SB 26-189, ADMT and consequential decisions (C.R.S. Title 6, Art. 1, Part 17 as reenacted)
Scope: automated decision-making technology in consequential decisions
The replacement law regulates technology used to materially influence consequential decisions: those affecting education access, employment, property and housing transactions, financial or lending services, insurance, health care, and essential government services. The old high-risk AI system concept is gone; ADMT is defined broadly and does not require the system to make inferences.
The definition captures far more than bespoke HR algorithms. A recruiter pasting resumes into a general-purpose chatbot to shortlist candidates, or a manager asking one to summarize performance data before a termination, is arguably using ADMT to materially influence an employment decision. Organizations need to know where that happens before they can decide whether the law's notice duties attach, and most cannot: LayerX measured in 2025 that organizations have no insight into roughly 89% of AI usage.
SB 26-189, developer duties
Developer documentation and disclosure to deployers
Developers that market ADMT for consequential decisions must give deployers documentation covering intended uses, known harmful uses, categories of training data, known limitations, and instructions for compliant use, must notify deployers of material updates within a reasonable time, and must keep records for at least three years.
If your product embeds AI in decisions about people, you owe your customers a documented account of what data trained it and what it should not be used for. That account is hard to write honestly if your own staff have been pasting customer or user data into external AI tools during development, because you no longer control what those tools retained. Point-of-entry controls on what leaves in prompts keep the documentation defensible.
SB 26-189, deployer pre-use notice
Consumer notice before ADMT influences a decision
Deployers must give clear and conspicuous notice, before the fact, that ADMT will materially influence a consequential decision about the consumer, via a prominent public notice or link.
Notice obligations presuppose an inventory: you can only disclose AI use you know about. Shadow use of browser AI tools inside hiring, lending, or benefits workflows makes every notice incomplete, and IBM found in 2025 that 63% of organizations have no AI governance policy at all. An accurate pre-use notice starts with visibility into which AI tools employees actually use on decision-related data.
SB 26-189, adverse-outcome disclosures and human review
Post-decision disclosure, data correction, and meaningful human review
After an adverse consequential decision, deployers must provide a plain-language description of the decision and the ADMT's role, the data inputs involved, and the consumer's rights, including access to and correction of inaccurate personal data and a right to request meaningful human review by trained personnel with authority to override the outcome. Records must be kept for at least three years.
Explaining what data went into a decision requires actually knowing it. If a rejected applicant's file was partly assembled by an employee running their personal information through an unapproved chatbot, the deployer cannot describe the data inputs accurately or correct them. Keeping personal identifiers out of external AI prompts is what keeps the disclosure and correction rights answerable.
SB 24-205 (repealed): reasonable care, impact assessments, NIST AI RMF presumption
What the original act required, and what survived
The 2024 act imposed a duty of reasonable care on developers and deployers to protect consumers from algorithmic discrimination, required deployer risk management programs and annual impact assessments, and gave deployers a rebuttable presumption of reasonable care if they maintained a risk management program aligned with the NIST AI RMF or ISO/IEC 42001. SB 26-189 removed all of these.
The repeal does not make risk management pointless. Discrimination in ADMT-driven decisions remains actionable under existing civil rights and consumer protection law, other states have kept assessment-style requirements, and a NIST-aligned program is still the credible answer to regulators, insurers, and enterprise customers. Organizations that built governance for the original act should keep it and repoint it at the notice, disclosure, and record-keeping duties that survived.