Developers must use reasonable care to avoid algorithmic discrimination
Context fileUnder Colorado AI Act, C.R.S. 6-1-1702(1)
What does it require?
A developer of a high-risk AI system must use reasonable care to protect consumers from any known or reasonably foreseeable risk of algorithmic discrimination arising from the intended and contracted uses of the system. A developer that meets the documentation, public-statement and Attorney General disclosure duties in the rest of section 6-1-1702 benefits from a rebuttable presumption that it used reasonable care.
Practical action
Run and record a discrimination-risk assessment for each high-risk system before release and keep it current so the statutory presumption can be claimed.
Who does it apply to?
Developers doing business in Colorado that develop or intentionally and substantially modify a high-risk AI system.
- Actors
- Provider / developer
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesProcessAI system owner · once per ai systemAI risk assessment and lifecycle risk register
Serves 12 recorded duties · evidence: AI system risk assessment, Per-system AI risk register, Residual-risk acceptance
Identifies and treats discrimination risk per system.
-
supportsTechnical measureQuality or testing lead · at launch and on material changeAccuracy, robustness, fairness and security testing
Serves 15 recorded duties · evidence: Pre-release test report, Test plan and acceptance criteria, Release test sign-off
Disparate-impact testing across protected classes.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Algorithmic discrimination risk assessment | report | |
| Bias evaluation results and mitigation record | record |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every Colorado (United States) duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| NIST AI RMF 1.0 | MAP 1.1, MEASURE 2.11, MANAGE 1.3 | Fairness and bias evaluated and managed. | medium |
| ISO/IEC 42001:2023 | Clause 6.1.2, 6.1.3 | AI risk assessment and treatment. | medium |
Cite this record
AIPolicyTracker (2026). “Developers must use reasonable care to avoid algorithmic discrimination (Colorado AI Act)”. https://aipolicytracker.org/obligations/us-colorado-ai-act-developer-reasonable-care (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: SB24-205 Consumer Protections for Artificial Intelligence, Colorado General Assembly, https://leg.colorado.gov/bills/sb24-205.
Similar obligations in other instruments
- Deployers must implement a risk management policy and programme — Colorado AI Act, Colorado (United States)
- Operators of high-impact AI must establish and operate a risk management plan — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea
- Deployers must use reasonable care to avoid algorithmic discrimination — Colorado AI Act, Colorado (United States)
- Apply minimum risk-management practices to high-impact AI — OMB M-25-21, United States
- Establish a risk management system for high-risk AI — EU AI Act, European Union
- Ensure AI systems are safe, secure and robust throughout their lifecycle — UK AI regulation framework, United Kingdom (voluntary)
- Prioritise, respond to and monitor AI risks (Manage) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.