US State AI & Privacy Laws

Colorado AI Act

Colorado Artificial Intelligence Act (SB 24-205, repealed and reenacted by SB 26-189 as the Automated Decision-Making Technology law)

Colorado passed the first comprehensive US state AI law in 2024, then rewrote it in 2026. Here is what the replacement law (SB 26-189) actually requires of organizations using AI in consequential decisions, and what it means for data privacy.

Colorado, United StatesEnacted May 2024, twice delayed, then repealed and replaced by SB 26-189 in May 2026; the replacement takes effect January 1, 2027Verified 2026-08-31

What it means for AI and data privacy

The Colorado AI Act has had a turbulent life: SB 24-205, signed in May 2024, was the first comprehensive US state AI law, built around a duty of reasonable care to avoid algorithmic discrimination, deployer risk management programs, and impact assessments, with an original effective date of February 1, 2026. That date was pushed to June 30, 2026 by SB 25B-004 in an August 2025 special session, and on May 14, 2026 Governor Polis signed SB 26-189, which repealed the original act entirely and replaced it with a narrower notice-and-transparency framework for automated decision-making technology (ADMT), effective January 1, 2027. The replacement drops the reasonable-care duty, the mandatory risk management programs, and the impact assessments, and instead requires developers to document their systems and deployers to notify consumers before ADMT materially influences a consequential decision in areas like employment, education, lending, housing, insurance, and health care, with post-decision disclosures and a right to meaningful human review after an adverse outcome. Enforcement sits exclusively with the Colorado Attorney General as a deceptive trade practice; there is no private right of action. For organizations, the practical privacy question underneath all of it is unchanged: you cannot give accurate notices about how AI influences decisions, or answer an AG inquiry, if employees are feeding candidate, customer, or patient data into AI tools nobody tracks.

Who it applies to

  • Developers that create, sell, license, or substantially modify automated decision-making technology used in consequential decisions affecting Colorado residents
  • Deployers (employers, lenders, insurers, schools, landlords, health providers) that use ADMT to materially influence consequential decisions
  • HR and recruiting teams using AI in hiring, promotion, or termination processes, one of the law's core consequential-decision categories
  • Organizations outside Colorado whose ADMT-driven decisions reach Colorado consumers
  • Vendors whose AI features are embedded in decision workflows and who owe deployers documentation under the developer duties

Enforcement and penalties

Violations of the replacement law are deceptive trade practices under the Colorado Consumer Protection Act, enforced exclusively by the Colorado Attorney General; there is no private right of action. The CCPA framework carries civil penalties that can reach $20,000 per violation, and each affected consumer or transaction can count separately, so exposure scales with the number of people a non-compliant ADMT touched. Until January 1, 2030, most violators get a 60-day cure period before an enforcement action, but knowing or repeated violations do not. The Attorney General must also adopt clarifying rules on disclosures and consumer rights by January 1, 2027, so obligations may tighten further.

Key provisions for AI and data privacy

SB 26-189, ADMT and consequential decisions (C.R.S. Title 6, Art. 1, Part 17 as reenacted)

Scope: automated decision-making technology in consequential decisions

The replacement law regulates technology used to materially influence consequential decisions: those affecting education access, employment, property and housing transactions, financial or lending services, insurance, health care, and essential government services. The old high-risk AI system concept is gone; ADMT is defined broadly and does not require the system to make inferences.

The definition captures far more than bespoke HR algorithms. A recruiter pasting resumes into a general-purpose chatbot to shortlist candidates, or a manager asking one to summarize performance data before a termination, is arguably using ADMT to materially influence an employment decision. Organizations need to know where that happens before they can decide whether the law's notice duties attach, and most cannot: LayerX measured in 2025 that organizations have no insight into roughly 89% of AI usage.

SB 26-189, developer duties

Developer documentation and disclosure to deployers

Developers that market ADMT for consequential decisions must give deployers documentation covering intended uses, known harmful uses, categories of training data, known limitations, and instructions for compliant use, must notify deployers of material updates within a reasonable time, and must keep records for at least three years.

If your product embeds AI in decisions about people, you owe your customers a documented account of what data trained it and what it should not be used for. That account is hard to write honestly if your own staff have been pasting customer or user data into external AI tools during development, because you no longer control what those tools retained. Point-of-entry controls on what leaves in prompts keep the documentation defensible.

SB 26-189, deployer pre-use notice

Consumer notice before ADMT influences a decision

Deployers must give clear and conspicuous notice, before the fact, that ADMT will materially influence a consequential decision about the consumer, via a prominent public notice or link.

Notice obligations presuppose an inventory: you can only disclose AI use you know about. Shadow use of browser AI tools inside hiring, lending, or benefits workflows makes every notice incomplete, and IBM found in 2025 that 63% of organizations have no AI governance policy at all. An accurate pre-use notice starts with visibility into which AI tools employees actually use on decision-related data.

SB 26-189, adverse-outcome disclosures and human review

Post-decision disclosure, data correction, and meaningful human review

After an adverse consequential decision, deployers must provide a plain-language description of the decision and the ADMT's role, the data inputs involved, and the consumer's rights, including access to and correction of inaccurate personal data and a right to request meaningful human review by trained personnel with authority to override the outcome. Records must be kept for at least three years.

Explaining what data went into a decision requires actually knowing it. If a rejected applicant's file was partly assembled by an employee running their personal information through an unapproved chatbot, the deployer cannot describe the data inputs accurately or correct them. Keeping personal identifiers out of external AI prompts is what keeps the disclosure and correction rights answerable.

SB 24-205 (repealed): reasonable care, impact assessments, NIST AI RMF presumption

What the original act required, and what survived

The 2024 act imposed a duty of reasonable care on developers and deployers to protect consumers from algorithmic discrimination, required deployer risk management programs and annual impact assessments, and gave deployers a rebuttable presumption of reasonable care if they maintained a risk management program aligned with the NIST AI RMF or ISO/IEC 42001. SB 26-189 removed all of these.

The repeal does not make risk management pointless. Discrimination in ADMT-driven decisions remains actionable under existing civil rights and consumer protection law, other states have kept assessment-style requirements, and a NIST-aligned program is still the credible answer to regulators, insurers, and enterprise customers. Organizations that built governance for the original act should keep it and repoint it at the notice, disclosure, and record-keeping duties that survived.

Practical compliance steps

  1. 1Inventory every process where AI or ADMT materially influences decisions about employment, education, lending, housing, insurance, or health care, including unapproved browser tools employees use inside those workflows
  2. 2Classify each system as making you a developer, a deployer, or both, and map the corresponding SB 26-189 duties
  3. 3Draft the pre-use consumer notice and the post-adverse-outcome disclosure templates now, before the January 1, 2027 effective date and the AG's clarifying rules
  4. 4Stand up a meaningful human review path: trained reviewers with real authority to override the system, working from primary evidence
  5. 5Put a technical control at the point of entry so personal data about candidates, borrowers, tenants, patients, and students does not leave in prompts to external AI tools
  6. 6Retain ADMT documentation, notices, and decision records for at least three years, and review vendor contracts for the void-indemnification provisions the new law adds
  7. 7Track the Colorado Attorney General's rulemaking, due by January 1, 2027, and adjust notices and disclosures to match

How Sanitized AI maps to this

Scope and inventory (ADMT discovery)

The extension shows administrators which AI tools employees actually use in the browser, surfacing shadow AI inside hiring, lending, and other consequential-decision workflows so the organization knows where the law's duties attach.

Deployer notices and adverse-outcome disclosures

Redacting personal identifiers from prompts before submission keeps candidate, borrower, and patient data out of external AI tools, so the data inputs a deployer must describe and correct after an adverse decision remain data the deployer actually controls.

Developer documentation duties

Interception reporting gives developers evidence that customer and user data was kept out of external AI tools during development, supporting honest documentation of training data categories and limitations.

AG enforcement and record-keeping

Usage and interception dashboards give the organization a running record of AI data flows, the kind of evidence that shortens an Attorney General inquiry and supports a cure within the 60-day window.

Frequently asked questions

When does the Colorado AI Act take effect?

January 1, 2027, but for a different law than the one passed in 2024. SB 24-205's original effective date of February 1, 2026 was delayed to June 30, 2026 by SB 25B-004 in August 2025, and before that date arrived, SB 26-189 (signed May 14, 2026) repealed the original act and replaced it with a narrower ADMT notice-and-transparency law effective January 1, 2027.

Did Colorado repeal its AI Act?

It repealed and replaced it. SB 26-189 removed the original act's duty of reasonable care to avoid algorithmic discrimination, the deployer risk management programs, and the annual impact assessments, and replaced them with developer documentation duties, consumer notices before ADMT influences a consequential decision, post-adverse-outcome disclosures, and a right to meaningful human review.

Does the Colorado AI law still have the NIST AI RMF safe harbor?

No. The original SB 24-205 gave deployers a rebuttable presumption of reasonable care if they ran a risk management program aligned with the NIST AI RMF or ISO/IEC 42001. SB 26-189 eliminated the reasonable-care duty entirely, so the presumption went with it. A NIST-aligned program still matters in practice, for other laws, insurers, and enterprise customers, but it is no longer a Colorado statutory presumption.

Who enforces the Colorado AI Act and can consumers sue?

The Colorado Attorney General has exclusive enforcement authority, and there is no private right of action. Violations are treated as deceptive trade practices under the Colorado Consumer Protection Act. Most violations carry a 60-day cure period before enforcement, though knowing or repeated violations do not, and the cure right expires January 1, 2030.

Does an employee using ChatGPT in hiring trigger the Colorado AI law?

It can. The replacement law covers technology used to materially influence consequential decisions, employment included, and does not require a purpose-built HR system. If staff run applicant materials through a general-purpose AI tool as part of screening or evaluation, the deployer duties (notice, disclosure, human review, records) plausibly attach, and the organization also loses control of the applicant's personal data. Gartner found in 2026 that 88% of employees with enterprise AI access also use personal AI tools, so this scenario is the norm, not the exception.

How does the Colorado law compare with NYC Local Law 144?

NYC Local Law 144 is narrow: it requires bias audits and candidate notice for automated employment decision tools used in NYC hiring and promotion. Colorado's replacement law is broader in sectors (employment, education, lending, housing, insurance, health care, government services) but lighter in substance, focused on notice, disclosure, and human review rather than mandated audits. Organizations hiring in both jurisdictions need both: an audit program for NYC and a notice-and-disclosure program for Colorado.

Primary sources

This guide summarizes the cited primary sources as of the verification date. It is general information, not legal advice.

The gap in every framework is the prompt box.

Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools employees actually use.

Get a demo

Related standards