The Colorado AI Act you may have prepared for no longer exists. SB 26-189, signed by Governor Polis on May 14, 2026, repealed and reenacted the statute. The new effective date is January 1, 2027.
This is not a deadline extension. The obligations changed.
What was repealed
Gone from the statute entirely:
- The written impact assessment requirement
- The documented risk management program
- The duty of reasonable care
- The NIST AI RMF and ISO 42001 safe harbor (a rebuttable presumption of reasonable care under the 2024 law)
- The "substantial factor" coverage test
- The under-50-employee small business exemption
- Annual reporting to the Attorney General
If a guide still lists any of these as Colorado obligations, it is describing the repealed 2024 law.
Who is covered now
A deployer is a person doing business in Colorado that uses automated decision-making technology (ADMT) which materially influences a consequential decision affecting a Colorado consumer.
"Materially influence" is a defined term at C.R.S. 6-1-1701(13): the output must affect the outcome, for example by constraining, ranking, scoring, recommending, or classifying it. Incidental, trivial, and clerical uses do not qualify.
The enumerated domains are employment, education, housing, financial and lending services, insurance, health care, and essential government services.
Statutory exclusions. The act expressly carves out advertising, marketing, product recommendations, search, and content moderation; cybersecurity, anti-fraud, anti-money-laundering, and sanctions tools; spreadsheets requiring manual analysis without machine learning; and tools that only summarize, organize, or present information for human review.
Entity carve-outs. Insurers subject to C.R.S. 10-3-1104.9 and their affiliates are deemed in compliance in the practice of insurance. HIPAA covered entities and business associates are excluded from C.R.S. 6-1-1701 through 6-1-1706; for health-care providers that applies only when operating from a Colorado location.
No size exemption. The under-50-employee carve-out was removed and nothing replaced it.
The four duties
Effective January 1, 2027:
- Pre-use notice that an ADMT will materially influence the decision
- An adverse-decision explanation when the outcome is unfavorable
- Consumer rights to inspect and correct the personal data used, and to request human review
- Three-year recordkeeping
Liability allocation is new
SB 26-189 added C.R.S. 6-1-1707, covering algorithmic discrimination claims under existing Colorado anti-discrimination law. It allocates fault between developer and deployer with no joint and several liability, limits developer liability to cases where the deployer used the system as intended and the output materially influenced the outcome, and voids contract provisions indemnifying a party for its own anti-discrimination violations.
Check your AI vendor agreements. Indemnities covering a party's own violations are unenforceable by statute.
Enforcement
Violations are deceptive trade practices under the Colorado Consumer Protection Act, enforced exclusively by the Attorney General, up to $20,000 per violation. No private right of action. Where the AG deems a cure possible it must give 60 days' notice and an opportunity to cure; that provision does not apply to knowing or repeated violations and sunsets January 1, 2030.
Enforcement is currently stayed, including for the new law. The April 27, 2026 order in *xAI v. Weiser* bars the AG from enforcing the Act "or any legislation replacing or amending it enacted this session," until 14 days after the court rules on a preliminary injunction motion that is not due until 28 days after the AG finishes rulemaking. The DOJ has intervened.
Rulemaking is unfinished. The AG must adopt rules by January 1, 2027. The pre-rulemaking comment window closed July 13, 2026 and no proposed rules have issued.
What to do
- Re-scope your inventory against "materially influences" and the statutory exclusions. Many systems previously in scope are not.
- If you are an insurer or a HIPAA entity, check the carve-outs first.
- Build the disclosure plumbing: notice, adverse-decision explanation, data inspection and correction, human review, three-year retention.
- Review vendor contracts against C.R.S. 6-1-1707.
- Stop describing NIST alignment as a Colorado safe harbor.
Resources
Regulations in this article
Regulome editors
The editorial desk covers AI and cyber regulation across the US, EU, and UK. Corrections and tips: editors@regulome.io
Not legal advice
This article is for information only. Consult qualified counsel before making compliance decisions. Run the free checker
