Colorado ADMT Law: What SB 26-189 Means for Your Business
On May 14, 2026, Colorado repealed and replaced its first-in-the-nation AI Act (SB 24-205) with SB 26-189 — a narrower transparency law for “automated decision-making technology” (ADMT), effective January 1, 2027. Here is what survived, what was removed, and exactly what you must do before the effective date.
The old June 30, 2026 deadline no longer exists
SB 24-205 was repealed before any of its duties took effect — there is no Colorado impact-assessment requirement and no risk-management-program mandate. The replacement law, SB 26-189 (C.R.S. §§ 6-1-1701 to 6-1-1709), applies to consequential decisions made on or after January 1, 2027.
What Is SB 26-189?
Colorado Senate Bill 26-189 repealed and reenacted part 17 of the Colorado Consumer Protection Act. It replaces the “high-risk artificial intelligence system” framework of the 2024 AI Act with a regime built around automated decision-making technology (ADMT): technology that processes personal data and uses computation to generate output — predictions, recommendations, classifications, rankings, scores — used to make, guide, or assist a decision about an individual.
The law applies when ADMT materially influences a consequential decision — its output is a non-de-minimis factor that affects the outcome (C.R.S. § 6-1-1701(13)). Instead of impact assessments, it imposes transparency duties: notice, post-adverse-outcome disclosure, data correction, human review, and record keeping.
Who Must Comply?
The law covers two roles — and there is no size, revenue, or headcount threshold:
Developers
Persons doing business in Colorado that create, sell, license, or substantially modify a covered ADMT — or a component designed for one (C.R.S. § 6-1-1701(8)).
Examples: AI hiring software companies, AI credit scoring vendors, AI underwriting tool providers.
Deployers
Persons doing business in Colorado that use a covered ADMT in consequential decisions — even if they didn't build it (C.R.S. § 6-1-1701(7)).
Examples: employers screening applicants with AI, lenders using AI credit scoring, landlords using tenant-screening ADMT.
Employees and job applicants are expressly protected
“Consumer” includes an employee, a Colorado-resident job applicant, and any individual whose access, eligibility, or opportunity in Colorado is evaluated in a consequential decision (C.R.S. § 6-1-1701(4)(b)). A New York-based company hiring remote workers in Denver is covered.
Which Decisions Are “Consequential”?
A consequential decision relates to a consumer's access to, eligibility for, selection for, or compensation for one of seven covered domains (C.R.S. § 6-1-1701(3), (6)):
Hiring, promotion, compensation — where an employer-employee relationship exists or may be created
Lease or purchase of residential property in Colorado
Credit and financial services decisions
Underwriting, pricing, coverage, claims adjudication
Health-care services
Education enrollment/opportunity; essential government services and public benefits
What is NOT covered? (C.R.S. § 6-1-1701(2)(b), (3)(b))
- Advertising, marketing, product recommendations, search, and content moderation
- Cybersecurity, anti-fraud, identity verification, AML and sanctions-screening technologies
- Low-stakes or routine decisions: scheduling, administrative routing, customer-service triage, workflow management
- Tools that only summarize, organize, or present information for human review without producing an outcome-influencing score, ranking, or inference
- Calculators, spreadsheets without machine learning, spam filters, firewalls, databases, and similar basic technology
What Must Deployers Do?
If you deploy a covered ADMT affecting Colorado consumers, from January 1, 2027:
Tell the consumer that ADMT was or will be used in a consequential decision affecting them, with instructions for getting more information. A prominent public notice reasonably accessible at points of consumer interaction — for example a link near the application or transaction — satisfies this duty (C.R.S. § 6-1-1704(1)-(2)).
If the decision denies, terminates, or materially worsens access or terms, provide: a plain-language description of the decision and the ADMT’s role; a simple process to request the ADMT’s name, version, developer, and the types, categories, and sources of personal data used; and an explanation of the consumer’s rights (C.R.S. § 6-1-1704(3)). AG rules due by January 1, 2027 will clarify the content.
Provide instructions for correcting factually incorrect or materially inaccurate personal data used in the decision, and an opportunity for meaningful human review and reconsideration to the extent commercially reasonable. The reviewer must be trained, must not default to the system output, and must have authority to approve, modify, or override the decision (C.R.S. §§ 6-1-1705(1), 6-1-1701(15)).
Keep records reasonably necessary to demonstrate compliance — ADMT version identifiers, changelogs, documentation of material mitigation changes — for at least 3 years after each consequential decision (C.R.S. § 6-1-1703).
What Do Developers Need to Do?
If you sell or license covered ADMT, from January 1, 2027 you must make available to each deployer, in a form that protects trade secrets (C.R.S. § 6-1-1702):
- A general statement of intended uses and known harmful or inappropriate uses
- The categories of data — including personal data — used to train the ADMT, to the extent known
- Known limitations, risks, and circumstances in which the ADMT should not be used
- Instructions for appropriate use, monitoring, and meaningful human review — plus the information deployers need for their own disclosure duties
- Notice of material updates and substantial modifications within a reasonable time (public release notes plus direct notice suffice), and 3-year record retention
The duty applies only where the ADMT was marketed, configured, contracted, sold, or licensed to materially influence consequential decisions — and developer liability in discrimination suits is limited to uses the developer intended or contracted for (C.R.S. §§ 6-1-1702(3), 6-1-1707(5)).
What Are the Penalties?
A violation is a deceptive trade practice under the Colorado Consumer Protection Act, enforced exclusively by the Colorado Attorney General — there is no private right of action (C.R.S. §§ 6-1-1706, 6-1-1709):
| Mechanism | Amount / effect |
|---|---|
| Civil penalty per violation (C.R.S. § 6-1-112(1)(a)) | Up to $20,000 |
| Each consumer or transaction involved | Counts as a separate violation |
| Violation committed against an elderly person (§ 6-1-112(1)(c)) | Up to $50,000 |
| Cure period (§ 6-1-1706(3)) | 60 days after AG notice, where the AG deems cure possible; waived for knowing or repeated violations |
The 60-day cure mechanism: what it means
Before enforcing, the Attorney General must issue a notice of violation if the AG deems a cure possible; you then have 60 days to cure. No cure period is required where the AG can demonstrate a knowing or repeated violation — and a cure completed within 60 days of written notice can count as a mitigating factor on penalties (C.R.S. § 6-1-1706(3)). This right-to-cure mechanism itself sunsets January 1, 2030 — after that date the AG is no longer required to offer a cure opportunity before enforcing, cure possible or not. Documentation that you tried to comply is what makes a cure credible.
SB 26-189 vs. the Repealed SB 24-205: What Changed
| Aspect | SB 24-205 (repealed) | SB 26-189 (current law) |
|---|---|---|
| Core concept | "High-risk artificial intelligence systems" | "Automated decision-making technology" (ADMT) that materially influences a decision |
| Impact assessments | Required initially + annually | REMOVED — no impact-assessment duty |
| Risk-management program | Required (NIST AI RMF / ISO 42001) | REMOVED |
| Consumer notice | Required | Required — public posting at interaction points suffices |
| Adverse-outcome disclosure | Statement of reasons | Plain-language description + ADMT details within 30 days |
| Human review | Appeal where feasible | Meaningful human review, to the extent commercially reasonable |
| Record retention | Varied | 3 years, developers and deployers |
| Effective date | June 30, 2026 (never reached) | January 1, 2027 |
| Enforcement | Colorado AG | Colorado AG (exclusive), up to $20,000 per violation, 60-day cure |
Your 5-Step SB 26-189 Action Checklist
Inventory your ADMT
List every tool that processes personal data and produces scores, rankings, recommendations, or classifications used in decisions about Colorado residents — including employees and applicants.
Apply the "materially influence" test
For each tool: is its output a non-de-minimis factor that affects the outcome of a decision in employment, housing, lending, insurance, health care, education, or government services? Incidental or clerical uses are out of scope.
Post your ADMT notice
Publish a clear, prominent notice at points of consumer interaction stating that ADMT is used in consequential decisions, with instructions for getting more information.
Build the 30-day adverse-outcome disclosure
Prepare the plain-language decision description, the ADMT name/version/developer details, and the data-category summary you must provide within 30 days of an adverse outcome.
Stand up human review and record keeping
Designate and train a reviewer with authority to override decisions, create the data-correction request path, and retain compliance records for 3 years.
Get ready for SB 26-189 in 30 minutes
Aegis Firma generates your ADMT notice, adverse-outcome disclosure process, and human-review documentation — mapped to the exact C.R.S. §§ 6-1-1702 to 6-1-1705 duties.