Skip to main content
Regulome
Search the register
For ProvidersRun the free checker

Colorado AI Act vs. EU AI Act

Colorado rewrote its AI law in May 2026 and the EU deferred its high-risk deadlines in July 2026. Where the two regimes stand today: scope, duties, penalties, and dates.

SB 26-189

Colorado AI Act

Enacted
  • Repealed and reenacted the 2024 law (SB 24-205) on May 14, 2026
  • Covers ADMT that makes or materially influences consequential decisions
  • Pre-use notice, adverse-decision explanation, human-review right, three-year records
  • AG enforcement only; max penalty $20,000 per violation
  • Effective January 1, 2027
Reg. 2024/1689

EU AI Act

In force
  • Risk-based: four tiers from prohibited to minimal risk
  • Conformity assessment, CE marking, and EU database registration for high-risk AI
  • Generally applicable since August 2, 2026; amended by Regulation (EU) 2026/1744
  • Max penalty €35M or 7% of global turnover
  • Annex III high-risk from December 2, 2027

Detailed comparison

AttributeColorado AI Act (SB 26-189)EU AI Act (Reg. 2024/1689)
JurisdictionUS, Colorado (consumers)European Union (27 member states)
Legal basisSB 26-189, signed May 14, 2026; repealed and reenacted SB 24-205Regulation (EU) 2024/1689, in force August 1, 2024; amended by Regulation (EU) 2026/1744
Core approachDisclosure-and-rights regime for automated decision-making technology (ADMT)Risk-based conformity requirements with CE marking
Coverage triggerADMT that makes, or materially influences, a consequential decision affecting a Colorado consumerFour risk tiers: unacceptable, high, limited, minimal
Covered domainsEmployment, education, housing, lending, insurance, health care, essential government services. Insurers under C.R.S. 10-3-1104.9 and HIPAA covered entities are carved outAnnex I (safety components in regulated products) and Annex III (standalone high-risk uses)
Prohibited AINone. The law sets disclosure duties and consumer rights, not bansYes. Eight practices banned since February 2, 2025; a ninth (nudification and CSAM tools) applies from December 2, 2026
Who bears obligationsDeployers and developers, with statutory fault allocation between themProviders and deployers; the provider is the primary duty-holder
Pre-deployment dutiesPre-use notice to consumers. SB 26-189 removed the impact assessment and risk-program requirementsConformity assessment and technical documentation for high-risk systems (providers)
Consumer rightsAdverse-decision explanation, data inspection and correction, and a right to request human reviewTransparency notices (Article 50, in force since August 2, 2026); human oversight is built into high-risk system design
Max penalty$20,000 per violation€35 million or 7% of global annual turnover (prohibited-practice violations)
Private right of actionNo. Attorney General enforcement only, with a conditional 60-day cure until January 1, 2030No. National market surveillance authorities and the European AI Office enforce
Key datesJanuary 1, 2027General application since August 2, 2026; Annex III high-risk from December 2, 2027; Annex I embedded from August 2, 2028
GPAI / foundation modelsNot specifically addressedDedicated GPAI chapter; obligations have applied since August 2, 2025
Reach beyond the jurisdictionYes, for any entity doing business in Colorado whose ADMT affects Colorado consumersYes, for any entity placing AI on the EU market or whose AI output is used in the EU

Where they align

  • Similar domain scope: Both cover employment, lending, housing, education, insurance, and health care as priority areas
  • Duties along the supply chain: Both place obligations on the organizations that build AI systems as well as those that deploy them
  • Public enforcement: Neither law creates a private right of action; the Colorado AG and EU market surveillance authorities enforce
  • Human involvement: Both require a human in the loop for important decisions, through Colorado's human-review right and the EU's oversight requirements
  • Deadlines still ahead: Colorado applies from January 1, 2027; the EU's Annex III high-risk obligations apply from December 2, 2027

Where they differ

  • No prohibitions in Colorado: The EU bans nine AI practices outright. Colorado prohibits nothing; it requires notice and rights handling
  • Conformity vs. disclosure: The EU requires formal conformity assessment and CE marking for high-risk AI. SB 26-189 dropped Colorado's risk-management framework in favor of consumer disclosures
  • Penalty magnitude: EU fines (up to 7% of global turnover) are orders of magnitude larger than Colorado's $20,000 per violation
  • GPAI coverage: The EU AI Act regulates general-purpose AI models directly. Colorado does not address foundation models
  • Individual appeal: Colorado grants consumers an explicit right to request human review of a consequential decision. The EU mandates oversight in system design, not an individual appeal right

Complying with both

The two regimes no longer mirror each other. SB 26-189 replaced Colorado's risk-management framework with a narrower disclosure-and-rights regime, so EU documentation does not by itself produce Colorado's consumer-facing notices. A workable sequence:

1

Classify once

Map each AI system against EU Annex III and Colorado's consequential-decision domains at the same time. The domain overlap is large.

2

Build the EU baseline

Conformity documentation, logging, and human oversight cover the heaviest engineering work and most of the shared substance.

3

Add the Colorado layer

Pre-use notices, adverse-decision explanations, data correction and human-review request handling, and three-year records.