Article-by-article breakdown
Colorado Automated Decision-Making Technology Law
Concerning the use of automated decision-making technology in consequential decisions, and, in connection therewith, making an appropriation.
Definitions — Key Definitions
Applies to
- ›Developers
- ›Deployers
- ›Consumers
Plain English
This section establishes the core terminology necessary to understand the Act's scope. An "automated decision-making technology" (ADMT) is broadly defined as any technology that processes personal data to generate outputs (like predictions or recommendations) used to make, guide, or assist a decision about an individual. However, it specifically excludes certain tools such as cybersecurity, web tools, spreadsheets requiring human analysis, and communication tools intended for human review, thereby narrowing the regulatory focus.
A "consequential decision" is central to the law, referring to decisions impacting an individual's access to, eligibility for, or compensation related to critical areas like education, employment, housing, financial services, insurance, healthcare, or essential government services. An "adverse outcome" is a decision that denies, terminates, revokes, or materially reduces a consumer's access or eligibility, or results in significantly less favorable terms. The Act also distinguishes between a "developer" (creator of ADMT) and a "deployer" (user of ADMT), assigning specific duties to each. Importantly, a "consumer" is broadly defined to include Colorado residents and any individual whose access or opportunity in Colorado is evaluated, explicitly extending protections to employees and job applicants.
Key points
- •ADMT is broadly defined but excludes specific low-risk technologies.
- •"Consequential decisions" cover critical life areas like employment, housing, and healthcare.
- •"Adverse outcome" triggers specific disclosure and rights requirements.
- •"Consumer" includes employees and job applicants, expanding typical privacy law scope.
- •Clear distinction between "developer" (creator) and "deployer" (user) of ADMT.
What you need to do
- 1.Identify if your technology falls under the ADMT definition and if your decisions are 'consequential'.
- 2.Determine if you are a 'developer' or 'deployer' to understand your specific obligations.
- 3.Ensure your internal definitions align with the Act's scope, especially regarding 'consumers' and 'adverse outcomes'.
Governance and Institutional Framework — Attorney General's Enforcement and Rulemaking Authority
Applies to
- ›Colorado Attorney General
- ›Developers
- ›Deployers
Plain English
This provision establishes the Colorado Attorney General (AG) as the sole authority for enforcing the Act. Unlike some other regulations, this law does not create a private right of action, meaning individuals cannot directly sue under its provisions; all enforcement actions must be initiated by the AG's office. This approach aims to centralize enforcement and ensure consistent application of the law across the state.
A critical aspect of the AG's role is the mandatory rulemaking authority. The Act requires the Attorney General to adopt rules by January 1, 2027, which is the same date the substantive obligations of the Act take effect. These rules are essential for clarifying key terms, outlining acceptable uses of ADMT, and providing practical guidance for both developers and deployers to ensure compliance. Businesses are strongly advised to monitor these forthcoming rules, as they will significantly influence compliance strategies and operational adjustments.
Key points
- •Colorado Attorney General has exclusive enforcement authority.
- •No private right of action for individuals under this Act.
- •AG must adopt clarifying rules by January 1, 2027.
- •Rules will define terms, acceptable uses, and compliance guidance.
What you need to do
- 1.Actively monitor the Colorado Attorney General's rulemaking process for detailed compliance requirements.
- 2.Understand that all enforcement will come from the AG's office, not individual lawsuits.
- 3.Prepare to adapt internal policies and procedures based on the AG's forthcoming rules.
Key Focus Areas (Developers) — Developer Documentation Requirements
Applies to
- ›Developers
Plain English
Starting January 1, 2027, developers of automated decision-making technology (ADMT) that materially influences consequential decisions must provide comprehensive technical documentation to the deployers (users) of their systems. This documentation is crucial for transparency and responsible deployment, ensuring that deployers understand the capabilities and limitations of the ADMT they are using.
The required documentation must detail the ADMT's intended uses, the categories of training data utilized, any known limitations or risks associated with its use, and clear instructions for appropriate deployment and human review. Furthermore, developers are obligated to notify deployers of any material updates or modifications made to the covered ADMT. This ensures that deployers always have up-to-date information to maintain compliance and manage risks effectively.
Key points
- •Developers must provide comprehensive technical documentation to deployers.
- •Documentation must cover intended uses, training data, and known limitations.
- •Instructions for appropriate use and human review are required.
- •Developers must notify deployers of material updates to the ADMT.
What you need to do
- 1.Establish a robust process for creating and maintaining detailed technical documentation for all covered ADMTs.
- 2.Develop a system to communicate material updates and changes to deployers promptly.
- 3.Ensure documentation clearly outlines the ADMT's capabilities, limitations, and responsible use guidelines.
Key Focus Areas (Deployers - Notice) — Deployer Consumer Notice and Adverse Outcome Disclosure
Applies to
- ›Deployers
Plain English
Deployers, the entities using automated decision-making technology (ADMT) in consequential decisions, have significant transparency obligations towards consumers. They must provide clear and conspicuous notice to consumers at the point of interaction, informing them that ADMT is being used or will be used in a decision that affects them. This notice must also include instructions on how consumers can obtain additional information about the ADMT's use.
Furthermore, if a consequential decision made by a covered ADMT results in an adverse outcome for a consumer, the deployer must provide a plain language description of the ADMT's role in that decision. This disclosure must be provided within 30 days of the adverse outcome and is intended to help consumers understand why a particular decision was made and how the automated system contributed to it. This ensures a level of explainability for critical decisions impacting individuals.
Key points
- •Deployers must provide clear and conspicuous notice of ADMT use to consumers.
- •Notice must be given at the point of interaction for consequential decisions.
- •Instructions for obtaining additional information about ADMT use must be included.
- •Plain language description of ADMT's role required within 30 days of an adverse outcome.
What you need to do
- 1.Implement mechanisms for providing clear, timely, and conspicuous notices to consumers when ADMT is involved in consequential decisions.
- 2.Develop standardized templates and processes for generating plain language descriptions of ADMT's role in adverse outcomes.
- 3.Train staff on how to provide additional information to consumers about ADMT use.
Cross-jurisdiction equivalents
Key Focus Areas (Deployers - Rights) — Consumer Rights: Access, Correction, and Human Review
Applies to
- ›Deployers
Plain English
This provision grants Colorado consumers specific rights when automated decision-making technology (ADMT) is used in consequential decisions. Consumers have the right to request access to their personal data used by a covered ADMT, allowing them to understand what information is feeding the automated decision-making process. Complementing this, consumers also have the right to request the correction of any factually incorrect personal data used by the ADMT, ensuring decisions are based on accurate information.
Crucially, the Act provides consumers with the right to request meaningful human review and reconsideration following an adverse outcome caused by a covered ADMT. This ensures that automated decisions are not final and that individuals have an avenue to appeal and have their case reviewed by a human, adding a vital layer of oversight and fairness to critical decisions.
Key points
- •Consumers have the right to request access to personal data used by ADMT.
- •Consumers have the right to request correction of factually incorrect personal data.
- •Consumers have the right to request meaningful human review of adverse outcomes.
- •Consumers have the right to reconsideration of adverse outcomes.
What you need to do
- 1.Establish clear, accessible processes for consumers to submit requests for data access and correction.
- 2.Develop and document a robust process for conducting meaningful human review and reconsideration of adverse ADMT decisions.
- 3.Train personnel involved in decision-making and customer service on these consumer rights and the procedures for handling requests.
Cross-jurisdiction equivalents
Key Focus Areas / Implementation Framework — Record Retention Requirements
Applies to
- ›Developers
- ›Deployers
Plain English
To ensure accountability and facilitate compliance oversight, both developers and deployers of automated decision-making technology (ADMT) are mandated to retain specific records. These records must be sufficient to demonstrate compliance with all provisions of the Act.
The retention period for these records is set at a minimum of three years from the date of the consequential decision. This requirement applies broadly to all documentation related to ADMTs, including technical specifications, training data information, consumer notices, adverse outcome disclosures, and records of human review and reconsideration processes. Maintaining these records is essential for demonstrating due diligence and responding to potential inquiries or enforcement actions by the Attorney General.
Key points
- •Both developers and deployers must retain records.
- •Records must demonstrate compliance with the Act.
- •Minimum retention period is three years from the consequential decision date.
What you need to do
- 1.Implement a comprehensive record-keeping system for all ADMT-related documentation, including technical specs, consumer interactions, and compliance efforts.
- 2.Ensure records are easily retrievable and can clearly demonstrate adherence to the Act's requirements.
- 3.Establish internal policies for data retention and secure storage of these records.
Monitoring and Evaluation — Attorney General's Annual Reporting
Applies to
- ›Colorado Attorney General
Plain English
The Colorado Attorney General's office is tasked with ongoing monitoring and evaluation of the Act's effectiveness and enforcement. A key component of this oversight is the requirement for the Attorney General to submit annual reports to the General Assembly.
These reports are scheduled to commence in January 2028 and will detail enforcement actions taken against developers and deployers. They are expected to provide insights into the types of violations encountered, the sectors most impacted, and the overall effectiveness of the legislation in achieving its objectives of consumer protection and responsible ADMT use. This reporting mechanism ensures legislative accountability and provides valuable data for potential future adjustments to the law.
Key points
- •Attorney General must submit annual reports to the General Assembly.
- •Reporting begins in January 2028.
- •Reports will detail enforcement actions against developers and deployers.
- •Reports will provide insights into the law's effectiveness and impact.
What you need to do
- 1.Be aware that enforcement trends and compliance challenges will be publicly reported.
- 2.Understand that the AG's reports may inform future legislative or regulatory changes.
- 3.Maintain robust compliance programs to minimize the likelihood of being included in negative enforcement statistics.
Penalties, Liability, and Appeals — Enforcement, Penalties, and Liability Framework
Applies to
- ›Developers
- ›Deployers
- ›Colorado Attorney General
Plain English
This section outlines the enforcement mechanisms, potential penalties, and liability framework under the Act. All violations are classified as deceptive trade practices, and the Colorado Attorney General holds exclusive enforcement authority, meaning there is no private right of action for individuals. Before initiating an enforcement action, the AG must provide written notice of the alleged violation, granting the developer or deployer a 60-day period to cure the non-compliance. If cured within this timeframe, civil penalties cannot be sought, though injunctive relief may still be pursued. This cure period is set to expire on January 1, 2030, after which the AG may bypass it for knowing or repeat violations.
Regarding liability, both developers and deployers can be held liable under existing anti-discrimination laws, with liability apportioned based on relative fault. Developer liability is specifically limited to situations where the ADMT was used as intended or marketed, protecting them from misuse by deployers. Importantly, any indemnification provisions between developers and deployers that attempt to shield either party from liability under relevant discrimination laws are explicitly declared void as contrary to public policy, ensuring continued accountability. Consumers also retain the right to request meaningful human review and reconsideration of adverse outcomes.
Key points
- •Violations are treated as deceptive trade practices; AG has exclusive enforcement.
- •No private right of action for individuals under this Act.
- •60-day cure period for violations (expires Jan 1, 2030) before civil penalties.
- •Liability for discrimination is fault-based and apportioned between developers and deployers.
- •Developer liability is limited to intended or marketed use of the ADMT.
- •Indemnification clauses attempting to avoid discrimination liability are void.
What you need to do
- 1.Establish internal protocols for promptly responding to any notice of alleged violation from the AG's office.
- 2.Review and update all contracts, especially indemnification clauses with ADMT providers/users, to ensure compliance with the anti-discrimination liability provisions.
- 3.Understand the specific conditions under which developer liability is limited to ensure proper use of ADMTs.
Relationship to Other Instruments — Preservation of Existing Rights and Interaction with Other Laws
Applies to
- ›Developers
- ›Deployers
Plain English
This Act significantly impacts the regulatory landscape by repealing and replacing Colorado's previous AI legislation, Senate Bill 24-205. This new law shifts from a broader 'high-risk AI system' framework to a more targeted approach focusing on 'automated decision-making technology' in 'consequential decisions,' emphasizing transparency and consumer rights. This replacement resolves prior legislative uncertainties and provides a clearer, albeit different, regulatory path.
Crucially, SB 26-189 explicitly preserves all existing rights and remedies available under other state and federal laws. This means compliance with this AI Act does not exempt businesses from obligations or liabilities under statutes such as the Colorado Anti-Discrimination Act, the Colorado Consumer Protection Act, product liability laws, or federal laws like Title VII of the Civil Rights Act. The Act reinforces that the use of an ADMT is not a shield against claims of discrimination. Furthermore, it clarifies that it does not require disclosures or actions prohibited by federal law, nor does it mandate actions that would compromise critical cybersecurity, fraud prevention, anti-money laundering, or counter-terrorist financing programs.
Key points
- •Repeals and replaces the previous Colorado AI law (SB 24-205).
- •Preserves all existing rights and remedies under other state and federal laws.
- •Compliance with this Act does not excuse obligations under anti-discrimination or consumer protection laws.
- •Indemnification clauses attempting to circumvent discrimination liability are void.
- •Does not require actions prohibited by federal law or that compromise critical security/compliance programs.
What you need to do
- 1.Conduct a comprehensive legal review to ensure ADMT use complies with all relevant state and federal laws, not just this Act.
- 2.Ensure ADMT implementation does not inadvertently create new liabilities under existing anti-discrimination or consumer protection statutes.
- 3.Verify that any required disclosures or actions under this Act do not conflict with federal laws or compromise essential security programs.
Need help applying this to your case?
The wizard takes 60 seconds and tells you which articles you actually need to worry about based on your jurisdictions, use case, and data.
Start the wizard →