The Business of AI, Decoded

Colorado AI Act Explained

245. Colorado AI Act Explained

⚖️ Colorado just rewrote its landmark AI law — and the new compliance deadline is January 1, 2027. This guide explains exactly what changed, who is covered, what deployers and developers must do now, and how to build a compliant workflow before the deadline hits.

Last Updated: August 28, 2026

The Colorado AI Act has had one of the most turbulent legislative histories of any US technology law. Originally signed in May 2024 as Senate Bill 24-205, it was the first comprehensive state-level AI governance statute in the United States. It was delayed once, then repealed and replaced entirely before it ever took effect. On May 14, 2026, Governor Jared Polis signed Senate Bill 26-189 — a wholesale rewrite of Colorado’s AI framework — creating a new compliance regime with a firm deadline of January 1, 2027. If your organization develops or deploys AI systems that influence decisions about consumers in Colorado — in hiring, lending, insurance, healthcare, housing, education, or government services — this is the law you need to understand now.

The stakes are concrete. The Colorado Attorney General enforces violations as unfair or deceptive trade practices under the Colorado Consumer Protection Act, with penalties reaching up to $20,000 per violation. There is no private right of action — only the AG can bring enforcement — but the AG has confirmed that enforcement will begin after rulemaking concludes, which must be completed by January 1, 2027. At least 20 states enacted or proposed AI-specific legislation in 2025 alone, and the trend across the United States is toward more regulation, not less. Colorado’s revised law — now formally called the Automated Decision-Making Technology in Consequential Decisions Act (ADMT Act) — sits between Texas’s TRAIGA and the EU AI Act on the regulatory intensity spectrum. For companies already navigating the EU AI Act’s August 2026 high-risk provisions, Colorado creates a parallel US compliance track that cannot be deferred.

This guide gives compliance leads, HR professionals, legal counsel, and technology leaders the complete picture: what the original law required, what changed in the May 2026 rewrite, who the new law covers, what developers and deployers must specifically do before January 1, 2027, and a practical compliance checklist you can use immediately. This article covers the Colorado ADMT Act specifically. For a broader view of the 2026 US and global AI regulatory landscape, our AI Regulation in 2026 guide covers the full legislative picture across jurisdictions. For a governance framework that applies across all of these laws simultaneously, our AI Governance Explained guide covers the policy and framework-building layer.

📖 New to AI terminology? Visit the AI Buzz AI Glossary — 65+ essential AI terms explained in plain English, each linking to a full in-depth guide.

⚖️ 1. The Colorado AI Act Timeline: From SB 24-205 to SB 26-189

Understanding where the law came from is essential context for understanding what it requires now — and why it changed so dramatically between 2024 and 2026. Colorado’s AI Act went through three distinct legislative phases before arriving at the framework businesses must comply with in 2027.

The original law, SB 24-205, was signed by Governor Polis on May 17, 2024, making Colorado the first US state to enact a comprehensive AI governance statute. It was modeled in part on the EU AI Act’s risk-tiered approach and imposed broad “duty of care” obligations on developers and deployers of “high-risk artificial intelligence systems” — requiring risk management programs, mandatory impact assessments, anti-discrimination safeguards, and annual reporting to the Attorney General. The original effective date was February 1, 2026. Governor Polis signed the bill with reservations, publicly asking the legislature to revisit the law before it took effect.

The Colorado AI Act in Context: SB 24-205 was the first comprehensive US state AI law. It was repealed before it ever took effect. The replacement, SB 26-189, is materially narrower — but narrower does not mean toothless. It casts a wider net than many compliance teams have appreciated, and it eliminates the conditional exemptions that federally regulated entities had under the original law.

In August 2025, the legislature passed SB 25B-004 — the “AI Sunshine Act” — which delayed the effective date from February 1 to June 30, 2026, while preserving core transparency and accountability measures. Then, in the spring 2026 legislative session, a working group that had convened in fall 2025 produced an entirely new framework. SB 26-189 passed the House 57-6 and the Senate 34-1 — one of the most decisive votes of the session — and Governor Polis signed it on May 14, 2026. The original Colorado AI Act no longer exists. The governing framework is now SB 26-189, effective January 1, 2027.

The Legal Challenge: xAI v. Weiser

One additional complication deserves mention. On April 9, 2026, Elon Musk’s xAI filed suit in the US District Court for the District of Colorado against Colorado Attorney General Philip Weiser, challenging the original SB 24-205 on constitutional grounds. On April 27, 2026 — just weeks before SB 26-189 was signed — the court granted a joint motion to stay enforcement. The Colorado AG has stated he does not intend to enforce SB 24-205 or any legislation replacing it until after the rulemaking process concludes. The practical implication: the law is currently on hold, but rulemaking must be complete by January 1, 2027, and enforcement is expected to follow. Organizations should not interpret the legal challenge or the enforcement stay as permission to delay compliance preparation.

DateEventCompliance Impact
May 17, 2024SB 24-205 signed — original Colorado AI ActFirst comprehensive US state AI law. Broad duty-of-care framework. Effective Feb 1, 2026.
August 2025SB 25B-004 signed — AI Sunshine ActEffective date delayed from Feb 1 to June 30, 2026.
April 9, 2026xAI v. Weiser filed — constitutional challengeEnforcement stay granted April 27. AG states no enforcement until rulemaking concludes.
May 14, 2026SB 26-189 signed — Colorado ADMT ActOriginal AI Act repealed. New ADMT framework replaces it. Effective Jan 1, 2027.
July 1, 2026Chatbot Safety Act signed (HB 26-1263)Companion law: chatbot disclosure, teen safety, suicide response protocols. Effective Jan 1, 2027.
January 1, 2027SB 26-189 + HB 26-1263 effectiveFull compliance required. AG rulemaking must be complete. Enforcement expected to begin.

🔍 2. What Is “Covered ADMT”? Who Does SB 26-189 Apply To?

The most significant structural change in SB 26-189 is the replacement of the original law’s “high-risk artificial intelligence system” standard with a new concept: “covered automated decision-making technology” (covered ADMT). Understanding this definition precisely is the foundational compliance step — because if your technology does not meet the definition of covered ADMT, the law does not apply. If it does, the full compliance framework kicks in.

Covered ADMT is defined as technology that processes personal data and uses computation to generate outputs — such as rankings, scores, classifications, or recommendations — that materially influence a consequential decision. The term “materially influence” is key: it means the ADMT output is a significant factor in the decision, not merely one data point among many that a human independently evaluates. The term “consequential decision” means a decision that has a material legal effect or similarly significant effect on a consumer’s access to employment, housing, financial services, insurance, healthcare, education, or essential government services.

The “Covered ADMT” Test: Ask two questions. First — does your technology process personal data to generate a score, ranking, classification, or recommendation? Second — does that output materially influence a decision affecting someone’s employment, housing, credit, insurance, healthcare, education, or government services access? If both answers are yes, your system is covered ADMT and the full SB 26-189 compliance framework applies.

The law applies to any business “doing business in Colorado” that develops or deploys covered ADMT affecting Colorado consumers — regardless of where the business is headquartered. A San Francisco company using an AI hiring tool to screen Colorado-based applicants is a deployer under SB 26-189. A New York company selling an AI underwriting model to Colorado insurers is a developer. The extraterritorial scope is identical in intent to the Colorado Privacy Act: if your system touches Colorado consumers, Colorado law applies. SB 26-189 also notably eliminates the conditional exemptions for federally regulated entities that existed under the original law — meaning banks, insurers, and healthcare organizations regulated at the federal level no longer have a blanket exemption pathway.

🔒 Building an AI governance framework? Browse the AI Buzz Governance & Security Hub — 30+ in-depth guides covering OWASP, NIST, ISO 42001, AI risk management, and enterprise AI security frameworks.

📋 3. SB 26-189 vs SB 24-205: What Changed and What Survived

For compliance teams that spent 2024–2025 preparing for the original Colorado AI Act, understanding exactly what changed — and what was preserved — is the fastest path to updating your compliance roadmap. The short version: the new law is meaningfully narrower for most deployers, but it introduces new requirements that the original law did not have, and it eliminates exemptions that some organizations were counting on.

RequirementSB 24-205 (Original — Repealed)SB 26-189 (Current — Effective Jan 1, 2027)
Core frameworkHigh-risk AI system + duty of care + algorithmic discrimination prohibitionCovered ADMT + consumer notice + adverse outcome explanation + human review
Risk management program✅ Mandatory — aligned to NIST AI RMF or ISO 42001❌ Removed — still recommended as best practice
Impact assessments✅ Annual — within 90 days of deployment❌ Removed as mandatory requirement
Pre-use consumer notice⚠️ Limited disclosure requirements✅ Mandatory — clear notice before ADMT use in consequential decision
Adverse outcome notice⚠️ General disclosure✅ Mandatory — within 30 days of adverse decision; must explain ADMT’s role
Human review right⚠️ Implied✅ Explicit — consumers may request meaningful human review
Data correction right⚠️ Limited✅ Explicit — consumers may access and correct personal data used in decision
Recordkeeping⚠️ General documentation✅ Minimum 3 years — includes ADMT version IDs, changelogs, material change documentation
Federal entity exemptions✅ Conditional exemptions for federally regulated entities❌ Eliminated — banks, insurers, healthcare orgs now fully covered
PenaltiesUp to $20,000 per violation (AG-enforced)Up to $20,000 per violation (AG-enforced) — no private right of action

🏢 4. Deployer Obligations Under SB 26-189: The Three Core Requirements

A deployer is any business doing business in Colorado that uses covered ADMT to materially influence a consequential decision. Most organizations using AI in HR, lending, insurance, healthcare, or education will be deployers. The new law establishes three core requirements for deployers, each of which requires specific operational implementation before January 1, 2027. The Human-in-the-Loop framework is directly relevant here — SB 26-189’s human review requirement is a codified version of what responsible AI governance teams have already been building.

Requirement 1: Pre-Use Consumer Notice

Before using covered ADMT to materially influence a consequential decision about a consumer, the deployer must provide clear and conspicuous notice. The notice must inform the consumer that a covered ADMT is being used, describe the categories of personal data being processed, and explain the types of decisions the ADMT influences. For employers, this means informing job applicants before any AI-driven resume screening, assessment scoring, or interview analysis tool is applied to their application. The notice must be provided before the AI evaluation takes place — not after an adverse decision has already been made.

Requirement 2: Adverse Outcome Notice and Explanation

If covered ADMT materially influences an adverse decision — a rejection, a denial, an unfavorable outcome — the deployer must notify the affected consumer within 30 days. The notice must explain the ADMT’s role in the decision, identify the personal data that was used, and inform the consumer of their rights under the law. This is a significantly more structured requirement than most organizations currently have in place. Most AI-assisted hiring, lending, and insurance workflows today lack any systematic adverse outcome notification process tied to AI involvement.

Requirement 3: Meaningful Human Review and Data Correction

Consumers have the right to request meaningful human review of any adverse decision that was materially influenced by covered ADMT. They also have the right to access the personal data used in the decision and to correct any factually incorrect or materially inaccurate data. The law qualifies the human review right with “to the extent commercially reasonable” — but this qualification does not eliminate the obligation. Organizations must build a documented process for receiving, logging, and responding to human review requests before January 1, 2027.

🔧 5. Developer Obligations Under SB 26-189

A developer is any business doing business in Colorado that develops, offers, sells, leases, licenses, or otherwise makes commercially available a covered ADMT. AI vendors selling hiring tools, underwriting models, credit scoring systems, or clinical decision support software to Colorado businesses are developers under SB 26-189. Developer obligations are documentation-focused — the law requires developers to supply deployers with specific technical documentation about their systems.

From January 1, 2027, developers must provide deployers with documentation covering: the system’s intended uses and known limitations; training data categories, to the extent known; instructions for appropriate use and monitoring; and known harmful uses of the covered ADMT. Critically, the law does not require disclosure of proprietary source code, model weights, or trade secrets. The documentation obligation is about transparency of purpose and limitation — not technical architecture. Developers must also provide notice of any material updates or modifications to their covered ADMT that could affect deployer compliance obligations. Review the AI Vendor Due Diligence Checklist for the full set of questions deployers should ask AI vendors to confirm compliance with these documentation requirements before contract signature.

The Vendor Accountability Shift: SB 26-189 limits liability allocation between developers and deployers based on fault — and voids certain indemnification clauses that attempt to shift all liability to the deployer. If an adverse outcome results from a developer’s failure to document known limitations of their ADMT, the developer — not just the deployer — bears accountability. This means both sides of an AI procurement relationship now carry statutory obligations under Colorado law.

✅ 6. Colorado ADMT Act Compliance Checklist: 12 Actions Before January 1, 2027

Building compliance before the January 1, 2027 deadline requires a structured programme of operational, legal, and technical actions. The following checklist covers the minimum requirements for both deployers and developers. Organizations should complete an AI risk assessment as part of this process — identifying all systems that potentially meet the covered ADMT definition is the foundational step from which all other compliance actions follow. For organizations also navigating EU AI Act obligations, alignment with the NIST AI Risk Management Framework creates a governance foundation that satisfies the documentation and oversight spirit of both frameworks simultaneously.

#Compliance ActionApplies ToPriority
1☐ Inventory all AI/automated tools that process personal data to influence decisions about Colorado consumersDeployers + Developers🔴 Do first — all other actions depend on this
2☐ Apply the “covered ADMT” test to each system — does it meet both the processing and material-influence definitions?Deployers + Developers🔴 Legal counsel required
3☐ Draft pre-use consumer notice for each covered ADMT deployment — must be clear, conspicuous, and delivered before AI processingDeployers🔴 High — required for every covered deployment
4☐ Build adverse outcome notification workflow — 30-day clock, explanation of ADMT role, consumer rights disclosureDeployers🔴 High — most organizations currently lack this
5☐ Establish a documented human review process — intake, logging, response timeline, escalation pathDeployers🔴 High — “commercially reasonable” does not mean optional
6☐ Implement data access and correction rights — consumers must be able to access and correct personal data used in decisionsDeployers⚠️ Medium — may require CRM/ATS configuration
7☐ Set up 3-year recordkeeping system — ADMT version IDs, changelogs, material change documentation per covered deploymentDeployers⚠️ Medium — must be in place from day one of deployment
8☐ Audit AI vendor contracts — request ADMT documentation package from each developer; verify DPA and material update notice provisionsDeployers⚠️ Medium — vendor may be non-compliant
9☐ Prepare ADMT technical documentation package — intended uses, known limitations, training data categories, appropriate use instructionsDevelopers🔴 High — required to supply to deployer clients
10☐ Build material update notification process — developers must notify deployers of significant changes to covered ADMTDevelopers⚠️ Medium — affects deployer compliance downstream
11☐ Designate a compliance owner — legal counsel, privacy officer, or AI governance lead responsible for tracking AG rulemakingDeployers + Developers⚠️ Medium — rules will clarify scope
12☐ Monitor AG rulemaking timeline at coag.gov/ai/ — rules must be complete by Jan 1, 2027; rules will clarify scope, not change itDeployers + Developers✅ Ongoing — do not wait for rules to start

🌐 7. Colorado + EU AI Act: The Dual-Jurisdiction Compliance Stack

For organizations that serve both Colorado consumers and EU customers or employees, 2026 and 2027 represent the most complex dual-jurisdiction AI compliance environment in history. The EU AI Act’s high-risk provisions became active in August 2026 — meaning that for many organizations, the EU AI Act compliance sprint is already underway while Colorado’s January 2027 deadline is approaching simultaneously. Understanding how the two frameworks interact — and where they diverge — is the most efficient path to building a compliance programme that satisfies both without duplicating effort.

The frameworks share a philosophical foundation: both require transparency when AI influences high-stakes decisions about individuals, both require human oversight mechanisms, and both impose documentation obligations on AI developers. However, they differ significantly in scope and structure. The EU AI Act uses a risk-tiered classification system with prohibitions, high-risk requirements, and transparency obligations. Colorado’s ADMT Act uses a decision-type framework — if your system influences a defined consequential decision, the compliance obligations apply uniformly. For companies with EU customers, the EU AI Act’s penalties reach €35 million or 7% of global annual revenue — making the Colorado + EU dual-jurisdiction stack currently the most consequential compliance combination in play for mid-to-large enterprises. According to AI Law Tracker’s August 2026 analysis, Colorado companies serving European customers face the most complex dual-jurisdiction AI compliance stack currently active.

The good news for compliance teams: building toward NIST AI Risk Management Framework alignment or ISO/IEC 42001 certification satisfies the documentation, human oversight, and risk management spirit of both Colorado and EU frameworks simultaneously. The NIST AI RMF’s Govern, Map, Measure, and Manage functions map directly to SB 26-189’s human review, documentation, and recordkeeping requirements. Organizations investing in a single governance framework that addresses both jurisdictions will spend significantly less on compliance than those building siloed compliance programmes for each law independently. Our NIST Cyber AI Profile guide covers how NIST IR 8596 applies to AI system security specifically.

🏁 8. Conclusion: The Compliance Window Is Open — Start Now

The Colorado ADMT Act (SB 26-189) is a meaningfully different law from the original Colorado AI Act it replaced. It is narrower in governance scope — dropping mandatory risk management programs and annual impact assessments — but more specific and consumer-focused in its operational requirements. The three core deployer obligations (pre-use notice, adverse outcome notice within 30 days, meaningful human review) require genuine operational implementation, not just policy documentation. The three-year recordkeeping requirement needs systems in place from the first day of covered ADMT deployment. And the elimination of federal entity exemptions means that banks, insurers, and healthcare organizations that were relying on carve-outs under the original law are now fully in scope.

The 2026 consensus among US compliance teams navigating AI regulation is a framework-first approach: build to NIST AI RMF or ISO 42001 governance standards, then layer jurisdiction-specific requirements on top. This approach satisfies Colorado, positions organizations for EU AI Act compliance, and creates the audit-ready documentation infrastructure that the AG’s rulemaking will almost certainly require. The AG rulemaking must complete by January 1, 2027, and based on the Colorado AG’s approach to Colorado Privacy Act rulemaking, the rules will clarify rather than change the scope of the law. Start compliance preparation now — before the rules arrive, not after.

📌 Key Takeaways

Takeaway
The original Colorado AI Act (SB 24-205) was repealed before it ever took effect. Governor Polis signed its replacement, SB 26-189, on May 14, 2026. The new law — the Colorado ADMT Act — takes effect January 1, 2027.
SB 26-189 replaces “high-risk AI systems” with “covered ADMT” — any technology that processes personal data to generate outputs (scores, rankings, classifications) that materially influence a consequential decision in employment, housing, credit, insurance, healthcare, education, or government services.
Three core deployer obligations: (1) pre-use consumer notice before any covered ADMT is applied; (2) adverse outcome notice within 30 days explaining the ADMT’s role; (3) meaningful human review and data correction rights on consumer request.
SB 26-189 eliminates the conditional exemptions for federally regulated entities that existed in the original law — banks, insurers, and healthcare organizations regulated at the federal level are now fully covered under Colorado’s ADMT framework.
Deployers must retain compliance records for a minimum of three years — including ADMT version identifiers, changelogs, and documentation of material changes — starting from January 1, 2027.
Enforcement is by the Colorado AG only — penalties up to $20,000 per violation under the Colorado Consumer Protection Act. There is no private right of action. The AG has stated enforcement will not begin until rulemaking concludes — but rulemaking must complete by January 1, 2027.
Colorado ADMT Act applies extraterritorially — any business doing business in Colorado that deploys covered ADMT affecting Colorado consumers must comply, regardless of where the business is headquartered.
Building to NIST AI RMF or ISO 42001 governance standards satisfies the documentation, human oversight, and accountability spirit of both Colorado and EU AI Act requirements simultaneously — making framework alignment the highest-ROI compliance investment for multi-jurisdiction organizations.

🔗 Related Articles

⚖️ Frequently Asked Questions: Colorado AI Act (SB 26-189)

1. Did the Colorado AI Act take effect in February 2026?

No. The original Colorado AI Act (SB 24-205) was delayed to June 30, 2026, then repealed entirely before it ever took effect. It was replaced by SB 26-189, signed May 14, 2026, which takes effect January 1, 2027. Read the full timeline and what changed in our Colorado AI Act compliance guide.

2. Who does Colorado’s SB 26-189 apply to?

Any business doing business in Colorado that develops or deploys “covered ADMT” — automated decision-making technology that processes personal data to materially influence consequential decisions about consumers. Consequential decisions include employment, housing, credit, insurance, healthcare, education, and government services. The law applies regardless of where your company is headquartered. Our AI Governance guide covers the broader governance framework relevant to compliance.

3. What is the penalty for violating Colorado’s ADMT Act?

The Colorado Attorney General enforces violations as unfair or deceptive trade practices under the Colorado Consumer Protection Act — with penalties up to $20,000 per violation. There is no private right of action, meaning only the AG can bring enforcement actions. The AG has stated enforcement will not begin until rulemaking concludes before January 1, 2027.

4. How does Colorado’s ADMT Act compare to the EU AI Act?

Both require transparency and human oversight when AI influences high-stakes decisions, but they differ in structure. The EU AI Act uses a risk-tier classification system with prohibitions and high-risk requirements. Colorado’s ADMT Act uses a decision-type framework — if your system influences a covered consequential decision, the same obligations apply uniformly. For organizations serving both Colorado consumers and EU customers, both compliance frameworks must be satisfied simultaneously. Our EU AI Act guide covers the EU framework in full.

5. What is the fastest way to start Colorado ADMT Act compliance?

Start with an AI system inventory — identify all tools that process personal data to generate outputs influencing consequential decisions about Colorado consumers. Then apply the “covered ADMT” test to each system. Prioritize building the three operational workflows: pre-use consumer notice, adverse outcome notification (30-day clock), and human review intake process. Our AI Vendor Due Diligence Checklist helps evaluate whether your current AI vendors meet their developer obligations under SB 26-189.

📧 Get the AI Buzz Weekly Digest

Weekly AI insights, tools, and strategies — delivered every Monday. Free.

Join our YouTube Channel for weekly AI Tutorials.



Share with others!


Author of AI Buzz

About the Author

Sapumal Herath

Sapumal is a specialist in Data Analytics and Business Intelligence. He focuses on helping businesses leverage AI and Power BI to drive smarter decision-making. Through AI Buzz, he shares his expertise on the future of work and emerging AI technologies. Follow him on LinkedIn for more tech insights.

Leave a Reply

Your email address will not be published. Required fields are marked *

Latest Posts…