Business

Colorado reset its AI law. Here’s what that means for you.

Business
By Bianca
image post Colorado reset its AI law. Here’s what that means for you.
The short version

Colorado’s famous AI Act, the one your compliance newsletter warned you about for two years, never took effect. On May 14, 2026, weeks before its start date, Governor Polis signed SB 26-189, which repealed the original law and replaced it with something narrower. The risk-management programs and impact assessments are gone. What’s left is a notice-and-transparency law aimed at automated decision-making technology (ADMT) that materially influences decisions about people: hiring, pay, housing, lending, insurance, healthcare, education. It takes effect January 1, 2027. If you run a business in Colorado, the question to answer before then is simple: does any tool in your stack materially influence a “consequential decision” about a person? This is the plain-English version of what changed and what to do about it.

What actually happened

In 2024, Colorado passed the first comprehensive state AI law in the country: SB 24-205, the “Colorado AI Act.” It required businesses deploying “high-risk” AI systems to run formal risk-management programs, conduct impact assessments, and use reasonable care to prevent algorithmic discrimination. Industry pushback was intense. The operative date was extended twice, and a federal court temporarily suspended enforcement in early 2026 following a lawsuit filed by xAI, which the U.S. Department of Justice intervened to support. Then, on May 14, 2026, Governor Polis signed SB 26-189, which repealed the original law before it ever took effect and reenacted a substantially lighter framework.

So if your mental model of “the Colorado AI law” was built on 2024–2025 coverage, discard it. The impact assessments you may have budgeted for: gone. The risk-management program mandate: gone. The duty-of-care standard for algorithmic discrimination: gone. The new law regulates something more specific, covered automated decision-making technology (covered ADMT), and mostly asks you to be transparent about it and give people a path to recourse.

Jan 1, 2027 the date SB 26-189 takes effect, along with the attorney general’s implementing rules
30 days deadline to disclose an adverse outcome that a covered ADMT materially influenced
3 yrs minimum retention period for records demonstrating compliance after a consequential decision
60 days cure period before most enforcement actions, a right that sunsets on January 1, 2030

Does this apply to your business?

The law applies to “deployers” (any person doing business in Colorado that deploys a covered ADMT) and to “developers” who build or sell those systems. There is no headcount threshold. What determines whether you’re in scope is not how big you are, but what your tools do. Two tests, in order.

Test one: is the tool an ADMT?

ADMT is technology that processes personal data and uses computation to generate output, such as predictions, recommendations, classifications, rankings, or scores, used to make, guide, or assist a decision about an individual. One nuance worth noting: unlike the old law, this definition does not require that a system make inferences from inputs. Simpler automated tools can qualify, so don’t assume something is excluded just because it isn’t “real AI.” The statute does carve out plumbing-level technology explicitly: calculators, databases, spreadsheets that require human analysis, firewalls, spam filters, spell-checkers, web hosting, and tools used solely to summarize, organize, or present information for human review.

Test two: does it materially influence a consequential decision?

The law only covers ADMT that materially influences “consequential decisions,” meaning decisions about a person’s access to, eligibility for, selection for, or compensation in the covered domains: employment, education, residential real estate, financial or lending services, insurance, healthcare services, and essential government services. “Materially influence” means the output is a non-de-minimis factor that affects the outcome, whether by constraining, ranking, scoring, recommending, or classifying. Incidental, trivial, or clerical uses don’t count. And note who counts as a “consumer” here: the definition expressly includes your employees and job applicants who are Colorado residents.

Likely in scope
  • AI resume screening or candidate ranking in your ATS
  • Tools that score or rank people in a way that affects hiring or pay
  • AI-driven tenant screening for residential real estate
  • Automated underwriting or pricing in lending or insurance
  • Systems that set differentiated pricing or terms for individuals in covered domains
Likely out of scope
  • Routine scheduling, administrative routing, and workflow management
  • Customer service triage and chatbots not configured for consequential decisions
  • Advertising, marketing, product recommendations, search, content moderation
  • Cybersecurity, fraud prevention, and identity verification tools
  • Tools that only summarize or present information for a human to review

The gray zone is HR tech. If any tool in your hiring funnel scores, ranks, filters, or recommends candidates, assume it’s in scope and check with the vendor. Most of the operational AI businesses run day to day (dispatch, forecasting, front-desk automation) sits in the categories the legislature explicitly excluded.

The four things covered businesses must do

If you’re deploying covered ADMT, the obligations starting January 1, 2027 are concrete and operational rather than documentary.

1. Tell people when ADMT is used in a decision about them

Before using a covered ADMT to materially influence a consequential decision, you must provide clear and conspicuous notice to the consumer, plus instructions for obtaining more information. A prominent public notice reasonably accessible at points of consumer interaction, such as a link proximate to the transaction, satisfies this. For hiring, that likely means the job posting or careers page. Notices must be reasonably accessible to people with disabilities and limited English proficiency.

2. Disclose adverse outcomes within 30 days

If a covered ADMT materially influenced a decision that went against someone (a rejected application, a denied or reduced opportunity, materially worse pricing or terms than similar consumers received), you have 30 days to provide a plain-language description of the decision, the role the ADMT played, a simple process to request more information about the system and its inputs, and an explanation of the person’s rights.

3. Let people correct inaccurate data

Someone who experiences an adverse outcome can request instructions for accessing and correcting factually incorrect or materially inaccurate personal data used in the decision. The law doesn’t require correcting opinions, predictions, scores, or protected evaluations. The right targets the underlying data.

4. Provide meaningful human review

People affected by an adverse ADMT decision get an opportunity for meaningful human review and reconsideration, to the extent commercially reasonable. And the statute defines “meaningful”: a trained, designated individual with actual authority to approve, modify, or override the decision, who considers primary evidence and does not simply default to the system’s output. A rubber stamp doesn’t qualify.

Plus a housekeeping duty: retain records demonstrating compliance for at least three years after the date of a consequential decision. And one mercy the original law didn’t emphasize: before most enforcement actions, the attorney general must issue a notice of violation and give you 60 days to cure. That protection doesn’t extend to knowing or repeated violations, and the cure right itself is repealed on January 1, 2030.

Your vendor contracts need attention too

Two parts of the law reach directly into your relationship with AI vendors. First, developers must give deployers formal documentation starting January 1, 2027: intended uses and known harmful or inappropriate uses, the categories of data used to train the system, known limitations, and instructions for appropriate use, monitoring, and human review, plus notice of material updates. Most vendors are not yet delivering this as a standard contractual commitment, so it’s worth negotiating into contracts now rather than at renewal.

Second, the law voids any contract clause that purports to indemnify a party for its own discriminatory acts or omissions related to using ADMT in consequential decisions. It also sets a fault-allocation framework between developers and deployers in discrimination claims: a developer is liable only to the extent its system was used as intended, documented, or contracted, while a deployer that goes off-script carries that risk itself. Standard AI vendor agreements with broad mutual indemnities may need revision before the next renewal cycle.

Questions worth asking every AI vendor this year

Does your product use automation to materially influence decisions about employment, housing, lending, insurance, healthcare, or education? Will you provide the developer documentation SB 26-189 requires (intended uses, training data categories, known limitations, and human-review instructions), and will you commit to it in the contract? How will you notify us of material updates to the system? Can your product log which decisions it influenced and surface the system name, version, and data sources we’d need for a 30-day adverse-outcome disclosure? A vendor that can’t answer these is a signal in itself.

Why this is easier — and harder — than the old law

Easier, because the paperwork burden collapsed. No risk-management program, no impact assessments, no duty-of-care standard for algorithmic discrimination. For a small or mid-sized business, that’s the difference between a compliance project and a checklist.

Harder, in one specific way: the four duties above are operational, not documentary. “Disclose adverse outcomes within 30 days” means your systems have to know which decisions AI influenced, log them, and trigger a notice. “Provide meaningful human review” means a workflow, a queue, and a trained person with real override authority. Data correction and human review are two distinct entitlements, each needing its own process. You can’t satisfy this law with a policy PDF. You satisfy it with plumbing: decision logging, notice triggers, and a review path wired into the tools you already run.

That’s the part multi-location operators should start early. A single-site shop can handle reconsideration requests informally. A twelve-location operator needs the same disclosure and review process to fire identically whether the decision happened in Denver or Colorado Springs, which is a systems design question, not a legal one.

What to do before January 1, 2027

Inventory (this quarter)

Map every tool that processes personal data to influence a decision about employment, housing, lending, insurance, healthcare, or education. Assess each one against the statutory carveouts and, if you’re in a regulated industry, the sector-specific safe harbors. Creditors following ECOA and FCRA notice processes, Colorado-regulated insurers, HIPAA-covered entities, and FERPA-covered institutions can largely satisfy the law through their existing compliance frameworks, with limited exceptions such as employment decisions. This inventory drives everything else.

Classify and fix contracts (early fall)

Sort the list into in-scope, out-of-scope, and gray, and get counsel’s read on the gray ones. Request developer documentation deliverables from vendors now, and review indemnification and liability provisions against the new allocation rules before the renewal cycle closes the window.

Build the plumbing (fall)

Decision logging, AI-interaction notices, the 30-day adverse-outcome disclosure trigger, and the human-review workflow, with separate procedures for data-correction requests and review requests. Decide who owns the 30-day clock. Design once, deploy to every location.

Train, document, and track the rulemaking (December)

Managers at each location need to know what a reconsideration request looks like and where it goes. Start the three-year record-keeping clock organized, not scrambling. And watch the attorney general’s rulemaking docket: rules due by January 1, 2027 will define disclosure content in detail, including sector-specific guidance and clarification of “materially influence.”

When you can mostly ignore this

Authority means saying who’s off the hook. If your AI is purely operational (dispatch, forecasting, routing, customer service triage, marketing), this law largely isn’t your problem, because the legislature wrote those functions out of the definition of “consequential decision” explicitly. Don’t let a compliance scare stall an automation roadmap the law was deliberately rewritten not to burden. The companies that read the reset correctly will keep automating while their competitors wait for clarity that already arrived.

Colorado didn’t kill AI regulation — it swapped a paperwork law for a plumbing law. The obligations are fewer, but they’re wired into how your systems actually behave: log the decision, notify the person, offer a human. If your stack is fragmented across locations, that’s the real compliance risk, not the AI itself.

Frequently asked questions

Do we still need impact assessments and a risk-management program?

No. SB 26-189 removed the three obligations that drove the most concern under the original 2024 law: the risk-management program mandate, the impact assessment requirement, and the duty to use reasonable care to prevent algorithmic discrimination. What replaced them is a targeted framework built around developer documentation, deployer transparency, and consumer rights. That said, compliance with SB 26-189 is not a defense to other laws. Anti-discrimination obligations under existing state and federal law still apply in full, and using an ADMT never excuses a discriminatory outcome.

What counts as an “adverse outcome”?

A decision that denies, terminates, revokes, or materially reduces or restricts someone’s access to, eligibility for, selection for, or compensation for an opportunity or service. Think a rejected job application or a denied lease. It also covers decisions that give someone materially less favorable pricing, costs, compensation, or terms than similarly situated consumers, in a way that’s reasonably likely to materially limit, delay, or effectively deny their access or opportunity.

Can someone sue you under this law?

SB 26-189 explicitly creates no new private right of action. Violations are treated as deceptive trade practices under the Colorado Consumer Protection Act and are enforced exclusively by the Colorado Attorney General. Before most enforcement actions, the AG must issue a notice of violation and allow 60 days to cure, but that protection doesn’t apply to knowing or repeated violations, and it sunsets entirely on January 1, 2030. Keep in mind the law doesn’t limit existing rights either: developers and deployers can still be held liable under state anti-discrimination law for consequential decisions materially influenced by a covered ADMT.

We’re in a regulated industry. Do we have to build all of this from scratch?

Probably not. The law includes sector-specific accommodations that were largely absent from the prior statute. Creditors providing adverse action notices under ECOA and FCRA can satisfy the post-adverse-outcome disclosure through those existing processes. Insurers subject to Colorado’s existing algorithmic-discrimination rules are deemed compliant in the practice of insurance, though not for their own employment decisions. HIPAA-covered entities are largely exempt outside employment decisions and financial-assistance determinations, and FERPA-covered institutions can rely on their existing notice, correction, and review processes. FDA-regulated medical devices and pharmaceutical R&D are excluded entirely. The threshold question for any compliance assessment is whether a safe harbor applies before you build anything new.

This article is general information, not legal advice. Scope questions under SB 26-189 should go to your counsel. But the build itself is an integration project with a statutory deadline: wiring decision logging, notice triggers, and human-review workflows into the systems you already run, consistently across every location, is exactly the kind of work we do. Want a second set of eyes on your AI stack before the January deadline? Book a call.