The Colorado AI Act takes effect January 1, 2027. Before you work through any checklist, know that the statute was repealed and reenacted by SB 26-189, signed May 14, 2026. Checklists written for the 2024 law send you after obligations that no longer exist.
This one is built from the enrolled text.
What the rewrite removed
- Written impact assessments
- The documented risk management program
- The duty of reasonable care
- The NIST AI RMF / ISO 42001 safe harbor
- The "substantial factor" coverage test
- The under-50-employee exemption
- Annual reporting to the AG
Who must comply
You are a deployer if you do business in Colorado and use automated decision-making technology (ADMT) that materially influences a consequential decision affecting a Colorado consumer.
"Materially influence" is defined at C.R.S. 6-1-1701(13): the output must affect the outcome, by constraining, ranking, scoring, recommending, or classifying. Incidental, trivial, and clerical uses are out.
Covered domains: employment, education, housing, financial and lending services, insurance, health care, and essential government services. The 2024 law's reference to categories such as legal services was not carried forward.
Developers that build or substantially modify covered ADMT have narrower duties, mainly documentation and disclosure to deployers.
There is no small-business exemption. The under-50-employee carve-out was removed with nothing replacing it.
Phase 1: Scope (start here)
- [ ] Inventory every automated system that touches a decision about an individual
- [ ] For each, ask whether it *materially influences* the outcome, using the statutory definition rather than a general sense of "involved"
- [ ] Screen out statutory exclusions: advertising, marketing, product recommendations, search, content moderation; cybersecurity, anti-fraud, AML, and sanctions tools; spreadsheets without ML; tools that only summarize or organize information for human review
- [ ] Confirm the decision falls in one of the seven enumerated domains
- [ ] Confirm affected individuals are Colorado consumers
- [ ] Check the entity carve-outs before going further. Insurers subject to C.R.S. 10-3-1104.9 are deemed compliant in the practice of insurance; HIPAA covered entities and business associates are excluded from C.R.S. 6-1-1701 through 6-1-1706
- [ ] Document your covered / not covered determination and the reasoning
Phase 2: Vendor and contract review
- [ ] Request from each vendor: system purpose, the data it uses, how outputs are generated, and what they will supply to support your disclosure duties
- [ ] Confirm you can obtain the personal data a consumer is entitled to inspect and correct. You cannot service that right without it
- [ ] Review indemnity clauses against C.R.S. 6-1-1707. Provisions indemnifying a party for its own anti-discrimination violations are void by statute
- [ ] Note that fault is allocated between developer and deployer with no joint and several liability
Phase 3: Build the disclosures
- [ ] Draft pre-use notice: plain language, delivered before the ADMT materially influences the decision
- [ ] Draft the adverse-decision explanation for unfavorable outcomes
- [ ] Build the path for a consumer to inspect the personal data used
- [ ] Build the path to correct inaccurate personal data
- [ ] Build the path to request human review
- [ ] Have counsel review the templates
- [ ] Implement delivery in the systems that make the decisions
Phase 4: Records and ownership
- [ ] Set up three-year retention for the records the statute requires
- [ ] Assign an owner for each covered system
- [ ] Train the teams that operate these systems on the disclosure duties
- [ ] Assign someone to track the AG's rulemaking, due January 1, 2027, and the *xAI v. Weiser* docket
Key definitions
ADMT: automated decision-making technology that materially influences a consequential decision. Note this is not the 2024 law's "high-risk AI system."
Materially influences (C.R.S. 6-1-1701(13)): the output affects the outcome, for example by constraining, ranking, scoring, recommending, or classifying.
Consequential decision: a decision with a material legal or similarly significant effect on access to, or the terms of, one of the seven enumerated domains.
Deployer: a person doing business in Colorado that deploys covered ADMT.
Penalties
| Item | Detail |
|---|---|
| Maximum civil penalty | $20,000 per violation |
| Enforcement | Colorado Attorney General, exclusive |
| Private right of action | None |
| Cure period | 60 days, only if the AG deems a cure possible; not for knowing or repeated violations; sunsets January 1, 2030 |
| Safe harbor | None. The NIST/ISO presumption was repealed |
| Current status | Enforcement stayed under *xAI v. Weiser*, including for the reenacted law |
Frequently asked questions
Does this apply if we are not based in Colorado?
The statute defines a deployer as a person doing business in Colorado. You do not need to be headquartered there, but you do need to be doing business there. Affecting a Colorado resident with no business presence in the state is not by itself the test.
Our vendor says they are compliant. Does that cover us?
No. Deployer duties are yours. Vendor documentation helps you build notices and service data-inspection requests, but the disclosure obligations sit with you. Note also that C.R.S. 6-1-1707 voids indemnities for a party's own anti-discrimination violations, so contractual risk transfer is narrower than it may appear.
What if a human makes the final decision?
Human involvement does not automatically remove you from scope. The test is whether the ADMT output materially influenced the outcome by constraining, ranking, scoring, recommending, or classifying. A human approving a machine-produced ranking is generally still covered.
Are small businesses exempt?
No. The 2024 law's under-50-employee exemption was removed and nothing replaced it.
Do we still need our NIST program?
Not as a Colorado defense; that presumption was repealed. It remains useful governance, it is still a safe harbor under Texas TRAIGA, and ISO 42001 carries weight in procurement.
How regulome.io can help
Not sure whether the law applies to you? Free compliance checker
Need the full picture? Colorado AI Act analysis and the free checklist
Need a bias auditor or governance consultant? Browse the register
Regulations in this article
Regulome editors
The editorial desk covers AI and cyber regulation across the US, EU, and UK. Corrections and tips: editors@regulome.io
Not legal advice
This article is for information only. Consult qualified counsel before making compliance decisions. Run the free checker
