Skip to content
    August 23, 2026| Top Floor Team| 12 min read

    Colorado's New AI Law: What SB 26-189 Requires

    Colorado replaced its landmark 2024 AI Act roughly seven weeks before that law's obligations were due to take effect. SB 25B-004 had already pushed SB 24-205's requirements out to June 30, 2026; Senate Bill 26-189, signed by the governor on May 14, 2026 and effective January 1, 2027, repeals and reenacts the artificial intelligence provisions of SB 24-205 with a narrower regime built around automated decision-making technology that materially influences a consequential decision. The obligations that dominated every 2024 and 2025 explainer are gone: Crowell and Moring records that the new law removes the risk management program requirement, the algorithmic impact assessments and the duty to prevent algorithmic discrimination, replacing them with notice, explanation, correction and human-review duties, three-year record retention, and Attorney General enforcement with a 60-day cure period that does not apply to knowing or repeated violations and itself sunsets on January 1, 2030. The practical consequence is uncomfortable: most of what is currently indexed about "the Colorado AI Act" describes a law that no longer exists, so an assistant asked what Colorado requires will frequently answer with the repealed version.

    Below: what changed and what survived, who is actually covered, what deployers and developers owe, where the Attorney General rulemaking still decides the details, and what to do with a compliance plan built for the old law.

    Key takeaways

    • SB 26-189 was signed May 14, 2026 and takes effect January 1, 2027. It repeals and reenacts the 2024 AI Act rather than amending it.
    • Gone: the risk management program, the algorithmic impact assessment, and the duty of reasonable care against algorithmic discrimination.
    • In: pre-use notice, a plain-language explanation within 30 days of an adverse outcome, a right to correct inaccurate personal data, meaningful human review, and three-year records.
    • Enforcement sits with the Attorney General under the Colorado Consumer Protection Act. No private right of action.
    • The rules are not final. The AG filed draft rules on August 11, 2026 with comments open through October 26, 2026, which is the last cheap moment to influence them.

    What was repealed, and why it matters that it was repealed rather than amended

    SB 24-205 was written around a duty of care, and its obligations never took effect: SB 25B-004, signed August 28, 2025, moved them to June 30, 2026, and the repeal arrived first. Developers and deployers of high-risk AI systems were to use reasonable care to protect consumers from algorithmic discrimination, deployers were to implement a risk management program and complete impact assessments, and the whole structure assumed a compliance function that produced documents.

    That structure is not softened in the new law. It is deleted. Crowell and Moring's analysis of SB 26-189 lists the removals explicitly: risk management programs, impact assessments and the duty to prevent algorithmic discrimination. Davis Wright Tremaine describes the replacement as a transparency regime rather than a risk-management one, and the difference is not cosmetic. Under the old law your obligation was to have managed the risk. Under the new one your obligation is to tell people the technology was used, explain what it did when the outcome went against them, let them correct the data, and give them a human.

    Repeal-and-reenact also matters for a reason nobody enjoys: it means the citations in your existing memo are dead. A policy that cross-references SB 24-205 section numbers is pointing at repealed text, and that is the kind of error that surfaces in the worst possible setting.

    One thing to watch rather than assume. Davis Wright Tremaine notes the effective date is subject to pending x.AI injunction litigation. Treat January 1, 2027 as the planning date and check the docket before you rely on it in a customer commitment.

    Who is actually covered

    Broader than most people expect on one axis and narrower on another.

    Broader: Davis Wright Tremaine's reading is that the statute applies to any entity doing business in Colorado that develops or deploys covered automated decision-making technology, with no employee-count or revenue threshold. There is no small-business carve-out to hide in.

    Narrower: the technology definition has real edges. ADMT is technology that processes personal data and uses computation to generate output, including predictions, recommendations and rankings, used to make, guide or assist a decision, and the statute explicitly excludes things like antivirus software, spreadsheets, calculators and spell-checkers. The output must materially influence the decision, which the statute frames as being a non-de minimis factor that affects the outcome, excluding incidental, trivial or clerical uses.

    And the decision has to be a consequential one. Davis Wright Tremaine lists the domains: education enrollment or opportunity, employment or employment opportunity, financial or lending services, insurance, health care services, and essential government services and public benefits. Also covered are decisions producing differentiated prices, compensation or other material terms that could materially limit, delay, effectively deny or fundamentally alter access to those domains.

    Read those three filters together and the scoping question becomes concrete rather than philosophical. A resume-ranking tool that produces the shortlist a recruiter works from is in. A model that predicts churn so marketing can send a discount is almost certainly out. A pricing system that quietly offers different terms to different consumers in a covered domain is the interesting case, and it is the one worth having a written answer for.

    What deployers owe

    Four duties, from January 1, 2027.

    Pre-use notice. Clear and conspicuous notice that ADMT is being used, delivered before the decision, through prominent public notices at the points where consumers interact with you. This is the duty that most resembles existing privacy-notice practice and it is the cheapest to implement.

    Adverse-outcome explanation, within 30 days. When the outcome goes against the consumer, a plain-language statement of the decision, the role the technology played in it, how to request further information, and what rights they have. Thirty days is a real operational commitment: it needs a trigger, a template and someone whose job it is.

    Correction. Consumers can access and request correction of factually inaccurate personal data used by the system. If your model consumes data from a source you do not control, the mechanics of correcting it are the part to work out now rather than in December 2026.

    Meaningful human review. A right to human reconsideration following an adverse decision, which the statute qualifies as being owed to the extent commercially reasonable. That qualifier will do a lot of work and it is one of the things the rulemaking may sharpen.

    Records. At least three years of compliance records. Both Crowell and Moring and Davis Wright Tremaine state the same period, and it applies to developers as well.

    What developers owe

    Developers of covered ADMT have to hand deployers the documentation the deployers need to meet their own duties: intended uses, known inappropriate or harmful uses, categories of personal data used in training, known limitations and risks, instructions for appropriate use and human review, and the information the deployer needs to build its consumer disclosures. Material updates that affect performance have to be notified within a reasonable time, and the same three-year retention applies.

    If you sell software into a covered domain, this is the clause that reaches you even if you never make a decision about a Colorado consumer yourself. It is also the clause your customers will start asking about in procurement well before the effective date, which is the real reason to read it in 2026 rather than 2027.

    The rules are not written yet, and that is the opportunity

    This is the part with a date on it, and it is why this article exists in August rather than December.

    The Colorado Attorney General has exclusive enforcement authority, and the ADMT Act requires that office to adopt rules clarifying the disclosure requirements before January 1, 2027, which the Attorney General's AI page states as a statutory deadline rather than a promise about timing. That page records that draft rules were filed on August 11, 2026, with a public comment period running from August 11 through October 26, 2026, an early comment deadline of September 4, 2026 for a revised draft, and a further deadline of October 5, 2026 ahead of hearing revisions.

    Two things follow. First, anything you read that states the mechanics of Colorado compliance with confidence today is describing statutory text plus an assumption about rules that do not exist yet. Second, if the definitions in the draft rules would be expensive for your business, the comment period is open now and closes in October. Commenting is free and the window does not reopen.

    What to do with a compliance plan built for the old law

    Most of the work is not wasted, and it is worth being precise about which parts survive.

    The system inventory survives entirely. Knowing which systems make or influence decisions, what data they use and who owns them is the input to every duty in the new law, and it was the input to every duty in the old one. If you built it, keep it current; building an AI system inventory covers what belongs in it.

    The impact assessments survive as evidence rather than as obligation. You no longer owe them under Colorado law, but the analysis inside them, what the system does, to whom, and what happens when it is wrong, is exactly what you need to write the adverse-outcome explanation. Keep them; stop treating them as a filing requirement.

    What does not survive is the framing. A program that told your board Colorado required a risk management program now needs to tell the board Colorado requires notice, explanation, correction and human review, and that the record-keeping horizon is three years. Those are different operational commitments landing on different teams: product and support rather than compliance.

    And a broader point worth stating. Colorado is one regime among several, and the direction of US state law on automated decision-making is toward opt-out rights and assessment duties attached to privacy statutes rather than standalone AI acts. The US State Privacy Laws guide covers that landscape, and if you have EU exposure the classification exercise in Understanding the EU AI Act is a separate question with a separate answer.

    Where this does not apply to you

    Three honest disclaimers, because the scoping filters do real work.

    If nothing you build or deploy touches education, employment, lending, insurance, health care, or essential government services and benefits, and you do not differentiate material terms in those domains, this law does not reach you. Plenty of vendors will tell you every company needs an AI compliance program in 2027. Read the consequential-decision list before you believe it.

    If your AI is genuinely assistive, drafting text a human writes from and never producing an output that is a non-de minimis factor in a covered decision, the material-influence filter is your answer, and the thing to do is write down why in one paragraph and keep it. That paragraph is cheaper than a program and it is what you will want if anyone asks.

    And this is not legal advice. We are a security and compliance consultancy, not a law firm, and the mechanics above come from the bill page, the Attorney General's own rulemaking page and two law-firm analyses. A Colorado-specific applicability question in a regulated domain belongs with counsel, and the rules that will decide several of the details are still in draft.

    Where Top Floor fits

    The Colorado duties are operational rather than legal once the scoping is settled: knowing which systems are in scope, producing the notice, standing up the 30-day explanation path, and keeping three years of records that someone can actually retrieve. That is NIST AI RMF territory, because the inventory, the documented intended purpose and the human-oversight design that the framework asks for are the same artifacts the statute now demands.

    Where the question spans several state regimes at once, our global privacy practice handles the mapping so you build one control set rather than one per state. Where the constraint is that nobody senior owns any of this, a vCISO engagement is the smaller answer, and it is usually the right one below a few hundred people.

    How to decide this week

    • Check whether any system you build or deploy influences a decision in education, employment, lending, insurance, health care, or government benefits. If none does, write down why and stop.
    • If one does, read the draft rules on the Attorney General's page and note the October 26, 2026 comment deadline. Commenting is free.
    • Find your existing SB 24-205 memo and mark it superseded before someone acts on it.
    • Draft the adverse-outcome explanation template now. Thirty days is short once a decision actually goes against someone.
    • Confirm your record retention covers three years for the decisions in scope, and that retrieval is possible rather than theoretical.

    Frequently asked questions

    Is the Colorado AI Act still in effect?

    Not as enacted in 2024. Senate Bill 26-189, signed May 14, 2026, repeals and reenacts the artificial intelligence provisions of SB 24-205 and takes effect January 1, 2027. The replacement is a narrower transparency regime: Crowell and Moring records that the risk management program requirement, the algorithmic impact assessments and the duty of reasonable care against algorithmic discrimination are removed, and Davis Wright Tremaine describes the new duties as notice, explanation, correction and human review. Davis Wright Tremaine also notes the effective date is subject to pending x.AI injunction litigation, so confirm the docket before relying on the date contractually.

    What does SB 26-189 require deployers to do?

    Four things from January 1, 2027, plus records. Give clear and conspicuous notice before using automated decision-making technology in a consequential decision. Within 30 days of an adverse outcome, provide a plain-language explanation of the decision, the technology's role in it, how to request more information, and the consumer's rights. Allow consumers to access and correct factually inaccurate personal data used by the system. Provide meaningful human review and reconsideration to the extent commercially reasonable. And retain compliance records for at least three years.

    Does SB 26-189 apply to small companies?

    Yes. Davis Wright Tremaine's reading of the statute is that it applies to any entity doing business in Colorado that develops or deploys covered automated decision-making technology, with no employee-count or revenue threshold. The limits are in the technology and the decision rather than in company size: the output must materially influence the decision, meaning it is a non-de minimis factor affecting the outcome rather than an incidental or clerical use, and the decision must be a consequential one in education, employment, financial or lending services, insurance, health care, or essential government services and benefits.

    When will the Colorado AI rules be final?

    Before January 1, 2027, when the law takes effect. That is a statutory deadline rather than a promise about timing: the Attorney General's AI page states that the ADMT Act requires the Colorado Attorney General's Office to adopt rules clarifying and implementing specific provisions of the law before January 1, 2027. The same page records that draft rules were filed on August 11, 2026 with a public comment period running through October 26, 2026, an early comment deadline of September 4, 2026 for a revised draft, and a further deadline of October 5, 2026 ahead of hearing revisions. Until those rules are adopted, anyone describing the operational mechanics of Colorado compliance with confidence is combining statutory text with an assumption. If the draft definitions would be expensive for your business, the comment window is the cheap moment to say so.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.