Colorado AI Consumer Protections Act
Concerning Consumer Protections in Interactions with Artificial Intelligence Systems
United States • Colorado
RAI-US-CO-SB24205-2024SB 24-205
Colorado SB24-205, a pioneering AI consumer protection act, was enacted in May 2024 but later repealed and replaced by SB26-189 in May 2026.
Overview
Colorado Senate Bill 24-205, officially titled “Concerning Consumer Protections in Interactions with Artificial Intelligence Systems,” represented a pioneering legislative effort in the United States to regulate artificial intelligence, particularly focusing on high-risk AI systems. Enacted on May 17, 2024, the bill was designed to safeguard consumers from algorithmic discrimination stemming from the deployment of AI technologies that significantly influence consequential decisions. These decisions encompassed critical areas such as housing, lending, employment, education, and healthcare. The legislation sought to establish a comprehensive governance framework, imposing substantial responsibilities on both developers and deployers of AI systems operating within Colorado. Its original effective date was set for February 1, 2026, marking a significant stride towards proactive AI regulation at the state level.
However, it is crucial to note that while SB24-205 was a landmark piece of legislation, its trajectory was significantly altered. On May 14, 2026, before SB24-205 could officially take effect, Colorado Governor Jared Polis signed Senate Bill 26-189 into law. This subsequent legislation explicitly repealed and replaced SB24-205, effectively superseding its provisions. The new enactment, SB26-189, refined the original statute, postponed the effective date for AI regulations to January 1, 2027, and reoriented Colorado's regulatory approach. While SB24-205 laid the groundwork for a robust risk-management-centric framework, its successor, SB26-189, shifted towards a more limited structure emphasizing consumer transparency and rights related to consequential automated decision-making. Therefore, while understanding SB24-205 is essential for tracing the evolution of AI regulation in Colorado, its specific requirements are no longer in force, having been superseded.
Definitions
Central to Colorado SB24-205 were several key definitions that delineated the scope and applicability of the act. A primary concept was the “high-risk artificial intelligence system.” This term referred to any AI system that, when deployed, made or was a substantial factor in making a “consequential decision.” Consequential decisions were defined broadly to include those with a material legal or similarly significant effect on access to or terms of opportunities and services. Specifically, these included decisions related to employment, housing, credit, insurance, education, and healthcare. This classification was critical because the most stringent obligations under the act were reserved for systems falling into this high-risk category, reflecting the legislature's intent to focus regulatory efforts where potential harm to consumers was greatest.
Another fundamental definition was “algorithmic discrimination.” The act defined this as any condition where the use of an AI system resulted in unlawful differential treatment or impact based on protected classes under Colorado and federal law. These protected classes included, but were not limited to, race, disability, age, gender, religion, veteran status, and genetic information. The legislation notably clarified that using an AI system to expand an applicant pool to increase diversity or remedy historical discrimination would not constitute algorithmic discrimination. The act also clearly distinguished between a “developer,” defined as an entity that creates or substantially modifies an AI system, and a “deployer,” which was an entity that uses or makes available an AI system to make consequential decisions. These distinctions were crucial for assigning specific duties and responsibilities under the act, ensuring accountability across the AI development and deployment lifecycle.
Governance and Institutional Framework
The governance and institutional framework established by Colorado SB24-205 primarily vested authority in the Colorado Attorney General. The act granted the Attorney General exclusive authority to enforce its provisions and to promulgate rules necessary for its implementation. This included developing regulations concerning documentation requirements, consumer notice, impact assessments, risk management policies and programs, and the establishment of rebuttable presumptions and affirmative defenses. This centralized enforcement mechanism underscored the state's commitment to a consistent and unified approach to AI regulation, aiming to prevent a patchwork of interpretations across different agencies or jurisdictions within Colorado. The Attorney General's office was positioned as the primary arbiter and oversight body for ensuring compliance with the act's mandates, particularly regarding the prevention of algorithmic discrimination in high-risk AI systems.
While the Attorney General held exclusive enforcement authority, the act also outlined specific responsibilities for developers and deployers, effectively creating a distributed governance model where private entities were tasked with internal compliance. Developers were required to use reasonable care to protect consumers from known or foreseeable risks of algorithmic discrimination, necessitating robust internal documentation. Deployers, in turn, were mandated to implement comprehensive risk management policies and programs. This framework aimed to foster a culture of responsible AI development and deployment by integrating regulatory oversight with industry best practices. The Attorney General's rulemaking authority was intended to provide the necessary guidance and specificity for these entities to meet their obligations, ensuring that the act's principles translated into actionable compliance measures across various sectors utilizing high-risk AI.
Key Focus Areas
Colorado SB24-205 concentrated on several key areas to achieve its objective of consumer protection in the context of artificial intelligence. A central tenet was the imposition of a “duty of reasonable care” on both developers and deployers of high-risk AI systems. Developers were required to exercise reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of their systems. This duty extended to maintaining comprehensive documentation describing the AI system, its purpose, intended uses, and an assessment of its known or foreseeable risks of algorithmic discrimination. Deployers had a similar duty, extending to the deployment and use of high-risk AI systems, and were expected to implement robust risk management policies and programs.
Another critical focus area was risk management and impact assessments. Deployers were mandated to implement a risk management policy and program that was dynamic, iterative, and aligned with nationally or internationally recognized frameworks, such as the NIST AI Risk Management Framework or ISO/IEC 42001. This program was to include measures for identifying, evaluating, and mitigating risks of algorithmic discrimination. Furthermore, deployers were required to conduct annual impact assessments for each high-risk AI system they deployed. These assessments needed to detail the system's purpose, intended use cases, deployment context, and any expected benefits, while also identifying potential misuse or misapplication that could lead to discriminatory outcomes. The act also emphasized transparency and disclosure, requiring deployers to inform consumers when they were interacting with an AI system and to provide notice when an AI system made an adverse consequential decision, along with an opportunity to appeal.
Implementation Framework
The original implementation framework for Colorado SB24-205 was designed to introduce a phased approach to compliance, with most of its core provisions slated to become effective on February 1, 2026. This timeline was intended to provide developers and deployers of high-risk AI systems sufficient time to establish the necessary internal processes, policies, and documentation to meet the act's requirements. Key aspects of this framework included the development of internal risk management programs by deployers, the completion of initial impact assessments before the deployment of high-risk systems, and the establishment of mechanisms for consumer disclosure and appeal. The act also outlined specific criteria for demonstrating reasonable care, including adherence to recognized risk management frameworks and proactive measures to discover and correct violations.
However, as previously noted, the implementation framework for SB24-205 was superseded by the enactment of SB26-189 on May 14, 2026. This successor legislation effectively repealed SB24-205 and introduced a revised framework with a new effective date of January 1, 2027. While SB24-205's original framework focused heavily on proactive risk management obligations, SB26-189 shifted the emphasis towards consumer transparency and rights in the context of consequential automated decision-making. The Attorney General's rulemaking authority, initially granted under SB24-205, was carried over to SB26-189, indicating that the detailed operationalization of the law would still depend on subsequent regulatory guidance. Therefore, while SB24-205 laid the conceptual groundwork, its practical implementation framework was ultimately replaced before it could become operative.
Monitoring and Evaluation
Colorado SB24-205 placed significant emphasis on ongoing monitoring and evaluation as a core component of responsible AI governance. For deployers of high-risk artificial intelligence systems, the act mandated regular review processes to ensure continuous compliance and to identify any emerging risks of algorithmic discrimination. Specifically, deployers, or a third party contracted by them, were required to review the deployment of each high-risk AI system at least annually, starting on or before February 1, 2026. The primary objective of these reviews was to verify that the AI system was not causing algorithmic discrimination, thereby upholding the act's central consumer protection goals. This continuous evaluation mechanism was designed to ensure that AI systems remained compliant throughout their operational lifecycle, adapting to changes in data, models, or deployment contexts.
Beyond annual reviews, the act also required impact assessments to be completed not only before deployment but also within 90 days of any intentional and substantial modification to a high-risk AI system. This provision aimed to ensure that any changes to the system that could introduce new risks or alter existing ones were promptly evaluated for potential discriminatory outcomes. The documentation generated from these monitoring and evaluation activities, including impact assessments and risk management program details, was crucial for demonstrating a deployer's reasonable care and for potential scrutiny by the Attorney General. Although SB24-205 was later superseded, its focus on iterative monitoring and evaluation, along with regular assessments, established a foundational principle for AI accountability that influenced subsequent legislative efforts in Colorado.
Penalties, Liability, and Appeals
Under Colorado SB24-205, violations of the act's provisions were treated seriously, primarily by categorizing them as a “deceptive trade practice” under the existing Colorado Consumer Protection Act. This classification meant that the Colorado Attorney General, who held exclusive enforcement authority, could pursue actions against non-compliant entities, potentially leading to fines and other remedies available under consumer protection law. It is important to note that the act explicitly stated that it did not provide a private right of action for consumers, meaning individuals could not directly sue developers or deployers for violations of SB24-205. Enforcement was solely at the discretion of the Attorney General, who was also tasked with promulgating rules to implement the law.
The act also provided for certain affirmative defenses, offering pathways for developers and deployers to demonstrate compliance and mitigate potential liability. An affirmative defense could be established if the entity involved was in compliance with a nationally or internationally recognized risk management framework for artificial intelligence systems, as designated by the act or the Attorney General. Examples of such frameworks included the NIST AI Risk Management Framework or ISO/IEC 42001. Additionally, an affirmative defense was available if the entity took specified measures to discover and correct violations of the act. In terms of consumer rights, the act mandated that consumers subjected to an adverse consequential decision made or materially influenced by a high-risk AI system must be provided with an opportunity to appeal that decision. This appeal process could necessitate human review, ensuring a mechanism for redress for affected individuals.
Relationship to Other Instruments
Colorado SB24-205 was designed to integrate with and build upon existing legal frameworks, particularly within Colorado's consumer protection landscape. A key relationship was its connection to the “Colorado Consumer Protection Act.” The act explicitly stipulated that a violation of its provisions would constitute a “deceptive trade practice” under Section 6-1-105 of the Colorado Revised Statutes, which forms part of the broader Consumer Protection Act. This linkage provided a clear enforcement mechanism, allowing the Colorado Attorney General to utilize established legal tools and remedies to address non-compliance with AI-specific regulations. Furthermore, the act provided exemptions or deemed compliance for certain regulated entities, such as insurers and financial institutions, if they were already subject to specific laws, guidance, or regulations governing their use of external consumer data, algorithms, and predictive models, provided these met criteria specified in the act.
Crucially, the most significant relationship for SB24-205 is its supersession by Colorado Senate Bill 26-189. Signed into law on May 14, 2026, SB26-189 repealed and replaced SB24-205 entirely, before the latter's original effective date. This means that while SB24-205 represented Colorado's initial comprehensive attempt to regulate high-risk AI, its specific legal force and requirements have been nullified and replaced by the provisions of SB26-189. Therefore, any analysis of AI regulation in Colorado must now primarily refer to SB26-189, with SB24-205 serving as a historical precursor. Conceptually, SB24-205 also drew inspiration from international efforts, particularly borrowing concepts from the European Union's comprehensive AI Act, especially in its focus on high-risk systems and algorithmic discrimination, demonstrating an alignment with emerging global regulatory trends.
International Alignment
Colorado SB24-205 demonstrated a clear intent to align with and draw upon established or emerging international standards and frameworks for artificial intelligence governance. A prominent example of this alignment was the act's explicit reference to nationally or internationally recognized risk management frameworks. Deployers of high-risk AI systems were encouraged, and in some cases, effectively required, to implement risk management policies and programs that conformed to such frameworks. The legislation specifically mentioned the NIST AI Risk Management Framework (AI RMF) and ISO/IEC 42001 as examples of acceptable standards. This approach aimed to leverage existing expertise and best practices in risk management, promoting a harmonized approach to AI safety and accountability that transcends state borders.
Furthermore, SB24-205 was noted by legal observers for borrowing concepts from the European Union's comprehensive AI Act. This conceptual borrowing was particularly evident in its focus on regulating “high-risk AI systems” and its efforts to prevent “algorithmic discrimination.” By adopting similar classifications and regulatory principles, Colorado's initial AI legislation sought to align itself with a broader global movement towards robust AI governance, particularly in areas concerning fundamental rights and consumer protection. While the act was a state-level initiative, its design reflected an awareness of, and a desire to contribute to, a global dialogue on responsible AI development and deployment, anticipating future interstate and international harmonization efforts.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Bill Introduced | 2024-04-10 | Introduced in the Senate and assigned to Judiciary. |
| Passed Legislature | 2024-05-08 | Passed by the Colorado Legislature. |
| Governor Signed | 2024-05-17 | Signed into law by Governor Jared Polis. |
| Original Effective Date | 2026-02-01 | Initial date for most provisions to become operative. |
| Superseded by SB26-189 | 2026-05-14 | Colorado SB24-205 was repealed and replaced by SB26-189. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Duty of Reasonable Care (Developer) | Use reasonable care to protect consumers from known or foreseeable risks of algorithmic discrimination in intended and contracted uses of high-risk AI systems. |
| Duty of Reasonable Care (Deployer) | Use reasonable care to protect consumers from known or foreseeable risks of algorithmic discrimination in the deployment and use of high-risk AI systems. |
| Risk Management Program (Deployer) | Implement a comprehensive, dynamic, and iterative risk management policy and program for high-risk AI systems, aligned with recognized frameworks (e.g., NIST AI RMF, ISO/IEC 42001). |
| Impact Assessments (Deployer) | Conduct annual impact assessments for each high-risk AI system before deployment, annually, and within 90 days of substantial modification. |
| Consumer Disclosure (Interaction) | Ensure disclosure to consumers when they are interacting with an artificial intelligence system. |
| Consumer Disclosure (Adverse Decision) | Provide notice to consumers when an AI system is a substantial factor in an adverse consequential decision, including the reason for the decision and opportunity to correct data. |
| Right to Appeal (Consumer) | Offer consumers an opportunity to appeal adverse consequential decisions made or influenced by a high-risk AI system, potentially involving human review. |
| Documentation Maintenance | Maintain comprehensive documentation of high-risk AI systems, including purpose, intended uses, and risk assessments. |
Sources and References
| Source | Type |
|---|---|
| Colorado General Assembly: SB24-205 | official |
| Colorado SB24-205 Enrolled Bill Text | official |
| Colorado SB24-205 Initial Bill Text | official |
| Colorado SB24-205 Engrossed Bill Text | official |
| Governor Polis's Signing Statement for SB24-205 | official |
Related Regulations
Concerning Consumer Protections in Interactions with Artificial Intelligence Systems
Colorado, United States100% similar
Colorado SB24-205 — Consumer Protections for Artificial Intelligence Act
United States93% similar
Senate Bill 26-189 — A Bill Concerning the Use of Automated Decision-Making Technology in Consequential Decisions
Colorado, United States92% similar
Concerning the Use of Automated Decision-Making Technology in Consequential Decisions, and, in Connection Therewith, Making an Appropriation.
Colorado, United States89% similar
Increase Transparency for Algorithmic Systems
Colorado, United States89% similar
© Regulations.AI — created on 12-Jul-2026 using Gemini 2.5 Flash