Colorado Automated Decision-Making Technology Act
Concerning the Use of Automated Decision-Making Technology in Consequential Decisions, and, in Connection Therewith, Making an Appropriation.
United States • Colorado
RAI-US-CO-SB26189-2026SB 26-189
Colorado's SB 26-189 regulates automated decision-making in consequential decisions, emphasizing consumer rights and transparency, enforced by the Attorney General.
Summary
Read full text ↗Plain English
Overview
Colorado Senate Bill 26-189, officially titled "Concerning the Use of Automated Decision-Making Technology in Consequential Decisions, and, in Connection Therewith, Making an Appropriation," represents a significant legislative effort to regulate the rapidly evolving landscape of artificial intelligence and automated decision-making. Enacted on May 14, 2026, and set to become effective on January 1, 2027, this law repeals and replaces the state's previous Artificial Intelligence Act, Senate Bill 24-205, which had drawn criticism for its broad scope and burdensome compliance requirements. The new legislation shifts the regulatory focus from a comprehensive "high-risk artificial intelligence system" framework to a more targeted approach, specifically addressing "automated decision-making technology" (ADMT) that processes personal data to materially influence "consequential decisions" affecting consumers. This strategic pivot aims to balance innovation with robust consumer protections, particularly in critical sectors such as employment, housing, healthcare, and financial services.
The primary objective of SB 26-189 is to enhance transparency, accountability, and fairness in the deployment of ADMT. Unlike its predecessor, which mandated extensive risk management programs and impact assessments, the new law emphasizes consumer rights, including the right to notice, explanation of adverse outcomes, correction of inaccurate data, and meaningful human review. This procedural framework is designed to provide individuals with greater control and understanding when their lives are impacted by automated systems, without unduly stifling technological advancement. The law establishes clear obligations for both developers and deployers of ADMT, requiring them to provide specific disclosures and maintain records to demonstrate compliance. By narrowing the scope and refining the compliance mechanisms, Colorado seeks to create a more practical and enforceable regulatory environment for automated decision-making technologies, setting a precedent for other states grappling with similar challenges in AI governance.
Definitions
Central to the understanding and application of SB 26-189 are its precise definitions of key terms. "Automated Decision-Making Technology" (ADMT) is defined as technology that processes personal data and utilizes computation to generate outputs such as predictions, recommendations, classifications, rankings, or scores. These outputs are then used to make, guide, or assist a decision, judgment, or determination concerning an individual. The law explicitly excludes certain routine technologies from this definition, including anti-malware and anti-virus software, calculators, databases, firewalls, and spell-checking tools. It also carves out spreadsheets that require human analysis and do not employ machine learning or large language models, as well as tools used solely for summarizing, organizing, translating, drafting, or presenting information for human review. Chatbots are generally excluded if they are used for informational purposes, not contracted or marketed for consequential decisions, and are subject to an acceptable use policy prohibiting such applications.
A "consequential decision" is another critical definitional component, referring to a decision that materially affects a consumer's access to, eligibility for, selection for, or compensation in specific "covered domains". These domains encompass vital aspects of daily life, including education enrollment and opportunities, employment or employment opportunities, real estate transactions (lease or purchase of residential real estate), financial and lending services, insurance and access to benefits, health-care services, and essential government services and public benefits. The law also distinguishes between "developers" and "deployers." A "developer" is any person doing business in Colorado who develops, offers, sells, leases, licenses, or otherwise makes commercially available a covered ADMT, including individuals who develop components or substantially modify an ADMT. A "deployer" is defined as a person doing business in Colorado that deploys a covered ADMT. These distinctions are crucial for allocating responsibilities and liabilities under the Act.
Governance and Institutional Framework
The governance and institutional framework established by Colorado SB 26-189 designates the Colorado Attorney General as the exclusive enforcement authority for violations of the Act. This centralization of enforcement power ensures a consistent and coordinated approach to regulating automated decision-making technologies across the state. The law explicitly states that it does not create a new private right of action, meaning individuals cannot directly sue developers or deployers under this statute. Instead, all violations are considered deceptive trade practices and are pursued by the Attorney General under the Colorado Consumer Protection Act. This framework aims to prevent a proliferation of private litigation while still providing a robust mechanism for addressing harm caused by ADMT.
A significant aspect of the governance framework is the mandatory rulemaking process. The Attorney General is directed to adopt rules by January 1, 2027, to clarify various requirements of the Act. These rules are expected to provide detailed guidance on post-adverse outcome disclosure requirements and to further define what constitutes a "material influence" in consequential decisions, potentially including presumptions, illustrative examples, and objectives. This rulemaking is critical for the practical implementation and interpretation of the law, ensuring that both developers and deployers have clear guidelines for compliance. Furthermore, beginning in January 2028 and annually thereafter, the Attorney General is mandated to produce a report identifying enforcement actions brought under the Act and detailing the cure periods offered to alleged violators. This reporting requirement fosters transparency in enforcement and allows for ongoing evaluation of the law's effectiveness.
Key Focus Areas
Colorado SB 26-189 places a strong emphasis on consumer rights and transparency as its core regulatory principles for automated decision-making technology. One of the most impactful provisions is the requirement for deployers to provide clear and conspicuous notice to consumers at the point of interaction with a covered ADMT, informing them that a consequential decision will be influenced by such technology. This proactive disclosure is intended to empower consumers by making them aware of the role ADMT plays in decisions that significantly affect their lives. Beyond initial notice, the law mandates that if a covered ADMT makes a consequential decision resulting in an adverse outcome for a consumer, the deployer must provide a plain language description of the ADMT's role in that decision within 30 days. This explanation aims to demystify algorithmic processes and provide individuals with actionable information regarding decisions that impact them.
Further strengthening consumer protections, the Act grants individuals specific rights related to their personal data and the outcomes of ADMT-influenced decisions. Consumers have the right to request access to their personal data processed by a covered ADMT and, crucially, the right to request the correction of any materially incorrect personal data used by the system. This provision ensures data accuracy, which is fundamental to fair algorithmic outcomes. Moreover, the law establishes a right for consumers to request a meaningful human review and reconsideration following a consequential decision that results in an adverse outcome, where such review is commercially reasonable. This human oversight mechanism serves as a critical safeguard against potential algorithmic errors or biases, offering a pathway for redress and ensuring that human judgment can ultimately override automated decisions in critical circumstances. The law applies these protections across various consequential domains, including employment, housing, lending, insurance, healthcare, education, and essential government services.
Implementation Framework
The implementation framework of Colorado SB 26-189 delineates distinct, yet interconnected, obligations for both developers and deployers of automated decision-making technology (ADMT) to ensure compliance with the Act. Commencing January 1, 2027, developers of ADMT that is used to materially influence a consequential decision (i.e., a covered ADMT) are required to provide deployers with comprehensive technical documentation. This documentation must describe the covered ADMT's intended uses and any known harmful uses, the categories of training data utilized, known limitations, and clear instructions for appropriate use and meaningful human review by the deployer. Furthermore, developers are obligated to notify deployers of any material updates or modifications to the covered ADMT, ensuring that deployers always have current information regarding the systems they deploy. These requirements are designed to foster transparency throughout the ADMT supply chain and equip deployers with the necessary information to use these technologies responsibly.
Deployers, on the other hand, bear the primary responsibility for direct consumer interaction and compliance at the point of decision-making. As outlined in the key focus areas, deployers must provide clear and conspicuous notice to consumers before using a covered ADMT to materially influence a consequential decision. In the event of an adverse outcome resulting from such a decision, deployers are mandated to provide the affected consumer with a plain language description of the consequential decision and the ADMT's role within 30 days. This disclosure must also include instructions for consumers to request additional information about the ADMT and an explanation of their right to request personal data and correction of factually incorrect personal data, as well as the right to request meaningful human review. Both developers and deployers are subject to a record-retention obligation, requiring them to maintain records necessary to demonstrate compliance with the Act for a minimum of three years. This comprehensive framework aims to create a system of shared responsibility and accountability across the lifecycle of ADMT deployment.
Monitoring and Evaluation
The monitoring and evaluation mechanisms embedded within Colorado SB 26-189 are designed to ensure ongoing oversight and assessment of the Act's effectiveness in practice. A central component of this framework is the mandatory annual reporting requirement placed upon the Colorado Attorney General. Beginning in January 2028, and every January thereafter, the Attorney General is directed to produce a comprehensive report. This report must detail the enforcement actions brought under the Act during the preceding year, providing insights into the types of violations encountered, the sectors affected, and the outcomes of these actions. By publicly documenting enforcement activities, the state aims to foster transparency and allow stakeholders to understand how the law is being applied and where potential areas of concern or non-compliance may exist.
In addition to tracking enforcement actions, the Attorney General's annual report must also identify the cure periods offered to developers and deployers. The Act includes a provision allowing a 60-day notice and opportunity to cure alleged violations before formal enforcement action is initiated, a provision that is set to expire on January 1, 2030. By reporting on the utilization and effectiveness of these cure periods, the state can evaluate whether this mechanism is successfully promoting voluntary compliance and remediation of issues without immediately resorting to penalties. This ongoing monitoring and evaluation process, coupled with the Attorney General's mandatory rulemaking, suggests a dynamic regulatory approach that can adapt to new challenges and insights gleaned from real-world implementation. It provides a structured feedback loop to assess the law's impact on businesses and consumers, potentially informing future legislative adjustments or refinements to the regulatory framework.
Penalties, Liability, and Appeals
Colorado SB 26-189 establishes a clear framework for penalties, liability, and the absence of a private right of action, delineating how violations will be addressed. Crucially, the Act explicitly states that it does not create a new private right of action. This means that individuals who believe they have been harmed by a violation of the Act cannot directly sue the responsible developer or deployer. Instead, all violations are considered deceptive trade practices and fall under the exclusive enforcement authority of the Colorado Attorney General. This approach centralizes enforcement and aims to provide a consistent application of the law, preventing a fragmented landscape of private litigation.
Before initiating an enforcement action, particularly prior to January 1, 2030, the Attorney General is generally required to provide the developer or deployer with a 60-day notice and opportunity to cure the alleged violation, provided a cure is deemed possible. If the alleged violation is successfully cured within this period, the Attorney General may not seek civil penalties, although injunctive relief to prevent future violations remains an option. This cure period mechanism is intended to encourage prompt remediation and voluntary compliance. Regarding liability, the Act introduces a nuanced structure for allocating fault between developers and deployers in civil actions alleging unlawful discrimination under existing state anti-discrimination laws. Liability is based on proportional fault, rather than joint and several liability, meaning each party is responsible for their share of the fault. Developers are specifically liable if the technology was used as intended and materially influenced the consequential decision. Furthermore, the law includes a provision that voids contractual clauses purporting to indemnify a party for its own discriminatory acts related to Automated Decision-Making Technology, demanding immediate review of AI vendor contracts. This ensures that parties cannot contractually shift responsibility for their own unlawful conduct.
Relationship to Other Instruments
Colorado SB 26-189 fundamentally redefines the state's approach to AI regulation by repealing and reenacting the provisions of its predecessor, Senate Bill 24-205. The original SB 24-205, signed in May 2024, was the nation's first comprehensive state AI law, imposing broad obligations on developers and deployers of "high-risk artificial intelligence systems". However, it faced significant criticism from business stakeholders for its extensive risk-management obligations and impact assessment requirements, leading to calls for amendments and even a federal lawsuit challenging its constitutionality. SB 26-189 emerged from a working group convened in the fall of 2025, tasked with developing a replacement framework that addressed these concerns. The new law, therefore, is not merely an amendment but a complete overhaul, shifting away from the prescriptive risk-management approach towards a more targeted framework centered on transparency, disclosure, and consumer rights. This legislative evolution demonstrates a responsive effort to refine AI governance in light of practical implementation challenges and industry feedback.
Beyond its relationship with the prior state AI law, SB 26-189 also incorporates provisions that acknowledge and align with existing federal and state regulatory instruments. For instance, the Act includes sector-specific accommodations designed to integrate with established compliance frameworks. For educational institutions subject to the Family Educational Rights and Privacy Act (FERPA), the law specifies that existing student record processes for inspection, review, and amendment can satisfy the requirements of SB 26-189 related to data correction and human review. This integration aims to reduce duplicative compliance burdens for educational entities. Similarly, the amended law introduces accommodations for entities covered by the Health Insurance Portability and Accountability Act (HIPAA), as well as for insurers and creditors, and U.S. Food and Drug Administration-regulated medical devices. These sector-specific provisions highlight an effort to harmonize the state's AI regulations with existing industry-specific legal obligations, thereby streamlining compliance for regulated entities while still extending consumer protections where ADMT is used in consequential decisions.
National/Federal Alignment
Colorado SB 26-189's development and enactment occurred within a broader national context of evolving AI regulation and federal scrutiny. The original Colorado AI Act (SB 24-205) had garnered significant attention, including from the federal government. President Donald Trump's December 2025 executive order on "Ensuring a National Policy Framework for Artificial Intelligence" specifically named Colorado's initial law as an example of state regulation that could potentially stifle innovation. This executive order directed federal agencies to challenge state AI laws deemed inconsistent with federal deregulatory policy. Furthermore, a federal magistrate judge stayed enforcement of SB 24-205 in April 2026, and the U.S. Department of Justice intervened in a lawsuit challenging its constitutionality, signaling strong federal opposition to the initial, broader regulatory approach.
In response to this federal pressure and significant feedback from industry stakeholders, SB 26-189 represents a strategic recalibration by the state of Colorado. By repealing and replacing the original law with a narrower, more targeted framework focused on consumer disclosures, data correction, and human review, the state has moved away from the more prescriptive risk management and impact assessment requirements that were a point of contention. This shift may be interpreted as an attempt to achieve a greater degree of alignment, or at least reduce conflict, with potential federal AI policies that might favor a less burdensome regulatory environment. While SB 26-189 still establishes comprehensive state-level requirements, its refined scope and emphasis on transparency over extensive governance programs could be seen as a more harmonized approach that addresses consumer protection concerns without triggering as much federal opposition, allowing Colorado to maintain its role as a leader in state-level AI regulation while navigating the complexities of national policy discussions.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Bill Passed Legislature | 2026-05-09 | Passed by the House on third reading. |
| Governor Signed into Law | 2026-05-14 | Governor Jared Polis signed SB 26-189 into law. |
| Effective Date of Law | 2027-01-01 | The law becomes effective. |
| Attorney General Rulemaking Deadline | 2027-01-01 | Attorney General must adopt rules clarifying requirements. |
| Attorney General Annual Reporting Begins | 2028-01-01 | First annual report on enforcement actions and cure periods due. |
| 60-day Cure Period Expiration | 2030-01-01 | The provision for a 60-day cure period before enforcement expires. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Developer Obligations | |
| Provide Technical Documentation | For covered ADMT, provide deployers with documentation on intended uses, training data, known limitations, and instructions for appropriate use and human review. |
| Notify of Material Updates | Inform deployers of any material updates or modifications to the covered ADMT. |
| Retain Records | Maintain records demonstrating compliance for at least three years. |
| Deployer Obligations | |
| Provide Consumer Notice | Provide clear and conspicuous notice to consumers at the point of interaction with a covered ADMT when it will materially influence a consequential decision. |
| Provide Post-Adverse Outcome Explanation | Within 30 days of an adverse outcome from a covered ADMT, provide a plain language description of the decision and the ADMT's role. |
| Inform of Consumer Rights | In post-adverse outcome notices, explain consumer rights to request additional ADMT information, correct inaccurate personal data, and request meaningful human review. |
| Facilitate Data Correction | Establish processes for consumers to request correction of materially inaccurate personal data used by a covered ADMT. |
| Facilitate Human Review | Provide a mechanism for consumers to request meaningful human review and reconsideration of adverse outcomes where commercially reasonable. |
| Retain Records | Maintain records demonstrating compliance for at least three years. |
| General Compliance | |
| Review ADMT Systems | Inventory all automated decision-making tools in use or under development that could materially influence consequential decisions in covered domains. |
| Assess Developer/Deployer Status | Clearly identify whether your organization acts as a developer, deployer, or both. |
| Review Vendor Contracts | Examine existing AI vendor contracts for indemnification clauses, as those purporting to indemnify a party for its own discriminatory ADMT-related acts are voided. |
| Monitor AG Rulemaking | Stay informed about the Attorney General's mandatory rulemaking process for clarification of requirements by January 1, 2027. |
Sources and References
| Source | Type |
|---|---|
| Colorado General Assembly - SB26-189 Automated Decision-Making Technology | legal |
Colorado's new law, Senate Bill 26-189, regulates how companies use automated decision-making technology (ADMT) when making important "consequential decisions" that affect Colorado residents, including employees and job applicants.
Taking effect on January 1, 2027, this law applies to "developers" who create ADMT and "deployers" who use it, if their technology processes personal data to make, guide, or assist decisions impacting an individual's access to or eligibility for critical services like education, employment, housing, financial services, insurance, healthcare, or government benefits. This broad scope means many businesses using artificial intelligence for hiring, lending, or patient care will be affected.
The law imposes several key obligations. Developers must provide deployers with detailed technical documentation about their ADMT, including its intended uses, training data, known limitations, and instructions for human review. Deployers, in turn, must give clear notice to consumers when ADMT is used in a consequential decision. If an ADMT leads to an "adverse outcome" – such as denying a loan or job – deployers must provide a plain language explanation of the ADMT's role within 30 days. Consumers also gain important rights: they can request access to and correction of factually incorrect personal data used by the ADMT, and they have the right to request meaningful human review and reconsideration of adverse decisions. Both developers and deployers must keep records demonstrating compliance for at least three years.
Enforcement is exclusively handled by the Colorado Attorney General, with violations treated as deceptive trade practices. Before January 1, 2030, the Attorney General must provide a 60-day period to cure alleged violations before seeking civil penalties, though injunctive relief is still possible. After this date, the cure period may be bypassed for knowing or repeat violations. A key surprise is that the law explicitly extends protections to employees and job applicants, a group often excluded from general privacy laws, making it crucial for HR tech and hiring platforms. Businesses should also closely watch the Attorney General's rules, due by January 1, 2027, which will provide vital practical guidance.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
Read this article-by-article
Plain-English breakdown of 9 key articles, with cross-jurisdiction equivalents where applicable.
What you must do — compliance checklist
0 / 11 marked completePlain-English obligations under Colorado Automated Decision-Making Technology Act. Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Jan 1, 2027
Applies to: Developers of automated decision-making technology.
“For developers, the Act mandates that, starting January 1, 2027, they must provide deployers with comprehensive technical documentation for any covered ADMT.”
- #2Critical⏰ Jan 1, 2027
Applies to: Deployers of automated decision-making technology.
“Deployers... are required to provide clear and conspicuous notice to consumers at the point of interaction with a covered ADMT.”
- #3Critical⏰ Within 30 days of adverse outcome
Applies to: Deployers of automated decision-making technology.
“the deployer must provide a plain language description of the ADMT's role in that decision within 30 days.”
- #4Critical⏰ Jan 1, 2027
Applies to: Deployers of automated decision-making technology.
“Consumers also have the right to request meaningful human review and reconsideration following an adverse outcome.”
- #5Critical⏰ Jan 1, 2027
Applies to: Deployers of automated decision-making technology.
“Consumers also have the right to request access to and correction of factually incorrect personal data used by a covered ADMT.”
- #6Critical⏰ Jan 1, 2027
Applies to: Developers and deployers of automated decision-making technology.
“Both developers and deployers are also subject to a three-year record retention requirement.”
- #7Critical⏰ Jan 1, 2027
Applies to: Developers and deployers of automated decision-making technology.
“The use of an ADMT is not a shield against claims of discrimination under these pre-existing legal frameworks.”
- #8Critical⏰ Jan 1, 2027
Applies to: Developers and deployers of automated decision-making technology.
“indemnification provisions... that attempt to shield either party from liability under relevant discrimination laws are explicitly declared void.”
- #9Important⏰ Jan 1, 2027
Applies to: Developers of automated decision-making technology.
“developers are required to notify deployers of any material updates or modifications to the covered ADMT.”
- #10Important⏰ Within 60 days of notice
Applies to: Developers and deployers of automated decision-making technology.
“granting them a 60-day period to cure the violation. If the alleged violation is cured... the Attorney General is precluded from seeking civil penalties.”
- #11Important⏰ Jan 1, 2027
Applies to: Developers and deployers of automated decision-making technology.
“The Act mandates that the Attorney General's office adopt rules to clarify and implement the requirements of the law by January 1, 2027.”
Related Regulations
Senate Bill 26-189 — A Bill Concerning the Use of Automated Decision-Making Technology in Consequential Decisions
Colorado, United States95% similar
Colorado SB24-205 — Consumer Protections for Artificial Intelligence Act
United States94% similar
Increase Transparency for Algorithmic Systems
Colorado, United States93% similar
Concerning the use of artificial intelligence in health care.
Colorado, United States92% similar
Colorado SB 21-169 - AI in Insurance Underwriting
United States92% similar
© Regulations.AI — created on 27-May-2026 using Gemini 2.5 Flash