When does Colorado Artificial Intelligence Act take effect?
Colorado Artificial Intelligence Act is scheduled to take effect on January 1, 2027.
Compliance reference — obligations, penalties, applicability, and primary sources.
Last verified June 17, 2026
Status update (verified 2026-06-17): Colorado's original AI Act, SB 24-205, did not take effect as first scheduled. A federal court paused enforcement on April 27, 2026, and on May 14, 2026 Governor Polis signed SB 26-189 ("Automated Decision-Making Technology"), which repeals and reenacts the SB 24-205 framework as a narrower automated-decision-making-technology regime effective January 1, 2027. The sections below describe both the framework as originally enacted and the 2026 developments that changed it.
The Colorado Artificial Intelligence Act governs developers and deployers of "high-risk artificial intelligence systems" — AI that makes, or is a substantial factor in making, a consequential decision affecting Colorado consumers. Consequential decisions are those that materially affect access to housing, employment, education, financial or lending services, essential government services, health care, insurance, or legal services.
A sequence of 2026 events overtook SB 24-205's original February 1, 2026 implementation date, which had already been postponed to June 30, 2026 by SB25B-004:
These facts are drawn from the Colorado General Assembly bill pages (leg.colorado.gov, retrieved 2026-06-17) and contemporaneous regulatory trackers; compliance programs should confirm current status with the Colorado Attorney General before treating any obligation as enforceable or assigning it to an AI compliance framework.
Under SB 24-205 as enacted, a system is "high-risk" when it is a substantial factor in a consequential decision. General-purpose features, narrow procedural tasks, and several enumerated technologies (such as anti-fraud and cybersecurity tools) were excluded unless they themselves make consequential decisions. SB 26-189 reframes the covered technology as "automated decision-making technology" used in the same consequential-decision domains.
As originally enacted, SB 24-205 imposed three core duties: developers had to give deployers the documentation needed to evaluate a system and complete impact assessments; deployers had to use reasonable care to avoid algorithmic discrimination and complete annual impact assessments; and deployers had to disclose to consumers when a high-risk system was used in a consequential decision.
SB 26-189 narrows these duties. Developers must provide technical documentation to deployers beginning January 1, 2027, and deployers must notify consumers of ADMT use and disclose the technology's role within 30 days of an adverse outcome. The reenacted framework drops SB 24-205's standalone annual impact-assessment mandate and its broad algorithmic-discrimination duty.
SB 24-205 required deployers to complete an impact assessment of each high-risk system at least annually and after any intentional, substantial modification, covering the system's purpose, known risks of algorithmic discrimination, categories of data processed, performance metrics, transparency measures, and post-deployment monitoring. SB 26-189's ADMT framework replaces that standalone assessment obligation with documentation- and notice-centered duties; programs that already built SB 24-205 impact-assessment workflows can repurpose them as evidence of reasonable care.
Consumers covered by the framework are entitled to be told when automated technology is used in a consequential decision, to receive an explanation when a decision is adverse, to correct inaccurate personal data the system relied on, and to request meaningful human review where technically feasible.
Both SB 24-205 and SB 26-189 are enforced exclusively by the Colorado Attorney General as deceptive trade practices under the Colorado Consumer Protection Act; neither creates a private right of action. Civil penalties run up to $20,000 per violation under C.R.S. § 6-1-112. Enforcement under SB 26-189 is contingent on the Attorney General completing rulemaking, and enforcement of the original SB 24-205 framework is judicially stayed as described above.
The consequential-decision categories enumerated above map directly to the industries most exposed under a Colorado-style automated-decision-making-technology regime. Compliance teams scoping controls by sector can start from the relevant Atlas industry hub: AI in insurance compliance for underwriting, rating, and claims-handling automation; financial services AI compliance for credit, lending, and account decisions; healthcare AI compliance for care, coverage, and eligibility determinations; HR and hiring AI compliance for employment decisions; and the housing, education, legal services, and government services hubs for the remaining enumerated consequential-decision categories. Because SB 26-189 turns on the type of decision rather than the sector, a single deployer can fall under more than one of these applicability areas at once. Related Atlas coverage: Utah AI Policy Act.
Specific compliance requirements derived from the primary source. Each item links to the relevant statutory section where applicable.
On and after January 1, 2027, make available to each deployer of a covered automated decision-making technology (ADMT), in a form understandable to the deployer and protective of trade secrets, a statement of the system's intended and known harmful or inappropriate uses, the categories of data (including personal data) used to train it, its known limitations and risks, instructions for appropriate use, monitoring, and meaningful human review, and the information the deployer needs to satisfy its disclosure duties under § 6-1-1704; developers must also notify deployers of material updates and retain compliance records for at least three years.
Deadlinefrom_2027-01-01
Before using a covered ADMT to materially influence a consequential decision, provide a clear and conspicuous notice to the consumer that automated decision-making technology is or will be used in a consequential decision affecting them, with instructions for obtaining further information; a prominent public notice kept reasonably accessible at points of consumer interaction satisfies this requirement.
Deadlinebefore_decision
When a covered ADMT materially influences a consequential decision that results in an adverse outcome, provide the consumer, within 30 days of the decision, a plain-language description of the decision and the role the ADMT played, a simple process to request additional information (the system's name, version, developer, and the types, categories, and sources of personal data used), and an explanation of the consumer's correction and human-review rights under § 6-1-1705.
Deadlinewithin_30_days_of_adverse_outcome
On request from a consumer who experiences an adverse outcome, provide instructions to access and correct factually incorrect or materially inaccurate personal data used in the consequential decision (consistent with C.R.S. § 6-1-1306) and an opportunity for meaningful human review and reconsideration of the decision to the extent commercially reasonable; correction is not required for opinions, predictions, scores, or protected evaluations.
Deadlineon_consumer_request
Retain, for at least three years after a consequential decision, the records reasonably necessary to demonstrate compliance with Part 17 of article 1 of title 6 — including covered-ADMT version identifiers, changelogs, and documentation of material mitigation changes.
Deadlineretain_3_years
Use the side-by-side comparisons to see how this law interacts with adjacent US AI laws and governance frameworks.
Compare scope, roles, penalties, and source-backed compliance evidence side by side.
Compare the law and framework records using the same source-backed entity data.
Compare source-backed law records, applicability, penalties, and compliance scope.
Deeper Atlas write-ups on how this law is being interpreted and operationalized.
A practical pre-enforcement checklist — scoping, impact assessments, disclosures, and AG-facing records.
How the GOVERN-MAP-MEASURE-MANAGE functions line up with the Colorado AI Act obligations.
For teams operating in both regimes: concrete differences that change how a control set is built.
A single law is one input to a broader program. These guides show how to assign accountability, map every obligation to a control, and split developer-versus-deployer duties across the systems a team operates.
The operating model — owners, committee, decision rights, lifecycle gates — that turns a law into an accountable, auditable program anchored to the NIST AI RMF GOVERN function.
How to map each AI system to the laws it triggers, the controls that satisfy them, and the evidence that proves the controls operate.
Which duties attach to building an AI system versus putting one into use — the split most state AI laws turn on.
Colorado Artificial Intelligence Act is scheduled to take effect on January 1, 2027.
Up to $20K per violation under Colorado Artificial Intelligence Act.
Colorado Artificial Intelligence Act applies to developer, deployer of AI systems within its jurisdictional scope.
Every fact above is sourced from the official primary source. Independent verification recommended before acting on the information.
Last reviewed June 17, 2026. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.
We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.