Colorado Chatbot Safety Act
Concerning requirements for an operator of a conversational artificial intelligence service.
United States • Colorado
RAI-US-CO-HB26126-2026HB 26-1263
Colorado HB 26-1263 mandates transparency, age estimation, and safety protocols for conversational AI services to protect consumers and minors.
Summary
Read full text ↗Plain English
Overview
Colorado House Bill 26-1263, officially titled "Concerning requirements for an operator of a conversational artificial intelligence service," represents a significant legislative effort by the State of Colorado to regulate the burgeoning field of conversational artificial intelligence (AI). Enacted in 2026, this bill is designed to establish clear guidelines and obligations for entities that develop, make available, or control access to AI systems capable of simulating human conversation. The primary objective is to safeguard consumers, particularly minors, from potential harms associated with these technologies, such as misrepresentation, exposure to inappropriate content, and the development of unhealthy emotional dependencies. The legislation mandates various disclosures, safety protocols, and reporting mechanisms, reflecting a proactive approach to AI governance at the state level.
Unlike broader AI regulations that address automated decision-making across various sectors, HB 1263 specifically targets conversational AI services, often referred to as chatbots. This targeted approach underscores the unique risks and challenges posed by AI systems that directly interact with users in a conversational manner. The bill's provisions are set to become effective on January 1, 2027, allowing operators a period to implement the necessary technical and operational changes. Enforcement of the act will fall under the purview of the Colorado Attorney General's office, with violations classified as deceptive trade practices under the Colorado Consumer Protection Act, carrying civil penalties.
Definitions
Central to Colorado HB 26-1263 are its definitions, which precisely delineate the scope of the regulation. The bill defines a 'conversational artificial intelligence service' as an artificial intelligence system that is accessible to the general public and that primarily simulates human conversation and interaction through adaptive textual, visual, or aural communications. This definition is crucial as it distinguishes the regulated AI systems from other forms of AI that may not engage in direct, simulated human conversation. The emphasis on general public accessibility and the primary function of simulating human interaction through various communication modalities ensures that the law targets widely available chatbot technologies.
An 'operator' is defined as a person, partnership, corporation, or entity that develops and makes publicly available a conversational artificial intelligence service or offers such a service to a consumer. This broad definition ensures comprehensive coverage, encompassing both the developers of these AI systems and the entities that deploy or provide access to them for end-users. The bill also refers to 'account holders' and 'users,' differentiating between those who create an account or profile for the service and other individuals who interact with it. These clear definitions are fundamental to establishing accountability and ensuring that the regulatory requirements are applied consistently across the relevant entities and technologies within the state of Colorado.
Governance and Institutional Framework
The governance and institutional framework for Colorado HB 26-1263 primarily designates the Colorado Attorney General's office as the key authority responsible for oversight and enforcement. This centralized enforcement mechanism aims to ensure consistent application of the bill's provisions across all regulated conversational AI service operators. The Attorney General's office is tasked with receiving and publishing annual reports from operators regarding their protocols for addressing user prompts related to suicidal ideation or self-harm. This reporting requirement is a cornerstone of the bill's oversight framework, providing a transparent mechanism for monitoring compliance with critical safety measures.
By classifying violations of the act as deceptive trade practices under the 'Colorado Consumer Protection Act,' the bill leverages existing legal structures for enforcement. This approach allows the Attorney General to utilize established investigative and prosecutorial powers to address non-compliance, including the imposition of civil penalties. The framework also implies a role for ongoing engagement between the Attorney General's office and industry stakeholders, potentially through rulemaking or interpretive guidance, to clarify the practical application of the bill's requirements as AI technology evolves. The emphasis on consumer protection through an existing legal framework provides a robust foundation for the effective governance of conversational AI services in Colorado.
Key Focus Areas
Colorado HB 26-1263 establishes several key focus areas to regulate conversational AI services, with a strong emphasis on consumer protection and the well-being of minors. A primary focus is on transparency and disclosure, requiring operators to clearly and conspicuously inform users, persistently and responsively, that they are interacting with an artificial intelligence service, not a human. This fundamental requirement aims to prevent user deception and foster an understanding of the nature of the interaction.
Another critical area is the protection of minors. Operators are mandated to use commercially reasonable or generally accepted methods to estimate the age of users. For known minor users, the bill imposes stringent requirements: prohibiting incentives for increased engagement, implementing technically feasible measures to prevent the generation of sexually explicit content or statements simulating emotional dependence, and providing tools for minors or their parents/guardians to manage privacy and account settings. Furthermore, the bill addresses safety protocols for vulnerable users, specifically requiring operators to implement a protocol for user prompts regarding suicidal ideation or self-harm, which must include referring the user to crisis service providers. Lastly, the act prohibits operators from misrepresenting AI output as being provided by, endorsed by, or equivalent to services offered by licensed or certified professionals in fields such as healthcare, legal, accounting, or financial services, thereby preventing the unauthorized practice of professions and protecting consumers from potentially harmful or misleading advice.
Implementation Framework
The implementation framework for Colorado HB 26-1263 outlines the practical steps and operational requirements that conversational AI service operators must undertake to comply with the new regulations. A foundational element is the requirement for operators to employ commercially reasonable or generally accepted methods for age estimation of consumers, including both account holders and other users. This is critical for triggering the specific protections afforded to minors under the act. Once a user is identified as a minor, operators must institute a series of technically feasible measures, such as preventing the AI from generating sexually explicit content, intimate digital depictions, or statements that simulate emotional dependence.
Beyond technical safeguards, the framework mandates clear and persistent consumer disclosures, ensuring that all users are aware they are interacting with an AI service. For minor users, these disclosures must be repetitive and responsive. Operators are also required to develop and implement a robust protocol for responding to user prompts regarding suicidal ideation or self-harm, which must include direct referrals to crisis service providers. This necessitates the integration of detection mechanisms and pre-defined response pathways within the AI service. Furthermore, operators must provide privacy and account management tools for minors or their parents/guardians, empowering them to control their interactions and data. The prohibition against false professional representation also forms a key part of the implementation, requiring careful review of AI output and marketing claims to ensure no implication of professional endorsement or equivalency.
Monitoring and Evaluation
Monitoring and evaluation under Colorado HB 26-1263 are primarily centered on the annual reporting requirements imposed on conversational AI service operators. The act mandates that operators submit an annual report to the Colorado Attorney General's office. This report must contain specific information regarding the protocols the operator is implementing for user prompts concerning suicidal ideation or self-harm. This data collection is crucial for the Attorney General to assess the effectiveness and prevalence of these critical safety measures across the industry.
In a move towards greater transparency and public accountability, the bill also requires the Attorney General's office to publish the information received in these annual reports on its website. This public posting allows for broader scrutiny and evaluation of how operators are addressing serious safety concerns, such as suicide prevention. While the bill does not explicitly detail a continuous audit or independent evaluation mechanism, the annual reporting and public disclosure serve as the primary tools for monitoring compliance and identifying potential areas for improvement or further regulatory action. This framework aims to foster a cycle of continuous improvement in AI safety and responsible operation through mandated transparency and governmental oversight.
Penalties, Liability, and Appeals
Colorado HB 26-1263 establishes clear provisions regarding penalties and liability for non-compliance, underscoring the state's commitment to enforcing its conversational AI regulations. A violation of any of the requirements set forth in the bill is explicitly categorized as a deceptive trade practice under the 'Colorado Consumer Protection Act'. This classification is significant as it leverages an existing and well-established legal framework for enforcement, providing the Attorney General with a clear pathway to pursue legal action against non-compliant operators.
Operators found in violation of the act are subject to civil penalties. The bill specifies that a person or entity committing a deceptive trade practice under these provisions may face a civil penalty of $1,000, with some sources indicating it could be up to $5,000 per violation. Furthermore, additional penalties may be imposed for subsequent violations of a court order or injunction, indicating a tiered enforcement approach designed to deter repeat offenses. The act does not explicitly detail an appeals process within its text, implying that appeals would follow the standard procedures established under the Colorado Consumer Protection Act for challenging findings of deceptive trade practices and associated penalties. This integration into existing consumer protection law provides a familiar legal avenue for both enforcement and potential redress.
Relationship to Other Instruments
Colorado HB 26-1263 operates within a broader, evolving landscape of AI regulation, both within Colorado and at the national level. It is crucial to distinguish HB 1263 from other significant AI legislation in Colorado, particularly Senate Bill 26-189 (the Revised Colorado AI Act), which was signed into law around the same time. While both address AI, they have distinct scopes. SB 26-189 focuses on automated decision-making technologies (ADMT) that materially influence consequential decisions, such as in employment, housing, and financial services, and aims to prevent algorithmic discrimination.
In contrast, HB 1263 is specifically tailored to conversational artificial intelligence services, addressing unique concerns related to simulated human interaction, particularly concerning minors and vulnerable users. The two bills are complementary rather than overlapping, with HB 1263 filling a specific regulatory niche for chatbots and interactive AI. This targeted approach reflects a growing trend in state-level AI regulation to address specific AI applications or risks, rather than attempting a single, comprehensive framework for all AI. The bill also implicitly aligns with broader principles of consumer protection and child safety found in existing state and federal laws, enhancing protections in the context of emerging AI technologies without repealing or directly amending those broader statutes.
National/Federal Alignment
Colorado HB 26-1263 contributes to the growing patchwork of state-level AI regulations in the United States, in the absence of a comprehensive federal framework. While there is no direct federal law specifically regulating conversational AI in the same manner as HB 1263, the bill aligns with general federal priorities concerning consumer protection, child safety, and preventing deceptive practices. Federal agencies like the Federal Trade Commission (FTC) have expressed concerns about AI-driven deception and the impact on vulnerable populations, which resonate with HB 1263's mandates for disclosures and protections for minors.
The Colorado bill's focus on transparency, age-appropriate safeguards, and protocols for self-harm aligns with broader societal expectations for responsible technology development and deployment. This state-level action can also serve as a model or influence future federal discussions on AI regulation, demonstrating practical approaches to specific AI challenges. However, the fragmented nature of state-by-state AI laws also presents challenges for operators, who must navigate varying requirements across different jurisdictions. As federal discussions on AI continue, there may be future efforts to harmonize state laws or establish a baseline federal standard, which could impact the long-term alignment and interpretation of bills like Colorado HB 26-1263.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Bill Introduced | 2026-02-19 | House Bill 26-1263 introduced in the Colorado House of Representatives. |
| Passed House | 2026-03-26 | Referred to Committee of the Whole, then passed by the House. |
| Passed Senate | 2026-05-05 | Referred to Committee of the Whole, then passed by the Senate. |
| Sent to Governor | 2026-05-28 | Bill sent to the Governor for signature. |
| Effective Date | 2027-01-01 | Requirements for operators of conversational AI services become effective. |
| Annual Reporting Begins | Annually from 2027 | Operators required to submit annual reports to the Attorney General's office. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Age Estimation | Implement commercially reasonable or generally accepted methods to estimate the age of all users of conversational AI services. |
| General Disclosure | Clearly and conspicuously disclose to all users, persistently and responsively, that they are interacting with an artificial intelligence service. |
| Minor User Disclosures | For known minor users, provide persistent, repetitive, and responsive disclosures that they are interacting with AI. |
| No Minor Incentives | Prohibit providing points or rewards to minor account holders or users to encourage engagement with the AI service. |
| Content Prevention (Minors) | Institute technically feasible measures to prevent the AI service from producing sexually explicit content, intimate digital depictions, or statements that simulate emotional dependence for minor users. |
| Self-Harm Protocol | Implement a protocol for user prompts regarding suicidal ideation or self-harm, ensuring referral to crisis service providers. |
| Professional Misrepresentation | Prohibit indicating or implying that AI output is provided by, endorsed by, or equivalent to services from licensed professionals (e.g., healthcare, legal, financial). |
| Minor Privacy Tools | Provide tools for minor account holders/users or their parents/guardians to manage privacy and account settings. |
| Annual Reporting | Submit an annual report to the Attorney General's office detailing protocols for user prompts regarding suicidal ideation or self-harm. |
Sources and References
| Source | Type |
|---|---|
| HB26-1263 Conversational AI Service Operator Requirements | Colorado General Assembly | official |
| HB 26-1263: CONVERSATIONAL AI SERVICE OPERATOR REQUIREMENTS - Colorado General Assembly | official |
| CO HB1263 - BillTrack50 | legal |
Colorado's new law, HB 26-1263, sets rules for companies operating conversational artificial intelligence (AI) services, often called chatbots, to protect consumers, especially minors. This law applies to any person or entity that develops, makes available, or controls access to AI systems accessible to the general public that primarily simulate human conversation through text, visuals, or audio.
Starting January 1, 2027, operators of these services must meet several key requirements. First, they must clearly and persistently tell users they are interacting with an AI, not a human. Second, they need to use reasonable methods to estimate user age. For known minor users, the rules are stricter: operators cannot offer incentives for engagement, must prevent the AI from generating sexually explicit content or statements simulating emotional dependence, and provide tools for minors or their guardians to manage privacy. Third, operators must have a protocol for handling user prompts about suicidal thoughts or self-harm, including referring users to crisis services. Finally, the law prohibits misrepresenting AI output as coming from or being endorsed by licensed professionals like doctors or lawyers.
The Colorado Attorney General's office will enforce this law, treating violations as deceptive trade practices under the Colorado Consumer Protection Act. Companies found in violation face civil penalties, starting at $1,000 per offense, with higher fines for repeat issues. A practical surprise for many operators might be the annual requirement to report their self-harm protocols to the Attorney General, which will then be made public. This means your safety measures will be under public scrutiny, pushing for robust and transparent practices.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 9 marked completePlain-English obligations under Colorado Chatbot Safety Act. Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Jan 1, 2027
Applies to: Operators of conversational AI services accessible to the general public.
“Operators are mandated to use commercially reasonable or generally accepted methods to estimate the age of users.”
- #2Critical⏰ Jan 1, 2027
Applies to: Operators of conversational AI services accessible to the general public.
“clearly and conspicuously inform users, persistently and responsively, that they are interacting with an artificial intelligence service, not a human.”
- #3Critical⏰ Jan 1, 2027
Applies to: Operators of conversational AI services with known minor users.
“For known minor users, these disclosures must be repetitive and responsive.”
- #4Critical⏰ Jan 1, 2027
Applies to: Operators of conversational AI services with known minor users.
“prohibiting incentives for increased engagement”
- #5Critical⏰ Jan 1, 2027
Applies to: Operators of conversational AI services with known minor users.
“implementing technically feasible measures to prevent the generation of sexually explicit content or statements simulating emotional dependence”
- #6Critical⏰ Jan 1, 2027
Applies to: Operators of conversational AI services accessible to the general public.
“implement a protocol for user prompts regarding suicidal ideation or self-harm, which must include referring the user to crisis service providers.”
- #7Critical⏰ Jan 1, 2027
Applies to: Operators of conversational AI services accessible to the general public.
“prohibits operators from misrepresenting AI output as being provided by, endorsed by, or equivalent to services offered by licensed or certified professionals”
- #8Critical⏰ Jan 1, 2027
Applies to: Operators of conversational AI services with known minor users.
“provide tools for minors or their parents/guardians to manage privacy and account settings.”
- #9Critical⏰ Annually from 2027
Applies to: Operators of conversational AI services accessible to the general public.
“operators submit an annual report to the Colorado Attorney General's office. This report must contain specific information regarding the protocols”
Related Regulations
Concerning the use of artificial intelligence in health care.
Colorado, United States93% similar
Idaho S 1297 - Conversational AI Safety Act
United States92% similar
Idaho S 1297 - Conversational AI Safety Act
United States92% similar
Georgia Conversational Artificial Intelligence Safety Act
Georgia, United States92% similar
A bill for an act establishing requirements and guidelines for conversational AI services, and providing civil penalties, and including applicability provisions.
Iowa, United States92% similar
© Regulations.AI — created on 09-Jun-2026 using Gemini 2.5 Flash