Hael
Book a meeting
US State AI Laws · Colorado

Colorado AI Act requirements

Hael · Updated 6 July 2026 · 6 min read
Key takeaway
The requirements in force are those of SB 26-189, effective 1 January 2027: pre-use notice, a 30-day adverse-outcome explanation, meaningful human review, access and correction of personal data, three-year records, and developer documentation to deployers. The repealed SB 24-205 duties, the duty of care, impact assessments, risk management programmes, and the NIST/ISO affirmative defence, are gone and should be removed from compliance plans.
  • SB 26-189 has six duties; five sit with the deployer, one with the developer.
  • The duty of care, impact assessments and risk-management programme are removed.
  • The NIST AI RMF / ISO 42001 affirmative defence is gone; the frameworks still travel as good practice.
  • AG-only enforcement, no private right of action, 60-day cure period until 2030.
  • Current as of July 2026. The Colorado position is in active motion; this guide tracks the live state.

The six duties, precisely

One: clear and conspicuous notice to the individual before covered ADMT is used in a consequential decision about them. Two: on an adverse outcome, a plain-language explanation within 30 days, covering the role the technology played. Three: meaningful human review and reconsideration of the decision on request. Four: the ability for individuals to access, and correct, inaccurate personal data used about them. Five: retention of records for three years. Six, on the developer side: documentation to deployers of intended uses, known harmful uses, training data categories, and known limitations. That is the complete statutory core; everything else commonly listed for "Colorado AI compliance" belongs to the repealed law.

What was removed, and why it matters

SB 26-189 deliberately dropped the risk-based architecture: no duty of reasonable care against algorithmic discrimination, no mandatory impact assessments, no risk management programme requirement, and no affirmative defence for following the NIST AI RMF or ISO/IEC 42001. If a vendor or adviser is still selling you a Colorado compliance programme built on those elements, they are working from the repealed text. The frameworks remain the practical way to run the surviving duties well; they no longer carry any Colorado statutory shield.

Enforcement, liability and timing

Attorney General enforcement only, no private right of action, a 60-day cure period until 2030, and voided contract clauses that shift liability for a party's own discriminatory ADMT use. Enforcement is paused as of July 2026 pending federal litigation and the AG's rulemaking, and the rules will supply the operational detail, notice form, explanation content, review mechanics, ahead of the 1 January 2027 effective date.

Running the duties without a programme

Each duty maps to an operating behaviour of a governed system: notice is a deployment-time control, the explanation is generated from the decision record, human review is a workflow with a named owner, correction is a data-handling path, and the three-year record is retention policy on evidence you already produce. Organisations that keep one live record per system meet Colorado's requirements as outputs, which is the difference between a fortnight of configuration and a quarter of programme work.

Key terms

Pre-use notice
The clear and conspicuous notice a deployer gives before covered ADMT is used in a consequential decision.
Adverse outcome
A decision unfavourable to the individual that triggers the 30-day plain-language explanation duty.
Human review
Meaningful review and reconsideration of the decision by a person, on request.
Record retention
The three-year retention duty for records supporting the covered ADMT use.
Affirmative defence (repealed)
The statutory shield in SB 24-205 for following NIST AI RMF or ISO 42001; not part of SB 26-189.

References

Related guides

Keep reading.

Free check

See where you stand on US State AI Laws, free.

Answer a short set of questions and see what US State AI Laws expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether US State AI Laws applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to US State AI Laws.

Or speak to us about your deadline. Book a meeting.