ComplianceJuly 27, 202612 min read

Colorado Replaced Its AI Act: What SB 26-189 Requires in 2027

Colorado SB 26-189 replaces the 2024 AI Act with ADMT disclosure, explanation, data-correction, human-review, and recordkeeping duties from January 2027.

Antonella Serine

Antonella Serine

Founder, KLA

Founder of KLA, building the independent runtime governance control plane for regulated AI agents under the EU AI Act.

Status

SB 26-189 was approved on 14 May 2026. It repeals and reenacts Colorado Revised Statutes, title 6, article 1, part 17.

Main date

Most provisions take effect on 1 January 2027 and apply to consequential decisions made on or after that date.

Core deployer duties

Point-of-interaction notice, a post-adverse-outcome explanation within 30 days, three-year records, data-correction instructions, and an opportunity for meaningful human review and reconsideration.

Rules are pending

The Attorney General must adopt rules for post-adverse disclosures and consumer review rights by 1 January 2027. As of 27 July 2026, formal rulemaking has not begun.

Colorado enacted a replacement AI law on 14 May 2026. SB 26-189 repeals and reenacts the part of the Colorado Consumer Protection Act created by SB 24-205. The new text regulates automated decision-making technology, or ADMT, when its output materially influences a consequential decision in education, employment, housing, financial services, insurance, health care, or essential government services.

Most of SB 26-189 takes effect on 1 January 2027 and applies to consequential decisions made on or after that date. Several provisions needed to start rulemaking took effect when the governor approved the bill. The Colorado Attorney General's rulemaking page says formal rulemaking has not begun as of 27 July 2026.

This guide separates enacted requirements from future rules and translates the statute into work for developers and deployers. It is general information and does not provide legal advice.

SB 26-189 repealed and reenacted Colorado part 17

The enacted session law uses the phrase "repeal and reenact, with amendments." Colorado therefore still has an enacted law governing automated decisions. SB 26-189 replaces the framework created by the 2024 session law, SB 24-205 with a different part 17 titled "Automated Decision-Making Technology in Consequential Decisions."

SB 24-205 was approved on 17 May 2024. Its principal duties were originally scheduled for 1 February 2026. The General Assembly then enacted SB 25B-004 in August 2025, moving those duties to 30 June 2026. SB 26-189 was approved on 14 May 2026, before that delayed date, and supplied the replacement requirements that apply from 1 January 2027.

The date printed on a bill page can describe the act, a particular section, or the regulated conduct. Here, the approval date is 14 May 2026. The rulemaking, appropriation, effective-date, and safety-clause provisions took effect upon passage. Most substantive duties take effect on 1 January 2027, and the act applies to consequential decisions made on or after that date.

Colorado AI-law timeline from SB 24-205 to SB 26-189
DateEventLegal effect
17 May 2024Governor approves SB 24-205Creates part 17 and schedules its principal high-risk AI duties for 1 February 2026
28 August 2025Governor approves SB 25B-004Moves the principal SB 24-205 duties to 30 June 2026
14 May 2026Governor approves SB 26-189Repeals and reenacts part 17; specified rulemaking and administrative sections take effect upon passage
1 January 2027Replacement duties take effectMost of SB 26-189 applies to consequential decisions made on or after this date

The coverage test: ADMT, material influence, consequential decision

The enacted text defines ADMT as technology that processes personal data and uses computation to generate an output used to make, guide, or assist a decision about an individual. Predictions, recommendations, classifications, rankings, and scores are named examples. The complete definitions and exclusions are in section 6-1-1701.

An ADMT becomes a covered ADMT when it is used to materially influence a consequential decision. Material influence requires the output to be a non-de minimis factor used in the decision and to affect its outcome, such as by constraining, ranking, scoring, recommending, or classifying. Incidental, trivial, and clerical uses fall outside that definition.

The seven covered domains are education enrollment or opportunity; employment opportunities that create or may create an employer-employee relationship; the lease or purchase of Colorado residential real estate; financial or lending services; insurance; health-care services; and essential government services or public benefits.

The statute excludes several categories from the consequential-decision definition. These include low-stakes routine processes, advertising and marketing, administrative summarization that produces no influential inference, narrow procedural processing, certain cybersecurity, anti-money-laundering, counter-terrorist-financing, sanctions, and fraud-prevention activities, and routine academic administration. Each exclusion has conditions in the enacted text.

A practical SB 26-189 coverage screen
QuestionEvidence to collectWhy it matters
Does the technology process personal data and generate an output about an individual?System purpose, input categories, output schema, data-flow mapEstablishes whether the system is ADMT
Is the output used in one of the seven covered domains?Business Process, decision catalogue, Colorado nexus, consumer populationEstablishes whether the decision concerns a covered domain
Is the output a non-de minimis factor that affects the outcome?Decision logic, weights, thresholds, reviewer instructions, outcome testsEstablishes material influence and covered-ADMT status
Does a statutory exclusion apply?Documented use, contract, configuration, acceptable-use policy, human-review designSupports a bounded exclusion analysis

What changed from SB 24-205

The 2024 act regulated "high-risk artificial intelligence systems" that made or were a substantial factor in consequential decisions. It imposed reasonable-care duties tied to algorithmic discrimination, deployer risk-management programs, impact assessments at least annually, and public statements about risk management.

The 2026 replacement uses covered ADMT and material influence as its central trigger. Its enacted part 17 omits the former risk-management-program, annual-impact-assessment, and public risk-statement requirements. It centers developer documentation, update notices, three-year records, consumer notices, explanations after adverse outcomes, correction procedures, and meaningful human review.

Existing discrimination and consumer-protection law still applies. Section 6-1-1707 addresses liability under state anti-discrimination law and allocates fault between a developer and deployer based on their relative fault. Compliance with part 17 supplies no defense for violating another applicable law.

Principal differences between the 2024 and 2026 enacted texts
TopicSB 24-205 frameworkSB 26-189 replacement
Regulated technologyHigh-risk AI system that makes or is a substantial factor in a consequential decisionADMT used to materially influence a consequential decision
Risk governanceReasonable-care duties, deployer risk-management program, annual impact assessmentsThose part 17 duties are omitted from the replacement text
Developer packageBroad documentation, impact-assessment support, public statement, discrimination-risk reportingIntended and harmful uses, training-data categories, known limitations, use and review instructions, material-update notices
Consumer processPre-decision notice and adverse-decision disclosuresPoint-of-interaction notice, 30-day adverse-outcome explanation, correction instructions, meaningful human review and reconsideration
RecordsImpact-assessment records retained for at least three years after final deploymentDeveloper compliance records and deployer decision records retained for at least three years

Developer duties from 1 January 2027

Section 6-1-1702 of the session law requires a developer to make a reasonably understandable package available to each deployer for covered uses. The package must protect trade secrets and information protected by state or federal law.

The package must describe intended uses and known harmful or inappropriate uses; the known categories of training data, including personal data; known limitations, risks, and circumstances where the ADMT should not be used; instructions for appropriate use, monitoring, and meaningful human review where applicable; and information the deployer reasonably needs for its disclosure duties.

A developer must notify each deployer of material updates, intentional and substantial modifications, and changes to intended use, limitations, or risk mitigation within a reasonable time. Public release notes can carry the content when the developer also gives each deployer direct notice of the release.

Developer records reasonably necessary to demonstrate compliance must be retained for at least three years after creation, or longer when another law requires it. The statute names system-version identifiers, changelogs, documentation, and material-update notices.

  • Scope the covered use: record how the ADMT was marketed, configured, contracted, sold, or licensed for consequential decisions.
  • Version the documentation: bind intended use, limitations, input categories, monitoring, and human-review instructions to a system version.
  • Notify deployers: record the update, affected versions, recipients, delivery time, and any changed mitigation.
  • Preserve the record: retain the compliance package and delivery evidence for the statutory period.

Deployer notice, explanation, and recordkeeping duties

Before using a covered ADMT to materially influence a consequential decision, a deployer must give the consumer a clear and conspicuous notice. A prominent notice placed reasonably close to the interaction can satisfy this point-of-interaction requirement. Section 6-1-1704 requires the notice to say that covered ADMT was or will be used and explain how to obtain additional information.

When that use results in an adverse outcome, the deployer has 30 days after making the decision to provide a plain-language description of the decision and the ADMT role. The notice must also give a simple process for requesting information about the ADMT and inputs, including its name, version where applicable, developer, and the types, categories, and sources of personal data, to the extent the developer supplied the necessary information. The deployer must explain the consumer rights in section 6-1-1705 and how to exercise them.

Required notices and disclosures must be reasonably accessible to consumers with disabilities and consumers with limited English proficiency, consistent with applicable law. The statute includes sector-specific provisions for credit, education under FERPA, insurers, HIPAA-covered entities, and medical devices.

Deployers must retain records reasonably necessary to demonstrate compliance for at least three years after the consequential decision. Version identifiers, changelogs, and material-mitigation documentation are named examples.

Recommended operating record for a covered consequential decision
StageStatutory operationRecommended evidence to retain
Before material influenceProvide clear, conspicuous point-of-interaction noticeNotice version, placement, locale, accessibility state, delivery timestamp
DecisionRecord the ADMT and human decision contextSystem and version, inputs and sources, output, reviewer, outcome, timestamps
Within 30 days after an adverse outcomeProvide the plain-language decision and role description, request process, and rights explanationDisclosure copy, delivery record, request channel, source documentation
For at least three yearsRetain records reasonably necessary to demonstrate complianceDecision records, versions, changelogs, notices, mitigation changes, review record

Meaningful human review is a defined consumer right

After an adverse outcome from a consequential decision materially influenced by a covered ADMT, a consumer may request two forms of recourse under section 6-1-1705. The deployer must provide instructions for requesting the personal data used and correcting factually incorrect or materially inaccurate personal data. The deployer must also provide an opportunity for meaningful human review and reconsideration, to the extent commercially reasonable.

Meaningful human review has a statutory definition. The deployer designates a person with authority to approve, modify, or override the consequential decision. That person considers relevant available primary evidence, is trained for the review, evaluates the case without defaulting to the system output, and receives enough information to understand the output’s intended use, material limitations, input categories, and principal factors.

The correction right does not require correction of opinions, predictions, scores, or protected evaluations. Education deployers subject to FERPA can use qualifying student-record and appeal procedures. The Attorney General must clarify and implement the broader correction, review, and reconsideration requirements through rules by 1 January 2027.

A workable review process therefore needs named authority, an evidence packet, trained reviewers, an independent decision step, a reconsidered outcome, and a durable record. The human-oversight model shows how to route a consequential action to a person with explicit decision authority, while control mapping ties the statutory duty to its operating control and evidence.

  • Authority: the reviewer can approve, modify, or override the decision.
  • Primary evidence: the reviewer receives the relevant source material behind the case.
  • Training: the reviewer understands the decision, review method, and covered ADMT.
  • Independent judgment: the process requires evaluation of the evidence and records the reviewer’s own rationale.
  • System context: intended use, limitations, input categories, and principal factors are available at review time.
  • Reconsideration record: the request, evidence, reviewer, rationale, outcome, and delivery are retained.

Enacted duties and future Attorney General rules

Two mandatory rulemakings are written into the statute. The Attorney General must adopt rules by 1 January 2027 for post-adverse-outcome disclosures under section 6-1-1704(4) and for correction, meaningful review, and reconsideration under section 6-1-1705(3). The Attorney General also has authority to adopt other implementation rules, including rules clarifying "materially influence."

The Attorney General's AI rulemaking page says the office completed an informal pre-rulemaking comment period on 13 July 2026 and that formal rulemaking has not begun. Proposed rules, hearing details, adopted rules, and effective dates will be published there. Informal discussion topics and possible rule language carry no enacted obligation.

The enacted statute already fixes the principal duty, actor, trigger, and outer date. Rules may clarify content, format, sector examples, the description of the ADMT role, personal-data categories, review procedures, and application alongside other law. Implementation teams can build the statutory baseline now and keep the configurable details under change control for the formal rules.

What is fixed in the statute and what remains for rulemaking
TopicEnacted baselineRulemaking status on 27 July 2026
Post-adverse disclosureWithin 30 days; plain-language decision and ADMT role; request process; rights explanationMandatory clarifying rules due by 1 January 2027
Correction and human reviewInstructions for data access and correction; opportunity for meaningful review and reconsideration to the extent commercially reasonableMandatory implementation rules due by 1 January 2027
Material influenceNon-de minimis factor used in and affecting the outcome; incidental, trivial, and clerical uses excludedAttorney General may add presumptions, examples, and objective indicators
Formal proposalsNone in the session lawFormal rulemaking has not begun according to the Attorney General

Enforcement and a practical preparation plan

The Attorney General has exclusive authority to enforce the disclosure duties and consumer rights in part 17 through the Colorado Consumer Protection Act. A violation is a deceptive trade practice. The statute creates no new private right of action. Existing state and federal rights and remedies remain available.

When the Attorney General considers a violation curable, the office must issue a notice before enforcement and allow 60 days to cure. A cure period is unnecessary when the Attorney General can demonstrate a knowing or repeated violation. The entire subsection containing this pre-enforcement cure regime and the related annual reporting requirements is scheduled to repeal on 1 January 2030.

Preparation starts with an inventory of Colorado consequential decisions and the technology that influences them. For each candidate, record the domain, Colorado nexus, personal data, output, decision role, exclusion analysis, developer, version, consumer touchpoint, adverse-outcome path, reviewer authority, and retention owner.

Then bind the decision to runtime controls: show the notice at the point of interaction, preserve the exact system version and inputs, generate the explanation when an adverse outcome occurs, route a review request to an authorized person, and retain the complete record for three years. The EU AI Act requirements guide provides a separate obligation map for organizations operating in Europe; keep the two jurisdictional analyses distinct.

  • Inventory: find every Colorado decision in the seven covered domains and identify each computational input.
  • Classify: document ADMT status, material influence, consequential-decision status, exclusions, developer, and deployer.
  • Contract: obtain versioned developer documentation, limitations, update notices, and data-source information.
  • Operate: place notices, explanations, correction intake, and meaningful review inside the decision process.
  • Retain: preserve notices, versions, inputs, outcomes, disclosures, requests, reviews, and changes for at least three years.
  • Monitor rules: track the Colorado Attorney General's rulemaking page and update controls against adopted text.

Frequently Asked Questions

Did Colorado repeal its AI Act?

SB 26-189 repealed and reenacted Colorado Revised Statutes, title 6, article 1, part 17. The 2024 framework was replaced with an enacted ADMT framework whose principal duties take effect on 1 January 2027.

When does Colorado SB 26-189 take effect?

Most provisions take effect on 1 January 2027 and apply to consequential decisions made on or after that date. Specified rulemaking, appropriation, effective-date, and safety-clause provisions took effect when the bill was approved on 14 May 2026.

What technology does SB 26-189 cover?

It covers automated decision-making technology that processes personal data, generates an output about an individual, and materially influences a consequential decision in one of seven covered domains. The statute contains detailed technology and use-case exclusions.

What must a deployer provide after an adverse outcome?

Within 30 days, the deployer must provide a plain-language description of the decision and ADMT role, a simple process for requesting system and input information, and an explanation of the consumer’s correction and human-review rights.

What does meaningful human review require?

The reviewer must have authority to approve, modify, or override the decision; consider relevant primary evidence; be trained; evaluate the case without defaulting to the system output; and understand the intended use, limitations, inputs, and principal factors.

Are the Colorado Attorney General rules final?

No. The Attorney General’s public page says formal rulemaking has not begun as of 27 July 2026. The statute requires rules on post-adverse disclosures and consumer review rights by 1 January 2027.

Key Takeaways

SB 26-189 gives Colorado a replacement ADMT law for consequential decisions from 1 January 2027. Its operating model is concrete: document the system, notify the consumer, preserve the decision record, explain an adverse outcome, support correction, and provide meaningful human review and reconsideration. Build against the enacted session law and track the Attorney General's rulemaking page for the formal rules.

See It In Action

Ready to automate your compliance evidence?

Book a 20-minute demo to see how KLA helps you prove human oversight and export audit-ready Annex IV documentation.

Colorado AI Act: SB 26-189 Requirements for 2027