If you are here because you read that aligning to the NIST AI Risk Management Framework gives you a safe harbor under Colorado law, that was true. It is not true now.
What the safe harbor was
Under the 2024 Colorado AI Act (SB 24-205), a deployer or developer that maintained a program aligned to the NIST AI RMF, or an equivalent such as ISO/IEC 42001, could claim a rebuttable presumption that it had used reasonable care to protect consumers from algorithmic discrimination. In practice that functioned as an affirmative defense: the burden shifted, and a documented NIST-aligned program was the thing you pointed at.
It was one of the most-discussed provisions in the statute, and it drove a lot of 2025 and 2026 program spending.
What happened
SB 26-189, signed by Governor Polis on May 14, 2026, did not amend the Colorado AI Act. It repealed and reenacted it. The safe harbor was not carried forward.
Two things ended at once:
- The presumption is gone. No provision in the reenacted statute gives NIST, ISO 42001, or any other framework a defensive effect.
- The duty it defended against is also gone. The reenacted law contains no duty of reasonable care. With nothing to defend, there is nothing for a presumption to attach to.
Colorado law now contains no safe harbor and no codified affirmative defense.
What the law asks for instead
The reenacted statute is a disclosure-and-rights regime, effective January 1,
- Four operative duties:
- Pre-use notice when an automated decision-making technology (ADMT) will materially influence a consequential decision
- An explanation when the decision is adverse
- Consumer rights to inspect and correct the personal data used, and to request human review
- Three-year recordkeeping
None of these are satisfied by having a governance framework. They are implementation work: notices, explanation text, a data correction path, a human review path, and retention.
Should you abandon your NIST program?
No, but be clear about why you are keeping it.
NIST AI RMF and ISO 42001 remain good documentation backbones. They give you an AI inventory, a risk register, and an evidence trail, all of which make the new disclosure duties easier to implement and easier to prove. Texas TRAIGA does still provide a NIST-based safe harbor, and ISO 42001 certification carries weight in enterprise procurement.
What has to change is how you describe it. A NIST-aligned program is governance. Under Colorado law it is not a defense, and policies, client advice, or marketing that say otherwise are describing a repealed statute.
What to check this week
- Search your policies, client alerts, and marketing pages for "safe harbor" in a Colorado context. Fix what you find.
- If a vendor is selling you NIST or ISO 42001 alignment on the strength of Colorado protection, ask them which section of the enrolled act they are relying on.
- Re-scope against the new coverage test. The standard is now whether an ADMT materially influences a consequential decision, a defined term at C.R.S. 6-1-1701(13). The 2024 law’s "substantial factor" language appears nowhere in the enrolled act.
Full analysis with primary citations is on the Colorado AI Act page, and the free checklist is built from the enrolled text.
Regulations in this article
Regulome editors
The editorial desk covers AI and cyber regulation across the US, EU, and UK. Corrections and tips: editors@regulome.io
Not legal advice
This article is for information only. Consult qualified counsel before making compliance decisions. Run the free checker
