not just a logged request
Documentation & records
Three years per decision, and the clock starts at the decision.
- Compliance records retained three years from each decision
- Developer disclosures and material-update notices kept with them
- Notices as issued, with their dates and versions
- Review and correction requests, and what was done about them
Want to see what lands on your desk?
Every obligation below is paired with the artefact that discharges it, so you can tell what the engagement produces before you commission it.
What the statute says. What we hand you.
Twelve obligations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the duty beside it.
- Developer documentation pack Intended uses, known harmful uses, training-data categories, limitations
- A drafted pack per model, and a gap list against what your vendors currently supply.
- Material-update notice Deployers told of substantial modifications
- A change-notification clause and a trigger definition your release process can actually follow.
- ADMT inventory What you run, and where it touches a decision
- A register with owners, vendors, domains and the materiality call recorded against each entry.
- Covered-ADMT classification "Materially influences" is the test
- A written classification per system with its reasoning, so the borderline calls survive being asked about.
- Point-of-interaction notice Clear, conspicuous, before use
- Notice copy per channel, where it sits in the journey, and who owns the wording.
- Adverse-outcome disclosure Plain language, within 30 days
- A template disclosure and the operational trigger that starts the 30-day clock.
- Consumer information request System name, version, developer, data types and sources
- A response pack per system and one intake route, so answers do not vary by who replies.
- Meaningful human review Designated, trained, able to override
- A review procedure, the reviewer brief, and the evidence the reviewer sees before deciding.
- Data correction route Factually inaccurate personal data
- A correction workflow with a recorded outcome, and the boundary against opinions and scores written down.
- Three-year records From each consequential decision
- A retention schedule mapped to your systems of record, with the deletion rule stated rather than assumed.
- Accessible notices Disability and limited English proficiency
- An accessibility check of every notice, and the plain-language pass most of them need.
- Exemption position Insurance, HIPAA, FDA, ECOA/FCRA
- A written position on each carve-out you rely on — including where it stops.
Where the statute leaves a choice, we state it. Two of these lines depend on Attorney General rules that are not adopted yet — the exact shape of the adverse-outcome disclosure, and how far the information request has to go. We draft to the statute, mark the two open points in the report, and revisit them when the rules land rather than guessing now and quietly being wrong later.
Six ways to waste 2026
The patterns we keep seeing in Colorado programmes. The first two are both consequences of the repeal, and they fail in opposite directions.
Still building to SB 24-205
Impact assessments, a duty of care and a NIST-aligned risk programme were the 2024 Act, and it was repealed before it ever took effect. Work scoped in 2025 needs re-pointing, not finishing.
Hearing "repealed" and stopping
The replacement is narrower, not absent. Notice, 30-day disclosure, human review, correction and three-year records all start on 1 January 2027, and none of them are quick to retrofit.
Reading "AI" too narrowly
ADMT is defined by what the technology does to personal data, not by whether anyone calls it AI. A scored rules engine or a regression model in a spreadsheet can sit squarely inside it.
Treating a carve-out as blanket
The insurance and HIPAA carve-outs are subject-matter carve-outs. Neither reaches employment decisions, and an insurer screening job applicants is a deployer like any other.
Leaving human review undesigned
"Meaningful" excludes a reviewer who defaults to the system output, and one with no authority to overturn it. If nobody can name that person, you do not have the control.
No retention rule
Three years runs from each consequential decision, not from the end of a reporting year. Systems that overwrite decision context on the next run quietly destroy the evidence.
Why teams bring iDharma in on this one
We track the statute, not the headline
This page was rewritten the week SB 26-189 replaced SB 24-205. Where a scope question is genuinely arguable, we say so in writing rather than pick the convenient answer.
Independent of your vendors
We do not resell the tools we assess and we take no fee from the platforms in your decision path, so the classification call is not commercially convenient to anybody.
One review, several regimes
The inventory and classification work carries straight into the EU AI Act, NIST AI RMF and LL 144 scopes. Colorado alone is rarely the whole answer for a business this size.
Artefacts, not a slide deck
You get the register, the classification memo, the notice copy and the retention schedule — the things you will actually be asked to produce, in formats you can put into use.
Frequently asked questions
What the law is now, what it reaches, and what the engagement involves.
Is the Colorado AI Act still law?
No. SB 24-205 was repealed by SB 26-189 and never took effect. Its start date had already moved from 1 February 2026 to 30 June 2026 before the repeal landed.
What replaced it?
SB 26-189, signed 14 May 2026, effective 1 January 2027. It regulates automated decision-making technology used in consequential decisions, built on disclosure and consumer rights rather than risk management and a duty of care.
Why does this page still sit at /colorado-ai-act?
Because that is what the law is still called in conversation, in search, and in every inbound link. The heading and the first line name SB 26-189, so the URL is never the claim.
Does anything from SB 24-205 survive?
The enforcement shape does — Attorney General only, a deceptive trade practice, no private right of action — and the domain list is close to unchanged. The duty of care, the risk-management programme and the impact assessments do not.
What is ADMT?
Technology that processes personal data by computation to produce a prediction, recommendation, classification, ranking or score used to make or guide a decision about a person. It excludes tools that do none of that.
What makes ADMT "covered"?
It materially influences a consequential decision — the output is a non-trivial factor in the outcome. A system that only formats or routes work is not covered; one whose score decides who progresses is.
What is a consequential decision?
A decision about access, eligibility, selection or compensation in education, employment, housing, financial or lending services, insurance, health care or essential government services — plus differentiated pricing reasonably likely to materially limit access.
We are not in Colorado. Does it reach us?
If you make or materially influence a consequential decision about a Colorado consumer, yes. The trigger is the consumer, not your address.
Are we exempt as an insurer or a HIPAA entity?
Partly, and the boundary matters. Insurers are treated as compliant for insurance practices under section 10-3-1104.9; HIPAA entities sit outside the principal duties. Neither carve-out reaches employment decisions, and HIPAA entities still owe general technology notice plus extra disclosure on financial-assistance eligibility.
What does a deployer actually have to do?
Notice before covered ADMT is used; plain-language disclosure within 30 days of an adverse outcome covering what the decision was and what part the technology played; a route to correct inaccurate personal data and to request meaningful human review; and records kept three years from the decision.
What counts as meaningful human review?
A designated individual with authority to override, trained on the system, who weighs the evidence and does not default to the output — with enough information about the system to review it, without the developer exposing trade secrets.
Do we still need impact assessments?
Not under Colorado law. If you run them for the EU AI Act, a NIST AI RMF programme or your own governance, keep them — they make classification and review evidence far easier to produce — but SB 26-189 does not require them.
What are the penalties?
A violation is a deceptive trade practice under the Colorado Consumer Protection Act, enforced only by the Attorney General, with a 60-day cure period that falls away for knowing or repeated violations. There is no private right of action.
Should we wait for the Attorney General rules?
No. They are due by 1 January 2027 and mainly shape the post-adverse-outcome disclosure. The inventory, the classification, the review route and the retention rule are all statutory, and none of them get faster by being started late.
What does an iDharma readiness review cost, and how long does it take?
It is scoped before you are charged. The variables are how many systems sit in a decision path and how much developer documentation your vendors already supply; we tell you the shape of both after a short scoping call.
Do not take our word for it
This page is a summary written against secondary analyses. Where a scoping decision turns on the wording, go to the bill.
Primary sources
Colorado General Assembly and the Attorney General. External links.
Related on this site
The regimes that most often sit alongside Colorado in the same scope.
- EU AI Act compliance scan The transparency and high-risk regime most Colorado deployers also carry
- Colorado SB 21-169 ECDIS governance for life, auto and health insurers
- NYC Local Law 144 Bias audits for automated employment decision tools
- NIST AI RMF Govern, Map, Measure and Manage, assessed end to end
- Every framework we audit against The full catalog, by region and kind
Find out what 1 January 2027 asks of you
A scoping call, then a written scope. You get the ADMT register, the covered-ADMT classification with its reasoning, the notice and disclosure drafts, and the retention rule — scoped before you are charged.
This page is guidance on how we scope a Colorado readiness review, not legal advice. It is written against secondary analyses of SB 26-189 and has not been line-checked against the enrolled text; where a scope question is genuinely arguable, we say so in writing rather than pick the convenient answer.
From Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
Read the notesWhat Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
Read the notesWhat an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Read the guide