The Colorado AI Act, SB 24-205, no longer exists. On 14 May 2026, Governor Jared Polis signed Senate Bill 26-189, which repeals SB 24-205 and replaces it with a disclosure-and-rights framework focused on automated decision-making technology. The new framework takes effect 1 January 2027.

Colorado AI Act never took effect. Its original start date of 1 February 2026 was delayed to 30 June 2026 by SB 25B-004 before SB 26-189 replaced the framework entirely in May 2026.

The new law taking place of Colorado AI Act is commonly referred to as the Colorado Automated Decision-Making Technology Act, or ADMT Act. It is materially narrower than what it replaced. It is not, however, toothless, and its scope reaches organisations that had concluded they were outside the original Act’s perimeter.

This guide explains what changed, why it changed, what the ADMT framework requires, how it compares to the EU AI Act, and what organisations should do before 1 January 2027.

Key Colorado AI Act Definitions

TermDefinition
SB 24-205The original Colorado AI Act, signed May 2024. Repealed by SB 26-189. Never took effect
SB 26-189The replacement law, signed 14 May 2026. Effective 1 January 2027
ADMTAutomated decision-making technology. Technology that processes personal data to materially influence a consequential decision
Consequential decisionA decision materially affecting access to employment, housing, lending, insurance, health care, education, or essential government services
Materially influencesThe standard by which ADMT is brought into scope. Replaces the “substantial factor” test in SB 24-205
DeveloperAn entity that develops or substantially modifies ADMT used to materially influence consequential decisions
DeployerAn entity that uses ADMT to make or materially influence consequential decisions about consumers
Meaningful human reviewHuman involvement in a decision sufficient to constitute genuine oversight rather than rubber-stamping
Algorithmic discriminationThe concept central to SB 24-205. Removed as an operative duty under SB 26-189

What Happened to the Colorado AI Act?

The Original Colorado AI Act Framework

Signed in May 2024, Colorado AI Act (SB 24-205) was the nation’s first comprehensive state AI law. It imposed obligations on developers and deployers of high-risk artificial intelligence systems used in consequential decisions including employment, housing, health care, insurance, education, lending, legal services, and essential government services.

When Colorado enacted the first comprehensive state AI law in 2024, it imported the conceptual architecture of the EU AI Act: a risk-based regime built on duties of care, risk management programs, and impact assessments.

The core obligations under SB 24-205 (Colorado AI Act) were a duty of reasonable care to protect consumers from algorithmic discrimination, mandatory risk management programmes for deployers, annual impact assessments for high-risk systems, and consumer notice before and after consequential decisions.

Two Years of Failed Colorado AI Act Amendment

Governor Polis signed SB 24-205 with publicly stated reservations, explicitly encouraging the legislature to refine the approach before Colorado AI Act took effect. That invitation set in motion a sustained reconsideration process that ran across three legislative sessions.

In 2025, legislators introduced SB 25-318 to narrow and delay Colorado AI Act, but the bill did not advance. Following a special session, SB 25B-004 was enacted, delaying implementation of SB 24-205 until 30 June 2026, to allow additional legislative consideration during the 2026 session.

The Governor’s AI Policy Working Group did the heavy lifting in advance: roughly six months of stakeholder consultation produced a draft framework released in March 2026.

The Litigation That Accelerated Everything

On 9 April 2026, xAI, Elon Musk’s AI company and developer of the Grok chatbot, filed suit in the US District Court for the District of Colorado seeking to block SB 24-205 on constitutional grounds. The complaint argued the law was unconstitutionally vague, violated the First Amendment through compelled speech, offended the Dormant Commerce Clause by regulating out-of-state actors, and denied equal protection through what xAI characterised as ideologically motivated carve-outs.

On 24 April, the Department of Justice intervened on xAI’s side, the first time the federal government had sought to invalidate a state AI law. The DOJ focused on the equal protection argument, contending the Colorado AI Act’s diversity-oriented provisions constituted impermissible characteristic-based classifications. Three days later, a federal magistrate judge granted a joint motion to stay enforcement of the original law pending resolution of xAI’s forthcoming preliminary injunction motion.

In practical terms, Colorado AI Act was frozen. The Colorado legislature, by now working against the clock and the courts simultaneously, accelerated its replacement bill. Senate Bill 26-189 passed the House 57-6 and the Senate 34-1.

The margins are notable. A bill that had generated two years of legislative deadlock passed both chambers almost unanimously once the courts had frozen its predecessor and the federal government had intervened against it.

What Changed: SB 24-205 versus SB 26-189

What changed: the high-risk AI classification, mandatory risk management programs, annual impact assessments and the duty of care are gone. In their place, SB 26-189 regulates ADMT that materially influences consequential decisions, with duties built around consumer notice, adverse-outcome explanations, meaningful human review and developer documentation.

FeatureSB 24-205 (repealed)SB 26-189 (effective 1 January 2027)
Covered technologyHigh-risk artificial intelligence systemsAutomated decision-making technology (ADMT) processing personal data
Trigger standardSubstantial factor in consequential decisionMaterially influences consequential decision
Duty of careReasonable care to prevent algorithmic discriminationRemoved
Risk management programmeMandatory for deployersRemoved
Annual impact assessmentsMandatory for high-risk systemsRemoved
Consumer noticeRequired before and after decisionsRequired before ADMT use
Adverse outcome explanationRequiredRequired within 30 days
Human reviewNot explicitly requiredMeaningful human review required
Developer documentationRequired as part of risk frameworkRequired, narrower scope
Data correction rightsLimitedConsumers may request and correct inaccurate personal data used by ADMT
ExemptionsLimited and conditional exemptions for federally regulated entitiesThe original AI Act had limited and conditional exemptions for various federally regulated entities. The new bill does not.
Effective dateNever took effect1 January 2027

The Scope Trap

For most businesses that operate as deployers of AI, SB 26-189 is meaningfully narrower than Colorado AI Act (SB 24-205). That is the headline. The detail is more complicated.

The elimination of exemptions is significant and under-discussed. Organisations that had assessed themselves as exempt from SB 24-205 because they were federally regulated financial institutions, insurers, or health care entities do not carry that exemption forward into SB 26-189. Some organisations that were outside the original Act are inside the new one.

The shift from “high-risk artificial intelligence system” to “automated decision-making technology processing personal data” also changes the technical scope. ADMT is defined by function and data processing, not by whether the underlying technology is classified as AI. A statistical scoring model that would not have qualified as a high-risk AI system under SB 24-205 may qualify as ADMT under SB 26-189 if it processes personal data to materially influence a consequential decision.

What SB 26-189 Requires

Senate Bill 26-189 requires deployers to notify consumers when covered ADMT influences consequential decisions, explain adverse outcomes within 30 days and offer meaningful human review.

Deployer Obligations

ObligationWhat is requiredTiming
Pre-use consumer noticeNotify consumers that covered ADMT will be used to materially influence a consequential decision about themBefore ADMT is used
Adverse outcome explanationWhere the ADMT contributes to an adverse decision, explain the principal reasons for that outcomeWithin 30 days of the decision
Meaningful human reviewOffer consumers the ability to have an adverse decision reviewed by a human with authority to change the outcomeOn consumer request following adverse decision
Data correction rightsEnable consumers to request and correct inaccurate personal data used by the ADMTOn consumer request
Record retentionMaintain records of ADMT use sufficient to demonstrate complianceOngoing

Developer Obligations

Developers of ADMT used to materially influence consequential decisions must provide documentation to deployers sufficient for deployers to meet their own obligations. The documentation requirements are narrower than the impact assessment obligations under SB 24-205 but the underlying purpose is similar: deployers cannot comply without information that only the developer holds.

Enforcement and Rulemaking

Enforcement is contingent on the Attorney General completing rulemaking. The Colorado Attorney General has opened ADMT and Chatbot Safety rulemaking, with the formal rulemaking hearing scheduled for October 2026.

This is a meaningful practical qualifier. The obligations take effect 1 January 2027, but the operational detail of what compliance looks like will be determined by rules that have not yet been finalised. Organisations building compliance programmes now are building against a statutory framework whose implementing detail is still being written.

Why This Matters Beyond Colorado

The substance of the rewrite has been well-covered. Less examined is how Colorado got here, and what the speed and direction of the pivot signal for the rest of the state AI regulatory landscape.

Colorado’s original framework was explicitly modelled on the EU AI Act: risk classification, duty of care, risk management programmes, impact assessments. Its replacement moves decisively away from that model toward a disclosure-and-transparency framework built on consumer notice, explanation, and human review.

This matters for three reasons.

First, other US states that were tracking Colorado AI Act and its approach as a model now have a different template. The states that had drafted legislation on the SB 24-205 architecture will need to reassess whether the EU-style risk-based model is politically viable in the current US environment.

Second, the federal intervention in the xAI litigation established a precedent. The DOJ’s involvement was the first time the federal government had sought to invalidate a Colorado AI Act and basically any state’s AI law. Any state considering EU-style AI regulation must now factor in the possibility of federal constitutional challenge with DOJ support.

Third, and most significantly for organisations with cross-border operations: the divergence between the EU and US regulatory models is widening, not converging. Organisations that assumed a single AI governance programme could satisfy both frameworks are now managing two structurally different compliance regimes.

Colorado ADMT versus the EU AI Act

FeatureColorado SB 26-189EU AI Act
Regulatory modelDisclosure and consumer rightsRisk-based classification with duties
Covered technologyADMT processing personal dataAI systems by risk tier
Classification requirementNone. Function-based scopeMandatory classification under Article 6
Risk management systemNot requiredRequired under Article 9 for high-risk systems
Impact assessmentNot requiredFRIA required under Article 27 for certain deployers
Technical documentationDeveloper documentation to deployersAnnex IV technical documentation
Conformity assessmentNot requiredRequired under Article 43 for high-risk systems
Human oversightMeaningful human review on requestDesigned-in oversight capability under Article 14
Consumer noticeRequired before ADMT useRequired under Article 26(8) for high-risk deployers
Explanation rightAdverse outcome explanation within 30 daysRight to explanation under Article 86
RegistrationNot requiredEU database registration under Article 49
PenaltiesState enforcement, AG rulemaking pendingUp to €15M or 3% worldwide turnover
Effective date1 January 2027Phased: February 2025 to August 2028

The two frameworks overlap in what they require organisations to be able to explain, and diverge substantially in what they require organisations to build. An EU AI Act compliance programme will generate most of what Colorado requires. A Colorado ADMT compliance programme will not come close to satisfying the EU AI Act.

What Organisations Should Do Now

Reassess your exemption position. If you concluded you were exempt from Colorado AI Act as a federally regulated entity, that conclusion does not carry forward. SB 26-189 eliminated those exemptions. Reassess whether your ADMT use falls within scope.

Map ADMT, not high-risk AI. The scope test has changed from “high-risk AI system” to “ADMT processing personal data to materially influence consequential decisions.” Statistical models, scoring tools, and rules-based systems processing personal data may be in scope even where they were not classified as AI under the previous framework.

Build the notice and explanation infrastructure. Pre-use notice, 30-day adverse outcome explanation, and meaningful human review are the operational core of the new law. These require process, routing, record-keeping, and staffing decisions, not just policy documents.

Track the AG rulemaking. The formal rulemaking hearing is scheduled for October 2026, with written comments accepted in advance. The rules will determine the operational detail of compliance. Organisations with material exposure under previous Colorado AI Act, should consider participating in the consultation.

Reconcile with your EU AI Act programme. Where you operate in both jurisdictions, map which obligations overlap and which do not. The EU framework requires substantially more. The Colorado framework requires specific consumer-facing capabilities that the EU framework does not directly mandate in the same form.

Is the Colorado AI Act still in force?

No. SB 24-205, the Colorado AI Act, was repealed by SB 26-189 on 14 May 2026. It never took effect. Its original effective date of 1 February 2026 was delayed to 30 June 2026, and it was repealed before that date arrived.

What is the new law instead of Colorado AI Act called?

SB 26-189 is formally titled as legislation concerning automated decision-making technology. It is commonly referred to as the Colorado Automated Decision-Making Technology Act or the Colorado ADMT Act. Some practitioners still refer to it as the Colorado AI Act, which is imprecise given the deliberate shift away from AI-specific terminology.

When does SB 26-189 take effect?

1 January 2027, applying to decisions made on or after that date. Enforcement is contingent on the Colorado Attorney General completing rulemaking, which is currently in progress with a formal hearing scheduled for October 2026.

What is the difference between a high-risk AI system and ADMT?

SB 24-205 regulated high-risk artificial intelligence systems, defined by whether the system was a substantial factor in consequential decisions. SB 26-189 regulates automated decision-making technology, defined as technology that processes personal data to materially influence consequential decisions. The ADMT definition is function-based rather than technology-based, which means systems not classified as AI may still be in scope if they process personal data to influence covered decisions.

We were exempt under Colorado AI Act. Are we exempt under SB 26-189?

Probably not. SB 26-189 eliminated the conditional exemptions for federally regulated entities that existed under the original Act. Organisations that relied on those exemptions should reassess their position under the new framework.

Do we still need a risk management program and impact assessments?

Not under Colorado law. SB 26-189 removed the mandatory risk management programme and annual impact assessment requirements. However, organisations subject to the EU AI Act still require a risk management system under Article 9 and, for certain deployers of Annex III systems, a Fundamental Rights Impact Assessment under Article 27. Colorado’s simplification does not affect EU obligations.

Does the Colorado ADMT Act apply to companies outside Colorado?

Yes, where the ADMT is used to make or materially influence consequential decisions about Colorado consumers. Territorial scope follows the consumer, not the business location. This was one of the constitutional grounds xAI raised in its challenge to the original Act under the Dormant Commerce Clause.

What are the penalties under SB 26-189?

Enforcement is by the Colorado Attorney General. The specific penalty framework and enforcement approach will be determined substantially by the rule-making currently in progress. Organisations should track the rule-making to understand the enforcement posture before the January 2027 effective date.

How does Colorado AI Act demolition affect our EU AI Act compliance programme?

The EU AI Act and the new law, Colorado SB 26-189, are now structurally different frameworks. An EU AI Act programme built on classification, risk management, technical documentation, and conformity assessment will generate most of the evidence Colorado requires, but Colorado’s specific consumer-facing requirements including pre-use notice, 30-day adverse outcome explanation, and meaningful human review require dedicated operational capability. Neither programme substitutes for the other.

How does Grecta support multi-jurisdiction AI compliance?

Grecta operates at the product and system level, mapping obligations across multiple regulatory frameworks simultaneously rather than treating each jurisdiction as a separate compliance exercise. For organisations subject to both the EU AI Act and US state AI laws including Colorado’s ADMT framework, this means a single system inventory and evidence base supporting obligations that differ in structure but overlap substantially in the underlying facts about each system: what it does, what data it processes, what decisions it influences, and who it affects.

As frameworks diverge, as Colorado AI Act demonstrated, that shared factual foundation becomes more valuable, not less.

Back to Blog