AI Compliance / State AI Law

Colorado AI Act: What Businesses Need to Know Before January 2027

A plain-language guide to Colorado's automated decision-making technology law, who it covers, what changed in the 2026 rewrite, and how to build the governance controls it requires.

CyberAB RPO #1449 BBB A+ Since 2003 24+ Years in Business

Last Updated: September 15, 2026

What Is the Colorado AI Act?

The "Colorado AI Act" is the common name for Colorado's law regulating automated decision-making technology (ADMT), the software systems that use personal data and computation to generate scores, rankings, classifications, or recommendations that influence significant decisions about a person. It began in 2024 as Senate Bill 24-205, "Consumer Protections for Artificial Intelligence," and has since been substantially rewritten. As of this writing, the operative version is Senate Bill 26-189, signed into law on May 14, 2026, which repeals and replaces SB 24-205 and is scheduled to take effect January 1, 2027.

If you found older articles describing a "high-risk artificial intelligence system" duty of care, an impact-assessment mandate, and a June 30, 2026 effective date, that was the prior version of the law. The legislature narrowed and renamed the framework in May 2026. This page reflects the current SB 26-189 framework and flags where the law is still subject to attorney general rulemaking before it takes effect.

Key Takeaways

  • The original Colorado AI Act (SB 24-205) was repealed and replaced by SB 26-189, signed May 14, 2026.
  • SB 26-189 takes effect January 1, 2027, not the earlier June 30, 2026 date some sources still cite.
  • The law now centers on "automated decision-making technology" (ADMT) used in "consequential decisions," not the older "high-risk AI system" label.
  • Covered decisions span employment, education, financial services, government services, healthcare, housing, and insurance.
  • Enforcement rests exclusively with the Colorado Attorney General; there is no private right of action.
  • Out-of-state businesses are covered if their ADMT affects Colorado residents, regardless of where the company is headquartered.

Petronella Technology Group is not a law firm, and nothing on this page is legal advice. What follows is intended to help operations, IT, and compliance leaders understand the shape of the obligation so they can scope a technical and documentation response. Verify specific legal questions, deadlines, and applicability determinations with qualified counsel before making compliance decisions, and check the Colorado General Assembly's bill page for the current text, since Attorney General rulemaking is still in progress as of this update.

The Timeline: From SB 24-205 to SB 26-189

Colorado's approach to AI regulation has moved through three distinct stages in about two years, and the details matter if you are trying to figure out which rules actually apply to your business today.

Stage 1: SB 24-205, signed 2024

The original Colorado AI Act passed in 2024 as the first comprehensive, cross-industry AI regulation enacted by a U.S. state. It introduced a "high-risk artificial intelligence system" category, a duty of reasonable care to avoid algorithmic discrimination, mandatory risk management programs, and impact assessments for developers and deployers of covered systems. It was originally scheduled to take effect February 1, 2026.

Stage 2: SB25B-004, the delay

Before the original law ever took effect, the Colorado General Assembly passed SB25B-004 in a special session, and Governor Jared Polis signed it August 28, 2025. That bill pushed the effective date from February 1, 2026, to June 30, 2026, in response to business community concerns about compliance readiness and the risk of a patchwork of conflicting state AI laws.

Stage 3: SB 26-189, the rewrite

Before the June 30, 2026 date arrived, the legislature went further and rewrote the law from the ground up. SB 26-189 was signed by Governor Polis on May 14, 2026. It repeals SB 24-205 in its entirety and replaces it with a narrower framework built around automated decision-making technology and consequential decisions, rather than the broader "high-risk AI system" concept. The new effective date is January 1, 2027, and the Colorado Attorney General is required to adopt implementing rules before that date arrives.

Because rulemaking is still underway, some operational details (notice content, technical formats, specific exemption thresholds) may be refined between now and January 1, 2027. Treat any specific numeric threshold you read anywhere, including on this page, as subject to confirmation against the final adopted rules.

Who Is Subject to the Colorado AI Act?

SB 26-189 splits obligations between two roles, and many companies will find themselves in both categories depending on the tool in question.

  • Developers build or substantially modify an ADMT system that is used, or intended to be used, in a consequential decision. This includes software vendors, in-house engineering teams building internal tools, and companies that materially customize a third-party model for a new covered use case.
  • Deployers use a covered ADMT system to make or materially influence a consequential decision about a Colorado resident. This is the more common category for small and mid-sized businesses: a company using a third-party hiring tool, a lending scoring model, a tenant-screening product, or an insurance underwriting algorithm is a deployer even though it did not build the underlying model.

Applicability follows the resident, not the headquarters address. A business based in North Carolina, Texas, or anywhere else that uses ADMT to influence decisions about job applicants, customers, tenants, patients, or policyholders who are Colorado residents can be a covered deployer under SB 26-189. Physical presence in Colorado is not required to trigger the law; the location of the affected individual is what matters. This mirrors how the Colorado Privacy Act and similar state consumer-protection statutes are structured, and it is the same reason a growing number of Raleigh-area and Triangle-region businesses that sell or hire nationally need to track Colorado's rules even though they are not Colorado companies.

The law does include narrower carve-outs than the original 2024 version. Independent contractors, out-of-state job applicants, and employees who reside outside Colorado are generally exempted from certain employment-related provisions, and a limited small-employer exemption applies to organizations with a small headcount for specific employment-decision obligations. These thresholds and carve-outs are exactly the kind of detail that is still being finalized in Attorney General rulemaking, so confirm current thresholds before relying on an exemption. This is also where shadow AI detection becomes relevant operationally: many companies deploy ADMT-covered tools (an AI-powered applicant tracking system, a chatbot that screens support tickets before routing them to a human, an underwriting model embedded in a SaaS platform) without a central inventory of where those systems are used, which makes an accurate applicability determination difficult until the tools themselves are catalogued.

What Counts as a Covered Use: The Decision Table

Under SB 26-189, the trigger is not simply "does this business use AI." The trigger is whether the system's output materially influences a consequential decision about an individual. Use this table as a starting screen, not a final legal determination.

QuestionIf YesIf No
Does the system process personal data about individuals and generate a score, ranking, classification, or recommendation?Likely ADMT under the statute's definitionLikely outside scope
Does that output make, guide, or materially influence a decision affecting employment, education, financial services, government services, healthcare, housing, or insurance?Likely a "consequential decision"Likely not a consequential decision, even if the tool is AI-powered
Is at least one affected individual a Colorado resident?The Colorado law can applyColorado's law does not apply to that instance, though another state's law may
Is a qualified human reviewer the actual decision-maker, with the tool providing only non-determinative, easily overridden input?May fall outside the "materially influences" standard, depending on final rulesMore likely to be a covered ADMT use
Is the tool purely internal (e.g., IT ticket routing, spam filtering, internal scheduling) with no effect on an individual's access to opportunities or services?Generally outside scopeMay be in scope if it touches a covered decision category

Notice what changed from the original 2024 law: SB 24-205 asked whether a system was a "high-risk artificial intelligence system" in the abstract. SB 26-189 asks a narrower, more concrete question about a specific decision and a specific individual. That is a meaningfully smaller net, but it is not a small net. Hiring, lending, tenant screening, insurance underwriting, and healthcare triage tools are squarely in scope for most companies that use them.

Not Sure If Your AI Tools Are Covered?

Petronella Technology Group helps businesses inventory their AI systems, map them against consequential-decision categories, and build the documentation trail regulators expect. This is a technical and operational compliance service, not a substitute for legal counsel.

Core Obligations Under SB 26-189

The 2026 rewrite removed some of the heavier requirements from the original bill, including the blanket duty of care against algorithmic discrimination and the mandatory formal risk-management-program and impact-assessment regime. What remains is narrower but still concrete, and it maps closely to controls most mature IT and security programs already maintain in other contexts.

For developers

  • Notify deployers of material updates or modifications to a covered ADMT system that could change how it affects a consequential decision.
  • Maintain documentation sufficient to demonstrate compliance, retained for at least three years.
  • Provide deployers with the information reasonably necessary for the deployer to meet its own notice and transparency obligations.

For deployers

  • Provide clear and conspicuous notice to an individual before ADMT is used to make or materially influence a consequential decision about them.
  • Maintain compliance records for at least three years.
  • Establish an internal process for individuals to understand and, where the law provides, contest or seek human review of a covered decision.

In practice, this means most covered businesses need three things: an accurate inventory of which tools qualify as ADMT and which decisions they touch, a documented AI governance framework that assigns ownership for notice, recordkeeping, and vendor coordination, and a way to demonstrate all of it to a regulator on request. Petronella Technology Group builds these controls the same way we build controls for CMMC and HIPAA engagements: policy documentation, evidence collection, and ongoing monitoring rather than a one-time PDF that goes stale within a quarter.

Two areas deserve special attention because they are easy to miss. First, if you use a third-party AI vendor for hiring, lending, underwriting, or similar decisions, your vendor's terms of service rarely cover your Colorado notice obligation for you; a structured AI vendor security questionnaire process helps confirm what the vendor will and will not provide. Second, an AI acceptable use policy that only addresses internal employee use of tools like chatbots misses the deployer-side obligations that attach when the business itself uses AI to make decisions about customers, applicants, and other outside parties.

Colorado AI Act vs. EU AI Act vs. No Compliance Program

Businesses that already track the EU AI Act often ask how Colorado's law compares. They are built on similar risk-based instincts but differ in scope, penalty structure, and maturity of the rulemaking. The table below is a general comparison for planning purposes; consult the actual regulatory text for either law before making a compliance decision.

Colorado AI Act (SB 26-189)EU AI ActNo Compliance Program
Effective dateJanuary 1, 2027Entered into force August 2024; obligations phased in through 2026-2027 by risk tierN/A
TriggerADMT that materially influences a consequential decision about a Colorado residentRisk-tiered: unacceptable, high-risk, limited-risk, and minimal-risk AI systems and general-purpose AI modelsNo structured trigger; exposure discovered reactively, often after a complaint or audit
Core dutiesNotice to individuals, developer-to-deployer update notice, 3-year recordkeepingConformity assessments, technical documentation, risk management systems, human oversight, transparency obligations for high-risk systemsNone documented; controls exist only if built for another framework
EnforcementColorado Attorney General only; no private right of action; 60-day cure period (sunsets 2030) except for knowing or repeat violationsNational market surveillance authorities; fines up to 7% of global annual turnover or 35 million euros for the most serious violations, whichever is higherReactive: regulatory, contractual, or reputational fallout after the fact
Penalty rangeRoughly $2,000 to $20,000 per violation under the Colorado Consumer Protection Act, plus injunctive reliefTiered by violation category and company sizeUnquantified until a problem surfaces

Companies that already hold an ISO 42001 certification or have built an AI management system to that standard have a meaningful head start on Colorado readiness, since the underlying discipline (an AI system inventory, documented roles, and ongoing monitoring) overlaps substantially with what SB 26-189 expects. The NIST AI Risk Management Framework is another useful reference point for structuring the governance program, even though neither ISO 42001 nor the NIST AI RMF is itself a Colorado legal requirement.

Penalties and Enforcement

SB 26-189 treats a violation as a deceptive trade practice under the Colorado Consumer Protection Act. Reported penalty ranges for violations run from roughly $2,000 to $20,000 per violation, along with the possibility of injunctive relief. There is no private right of action; only the Colorado Attorney General can bring an enforcement action.

The law also includes a cure period: before pursuing enforcement, the Attorney General generally must give 60 days' notice and an opportunity to fix the violation, except in cases of knowing or repeat violations. That cure opportunity is currently set to sunset January 1, 2030, after which the grace period goes away for all violations, not just repeat ones.

This structure rewards businesses that can show a documented, good-faith compliance program if something goes wrong. An organization that can produce an AI system inventory, notice records, and vendor documentation on short notice is in a materially different position during a 60-day cure window than one that has to build all of that from scratch under deadline pressure. That documentation trail is also exactly what supports a faster, calmer AI incident response process if a covered system produces a disputed or erroneous decision.

How Petronella Technology Group Helps

Petronella Technology Group provides technical and operational compliance support for the Colorado AI Act and similar state AI laws. We do not practice law and do not replace your attorney's review of specific applicability questions or notice language. What we do build is the underlying governance infrastructure a legal opinion depends on: an accurate inventory of AI systems in use, documentation of which ones touch consequential decisions, policy and process controls, and ongoing monitoring so the compliance posture does not decay after the initial project ends.

Founder Craig Petronella is a CMMC Registered Practitioner, MIT-certified in AI and cybersecurity, and the author of "Beautifully Inefficient," a book on AI, human creativity, and organizational change. Petronella Technology Group's compliance work spans CMMC, HIPAA, SOC 2, and now AI governance, using the same evidence-based methodology across all four: identify the control requirement, document current state, close the gap, and monitor it going forward.

  • AI system inventory and applicability screening using the decision framework above, tailored to your actual tool stack.
  • AI governance consulting to assign ownership, build policy, and establish the documented framework regulators expect to see.
  • AI guardrails implementation so covered systems operate inside documented, monitored boundaries rather than as black boxes.
  • AI audit services to test whether your current controls actually match your documentation before a regulator asks.
  • AI readiness assessment for businesses that are earlier in the process and need a baseline before building a full program.
"Craig takes the time to understand our business model, not just our technology stack. It makes his recommendations more strategic and tailored to our actual goals."Daniel Lee, TrustIndex verified review

Petronella Technology Group is rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews, and has been BBB A+ accredited since 2003. As a CyberAB Registered Provider Organization (RPO #1449), our team already works inside formal, evidence-based compliance frameworks daily; extending that discipline to AI governance is a natural fit rather than a new specialty bolted on for a trend.

Who Should Be Paying Attention Now

Even with an effective date of January 1, 2027, the businesses most exposed under SB 26-189 benefit from starting the inventory and governance work well before the deadline, because building an accurate AI system inventory and a working notice process takes longer than most teams expect.

  • Employers using AI-powered applicant tracking, resume screening, or candidate ranking tools for roles that could draw Colorado-based applicants.
  • Lenders, fintech companies, and financial services firms using automated underwriting or credit-scoring models.
  • Healthcare organizations using AI for triage, diagnosis support, or care-management decisions that reach Colorado patients.
  • Insurance carriers and agencies using algorithmic underwriting or claims-scoring tools.
  • Property managers and landlords using automated tenant-screening software.
  • Education providers and edtech companies using AI in admissions, placement, or proctoring decisions.
  • Any SaaS vendor whose product functions as a "developer" under the law because its customers use the output to make covered decisions about Colorado residents.

Businesses outside Colorado, including here in Raleigh, Durham, Cary, Chapel Hill, and the broader Triangle region, are not exempt simply because they are headquartered elsewhere. If your hiring, lending, or customer-facing decisions reach Colorado residents, plan on the same governance work as a Colorado-based company.

Start Your AI Governance Program Before the Deadline

Petronella Technology Group can help you build the AI system inventory, documentation, and monitoring the Colorado AI Act expects, ahead of the January 1, 2027 effective date.

Frequently Asked Questions

Who is subject to the Colorado AI Act?

Two groups: "developers" who build or substantially modify automated decision-making technology used in a consequential decision, and "deployers" who use that technology to make or materially influence a consequential decision about a Colorado resident. Most small and mid-sized businesses will find themselves in the deployer category, using a third-party AI tool for hiring, lending, tenant screening, or a similar decision, rather than the developer category.

When does the Colorado AI Act take effect?

The current effective date is January 1, 2027, under SB 26-189. This is a change from the earlier June 30, 2026 date that applied to the original SB 24-205 before it was repealed and replaced in May 2026. Given the law's history of amendment, confirm the current effective date against the Colorado General Assembly's bill page before finalizing a compliance timeline.

What are "high-risk AI systems" under the law, and does that term still apply?

The "high-risk artificial intelligence system" label came from the original 2024 version of the law. SB 26-189 replaced it with the narrower concept of automated decision-making technology (ADMT) that materially influences a "consequential decision," meaning a decision affecting an individual's access to or terms of employment, education, financial services, government services, healthcare, housing, or insurance. If you see "high-risk AI system" language describing current Colorado obligations, it is likely describing the repealed version of the law.

What are the penalties for violating the Colorado AI Act?

Violations are treated as deceptive trade practices under the Colorado Consumer Protection Act, with reported penalty ranges of roughly $2,000 to $20,000 per violation plus potential injunctive relief. Only the Colorado Attorney General can enforce the law; there is no private right of action. A 60-day cure period generally applies before enforcement for most violations, except knowing or repeat violations, and that cure opportunity is scheduled to sunset January 1, 2030.

How does the Colorado AI Act differ from the EU AI Act and other state AI laws?

The EU AI Act uses a broader risk-tier system covering unacceptable-risk, high-risk, limited-risk, and minimal-risk AI systems, with obligations phased in from 2024 through 2026-2027 and penalties that can reach a percentage of global annual turnover. Colorado's law is narrower and decision-specific: it asks whether a system materially influences one of a defined list of consequential decisions about a Colorado resident, rather than classifying entire AI systems by abstract risk category. Other states, including California, have taken yet other approaches, often focused on specific use cases like automated employment decision tools rather than a single omnibus AI statute, so a multi-state compliance program needs to track each state's definitions separately rather than assuming they align.

Does a company outside Colorado need to comply?

Potentially, yes. SB 26-189's applicability follows the residency of the affected individual, not the location of the business. A company headquartered outside Colorado that uses ADMT to influence a consequential decision about a Colorado resident, an applicant, customer, tenant, patient, or policyholder, can be a covered deployer. There are narrower carve-outs for certain out-of-state employees and independent contractors, but the general rule is that Colorado residency of the affected person is what triggers the law, not company headquarters.

What should a business do first to prepare?

Start with an inventory: list every tool that uses personal data to generate a score, ranking, classification, or recommendation feeding into a decision about employment, lending, housing, healthcare, insurance, education, or government services. From there, determine which tools touch Colorado residents, document your role as developer or deployer for each one, and build the notice and recordkeeping process the law requires. An AI readiness assessment is a practical way to structure that first pass before committing to a full governance program.

Is Petronella Technology Group a law firm, and can it tell me whether my business is covered?

No. Petronella Technology Group is a managed IT, cybersecurity, and compliance services firm, not a law firm, and nothing on this page is legal advice. We help with the technical and operational side of compliance, including AI system inventories, governance frameworks, documentation, and monitoring. For a binding determination of whether your specific business and specific AI systems are covered under SB 26-189, consult an attorney licensed to practice in Colorado or your relevant jurisdiction.

Ready to Get Started?

Contact Petronella Technology Group for a free consultation on Colorado AI Act readiness and AI governance controls.