Colorado Governor Jared Polis signed Senate Bill 189 (“SB 189”), a bill that repeals and replaces the 2024 Colorado AI Act with a narrower, more business-friendly framework focused on automated decision-making technology (“ADMT”) used in consequential decisions. The new law significantly scales back the obligations that would have applied under the 2024 Colorado AI Act that was set to take effect June 30, 2026, while preserving notice, recordkeeping, consumer rights and certain other obligations for ADMT used in high-impact contexts. Colorado will continue to have one of the most far-reaching legislatively enacted private-sector artificial intelligence (“AI”) or ADMT laws in the United States. The new law takes effect January 1, 2027.  

Background: From the Colorado AI Act to SB 189

In May 2024, Colorado became the first U.S. state to enact comprehensive AI legislation when it adopted SB 24-205. The 2024 law applied to developers and deployers doing business in Colorado that developed or used “high-risk artificial intelligence systems,” defined generally as AI systems that, when deployed, made or were a substantial factor in making consequential decisions. Consequential decisions under the 2024 law included decisions affecting education, employment, financial or lending services, essential government services, healthcare services, housing, insurance, and legal services.

The 2024 law imposed a risk-based compliance framework designed to prevent algorithmic discrimination. Developers and deployers were required to use reasonable care to protect consumers from known or foreseeable risks of algorithmic discrimination, and compliance with the statute and any implementing regulations created a rebuttable presumption that reasonable care had been used. Developers were required to provide deployers with information about foreseeable uses, known harmful or inappropriate uses, training data, governance measures, potential biases, mitigation measures, and information needed for deployers to complete impact assessments and understand system outputs. Deployers were required to implement and regularly update a risk management policy and program, complete impact assessments, conduct annual reviews, provide consumer notices, and provide rights under the Colorado Privacy Act (“CPA”), including a right to appeal an adverse consequential decision. The 2024 law also required certain notices to the Colorado Attorney General if a high-risk AI system caused, or posed known or reasonably foreseeable risks of causing, algorithmic discrimination.

The original Colorado AI Act was initially scheduled to take effect on February 1, 2026. Following criticism that the law could stifle AI innovation, the Colorado legislature considered amendments during the next regular session and a special session, and ultimately extended the effective date to June 30, 2026. In March 2026, Governor Polis announced that a working group he had convened had agreed on a policy framework to replace the Colorado AI Act, which ultimately became SB 189 and was. signed by the Governor on May 14, 2026.

Analysis of the New Law

Covered ADMT and Covered Uses

SB 189 shifts the core regulatory trigger from “high-risk AI systems” to “covered ADMT.” ADMT is defined broadly as technology that processes personal data and uses computation to generate output, including predictions, recommendations, classifications, rankings, scores, or other information used to make, guide, or assist a decision, judgment, or determination concerning an individual. “Covered ADMT” means ADMT that is used to materially influence a consequential decision.

The statute defines “materially influence” to mean that the ADMT output is a “non-de minimis factor” used in making a consequential decision and affects the outcome of that decision, including by constraining, ranking, scoring, recommending, classifying, or otherwise meaningfully altering how the decision is made. The definition excludes incidental, trivial, or clerical uses. Because the scope of “materially influence” will be central to the law’s practical reach, the statute authorizes the Colorado Attorney General to adopt rules clarifying the definition.

The new law applies when a covered ADMT materially influences a “consequential decision” about a consumer. A consequential decision includes a decision, determination, or action about a consumer that relates to the provision of, or the consumer’s access to, eligibility for, selection for, or compensation for a covered domain and decisions about differentiated price, cost sharing, compensation, or other material terms where the decision is reasonably likely to materially limit, delay, effectively deny, or otherwise fundamentally alter the consumer’s access, eligibility, or opportunity in a covered domain.

The covered domains are education enrollment or opportunity, employment or an employment opportunity creating or potentially creating an employer-employee relationship, the lease or purchase of residential real estate in Colorado, financial or lending services, insurance, health-care services, and essential government services and public benefits. Notably, the new law’s covered domains do not include legal services, which were included in the 2024 Colorado AI Act.

The statute contains several exclusions that narrow the scope of covered activity. For example, ADMT does not include listed technologies such as anti-malware, anti-virus, calculators, databases, data storage, firewalls, networking, spell-checking, or spreadsheets that require human analysis and do not use machine learning, foundation models, or large language models, web caching, or web hosting. The definition of consequential decision also excludes low-stakes or routine decisions and business processes, advertising and marketing, differentiated product recommendations, search, and content moderation, among other exceptions.

Developer Obligations

SB 189 maintains the 2024 law’s differentiation between developers and deployers. Developer obligations are primarily documentation obligations owed to deployers. Developers must make available to each deployer of covered ADMT information including a general statement describing the intended uses and known harmful or inappropriate uses of the covered ADMT. It also must include a description of the categories of data, including personal data, used to train the covered ADMT, to the extent known. Developers must disclose known limitations of the covered ADMT, including known risks and circumstances in which the ADMT should not be used. Developers also must provide instructions for the deployer’s appropriate use, monitoring, and meaningful human review, where applicable, and information reasonably necessary for the deployer to comply with the deployer disclosure requirements.

The developer obligations apply when the developer creates a covered ADMT intended, documented, marketed, advertised, configured, or contracted for use in consequential decisions, or when the developer becomes aware that the covered ADMT is being used to make consequential decisions in a manner consistent with the intended and contracted uses.

Deployer Obligations

SB 189 defines a deployer as a person doing business in Colorado that deploys a covered ADMT. The deployer obligations are more extensive than the developer obligations, but substantially less onerous than the obligations imposed under the 2024 law.

Consumer Disclosures

Before using covered ADMT to materially influence a consequential decision, a deployer must provide a clear and conspicuous notice to the consumer that the deployer used or will use covered ADMT in a consequential decision affecting the consumer. A deployer may satisfy this pre-use notice requirement by maintaining a prominent public notice that is reasonably accessible at points of consumer interaction, including through a link or posting reasonably proximate to the interaction or transaction in which a consequential decision may occur.

If a deployer uses covered ADMT to materially influence a consequential decision that results in an adverse outcome for a consumer, the deployer must provide a post-adverse outcome disclosure within 30 days after making the decision. An adverse outcome includes a decision that denies, terminates, revokes, or materially reduces or restricts a consumer’s access to, eligibility for, selection for, compensation for, or provision of an opportunity or service. It also includes a decision resulting in materially less favorable differentiated price, cost, compensation, or other material terms reasonably likely to materially limit, delay, effectively deny, or fundamentally alter a consumer’s access to, eligibility for, selection for, compensation for, or provision of an opportunity or service compared with terms offered to similarly situated consumers.

The post-adverse outcome disclosure must provide a plain language description of the consequential decision and the role the covered ADMT played in that decision. It also must provide instructions and a simple-to-follow process for requesting additional information about the covered ADMT and the inputs used, including the name of the covered ADMT, version number if applicable, developer, and the types, categories, and sources of personal data used, to the extent the deployer receives the necessary information from the developer. The disclosure must also explain the consumer rights provided by the statute and how to exercise them. Notably, this disclosure of personal data types, categories, and sources used in the decision mirrors obligations under the CPA and may require deployers to coordinate AI disclosures with privacy notice updates.

The statute directs the Attorney General to adopt rules by January 1, 2027, to clarify and implement the post-adverse outcome disclosure requirements. This shift under the new law focuses on transparency, which has been the focus of many legislative efforts across the country seeking to govern the use of AI. The Colorado statute also provides that a creditor required to provide, and does provide, notices under the Equal Credit Opportunity Act and, when applicable, the Fair Credit Reporting Act, need not provide duplicative notices if the federal notice also satisfies the relevant SB 189 requirements.

Recordkeeping

Deployers must retain, for at least three years after the date of a consequential decision or for a longer period required by applicable state or federal law, records reasonably necessary to demonstrate compliance with the new law. Relevant records may include information about the ADMT tool used, the version of the pre-use notice, records showing how the notice was communicated, adverse action notices, and records of the decision-making process.

Consumer Rights

When a consumer experiences an adverse outcome resulting from a consequential decision in which covered ADMT materially influenced the decision, the consumer may request certain rights from the deployer. In response, the deployer must provide instructions for requesting personal data and correcting factually incorrect or materially inaccurate personal data used in the consequential decision, consistent with the CPA. This integration with the CPA rights means deployers must ensure their data subject’s access request and correction workflows can address the particular personal data used in ADMT-driven decisions. The deployer also must provide an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable.

“Meaningful human review” is specifically defined. The review must be conducted by an individual designated by the deployer who has authority to approve, modify, or override the consequential decision. The Colorado Attorney General must adopt rules by January 1, 2027, to clarify and implement the consumer rights requirements.

Enforcement and Liability

A violation of the new law is a deceptive trade practice subject to the Colorado Consumer Protection Act. The law will be enforced by the Colorado Attorney General and does not create a new private right of action. Before bringing an enforcement action, the Attorney General must issue a notice of violation to a developer or deployer if the Attorney General deems a cure possible. If the developer or deployer fails to cure within 60 days after receiving the notice, the Attorney General may bring an action. The cure period requirement sunsets on January 1, 2030.

SB 189 also includes express liability allocation provisions for unlawful discrimination claims arising from consequential decisions materially influenced by covered ADMT. A developer or deployer may be held liable in an action alleging unlawful discrimination under Colorado anti-discrimination laws, including the Colorado Anti-Discrimination Act, arising from a consequential decision materially influenced by covered ADMT.

The law also restricts indemnification for certain liabilities. Contract provisions that purport to indemnify, defend, or hold harmless a party from liability for damages resulting from that party’s own acts or omissions related to the use of ADMT in consequential decisions in violation of the Colorado Anti-Discrimination Act or other Colorado anti-discrimination law are contrary to public policy and void.

New Law within the Broader AI Regulatory Landscape

SB 189 reflects a shift toward a narrower, more disclosure-oriented approach to AI and automated decision-making regulation that favors innovation over complex regulation.

Even with the reduced obligations, businesses face an increasingly complex patchwork of AI and automated decision-making laws. Many other states have continued to pass AI regulation. Among them are California’s risk assessment and automated decision-making technology regulations, employment-related laws in Illinois and New York City, and additional AI-related legislation under consideration in state legislatures nationwide. Businesses using AI or ADMT in employment, financial services, housing, healthcare, insurance, education, government benefits, and other high-impact contexts should expect continued regulatory development.

Key Takeaways

  • Companies doing business in Colorado should revisit AI governance programs to determine whether they use ADMT that processes personal data and materially influences consequential decisions in a covered domain.
  • Developers should prepare deployer-facing documentation describing intended uses, known harmful or inappropriate uses, training data categories, known limitations, circumstances in which the covered ADMT should not be used, and instructions for appropriate use, monitoring, and meaningful human review.
  • Deployers should develop pre-use notices, post-adverse outcome disclosure processes, and consumer request workflows for correction and meaningful human review. Deployers should also implement record retention practices designed to preserve records reasonably necessary to demonstrate compliance for at least three years after each consequential decision.
  • Businesses should review developer-deployer contracts for documentation commitments, update-notice obligations, obligations to obtain access to information needed for consumer disclosures, and indemnification provisions that may be void under the new statute. Businesses should also assess whether existing data retention policies support these three-year retention requirements while also complying with data minimization principles under the CPA.
  • Privacy teams should coordinate with AI governance functions to ensure that ADMT-related personal data processing is accurately reflected in privacy notices, data inventories, and data processing records. The law’s reliance on personal data as a definitional trigger means existing privacy compliance infrastructure may need to be updated to capture ADMT-specific processing activities.
  • Organizations should monitor Colorado Attorney General rulemaking closely as such rules are likely to be especially important in determining the law’s practical scope, the content of required notices, and the operational requirements for consumer rights.

For more information or assistance, please contact Sharon R. Klein, Alex C. Nisenbaum, Rachel L. Schaller, Karen H. Shin, Gabrielle N. Ganze, or another member of Blank Rome’s Privacy, Security & Data Protection team.