The written impact assessment was the most operational requirement in the 2024 Colorado AI Act, and the single biggest line item in most compliance programs built for it.
It is not in the law any more.
What changed
SB 26-189, signed May 14, 2026, repealed and reenacted the Colorado AI Act rather than amending it. The reenacted statute, effective January 1, 2027, contains no impact assessment requirement. It also drops the documented risk management program, the duty of reasonable care, and the NIST/ISO 42001 safe harbor.
If a checklist still tells you to complete an annual impact assessment under Colorado law, it is describing a statute that was repealed.
What replaced it
A narrower disclosure-and-rights regime with four operative duties:
- Pre-use notice when an ADMT will materially influence a consequential decision
- An adverse-decision explanation when the outcome is unfavorable
- Consumer rights to inspect and correct the personal data used, and to request human review
- Three-year recordkeeping
The coverage test changed too. The standard is whether the technology materially influences the decision, a defined term at C.R.S. 6-1-1701(13): the output must affect the outcome by constraining, ranking, scoring, recommending, or classifying it. Incidental, trivial, and clerical uses do not count. The 2024 law’s "substantial factor" test is gone.
Was the work wasted?
Mostly not, if you repurpose it deliberately.
Still useful: the AI inventory, the record of which systems touch which decisions, the demographic testing data, and the documentation of what data each system uses. That last one maps directly onto the new consumer right to inspect and correct personal data, which you cannot service without knowing what data went in.
No longer a Colorado obligation: the assessment document itself, the annual refresh cycle, the 90-day review after material changes, and the framing of the whole exercise as evidence of reasonable care.
Still required elsewhere: if you operate in the EU, the Fundamental Rights Impact Assessment under the EU AI Act is a live obligation and unaffected by anything Colorado did. ISO 42001 also has its own AI system impact assessment. Do not delete the work on the strength of a Colorado change.
What to do instead
- Re-scope your inventory against "materially influences" and screen out the statutory exclusions. The reenacted act expressly excludes advertising, marketing, product recommendations, search, and content moderation; cybersecurity, anti-fraud, anti-money-laundering, and sanctions tools; spreadsheets without machine learning; and tools that only summarize or organize information for human review. Many systems previously in scope are not.
- Check the entity carve-outs before anything else. Insurers subject to C.R.S. 10-3-1104.9 are deemed compliant in the practice of insurance, and HIPAA covered entities and business associates are excluded from C.R.S. 6-1-1701 through 6-1-1706.
- Note that the under-50-employee exemption was removed, with nothing replacing it. Small employers previously outside the law are inside this one.
- Build the disclosure plumbing. That is the actual January 1, 2027 deliverable.
Full analysis with primary citations is on the Colorado AI Act page, and the free checklist is built from the enrolled text.
Regulations in this article
Regulome editors
The editorial desk covers AI and cyber regulation across the US, EU, and UK. Corrections and tips: editors@regulome.io
Not legal advice
This article is for information only. Consult qualified counsel before making compliance decisions. Run the free checker
