The Colorado AI Act (SB 24-205) is a Colorado statute requiring developers and deployers of high-risk AI systems to use reasonable care to avoid algorithmic discrimination in consequential decisions. Enacted on May 17, 2024, it was the first US state law primarily focused on AI equity and anti-discrimination. As of mid-2026 the Act faces a federal constitutional challenge from xAI and the U.S. Department of Justice, and a working group convened by Governor Jared Polis has proposed repealing and replacing it with a narrower transparency regime, carried by SB 26-189.
Enacted: 2024-05-17 Effective: June 30, 2026 (amended from Feb 1, 2026 by SB 25B-004) Enforcement: Colorado Attorney General (no private right of action)
Status and timeline
SB 24-205 was enacted on May 17, 2024. Its effective date, originally February 1, 2026, was moved to June 30, 2026 by SB 25B-004. Governor Polis signed the original bill "with reservations," and Attorney General Philip J. Weiser has publicly expressed his own reservations about the Act.
After an August 2025 special session that did not produce a revised bill, Governor Polis convened the Colorado AI Policy Work Group, which met weekly beginning in October 2025. On March 17, 2026 the work group released a unanimous framework to repeal and replace SB 24-205, targeting a January 1, 2027 effective date (Governor's announcement: governorsoffice.colorado.gov). On May 1, 2026 Senate Majority Leader Robert Rodriguez (the original 2024 sponsor) and Senate President James Coleman introduced SB 26-189 to carry that framework into law before the June 30 effective date. The Colorado General Assembly adjourned May 13, 2026; if SB 26-189 does not pass, the original SB 24-205 takes effect June 30, 2026 as written (Source: coloradonewsline.com).
Separately, xAI filed a federal constitutional challenge on April 9, 2026 (see Legal challenges), and the U.S. Department of Justice moved to intervene on April 24, 2026.
Scope and definitions
The Act applies to high-risk AI systems, defined as those making consequential decisions about education, employment, lending, healthcare, housing, insurance, or legal services. Compliance with the Act's duties creates a rebuttable presumption of reasonable care.
It was the first US legislation framed around equity and discrimination rather than safety, competition, or national security. Compared with other US AI-regulation approaches, it represents an anti-discrimination model focused on equity in decisions and targeting deployers primarily:
| Approach | Example | Focus | Target | ||
|---|---|---|---|---|---|
| Frontier transparency | [[california-sb-53 | SB 53]] / [[new-york-raise-act | RAISE Act]] | Safety disclosure | Model developers |
| Product liability | [[ai-lead-act | AI LEAD Act]] | Harm compensation | Developers + deployers | |
| Anti-discrimination | Colorado AI Act | Equity in decisions | Deployers primarily |
The Act's consumer notice and opt-out provisions offer a different approach to AI control than the technical solutions discussed in AI as Normal Technology. It has been cited as an example of Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race, a state filling a regulatory gap not addressed federally, and its "consequential decision" focus connects to AI Labor Disruption, given AI's role in employment and lending decisions.
Obligations by actor
Developers of high-risk AI systems must use reasonable care to avoid algorithmic discrimination, provide documentation on training data and known limitations, and conduct impact assessments.
Deployers must implement risk management policies, complete annual impact assessments, notify consumers when AI is used in consequential decisions, allow opt-out where feasible, and disclose the principal reasons for adverse decisions.
Enforcement and penalties
Enforcement rests with the Colorado Attorney General; the Act provides no private right of action.
Legal challenges
xAI v. Weiser (D. Colo. 1:26-cv-01515, filed April 9, 2026)
xAI Corp. (Elon Musk's AI company, Nevada-incorporated and Palo Alto-headquartered) filed a six-count federal complaint against Colorado AG Philip J. Weiser on April 9, 2026 in the U.S. District Court for the District of Colorado, seeking declaratory judgment and a permanent injunction against enforcement before the June 30, 2026 effective date. The complaint seeks no damages. It alleges First Amendment, Equal Protection, Due Process, and Dormant Commerce Clause violations, and a preliminary-injunction motion is expected before June 30, 2026. The primary source is xAI Corp. v. Weiser — Complaint; the raw document is a complaint reconstruction (Source: Raw Sources/xAI v. Colorado Complaint).
The six counts are:
- First Amendment — Compelled Speech / Editorial Modification. Training-data selection, fine-tuning, system-prompt drafting, and guardrail design are characterized as expressive editorial acts; the reasonable-care duty compels xAI to alter them. The complaint demands strict scrutiny under Moody v. NetChoice (2024) and 303 Creative v. Elenis (2023).
- First Amendment — Viewpoint Discrimination. The Act's "increase diversity or redress historical discrimination" carve-out allegedly protects favored viewpoint-laden outputs while penalizing disfavored ones.
- First Amendment — Compelled Disclosure. Mandatory developer documentation is alleged to be content-based compelled speech; evaluating "algorithmic discrimination" is described as "inherently subjective" and thus outside Zauderer.
- Dormant Commerce Clause. The Act reaches any developer doing business in Colorado and regulates outputs produced anywhere that affect Colorado residents, which the complaint characterizes as extraterritorial overreach.
- Due Process — Vagueness. The terms "reasonable care," "algorithmic discrimination," "historical discrimination," "substantial factor," and "material legal or similarly significant effect" allegedly provide no ascertainable standard.
- Equal Protection. The diversity / historical-discrimination carve-out is characterized as a race-conscious classification that, per SFFA v. Harvard (2023), cannot survive strict scrutiny.
The complaint's load-bearing doctrinal move is the theory that every stage of AI model development — training-data curation, fine-tuning / RLHF, system-prompt drafting, and guardrail design — is expressive editorial activity protected by the First Amendment, extending Moody v. NetChoice one layer down the stack from content moderation to model development itself. The complaint, as quoted in coverage, argues that the challenged provisions "prohibit developers of AI systems from producing speech that the State of Colorado dislikes, while compelling them to conform their speech to a state-enforced orthodoxy on controversial topics of great public concern," and that enforcement would "force [Grok] to abandon its disinterested pursuit of truth." The doctrinal debate is covered in full at AI and the First Amendment.
The suit was filed in parallel with the AI Litigation Task Force created by EO 14365 (Dec. 11, 2025), which directed the U.S. AG to challenge state AI laws and specifically named the Colorado AI Act. AG Weiser's and Governor Polis's stated reservations about the Act (noted above) are facts xAI leverages for its vagueness claim. It is the first major constitutional challenge to a state AI anti-discrimination statute.
On April 24, 2026 the U.S. Department of Justice moved to intervene on xAI's side, arguing the law violates the Constitution by requiring discrimination (Source: bloomberg.com; insideaipolicy.com).
Federal preemption and lobbying
An FTC policy statement issued under the December 2025 Trump executive order, made public July 2, 2026, claimed preemption authority over "ideological" state AI laws and singled out the Colorado AI Act as appearing to "coerce companies into altering the output of their AI models" (Source: insideaipolicy.com).
A federal-preemption effort led by David Sacks of the President's Council of Advisors on Science and Technology (PCAST) has stalled in Congress, leaving the court challenge and direct state lobbying as the industry's primary tools. The American Innovators Network (AIN) has grown to more than 30 partners and hired Jeremy Kudon as executive director to oppose similar legislation state by state (Source: washingtonpost.com).
Repeal-and-replace effort
Working-group framework (March 2026)
On March 17, 2026 the Colorado AI Policy Work Group released a unanimous framework to repeal and replace SB 24-205. Andrew Clearwater, in a March 17, 2026 Substack analysis (classified as supporting; Source: andrewclearwater.substack.com), described it as "the most significant shift in the US AI regulatory landscape since the original law was signed in May 2024."
Under the framework, the "reasonable care" anti-discrimination duty is removed and replaced by procedural requirements: developers provide documentation; deployers give notice and post-adverse disclosures within 30 days; and consumers gain data-correction rights and meaningful human review. Clearwater characterizes the shift as moving the operative theory from preventing discrimination to telling people what is being done and giving them recourse — a transparency regime rather than an anti-discrimination regime.
Impact assessments are eliminated: no pre-deployment assessment, no annual review, and no 90-day modification trigger. Three-year record retention becomes the accountability mechanism.
Scope is narrowed. "High-risk AI system" is replaced by "Covered ADMT" (Automated Decision-Making Technology) that must "materially influence" a consequential decision, defined as a non-de minimis factor that affects the outcome. General-purpose tools such as ChatGPT are excluded if they are not configured for consequential decisions and carry an acceptable use policy prohibiting that use.
Liability changes from joint-and-several to allocation based on relative responsibility under existing anti-discrimination law, with developers liable only when their tool was used as intended and documented. Indemnification clauses shielding a party from its own discriminatory acts are void as against public policy, which Clearwater notes will require practitioners to renegotiate vendor contracts.
Enforcement remains AG-only, with a 90-day cure period and no private right of action. Post-adverse disclosure rules are to be defined through AG rulemaking by December 31, 2026.
Clearwater highlights that consumer advocates agreed to the framework, trading a duty of care, mandatory impact assessments, and "algorithmic discrimination" as a standalone concept for a transparency-and-notice regime, which he describes as a major concession. The term "algorithmic discrimination," which had made Colorado's law distinctive, does not appear in the new framework; discrimination liability would flow entirely through existing civil rights law, the Colorado Anti-Discrimination Act. Clearwater also notes the framework's timing, arriving as the Department of Commerce report identifying "onerous" state AI laws was due, and suggests that by slimming from an anti-discrimination framework to a transparency regime Colorado may be making itself a harder federal-preemption target.
Clearwater's reading of the broader trajectory: "Colorado was the proof of concept for comprehensive state-level AI regulation in the US. Two years later, the comprehensive part is likely being stripped out. The strategic read: the US is not getting a Colorado-style duty of care or mandatory impact assessment regime at the state level anytime soon. Not because nobody wants it but because federal preemption threats, industry lobbying, and interstate competition for tech companies make it politically unsustainable." He argues that what the US is getting instead is a floor of transparency, notice, and existing civil rights law applied to AI.
For practitioners, Clearwater advises continuing to conduct impact assessments — noting that the EU AI Act requires them, California makes bias testing relevant, and the NIST AI RMF assumes them, so one state dropping a mandate does not change the calculus for a defensible program. He recommends building around transparency as the floor, observing that Colorado is converging with Illinois (AI disclosure, effective January 2026), California's CCPA automated decision-making rules, and NYC Local Law 144, with notice, recourse, and audit trails as the common denominator. He further advises renegotiating vendor contracts for relative-responsibility fault allocation, planning for two timelines (the new framework targets January 1, 2027; if the bill does not pass, the original SB 24-205 takes effect June 30, 2026), and not mistaking deregulation for derisking, since the framework explicitly states that using AI does not excuse noncompliance with any existing law.
SB 26-189 (introduced May 1, 2026)
On May 1, 2026 Senate Majority Leader Robert Rodriguez and Senate President James Coleman introduced SB 26-189, which would repeal and rewrite most of SB 24-205 before its June 30, 2026 effective date. The bill implements, with slight modifications, the March 17 working-group framework. It scraps the affirmative duties on developers and deployers in the original act; replaces "high-risk AI systems" and "algorithmic discrimination" with a narrower "automated decision-making technology" definition; and requires detailed disclosures only on consumer request, within 30 days of an adverse outcome, which is substantially narrower than the original act's pre-deployment notice-and-opt-out regime. The Colorado General Assembly adjourned May 13, giving roughly two weeks for passage; if SB 26-189 fails, the original SB 24-205 takes effect June 30 as written (Source: coloradonewsline.com).
Reactions
David Sacks (co-chair, PCAST), supporting the challenge, said: "This is Woke AI. It teaches AI models to lie. And it's a violation of the First Amendment." Travis Hall (Center for Democracy & Technology), opposing the challenge, argued that the Act "actually does regulate the way in which artificial intelligence is being used for consequential decisions like people's health care and their employment" rather than regulating speech.
Sources
- Colorado AI Act source summary
- xAI Corp. v. Weiser — Complaint (2026-04-09) — primary legal filing articulating the First Amendment / Commerce Clause / Due Process / Equal Protection challenge
- AI & Tech Brief: Radical Activists and AI Safety (Source: washingtonpost.com) (2026-04-13) — press coverage of the filing and surrounding politics
- Andrew Clearwater, "The First Comprehensive US state AI law Is About To Be Gutted And Rebuilt" (Source: andrewclearwater.substack.com) (2026-03-17) — supporting source folded into this page; framework analysis
- Governor's Announcement (March 17, 2026): https://governorsoffice.colorado.gov/governor/news/colorado-artificial-intelligence-policy-workgroup-delivers-unanimous-support-revised-policy
- Full Proposed Framework (PDF): https://drive.google.com/file/d/1L2plsS3q1vzCrI8LuHj-5SNFjAoYoA_d/view
- Full text: SB 24-205 + SB 25B-004, Colorado Legislature