The current transitional framework requires reasonable care against algorithmic discrimination, developer documentation, deployer risk-management and impact assessments, consumer notices, explanations, correction and appeal mechanisms, public disclosures and reporting to the Attorney General. SB25B-004 delayed operation to 30 June 2026; SB26-189 repeals and reenacts the framework principally from 1 January 2027.
Regulation
Verified record
- Risk classification summary
- The Act governs high-risk AI systems that make or substantially influence consequential decisions and separately requires disclosure when consumers interact with AI systems.
- Requirements summary
- Developers must provide documentation and known-risk information. Deployers must maintain risk-management programmes, complete annual and material-change impact assessments, notify consumers, explain adverse decisions, support data correction, appeals and human review, publish disclosures and report known algorithmic-discrimination risks to the Attorney General.
- Affected entities
- Developers and deployers of high-risk AI systems used for consequential decisions in Colorado, plus providers of covered consumer-facing AI interactions.
- Enforcement summary
- The Colorado Attorney General has exclusive enforcement authority under the Colorado Consumer Protection Act. The Act creates no new private right of action and provides a statutory affirmative defence for qualifying discovered and remediated violations.
- Penalty summary
- SB24-205 creates no standalone AI fine schedule. Violations are deceptive trade practices enforced under the Colorado Consumer Protection Act, which generally permits civil penalties up to $20,000 per violation.