Colorado Rewrites Major AI Law Ahead of January 2027 Rollout

Colorado Rewrites Major AI Law Ahead of January 2027 Rollout

Updated:

August 22, 2026

Table of Contents

    Colorado’s Automated Decision-Making Technology Act has replaced the state’s 2024 artificial intelligence law with a transparency regime built on disclosure, notice and human review instead of algorithmic discrimination duties. Signed on May 14, 2026, SB 26-189 requires developers and deployers of covered automated decision-making technology to document intended uses, notify consumers before consequential decisions and explain adverse outcomes within 30 days, with Attorney General enforcement carrying civil penalties of up to $20,000 for each violation.

    Colorado SB 26-189 Replaces The Colorado AI Act
    Colorado SB 26-189 Replaces The Colorado AI Act

    What Does Colorado SB 26-189 Require Developers And Deployers To Do?

    Colorado SB 26-189 splits its obligations between the businesses that build automated decision-making technology and the businesses that use it, and both sets of duties begin on January 1, 2027.

    Developers must document intended uses, known harmful uses, training data categories, known limitations and risks, and instructions for monitoring and human oversight. They must notify deployers of material updates and retain records for three years. Because deployers rely on that documentation to meet their own duties, it functions as a procurement artifact, much as ISO/IEC 42001 has moved from a voluntary AI standard to a vendor requirement in enterprise buying reviews.

    Deployers must give clear and conspicuous notice before covered technology materially influences a consequential decision. Within 30 days of an adverse outcome they must describe the decision in plain language, explain the technology’s role, tell the consumer how to request technical details and set out their rights. Lathrop GPM noted those disclosures must also reach consumers with disabilities and limited English proficiency.

    Colorado Rewrites Major AI Law Ahead of January 2027 Rollout

    When Did Colorado SB 26-189 Replace The Colorado AI Act?

    Colorado SB 26-189 was signed on May 14, 2026, after moving through the legislature in under two weeks, and it repealed the Colorado Artificial Intelligence Act before that earlier law ever took effect.

    The bill was introduced on May 1, 2026, passed the Senate on May 7 and cleared the House on May 9, sponsored by Senators Robert Rodriguez and James Coleman and Representatives Monica Duran and Jennifer Bacon.

    The law it replaced, SB 24-205, was enacted on May 17, 2024 with an original effective date of February 1, 2026, later pushed to June 30, 2026. Skadden noted the 2024 Act was built around high-risk AI systems and algorithmic discrimination duties, a structure closer to the European approach than anything else in US state law.

    Which Decisions And Organizations Fall Under Colorado SB 26-189?

    Colorado SB 26-189 reaches businesses operating in Colorado that develop or deploy covered automated decision-making technology influencing decisions in seven domains: education, employment, housing, lending and financial services, insurance, healthcare and essential government services.

    A covered technology processes personal data and computes outputs such as predictions, recommendations, classifications, rankings or scores. A consequential decision affects a consumer’s access, eligibility, selection, compensation or pricing. The obligation attaches only when the technology materially influences that decision, which Epstein Becker Green described as a non-de minimis factor rather than an incidental use.

    There is no employee-count or revenue threshold. The exclusions are functional instead, covering spreadsheets that need human analysis, identity verification, fraud prevention, cybersecurity work, routine scheduling and conversational tools barred by policy from consequential use. Entities under HIPAA, FERPA, ECOA and FDA device rules get exemptions or safe harbours, though Greenberg Traurig noted HIPAA entities stay covered for employment and financial assistance decisions.

    What Did Colorado SB 26-189 Remove From The 2024 Law?

    Colorado SB 26-189 stripped out the compliance machinery that made the 2024 Act distinctive, keeping the disclosure duties and discarding the risk governance ones.

    Littler reported that the amendment eliminated impact assessments, risk management programs, annual tool reviews, mandatory reporting of discriminatory outcomes to the Attorney General and the requirement to tell people they were interacting with an AI system. IAPP reported that it also drops the duty of care along with the algorithmic discrimination language itself, leaving existing anti-discrimination law to carry that weight.

    Colorado moved from asking organizations to govern AI risk to asking them to explain AI decisions.

    What Enforcement And Penalties Come With Colorado SB 26-189?

    Colorado SB 26-189 is enforced exclusively by the Colorado Attorney General, who treats violations as deceptive trade practices under the Colorado Consumer Protection Act. Penalties run up to $20,000 for each violation and the law creates no private right of action.

    The Attorney General must issue a notice of violation with a 60-day cure period before acting, except where a violation is knowing or repeated. That provision sunsets on January 1, 2030, so the posture tightens three years in. A cybersecurity gap analysis can compare current notice coverage, retention records and review workflows against the statute before a cure letter arrives.

    Developer liability is bounded by documented intent. Epstein Becker Green reported that exposure is limited to uses matching what a developer documented, marketed or agreed by contract, with no joint and several liability.

    What Should Organizations Do To Comply With Colorado SB 26-189?

    The operational priority is knowing which systems touch consequential decisions about Colorado residents, and being able to prove what each system did.

    1. Inventory every system that processes personal data and feeds decisions in the seven covered domains.
    2. Classify each system by whether it materially influences the decision or merely informs it, and record the reasoning.
    3. Collect developer documentation for every third-party tool and flag vendors that have not supplied it.
    4. Deploy pre-decision notices at the point of interaction, including job postings and application flows.
    5. Build the 30-day adverse-outcome response covering the explanation, the request route and the correction path.
    6. Designate and train reviewers, and confirm they hold authority to override an outcome.
    7. Retain tool identifiers, version changelogs, notices issued and review decisions for three years.
    8. Update vendor contracts to require update notices and cooperation with consumer requests.

    What Rulemaking Is Underway Under Colorado SB 26-189?

    Colorado SB 26-189 depends on Attorney General rulemaking that is running now, and the comment window is open. The rules must be adopted before January 1, 2027, the same day the obligations attach.

    The Attorney General’s office filed proposed rules on August 11, 2026. Early comments are due September 4, a revised draft is expected by September 23, comments on that revision are due October 5 and the final deadline is October 26, 2026. The office said it will produce better rules if it receives strong, diverse input from interested persons.

    Those rules must define “materially influence” and specify the content of post-adverse-outcome disclosures. Both determine how much of an organization’s AI estate falls inside the law, which makes this the most consequential remaining chance to shape the regime. The same track covers the Chatbot Safety Act, House Bill 26-1263, signed on July 1, 2026 and also effective January 1, 2027.

    The rewrite arrived during active federal pressure on state AI regulation, and that pressure targeted the law SB 26-189 repealed.

    xAI sued Colorado on April 9, 2026, challenging the 2024 Act. The Justice Department moved to intervene on April 24, 2026, arguing the law violated the Equal Protection Clause by requiring companies to prevent unintentional disparate impact while exempting algorithms designed to advance diversity. Assistant Attorney General Brett A. Shumate said laws forcing AI models to produce false results or promote ideological bias threaten national and economic security.

    Skadden reported the repeal followed industry opposition and federal intervention, including a December 2025 executive order directing the US Attorney General to challenge state AI laws. Because SB 26-189 removed the provisions the suit attacked, the litigation’s bearing on the replacement law is unsettled in public reporting.

    How Did Industry And Privacy Advocates Respond To Colorado SB 26-189?

    Reaction split along predictable lines. Littler characterised the amendment as substantially reducing obligations on employers, while IAPP framed the change as a move from risk to transparency.

    EPIC said the bill removes many important safety and testing requirements, pointing to the loss of the duty of care, risk management programs, impact assessments and Attorney General reporting. EPIC also noted that Governor Polis had backed a proposed 10-year moratorium on state AI regulation that 40 attorneys general, including Colorado’s Phil Weiser, opposed.

    What Costs And Business Risks Follow From Colorado SB 26-189?

    Colorado SB 26-189 lowers governance cost relative to the 2024 Act while raising operational cost, because notice, explanation and human review have to work in production rather than on paper.

    The heaviest lift is the 30-day adverse-outcome response, which requires knowing which tool touched which decision, retrieving what it contributed, rendering that in plain language and routing a human with override authority, at production volume. Organizations that cannot trace a decision to a system and a version will struggle to answer.

    The wider risk is divergence. Colorado has moved away from the risk-based model shaping the EU AI Act compliance timeline, while obligations such as California’s CCPA cybersecurity audit requirements attach on different terms again. Multi-state operators must reconcile several regimes, and a structure such as AI governance under ISO/IEC 42001 can hold AI inventories, oversight records and supplier documentation in one place rather than one per jurisdiction.

    What Remains Unclear About Colorado SB 26-189?

    The largest open question is the meaning of “materially influence.” Until the rules are final, organizations cannot say with confidence which systems are covered, and those rules are not due until the day compliance begins.

    A second open issue is how the repeal interacts with the pending litigation. The provisions xAI and the Justice Department attacked no longer exist in Colorado law, but the reporting reviewed here does not establish what that means for the case or for future federal challenges.

    A third issue is what “to the extent commercially reasonable” permits. The human review right is qualified by that phrase, and neither the statute nor the reporting reviewed here defines how much cost or volume makes review unreasonable.

    How Bright Defense Helps Organizations Prepare For Colorado SB 26-189

    Bright Defense helps organizations prepare for obligations like these through Continuous Compliance. We maintain control evidence, monitor for drift and keep documentation current so that notice coverage, retention records and review decisions are provable when a regulator or a consumer asks.

    Sources Cited In This Colorado SB 26-189 Report

    1. Colorado General Assembly — SB26-189 Automated Decision-Making Technology (May 14, 2026)
    2. Colorado Attorney General — Automated Decision-Making Technology Act And Chatbot Safety Act Rulemaking (August 11, 2026)
    3. United States Department of Justice — Justice Department Intervenes In xAI Lawsuit Challenging Colorado’s Algorithmic Discrimination Law (April 24, 2026)
    4. IAPP — Amendments Move Colorado AI Act’s Focus From Risk To Transparency (May 13, 2026)
    5. Greenberg Traurig — Colorado Repeals And Replaces The Colorado AI Act (May 2026)
    6. Skadden, Arps, Slate, Meagher & Flom — Colorado Repeals And Replaces Its AI Act (June 2026)
    7. Littler — Colorado Amends Its Artificial Intelligence Law, Substantially Reducing Obligations On Employers (2026)
    8. Epstein Becker Green — Inside Colorado’s Senate Bill 26-189: Impacts And Implications For Employers (2026)
    9. Lathrop GPM — Colorado Enacts New Law Regulating Automated Decision-Making Technology (2026)
    10. Seyfarth Shaw — Colorado Enacts Artificial Intelligence Replacement Law (2026)
    11. Electronic Privacy Information Center — Colorado Legislature Again Amends Landmark AI Law (2026)

    Tamzid brings 5+ years of writing experience across SaaS, cybersecurity, compliance, and blockchain. He holds a foundational Cisco cybersecurity certification and turns complex topics into clear, practical insights.

    Get In Touch

      Group 1298 (1)-min