Developers must notify the Attorney General and deployers of discovered algorithmic discrimination
Context fileUnder Colorado AI Act, C.R.S. 6-1-1702(5)
What does it require?
Within 90 days after a developer discovers, through ongoing testing or a credible report from a deployer, that a high-risk AI system it developed has caused or is reasonably likely to have caused algorithmic discrimination, it must disclose this to the Colorado Attorney General and to all known deployers or other developers of the system, without unreasonable delay.
Practical action
Route bias findings and deployer complaints into an incident process with a 90-day regulatory and customer notification clock.
Who does it apply to?
Developers of high-risk AI systems that become aware of algorithmic discrimination caused by their system.
- Actors
- Provider / developer
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesProcessIncident coordinator · continuousAI incident management and regulatory reporting
Serves 14 recorded duties · evidence: AI incident response playbook, AI incident record, Incident report to an authority
Discrimination findings treated as reportable incidents with the 90-day clock.
-
supportsTechnical measureAI system owner · continuousPost-deployment monitoring and drift detection
Serves 10 recorded duties · evidence: Post-market monitoring plan, Monitoring dashboard or periodic monitoring report, Monitoring review decision
Ongoing testing is one of the discovery routes the statute names.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Discrimination incident log with notification dates | register | |
| Attorney General and deployer notification letters | document |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every Colorado (United States) duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| NIST AI RMF 1.0 | MANAGE 4.3, GOVERN 6.2 | Incident communication to authorities and downstream parties. | medium |
| ISO/IEC 42001:2023 | Clause 10.2; Annex A.8.4 | Corrective action and incident communication. | medium |
Cite this record
AIPolicyTracker (2026). “Developers must notify the Attorney General and deployers of discovered algorithmic discrimination (Colorado AI Act)”. https://aipolicytracker.org/obligations/us-colorado-ai-act-developer-disclosure-to-attorney-general (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: SB24-205 Consumer Protections for Artificial Intelligence, Colorado General Assembly, https://leg.colorado.gov/bills/sb24-205.
Similar obligations in other instruments
- Report serious incidents to market surveillance authorities — EU AI Act, European Union
- Providers must take corrective action and inform the supply chain about non-conforming high-risk AI — EU AI Act, European Union
- Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office — EU AI Act, European Union
- Implement reasonable security safeguards and notify breaches — India DPDP Act, India
- Report critical safety incidents to the Office of Emergency Services — California SB 53, California (United States)
- Deployers must notify the Attorney General of discovered algorithmic discrimination — Colorado AI Act, Colorado (United States)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.