Colorado AI Act: requirements, deadlines and compliance actions
Colorado Senate Bill 24-205: Consumer Protections for Artificial Intelligence (Colorado AI Act)
What is the Colorado AI Act?
The Colorado AI Act requires developers and deployers of high-risk AI systems to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. High-risk systems are those that make, or are a substantial factor in making, consequential decisions about education, employment, financial or lending services, essential government services, healthcare, housing, insurance or legal services. Deployers must run risk-management programmes and impact assessments, notify consumers, and explain adverse decisions; developers must document systems and disclose known risks.
Status note: Signed 17 May 2024. The effective date was moved from 1 February 2026 to 30 June 2026 by SB 25B-004, signed in August 2025. A reviewer must confirm whether the 2026 legislative session amended the substance or date again.
Who does it apply to?
Applies to developers and deployers doing business in Colorado of high-risk AI systems affecting Colorado consumers, with exemptions (for example certain small deployers, systems approved by federal agencies, and some regulated financial institutions). Enforcement is exclusively by the Attorney General; there is no private right of action.
Developers and deployers of high-risk AI systems used to make consequential decisions about Colorado residents.
- Sectors
- Employment and HRFinancial services and creditHealthcare and life sciencesEducation and trainingPublic services and government
- AI use cases
- AI in hiring and employmentAI in healthcareAI in finance, credit and insuranceAI in educationAI in public services
- Risk categories
- High-risk
- AI system types
- Automated decision-making systemPredictive or scoring system
When do the requirements apply?
Signed 17 May 2024; effective 30 June 2026 after the SB 25B-004 delay (subject to verification).
| Date | Milestone | Source reference | Status |
|---|---|---|---|
| Signed into law Governor signed SB 24-205. |
— | Passed | |
| Original effective date (superseded) Replaced by SB 25B-004. |
— | Superseded | |
| Effective date after SB 25B-004 delay Reviewer must confirm no further delay was enacted in the 2026 session. |
— | Scheduled confidence: medium |
Effective date per SB 25B-004 (2025 special session); confirm against the current statute.
What must organisations do?
Deployers: adopt a risk-management policy and programme, complete impact assessments annually and within 90 days of substantial modification, notify consumers before a consequential decision, explain adverse decisions and offer correction and appeal, and notify the Attorney General of discovered algorithmic discrimination within 90 days. Developers: provide documentation and known-risk disclosures to deployers, publish a public statement on high-risk systems, and notify the Attorney General of discovered discrimination.
Legal requirement Deployers must implement a risk management policy and programme C.R.S. 6-1-1703(2)
Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and reasonable in light of recognised frameworks such as the NIST AI RMF or ISO/IEC 42001.
Practical action: Adopt an AI risk policy referencing NIST AI RMF or ISO/IEC 42001 and keep programme records.
Evidence examples: AI risk management policy and programme
Framework mapping (original, editorial): NIST AI RMF 1.0 Whole framework (named in the statute); ISO/IEC 42001:2023 Whole management system (named in the statute)
Obligation pageApplies from 30 Jun 2026 Source-linked
Legal requirement Deployers must complete impact assessments for high-risk AI C.R.S. 6-1-1703(3)
Deployers must complete an impact assessment before deployment, annually, and within 90 days of any intentional and substantial modification, covering purpose, risks of algorithmic discrimination and mitigation, data categories, performance metrics, transparency measures and post-deployment monitoring, and retain assessments for at least three years.
Practical action: Build an impact-assessment template aligned with the statutory elements and calendar the annual refresh.
Evidence examples: Algorithmic impact assessment
Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 6.1.4 AI system impact assessment; NIST AI RMF 1.0 MAP 5.x
Obligation pageApplies from 30 Jun 2026 Source-linked
Legal requirement Notify consumers and explain adverse consequential decisions C.R.S. 6-1-1703(4)
Before a high-risk system makes a consequential decision, deployers must notify the consumer that AI is used, describe its purpose and nature, and provide contact and opt-out information where applicable. After an adverse decision they must state the principal reasons, the data used and its sources, and offer an opportunity to correct data and to appeal for human review where feasible.
Practical action: Add pre-decision AI notices and an adverse-decision explanation and appeal workflow.
Evidence examples: Consumer notice and adverse-action explanation templates
Framework mapping (original, editorial): NIST AI RMF 1.0 GOVERN 5.x, MANAGE 4.x
Obligation pageApplies from 30 Jun 2026 Source-linked
Legal requirement Developers must document high-risk systems and disclose known risks C.R.S. 6-1-1702
Developers must make available to deployers a general statement of intended uses, documentation of known or reasonably foreseeable risks of algorithmic discrimination, training-data summaries, limitations, performance evaluation and mitigation measures, and information needed for deployer impact assessments, and must publish a public statement describing their high-risk systems and how they manage discrimination risks.
Practical action: Prepare a deployer information pack and a public high-risk systems statement.
Evidence examples: Deployer documentation pack; Public statement on high-risk systems
Framework mapping (original, editorial): NIST AI RMF 1.0 GOVERN 1.4, MAP 3.x
Obligation pageApplies from 30 Jun 2026 Source-linked
Penalties
Violations are deceptive trade practices under the Colorado Consumer Protection Act, enforced by the Attorney General. A rebuttable presumption of reasonable care is available where the statute's requirements are met, and an affirmative defence exists for organisations that cure violations and follow a recognised risk framework such as the NIST AI RMF or ISO/IEC 42001.
Official sources
-
SB24-205 Consumer Protections for Artificial Intelligence
Colorado General Assembly · 17 May 2024 · Tier 1 source
-
SB25B-004 Artificial Intelligence Sunshine Act / effective-date delay
Colorado General Assembly · 28 Aug 2025 · Tier 1 source
Change history
- — Colorado delays the AI Act effective date to 30 June 2026
- — Colorado signs the first US state law on algorithmic discrimination
Record version 1: Initial structured record reflecting the SB 25B-004 delay; 2026 amendments unverified.. Full edit history is in the GitHub repository.
Frequently asked questions
- When does the Colorado AI Act take effect?
- The effective date was delayed to 30 June 2026 by SB 25B-004 in the August 2025 special session. Confirm the current date on the Colorado General Assembly site, because further amendments were debated in 2026.
- Does the Colorado AI Act allow consumers to sue?
- No. Enforcement is exclusively by the Colorado Attorney General; there is no private right of action.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.