Deployers must publish a statement about the high-risk AI systems they use
Context fileUnder Colorado AI Act, C.R.S. 6-1-1703(5)
What does it require?
A deployer must make available on its website, or in another public way, a clear and readily available statement summarising the types of high-risk AI systems it currently deploys, how it manages known or reasonably foreseeable risks of algorithmic discrimination from those systems, and the nature, source and extent of the information it collects and uses. The statement must be updated periodically.
Practical action
Publish an AI-use page listing high-risk systems in plain language and review it whenever a system is added or changed.
Who does it apply to?
Deployers of high-risk AI systems, subject to the small-deployer relief in 6-1-1703(6).
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesProcessProduct owner · at launch and on material changeAI interaction and use disclosure notices
Serves 17 recorded duties · evidence: AI interaction or use notice, Notice catalogue, Notice wording approval
Organisation-level public statement rather than per-interaction notice.
-
supportsProcessAI governance lead · continuousAI system inventory and classification
Serves 11 recorded duties · evidence: AI system register, Risk-tier classification sign-off, AI intake and classification procedure
Source of the list of deployed high-risk systems.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Public statement on high-risk AI use | document |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every Colorado (United States) duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| NIST AI RMF 1.0 | GOVERN 4.2, MAP 5.2 | Transparency about deployed systems and their impacts. | medium |
| ISO/IEC 42001:2023 | Annex A.8.5 | Information for interested parties. | medium |
Cite this record
AIPolicyTracker (2026). “Deployers must publish a statement about the high-risk AI systems they use (Colorado AI Act)”. https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-public-statement (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: SB24-205 Consumer Protections for Artificial Intelligence, Colorado General Assembly, https://leg.colorado.gov/bills/sb24-205.
Similar obligations in other instruments
- Disclose AI interaction and label synthetic content — EU AI Act, European Union
- Employers must inform workers and their representatives before using high-risk AI at work — EU AI Act, European Union
- Deployers must tell natural persons that a high-risk AI system is used in decisions about them — EU AI Act, European Union
- Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way — EU AI Act, European Union
- Deployers of emotion recognition or biometric categorisation must inform exposed persons — EU AI Act, European Union
- Deployers must disclose deepfakes and AI-generated text published on matters of public interest — EU AI Act, European Union
- Deployers must explain individual decisions taken with high-risk AI on request — EU AI Act, European Union
- Provide deployers with clear instructions for use — EU AI Act, European Union
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.