AIPolicyTracker
Legal requirement AI risk management Colorado (United States) Adopted

Deployers must use reasonable care to avoid algorithmic discrimination

Context fileUnder Colorado AI Act, C.R.S. 6-1-1703(1)

Source-linked Open official source

What does it require?

A deployer of a high-risk AI system must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. A deployer that runs the required risk-management programme, completes impact assessments, gives consumer notices and makes the required disclosures benefits from a rebuttable presumption of reasonable care; some deployers with fewer than 50 employees are relieved of parts of the programme and assessment duties when they rely on the developer's impact assessment.

Practical action

Treat each consequential-decision use of AI as a governed system with an owner, a risk record and the statutory paperwork so the presumption is available.

Who does it apply to?

Deployers doing business in Colorado that use a high-risk AI system to make or substantially inform consequential decisions.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • satisfiesPolicyExecutive sponsor for AI · annual
    AI governance policy and accountability structure

    Serves 16 recorded duties · evidence: AI policy, Board or executive approval of the AI policy, AI governance forum minutes

    Ownership and the standard of care documented for each system.

  • supportsProcessAI system owner · once per ai system
    AI risk assessment and lifecycle risk register

    Serves 12 recorded duties · evidence: AI system risk assessment, Per-system AI risk register, Residual-risk acceptance

    Discrimination risk identified for each consequential-decision use.

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
Deployer compliance checklist per high-risk systemrecord

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every Colorado (United States) duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
NIST AI RMF 1.0GOVERN 1.1, MANAGE 1.3Legal requirements and risk treatment for deployed systems.medium
ISO/IEC 42001:2023Clause 6.1.2; Annex A.9.2Risk assessment and responsible-use processes.medium

Cite this record

AIPolicyTracker (2026). “Deployers must use reasonable care to avoid algorithmic discrimination (Colorado AI Act)”. https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-reasonable-care (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: SB24-205 Consumer Protections for Artificial Intelligence, Colorado General Assembly, https://leg.colorado.gov/bills/sb24-205.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.