That was fast! Colorado repeals and replaces 2024 AI law
On May 14, 2026, Gov. Jared Polis (D) signed Senate Bill 26-189, which repeals and replaces Colorado’s 2024 Artificial Intelligence Act. The revised law generally applies to consequential decisions made on or after January 1, 2027.
The new law substantially narrows Colorado’s regulation of automated decision-making technology, replacing the broad governance framework enacted in 2024 with a more targeted approach focused on transparency, notice, recordkeeping, and human review.
The original AI Act (SB 24-205) made national headlines as the first comprehensive state law regulating “high-risk” artificial intelligence systems. It would have required organizations deploying certain high-risk AI systems to implement risk-management programs, conduct impact assessments, exercise reasonable care to prevent algorithmic discrimination, and satisfy extensive governance and documentation requirements. The original Act’s substantive requirements were initially scheduled to take effect on February 1, 2026, but the General Assembly later postponed that date until June 30.
Employers, technology companies, and other stakeholders raised significant concerns regarding the original law’s complexity and practical implementation. In response, the General Assembly enacted SB 26-189 before the original requirements became operative, substantially rewriting the statute and postponing the applicability of the replacement requirements until January 1, 2027.
Although the revised law significantly reduces employers’ compliance obligations, it does not eliminate them. Employers who use AI-enabled or other automated technologies to make or materially influence decisions related to hiring, compensation, promotion, discipline, or termination should begin evaluating whether those technologies are subject to the new law.
The following is a summary of the requirements under the new law (SB 26-189).
Covered technology
The law regulates certain “automated decision-making technology,” or “ADMT.” ADMT generally means technology that processes personal data and uses computation to generate predictions, recommendations, classifications, rankings, scores, or other information used to make, guide, or assist a decision concerning an individual.
ADMT is covered only when it “materially influences” a “consequential decision.” An automated output “materially influences” a decision when it is a non-de minimis factor that affects the outcome. This includes ranking, scoring, recommending, or classifying an individual. Incidental, trivial, and clerical uses of ADMT are excluded.
In the employment context, “consequential decisions” include decisions affecting an individual’s access to, eligibility for, selection for, or compensation for employment or an employment opportunity. Depending on the circumstances, this may include hiring, promotion, compensation, discipline, and termination decisions.
Not every workplace technology is covered. The statute excludes tools used solely to summarize, organize, translate, draft, route, or present information for human review of administrative processing. It also excludes routine business processes that do not materially influence an employment opportunity as well as tools that merely present information without producing a score, ranking, recommendation, classification, prediction, or other “inference” that materially affects the decision.
Thus, a tool that merely organizes application materials for human review may fall outside the law. However, a tool that scores or ranks applicants and meaningfully affects who advances is more likely to be covered.
Who is covered
The law regulates employers doing business in Colorado when they use covered ADMT to materially influence consequential employment decisions. An employer need not be headquartered or based in Colorado to be covered.
The statute uses the term “consumer” to describe the individual affected by an automated decision. In the employment context, “consumer” includes an employee; a Colorado-resident job applicant; and any individual whose access to, eligibility for, or opportunity in Colorado is evaluated in a consequential decision by a person doing business in Colorado.
Thus, an out-of-state employer may be subject to the law if it does business in Colorado and uses covered ADMT to materially influence a decision (1) involving an applicant who is a Colorado resident or (2) regarding an employment opportunity in Colorado. The statute does not expressly limit its coverage of employees to Colorado residents, but forthcoming regulations may provide additional guidance concerning its geographic scope.
Employer obligations
“Developer” versus “deployer.” The law distinguishes “developers,” who create or make covered ADMT commercially available, from “deployers,” who use it. An employer using a vendor’s technology to materially influence an employment decision will generally be the deployer.
Starting January 1, 2027, developers must provide deployers with information regarding the technology’s intended uses, known harmful or inappropriate uses, training-data categories, known limitations, and instructions for appropriate use, monitoring, and meaningful human review. Developers must also notify deployers within a reasonable time of material updates, intentional and substantial modifications, and changes to the technology’s intended use, limitations, or risk-mitigation measures.
Required notices. Before using covered ADMT to “materially influence” a “consequential decision,” an employer must provide affected applicants or employees with clear and conspicuous notice that covered ADMT was or will be used and explain how they may obtain additional information. An employer may satisfy this requirement through a prominent public notice that is reasonably accessible at the point of interaction.
If covered ADMT materially influences a consequential decision resulting in an adverse outcome, the employer must provide the affected individual with an additional disclosure within 30 days after making the decision. The disclosure must describe the decision and the role the technology played, explain how to request additional information about the technology and the personal data used, and explain the individual’s statutory rights and how to exercise them.
Human review and correction. After an adverse “consequential decision” that was “materially influenced” by covered ADMT, an individual may request instructions for obtaining the personal data used in the decision. The individual must also have the opportunity to correct any factually incorrect or materially inaccurate personal data. However, the employer is not required to correct opinions, predictions, scores, or protected evaluations.
The individual may also request meaningful human review and reconsideration, to the extent commercially reasonable. The review must be conducted by a trained person with authority to approve, modify, or override the decision. The reviewer must consider relevant evidence and may not simply default to the automated output.
Record retention. Employers who use covered ADMT must retain records reasonably necessary to demonstrate compliance for at least three years after the “consequential decision,” or longer if required by another law.
Enforcement and rulemaking
The law creates no new private right of action. Its disclosure, recordkeeping, and consumer-rights requirements are enforceable exclusively by the Colorado Attorney General under the Colorado Consumer Protection Act. The law nevertheless preserves claims and remedies available under existing laws, including the Colorado Anti-Discrimination Act.
In actions alleging discrimination under existing Colorado anti-discrimination laws, fault is allocated between a developer and deployer according to their relative responsibility for the violation. A developer generally may be liable only when its technology (1) was used as the developer intended, documented, marketed, advertised, configured, or contracted for, and (2) materially influenced the decision giving rise to the violation. A deployer (the employer) remains responsible for its independent acts or omissions, including using the technology in a manner that the developer did not intend.
The law also makes void any contractual provision between a developer and a deployer to the extent that the provision purports to indemnify, defend, or hold either party harmless from liability for its own acts or omissions in violation of the state anti-discrimination law.
On or before January 1, 2027, the Attorney General must adopt rules clarifying the required post-adverse-outcome disclosures and implementing the law’s requirements concerning correction of inaccurate personal data, meaningful human review, and reconsideration.
Until January 1, 2030, the Attorney General generally must provide notice of a violation and a 60-day opportunity to cure if the Attorney General determines that a cure is possible. No cure period is required if the Attorney General can demonstrate that the developer or deployer knowingly or repeatedly violated the law.
Be ready for January 1!
Before January 1, 2027, employers subject to the law should do the following:
- Identify employment technologies used throughout the employment life cycle that may be covered ADMT. This could include resume-screening software, candidate-matching systems, automated interview tools, performance management systems, compensation recommendation software, and productivity analytics. For each technology, employers should determine whether it generates a prediction, ranking, score, recommendation, classification or other output, and whether that output materially influences an employment decision.
- Review how automated outputs affect employment-related decisions.
- Evaluate vendor documentation and contracts. Employers should ensure that vendor contracts provide access to the information needed to satisfy the law and appropriately address compliance responsibilities, material updates, data access, recordkeeping, and insurance.
- Prepare the required notices and adverse-outcome disclosures.
- Establish correction and meaningful procedures for human review.
- Ensure that relevant records are retained for at least three years.
- Monitor forthcoming guidance from the Colorado Attorney General.
Need help?
If you need assistance, please feel free to contact any attorney in Constangy’s Denver Office, Artificial Intelligence or Cybersecurity & Data Privacy Group.