United States - Colorado - AI Consumer Protections (SB24-205)
Colorado SB24-205 — Consumer Protections for Artificial Intelligence Act
United States
RAI-US-CO-CSCPAXX-2024Colorado Senate Bill 24-205, signed May 17, 2024, establishes the first comprehensive US state framework for regulating high-risk artificial intelligence systems. The law requires developers and deployers of AI systems making consequential decisions about consumers in employment, education, financial services, healthcare, housing, insurance, and legal services to implement risk management programs, conduct impact assessments, provide consumer disclosures, and enable meaningful human oversight. The Attorney General has exclusive enforcement authority.
Summary
Read full text ↗Plain English
Overview
Colorado Senate Bill 24-205, the Consumer Protections for Artificial Intelligence Act, represents landmark legislation as the first comprehensive US state law governing artificial intelligence systems affecting consumers. Signed by Governor Jared Polis on May 17, 2024, the law establishes a risk-based framework requiring developers and deployers of high-risk AI systems to implement safeguards against algorithmic discrimination, provide consumer transparency, and maintain accountability mechanisms. The legislation responds to growing concerns about AI systems making consequential decisions in critical areas such as employment, lending, housing, healthcare, and insurance—areas where algorithmic bias can cause significant harm to individuals. Colorado's approach draws inspiration from the European Union AI Act while adapting the framework to US legal structures and consumer protection traditions. The law takes effect February 1, 2026, providing an 18-month implementation period for affected organizations to develop compliance programs. Governor Polis, while signing the bill, expressed some reservations about potential compliance costs and called for continued refinement, but ultimately supported the legislation as an important step in responsible AI governance.
Definitions
SB24-205 establishes foundational definitions that determine regulatory scope and obligations. Artificial intelligence system means any machine-based system that, for any explicit or implicit objective, infers from inputs it receives how to generate outputs including content, decisions, predictions, or recommendations that can influence physical or virtual environments. High-risk artificial intelligence system means any AI system that, when deployed, makes or is a substantial factor in making a consequential decision—a decision with material legal or similarly significant effect on a consumer's access to or conditions of education enrollment or opportunities, employment or employment opportunities, financial or lending services, essential government services, healthcare services, housing, insurance, or legal services. Algorithmic discrimination means any condition in which an AI system's use results in unlawful differential treatment or impact disfavoring individuals based on actual or perceived age, color, disability, ethnicity, genetic information, limited English proficiency, national origin, race, religion, reproductive health, sex, veteran status, or other protected classifications under state or federal law. Developer means any person doing business in Colorado that develops or intentionally and substantially modifies an AI system. Deployer means any person doing business in Colorado that deploys a high-risk AI system. Substantial factor means a factor that assists in making a consequential decision or is capable of altering the outcome of a consequential decision, excluding factors providing only information or data or performing narrow procedural or preparatory tasks.
Governance and Institutional Framework
SB24-205 establishes the Colorado Attorney General as the exclusive enforcement authority, incorporating AI-related violations into the existing Colorado Consumer Protection Act framework. No private right of action exists under the statute, concentrating enforcement discretion in a single state authority capable of developing consistent interpretation and prioritizing enforcement resources. The law charges the Attorney General with adopting rules for implementation, including guidance on discrimination testing procedures and recognized compliance frameworks that may establish rebuttable presumptions of reasonable care. The Colorado Attorney General may investigate potential violations, issue subpoenas, and bring enforcement actions seeking injunctive relief and civil penalties. The legislation contemplates ongoing regulatory development, recognizing that AI governance requires adaptive approaches as technology evolves. Developers bear upstream compliance obligations including documentation, disclosure to deployers, and public transparency, while deployers hold downstream responsibilities for risk management, impact assessment, consumer notification, and human oversight. The framework creates a distributed compliance model where both system creators and system users share accountability for preventing algorithmic discrimination and ensuring consumer protection. The law explicitly addresses the interstate nature of AI development and deployment by applying to entities 'doing business in Colorado,' capturing both in-state companies and out-of-state organizations whose AI systems affect Colorado consumers.
Key Focus Areas
- Algorithmic Discrimination Prevention: Both developers and deployers must use reasonable care to protect consumers from known or foreseeable risks of algorithmic discrimination, establishing non-discrimination as the law's central objective.
- Risk Management Programs: Deployers must implement risk management policies governing AI system use, including employee training, technical safeguards, and ongoing monitoring procedures.
- Impact Assessments: Deployers must complete and maintain impact assessments before deploying high-risk AI systems, documenting system purposes, intended uses, known risks, and discrimination testing results.
- Developer Documentation: Developers must provide deployers with reasonably sufficient documentation on system capabilities, known risks, training data characteristics, and information needed for impact assessments.
- Consumer Disclosure: Deployers must inform consumers before consequential decisions that AI systems will be used, providing mechanisms to request human review and explanations of adverse decisions.
- Meaningful Human Oversight: Deployers must ensure employees overseeing high-risk AI systems understand system purpose and limitations and can intervene to prevent algorithmic discrimination.
- Adverse Decision Explanations: When AI contributes to adverse decisions, deployers must explain the principal reasons, describe data types used, and provide appeal or correction opportunities.
- Public Transparency: Developers must publish summaries of AI systems offered, and deployers must make public their policies regarding high-risk AI system usage.
- Safe Harbor for Frameworks: Compliance with nationally or internationally recognized AI risk management frameworks creates a rebuttable presumption of reasonable care.
- Discrimination Testing: Developers must provide information enabling deployers to test for algorithmic discrimination in specific deployment contexts.
Implementation Framework
SB24-205 takes effect February 1, 2026, establishing an extended implementation timeline that reflects the complexity of developing AI governance programs. Before the effective date, the Colorado Attorney General must adopt rules implementing the statute, including guidance on discrimination testing procedures and criteria for recognized AI governance frameworks qualifying for safe harbor treatment. Organizations must begin compliance preparations immediately given the extensive requirements including risk management program development, impact assessment procedures, consumer disclosure mechanisms, and employee training programs. Developers face earlier practical compliance deadlines as they must create documentation packages that deployers need for their own assessments. The law applies prospectively, governing AI systems deployed after the effective date, though organizations using existing systems should assess whether continued use constitutes 'deployment' requiring compliance. Impact assessments must be completed 'as soon as reasonably practicable' after deployment but in any case before using AI systems for consequential decisions. Documentation retention requirements span the longer of the period the AI system is used or three years after discontinuation. The Attorney General may phase in enforcement, potentially providing additional compliance time through guidance or enforcement discretion during initial implementation periods.
Monitoring and Evaluation
SB24-205 establishes several ongoing compliance monitoring obligations. Deployers must conduct regular reviews of their high-risk AI systems to ensure continued compliance with risk management policies. Impact assessments must be updated 'as reasonably necessary' when systems are substantially modified or when new risks emerge. The law requires deployers to maintain documentation for three years after discontinuing AI system use, creating an accountability trail for retrospective review. Developers must keep records of known risks and mitigation measures throughout the commercial availability of their systems. The Attorney General receives deployment notifications when high-risk AI systems are involved in discrimination claims, creating a feedback loop for enforcement prioritization. While the law does not mandate external audits or government inspections, the documentation and transparency requirements enable both internal compliance verification and external oversight by regulators, auditors, and researchers. The safe harbor provision for recognized frameworks incentivizes organizations to adopt structured governance approaches with built-in evaluation mechanisms. Consumer complaint processes and adverse decision appeals create additional monitoring channels, surfacing potential compliance issues through direct user feedback. The Attorney General's rulemaking authority enables ongoing adaptation of monitoring requirements as implementation experience accumulates and AI governance best practices evolve.
Penalties, Liability, and Appeals
SB24-205 incorporates enforcement into Colorado's Consumer Protection Act, making violations subject to established penalty structures for unfair or deceptive trade practices. The Attorney General may seek injunctive relief to halt ongoing violations and civil penalties for violations. While the statute does not specify penalty amounts, Colorado Consumer Protection Act penalties can reach up to $20,000 per violation, with enhanced penalties for knowing violations affecting elderly or disabled consumers. Each affected consumer may constitute a separate violation, potentially generating substantial cumulative liability for systemic compliance failures. The law creates no private right of action, preventing individual consumer lawsuits but preserving Attorney General discretion over enforcement priorities. The rebuttable presumption of reasonable care for organizations following recognized AI governance frameworks provides an important defense mechanism, though the presumption can be overcome with evidence of actual algorithmic discrimination or inadequate framework implementation. Organizations may contest enforcement actions through administrative procedures and judicial review. The law exempts certain entities including state and local governments (unless deploying in insurance), federally regulated financial institutions (to the extent AI use is regulated by federal law), and HIPAA-covered healthcare entities (for HIPAA-regulated activities). These exemptions recognize existing federal oversight regimes while preserving state authority over unregulated AI applications.
Relationship to Other Instruments
SB24-205 operates within a broader ecosystem of AI governance frameworks. The European Union AI Act provides the most direct international comparison, sharing Colorado's risk-based approach, high-risk categorization, and focus on prohibited discriminatory applications. However, Colorado's framework is narrower, focusing specifically on consumer protection rather than the EU's comprehensive regulatory system covering public safety, fundamental rights, and market access. Executive Order 14110 on Safe, Secure, and Trustworthy AI establishes federal policy direction that Colorado's law complements at the state level. Colorado's law explicitly accommodates federal frameworks, exempting federally-regulated activities and recognizing federal AI governance standards for safe harbor treatment. Within Colorado, SB24-205 intersects with existing anti-discrimination statutes including the Colorado Anti-Discrimination Act, which prohibits employment discrimination, and fair lending laws governing financial services. The Consumer Protection Act integration provides established enforcement mechanisms and legal interpretations applicable to AI-specific violations. Future California legislation, including SB 53 on frontier AI safety, addresses different aspects of AI governance, potentially creating complementary rather than conflicting state frameworks. The NIST AI Risk Management Framework and ISO/IEC AI standards may qualify as recognized frameworks under Colorado's safe harbor provision, creating alignment between state requirements and international governance standards.
International Alignment
Colorado's Consumer Protections for AI Act reflects the global trend toward risk-based AI regulation while adapting international concepts to US legal structures. The European Union AI Act's risk categorization approach clearly influenced Colorado's high-risk AI system framework, though Colorado focuses narrowly on consumer protection rather than the EU's comprehensive regulatory scope. The law's emphasis on algorithmic discrimination aligns with international human rights frameworks addressing AI bias, including UNESCO's Recommendation on the Ethics of AI and OECD AI Principles. Colorado's safe harbor provision for recognized AI governance frameworks explicitly enables international standard compliance—organizations following ISO/IEC AI management standards or other internationally recognized frameworks may claim the rebuttable presumption of reasonable care. The Council of Europe's emerging AI Convention, which addresses human rights implications of AI systems, shares Colorado's focus on preventing discriminatory impacts. Unlike the EU AI Act's extraterritorial application covering any AI system affecting EU residents, Colorado's jurisdictional reach is limited to entities 'doing business in Colorado,' creating a narrower but more clearly defined compliance scope. The law's human oversight requirements align with international principles of human agency over AI systems articulated in frameworks from the EU, OECD, and G20. As the first comprehensive US state AI law, Colorado's approach may influence both other US states and international frameworks seeking US-compatible governance models.
Implementation Timeline
| Date | Milestone |
|---|---|
| January 2024 | SB24-205 introduced in Colorado General Assembly |
| May 8, 2024 | Bill passes Colorado House and Senate |
| May 17, 2024 | Governor Jared Polis signs SB24-205 into law |
| 2024-2025 | Attorney General rulemaking on discrimination testing and framework recognition |
| February 1, 2026 | Law takes effect; compliance required for high-risk AI deployments |
| Ongoing | Impact assessment updates required when systems materially modified |
| 3 years post-discontinuation | Documentation retention period following AI system retirement |
Compliance Checklist
| Requirement | Details |
|---|---|
| Determine Applicability | Assess whether AI systems make or substantially factor in consequential decisions affecting Colorado consumers in covered areas |
| Developer: Document System Information | Create documentation on intended uses, known risks, training data, and discrimination testing capabilities |
| Developer: Publish AI System Summary | Make publicly available a summary of high-risk AI systems offered |
| Deployer: Implement Risk Management Policy | Establish governance procedures, employee training, and technical safeguards |
| Deployer: Complete Impact Assessment | Document system purpose, intended uses, known risks, and discrimination testing results before deployment |
| Deployer: Establish Consumer Disclosure | Inform consumers before AI-assisted consequential decisions and provide human review options |
| Deployer: Enable Adverse Decision Appeals | Create processes for explaining AI-assisted decisions and allowing corrections |
| Deployer: Train Oversight Personnel | Ensure employees understand AI system limitations and can intervene to prevent discrimination |
| Deployer: Public Policy Disclosure | Make publicly available the deployer's policy governing high-risk AI system use |
| Consider Framework Safe Harbor | Evaluate adopting NIST AI RMF, ISO standards, or other recognized frameworks for rebuttable presumption |
| Establish Documentation Retention | Maintain records for duration of use plus three years |
| Notify AG of Discrimination Claims | Report when high-risk AI systems are involved in discrimination allegations |
Sources and References
| Source | Type |
|---|---|
| SB24-205 Bill Page - Colorado General Assembly | Primary Source |
| SB24-205 Signed Act Text | Primary Source |
| Colorado Attorney General | Enforcement Authority |
| NIST AI Risk Management Framework | Recognized Framework |
Colorado SB 24-205 — the Colorado AI Act — is the first US state law to comprehensively regulate AI in private-sector decisions about consumers. It takes effect on 1 February 2026.
What it covers: 'high-risk AI systems' — meaning AI that makes, or is a substantial factor in making, a 'consequential decision' about a Colorado consumer. Consequential decisions are ones that affect access to education, employment, financial services, healthcare, housing, insurance, legal services, or government services.
The law splits responsibilities between two roles: - Developers (people who build the AI) must give deployers clear documentation: what the system is for, its known limitations, the data used to train it, how it was evaluated, and how to mitigate risk. - Deployers (people who use the AI to make decisions) carry the bulk of obligations: write a risk-management policy, do an annual impact assessment, notify consumers before the AI is used on them, and — if the AI makes an adverse decision — explain why, share the data used, give the consumer a chance to correct it, and offer an appeal to a human.
Both developers and deployers must disclose to the Colorado Attorney General within 90 days if they discover the AI has caused algorithmic discrimination (illegal disparate impact based on protected class).
There are sensible exemptions: small businesses with under 50 employees that don't use their own data to fine-tune the AI get a lighter regime; HIPAA-regulated healthcare, certain financial services, and approved fraud-detection use cases are partly exempt.
Enforcement is exclusively by the Colorado Attorney General — no private right of action. But because the obligations are very specific, AG enforcement is expected to be meaningful, and Colorado has signalled it will look at this seriously.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 8 marked completePlain-English obligations under United States - Colorado - AI Consumer Protections (SB24-205). Not legal advice — verify against the official text before relying on it.
- #1CriticalSec. 6-1-1701(3)⏰ Feb 1, 2026
Applies to: Developers and deployers of AI systems used by Colorado consumers.
- #2CriticalSec. 6-1-1703(2)⏰ Feb 1, 2026
Applies to: Deployers of high-risk AI systems.
- #3CriticalSec. 6-1-1703(3)⏰ Feb 1, 2026
Applies to: Deployers of high-risk AI systems.
- #4CriticalSec. 6-1-1703(4)(a)⏰ Feb 1, 2026
Applies to: Deployers making consequential decisions about Colorado consumers.
- #5CriticalSec. 6-1-1703(4)(b)⏰ Feb 1, 2026
Applies to: Deployers.
- #6CriticalSec. 6-1-1702(7) & 1703(7)⏰ Feb 1, 2026
Applies to: Developers and deployers.
- #7ImportantSec. 6-1-1702(2)⏰ Feb 1, 2026
Applies to: Developers of high-risk AI systems.
- #8ImportantSec. 6-1-1703(5)⏰ Feb 1, 2026
Applies to: Deployers of high-risk AI systems.
Real enforcement actions
1 action recordedPublic enforcement actions where regulators cited United States - Colorado - AI Consumer Protections (SB24-205). Helps you see how the law is actually applied in practice.
- Enforcement orderDec 19, 2023
U.S. Federal Trade Commission (FTC) vs Rite Aid Corporation
Sector: Retail / loss-prevention
FTC banned Rite Aid from using facial-recognition AI in any form for 5 years after finding the company deployed the technology in hundreds of stores without reasonable safeguards. The system disproportionately misidentified women and people of colour as shoplifters, leading to wrongful detentions and humiliating searches. Cited FTC Act §5 (unfair and deceptive practices). The same biometric-identification deployment in a US jurisdiction with an AI law (e.g. Colorado AI Act once 'consequential decisions' kicks in, or any future federal AI law) would face direct duties on bias testing, deployer impact assessments and consumer notice.
Source ↗
Related Regulations
Concerning the Use of Automated Decision-Making Technology in Consequential Decisions, and, in Connection Therewith, Making an Appropriation.
Colorado, United States94% similar
Increase Transparency for Algorithmic Systems
Colorado, United States94% similar
Concerning the use of artificial intelligence in health care.
Colorado, United States93% similar
Concerning Consumer Protections in Interactions with Artificial Intelligence Systems
Colorado, United States93% similar
Concerning Consumer Protections in Interactions with Artificial Intelligence Systems
Colorado, United States93% similar
© Regulations.AI — created on 05-Aug-2026