AI Regulation Colorado, US

Colorado AI Act: The First US Algorithmic Discrimination Law

Colorado's Artificial Intelligence Act (SB 24-205) explained: high-risk AI in consequential decisions, developer and deployer duties, impact assessments, and the delayed effective date.

Regulation

Colorado Artificial Intelligence Act, SB 24-205 (2024), codified at C.R.S. 6-1-1701 et seq.; effective date delayed by SB 25B-004 to June 30, 2026

Max Penalty

Violations are unfair trade practices under the Colorado Consumer Protection Act, up to $20,000 per violation

Enforcing Authority

Colorado Attorney General (exclusive enforcement; no private right of action)

Official Source

leg.colorado.gov

Executive Summary

  • Colorado enacted the first comprehensive US state AI law in May 2024, targeting algorithmic discrimination from high-risk AI systems used in consequential decisions: employment, education, financial services, housing, healthcare, insurance, legal services, and essential government services.
  • Both developers and deployers owe a duty of reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination.
  • Deployers must run a risk-management program (NIST AI RMF or ISO 42001 explicitly satisfy it), complete impact assessments, notify consumers of AI use in consequential decisions, and provide adverse-decision explanations with appeal and human-review rights.
  • The legislature delayed the effective date from February 1, 2026 to June 30, 2026 in a 2025 special session after amendment efforts failed; further amendment attempts are likely before then.
  • The Attorney General enforces exclusively under the Consumer Protection Act (up to $20,000 per violation); compliance with a recognized risk framework supports an affirmative defense posture.

Colorado did what Congress has not: it wrote enforceable, cross-sector AI law with a specific theory of harm, discrimination in the decisions that gate people’s jobs, homes, credit, care, and schooling. The statute’s architecture is a study in pragmatism: duties split along the supply chain, recognized frameworks like NIST AI RMF and ISO 42001 accepted as the program backbone, presumptions and defenses that reward documentation over perfection, and an effective-date fight that reveals how contested this ground remains. For companies in covered sectors the strategic read is simple: every serious AI-accountability proposal now circling US legislatures shares Colorado’s skeleton, so building the inventory, the discrimination testing, the vendor-documentation pipeline, and the explanation machinery is not a bet on one state’s statute surviving intact. It is the entry fee for algorithmic decision-making in regulated markets, payable once, reusable everywhere.

Signed / effectiveMay 17, 2024; effective June 30, 2026 (delayed from Feb 1)
RegulatesHigh-risk AI in consequential decisions; harm hinge is algorithmic discrimination
Key dutiesReasonable care, developer disclosures, deployer risk program + impact assessments, notices, appeal rights
Named frameworksNIST AI RMF, ISO/IEC 42001 satisfy the program requirement
EnforcementColorado AG only; CCPA penalties to $20,000 per violation
StatuteSB 24-205

Building for June 2026

Stand up the framework now. NIST AI RMF or ISO 42001 is named-in-statute governance; it survives any amendment.

Test for disparate impact. Discrimination analysis is Colorado’s technical center; AI bias audit practices transfer directly.

Demand the developer packet. Procurement contracts should require the statutory disclosures per system and version.

Reconcile with CPA machinery. Profiling opt-outs and DPIAs share plumbing; see automated decision-making opt-outs and the EU AI Act comparison.

Consequential-decision flows often start at your website: see what your forms and tools collect with a free scan.

Frequently Asked Questions

What does the Act regulate, and what counts as a high-risk system?

The target is algorithmic discrimination: any condition in which use of an AI system results in unlawful differential treatment or impact disfavoring people on the basis of actual or perceived age, color, disability, ethnicity, genetic information, limited English proficiency, national origin, race, religion, reproductive health, sex, veteran status, or other protected classifications under Colorado or federal law. A high-risk AI system is one that, when deployed, makes or is a substantial factor in making a consequential decision: a decision with material legal or similarly significant effect on provision, denial, cost, or terms of education enrollment or opportunity, employment or an employment opportunity, a financial or lending service, an essential government service, healthcare services, housing, insurance, or a legal service. 'Substantial factor' captures systems that assist human deciders, not only fully automated ones, a resume screener that ranks candidates for a human recruiter is in scope. Carve-outs exclude systems performing narrow procedural tasks and enumerated technologies (calculators, spam filters, cybersecurity tools, spell-checkers) unless they make or substantially influence consequential decisions. The frame will feel familiar to EU AI Act readers, consequential-decision categories echo Annex III, but Colorado's single hinge is discrimination, not the EU's broader health-safety-fundamental-rights sweep, which makes disparate-impact analysis the technical center of Colorado compliance.

What do developers owe under the Act?

Developers (who create or intentionally and substantially modify a high-risk system) owe reasonable care against algorithmic discrimination plus a disclosure regime built to let deployers comply downstream. To deployers: a statement of the system's intended uses and known harmful or inappropriate uses; documentation of training-data summaries, known or foreseeable limitations and discrimination risks, the system's purpose, intended benefits, and evaluated performance; and the information a deployer needs to complete its impact assessments and to understand outputs and monitor performance. Publicly: a statement summarizing the types of high-risk systems the developer makes available and how it manages known or reasonably foreseeable algorithmic-discrimination risks. To the Attorney General: disclosure, within 90 days, of any known or reasonably foreseeable risk of algorithmic discrimination the developer discovers the system has caused or is reasonably likely to cause, whether discovered internally or via a credible deployer report. The duty of care carries a rebuttable presumption of compliance if the developer meets the section's requirements, the statute's core carrot: paper the disclosures properly and the burden shifts. For AI vendors selling into Colorado's covered sectors, the practical work is productizing this documentation, a 'Colorado packet' per system, versioned with releases, because every deployer's compliance depends on receiving it and contracts will demand it.

What do deployers owe, especially around impact assessments and consumer rights?

Deployers (Colorado businesses using high-risk systems) carry the heavier operational load. Risk-management program: a documented, iterative program governing high-risk AI deployment, and the statute names its acceptable shapes, the NIST AI Risk Management Framework, ISO/IEC 42001, or another recognized comparable framework, sized to the deployer's scale and the system's risk. Impact assessments: before deploying and at least annually (and within 90 days after an intentional substantial modification), covering purpose and intended use, discrimination risk analysis and mitigation, data categories processed, performance metrics and limitations, transparency measures, and post-deployment monitoring; assessments are retained and producible to the AG on demand. Consumer notice: before or at the time a high-risk system makes or substantially factors into a consequential decision about a consumer, tell them, plus a plain-language statement of the system's purpose and the decision's nature, and the deployer's public website must describe the high-risk systems it deploys and its risk management. Adverse decisions: if the decision is adverse, the consumer gets the principal reasons (including the degree the system contributed and the data types and sources involved), an opportunity to correct inaccurate personal data the decision relied on, and an opportunity to appeal with human review where feasible. Small-deployer relief: employers under 50 FTE using systems as intended without their own training data get partial exemptions from the program, assessment, and website duties. General-purpose consumer-facing AI (any AI system interacting with consumers, not just high-risk) must disclose it is AI unless obvious.

When does it take effect, and why did the date move?

The original effective date was February 1, 2026. It is now June 30, 2026, moved by SB 25B-004 in an August 2025 special session, and the story behind the move matters for planning. Governor Polis signed SB 24-205 in May 2024 'with reservations,' publicly inviting amendment before effectiveness; a 2025 regular-session rewrite effort (SB 25-318) collapsed; stakeholder negotiations between industry (seeking narrower definitions, duty relief for small business, and delay) and consumer advocates (defending the discrimination core) deadlocked; and the special session produced only the delay, not substantive amendment. Read three implications. First, the June 30, 2026 date is real for planning purposes, systems, contracts, and assessment programs take quarters to build, and betting on repeal is not a program. Second, substantive amendment before effectiveness remains genuinely possible in the 2026 regular session, most plausibly around definitions, small-business thresholds, and cure provisions, so build the durable components (inventory, discrimination testing, vendor documentation flows) that survive any likely amendment, and defer only the pure-paperwork artifacts most exposed to rewording. Third, Colorado's stumble chilled copycat momentum, other states watched the fight, Connecticut's similar bill stalled repeatedly, and the 2025-2026 state pattern shifted toward narrower laws (Utah's disclosure statute, Illinois' employment-AI amendments, Texas's TRAIGA) and toward scrutiny of federal preemption efforts, so Colorado remains the high-water mark of US comprehensive AI regulation for now.

How does it interact with the EU AI Act, the Colorado Privacy Act, and how should a company sequence compliance?

Against the EU AI Act: Colorado borrowed the consequential-decision architecture but narrowed the harm to discrimination, dropped the prohibition tier and conformity-assessment machinery, and split duties along the same developer/deployer seam. A company building EU high-risk compliance holds most Colorado assets already: the EU risk-management system exceeds Colorado's program requirement (both map to NIST AI RMF and ISO 42001), Annex IV documentation covers most of Colorado's developer disclosure content, and EU human-oversight design covers Colorado's human-review expectations; the genuine Colorado deltas are the discrimination-specific impact analysis (disparate-impact testing against US protected classes, a different statistical and legal exercise than EU fundamental-rights analysis), the adverse-decision explanation and appeal workflow with its specific content requirements, and the AG-notification clock. Against the Colorado Privacy Act: the CPA's profiling opt-out and DPIA requirements already touch automated decisions with significant effects, and the two regimes share data-inventory and assessment plumbing; run one assessment pipeline emitting both artifacts, and reconcile the consumer-notice surfaces so the privacy notice, CPA opt-out disclosures, and AI Act statements do not contradict each other. Sequencing for a company facing both continents: EU first if 2026 EU exposure exists (broader duties, bigger fines), Colorado's deltas layered on the same chassis; Colorado-only companies should stand up NIST AI RMF governance now, wire the vendor-documentation demands into procurement immediately (developer packets take vendors quarters to produce), build discrimination testing where consequential decisions run, and hold the notice and appeal templates until the amendment picture clarifies in spring 2026.

Regulatory Crosswalk

EU AI ActNIST AI RMFISO/IEC 42001Colorado Privacy Act

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.