Blog

Colorado AI Act Risk Management Updates for Deployers

Colorado refined AI Act risk management duties for deployers of high-risk systems. Summary of obligations, deadlines, and documentation.

Colorado AI Act risk management updates 2026 ADMT deployer obligations SB 26-189
Colorado replaced mandatory risk programs with transparency duties effective January 1, 2027.

Colorado's landmark AI Act (SB 24-205) promised the nation's first comprehensive deployer risk management regime for high-risk artificial intelligence. In 2026, the legislature repealed and replaced that framework with SB 26-189, the Automated Decision-Making Technology Act (ADMTA). The new law takes effect January 1, 2027, pending Attorney General rulemaking. Deployers no longer face statutory mandates for risk management programs, impact assessments, annual reviews, or algorithmic discrimination reporting to the AG. Instead, Colorado shifted to notice, adverse-outcome disclosure, consumer correction rights, and three-year record retention.

This guide explains Colorado AI Act 2026 updates for deployers of covered ADMT, maps what replaced former high-risk AI Colorado duties, and offers a practical AI deployer compliance checklist for teams evaluating AI regulation alongside AI chatbot products used in consequential decisions.

2026 Amendments Replace the Original Colorado AI Act

SB 26-189 repeals SB 24-205 and reenacts Colorado's AI rules around automated decision-making technology rather than a broad "artificial intelligence" label. Governor Polis signed the bill after a 2025 working group convened stakeholders who argued the original act's risk management and impact assessment duties were unworkable for many deployers.

Key eliminations include the duty of reasonable care to avoid algorithmic discrimination, mandatory risk management policies and programs, required impact assessments, annual reviews, and AG reporting when discrimination is discovered. Developers and deployers are no longer required to publish public website statements about AI governance. Liability theories narrowed, but transparency obligations expanded in targeted ways.

The Colorado Attorney General published draft ADMTA rules on August 11, 2026, with public comment open through at least October 26, 2026. Rules will clarify post-adverse outcome disclosure content, sector-specific guidance, and standards for describing ADMT roles in decisions. Deployers should monitor final rules before the January 1, 2027 effective date.

How Colorado Defines High-Risk ADMT Systems

Colorado regulates "covered ADMT": automated decision-making technology used to materially influence consequential decisions about individuals. ADMT means technology that processes personal data and uses computation to generate outputs (predictions, recommendations, classifications, rankings, scores, or similar information) used to make, guide, or assist decisions about people.

Consequential decisions relate to education, employment, housing, financial or lending services, insurance, health-care services, or essential government services and public benefits. A chatbot that answers FAQs without influencing those decisions may fall outside scope. An AI scoring tool that ranks job applicants or denies insurance quotes likely qualifies as covered ADMT.

Term ADMTA meaning
ADMT Personal-data processing plus computational outputs guiding decisions
Consequential decision Education, employment, housing, credit, insurance, health, essential government benefits
Covered ADMT ADMT that materially influences a consequential decision
Developer Entity that develops or substantially modifies ADMT
Deployer Entity using covered ADMT to make or assist consequential decisions

Impact Assessments and What Replaced Them

SB 26-189 does not require formal AI impact assessments, but deployers still need documentation that supports consumer rights and AG enforcement. The Colorado Privacy Act may require risk assessments for certain processing activities, so privacy teams should not assume ADMTA repeal eliminates all assessment work.

Deployer obligations under the new framework include three core duties. First, provide clear pre-use notice at the point of interaction describing that covered ADMT will be used. Second, within 30 days of a consequential decision that results in an adverse outcome, deliver a plain-language description of the decision, the ADMT's role, instructions for requesting more information about inputs, and how to exercise consumer rights. Third, enable access and correction of personal data and meaningful human review to the extent commercially reasonable.

Developers must supply deployers with documentation on intended uses, training data categories, known limitations, and human review instructions. Developers notify deployers of material updates and retain compliance records for at least three years, including version identifiers and changelogs. Deployers retain records demonstrating compliance for the same three-year minimum. Many enterprises will voluntarily maintain risk assessments because vendor diligence, EU AI Act planning, and internal audit standards still expect them even when Colorado no longer mandates the programs explicitly.

Small Business and Volume Exemptions

SB 26-189 includes exemptions for certain small businesses and limited decision volumes, but deployers should verify statutory thresholds with counsel before assuming exemption. The original CAIA contained small-business relief that evolved in SB 26-189; final AG rules may clarify how exemptions interact with developer documentation duties.

Even exempt deployers may face market pressure to provide notices and human review because enterprise customers and federal contractors increasingly require AI governance artifacts regardless of state thresholds. Colorado's Chatbot Safety Act, signed May 29, 2026, imposes separate duties on companion chatbot developers and runs parallel rulemaking with ADMTA. Deployers using general-purpose chatbots in Colorado should map both statutes.

Multi-state operators should compare Colorado's transparency model with California, Texas, and Illinois bills advancing in 2026. Colorado's repeal of mandatory risk management does not signal a national retreat from AI regulation; it signals a pivot toward disclosure and consumer remedy rather than ex ante program audits.

Frequently Asked Questions

When does the Colorado ADMTA take effect?

January 1, 2027, provided the Attorney General completes required rulemaking by that date. Draft rules were published August 11, 2026.

Are risk management programs still required in Colorado?

No. SB 26-189 eliminated mandatory risk management policies, impact assessments, and annual reviews that SB 24-205 imposed. Voluntary or contractually required programs may still apply.

What triggers the 30-day adverse outcome notice?

When covered ADMT materially influences a consequential decision that results in an adverse outcome for the consumer. AG rules will clarify disclosure content and sector variations.

What must developers provide deployers?

Documentation on intended uses, training data categories, limitations, human review instructions, and notices of material updates. Public release notes suffice if each deployer receives direct notice of releases.

How long must records be kept?

Developers and deployers must retain compliance records for at least three years, including system versions, changelogs, and material update notices.

Related blogs

  • AI Microbiome Analysis: From Shotgun Sequencing to Personalized Nutrition Claims

    AI Microbiome Analysis: From Shotgun Sequencing to Personalized Nutrition Claims

    Shotgun metagenomics, diversity metrics, and machine learning power microbiome insights. Learn what sequencing measures, what studies prove, and what consumer kits can claim.

  • AI Warehouse AMR Fleet Coordination: Traffic Rules for Hundreds of Robots

    AI Warehouse AMR Fleet Coordination: Traffic Rules for Hundreds of Robots

    Multi-agent path finding prevents deadlocks when AMR fleets scale. Learn priority rules, elevator coordination, and WMS integration patterns.

  • AI Workflow for Ag Retail: Crop Advisory Drafts From Field Notes

    AI Workflow for Ag Retail: Crop Advisory Drafts From Field Notes

    Help agronomists draft seasonal advisory bulletins from field scouting notes using AI, with final recommendations validated against local conditions.

  • Embedding Models vs LLMs: Different Jobs in AI Tool Stacks

    Embedding Models vs LLMs: Different Jobs in AI Tool Stacks

    Embeddings power search and RAG; LLMs generate text. Clarify when you need each and how directories categorize both.

  • Best AI tools for Lawyers

    Best AI tools for Lawyers

    streamline legal processes, enhance research capabilities, and improve overall efficiency in the legal profession.

  • Best AI Detector Tools in 2026: Free & Paid Options Compared

    Best AI Detector Tools in 2026: Free & Paid Options Compared

    Compare the best AI detector tools for students, teachers, and writers. Free and paid options tested for accuracy, features, and ease of use in 2026.

Didn't find tool you were looking for?

Be as detailed as possible for better results