Colorado AI Compliance

Colorado AI Act Compliance Checklist (2026 Update: SB 26-189, Effective January 1, 2027)

2026 update: Colorado rewrote this law. SB 26-189 (signed May 14, 2026) narrowed it to notice and transparency for automated decision-making and moved the effective date to January 1, 2027; a federal court paused enforcement in April 2026. Last updated: June 2026.

Last updated: June 8, 2026 · 13 min read · By RunAIAudit Editorial Team

Colorado’s 2024 AI Act (SB 24-205) was substantially rewritten by SB 26-189, signed May 14, 2026. The sweeping deployer duties — risk management policies, annual impact assessments, and the duty of care to prevent algorithmic discrimination — were removed. What remains is a narrower notice-and-transparency regime for automated decision-making technology, effective January 1, 2027 (a federal court paused enforcement in April 2026). If you use AI for consequential decisions affecting Colorado residents, here’s what still applies and what changed.

Key Takeaways

⚠️ 2026 update: Colorado rewrote this law (SB 26-189, signed May 14, 2026). The original high-risk obligations were narrowed to notice and transparency, the effective date moved to January 1, 2027, and a federal court paused enforcement in April 2026. Use the runway to get ahead — other laws (NYC LL144, fair lending) still apply now.

What is the Colorado AI Act?

The Colorado AI Act, formally known as Senate Bill 24-205 ("Concerning Consumer Protections for Interactions with Artificial Intelligence Systems"), is the first comprehensive state-level AI regulation in the United States. Governor Jared Polis signed the bill into law on May 17, 2024, making Colorado the first state to impose broad obligations on both developers and deployers of high-risk AI systems.

Unlike narrower regulations such as New York City's Local Law 144, which targets only automated employment decision tools, the Colorado AI Act applies across eight categories of consequential decisions. It creates a two-sided regulatory framework: developers who build or substantially modify AI systems have obligations around documentation and disclosure, while deployers — the businesses that actually use these systems — bear the primary compliance burden.

The law reflects Colorado's position that AI regulation should focus on outcomes and accountability rather than prescribing specific technical standards. The operative concept is "algorithmic discrimination" — any condition in which the use of an AI system results in unlawful differential treatment or disparate impact based on protected characteristics including age, color, disability, ethnicity, genetic information, national origin, race, religion, sex, and veteran status.

Important distinction: The Colorado AI Act does not ban the use of high-risk AI systems. Instead, it requires deployers to use "reasonable care" to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. The law establishes specific steps that constitute a rebuttable presumption of reasonable care.

Who does the Colorado AI Act apply to?

The Colorado AI Act distinguishes between two categories of regulated entities: developers and deployers. Understanding which category your organization falls into — and recognizing that you may fall into both — is the first step toward compliance.

Deployers

A deployer is any person doing business in Colorado that deploys a high-risk AI system. "Deploy" means to use a high-risk AI system or to make a high-risk AI system available to be used. This is the broadest category, and it is where most compliance obligations fall.

Critically, there is no minimum company size threshold. Unlike certain data privacy laws that exempt businesses below revenue or data-processing thresholds, the Colorado AI Act applies to any entity that uses a high-risk AI system for consequential decisions involving Colorado consumers. A five-person startup using an AI hiring tool to screen Colorado-based applicants is subject to the same obligations as a Fortune 500 employer.

Developers

A developer is any person doing business in Colorado that develops or intentionally and substantially modifies an AI system. Developers have their own set of obligations, primarily around documentation, transparency, and providing deployers with the information they need to conduct impact assessments.

Key questions to determine applicability

If you answered "yes" to all four, you likely use automated decision-making technology covered by Colorado’s revised AI Act — with notice and transparency obligations taking effect January 1, 2027.

What is a high-risk AI system under Colorado law?

The Colorado AI Act defines a high-risk AI system as any AI system that, when deployed, makes or is a substantial factor in making a consequential decision. The law does not regulate AI generally — only AI systems whose outputs materially affect consumer access to opportunities, services, or resources.

A consequential decision is defined as a decision that has a material legal or similarly significant effect on a consumer's access to, or the cost, terms, or availability of:

  1. Education enrollment or opportunity — admissions, financial aid eligibility, academic assessments
  2. Employment or employment opportunity — hiring, promotion, termination, compensation, task allocation
  3. Financial or lending services — credit decisions, loan underwriting, interest rates, account terms
  4. Essential government services — benefits eligibility, licensing, permitting
  5. Healthcare services — treatment recommendations, coverage decisions, diagnostic support
  6. Housing — rental applications, mortgage qualification, property valuations
  7. Insurance — underwriting, premium calculations, claims decisions
  8. Legal services — risk assessments, case evaluations, sentencing recommendations
Practical example: If your HR department uses an AI-powered applicant tracking system that scores or ranks candidates before a human reviews them, that system is likely a high-risk AI system under the Colorado AI Act — even if a human makes the final decision. The "substantial factor" standard means AI does not need to be the sole decision-maker to trigger compliance obligations.

The law also carves out certain exemptions. AI systems that perform narrow procedural tasks, anti-fraud systems used in specific financial contexts, and certain cybersecurity tools may fall outside the definition. However, these exemptions are narrowly construed, and organizations should not assume they qualify without careful analysis. If you are unsure whether your AI systems meet the threshold, an independent compliance audit can provide clarity before the enforcement deadline.

What are the compliance requirements for deployers?

Historical note (2024 law): The five obligations described below were imposed by the original Colorado AI Act (SB 24-205). SB 26-189 (2026) removed the risk-management-program and impact-assessment mandates and narrowed the law to consumer notice and transparency for automated decision-making, effective January 1, 2027. The detail below is retained for reference and as good-practice guidance.

The Colorado AI Act establishes five core obligations for deployers of high-risk AI systems. Fulfilling all five creates a rebuttable presumption that the deployer exercised reasonable care to avoid algorithmic discrimination — a powerful legal protection if the Attorney General investigates.

1. Risk management policy and procedures

Deployers must implement and maintain a risk management policy and program that governs the deployment of all high-risk AI systems. This is not a one-page document — it must be a substantive, operational framework that includes:

The risk management policy must be proportional to the size and complexity of the deployer, the nature and scope of the AI systems used, and the sensitivity of the data processed. A national insurer using AI for underwriting across multiple product lines will need a more detailed program than a small recruiter using a single screening tool — but both must have one.

2. Annual impact assessments

Deployers must complete an impact assessment for each high-risk AI system at least annually, and also within 90 days of any intentional and substantial modification to the system. The impact assessment must include:

Impact assessments must be retained for at least three years after the last deployment of the AI system. They must be made available to the Attorney General upon request — though the law provides that submission does not waive attorney-client privilege or work product protection.

If you need to understand the metrics and methodologies behind bias testing, we have covered those in detail separately.

3. Consumer notification requirements

Before or at the time a high-risk AI system is used as a substantial factor in a consequential decision, the deployer must provide the consumer with notice that includes:

The notice must be in a format and language that is "clear and readily understandable" to the consumer. For a lending institution, this might mean updating loan application disclosures. For an employer, it means informing job applicants at the point of application that AI tools will be used in screening. The specifics will vary by industry, but the obligation is uniform.

4. Disclosure obligations

Deployers must also make available on their website or through other publicly accessible means:

This public-facing disclosure is separate from the individual consumer notice. Think of it as your organization's public AI transparency statement — a document that tells the world you use high-risk AI and that you have controls in place.

5. Discrimination discovery reporting

If a deployer discovers that a high-risk AI system has resulted in algorithmic discrimination, the deployer must notify the Colorado Attorney General within 90 days of the discovery. The notification must describe the discrimination discovered, the AI system involved, and the steps taken in response.

This is arguably the most consequential obligation from a risk perspective. It creates an affirmative duty to report, similar to data breach notification requirements. Organizations must therefore have monitoring systems capable of detecting algorithmic discrimination — because ignorance is not a defense if the discrimination was reasonably discoverable.

The complete compliance checklist

Note: SB 26-189 narrowed the mandatory items. The notice, transparency and appeal steps remain relevant; the impact-assessment and risk-management-program steps are now optional best practice rather than Colorado mandates.

Use this checklist to track your organization's readiness for the revised Colorado AI Act (SB 26-189), effective January 1, 2027. Each item corresponds to a specific legal requirement or a practical step necessary to meet one. This checklist is designed to be bookmarked, printed, and shared with your compliance team.

Phase 1: Discovery and Inventory

Inventory all AI systems currently in use across your organization, including third-party vendor tools, internally built models, and embedded AI features in SaaS platforms.
Map each AI system to the decisions it makes or substantially influences — hiring, lending, underwriting, claims, admissions, etc.
Classify each AI system as high-risk or not based on whether it is used for consequential decisions as defined by the Act.
Identify which AI systems touch Colorado consumers — even if your business is headquartered in another state.

Phase 2: Risk Management Framework

Draft a comprehensive risk management policy covering all high-risk AI systems, including principles, processes, and designated personnel.
Define human oversight procedures for each high-risk AI system — who reviews AI-influenced decisions, how, and when.
Establish an ongoing monitoring schedule for detecting algorithmic discrimination, including metrics, testing cadence, and escalation thresholds.
Create record retention procedures ensuring impact assessments, risk management documentation, and monitoring records are preserved for at least three years.

Phase 3: Impact Assessments

Conduct an initial impact assessment for each high-risk AI system, documenting purpose, inputs, outputs, performance metrics, and known limitations.
Analyze and document known or reasonably foreseeable risks of algorithmic discrimination for each system, including disparate impact across protected classes.
Set a calendar for annual reassessments and define triggers for reassessment upon substantial modification of any system.

Phase 4: Consumer-Facing Obligations

Implement consumer notice procedures for each deployment context — job applications, loan applications, insurance quotes, healthcare interactions, etc.
Create a consumer appeal and human review process — document how consumers can contest an AI-influenced decision and how requests will be handled.
Publish a public AI transparency statement on your website listing the types of high-risk AI systems you deploy and how you manage discrimination risks.

Phase 5: Reporting and Incident Response

Establish a discrimination discovery reporting protocol with clear internal escalation paths, documentation standards, and a 90-day notification timeline to the Colorado AG.
Identify the internal owner (compliance officer, legal counsel, or designated AI governance lead) responsible for AG notifications.
Develop an incident response plan for algorithmic discrimination events, including remediation steps, consumer notification, and system suspension criteria.

Phase 6: Training and Governance

Train all staff involved in AI deployment, oversight, or decision-making on their compliance obligations under the Colorado AI Act.
Ensure vendor contracts include provisions requiring developer cooperation — developers must provide the information deployers need for impact assessments.
Schedule a readiness review to get ahead of the revised Colorado AI Act before it takes effect January 1, 2027.

Key dates and timeline

Understanding the legislative timeline helps contextualize the urgency. The law has been in effect for over two years — the enforcement date is not a surprise.

Colorado AI Act Timeline

May 17, 2024
Bill signed into law. Governor Jared Polis signs SB 24-205, establishing the Colorado AI Act with a two-year implementation runway.
May 2024 – June 2026
Implementation and amendment period. The original obligations were debated and ultimately narrowed; in May 2026 the legislature replaced them via SB 26-189.
February 1, 2026
AG rulemaking authority begins. The Colorado Attorney General gains authority to adopt rules to implement and enforce the Act.
January 1, 2027 — Revised law (SB 26-189) takes effect
Revised law takes effect. SB 26-189’s notice-and-transparency obligations apply from this date. AG Weiser has indicated enforcement will not begin until rulemaking concludes.
May 14, 2026
SB 26-189 signed into law. Replaced original SB 24-205, removing impact assessments and risk management mandates. Narrowed the law to notice, disclosure, correction, and human review duties effective January 1, 2027.

What are the penalties for non-compliance?

The Colorado AI Act is enforced exclusively by the Colorado Attorney General under the Colorado Consumer Protection Act (CPA). There is no private right of action — individual consumers cannot sue deployers directly. Note that SB 26-189 (2026) narrowed the obligations and moved the effective date to January 1, 2027. AG Weiser has indicated enforcement will not begin until rulemaking concludes.

Each violation of the Colorado AI Act is treated as a deceptive trade practice under the CPA. The Attorney General can seek:

The law also provides an important affirmative defense. Deployers who comply with all five core obligations (risk management policy, impact assessments, consumer notice, public disclosure, and discrimination reporting) are afforded a rebuttable presumption of having exercised reasonable care. This is a strong incentive for full compliance: organizations that take the right steps can defend themselves effectively if challenged.

Additionally, deployers who discover and cure a violation — meaning they fix the problem and mitigate harm before the AG takes action — may have additional protections. The Act includes a cure provision, but it requires prompt action and good-faith remediation. It is not a blanket safe harbor for organizations that delayed compliance and hope to fix problems only when caught.

The potential costs of non-compliance can escalate quickly. To understand what proactive compliance typically costs compared to enforcement exposure, see our AI audit cost comparison guide.

How does the Colorado AI Act compare to other state AI laws?

The Colorado AI Act does not exist in a regulatory vacuum. Understanding how it compares to other existing and emerging AI regulations helps organizations build compliance programs that work across jurisdictions.

Dimension Colorado AI Act (SB 24-205) NYC Local Law 144 Illinois BIPA / AI Video Act
Scope High-risk AI across 8 decision categories Automated employment decision tools only Biometric data collection; AI video interviews
Geography Statewide (Colorado) New York City only Statewide (Illinois)
Key obligation Risk management + impact assessments + consumer notice Annual bias audit by independent auditor Consent before biometric collection; notice for AI interviews
Enforcement Attorney General only NYC DCWP (fines) Private right of action (BIPA); AG (AI Video)
Penalties Up to $20,000/violation (CPA) $500–$1,500/violation $1,000–$5,000/violation (BIPA); varies (AI Video)

The critical difference: the Colorado AI Act is the broadest state AI law in the country. While NYC LL144 is limited to employment and Illinois BIPA targets biometrics, Colorado covers nearly every high-stakes domain where AI touches consumer lives. Organizations already compliant with NYC LL144 have a head start on the employment component, but they will need to extend their programs significantly to cover financial services, healthcare, insurance, housing, education, legal services, and government services.

What should deployers do right now?

With the effective date now January 1, 2027 and enforcement paused pending rulemaking, you have real runway — use it to get ahead rather than scramble. Here is a prioritized action plan:

This week (days 1–7): Foundation

  1. Complete your AI inventory. You cannot comply if you do not know what AI systems you use. Catalog every tool, vendor, and model that touches consequential decisions. This is a non-negotiable first step.
  2. Classify systems as high-risk or not. Apply the eight-category test. When in doubt, classify as high-risk — over-inclusion is safer than under-inclusion.
  3. Draft your risk management policy. Start with a framework document that covers governance structure, roles, and principles. It can be refined over time, but it must exist.

Week two (days 8–14): Documentation

  1. Conduct initial impact assessments. For each high-risk system, document its purpose, data inputs, outputs, performance metrics, and discrimination risk profile. Request technical documentation from vendors — developers have obligations to provide this under the Act.
  2. Publish your transparency statement. Add a public-facing AI disclosure to your website. This is one of the fastest items to complete and demonstrates good faith.

Week three (days 15–22): Operationalize

  1. Implement consumer notice. Update application forms, intake processes, and customer-facing communications to include required AI disclosures.
  2. Stand up your appeal process. Document how consumers can request human review of AI-influenced decisions. Designate staff, create intake forms, and set response timelines.
  3. Establish your AG reporting protocol. Designate a responsible officer, create a reporting template, and document your 90-day notification workflow.
  4. Train key staff. Brief managers, HR staff, loan officers, claims adjusters, and anyone else involved in AI-influenced decisions on the new requirements.
  5. Engage an independent auditor. If you have not already, schedule an AI compliance audit to validate your program and identify gaps before the AG does.

The cure provision is not a compliance plan. While the Colorado AI Act allows deployers to cure violations, relying on the cure provision as your primary strategy is risky. The AG may argue that organizations with no compliance program at all cannot demonstrate good faith, even if they scramble to fix problems after receiving notice.

How RunAIAudit helps with Colorado AI Act compliance

RunAIAudit provides independent AI compliance audits designed to meet the specific requirements of the Colorado AI Act and other emerging regulations. Our approach is built around the exact obligations deployers face:

We work with organizations across industries — from financial services firms and healthcare systems to employers and insurers. Whether you need a comprehensive compliance program built from scratch or a gap analysis against an existing program, we can help. For a detailed breakdown of what AI audits typically cost, see our cost comparison guide.

Get ahead of the Colorado AI Act before January 1, 2027

The revised law takes effect January 1, 2027. Our team can assess your AI systems, identify gaps, and help you build a defensible compliance program. Start with a free consultation.

Get your audit

Frequently asked questions

When does the Colorado AI Act take effect?
The Colorado AI Act (SB 24-205, 2024) was substantially rewritten by SB 26-189, signed May 14, 2026. The revised law narrows obligations to notice and transparency for automated decision-making technology and moves the effective date to January 1, 2027. A federal court paused enforcement in April 2026 pending rulemaking. All compliance obligations must be met by the enforcement date.
Does the Colorado AI Act apply to my business?
The Colorado AI Act applies to any business that deploys a high-risk AI system to make or substantially influence consequential decisions affecting Colorado consumers. This includes decisions in employment, education, financial services, healthcare, housing, insurance, legal services, and government services. There is no minimum company size threshold — if you use AI for these decisions involving Colorado residents, the law applies to you. If you are unsure, this guide can help you determine whether you need an AI audit.
What is a high-risk AI system under the Colorado AI Act?
Under the Colorado AI Act, a high-risk AI system is any AI system that makes or is a substantial factor in making a consequential decision affecting a consumer. Consequential decisions include those related to employment, education, financial or lending services, healthcare, housing, insurance, legal services, and access to government services. The key test is whether the AI system has a material effect on consumer access to opportunities, services, or resources.
What are the penalties for violating the Colorado AI Act?
The Colorado AI Act is enforced exclusively by the Colorado Attorney General under the Colorado Consumer Protection Act. Each violation can be treated as a deceptive trade practice, carrying penalties of up to $20,000 per violation. There is no private right of action, meaning individual consumers cannot sue directly. Note that SB 26-189 (2026) narrowed the law and moved the effective date to January 1, 2027, with enforcement paused pending rulemaking; penalty specifics for the revised law are being finalized.
Do I need to notify consumers that AI is being used?
Yes. Deployers of high-risk AI systems must provide consumers with notice that an AI system is being used as a substantial factor in consequential decisions. The notice must include a description of the AI system in plain language, the purpose for which it is used, deployer contact information, and a description of how the consumer can request human review of or appeal the decision. This notice must be provided before or at the time the AI system is used.
How does the Colorado AI Act differ from NYC Local Law 144?
The Colorado AI Act is significantly broader than NYC Local Law 144. While NYC LL144 applies only to automated employment decision tools used in hiring and promotion within New York City, the Colorado AI Act covers high-risk AI systems across eight consequential decision categories including employment, education, financial services, healthcare, housing, insurance, legal services, and government services. Colorado's law also applies statewide rather than to a single city, and it requires ongoing risk management programs rather than just annual bias audits.