Deployers must complete impact assessments for high-risk AI
Under Colorado AI Act, C.R.S. 6-1-1703(3)
What does it require?
Deployers must complete an impact assessment before deployment, annually, and within 90 days of any intentional and substantial modification, covering purpose, risks of algorithmic discrimination and mitigation, data categories, performance metrics, transparency measures and post-deployment monitoring, and retain assessments for at least three years.
Practical action
Build an impact-assessment template aligned with the statutory elements and calendar the annual refresh.
Who does it apply to?
Deployers of high-risk AI systems.
Applies from:
Evidence examples
- Algorithmic impact assessment (report)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 6.1.4 AI system impact assessment | Original editorial mapping. | high |
| NIST AI RMF 1.0 | MAP 5.x | Original editorial mapping. | medium |
Similar obligations in other instruments
- Carry out a fundamental rights impact assessment before deployment — EU AI Act, European Union
- Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits — India DPDP Act, India
- Carry out a data protection impact assessment for high-risk AI processing — ICO AI guidance, United Kingdom
- Conduct a data protection impact assessment for high-risk processing using new technologies — UAE PDPL, United Arab Emirates
- Map context, intended use and potential impacts (Map) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.