SB 26-189
Colorado AI Act
Enacted- Repealed and reenacted the 2024 law (SB 24-205) on May 14, 2026
- Covers ADMT that makes or materially influences consequential decisions
- Pre-use notice, adverse-decision explanation, human-review right, three-year records
- AG enforcement only; max penalty $20,000 per violation
- Effective January 1, 2027
Reg. 2024/1689
EU AI Act
In force- Risk-based: four tiers from prohibited to minimal risk
- Conformity assessment, CE marking, and EU database registration for high-risk AI
- Generally applicable since August 2, 2026; amended by Regulation (EU) 2026/1744
- Max penalty €35M or 7% of global turnover
- Annex III high-risk from December 2, 2027
Detailed comparison
| Attribute | Colorado AI Act (SB 26-189) | EU AI Act (Reg. 2024/1689) |
|---|---|---|
| Jurisdiction | US, Colorado (consumers) | European Union (27 member states) |
| Legal basis | SB 26-189, signed May 14, 2026; repealed and reenacted SB 24-205 | Regulation (EU) 2024/1689, in force August 1, 2024; amended by Regulation (EU) 2026/1744 |
| Core approach | Disclosure-and-rights regime for automated decision-making technology (ADMT) | Risk-based conformity requirements with CE marking |
| Coverage trigger | ADMT that makes, or materially influences, a consequential decision affecting a Colorado consumer | Four risk tiers: unacceptable, high, limited, minimal |
| Covered domains | Employment, education, housing, lending, insurance, health care, essential government services. Insurers under C.R.S. 10-3-1104.9 and HIPAA covered entities are carved out | Annex I (safety components in regulated products) and Annex III (standalone high-risk uses) |
| Prohibited AI | None. The law sets disclosure duties and consumer rights, not bans | Yes. Eight practices banned since February 2, 2025; a ninth (nudification and CSAM tools) applies from December 2, 2026 |
| Who bears obligations | Deployers and developers, with statutory fault allocation between them | Providers and deployers; the provider is the primary duty-holder |
| Pre-deployment duties | Pre-use notice to consumers. SB 26-189 removed the impact assessment and risk-program requirements | Conformity assessment and technical documentation for high-risk systems (providers) |
| Consumer rights | Adverse-decision explanation, data inspection and correction, and a right to request human review | Transparency notices (Article 50, in force since August 2, 2026); human oversight is built into high-risk system design |
| Max penalty | $20,000 per violation | €35 million or 7% of global annual turnover (prohibited-practice violations) |
| Private right of action | No. Attorney General enforcement only, with a conditional 60-day cure until January 1, 2030 | No. National market surveillance authorities and the European AI Office enforce |
| Key dates | January 1, 2027 | General application since August 2, 2026; Annex III high-risk from December 2, 2027; Annex I embedded from August 2, 2028 |
| GPAI / foundation models | Not specifically addressed | Dedicated GPAI chapter; obligations have applied since August 2, 2025 |
| Reach beyond the jurisdiction | Yes, for any entity doing business in Colorado whose ADMT affects Colorado consumers | Yes, for any entity placing AI on the EU market or whose AI output is used in the EU |
Where they align
- Similar domain scope: Both cover employment, lending, housing, education, insurance, and health care as priority areas
- Duties along the supply chain: Both place obligations on the organizations that build AI systems as well as those that deploy them
- Public enforcement: Neither law creates a private right of action; the Colorado AG and EU market surveillance authorities enforce
- Human involvement: Both require a human in the loop for important decisions, through Colorado's human-review right and the EU's oversight requirements
- Deadlines still ahead: Colorado applies from January 1, 2027; the EU's Annex III high-risk obligations apply from December 2, 2027
Where they differ
- No prohibitions in Colorado: The EU bans nine AI practices outright. Colorado prohibits nothing; it requires notice and rights handling
- Conformity vs. disclosure: The EU requires formal conformity assessment and CE marking for high-risk AI. SB 26-189 dropped Colorado's risk-management framework in favor of consumer disclosures
- Penalty magnitude: EU fines (up to 7% of global turnover) are orders of magnitude larger than Colorado's $20,000 per violation
- GPAI coverage: The EU AI Act regulates general-purpose AI models directly. Colorado does not address foundation models
- Individual appeal: Colorado grants consumers an explicit right to request human review of a consequential decision. The EU mandates oversight in system design, not an individual appeal right
Complying with both
The two regimes no longer mirror each other. SB 26-189 replaced Colorado's risk-management framework with a narrower disclosure-and-rights regime, so EU documentation does not by itself produce Colorado's consumer-facing notices. A workable sequence:
1
Classify once
Map each AI system against EU Annex III and Colorado's consequential-decision domains at the same time. The domain overlap is large.
2
Build the EU baseline
Conformity documentation, logging, and human oversight cover the heaviest engineering work and most of the shared substance.
3
Add the Colorado layer
Pre-use notices, adverse-decision explanations, data correction and human-review request handling, and three-year records.