Colorado AI / ADMT Law — SB 24-205 repealed & replaced by SB 26-189 (operative Jan 1, 2027) Compliance Checklist 2026
CURRENT LAW: Colorado SB 26-189 — signed by Governor Polis on 14 May 2026 — REPEALED AND REENACTED part 17 of the Colorado Consumer Protection Act (C.R.S. §§ 6-1-1701 to 6-1-1709), replacing the origi…
Maximum penalty: Civil penalty up to $20,000 per violation — each consumer or transaction involved is a separate violation — and up to $50,000 per violation committed against an elderly person (C.R.S. § 6-1-112(1)(a), (1)(c), via §§ 6-1-1706(1)-(2) and 6-1-105(1)(uuuu)). AG-exclusive enforcement; 60-day cure notice where the AG deems cure possible, waived for knowing or repeated violations (§ 6-1-1706(3)); no private right of action (§ 6-1-1709).
Complete each item below to achieve compliance. Use Aegis Firma to generate all required documentation automatically.
Regulatory Requirements
1. AI Impact Assessment — REMOVED by SB 26-189 (no longer required)
HISTORICAL — NOT A CURRENT OBLIGATION. The original SB 24-205 would have required an initial and annual impact assessment for high-risk AI systems (former § 6-1-1703(3)). SB 26-189 (operative 1 Jan 2027) REPEALED AND REENACTED part 17 and REMOVED the impact-assessment and risk-management-program requirements entirely. There is no Colorado impact-assessment deadline. Caution when reading citations: under the reenacted part 17, § 6-1-1703 now contains deployer record keeping, not impact assessments. This entry is retained for historical reference only.
2. Consumer / Deployer Notice (ADMT)
Before using a covered ADMT to materially influence a consequential decision, a deployer must provide clear and conspicuous notice to the consumer that ADMT was or will be used, with instructions for obtaining the additional information the statute provides (§ 6-1-1704(1)); a prominent public notice reasonably accessible at points of consumer interaction satisfies this duty (§ 6-1-1704(2)). If the decision results in an adverse outcome, the deployer must provide within 30 days: a plain-language description of the decision and the ADMT's role in it; a simple process to request the ADMT's name, version, developer, and the types, categories, and sources of personal data used; and an explanation of the consumer rights under § 6-1-1705 (§ 6-1-1704(3)). Trade secrets need not be disclosed, but withholding requires notifying the consumer (§ 6-1-1704(5)). Creditors satisfying ECOA/Reg B (and FCRA where applicable) adverse-action notices for the same decision are deemed compliant (§ 6-1-1704(6)); FERPA-subject deployers comply through FERPA channels (§ 6-1-1704(9)). Notices must be accessible to consumers with disabilities and limited English proficiency (§ 6-1-1704(8)). AG rules due on or before 1 Jan 2027 will clarify post-adverse-outcome disclosure content (§ 6-1-1704(4)(b)).
Due: January 1, 2027
3. Consumer Rights — Data Correction and Meaningful Human Review
When a consumer experiences an adverse outcome from a consequential decision that a covered ADMT materially influenced, the deployer must on request provide: (1) instructions for requesting personal data and correcting factually incorrect or materially inaccurate personal data used in the decision, consistent with § 6-1-1306 (correction does not extend to opinions, predictions, scores, or protected evaluations, § 6-1-1705(1)(c)); and (2) an opportunity for meaningful human review and reconsideration of the decision, to the extent commercially reasonable (§ 6-1-1705(1)(a)). "Meaningful human review" requires a designated reviewer with authority to approve, modify, or override the decision who considers primary evidence, is trained, does not default to the system output, and understands the output's intended use, limitations, inputs, and principal factors (§ 6-1-1701(15)). FERPA-subject deployers comply through existing student-record inspection, amendment, and appeal procedures (§ 6-1-1705(2)). AG rules due on or before 1 Jan 2027 (§ 6-1-1705(3)).
Due: January 1, 2027
4. Risk-Management Program — REMOVED by SB 26-189 (no longer required)
HISTORICAL — NOT A CURRENT OBLIGATION. The original SB 24-205 would have required a deployer risk-management policy and program for algorithmic-discrimination risks (former § 6-1-1703(2), referencing the NIST AI RMF and ISO/IEC 42001). SB 26-189 (operative 1 Jan 2027) REMOVED the risk-management-program requirement, shifting to a transparency model. Retained for historical reference only.
5. Developer Documentation to Deployers (ADMT)
On and after January 1, 2027, a developer must make available to each deployer of its covered ADMT, in a reasonably understandable form that protects trade secrets: a general statement of intended uses and known harmful or inappropriate uses; a description of the categories of data (including personal data) used to train the ADMT, to the extent known; known limitations, risks, and circumstances in which it should not be used; instructions for appropriate use, monitoring, and meaningful human review; and information reasonably necessary for the deployer to meet its § 6-1-1704 disclosure duties — with notice to the deployer if information is withheld (§ 6-1-1702(1)). Developers must also notify deployers of material updates, intentional and substantial modifications, and changes to intended use, limitations, or risk mitigation within a reasonable time; public release notes plus direct notice of the release satisfy this (§ 6-1-1702(2)). The duty applies only where the ADMT was marketed, advertised, configured, contracted, sold, or licensed to materially influence consequential decisions (§ 6-1-1702(3), (5)).
Due: January 1, 2027
6. Record Retention — Developers and Deployers (3 years)
A developer must retain, for not less than 3 years after creation (or longer if other law requires), records reasonably necessary to demonstrate compliance with its documentation duties — including system version identifiers, changelogs, and the documentation and material-update notices provided to deployers (§ 6-1-1702(4)). A deployer must retain, for not less than 3 years after the date of a consequential decision (or longer if other law requires), records reasonably necessary to demonstrate compliance with part 17 — which may include covered ADMT version identifiers, changelogs, and documentation of material mitigation changes (§ 6-1-1703).
Due: January 1, 2027
Implementation Steps
7. Inventory every ADMT (automated decision-making technology) that processes personal data and produces scores, rankings, recommendations, or classifications used in decisions about Colorado residents — including employees and applicants
8. Apply the "materially influence" test to each tool: is its output a non-de-minimis factor in a consequential decision (employment, housing, lending, insurance, health care, education, or government services)? Incidental or clerical uses are out of scope
9. Publish a prominent pre-use ADMT notice at points of consumer interaction, with instructions for getting more information
10. Build the 30-day adverse-outcome disclosure process: plain-language decision description, ADMT name/version/developer details, and data-category summary
11. Designate and train a human reviewer with authority to override ADMT-influenced decisions
12. Create a data-correction request path for consumers to dispute inaccurate personal data used by the ADMT
13. Retain ADMT compliance records for at least 3 years after each consequential decision
14. If you sell or license ADMT to others: prepare the developer-side disclosure of training data categories and known limitations