AAI Compliance Atlas
FrameworksState lawsIndustriesToolsNews
GuidesMap my obligations →
AAI Compliance Atlas

Structured, continuously verified reference for US AI compliance — federal frameworks, state laws, and the obligations that connect them.

Atlas

  • Frameworks
  • State laws
  • Industries
  • By role
  • Comparisons

Tools

  • Compliance Checker
  • Penalty Calculator
  • Impact Assessment
  • Vendor Questionnaire

Resources

  • Guides
  • News
  • Blog
  • Methodology

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 AI Compliance Atlas. Informational only — not legal advice. Consult qualified counsel before making compliance decisions.Verified Jul 28, 2026
  1. Home/
  2. Colorado/
  3. Colorado Artificial Intelligence Act
Effective soonSB 24-205Colorado

Colorado Artificial Intelligence Act

Compliance reference — obligations, penalties, applicability, and primary sources.

Last verified June 17, 2026

Effective
January 1, 2027
Max penalty
$20K
Applies to
developer + deployer
Status
Effective soon

Summary

Status update (verified 2026-06-17): Colorado's original AI Act, SB 24-205, did not take effect as first scheduled. A federal court paused enforcement on April 27, 2026, and on May 14, 2026 Governor Polis signed SB 26-189 ("Automated Decision-Making Technology"), which repeals and reenacts the SB 24-205 framework as a narrower automated-decision-making-technology regime effective January 1, 2027. The sections below describe both the framework as originally enacted and the 2026 developments that changed it.

What the Colorado AI Act regulates

The Colorado Artificial Intelligence Act governs developers and deployers of "high-risk artificial intelligence systems" — AI that makes, or is a substantial factor in making, a consequential decision affecting Colorado consumers. Consequential decisions are those that materially affect access to housing, employment, education, financial or lending services, essential government services, health care, insurance, or legal services.

2026 litigation, enforcement stay, and SB 26-189

A sequence of 2026 events overtook SB 24-205's original February 1, 2026 implementation date, which had already been postponed to June 30, 2026 by SB25B-004:

  • April 9, 2026 — xAI filed a federal constitutional challenge to the Act, raising First Amendment compelled-speech, Dormant Commerce Clause, due-process vagueness, and equal-protection arguments.
  • April 24, 2026 — the U.S. Department of Justice moved to intervene against the Act, the first DOJ intervention in a state AI-law challenge, following federal Executive Order 14365 directing DOJ involvement in such cases.
  • April 27, 2026 — a federal court paused enforcement; the Colorado Attorney General will not open investigations or enforcement actions while the matter is stayed.
  • May 14, 2026 — Governor Polis signed SB 26-189 (Chapter 131 of the 2026 Session Laws), repealing and reenacting the SB 24-205 framework as an automated-decision-making-technology (ADMT) regime effective January 1, 2027.

These facts are drawn from the Colorado General Assembly bill pages (leg.colorado.gov, retrieved 2026-06-17) and contemporaneous regulatory trackers; compliance programs should confirm current status with the Colorado Attorney General before treating any obligation as enforceable or assigning it to an AI compliance framework.

High-risk AI systems and consequential decisions

Under SB 24-205 as enacted, a system is "high-risk" when it is a substantial factor in a consequential decision. General-purpose features, narrow procedural tasks, and several enumerated technologies (such as anti-fraud and cybersecurity tools) were excluded unless they themselves make consequential decisions. SB 26-189 reframes the covered technology as "automated decision-making technology" used in the same consequential-decision domains.

Developer and deployer duties

As originally enacted, SB 24-205 imposed three core duties: developers had to give deployers the documentation needed to evaluate a system and complete impact assessments; deployers had to use reasonable care to avoid algorithmic discrimination and complete annual impact assessments; and deployers had to disclose to consumers when a high-risk system was used in a consequential decision.

SB 26-189 narrows these duties. Developers must provide technical documentation to deployers beginning January 1, 2027, and deployers must notify consumers of ADMT use and disclose the technology's role within 30 days of an adverse outcome. The reenacted framework drops SB 24-205's standalone annual impact-assessment mandate and its broad algorithmic-discrimination duty.

Impact assessments

SB 24-205 required deployers to complete an impact assessment of each high-risk system at least annually and after any intentional, substantial modification, covering the system's purpose, known risks of algorithmic discrimination, categories of data processed, performance metrics, transparency measures, and post-deployment monitoring. SB 26-189's ADMT framework replaces that standalone assessment obligation with documentation- and notice-centered duties; programs that already built SB 24-205 impact-assessment workflows can repurpose them as evidence of reasonable care.

Consumer disclosures and rights

Consumers covered by the framework are entitled to be told when automated technology is used in a consequential decision, to receive an explanation when a decision is adverse, to correct inaccurate personal data the system relied on, and to request meaningful human review where technically feasible.

Enforcement and penalties

Both SB 24-205 and SB 26-189 are enforced exclusively by the Colorado Attorney General as deceptive trade practices under the Colorado Consumer Protection Act; neither creates a private right of action. Civil penalties run up to $20,000 per violation under C.R.S. § 6-1-112. Enforcement under SB 26-189 is contingent on the Attorney General completing rulemaking, and enforcement of the original SB 24-205 framework is judicially stayed as described above.

Sector applicability

The consequential-decision categories enumerated above map directly to the industries most exposed under a Colorado-style automated-decision-making-technology regime. Compliance teams scoping controls by sector can start from the relevant Atlas industry hub: AI in insurance compliance for underwriting, rating, and claims-handling automation; financial services AI compliance for credit, lending, and account decisions; healthcare AI compliance for care, coverage, and eligibility determinations; HR and hiring AI compliance for employment decisions; and the housing, education, legal services, and government services hubs for the remaining enumerated consequential-decision categories. Because SB 26-189 turns on the type of decision rather than the sector, a single deployer can fall under more than one of these applicability areas at once. Related Atlas coverage: Utah AI Policy Act.

Colorado Artificial Intelligence Act by compliance topic

Focused breakdowns of each part of the law — obligations, scope, penalties, and disclosures — with the primary source behind every requirement.

  • Colorado Artificial Intelligence Act compliance checklist

    A step-by-step checklist of the obligations to satisfy, each tied to the statutory section behind it.

  • Who must comply with Colorado Artificial Intelligence Act

    The organizations, roles, and thresholds that bring an AI system within scope of the law.

  • Colorado Artificial Intelligence Act penalties and enforcement

    Civil penalty amounts, how violations are counted, and the enforcement path under the statute.

  • Colorado Artificial Intelligence Act disclosure requirements

    The notices and disclosures the law mandates, and which consumers, employees, or downstream parties must receive them.

  • Colorado Artificial Intelligence Act consumer rights

    The correction, appeal, and opt-out rights the law grants consumers affected by a regulated AI system.

Key obligations

Specific compliance requirements derived from the primary source. Each item links to the relevant statutory section where applicable.

  • DocumentationRole: developerC.R.S. § 6-1-1702

    On and after January 1, 2027, make available to each deployer of a covered automated decision-making technology (ADMT), in a form understandable to the deployer and protective of trade secrets, a statement of the system's intended and known harmful or inappropriate uses, the categories of data (including personal data) used to train it, its known limitations and risks, instructions for appropriate use, monitoring, and meaningful human review, and the information the deployer needs to satisfy its disclosure duties under § 6-1-1704; developers must also notify deployers of material updates and retain compliance records for at least three years.

    Deadlinefrom_2027-01-01

  • DisclosureRole: deployerC.R.S. § 6-1-1704(1)–(2)

    Before using a covered ADMT to materially influence a consequential decision, provide a clear and conspicuous notice to the consumer that automated decision-making technology is or will be used in a consequential decision affecting them, with instructions for obtaining further information; a prominent public notice kept reasonably accessible at points of consumer interaction satisfies this requirement.

    Deadlinebefore_decision

  • DisclosureRole: deployerC.R.S. § 6-1-1704(3)

    When a covered ADMT materially influences a consequential decision that results in an adverse outcome, provide the consumer, within 30 days of the decision, a plain-language description of the decision and the role the ADMT played, a simple process to request additional information (the system's name, version, developer, and the types, categories, and sources of personal data used), and an explanation of the consumer's correction and human-review rights under § 6-1-1705.

    Deadlinewithin_30_days_of_adverse_outcome

  • Consumer rightRole: deployerC.R.S. § 6-1-1705(1)

    On request from a consumer who experiences an adverse outcome, provide instructions to access and correct factually incorrect or materially inaccurate personal data used in the consequential decision (consistent with C.R.S. § 6-1-1306) and an opportunity for meaningful human review and reconsideration of the decision to the extent commercially reasonable; correction is not required for opinions, predictions, scores, or protected evaluations.

    Deadlineon_consumer_request

  • GovernanceRole: deployerC.R.S. § 6-1-1703

    Retain, for at least three years after a consequential decision, the records reasonably necessary to demonstrate compliance with Part 17 of article 1 of title 6 — including covered-ADMT version identifiers, changelogs, and documentation of material mitigation changes.

    Deadlineretain_3_years

Related comparisons

Use the side-by-side comparisons to see how this law interacts with adjacent US AI laws and governance frameworks.

  • Colorado AI Act vs Texas TRAIGA

    Compare scope, roles, penalties, and source-backed compliance evidence side by side.

  • Colorado AI Act vs NIST AI RMF

    Compare the law and framework records using the same source-backed entity data.

  • California SB 53 vs Colorado AI Act

    Compare source-backed law records, applicability, penalties, and compliance scope.

Related analysis

Deeper Atlas write-ups on how this law is being interpreted and operationalized.

  • What compliance teams should do before Colorado AI Act enforcement ramps up

    A practical pre-enforcement checklist — scoping, impact assessments, disclosures, and AG-facing records.

  • Mapping NIST AI RMF functions to U.S. state AI laws

    How the GOVERN-MAP-MEASURE-MANAGE functions line up with the Colorado AI Act obligations.

  • EU AI Act vs U.S. state laws — 5 operational differences that matter

    For teams operating in both regimes: concrete differences that change how a control set is built.

Build a compliance program around these obligations

A single law is one input to a broader program. These guides show how to assign accountability, map every obligation to a control, and split developer-versus-deployer duties across the systems a team operates.

  • AI governance: building an AI compliance program

    The operating model — owners, committee, decision rights, lifecycle gates — that turns a law into an accountable, auditable program anchored to the NIST AI RMF GOVERN function.

  • AI compliance framework: the regulatory control map

    How to map each AI system to the laws it triggers, the controls that satisfy them, and the evidence that proves the controls operate.

  • Deployer vs developer obligations

    Which duties attach to building an AI system versus putting one into use — the split most state AI laws turn on.

Operationalize Colorado Artificial Intelligence Act compliance with OneTrust

partner link

Map obligations to controls, run impact assessments, and maintain audit-ready evidence in a single platform used by hundreds of regulated enterprises.

See OneTrust AI Governance →

Frequently asked questions

When does Colorado Artificial Intelligence Act take effect?

Colorado Artificial Intelligence Act is scheduled to take effect on January 1, 2027.

What is the maximum penalty under Colorado Artificial Intelligence Act?

Up to $20K per violation under Colorado Artificial Intelligence Act.

Who must comply with Colorado Artificial Intelligence Act?

Colorado Artificial Intelligence Act applies to developer, deployer of AI systems within its jurisdictional scope.

Sources

Every fact above is sourced from the official primary source. Independent verification recommended before acting on the information.

  • Officialleg.colorado.gov — C.R.S. § 6-1-1701 to § 6-1-1709
  • leg.colorado.gov
  • leg.colorado.gov
  • leg.colorado.gov
  • coag.gov
  • leg.colorado.gov

Last reviewed June 17, 2026. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.

Legal disclaimer

This content is informational only and does not constitute legal advice. Laws change frequently and vary by jurisdiction. Consult qualified legal counsel before making compliance decisions. Information accuracy not guaranteed as of any specific date.

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.