COLORADO · SB 26-189 REPLACES THE 2024 AI ACT · IN FORCE 1 JANUARY 2027

The Colorado AI Act you planned for does not exist.

SB 24-205 was repealed on 14 May 2026, before it ever took effect. What replaces it is SB 26-189, and it is a different animal: no duty of care, no risk-management programme, no impact assessments. Instead — tell people before you use the technology, explain an adverse outcome within 30 days, let a human look again, and keep the records three years. Narrower than the law it replaces. Closer than it looks.


Bound statute volumes on a dark shelf, one open and tabbed, beside a notebook and pen under warm light Illustrative materials
The statute changed. The programme has to follow.
ADMT Covered ADMT Consequential decision Adverse outcome Meaningful human review
Start here

If you read nothing else

What died SB 24-205

Signed 17 May 2024, deferred twice, repealed 14 May 2026. Never took effect for a single day.

What is live SB 26-189

Signed 14 May 2026. Bites on consequential decisions made on or after 1 January 2027.

What it covers Covered ADMT

Automated decision-making technology that materially influences a consequential decision about a Colorado consumer.

What you owe Four duties

Notice before use. Plain-language disclosure within 30 days of an adverse outcome. Correction and human review on request. Three years of records.

Who enforces The AG, alone

A violation is a deceptive trade practice. A 60-day cure period applies. There is no private right of action.

What you can stop building Three duties

Duty of care. Risk-management programme. Annual impact assessments. All three left with the 2024 Act.

Work scoped against Colorado in 2025 needs re-pointing, not finishing.

Scope check

Five questions. All five are yes, or you are out.

Colorado’s scope is narrow and specific. Run a system down this list before you budget anything against it.

  1. Does it process personal data by computation?

    And produce a prediction, recommendation, classification, ranking or score. If it does none of that it is not ADMT. Anti-malware, calculators, databases and spreadsheets without machine learning are out on this question alone.

  2. Does that output materially influence a decision?

    The test is whether the output is a non-trivial factor in the outcome. A system that formats, routes or schedules does not clear it. A system whose score decides who progresses does.

  3. Is the decision one of the eight?

    Education, employment, housing, financial or lending services, insurance, health care, essential government services, or differentiated pricing that materially limits access. Nothing else is a consequential decision.

  4. Is the person a Colorado consumer?

    That is the only geography in the test. Your head office, your servers and your place of incorporation do not come into it.

  5. Does a carve-out actually reach you?

    Insurance, HIPAA, FDA and ECOA/FCRA carve-outs exist, and every one of them stops somewhere. None of them reach employment decisions.

Five yeses and you are a deployer, with duties from 1 January 2027. Built the system yourself, or substantially and intentionally modified it? You are also a developer, and the documentation duty is yours as well.

The law

Two statutes. One of them never happened.

Here is which one binds you, what it is actually about, and who it reaches.

SB 26-189 is the law. Passed on 9 May 2026, signed on 14 May 2026, and applies to consequential decisions made on or after 1 January 2027. It repeals SB 24-205 — the 2024 Colorado AI Act — which was deferred twice and never took effect at all.

The subject is ADMT. Technology that processes personal data by computation to produce a prediction, recommendation, classification, ranking or score used to make or guide a decision about a person. Where that output materially influences a consequential decision — it is a non-trivial factor in the outcome — the system is covered ADMT and the duties attach.

The duties are disclosure duties, not risk duties. A deployer gives clear and conspicuous notice before the technology is used. Discloses in plain language within 30 days of an adverse outcome. Offers a route to correct inaccurate personal data and to request meaningful human review. Keeps the records three years. A developer supplies the documentation that makes all of that possible.

Enforcement is narrow and sharp. The Attorney General alone. A violation is a deceptive trade practice under the Colorado Consumer Protection Act. A 60-day cure period applies and falls away for knowing or repeated violations. There is no private right of action.

Who this reaches

  • Deployers

    You use covered ADMT to make or materially influence a consequential decision about a Colorado consumer. Most readers of this page are here.

  • Developers

    You build, or substantially and intentionally modify, ADMT made available for use in Colorado. Sold, licensed or handed to a sister company: same answer.

  • Employers and HR platforms

    Employment is a named domain, and it is the one domain the insurance and HIPAA carve-outs do not reach.

  • Lenders and financial services

    In scope by domain — though a creditor meeting the ECOA and FCRA notice requirements is treated as compliant for those disclosures.

  • Housing, education and government services

    Tenant screening, admissions and eligibility for an essential government service are consequential decisions on the face of the statute.

  • Businesses outside Colorado

    The trigger is a consequential decision about a Colorado consumer. Your head office, your servers and your place of incorporation are not the test.

Side by side

Gone. Kept. New.

If you built towards Colorado in 2024 or 2025, this is the section that matters. Three buckets, then the row-by-row for anyone who needs it.

Gone

Stop building these

Left with SB 24-205, and not required by anything now.

  • Duty of reasonable care on developers and deployers
  • Risk-management programme, with NIST AI RMF or ISO 42001 as safe harbour
  • Annual impact assessments, and assessments on substantial modification
  • The "high-risk AI system" framing entirely
Kept

The shape survived

Carried across the repeal essentially unchanged.

  • Attorney General as sole enforcer
  • A violation is a deceptive trade practice under the CCPA
  • No private right of action
  • The consequential-decision domain list, close to unchanged
New

Build these by 1 Jan 2027

What the replacement statute asks for instead.

  • "Automated decision-making technology" replaces "AI system" as the operative term
  • Clear and conspicuous notice at the point of interaction, before use
  • Plain-language disclosure within 30 days of an adverse outcome
  • Meaningful human review on request, to the extent commercially reasonable
  • Compliance records kept three years from each consequential decision
  • Mandatory Attorney General rulemaking by 1 January 2027
Show the full 15-row comparison Hide the full comparison
Comparison of Colorado SB 24-205 and SB 26-189 across fifteen attributes
Attribute SB 24-205 The 2024 Colorado AI Act — repealed SB 26-189 In force 1 January 2027
Short title Colorado AI Act — "Consumer Protections for Artificial Intelligence" Automated Decision-Making Technology
Enacted Signed 17 May 2024 Passed 9 May 2026, signed 14 May 2026
Status Repealed It never took effect In force From 1 January 2027
Effective date 1 February 2026, deferred to 30 June 2026 by SB 25B-004 Consequential decisions made on or after 1 January 2027
Core framing Risk management and a duty of care against algorithmic discrimination Disclosure, transparency and targeted consumer rights
Terminology "Artificial intelligence system", "high-risk AI system" "Automated decision-making technology" (ADMT), "covered ADMT"
Duty of reasonable care Required of developers and deployers Removed
Risk-management programme Required — NIST AI RMF or ISO 42001 named as a safe harbour Removed Not required by the statute
Impact assessments Annual, plus on substantial modification Removed
Consumer notice Notice before a consequential decision Clear and conspicuous notice at the point of interaction, before use
After an adverse outcome Statement of reasons and an opportunity to appeal Plain-language disclosure within 30 days, plus a route to the system details
Human review Appeal with human review where technically feasible Meaningful human review on request, to the extent commercially reasonable
Record retention Impact assessments kept three years Compliance records kept three years from each consequential decision
Enforcement Attorney General only; deceptive trade practice; no private right of action Unchanged in shape — AG only, deceptive trade practice, 60-day cure, no private right of action
Rulemaking Discretionary The Attorney General must adopt rules by 1 January 2027

What survives is the enforcement shape. Attorney General only, a violation as a deceptive trade practice, no private right of action, and a list of consequential-decision domains that is close to unchanged. What does not survive is everything that made SB 24-205 a risk-management statute. Insurers should also read Colorado SB 21-169, which is a separate regime and was not touched by either bill.

Scope

Eight domains. Yours is probably in three of them.

The domains are the statute’s. The examples are ours — because “education” does not tell an admissions team whether their scoring model is in scope, and “admissions and enrolment” does.

Employment

  • CV screening and ranking
  • Interview or assessment scoring
  • Promotion and termination support

Financial & lending

  • Credit decisioning and limits
  • Risk-based pricing
  • Collections and closure triage

Insurance

  • Underwriting and eligibility
  • Rating and tiering
  • Claims triage and fraud scoring

Health care

  • Coverage and prior authorisation
  • Triage and care-pathway ranking
  • Financial-assistance eligibility

Housing

  • Tenant screening and scoring
  • Rent and deposit setting
  • Waiting-list prioritisation

Education

  • Admissions and enrolment
  • Scholarship and aid allocation
  • Programme placement

Government services

  • Benefit eligibility screening
  • Licence and permit decisions
  • Case prioritisation

Differentiated pricing

  • Personalised pricing that limits access
  • Tiering that gates a product
  • Materially less favourable terms

Clean exclusions

Out of scope on the face of the statute.

  • Tools that neither rank nor score — anti-malware, calculators, databases, spreadsheets without machine learning
  • Chatbots whose acceptable-use policy prohibits use in consequential decisions
  • Advertising, recommendations, search and content moderation
  • Low-stakes and purely procedural tasks — scheduling, routing, formatting
  • Medical devices and research activities under FDA oversight

Partial — read the second half

Subject-matter carve-outs, not blanket exemptions. Every one of them stops somewhere.

  • Insurers Outside for insurance practices under §10-3-1104.9. Not outside for employment decisions.
  • HIPAA entities Outside the principal duties. Not outside for employment. General technology notice still applies, and extra disclosure is owed on financial-assistance eligibility.
  • Creditors Meeting the ECOA and FCRA notice requirements deems you compliant for those disclosures. Not for the rest of the statute.
Timeline

Two years, three bills, zero days in force.

The first three rows are history rather than deadlines. They are here because they are the answer to “we were told February 2026”.

  1. 17 May 2024 Superseded

    SB 24-205 signed

    The original Colorado AI Act: a duty of reasonable care, risk-management programmes and annual impact assessments, due to take effect on 1 February 2026.

  2. 28 August 2025 Superseded

    SB 25B-004 defers the start date

    A special session ends without a compromise on amendments, and the effective date moves from 1 February 2026 to 30 June 2026.

  3. 14 May 2026 Enacted

    SB 26-189 signed, SB 24-205 repealed

    Passed 9 May, signed 14 May. The 2024 Act is repealed outright, having never taken effect, and is replaced by a disclosure-and-transparency framework.

  4. Now to 31 Dec 2026 Window open

    Your build window

    Inventory the ADMT in your decision paths, classify what materially influences a consequential decision, and draft the notices, the review route and the retention rule.

  5. By 1 January 2027 Rulemaking

    Attorney General rules adopted

    The statute leaves the shape of the post-adverse-outcome disclosure to rulemaking. Draft to the statute now and reconcile to the rules when they land.

  6. 1 January 2027 In force

    SB 26-189 applies

    It bites on consequential decisions made on or after this date. A decision made on 31 December 2026 is not covered; the same decision a day later is.

  7. From January 2028 Reporting

    Annual enforcement reporting begins

    The Attorney General reports annually on enforcement actions. The reporting requirement itself sunsets on 1 January 2030.

A hand signing a printed report at a dark desk beside a stamp and a brass lamp
Illustrative materials

Three years of records, counted from each decision — not from year end.

The programme

Four things you have to be able to show

Not the old four. Governance, risk management and discrimination testing were SB 24-205’s, and three of those four are not required by anything now.

Inventory & classification

You cannot give notice about what you have not found.

  • A register of every ADMT in a decision path, vendor tools included
  • The consequential-decision domain each one touches
  • A recorded "materially influences" call, with its reasoning
  • Developer documentation on file for each third-party system

Notice & disclosure

Two moments, two different documents.

  • Point-of-interaction notice, with a route to more information
  • Post-adverse-outcome disclosure inside 30 days
  • A request path for system name, version, developer and data sources
  • Accessible for disability and limited English proficiency

Human review & correction

“Meaningful” is doing all the work in that phrase.

  • A designated reviewer with genuine override authority
  • Enough system information to review without exposing trade secrets
  • A correction route for factually inaccurate personal data
  • A recorded reconsideration outcome, not just a logged request

Documentation & records

Three years per decision, and the clock starts at the decision.

  • Compliance records retained three years from each decision
  • Developer disclosures and material-update notices kept with them
  • Notices as issued, with their dates and versions
  • Review and correction requests, and what was done about them

Want to see what lands on your desk?

Every obligation below is paired with the artefact that discharges it, so you can tell what the engagement produces before you commission it.

See the requirement ledger
Requirement & coverage

What the statute says. What we hand you.

Twelve obligations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the duty beside it.

Developer documentation pack Intended uses, known harmful uses, training-data categories, limitations
A drafted pack per model, and a gap list against what your vendors currently supply.
Material-update notice Deployers told of substantial modifications
A change-notification clause and a trigger definition your release process can actually follow.
ADMT inventory What you run, and where it touches a decision
A register with owners, vendors, domains and the materiality call recorded against each entry.
Covered-ADMT classification "Materially influences" is the test
A written classification per system with its reasoning, so the borderline calls survive being asked about.
Point-of-interaction notice Clear, conspicuous, before use
Notice copy per channel, where it sits in the journey, and who owns the wording.
Adverse-outcome disclosure Plain language, within 30 days
A template disclosure and the operational trigger that starts the 30-day clock.
Consumer information request System name, version, developer, data types and sources
A response pack per system and one intake route, so answers do not vary by who replies.
Meaningful human review Designated, trained, able to override
A review procedure, the reviewer brief, and the evidence the reviewer sees before deciding.
Data correction route Factually inaccurate personal data
A correction workflow with a recorded outcome, and the boundary against opinions and scores written down.
Three-year records From each consequential decision
A retention schedule mapped to your systems of record, with the deletion rule stated rather than assumed.
Accessible notices Disability and limited English proficiency
An accessibility check of every notice, and the plain-language pass most of them need.
Exemption position Insurance, HIPAA, FDA, ECOA/FCRA
A written position on each carve-out you rely on — including where it stops.

Where the statute leaves a choice, we state it. Two of these lines depend on Attorney General rules that are not adopted yet — the exact shape of the adverse-outcome disclosure, and how far the information request has to go. We draft to the statute, mark the two open points in the report, and revisit them when the rules land rather than guessing now and quietly being wrong later.

Pitfalls

Six ways to waste 2026

The patterns we keep seeing in Colorado programmes. The first two are both consequences of the repeal, and they fail in opposite directions.

Still building to SB 24-205

Impact assessments, a duty of care and a NIST-aligned risk programme were the 2024 Act, and it was repealed before it ever took effect. Work scoped in 2025 needs re-pointing, not finishing.

Hearing "repealed" and stopping

The replacement is narrower, not absent. Notice, 30-day disclosure, human review, correction and three-year records all start on 1 January 2027, and none of them are quick to retrofit.

Reading "AI" too narrowly

ADMT is defined by what the technology does to personal data, not by whether anyone calls it AI. A scored rules engine or a regression model in a spreadsheet can sit squarely inside it.

Treating a carve-out as blanket

The insurance and HIPAA carve-outs are subject-matter carve-outs. Neither reaches employment decisions, and an insurer screening job applicants is a deployer like any other.

Leaving human review undesigned

"Meaningful" excludes a reviewer who defaults to the system output, and one with no authority to overturn it. If nobody can name that person, you do not have the control.

No retention rule

Three years runs from each consequential decision, not from the end of a reporting year. Systems that overwrite decision context on the next run quietly destroy the evidence.

Why teams bring iDharma in on this one

We track the statute, not the headline

This page was rewritten the week SB 26-189 replaced SB 24-205. Where a scope question is genuinely arguable, we say so in writing rather than pick the convenient answer.

Independent of your vendors

We do not resell the tools we assess and we take no fee from the platforms in your decision path, so the classification call is not commercially convenient to anybody.

One review, several regimes

The inventory and classification work carries straight into the EU AI Act, NIST AI RMF and LL 144 scopes. Colorado alone is rarely the whole answer for a business this size.

Artefacts, not a slide deck

You get the register, the classification memo, the notice copy and the retention schedule — the things you will actually be asked to produce, in formats you can put into use.

Questions

Frequently asked questions

What the law is now, what it reaches, and what the engagement involves.

1 What the law is now
Is the Colorado AI Act still law?

No. SB 24-205 was repealed by SB 26-189 and never took effect. Its start date had already moved from 1 February 2026 to 30 June 2026 before the repeal landed.

What replaced it?

SB 26-189, signed 14 May 2026, effective 1 January 2027. It regulates automated decision-making technology used in consequential decisions, built on disclosure and consumer rights rather than risk management and a duty of care.

Why does this page still sit at /colorado-ai-act?

Because that is what the law is still called in conversation, in search, and in every inbound link. The heading and the first line name SB 26-189, so the URL is never the claim.

Does anything from SB 24-205 survive?

The enforcement shape does — Attorney General only, a deceptive trade practice, no private right of action — and the domain list is close to unchanged. The duty of care, the risk-management programme and the impact assessments do not.

2 Scope and coverage
What is ADMT?

Technology that processes personal data by computation to produce a prediction, recommendation, classification, ranking or score used to make or guide a decision about a person. It excludes tools that do none of that.

What makes ADMT "covered"?

It materially influences a consequential decision — the output is a non-trivial factor in the outcome. A system that only formats or routes work is not covered; one whose score decides who progresses is.

What is a consequential decision?

A decision about access, eligibility, selection or compensation in education, employment, housing, financial or lending services, insurance, health care or essential government services — plus differentiated pricing reasonably likely to materially limit access.

We are not in Colorado. Does it reach us?

If you make or materially influence a consequential decision about a Colorado consumer, yes. The trigger is the consumer, not your address.

Are we exempt as an insurer or a HIPAA entity?

Partly, and the boundary matters. Insurers are treated as compliant for insurance practices under section 10-3-1104.9; HIPAA entities sit outside the principal duties. Neither carve-out reaches employment decisions, and HIPAA entities still owe general technology notice plus extra disclosure on financial-assistance eligibility.

3 Obligations, enforcement and the engagement
What does a deployer actually have to do?

Notice before covered ADMT is used; plain-language disclosure within 30 days of an adverse outcome covering what the decision was and what part the technology played; a route to correct inaccurate personal data and to request meaningful human review; and records kept three years from the decision.

What counts as meaningful human review?

A designated individual with authority to override, trained on the system, who weighs the evidence and does not default to the output — with enough information about the system to review it, without the developer exposing trade secrets.

Do we still need impact assessments?

Not under Colorado law. If you run them for the EU AI Act, a NIST AI RMF programme or your own governance, keep them — they make classification and review evidence far easier to produce — but SB 26-189 does not require them.

What are the penalties?

A violation is a deceptive trade practice under the Colorado Consumer Protection Act, enforced only by the Attorney General, with a 60-day cure period that falls away for knowing or repeated violations. There is no private right of action.

Should we wait for the Attorney General rules?

No. They are due by 1 January 2027 and mainly shape the post-adverse-outcome disclosure. The inventory, the classification, the review route and the retention rule are all statutory, and none of them get faster by being started late.

What does an iDharma readiness review cost, and how long does it take?

It is scoped before you are charged. The variables are how many systems sit in a decision path and how much developer documentation your vendors already supply; we tell you the shape of both after a short scoping call.

Ready when you are

Find out what 1 January 2027 asks of you

A scoping call, then a written scope. You get the ADMT register, the covered-ADMT classification with its reasoning, the notice and disclosure drafts, and the retention rule — scoped before you are charged.

This page is guidance on how we scope a Colorado readiness review, not legal advice. It is written against secondary analyses of SB 26-189 and has not been line-checked against the enrolled text; where a scope question is genuinely arguable, we say so in writing rather than pick the convenient answer.