Colorado Replaced Its Landmark AI Act. The New Law Is About Notice, Explanations, and Human Review

Colorado did more than amend its first AI law. It replaced the law's operating model.

The 2024 statute was built around high-risk AI systems, algorithmic-discrimination duties, risk-management programs, impact assessments, and a reasonable-care standard. Senate Bill 26-189 repealed and reenacted that framework in May 2026.

The replacement law uses a different center of gravity. It regulates automated decision-making technology that materially influences consequential decisions. Its main requirements concern notices, technical documentation, explanations after adverse outcomes, correction of inaccurate personal data, and meaningful human review.

The new law takes effect January 1, 2027. It is narrower in some important ways, but it is not light-touch. Companies still need to know which systems are covered, who is acting as developer or deployer, what role the technology played in a decision, and whether a human reviewer can reconsider the result in a meaningful way.

The Short Answer

  • Colorado replaced the original "high-risk AI system" framework with a law covering automated decision-making technology, or ADMT, that materially influences consequential decisions.
  • The replacement removes the original law's broad duty-of-care, risk-management, impact-assessment, and algorithmic-discrimination structure.
  • Developers must provide deployers with technical documentation, known limitations, appropriate-use instructions, and human-review guidance.
  • Deployers must give notice at the point of interaction and explain the role of covered ADMT after an adverse outcome.
  • Consumers may request correction of inaccurate personal data and meaningful human review and reconsideration.
  • The Colorado Attorney General has exclusive enforcement authority under the Colorado Consumer Protection Act. The law creates no new private right of action.

From "High-Risk AI" to Covered ADMT

The change in terminology is substantive.

SB 26-189 defines ADMT as technology that processes personal data and uses computation to generate output used to make, guide, or assist a decision about an individual. The output can include a prediction, recommendation, classification, ranking, score, or other information.

The law applies when ADMT is used to "materially influence" a consequential decision. Covered domains include:

  • education;
  • employment and compensation;
  • housing;
  • financial and lending services;
  • insurance;
  • health-care services; and
  • essential government services and public benefits.

That framing puts the decision process ahead of the product label. A tool does not become covered simply because a vendor calls it artificial intelligence. A company also cannot assume a system falls outside the law because it uses an older statistical method or carries no AI branding. The relevant questions are whether the technology processes personal data, produces computational output, and materially influences a covered decision.

The statute excludes several categories of tools, including specified cybersecurity and fraud-prevention technologies, basic spreadsheets that require human analysis, and tools that merely communicate, organize, or summarize information for later human review. Those exclusions make the boundary around "materially influence" especially important. A system that only organizes information may be outside the definition. A system that ranks candidates or recommends a denial may be doing much more.

What Colorado Removed

The 2024 law asked developers and deployers of high-risk AI systems to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. It offered a rebuttable presumption of reasonable care for companies that followed a detailed compliance structure.

For deployers, that structure included a risk-management policy, impact assessments, annual reviews, public disclosures about high-risk systems, and reporting certain algorithmic-discrimination risks to the Attorney General.

SB 26-189 does not carry that architecture forward.

The replacement law removes the general reasonable-care duty tied to algorithmic discrimination. It also removes the statutory risk-management-program and impact-assessment requirements that made the original Colorado law resemble an enterprise AI governance regime.

That is a major narrowing. It matters for both compliance costs and the pending constitutional dispute over the earlier framework.

It does not mean discrimination risk disappeared. Existing civil-rights and antidiscrimination laws still apply. SB 26-189 also addresses how fault may be allocated between developers and deployers in civil actions alleging unlawful discrimination under existing law. What changed is the AI statute's own regulatory mechanism.

What Developers Must Provide

Starting January 1, 2027, a developer of covered ADMT must provide deployers with technical documentation. The documentation must address subjects that a deployer needs in order to use the system appropriately, including:

  • intended uses;
  • categories of training data;
  • known limitations;
  • instructions for appropriate use; and
  • instructions for human review.

Developers must also notify deployers of material updates or modifications.

This creates a practical supply-chain obligation. A deployer cannot provide a useful explanation or conduct a meaningful review if the developer supplies only a marketing deck and a generic assurance that the model is compliant.

Contracts should identify who will provide the required documentation, how updates will be communicated, and what information the deployer will receive about limitations and review. Procurement teams should also check whether the vendor's documentation is specific enough to support a real decision workflow.

Both developers and deployers must retain records needed to show compliance for at least three years.

What Deployers Must Tell People

The replacement law places much of the consumer-facing work on deployers.

A deployer must provide clear and conspicuous notice at the point where a consumer interacts with covered ADMT. If the ADMT materially influences a consequential decision that produces an adverse outcome, the deployer must provide a plain-language description within 30 days.

That description must explain the consequential decision and the role the covered ADMT played. The law also requires a process through which the consumer can request more information and exercise the rights provided by the statute.

This is not satisfied by a general privacy notice that says the company "may use automated tools." The required explanation is tied to an actual adverse decision and the technology's role in it.

Companies will need to preserve enough decision-level information to answer questions such as:

  • Which model or system version was used?
  • What data about the individual entered the process?
  • What output did the system produce?
  • Who received that output?
  • How did the output affect the final decision?
  • Could a human decision-maker depart from it?

Without those records, a 30-day explanation requirement can turn into an expensive reconstruction exercise.

Correction Rights and Meaningful Human Review

Consumers affected by an adverse outcome may request access to personal data and correction of factually incorrect or materially inaccurate personal data used in the decision. They may also request meaningful human review and reconsideration.

The word "meaningful" should do real work.

Review cannot amount to routing the same data through the same system and returning the same answer. A reviewer should have enough authority, information, and time to evaluate the decision. The process should show what the reviewer considered and whether the reviewer could change the result.

For employers, lenders, insurers, health-care organizations, and government programs, this raises an operational question that should be answered before launch: who can actually reconsider an adverse outcome?

A policy that promises human review without assigning a qualified reviewer or giving that person authority to act will be hard to defend.

Enforcement and the Cure Period

The Colorado Attorney General enforces SB 26-189 through the Colorado Consumer Protection Act. A violation is treated as a deceptive trade practice.

The statute does not create a new private right of action. Before bringing an enforcement action prior to January 1, 2030, the Attorney General must provide 60 days' notice and an opportunity to cure when a cure is possible.

The cure period reduces immediate enforcement pressure, but it is not a substitute for implementation. Some failures can be fixed prospectively. Missing decision records, inadequate notices, or a review process that never existed may be much harder to repair after an adverse outcome.

What the Replacement Means for the xAI Case

xAI filed its federal lawsuit against the original Colorado law in April 2026. The United States later intervened. Their constitutional claims targeted the earlier statute's algorithmic-discrimination and risk-governance structure.

SB 26-189 changes the object of that fight.

The federal court's April 27 order anticipated that possibility. It covers SB 24-205 and legislation enacted during the 2026 session that replaces or amends it. The order also allows xAI to amend its complaint, if necessary, after Colorado adopts final implementing rules. The Attorney General agreed not to enforce covered violations occurring on or before 14 days after the court rules on the forthcoming preliminary-injunction motion.

There is no final merits ruling. It is also too early to say which constitutional claims will remain live against the replacement law. Removing the earlier algorithmic-discrimination duty may narrow some arguments, while notice, documentation, and decision-review requirements could generate different ones.

For now, the litigation affects timing and uncertainty. It does not erase the January 1, 2027 statutory effective date or the need to prepare for the final rules.

What Companies Should Do Before 2027

Companies can start with the decision process rather than attempting a company-wide inventory of anything labeled AI.

First, identify systems that use personal data to rank, score, recommend, classify, or otherwise influence decisions in the covered domains.

Second, document why each system does or does not materially influence the decision. That boundary judgment may become important later.

Third, map developer and deployer roles. The same company may be a deployer for purchased software and a developer for internally built or substantially modified tools.

Fourth, test whether vendor documentation covers intended uses, training-data categories, limitations, updates, and human review. Add contract terms where the documentation or update process is weak.

Fifth, build the adverse-outcome workflow. Decide who sends the explanation, where the decision record lives, how correction requests are handled, and who performs reconsideration.

Finally, test the human-review process with a real example. A written promise of review is not enough if the reviewer cannot understand the system's contribution or change the outcome.

Bottom Line

Colorado's replacement law is less focused on enterprise-wide AI governance and more focused on what happens around an individual decision.

The central compliance questions are concrete. Was the technology covered? Did it materially influence the outcome? Was the person notified? Can the company explain what happened? Can inaccurate data be corrected? Can a human reviewer reconsider the decision?

SB 26-189 removed some of the most demanding parts of Colorado's original AI Act. It replaced them with obligations that depend on reliable decision records and working review procedures.

Companies have until January 1, 2027 to build those procedures. The systems, contracts, and records needed to make them work should be addressed well before then.

Sources and Related Clearon Coverage