Deployers must use reasonable care to avoid algorithmic discrimination
Context fileUnder Colorado AI Act, C.R.S. 6-1-1703(1)
What does it require?
A deployer of a high-risk AI system must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. A deployer that runs the required risk-management programme, completes impact assessments, gives consumer notices and makes the required disclosures benefits from a rebuttable presumption of reasonable care; some deployers with fewer than 50 employees are relieved of parts of the programme and assessment duties when they rely on the developer's impact assessment.
Practical action
Treat each consequential-decision use of AI as a governed system with an owner, a risk record and the statutory paperwork so the presumption is available.
Who does it apply to?
Deployers doing business in Colorado that use a high-risk AI system to make or substantially inform consequential decisions.
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesPolicyExecutive sponsor for AI · annualAI governance policy and accountability structure
Serves 16 recorded duties · evidence: AI policy, Board or executive approval of the AI policy, AI governance forum minutes
Ownership and the standard of care documented for each system.
-
supportsProcessAI system owner · once per ai systemAI risk assessment and lifecycle risk register
Serves 12 recorded duties · evidence: AI system risk assessment, Per-system AI risk register, Residual-risk acceptance
Discrimination risk identified for each consequential-decision use.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Deployer compliance checklist per high-risk system | record |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every Colorado (United States) duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| NIST AI RMF 1.0 | GOVERN 1.1, MANAGE 1.3 | Legal requirements and risk treatment for deployed systems. | medium |
| ISO/IEC 42001:2023 | Clause 6.1.2; Annex A.9.2 | Risk assessment and responsible-use processes. | medium |
Cite this record
AIPolicyTracker (2026). “Deployers must use reasonable care to avoid algorithmic discrimination (Colorado AI Act)”. https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-reasonable-care (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: SB24-205 Consumer Protections for Artificial Intelligence, Colorado General Assembly, https://leg.colorado.gov/bills/sb24-205.
Similar obligations in other instruments
- Deployers must implement a risk management policy and programme — Colorado AI Act, Colorado (United States)
- Operators of high-impact AI must establish and operate a risk management plan — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea
- Developers must use reasonable care to avoid algorithmic discrimination — Colorado AI Act, Colorado (United States)
- Apply minimum risk-management practices to high-impact AI — OMB M-25-21, United States
- Establish a risk management system for high-risk AI — EU AI Act, European Union
- Ensure AI systems are safe, secure and robust throughout their lifecycle — UK AI regulation framework, United Kingdom (voluntary)
- Prioritise, respond to and monitor AI risks (Manage) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.