Colorado’s 2024 AI Act (SB 24-205) was substantially rewritten by SB 26-189, signed May 14, 2026. The sweeping deployer duties — risk management policies, annual impact assessments, and the duty of care to prevent algorithmic discrimination — were removed. What remains is a narrower notice-and-transparency regime for automated decision-making technology, effective January 1, 2027 (a federal court paused enforcement in April 2026). If you use AI for consequential decisions affecting Colorado residents, here’s what still applies and what changed.
Key Takeaways
- The law was rewritten in 2026. SB 26-189 narrows it to notice and transparency and moves the effective date to January 1, 2027; enforcement is currently paused.
- The law covers eight categories of consequential decisions — employment, education, financial services, healthcare, housing, insurance, legal services, and government services.
- The original 2024 law required a risk management policy, annual impact assessments, consumer notices and AG reporting — but SB 26-189 removed most of these, leaving consumer notice and transparency.
- There is no private right of action. The Colorado Attorney General enforces the law under the Consumer Protection Act; obligations and penalties for the rewritten law are being set through rulemaking ahead of the January 1, 2027 effective date.
- No minimum company size threshold exists — any business using high-risk AI on Colorado consumers must comply, regardless of revenue or headcount.
⚠️ 2026 update: Colorado rewrote this law (SB 26-189, signed May 14, 2026). The original high-risk obligations were narrowed to notice and transparency, the effective date moved to January 1, 2027, and a federal court paused enforcement in April 2026. Use the runway to get ahead — other laws (NYC LL144, fair lending) still apply now.
What is the Colorado AI Act?
The Colorado AI Act, formally known as Senate Bill 24-205 ("Concerning Consumer Protections for Interactions with Artificial Intelligence Systems"), is the first comprehensive state-level AI regulation in the United States. Governor Jared Polis signed the bill into law on May 17, 2024, making Colorado the first state to impose broad obligations on both developers and deployers of high-risk AI systems.
Unlike narrower regulations such as New York City's Local Law 144, which targets only automated employment decision tools, the Colorado AI Act applies across eight categories of consequential decisions. It creates a two-sided regulatory framework: developers who build or substantially modify AI systems have obligations around documentation and disclosure, while deployers — the businesses that actually use these systems — bear the primary compliance burden.
The law reflects Colorado's position that AI regulation should focus on outcomes and accountability rather than prescribing specific technical standards. The operative concept is "algorithmic discrimination" — any condition in which the use of an AI system results in unlawful differential treatment or disparate impact based on protected characteristics including age, color, disability, ethnicity, genetic information, national origin, race, religion, sex, and veteran status.
Who does the Colorado AI Act apply to?
The Colorado AI Act distinguishes between two categories of regulated entities: developers and deployers. Understanding which category your organization falls into — and recognizing that you may fall into both — is the first step toward compliance.
Deployers
A deployer is any person doing business in Colorado that deploys a high-risk AI system. "Deploy" means to use a high-risk AI system or to make a high-risk AI system available to be used. This is the broadest category, and it is where most compliance obligations fall.
Critically, there is no minimum company size threshold. Unlike certain data privacy laws that exempt businesses below revenue or data-processing thresholds, the Colorado AI Act applies to any entity that uses a high-risk AI system for consequential decisions involving Colorado consumers. A five-person startup using an AI hiring tool to screen Colorado-based applicants is subject to the same obligations as a Fortune 500 employer.
Developers
A developer is any person doing business in Colorado that develops or intentionally and substantially modifies an AI system. Developers have their own set of obligations, primarily around documentation, transparency, and providing deployers with the information they need to conduct impact assessments.
Key questions to determine applicability
- Do you do business in Colorado? This includes serving Colorado-based customers, even if your company is headquartered elsewhere.
- Do you use any AI system — including third-party tools, vendor platforms, or internally built models?
- Does that AI system make or substantially influence a consequential decision? (See the next section for what qualifies.)
- Does the decision affect a Colorado consumer? A "consumer" is a Colorado resident acting in an individual capacity.
If you answered "yes" to all four, you likely use automated decision-making technology covered by Colorado’s revised AI Act — with notice and transparency obligations taking effect January 1, 2027.
What is a high-risk AI system under Colorado law?
The Colorado AI Act defines a high-risk AI system as any AI system that, when deployed, makes or is a substantial factor in making a consequential decision. The law does not regulate AI generally — only AI systems whose outputs materially affect consumer access to opportunities, services, or resources.
A consequential decision is defined as a decision that has a material legal or similarly significant effect on a consumer's access to, or the cost, terms, or availability of:
- Education enrollment or opportunity — admissions, financial aid eligibility, academic assessments
- Employment or employment opportunity — hiring, promotion, termination, compensation, task allocation
- Financial or lending services — credit decisions, loan underwriting, interest rates, account terms
- Essential government services — benefits eligibility, licensing, permitting
- Healthcare services — treatment recommendations, coverage decisions, diagnostic support
- Housing — rental applications, mortgage qualification, property valuations
- Insurance — underwriting, premium calculations, claims decisions
- Legal services — risk assessments, case evaluations, sentencing recommendations
The law also carves out certain exemptions. AI systems that perform narrow procedural tasks, anti-fraud systems used in specific financial contexts, and certain cybersecurity tools may fall outside the definition. However, these exemptions are narrowly construed, and organizations should not assume they qualify without careful analysis. If you are unsure whether your AI systems meet the threshold, an independent compliance audit can provide clarity before the enforcement deadline.
What are the compliance requirements for deployers?
Historical note (2024 law): The five obligations described below were imposed by the original Colorado AI Act (SB 24-205). SB 26-189 (2026) removed the risk-management-program and impact-assessment mandates and narrowed the law to consumer notice and transparency for automated decision-making, effective January 1, 2027. The detail below is retained for reference and as good-practice guidance.
The Colorado AI Act establishes five core obligations for deployers of high-risk AI systems. Fulfilling all five creates a rebuttable presumption that the deployer exercised reasonable care to avoid algorithmic discrimination — a powerful legal protection if the Attorney General investigates.
1. Risk management policy and procedures
Deployers must implement and maintain a risk management policy and program that governs the deployment of all high-risk AI systems. This is not a one-page document — it must be a substantive, operational framework that includes:
- Principles, processes, and personnel for identifying, documenting, and mitigating known or reasonably foreseeable risks of algorithmic discrimination
- An overview of the categories of high-risk AI systems the deployer currently uses or plans to use
- An overview of the categories of consequential decisions for which those systems are used
- Procedures for human oversight, including how employees are trained and how they intervene when algorithmic discrimination is suspected
- Processes for ongoing monitoring, periodic review, and updating of AI systems and the risk management program itself
The risk management policy must be proportional to the size and complexity of the deployer, the nature and scope of the AI systems used, and the sensitivity of the data processed. A national insurer using AI for underwriting across multiple product lines will need a more detailed program than a small recruiter using a single screening tool — but both must have one.
2. Annual impact assessments
Deployers must complete an impact assessment for each high-risk AI system at least annually, and also within 90 days of any intentional and substantial modification to the system. The impact assessment must include:
- A statement of the purpose, intended use cases, and deployment context of the AI system
- An analysis of whether the AI system poses known or reasonably foreseeable risks of algorithmic discrimination, and the nature of those risks
- A description of the data the AI system processes as inputs, and the outputs it produces
- The metrics used to evaluate the AI system's performance, and known limitations
- A description of the transparency measures provided to consumers
- A description of the post-deployment monitoring processes in place
Impact assessments must be retained for at least three years after the last deployment of the AI system. They must be made available to the Attorney General upon request — though the law provides that submission does not waive attorney-client privilege or work product protection.
If you need to understand the metrics and methodologies behind bias testing, we have covered those in detail separately.
3. Consumer notification requirements
Before or at the time a high-risk AI system is used as a substantial factor in a consequential decision, the deployer must provide the consumer with notice that includes:
- A statement that the deployer is using a high-risk AI system to make or be a substantial factor in the consequential decision
- A description of the AI system in plain language
- Contact information for the deployer
- A description of how the consumer may request human review of, or appeal, a decision where the AI system was a substantial factor
The notice must be in a format and language that is "clear and readily understandable" to the consumer. For a lending institution, this might mean updating loan application disclosures. For an employer, it means informing job applicants at the point of application that AI tools will be used in screening. The specifics will vary by industry, but the obligation is uniform.
4. Disclosure obligations
Deployers must also make available on their website or through other publicly accessible means:
- A statement that the deployer currently deploys high-risk AI systems
- The types of high-risk AI systems that the deployer currently deploys
- How the deployer manages known or reasonably foreseeable risks of algorithmic discrimination that may arise from the deployment
This public-facing disclosure is separate from the individual consumer notice. Think of it as your organization's public AI transparency statement — a document that tells the world you use high-risk AI and that you have controls in place.
5. Discrimination discovery reporting
If a deployer discovers that a high-risk AI system has resulted in algorithmic discrimination, the deployer must notify the Colorado Attorney General within 90 days of the discovery. The notification must describe the discrimination discovered, the AI system involved, and the steps taken in response.
This is arguably the most consequential obligation from a risk perspective. It creates an affirmative duty to report, similar to data breach notification requirements. Organizations must therefore have monitoring systems capable of detecting algorithmic discrimination — because ignorance is not a defense if the discrimination was reasonably discoverable.
The complete compliance checklist
Note: SB 26-189 narrowed the mandatory items. The notice, transparency and appeal steps remain relevant; the impact-assessment and risk-management-program steps are now optional best practice rather than Colorado mandates.
Use this checklist to track your organization's readiness for the revised Colorado AI Act (SB 26-189), effective January 1, 2027. Each item corresponds to a specific legal requirement or a practical step necessary to meet one. This checklist is designed to be bookmarked, printed, and shared with your compliance team.
Phase 1: Discovery and Inventory
Phase 2: Risk Management Framework
Phase 3: Impact Assessments
Phase 4: Consumer-Facing Obligations
Phase 5: Reporting and Incident Response
Phase 6: Training and Governance
Key dates and timeline
Understanding the legislative timeline helps contextualize the urgency. The law has been in effect for over two years — the enforcement date is not a surprise.
Colorado AI Act Timeline
What are the penalties for non-compliance?
The Colorado AI Act is enforced exclusively by the Colorado Attorney General under the Colorado Consumer Protection Act (CPA). There is no private right of action — individual consumers cannot sue deployers directly. Note that SB 26-189 (2026) narrowed the obligations and moved the effective date to January 1, 2027. AG Weiser has indicated enforcement will not begin until rulemaking concludes.
Each violation of the Colorado AI Act is treated as a deceptive trade practice under the CPA. The Attorney General can seek:
- Civil penalties up to $20,000 per violation — and in cases of systemic non-compliance affecting many consumers, each affected consumer may constitute a separate violation
- Injunctive relief — court orders requiring the deployer to stop using a non-compliant AI system or to take specific corrective actions
- Restitution — compensation to consumers harmed by algorithmic discrimination
- Costs and attorney fees
The law also provides an important affirmative defense. Deployers who comply with all five core obligations (risk management policy, impact assessments, consumer notice, public disclosure, and discrimination reporting) are afforded a rebuttable presumption of having exercised reasonable care. This is a strong incentive for full compliance: organizations that take the right steps can defend themselves effectively if challenged.
Additionally, deployers who discover and cure a violation — meaning they fix the problem and mitigate harm before the AG takes action — may have additional protections. The Act includes a cure provision, but it requires prompt action and good-faith remediation. It is not a blanket safe harbor for organizations that delayed compliance and hope to fix problems only when caught.
The potential costs of non-compliance can escalate quickly. To understand what proactive compliance typically costs compared to enforcement exposure, see our AI audit cost comparison guide.
How does the Colorado AI Act compare to other state AI laws?
The Colorado AI Act does not exist in a regulatory vacuum. Understanding how it compares to other existing and emerging AI regulations helps organizations build compliance programs that work across jurisdictions.
| Dimension | Colorado AI Act (SB 24-205) | NYC Local Law 144 | Illinois BIPA / AI Video Act |
|---|---|---|---|
| Scope | High-risk AI across 8 decision categories | Automated employment decision tools only | Biometric data collection; AI video interviews |
| Geography | Statewide (Colorado) | New York City only | Statewide (Illinois) |
| Key obligation | Risk management + impact assessments + consumer notice | Annual bias audit by independent auditor | Consent before biometric collection; notice for AI interviews |
| Enforcement | Attorney General only | NYC DCWP (fines) | Private right of action (BIPA); AG (AI Video) |
| Penalties | Up to $20,000/violation (CPA) | $500–$1,500/violation | $1,000–$5,000/violation (BIPA); varies (AI Video) |
The critical difference: the Colorado AI Act is the broadest state AI law in the country. While NYC LL144 is limited to employment and Illinois BIPA targets biometrics, Colorado covers nearly every high-stakes domain where AI touches consumer lives. Organizations already compliant with NYC LL144 have a head start on the employment component, but they will need to extend their programs significantly to cover financial services, healthcare, insurance, housing, education, legal services, and government services.
What should deployers do right now?
With the effective date now January 1, 2027 and enforcement paused pending rulemaking, you have real runway — use it to get ahead rather than scramble. Here is a prioritized action plan:
This week (days 1–7): Foundation
- Complete your AI inventory. You cannot comply if you do not know what AI systems you use. Catalog every tool, vendor, and model that touches consequential decisions. This is a non-negotiable first step.
- Classify systems as high-risk or not. Apply the eight-category test. When in doubt, classify as high-risk — over-inclusion is safer than under-inclusion.
- Draft your risk management policy. Start with a framework document that covers governance structure, roles, and principles. It can be refined over time, but it must exist.
Week two (days 8–14): Documentation
- Conduct initial impact assessments. For each high-risk system, document its purpose, data inputs, outputs, performance metrics, and discrimination risk profile. Request technical documentation from vendors — developers have obligations to provide this under the Act.
- Publish your transparency statement. Add a public-facing AI disclosure to your website. This is one of the fastest items to complete and demonstrates good faith.
Week three (days 15–22): Operationalize
- Implement consumer notice. Update application forms, intake processes, and customer-facing communications to include required AI disclosures.
- Stand up your appeal process. Document how consumers can request human review of AI-influenced decisions. Designate staff, create intake forms, and set response timelines.
- Establish your AG reporting protocol. Designate a responsible officer, create a reporting template, and document your 90-day notification workflow.
- Train key staff. Brief managers, HR staff, loan officers, claims adjusters, and anyone else involved in AI-influenced decisions on the new requirements.
- Engage an independent auditor. If you have not already, schedule an AI compliance audit to validate your program and identify gaps before the AG does.
The cure provision is not a compliance plan. While the Colorado AI Act allows deployers to cure violations, relying on the cure provision as your primary strategy is risky. The AG may argue that organizations with no compliance program at all cannot demonstrate good faith, even if they scramble to fix problems after receiving notice.
How RunAIAudit helps with Colorado AI Act compliance
RunAIAudit provides independent AI compliance audits designed to meet the specific requirements of the Colorado AI Act and other emerging regulations. Our approach is built around the exact obligations deployers face:
- AI system inventory and classification — we help you identify every AI system in your organization and determine which qualify as high-risk under the Act
- Impact assessment support — our team conducts rigorous bias testing and disparate impact analysis across protected classes, producing documentation that meets the Act's requirements
- Risk management policy development — we help you build a risk management framework proportional to your organization's size, complexity, and AI usage
- Consumer notice and disclosure templates — we provide tested language and implementation guidance for your consumer-facing obligations
- Ongoing monitoring setup — we help you establish metrics, testing cadences, and escalation procedures for continuous compliance
We work with organizations across industries — from financial services firms and healthcare systems to employers and insurers. Whether you need a comprehensive compliance program built from scratch or a gap analysis against an existing program, we can help. For a detailed breakdown of what AI audits typically cost, see our cost comparison guide.
Get ahead of the Colorado AI Act before January 1, 2027
The revised law takes effect January 1, 2027. Our team can assess your AI systems, identify gaps, and help you build a defensible compliance program. Start with a free consultation.
Get your audit