Colorado (United States) AI rules mapped to NIST AI RMF
Each row is one legal duty recorded for Colorado (United States) and the function of NIST AI Risk Management Framework 1.0 it corresponds to. Use it to find which duties your existing evidence already reaches.
Coverage of this crosswalk
10 of 10 recorded Colorado (United States) duties carry a mapping
The denominator is the number of duties this platform has broken out for Colorado (United States), not the number of duties the law contains. Unmapped duties are ones no reviewer has crosswalked yet, not ones the standard fails to address.
The mapping
| Legal duty | Binding? | NIST AI RMF function | Why they correspond | Confidence |
|---|---|---|---|---|
| Deployers must implement a risk management policy and programme Colorado AI Act, C.R.S. 6-1-1703(2) | Legal requirement | Whole framework (named in the statute) | The statute names the AI RMF as a recognised framework. | high |
| Deployers must complete impact assessments for high-risk AI Colorado AI Act, C.R.S. 6-1-1703(3) | Legal requirement | MAP 5.x | Original editorial mapping. | medium |
| Notify consumers and explain adverse consequential decisions Colorado AI Act, C.R.S. 6-1-1703(4) | Legal requirement | GOVERN 5.x, MANAGE 4.x | Recourse and communication. | medium |
| Developers must document high-risk systems and disclose known risks Colorado AI Act, C.R.S. 6-1-1702 | Legal requirement | GOVERN 1.4, MAP 3.x | Documentation and transparency. | medium |
| Developers must use reasonable care to avoid algorithmic discrimination Colorado AI Act, C.R.S. 6-1-1702(1) | Legal requirement | MAP 1.1, MEASURE 2.11, MANAGE 1.3 | Fairness and bias evaluated and managed. | medium |
| Developers must notify the Attorney General and deployers of discovered algorithmic discrimination Colorado AI Act, C.R.S. 6-1-1702(5) | Legal requirement | MANAGE 4.3, GOVERN 6.2 | Incident communication to authorities and downstream parties. | medium |
| Deployers must use reasonable care to avoid algorithmic discrimination Colorado AI Act, C.R.S. 6-1-1703(1) | Legal requirement | GOVERN 1.1, MANAGE 1.3 | Legal requirements and risk treatment for deployed systems. | medium |
| Deployers must publish a statement about the high-risk AI systems they use Colorado AI Act, C.R.S. 6-1-1703(5) | Legal requirement | GOVERN 4.2, MAP 5.2 | Transparency about deployed systems and their impacts. | medium |
| Deployers must notify the Attorney General of discovered algorithmic discrimination Colorado AI Act, C.R.S. 6-1-1703(7) | Legal requirement | MANAGE 4.3 | Incident response and reporting. | medium |
| Deployers and developers must disclose to consumers that they are interacting with an AI system Colorado AI Act, C.R.S. 6-1-1704 | Legal requirement | GOVERN 5.1, MANAGE 4.1 | Transparency to end users. | medium |
What a mapping means
The duty and the function ask for overlapping work, so evidence produced for one is likely to be reusable for the other. Confidence records how direct that overlap is.
What it does not mean
NIST AI RMF adoption does not discharge a legal duty and carries no force in Colorado (United States). A mapped row still has to be complied with on the statute's own terms.
Instruments in this crosswalk
- Colorado AI Act — Colorado (United States)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Does NIST AI RMF adoption satisfy Colorado (United States) AI rules?
- No. NIST AI RMF is a voluntary framework and carries no legal force in Colorado (United States). This crosswalk records that 10 of the 10 duties tracked here have a corresponding clause, which means the evidence may be reusable, not that the duty is discharged.
- How many Colorado (United States) AI duties map to NIST AI RMF?
- 10 of 10 duties recorded for Colorado (United States) carry a mapping to NIST AI Risk Management Framework 1.0.