Effective soonSB 24-205
Colorado Artificial Intelligence Act: Compliance Checklist
A practical checklist of the main obligations to satisfy under this law.
Compliance checklist
Run through these items to scope your obligations under Colorado Artificial Intelligence Act. Not legal advice; verify with counsel before acting.
- Confirm scope: does the law apply to your operations? See Who Must Comply or use the Compliance Checker.
- Inventory in-scope AI systems and classify them by role (developer/deployer) and decision type.
- Address each obligation:
- documentation — On and after January 1, 2027, make available to each deployer of a covered automated decision-making technology (ADMT), in a form understandable to the deployer and protective of trade secrets, a statement of the system's intended and known harmful or inappropriate uses, the categories of data (including personal data) used to train it, its known limitations and risks, instructions for appropriate use, monitoring, and meaningful human review, and the information the deployer needs to satisfy its disclosure duties under § 6-1-1704; developers must also notify deployers of material updates and retain compliance records for at least three years.C.R.S. § 6-1-1702
- disclosure — Before using a covered ADMT to materially influence a consequential decision, provide a clear and conspicuous notice to the consumer that automated decision-making technology is or will be used in a consequential decision affecting them, with instructions for obtaining further information; a prominent public notice kept reasonably accessible at points of consumer interaction satisfies this requirement.C.R.S. § 6-1-1704(1)–(2)
- disclosure — When a covered ADMT materially influences a consequential decision that results in an adverse outcome, provide the consumer, within 30 days of the decision, a plain-language description of the decision and the role the ADMT played, a simple process to request additional information (the system's name, version, developer, and the types, categories, and sources of personal data used), and an explanation of the consumer's correction and human-review rights under § 6-1-1705.C.R.S. § 6-1-1704(3)
- consumer right — On request from a consumer who experiences an adverse outcome, provide instructions to access and correct factually incorrect or materially inaccurate personal data used in the consequential decision (consistent with C.R.S. § 6-1-1306) and an opportunity for meaningful human review and reconsideration of the decision to the extent commercially reasonable; correction is not required for opinions, predictions, scores, or protected evaluations.C.R.S. § 6-1-1705(1)
- governance — Retain, for at least three years after a consequential decision, the records reasonably necessary to demonstrate compliance with Part 17 of article 1 of title 6 — including covered-ADMT version identifiers, changelogs, and documentation of material mitigation changes.C.R.S. § 6-1-1703
- Adopt a federal control framework: NIST AI RMF or ISO/IEC 42001 to demonstrate due care.
- Document evidence of compliance for each obligation, refreshed at the cadence the law requires.
- Build the AG-notification path if the law requires it (Colorado, California SB 53).
- Set the refresh cadence — annual for most impact-assessment regimes; continuous for monitoring.
We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.