Colorado's AI Act Evolved: What SB 26-189 Requires From Developers and Deployers Before the 2027 Deadline

Colorado repealed SB 24-205 and replaced it with SB 26-189, a new ADMT framework effective January 1, 2027. Here's what developers and deployers must do now to prepare for AG enforcement.

Colorado's AI Act Evolved: What SB 26-189 Requires From Developers and Deployers Before the 2027 Deadline
Loading AudioNative Player...

From SB 24-205 to SB 26-189: What Changed and Why It Matters

When Colorado Governor Jared Polis signed Senate Bill 24-205 into law on May 17, 2024, it became the first comprehensive U.S. state statute to impose developer- and deployer-level duties around AI systems that make consequential decisions about consumers. The original law — modeled in part on the EU AI Act's risk-tiered approach — was set to take effect February 1, 2026. But the legislative landscape shifted quickly.

In August 2025, Polis signed Senate Bill 25B-004 (the "AI Sunshine Act"), which delayed enforcement from February 1 to June 30, 2026 while preserving the core transparency and accountability measures. Then, on May 14, 2026, Polis signed Senate Bill 26-189, which repealed and reenacted the entire framework as the "Automated Decision-Making Technology in Consequential Decisions Act" (ADMT Act). The new law takes effect January 1, 2027, and the Colorado Attorney General must adopt implementing rules before that date.

For in-house counsel, the practical message is clear: the compliance target has moved, but the obligations have not disappeared. They have been restructured. If your company develops or deploys AI systems that influence decisions about consumers in Colorado — whether in hiring, lending, insurance, healthcare, housing, education, or government services — you need to understand what the current law actually requires and build a compliance roadmap before the 2027 deadline.

What Counts as "Covered ADMT": The New Scope Test

The most significant structural change in SB 26-189 is the shift from "high-risk AI systems" to "Covered ADMT." The new law defines automated decision-making technology (ADMT) as technology that processes personal data and uses computation to generate output — predictions, recommendations, classifications, rankings, scores, or other information — used to make, guide, or assist a decision about an individual. Only ADMT that "materially influences" a "consequential decision" triggers the law's substantive obligations.

"Materially influences" means the ADMT's output is a non-de minimis factor in the decision and affects the outcome — including by constraining, ranking, scoring, recommending, classifying, or otherwise meaningfully altering how the decision is made. Incidental, trivial, or clerical uses are excluded.

Consequential decisions are those that relate to a consumer's access to, eligibility for, selection for, or compensation within one of seven covered domains:

  • Education enrollment or opportunities
  • Employment or employment opportunities (creating or potentially creating an employer-employee relationship)
  • Leases or purchases of residential real estate in Colorado
  • Financial or lending services
  • Insurance (underwriting, pricing, coverage, claims adjudication)
  • Healthcare services
  • Essential government services and public benefits

The law also excludes a broad range of routine technologies from the definition of ADMT altogether — anti-malware, firewalls, calculators, spreadsheets that require human analysis without machine learning, spam filtering, and chatbots governed by acceptable-use policies that prohibit use in consequential decisions. This is a narrower scope than the original SB 24-205, which used the broader term "high-risk artificial intelligence system" and did not include the same detailed exclusions.

Developer Obligations Under SB 26-189

A developer is a person doing business in Colorado who develops or intentionally and substantially modifies ADMT. Under the new law, developers of Covered ADMT must:

  • Provide transparency documentation to deployers — including intended uses, harmful or inappropriate uses, training data categories (to the extent known), known limitations and risks, and instructions for appropriate use, monitoring, and meaningful human review.
  • Provide change notices — developers must notify deployers of material updates, intentional and substantial modifications, and changes to intended use, limitations, or risk-mitigation measures within a reasonable time.
  • Retain compliance records for at least three years.

Notably, the new law eliminates several obligations that existed under the original SB 24-205, including the requirement to report known or reasonably foreseeable risks of algorithmic discrimination to the Colorado Attorney General, the mandate to conduct formal AI impact assessments, and the obligation to implement a documented risk management policy. This represents a significant narrowing from the original framework, which had drawn comparisons to the EU AI Act's developer duties. For a deeper comparison of how U.S. state AI laws track or diverge from the EU framework, see our earlier analysis of the EU AI Act's deadline extension and what U.S. companies should do now.

Deployer Obligations Under SB 26-189

A deployer is a person doing business in Colorado who uses Covered ADMT. Deployers bear the most consumer-facing obligations under the new law:

  • Pre-use consumer notice — deployers must provide clear notice to consumers before using Covered ADMT to materially influence a consequential decision. This can be satisfied via a reasonably accessible, prominent public notice, including through a link or posting proximate to the consumer interaction or transaction.
  • Adverse outcome disclosure — if use of Covered ADMT results in an "Adverse Outcome" (defined as a decision that denies, terminates, revokes, or materially reduces a consumer's access, eligibility, or opportunity, or imposes materially less favorable pricing or terms), the deployer must, within 30 days, provide the impacted consumer with: a plain-language description of the decision and the ADMT's role, instructions to request additional information (including system name, version, developer, and types of personal data used), and an explanation of consumer rights.
  • Consumer rights to correction and human review — consumers may request correction of factually incorrect or materially inaccurate personal data used by the ADMT, and an opportunity for meaningful human review and reconsideration of the consequential decision.
  • Record retention — deployers must retain compliance records for at least three years after each use.

The original SB 24-205 required deployers to implement a risk management policy, complete impact assessments, and annually review each deployed system for algorithmic discrimination. These obligations are gone under SB 26-189. However, deployers should note that the Colorado Privacy Act already requires data protection assessments for profiling that carries reasonably foreseeable risks of substantial injury — so the practical compliance burden for high-risk profiling use cases may not have changed as much as the statutory text suggests.

Liability Allocation: Who Pays When ADMT Discriminates

One of the most consequential additions in SB 26-189 is its liability allocation framework. The law explicitly clarifies that both developers and deployers may be held liable for unlawful discrimination under Colorado anti-discrimination laws, including the Colorado Anti-Discrimination Act. However, liability is apportioned based on relative fault:

  • If a deployer uses Covered ADMT exactly as the developer intended, documented, marketed, advertised, configured, or contracted it — and the results are still discriminatory — the developer bears liability.
  • If a deployer uses Covered ADMT in a way that was not intended, documented, marketed, advertised, configured, or contracted by the developer, the deployer bears liability for such unlawful use.

The law does not create joint and several liability (except as permitted under existing law). Critically, indemnification clauses that purport to shift a developer's or deployer's liability for its own discriminatory acts or omissions onto the other party are void as against public policy. This means your standard AI vendor contracts may need revision — a topic we cover in our AI vendor contract due diligence checklist.

AG Enforcement: What to Expect

SB 26-189 does not create a private right of action. Enforcement is exclusive to the Colorado Attorney General, and violations are treated as deceptive trade practices under the Colorado Consumer Protection Act. The AG's office is currently in the pre-rulemaking phase, having collected informal public comments through July 13, 2026, and published a considerations paper to guide the drafting process. Formal rulemaking is expected to begin before the January 1, 2027 effective date.

For in-house counsel, this means two things. First, the specific compliance parameters — including what constitutes adequate notice, how consumer correction requests must be handled, and what records will satisfy the retention requirement — will be shaped by AG rules that have not yet been issued. Second, the AG's active engagement in the rulemaking process signals a genuine intent to enforce. Companies that wait until the rules are finalized to begin compliance planning will likely find themselves scrambling.

The AG's rulemaking also covers the companion Chatbot Safety Act (House Bill 26-1263), signed July 1, 2026, which requires chatbot operators to disclose AI interaction, estimate user age, safeguard teen users against sexually explicit content and simulated emotional dependence, implement suicide and self-harm response protocols, and submit annual reports to the AG. Both laws take effect January 1, 2027.

How Colorado Compares to TRAIGA and the EU AI Act

Colorado's revised framework sits between Texas's TRAIGA and the EU AI Act on the regulatory intensity spectrum. Texas's TRAIGA imposes disclosure obligations on developers of AI systems used for consequential decisions but offers a safe harbor for companies that comply with the NIST AI Risk Management Framework. Colorado's SB 26-189 does not include a comparable safe harbor provision, though it does allow deployers to rely on existing FCRA or FERPA notices if they meet the law's requirements — and insurers subject to Colorado's unfair trade practices law are deemed in compliance.

The EU AI Act, by contrast, maintains a more aggressive risk-tiered approach with mandatory conformity assessments, CE marking, and registration in an EU database for high-risk systems. Colorado's revised law dropped the impact assessment and risk management policy requirements that had drawn the EU comparison in the first place, making it a lighter-touch regime than either the EU AI Act or the original SB 24-205. But it remains the most prescriptive U.S. state law on AI-driven decision-making, and its consumer-facing disclosure and correction rights go beyond what TRAIGA requires.

Exemptions and Sector-Specific Safe Harbors

The new law includes several compliance shortcuts for regulated industries:

  • Insurers subject to Colorado Revised Statutes Section 10-3-1104.0 (prohibiting unfair or deceptive practices) are deemed in compliance with the ADMT Act's obligations.
  • Financial institutions examined by state or federal prudential regulators under published guidance meeting the law's criteria are in full compliance.
  • HIPAA-covered entities operating from locations within Colorado receive a partial exemption — but must still provide general notice to patients about use of advanced technologies, and must provide adverse-outcome disclosures when using Covered ADMT for financial assistance eligibility determinations. The HIPAA exemption does not apply to employment-related decisions.
  • Deployers may rely on existing FCRA or FERPA consumer notices if those notices meet the ADMT Act's notice requirements.

Actionable Next Steps

With the January 1, 2027 compliance deadline and AG rulemaking underway, in-house counsel should take the following steps now:

  1. Inventory your AI systems. Identify every system your company develops or deploys that processes personal data and generates predictions, scores, rankings, or classifications used in decisions about consumers. Map each system to a covered domain. This is the foundation of any defensible compliance program — and we've outlined a practical approach in our AI governance quick wins guide.
  2. Classify each system as developer, deployer, or both. Your obligations differ depending on whether you built the system, modified it, or simply use it. If you fine-tune a vendor's model for your own use case, you may be both a deployer and a developer.
  3. Audit your vendor contracts. The law voids indemnification clauses that shift liability for a party's own discriminatory acts. Review your AI vendor agreements for provisions that may now be unenforceable, and negotiate replacements that allocate risk consistent with the relative-fault standard.
  4. Build consumer-facing notice templates. Draft pre-use notices and adverse-outcome disclosure templates that can be deployed at points of consumer interaction. If you already provide FCRA or FERPA notices, evaluate whether they can be adapted to satisfy the ADMT Act's requirements.
  5. Establish a personal-data correction process. The law gives consumers the right to request correction of inaccurate personal data used in consequential decisions. Work with your data governance and engineering teams to build a process that can receive, evaluate, and act on correction requests within a reasonable timeframe.
  6. Monitor AG rulemaking. Sign up for updates from the Colorado AG's AI rulemaking page and plan to submit comments during the formal rulemaking phase. The rules will define the practical compliance parameters — and companies that participate in the process will have a head start on implementation.
  7. Document compliance efforts. Even though the formal impact assessment requirement is gone, maintaining records of your compliance activities — system inventories, vendor due diligence, consumer notices, correction requests — will be essential if the AG opens an investigation. The law requires record retention for at least three years.

The compliance window is real, and the AG has signaled an intent to enforce. Companies that begin now — while the rules are still being drafted — will have the flexibility to shape the process and the runway to implement changes before the deadline arrives.

If your company develops or deploys AI systems that touch Colorado consumers, you need a compliance roadmap tailored to SB 26-189's developer-deployer framework. Our team can help you assess your systems, revise vendor contracts, and build the disclosure and correction processes the law requires.

Contact our team