Skip to content
هذه ترجمة للتسهيل فقط. النسخة الإنجليزية هي النسخة الرسمية والملزمة قانونيا. عرض النسخة الإنجليزية
US-CODEEP coverage

Colorado AI / ADMT Law — SB 24-205 repealed & replaced by SB 26-189 (operative Jan 1, 2027): AI Compliance Requirements

CURRENT LAW: Colorado SB 26-189 — signed by Governor Polis on 14 May 2026 — REPEALED AND REENACTED part 17 of the Colorado Consumer Protection Act (C.R.S. §§ 6-1-1701 to 6-1-1709), replacing the original Colorado AI Act (SB 24-205, 2024) in its entirety. It takes effect 1 January 2027 and applies to consequential decisions made on or after that date. The replacement narrows the regime: it regulates "automated decision-making technology (ADMT)" that "materially influences" a "consequential decision" in a covered domain (education, employment, residential real estate, financial or lending services, insurance, health-care services, essential government services) — the term "artificial intelligence" is removed from the statute — and it REMOVES the original law's impact-assessment and risk-management-program mandates, shifting to a transparency model: deployer clear-and-conspicuous notice (§ 6-1-1704(1)-(2)), post-adverse-outcome disclosures within 30 days (§ 6-1-1704(3)), developer documentation to deployers (§ 6-1-1702), consumer rights to data correction and meaningful human review (§ 6-1-1705), and 3-year record retention for both roles (§§ 6-1-1702(4), 6-1-1703). A violation is a deceptive trade practice (§§ 6-1-1706(2), 6-1-105(1)(uuuu)) enforced exclusively by the Colorado Attorney General with a 60-day cure mechanism (§ 6-1-1706(3)); no private right of action (§ 6-1-1709). The AG must adopt implementing rules on or before 1 January 2027 (§§ 6-1-1704(4)(b), 6-1-1705(3)). HISTORICAL CONTEXT: SB 24-205 (signed May 2024) was the first US state comprehensive AI bill; its effective date was delayed from Feb 1, 2026 to June 30, 2026 by SB 25B-004 before SB 26-189 repealed and replaced it — no SB 24-205 obligation ever took effect.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2027

Maximum Penalty

Civil penalty up to $20,000 per violation — each consumer or transaction involved is a separate violation — and up to $50,000 per violation committed against an elderly person (C.R.S. § 6-1-112(1)(a), (1)(c), via §§ 6-1-1706(1)-(2) and 6-1-105(1)(uuuu)). AG-exclusive enforcement; 60-day cure notice where the AG deems cure possible, waived for knowing or repeated violations (§ 6-1-1706(3)); no private right of action (§ 6-1-1709).

What Your Business Must Do

6 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Consumer / Deployer Notice (ADMT)

High Priority

Before using a covered ADMT to materially influence a consequential decision, a deployer must provide clear and conspicuous notice to the consumer that ADMT was or will be used, with instructions for obtaining the additional information the statute provides (§ 6-1-1704(1)); a prominent public notice reasonably accessible at points of consumer interaction satisfies this duty (§ 6-1-1704(2)). If the decision results in an adverse outcome, the deployer must provide within 30 days: a plain-language description of the decision and the ADMT's role in it; a simple process to request the ADMT's name, version, developer, and the types, categories, and sources of personal data used; and an explanation of the consumer rights under § 6-1-1705 (§ 6-1-1704(3)). Trade secrets need not be disclosed, but withholding requires notifying the consumer (§ 6-1-1704(5)). Creditors satisfying ECOA/Reg B (and FCRA where applicable) adverse-action notices for the same decision are deemed compliant (§ 6-1-1704(6)); FERPA-subject deployers comply through FERPA channels (§ 6-1-1704(9)). Notices must be accessible to consumers with disabilities and limited English proficiency (§ 6-1-1704(8)). AG rules due on or before 1 Jan 2027 will clarify post-adverse-outcome disclosure content (§ 6-1-1704(4)(b)).

Deadline: January 1, 2027

Colo. Rev. Stat. § 6-1-1704(1)-(3) (SB 26-189; operative Jan 1, 2027)

Consumer Rights — Data Correction and Meaningful Human Review

High Priority

When a consumer experiences an adverse outcome from a consequential decision that a covered ADMT materially influenced, the deployer must on request provide: (1) instructions for requesting personal data and correcting factually incorrect or materially inaccurate personal data used in the decision, consistent with § 6-1-1306 (correction does not extend to opinions, predictions, scores, or protected evaluations, § 6-1-1705(1)(c)); and (2) an opportunity for meaningful human review and reconsideration of the decision, to the extent commercially reasonable (§ 6-1-1705(1)(a)). "Meaningful human review" requires a designated reviewer with authority to approve, modify, or override the decision who considers primary evidence, is trained, does not default to the system output, and understands the output's intended use, limitations, inputs, and principal factors (§ 6-1-1701(15)). FERPA-subject deployers comply through existing student-record inspection, amendment, and appeal procedures (§ 6-1-1705(2)). AG rules due on or before 1 Jan 2027 (§ 6-1-1705(3)).

Deadline: January 1, 2027

Colo. Rev. Stat. § 6-1-1705(1) (SB 26-189; operative Jan 1, 2027)

Developer Documentation to Deployers (ADMT)

High Priority

On and after January 1, 2027, a developer must make available to each deployer of its covered ADMT, in a reasonably understandable form that protects trade secrets: a general statement of intended uses and known harmful or inappropriate uses; a description of the categories of data (including personal data) used to train the ADMT, to the extent known; known limitations, risks, and circumstances in which it should not be used; instructions for appropriate use, monitoring, and meaningful human review; and information reasonably necessary for the deployer to meet its § 6-1-1704 disclosure duties — with notice to the deployer if information is withheld (§ 6-1-1702(1)). Developers must also notify deployers of material updates, intentional and substantial modifications, and changes to intended use, limitations, or risk mitigation within a reasonable time; public release notes plus direct notice of the release satisfy this (§ 6-1-1702(2)). The duty applies only where the ADMT was marketed, advertised, configured, contracted, sold, or licensed to materially influence consequential decisions (§ 6-1-1702(3), (5)).

Deadline: January 1, 2027

Colo. Rev. Stat. § 6-1-1702(1)-(2) (SB 26-189; operative Jan 1, 2027)

AI Impact Assessment — REMOVED by SB 26-189 (no longer required)

Medium Priority

HISTORICAL — NOT A CURRENT OBLIGATION. The original SB 24-205 would have required an initial and annual impact assessment for high-risk AI systems (former § 6-1-1703(3)). SB 26-189 (operative 1 Jan 2027) REPEALED AND REENACTED part 17 and REMOVED the impact-assessment and risk-management-program requirements entirely. There is no Colorado impact-assessment deadline. Caution when reading citations: under the reenacted part 17, § 6-1-1703 now contains deployer record keeping, not impact assessments. This entry is retained for historical reference only.

SB 24-205 former Colo. Rev. Stat. § 6-1-1703(3) (REPEALED by SB 26-189, 14 May 2026)

Risk-Management Program — REMOVED by SB 26-189 (no longer required)

Medium Priority

HISTORICAL — NOT A CURRENT OBLIGATION. The original SB 24-205 would have required a deployer risk-management policy and program for algorithmic-discrimination risks (former § 6-1-1703(2), referencing the NIST AI RMF and ISO/IEC 42001). SB 26-189 (operative 1 Jan 2027) REMOVED the risk-management-program requirement, shifting to a transparency model. Retained for historical reference only.

SB 24-205 former Colo. Rev. Stat. § 6-1-1703(2) (REPEALED by SB 26-189, 14 May 2026)

Record Retention — Developers and Deployers (3 years)

Medium Priority

A developer must retain, for not less than 3 years after creation (or longer if other law requires), records reasonably necessary to demonstrate compliance with its documentation duties — including system version identifiers, changelogs, and the documentation and material-update notices provided to deployers (§ 6-1-1702(4)). A deployer must retain, for not less than 3 years after the date of a consequential decision (or longer if other law requires), records reasonably necessary to demonstrate compliance with part 17 — which may include covered ADMT version identifiers, changelogs, and documentation of material mitigation changes (§ 6-1-1703).

Deadline: January 1, 2027

Colo. Rev. Stat. §§ 6-1-1702(4), 6-1-1703 (SB 26-189; operative Jan 1, 2027)

Who Does This Apply To?

CURRENT (SB 26-189, C.R.S. §§ 6-1-1701 to 6-1-1709, operative 1 Jan 2027): the law regulates "automated decision-making technology (ADMT)" — technology that processes personal data and uses computation to generate output used to make, guide, or assist a decision about an individual (§ 6-1-1701(2)) — where the ADMT "materially influences" (a non-de-minimis factor that affects the outcome, § 6-1-1701(13)) a "consequential decision" in a covered domain: education enrollment/opportunity, employment, lease or purchase of residential real estate in Colorado, financial or lending services, insurance, health-care services, or essential government services and public benefits (§ 6-1-1701(3), (6)). DEVELOPERS (create, sell, license, or substantially modify covered ADMT, § 6-1-1701(8)) and DEPLOYERS (persons doing business in Colorado that deploy covered ADMT, § 6-1-1701(7)) are covered; "consumer" includes employees and Colorado-resident job applicants (§ 6-1-1701(4)(b)). There is NO size, revenue, or data-volume threshold. STATUTORY EXCLUSIONS: advertising/marketing/search/content moderation, cybersecurity, fraud prevention, AML/sanctions screening, and low-stakes or routine decisions are not consequential decisions (§ 6-1-1701(3)(b)); HIPAA covered entities and their business associates are exempt from §§ 6-1-1701 to 6-1-1706 except for employment decisions, subject to a general advanced-technology notice duty (§ 6-1-1708(3)); FDA-regulated medical devices and FDA-supervised R&D are exempt (§ 6-1-1708(4)); insurers subject to C.R.S. § 10-3-1104.9 are deemed compliant in the practice of insurance (§ 6-1-1708(1)); creditors satisfying ECOA/Reg B (and FCRA where applicable) adverse-action notices are deemed compliant for the same decision (§ 6-1-1704(6)); FERPA-subject deployers comply through FERPA channels (§§ 6-1-1704(9), 6-1-1705(2)). AG rulemaking due on or before 1 Jan 2027 will clarify post-adverse-outcome disclosure content and may clarify "materially influence" (§§ 6-1-1704(4), 6-1-1705(3), 6-1-1706(5)). HISTORICAL (SB 24-205, repealed): covered "high-risk AI systems" and required impact assessments — no longer the law.

Recent Regulatory Guidance

ruling2026-05-14

Colorado SB 26-189 SIGNED — repeals & replaces the Colorado AI Act (SB 24-205), operative Jan 1, 2027

Governor Polis signed SB 26-189 on 14 May 2026, REPEALING AND REENACTING part 17 of the Colorado Consumer Protection Act (C.R.S. §§ 6-1-1701 to 6-1-1709) and replacing the original Colorado AI Act (SB 24-205) in its entirety. The new law takes effect 1 January 2027 and applies to consequential decisions made on or after that date. It reframes the regime from "high-risk artificial intelligence systems" to "automated decision-making technology (ADMT)" that materially influences "consequential decisions," REMOVES the original impact-assessment and risk-management-program mandates, and centers a transparency model: deployer clear-and-conspicuous notice, developer documentation, post-adverse-outcome disclosures within 30 days, data correction and meaningful human review on request, and 3-year record retention. A violation is a deceptive trade practice enforced exclusively by the Colorado Attorney General (up to $20,000 per violation under C.R.S. § 6-1-112(1)(a)), with a 60-day cure mechanism and no private right of action. The AG must adopt implementing rules on or before 1 January 2027 (§§ 6-1-1704(4)(b), 6-1-1705(3)). The previously-reported 30 June 2026 SB 24-205 effective date no longer applies.

Source
guidance2026-04-24

Colorado AG — Algorithmic Discrimination in AI (ADAI) rulemaking & enforcement posture

The Colorado Attorney General maintains the Algorithmic Discrimination in AI (ADAI) rulemaking page. As of an April 2026 public statement, the AG's Office said it does not intend to promulgate implementing rules, or to enforce the Colorado AI Act (or replacement/amending legislation), until the rulemaking process concludes — so detailed scope guidance (e.g. how broadly "substantially assist" reaches AI hiring tools) is pending the formal rulemaking, not yet issued. (Subsequent development: SB 26-189 was signed 14 May 2026, repealing and replacing SB 24-205 operative 1 Jan 2027 — see the entry above; AG rulemaking is due on or before 1 Jan 2027.)

Source
ruling2026-03-01

SB 25B-004: Delay of SB 24-205 effective date

Colorado legislature passed SB 25B-004 delaying SB 24-205 enforcement from February 1, 2026 to June 30, 2026. Delay intended to allow businesses more time for compliance and Attorney General more time to finalize guidance. No substantive changes to the law.

Source

Key Case Law & Precedent

Mobley v. Workday, Inc. (N.D. Cal., No. 3:23-cv-00770, filed 2023)

U.S. District Court, Northern District of California · 2023

Leading federal test case on whether an AI applicant-screening vendor can itself be liable for discriminatory screening (race, age, disability) — not just the employers using the tool. Directly relevant to Colorado's ADMT regime: SB 26-189 preserves discrimination liability under the Colorado Anti-Discrimination Act for consequential decisions materially influenced by covered ADMT and allocates fault between developers and deployers (C.R.S. § 6-1-1707).

Outcome: Ongoing — NOT settled. The court allowed disparate-impact claims to proceed against Workday as an agent of employers (2024), preliminarily certified an ADEA collective (May 2025), and authorized nationwide collective notice on 17 February 2026 (opt-in deadline passed 2026-03-07, membership now set). On 2026-06-22, Judge Rita F. Lin denied in part and granted in part Workday's motion to dismiss the Third Amended Complaint: FEHA claims survive (adequate California nexus alleged via Workday's HQ-based design/operation of the screening tools) and one plaintiff's ADA proxy-discrimination claim survives; Counts VII-VIII (all plaintiffs) and Count II (as to plaintiff Hughes) were dismissed with leave to amend. A modified Third Amended Complaint was accepted 2026-07-01. In discovery as of this cycle; no trial date set. CYCLE 10 (2026-08-22): cross-checked against this same case's status in `hawaii_no_ai_law`/`kentucky_no_ai_law`/`michigan_no_ai_law`/`new_york_state_general` (Cycle 9's fix) — this entry's status was stale relative to those (missing the 2026-06-22 ruling); now consistent across all five entries citing this case.

Case reference

Quarterly Enforcement Digest

Q2 2026: The decisive development is SB 26-189, signed by Gov. Polis on 14 May 2026, which REPEALED AND REENACTED part 17 (C.R.S. §§ 6-1-1701 to 6-1-1709), replacing the original Colorado AI Act (SB 24-205), effective 1 January 2027. The previously-reported 30 June 2026 SB 24-205 effective date no longer applies, and the impact-assessment / risk-management-program mandates are removed. The new law regulates "automated decision-making technology (ADMT)" that materially influences consequential decisions through a transparency model (deployer notice, developer documentation, 30-day post-adverse-outcome disclosures, data correction and meaningful human review, 3-year records). Violations are deceptive trade practices enforced exclusively by the Colorado AG — up to $20,000 per violation (C.R.S. § 6-1-112(1)(a)) — with a 60-day cure mechanism; AG implementing rules are due on or before 1 Jan 2027; no enforcement actions to date. (R167 correction: a prior digest line citing a "CO AG FAQ published January 15" was unverifiable and has been removed — see RQ-47/RQ-80.) Priority for in-scope businesses: plan for the 1 Jan 2027 ADMT transparency obligations, not a June 2026 deadline.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering Colorado AI / ADMT Law — SB 24-205 repealed & replaced by SB 26-189 (operative Jan 1, 2027)

These industry playbooks include jurisdiction-specific checklist items and guidance for Colorado AI / ADMT Law — SB 24-205 repealed & replaced by SB 26-189 (operative Jan 1, 2027).

Frequently Asked Questions

Does Colorado AI / ADMT Law — SB 24-205 repealed & replaced by SB 26-189 (operative Jan 1, 2027) apply to my business?

CURRENT LAW: Colorado SB 26-189 — signed by Governor Polis on 14 May 2026 — REPEALED AND REENACTED part 17 of the Colorado Consumer Protection Act (C.R.S. §§ 6-1-1701 to 6-1-1709), replacing the original Colorado AI Act (SB 24-205, 2024) in its… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Colorado AI / ADMT Law — SB 24-205 repealed & replaced by SB 26-189 (operative Jan 1, 2027) is: Civil penalty up to $20,000 per violation — each consumer or transaction involved is a separate violation — and up to $50,000 per violation committed against an elderly person (C.R.S. § 6-1-112(1)(a), (1)(c), via §§ 6-1-1706(1)-(2) and 6-1-105(1)(uuuu)). AG-exclusive enforcement; 60-day cure notice where the AG deems cure possible, waived for knowing or repeated violations (§ 6-1-1706(3)); no private right of action (§ 6-1-1709).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Colorado AI / ADMT Law — SB 24-205 repealed & replaced by SB 26-189 (operative Jan 1, 2027)?

The 6 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://leg.colorado.gov/bills/sb26-189

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan