Skip to main content
Regulome
Search the register
For ProvidersRun the free checker

How to Prepare for the Colorado AI Act After the SB 26-189 Rewrite

The statute was repealed and reenacted in May 2026. Preparation built for the 2024 law targets obligations that no longer exist. Five steps for the law as it stands.

Regulome editors8 min read

Read this first: SB 26-189, signed May 14, 2026, repealed and reenacted the Colorado AI Act. The effective date moved to January 1, 2027, and the obligations changed. Preparation built for the 2024 law aims at duties that no longer exist.

Step 1: Confirm you are actually covered

The coverage test changed. It is no longer whether a system is a "substantial factor" in a decision. It is whether automated decision-making technology (ADMT) materially influences a consequential decision, defined at C.R.S. 6-1-1701(13) as an output that affects the outcome by constraining, ranking, scoring, recommending, or classifying. Incidental, trivial, and clerical uses do not count.

You must also be doing business in Colorado, and the decision must fall in one of seven domains: employment, education, housing, financial and lending services, insurance, health care, or essential government services.

Check the exclusions before anything else. The act carves out advertising, marketing, product recommendations, search, and content moderation; cybersecurity, anti-fraud, AML, and sanctions tools; spreadsheets without machine learning; and tools that only summarize or organize information for human review. Insurers under C.R.S. 10-3-1104.9 are deemed compliant in the practice of insurance, and HIPAA covered entities and business associates are excluded from C.R.S. 6-1-1701 through 6-1-1706.

Note that the under-50-employee exemption is gone, with no replacement.

Step 2: Re-scope your inventory

If you built an inventory for the 2024 law, do not assume it carries over. Systems classified as "high-risk" under the old standard may fall outside "materially influences," and the exclusions remove more than most teams expect.

Keep the record of which data each system uses. You will need it for Step 3.

Step 3: Build the four disclosures

These are the actual obligations, effective January 1, 2027:

  1. Pre-use notice that an ADMT will materially influence the decision
  2. An adverse-decision explanation when the outcome is unfavorable
  3. Consumer rights to inspect and correct the personal data used, and to request human review
  4. Three-year recordkeeping

There is no impact assessment, no risk management program, and no reasonable-care duty in the reenacted statute. This is implementation work, not a governance programme.

Step 4: Review your vendor contracts

SB 26-189 added C.R.S. 6-1-1707. It allocates fault between developer and deployer with no joint and several liability, limits developer liability to cases where the deployer used the system as intended and the output materially influenced the outcome, and voids any provision indemnifying a party for its own violations of anti-discrimination law.

Indemnities negotiated on the assumption that risk could be pushed to the vendor need re-reading.

Step 5: Assign someone to watch two things

The AG's rulemaking, due January 1, 2027. The pre-rulemaking comment window closed July 13, 2026; formal proposed rules have not issued. The operational detail of the disclosure mechanics is not settled.

The *xAI v. Weiser* docket. The April 27, 2026 order bars the AG from enforcing the Act "or any legislation replacing or amending it enacted this session," which covers SB 26-189. It runs until 14 days after the court rules on a preliminary injunction motion not due until 28 days after rulemaking completes. The DOJ has intervened.

What if you miss the date?

Violations are deceptive trade practices under the Colorado Consumer Protection Act, enforced exclusively by the AG, up to $20,000 per violation. There is no private right of action. A 60-day cure applies only where the AG deems a cure possible, does not cover knowing or repeated violations, and sunsets January 1, 2030.

The stay is litigation-driven and could lift. The effective date stands regardless.

Resources

Regulations in this article

Colorado AI ActPreparationSB 26-189January 2027

Regulome editors

The editorial desk covers AI and cyber regulation across the US, EU, and UK. Corrections and tips: editors@regulome.io

Not legal advice

This article is for information only. Consult qualified counsel before making compliance decisions. Run the free checker

The weekly digest

Regulation changes, deadlines ahead, and enforcement news from the register. Free, unsubscribe anytime.