AI compliance obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

4 results

Legal requirement impact assessment Colorado (United States)

Deployers must complete impact assessments for high-risk AI

Colorado AI Act · C.R.S. 6-1-1703(3)

Deployers must complete an impact assessment before deployment, annually, and within 90 days of any intentional and substantial modification, covering purpose, risks of algorithmic discrimination and mitigation, data categories, performance metrics, transparency measures and post-deployment monitoring, and retain assessments for at least three years.

Source-linked Applies from 30 Jun 2026
Legal requirement risk management Colorado (United States)

Deployers must implement a risk management policy and programme

Colorado AI Act · C.R.S. 6-1-1703(2)

Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and reasonable in light of recognised frameworks such as the NIST AI RMF or ISO/IEC 42001.

Source-linked Applies from 30 Jun 2026
Legal requirement technical documentation Colorado (United States)

Developers must document high-risk systems and disclose known risks

Colorado AI Act · C.R.S. 6-1-1702

Developers must make available to deployers a general statement of intended uses, documentation of known or reasonably foreseeable risks of algorithmic discrimination, training-data summaries, limitations, performance evaluation and mitigation measures, and information needed for deployer impact assessments, and must publish a public statement describing their high-risk systems and how they manage discrimination risks.

Source-linked Applies from 30 Jun 2026
Legal requirement transparency Colorado (United States)

Notify consumers and explain adverse consequential decisions

Colorado AI Act · C.R.S. 6-1-1703(4)

Before a high-risk system makes a consequential decision, deployers must notify the consumer that AI is used, describe its purpose and nature, and provide contact and opt-out information where applicable. After an adverse decision they must state the principal reasons, the data used and its sources, and offer an opportunity to correct data and to appeal for human review where feasible.

Source-linked Applies from 30 Jun 2026
Search