Colorado's landmark AI Act (SB 24-205) promised the nation's first comprehensive deployer risk management regime for high-risk artificial intelligence. In 2026, the legislature repealed and replaced that framework with SB 26-189, the Automated Decision-Making Technology Act (ADMTA). The new law takes effect January 1, 2027, pending Attorney General rulemaking. Deployers no longer face statutory mandates for risk management programs, impact assessments, annual reviews, or algorithmic discrimination reporting to the AG. Instead, Colorado shifted to notice, adverse-outcome disclosure, consumer correction rights, and three-year record retention.
This guide explains Colorado AI Act 2026 updates for deployers of covered ADMT, maps what replaced former high-risk AI Colorado duties, and offers a practical AI deployer compliance checklist for teams evaluating AI regulation alongside AI chatbot products used in consequential decisions.
2026 Amendments Replace the Original Colorado AI Act
SB 26-189 repeals SB 24-205 and reenacts Colorado's AI rules around automated decision-making technology rather than a broad "artificial intelligence" label. Governor Polis signed the bill after a 2025 working group convened stakeholders who argued the original act's risk management and impact assessment duties were unworkable for many deployers.
Key eliminations include the duty of reasonable care to avoid algorithmic discrimination, mandatory risk management policies and programs, required impact assessments, annual reviews, and AG reporting when discrimination is discovered. Developers and deployers are no longer required to publish public website statements about AI governance. Liability theories narrowed, but transparency obligations expanded in targeted ways.
The Colorado Attorney General published draft ADMTA rules on August 11, 2026, with public comment open through at least October 26, 2026. Rules will clarify post-adverse outcome disclosure content, sector-specific guidance, and standards for describing ADMT roles in decisions. Deployers should monitor final rules before the January 1, 2027 effective date.
How Colorado Defines High-Risk ADMT Systems
Colorado regulates "covered ADMT": automated decision-making technology used to materially influence consequential decisions about individuals. ADMT means technology that processes personal data and uses computation to generate outputs (predictions, recommendations, classifications, rankings, scores, or similar information) used to make, guide, or assist decisions about people.
Consequential decisions relate to education, employment, housing, financial or lending services, insurance, health-care services, or essential government services and public benefits. A chatbot that answers FAQs without influencing those decisions may fall outside scope. An AI scoring tool that ranks job applicants or denies insurance quotes likely qualifies as covered ADMT.
| Term | ADMTA meaning |
|---|---|
| ADMT | Personal-data processing plus computational outputs guiding decisions |
| Consequential decision | Education, employment, housing, credit, insurance, health, essential government benefits |
| Covered ADMT | ADMT that materially influences a consequential decision |
| Developer | Entity that develops or substantially modifies ADMT |
| Deployer | Entity using covered ADMT to make or assist consequential decisions |
Impact Assessments and What Replaced Them
SB 26-189 does not require formal AI impact assessments, but deployers still need documentation that supports consumer rights and AG enforcement. The Colorado Privacy Act may require risk assessments for certain processing activities, so privacy teams should not assume ADMTA repeal eliminates all assessment work.
Deployer obligations under the new framework include three core duties. First, provide clear pre-use notice at the point of interaction describing that covered ADMT will be used. Second, within 30 days of a consequential decision that results in an adverse outcome, deliver a plain-language description of the decision, the ADMT's role, instructions for requesting more information about inputs, and how to exercise consumer rights. Third, enable access and correction of personal data and meaningful human review to the extent commercially reasonable.
Developers must supply deployers with documentation on intended uses, training data categories, known limitations, and human review instructions. Developers notify deployers of material updates and retain compliance records for at least three years, including version identifiers and changelogs. Deployers retain records demonstrating compliance for the same three-year minimum. Many enterprises will voluntarily maintain risk assessments because vendor diligence, EU AI Act planning, and internal audit standards still expect them even when Colorado no longer mandates the programs explicitly.
Small Business and Volume Exemptions
SB 26-189 includes exemptions for certain small businesses and limited decision volumes, but deployers should verify statutory thresholds with counsel before assuming exemption. The original CAIA contained small-business relief that evolved in SB 26-189; final AG rules may clarify how exemptions interact with developer documentation duties.
Even exempt deployers may face market pressure to provide notices and human review because enterprise customers and federal contractors increasingly require AI governance artifacts regardless of state thresholds. Colorado's Chatbot Safety Act, signed May 29, 2026, imposes separate duties on companion chatbot developers and runs parallel rulemaking with ADMTA. Deployers using general-purpose chatbots in Colorado should map both statutes.
Multi-state operators should compare Colorado's transparency model with California, Texas, and Illinois bills advancing in 2026. Colorado's repeal of mandatory risk management does not signal a national retreat from AI regulation; it signals a pivot toward disclosure and consumer remedy rather than ex ante program audits.
Frequently Asked Questions
When does the Colorado ADMTA take effect?
January 1, 2027, provided the Attorney General completes required rulemaking by that date. Draft rules were published August 11, 2026.
Are risk management programs still required in Colorado?
No. SB 26-189 eliminated mandatory risk management policies, impact assessments, and annual reviews that SB 24-205 imposed. Voluntary or contractually required programs may still apply.
What triggers the 30-day adverse outcome notice?
When covered ADMT materially influences a consequential decision that results in an adverse outcome for the consumer. AG rules will clarify disclosure content and sector variations.
What must developers provide deployers?
Documentation on intended uses, training data categories, limitations, human review instructions, and notices of material updates. Public release notes suffice if each deployer receives direct notice of releases.
How long must records be kept?
Developers and deployers must retain compliance records for at least three years, including system versions, changelogs, and material update notices.