Colorado AI Act requirements
- SB 26-189 has six duties; five sit with the deployer, one with the developer.
- The duty of care, impact assessments and risk-management programme are removed.
- The NIST AI RMF / ISO 42001 affirmative defence is gone; the frameworks still travel as good practice.
- AG-only enforcement, no private right of action, 60-day cure period until 2030.
- Current as of July 2026. The Colorado position is in active motion; this guide tracks the live state.
The six duties, precisely
One: clear and conspicuous notice to the individual before covered ADMT is used in a consequential decision about them. Two: on an adverse outcome, a plain-language explanation within 30 days, covering the role the technology played. Three: meaningful human review and reconsideration of the decision on request. Four: the ability for individuals to access, and correct, inaccurate personal data used about them. Five: retention of records for three years. Six, on the developer side: documentation to deployers of intended uses, known harmful uses, training data categories, and known limitations. That is the complete statutory core; everything else commonly listed for "Colorado AI compliance" belongs to the repealed law.
What was removed, and why it matters
SB 26-189 deliberately dropped the risk-based architecture: no duty of reasonable care against algorithmic discrimination, no mandatory impact assessments, no risk management programme requirement, and no affirmative defence for following the NIST AI RMF or ISO/IEC 42001. If a vendor or adviser is still selling you a Colorado compliance programme built on those elements, they are working from the repealed text. The frameworks remain the practical way to run the surviving duties well; they no longer carry any Colorado statutory shield.
Enforcement, liability and timing
Attorney General enforcement only, no private right of action, a 60-day cure period until 2030, and voided contract clauses that shift liability for a party's own discriminatory ADMT use. Enforcement is paused as of July 2026 pending federal litigation and the AG's rulemaking, and the rules will supply the operational detail, notice form, explanation content, review mechanics, ahead of the 1 January 2027 effective date.
Running the duties without a programme
Each duty maps to an operating behaviour of a governed system: notice is a deployment-time control, the explanation is generated from the decision record, human review is a workflow with a named owner, correction is a data-handling path, and the three-year record is retention policy on evidence you already produce. Organisations that keep one live record per system meet Colorado's requirements as outputs, which is the difference between a fortnight of configuration and a quarter of programme work.
Key terms
- Pre-use notice
- The clear and conspicuous notice a deployer gives before covered ADMT is used in a consequential decision.
- Adverse outcome
- A decision unfavourable to the individual that triggers the 30-day plain-language explanation duty.
- Human review
- Meaningful review and reconsideration of the decision by a person, on request.
- Record retention
- The three-year retention duty for records supporting the covered ADMT use.
- Affirmative defence (repealed)
- The statutory shield in SB 24-205 for following NIST AI RMF or ISO 42001; not part of SB 26-189.