Colorado AI in Healthcare Act

Concerning the use of artificial intelligence in health care.

United States • Colorado

RAI-US-CO-HB26113-2026

HB 26-1139

Effective: January 1, 2027
In Force(In Force)
ActTransparency and DisclosureGovernance and Oversight
Export PDF

Colorado HB 26-1139 establishes a regulatory framework for AI in healthcare, focusing on patient safety, equity, and human oversight in decisions.

Overview

Colorado House Bill 26-1139, officially titled “Use of Artificial Intelligence in Health Care,” establishes a foundational regulatory framework for the deployment and application of artificial intelligence (AI) systems within the state’s healthcare sector. Signed into law by Governor Polis on June 2, 2026, and slated to take effect on January 1, 2027, this legislation underscores Colorado's commitment to ensuring that healthcare remains human-centered amidst rapid technological advancements. The Act specifically targets areas where AI interaction with patients and healthcare decisions could have significant ethical and practical implications, aiming to balance innovation with patient safety, equity, and accountability. It addresses concerns about the potential for AI to introduce bias, erode trust, or diminish the quality of care if not properly governed.

The legislative declaration explicitly states that while AI systems offer valuable tools for efficiency and data analysis in healthcare, they cannot replace human judgment, compassion, or the nuanced understanding of a patient's unique life experiences. The General Assembly finds that healthcare decisions, which touch upon the most intimate and consequential aspects of human life, must be grounded in clinical judgment and individualized understanding. Therefore, the Act is designed to regulate AI use to ensure transparency, accountability, equity, and patient safety, prohibiting automated systems from making adverse coverage determinations without qualified human review and preserving the central role of licensed clinicians in decisions affecting Coloradans' health and well-being. Notably, while earlier versions of the bill included provisions regarding mental health companion chatbots and the unauthorized practice of psychotherapy by AI platforms, these specific elements were removed in the final enacted version, narrowing the Act's focus primarily to utilization review requirements and the prohibition of payer reimbursement for AI-delivered psychotherapy.

Definitions

The Colorado Act, in its effort to establish clear regulatory boundaries, implicitly and explicitly defines several key concepts central to its application in the healthcare domain. While the full text of the enacted bill would provide precise statutory definitions, the summaries indicate that an “artificial intelligence system or algorithm (AI)” is understood as the core technology being regulated, particularly when used in health care contexts. The legislation distinguishes between AI as an assistive tool and AI as a decision-making entity, especially in critical areas like utilization review. The Act also refers to “mental health professionals” and “licensed clinicians or physicians,” emphasizing the role of human expertise and accountability in healthcare delivery, particularly when AI is involved. These terms are crucial for delineating responsibilities and ensuring that human oversight remains paramount in sensitive medical decisions.

Furthermore, the Act introduces the concept of “utilization review,” which refers to the process by which health insurers and other entities determine coverage for healthcare services. The legislation sets specific parameters for how AI systems may be integrated into this process, particularly concerning “adverse coverage determinations,” which are decisions to deny or limit healthcare services. The emphasis on “individual medical or other clinical history” and “individual clinical circumstances,” as opposed to relying solely on “group data,” highlights the Act's focus on personalized, equitable care. Although initial drafts included definitions and regulations for “mental health companion chatbots,” these were ultimately removed from the final signed Act, indicating a refined scope that concentrates on the broader application of AI in health insurance and direct psychotherapy services.

Governance and Institutional Framework

The governance structure established by Colorado HB 26-1139 primarily designates existing state regulatory bodies to oversee and enforce the provisions related to artificial intelligence in healthcare. Entities that deploy AI systems for utilization review are mandated to provide written disclosures to relevant state agencies, including the Division of Insurance within the Department of Regulatory Agencies (DORA), the Department of Human Services (DHS), or the Department of Health Care Policy and Financing (HCPF), as applicable. These disclosures must detail how the AI system will be used, what oversight mechanisms are in place, and the audit procedures to ensure compliance with the Act's requirements. This approach leverages established regulatory expertise and infrastructure, rather than creating entirely new agencies, to integrate AI oversight into the existing healthcare regulatory landscape. The Act thus relies on the investigative and enforcement powers of these divisions to address potential non-compliance or patient complaints.

The Act also implies an expanded role for the Division of Professions and Occupations within DORA, particularly in handling complaints related to psychotherapy services. While the specific provisions concerning mental health companion chatbots were removed, the overarching goal of preventing the unauthorized practice of psychotherapy by AI systems and ensuring human accountability remains central. The requirement for human review by a licensed clinician or physician for any denial or delay of coverage based on medical necessity underscores a distributed governance model, where individual healthcare professionals bear significant responsibility in the AI-assisted decision-making process. This framework aims to ensure that ethical considerations and clinical judgment are not supplanted by automated processes, thereby maintaining a human-centric approach to healthcare governance.

Key Focus Areas

Colorado HB 26-1139 primarily focuses on two critical areas concerning the use of artificial intelligence in healthcare: utilization review by health insurers and the direct provision of psychotherapy services. Regarding utilization review, the Act imposes stringent requirements on entities employing AI systems for determining healthcare coverage. It mandates that such AI systems must base their determinations on an individual's medical or clinical history, individual clinical circumstances, and other relevant clinical information, explicitly prohibiting decisions based solely on group data without reference to the individual. Furthermore, any denial or delay of coverage based on medical necessity cannot be issued solely on the output of an AI system; it requires independent approval by a licensed clinician or physician or another competent regulated professional. This ensures human oversight in critical coverage decisions, aiming to prevent discriminatory outcomes and promote equitable application of AI.

The second major focus area is the direct provision of psychotherapy services. The Act unequivocally prohibits public and private payers, including Medicaid and the Children's Basic Health Plan (CHP+), from providing coverage for psychotherapy services conducted directly by an AI system. Consequently, mental health providers are also prohibited from billing for services rendered by an AI system. This provision highlights the legislature's intent to preserve the therapeutic relationship and the necessity of human empathy and judgment in mental health care. While the final Act removed broader regulations on mental health companion chatbots, this specific prohibition on AI-delivered psychotherapy underscores a clear boundary for AI's role in direct patient care, particularly in sensitive areas of mental health. The overarching goal across both focus areas is to ensure transparency, accountability, equity, and patient safety in the evolving landscape of AI in healthcare.

Implementation Framework

The implementation framework for Colorado HB 26-1139 is designed to integrate the new AI regulations into existing healthcare operations and oversight mechanisms, with a clear effective date of January 1, 2027. For entities utilizing AI in utilization review, a core component of the framework involves mandatory disclosure requirements. These entities, including health insurance companies, pharmacy benefit managers, and managed care entities, must provide written disclosures to the Division of Insurance, the Department of Human Services, or the Department of Health Care Policy and Financing, as appropriate. These disclosures must detail the specific utilization review functions for which the AI system will be used, the points in the process where it will be applied, the procedures for human oversight of adverse coverage determinations, and the methods for maintaining audit information to demonstrate compliance with the Act's stipulations. This proactive disclosure mechanism aims to provide regulatory bodies with the necessary information to monitor AI deployment and ensure adherence to the Act's principles of non-discrimination, accuracy, and reliability.

Beyond disclosures, the implementation framework emphasizes ongoing operational compliance. Entities must ensure that their AI systems make determinations based on individualized patient data, clinical history, and circumstances, rather than relying solely on generalized group data. Critically, any denial or delay of coverage based on medical necessity must undergo human review by a licensed clinician or physician competent in the relevant clinical area, preventing fully automated adverse decisions. For psychotherapy services, the implementation is straightforward: payers must cease covering AI-conducted psychotherapy, and providers must discontinue billing for such services as of the effective date. The Act also implies that regulatory agencies will need to adapt their complaint handling and enforcement processes to address potential violations related to AI use in healthcare, including instances of unauthorized practice or non-compliance with disclosure and oversight requirements. The fiscal note for the bill indicated minimal state workload impact, suggesting that the existing regulatory infrastructure is expected to absorb these new responsibilities with minor adjustments.

Monitoring and Evaluation

The monitoring and evaluation of Colorado HB 26-1139 will largely fall under the purview of the state agencies designated for oversight, specifically the Division of Insurance (DORA), the Department of Human Services (DHS), and the Department of Health Care Policy and Financing (HCPF). The Act's requirement for entities using AI in utilization review to provide written disclosures to these agencies forms the bedrock of the monitoring framework. These disclosures, which must outline the AI system's usage, human oversight processes, and audit procedures, will enable regulators to track the deployment of AI in healthcare and assess adherence to the statutory requirements. Regular review of these disclosures, coupled with potential audits, will be crucial for evaluating whether AI systems are being used in a non-discriminatory manner, are basing determinations on individual patient data, and are subject to appropriate human review for adverse coverage decisions. The ongoing nature of these disclosure requirements suggests a continuous monitoring approach rather than a one-time assessment.

Furthermore, the Act's emphasis on human oversight for denials of coverage provides a built-in mechanism for evaluation. The requirement that a denial or delay of coverage cannot be based solely on AI output without independent approval by a healthcare professional means that the effectiveness of human intervention can be monitored. Regulatory bodies could analyze patterns of AI-generated recommendations versus final human decisions to identify potential issues, biases, or areas where AI systems might be consistently misaligned with clinical judgment. While the bill's fiscal note projected minimal state workload, the increased volume of complaints related to AI use, particularly concerning psychotherapy services or utilization review, could trigger investigations by DORA's Division of Professions and Occupations. These investigations would serve as a reactive evaluation mechanism, providing insights into real-world impacts and potential areas for future legislative or regulatory refinement. The continuous feedback loop from disclosures, audits, and complaint resolution will be essential for assessing the Act's efficacy in achieving its goals of transparency, accountability, equity, and patient safety.

Penalties, Liability, and Appeals

While the full text of the enacted Colorado HB 26-1139 would detail specific penalties and liability provisions, the summaries indicate that non-compliance with the Act's requirements could lead to various forms of enforcement and potential legal ramifications. For instance, the bill increases the workload for the Division of Professions and Occupations in DORA to handle additional complaints related to psychotherapy services provided via AI. These complaints could involve both regulated mental health professionals and entities deploying AI systems that engage in the unauthorized practice of psychotherapy as defined by the bill. This suggests that existing professional licensing boards and regulatory bodies will apply their established disciplinary actions and penalties for violations, which can range from fines and license suspensions to other corrective measures, depending on the severity and nature of the infraction. The Act aims to ensure that accountability for healthcare decisions, even those assisted by AI, ultimately rests with human professionals.

Regarding utilization review, entities that fail to comply with the disclosure requirements or the mandates for human oversight in adverse coverage determinations could face regulatory scrutiny from the Division of Insurance, DHS, or HCPF. While specific monetary penalties are not explicitly detailed in the provided summaries, regulatory bodies typically have the authority to impose administrative fines, issue cease-and-desist orders, or require corrective action plans for violations of health insurance and healthcare regulations. The emphasis on preventing discriminatory AI use and ensuring fair and equitable application also opens avenues for potential legal challenges under existing anti-discrimination laws if AI systems are found to cause harm. For patients, the Act’s requirement for human review of adverse coverage denials implies a right to appeal such decisions, following established health insurance appeal processes, where the human reviewer's judgment, rather than solely the AI's output, would be subject to scrutiny. This framework ensures that patients retain avenues for redress and that AI decisions are not final without human validation.

Relationship to Other Instruments

Colorado HB 26-1139 operates within a broader legal and regulatory ecosystem, interacting with both existing state and federal healthcare laws and emerging AI-specific legislation. The Act's provisions are designed to complement, rather than supersede, established regulations governing health insurance, patient rights, and professional conduct in healthcare. For instance, the requirement that AI systems in utilization review must not be used in any way that discriminates against individuals explicitly ties the Act to existing state and federal anti-discrimination laws, ensuring that AI deployment upholds fundamental rights and equitable treatment. Similarly, the emphasis on human oversight and accountability for healthcare professionals using AI aligns with established principles of medical ethics and professional liability, reinforcing that AI is a tool to assist, not replace, human judgment. The Act also interacts with existing state programs like Medicaid and the Children's Basic Health Plan (CHP+), by explicitly prohibiting them from covering AI-conducted psychotherapy services, thereby integrating the new AI regulations directly into public health benefit administration.

The Colorado AI healthcare landscape has seen other legislative developments, such as Senate Bill 26-189 (which repealed and replaced an earlier AI Act, SB 24-205) and HB 26-1195, both signed around the same time as HB 26-1139. While SB 26-189 addresses broader AI regulations in Colorado, HB 26-1139 is specifically healthcare-focused and proceeds unaffected by any federal litigation or rulemaking delays impacting the broader AI Act. This indicates a deliberate legislative strategy to create sector-specific AI regulations that can function independently while still contributing to an overarching state policy on AI. HB 26-1195, signed on June 3, 2026, further regulates psychotherapy providers' use of AI, including prohibiting AI from engaging in therapeutic communication unless a human provider is actively present. These interconnected bills collectively form a comprehensive framework for AI governance in Colorado, with HB 26-1139 serving as a crucial pillar for health insurance and direct AI-provided psychotherapy, ensuring a coherent and layered regulatory approach across various aspects of AI in healthcare.

National/Federal Alignment

Colorado HB 26-1139 demonstrates a proactive state-level approach to regulating artificial intelligence in healthcare, often aligning with, and in some cases preceding, federal guidance and initiatives. The Act's emphasis on non-discrimination, transparency, and human oversight for AI systems in healthcare resonates with broader federal discussions and proposed frameworks for responsible AI development and deployment. For example, the requirement that AI systems in utilization review be applied fairly and equitably, including in accordance with regulations and guidance issued by the federal Department of Health and Human Services (HHS), directly links the state law to federal standards and best practices. This alignment ensures that Colorado's regulatory efforts are not isolated but contribute to a nationally consistent understanding of ethical AI use in sensitive sectors like healthcare, particularly as federal agencies continue to develop their own AI policies and guidelines.

While federal legislation specifically regulating AI in healthcare is still evolving, Colorado's Act provides a concrete example of how states can address immediate concerns such as biased algorithms in coverage decisions and the appropriate boundaries for AI in direct patient care. The principles embedded in HB 26-1139, such as the necessity of human review for adverse decisions and the prohibition of AI-only psychotherapy, reflect a cautious yet progressive stance that is likely to inform or be influenced by future federal regulations. The Act's focus on disclosures to state regulatory bodies also prepares the ground for potential future data sharing or reporting requirements that might emerge from federal mandates, ensuring a degree of interoperability in oversight. By establishing clear rules for AI use in utilization review and psychotherapy, Colorado is setting a precedent that could serve as a model or a point of comparison for other states and federal policymakers grappling with the complexities of AI integration into the healthcare system, ensuring that patient safety and ethical considerations remain paramount across different jurisdictional levels.

Implementation Timeline

MilestoneDateNotes
Bill Introduced2026-02-04Initial introduction of HB 26-1139 in the Colorado House of Representatives.
Passed House2026-03-16The bill successfully passed its third reading in the House.
Passed Senate2026-05-11The bill successfully passed its third reading in the Senate.
Sent to Governor2026-05-28Bill transmitted to the Governor for signature.
Signed/Enacted2026-06-02Governor Polis signed HB 26-1139 into law.
Effective Date2027-01-01The Act's provisions take effect.

Compliance Checklist

CheckRequired Action
AI System DocumentationEnsure comprehensive documentation of AI systems used in utilization review, including purpose, functionality, and data sources.
Non-Discriminatory UseVerify that AI systems are not used in any way that discriminates against individuals and are applied fairly and equitably, aligning with state and federal anti-discrimination laws.
Individualized DeterminationsConfirm that AI-driven utilization review decisions are based on the individual's medical/clinical history and circumstances, not solely on group data.
Human Oversight for DenialsImplement a process ensuring that any denial or delay of coverage based on medical necessity is not solely based on AI output and receives independent approval by a licensed clinician or physician.
Regulatory DisclosuresProvide written disclosures to DORA, DHS, or HCPF (as applicable) detailing AI use in utilization review, human oversight processes, and audit procedures.
Prohibition on AI Psychotherapy CoverageCease providing coverage for psychotherapy services directly conducted by an AI system.
Prohibition on Billing for AI PsychotherapyMental health providers must not bill for psychotherapy services provided by an AI system.
Periodic Review of AI OutcomesEnsure AI systems are periodically reviewed for accuracy, reliability, and that health data is not used beyond its intended purpose.

Sources and References

SourceType
HB 26-1139: Use of Artificial Intelligence in Health Care - Colorado General AssemblyGovernment
Bill Summary: HB26-1139 Use of Artificial Intelligence in Health Care - Colorado General AssemblyGovernment
CO HB1139 - BillTrack50Legal
CO HB1139 | 2026 | Regular Session - LegiScanLegal
Bill tracking in Colorado - HB 26-1139 (2026A legislative session) - FastDemocracyLegal
REREVISED - Colorado General Assembly (Bill Text)Government
Plain English

Colorado's new law, effective January 1, 2027, sets clear rules for how artificial intelligence can be used in healthcare, primarily impacting health insurers and mental health providers to ensure patient safety and human oversight. This legislation applies to entities like health insurance companies, pharmacy benefit managers, and mental health professionals who use AI systems in Colorado.

The law establishes several key requirements. First, if an AI system is used for utilization review – the process of determining healthcare coverage – it must base its decisions on an individual's specific medical history and circumstances, not just general group data. Crucially, any denial or delay of coverage based on medical necessity cannot be made solely by an AI; it requires independent approval from a licensed clinician or physician. Second, the law strictly prohibits public and private payers from covering psychotherapy services delivered directly by an AI system, and mental health providers cannot bill for such services. Entities using AI for utilization review must also disclose their AI usage, oversight, and audit procedures to relevant state agencies.

Enforcement falls to existing state regulatory bodies like the Division of Insurance. Non-compliance could lead to various actions, including fines, license suspensions, or cease-and-desist orders. Patients retain the right to appeal adverse coverage decisions, with human judgment being the ultimate arbiter. A practical takeaway is that while the law aims for human-centered care, it specifically targets utilization review and direct AI-delivered psychotherapy. Earlier discussions about regulating mental health companion chatbots were removed, meaning the law has a more focused scope than some might expect, emphasizing human accountability in critical decisions rather than a broad ban on all AI in mental health.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 8 marked complete

Plain-English obligations under Colorado AI in Healthcare Act. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalJan 1, 2027

    Applies to: Entities employing AI systems for utilization review.

    any denial or delay of coverage based on medical necessity cannot be issued solely on the output of an AI system; it requires independent approval by a licensed clinician or physician
  2. #2CriticalJan 1, 2027

    Applies to: Public and private payers (including Medicaid, CHP+).

    The Act unequivocally prohibits public and private payers... from providing coverage for psychotherapy services conducted directly by an AI system.
  3. #3CriticalJan 1, 2027

    Applies to: Mental health providers.

    mental health providers are also prohibited from billing for services rendered by an AI system.
  4. #4CriticalJan 1, 2027

    Applies to: Entities employing AI systems for utilization review.

    AI systems must base their determinations on an individual's medical or clinical history, individual clinical circumstances, and other relevant clinical information, explicitly prohibiting decisions based solely on group data
  5. #5CriticalJan 1, 2027

    Applies to: Entities using AI systems in utilization review.

    AI systems in utilization review must not be used in any way that discriminates against individuals
  6. #6CriticalJan 1, 2027

    Applies to: Entities utilizing AI in utilization review.

    Entities that deploy AI systems for utilization review are mandated to provide written disclosures to relevant state agencies...
  7. #7CriticalJan 1, 2027

    Applies to: Entities using AI systems in utilization review.

    These disclosures must detail... the methods for maintaining audit information to demonstrate compliance with the Act's stipulations.
  8. #8ImportantJan 1, 2027

    Applies to: Entities deploying AI systems in healthcare.

© Regulations.AI — created on 09-Jun-2026 using Gemini 2.5 Flash