Colorado SB 26-189 is a 2026 state law, signed by Governor Jared Polis on May 14, 2026, that repeals and reenacts CRS Part 17 of Article 1 of Title 6 to replace the 2024 Colorado AI Act with a disclosure-and-transparency framework governing Automated Decision-Making Technology (ADMT) in consequential decisions. It substitutes the 2024 Act's risk-based developer and deployer duties with documentation and disclosure obligations while preserving liability under existing Colorado anti-discrimination law.
| Jurisdiction | Colorado | |
| Bill ID | SB 189 | |
| Status | Signed by Governor Jared Polis on May 14, 2026 | |
| Replaces | [[legislation/colorado-ai-act | 2024 Colorado AI Act]] (the first U.S. state law to impose risk-based duties on AI developers and deployers in consequential decisions) |
Background
The 2024 Colorado AI Act was the first U.S. state law to impose EU-AI-Act-style risk-based duties on AI developers and deployers in consequential decisions (employment, lending, housing, insurance, and similar). It required impact assessments, bias audits, and notice obligations. SB 26-189 replaces that framework before the 2024 Act took effect, substituting a disclosure-and-transparency model. The Colorado General Assembly bill page lists the bill as passed (Source: leg.colorado.gov).
Key provisions
Per the full bill text (Colorado SB 26-189 (Signed Act, May 14 2026)), SB 26-189 centers on the following obligations:
- Developer documentation duties to deployers, covering intended uses, known risks, training data categories, limitations, and material-update notification — §6-1-1702, effective Jan 1, 2027.
- Deployer disclosure duties, comprising point-of-interaction notice and post-adverse-outcome disclosures within 30 days — §6-1-1704.
- Consumer rights to request correction of inaccurate personal data and to meaningful human review and reconsideration where commercially reasonable — §6-1-1705.
- Liability allocation under existing Colorado anti-discrimination law, with developer-deployer fault allocation and no joint-and-several liability unless permitted under existing law; indemnification clauses for own-acts violations are void as against public policy — §6-1-1707.
- Insurer carve-out: entities subject to CRS 10-3-1104.9 are treated as compliant — §6-1-1708.
The law creates no private right of action, but existing Colorado Anti-Discrimination Act, CCPA, product liability, and other applicable law are unaffected.
Scope and exclusions
Covered domains are explicit: education, employment, residential real estate, financial and lending, insurance, health-care, and essential government services and public benefits. Changes from the 2024 Act include broader insurance carve-outs (§6-1-1708) and FERPA-deference for education (§§6-1-1704(9), 6-1-1705(2)).
ADMT does not include simple summarization tools, customer service chatbots, fraud-detection, AML/BSA, cybersecurity tools, or natural-language consumer-communication systems not configured for consequential decisions. These exclusions narrow the law's scope relative to a literal reading of "automated decision-making technology."
Federal-credit-notice compliance under ECOA and FCRA can satisfy the §6-1-1704 notice obligations (§6-1-1704(6)), a partial federal-preemption mechanic with implications for FTC algorithmic-discrimination enforcement.
Enforcement and penalties
Enforcement rests solely with the Attorney General under the Colorado Consumer Protection Act; violations are deceptive trade practices — §6-1-1706. The law provides a 60-day right to cure, which sunsets Jan 1, 2030, with cure denial available for knowing or repeated violations. Annual AG reporting begins in January 2028.
AG rulemaking due by Jan 1, 2027 will define the operative content of post-adverse-outcome disclosures (§6-1-1704(4)) and the consumer-correction and human-review processes (§6-1-1705(3)).
Rulemaking
On August 11, 2026 the Colorado Department of Law's Consumer Protection Section filed proposed rules at 4 CCR 904-6 with the Secretary of State, implementing SB 26-189 and HB 26-1263 in a single fourteen-rule package. Rules 1 through 7 address this act. Rule 2 defines terms including "Midstream Developer" — a party that integrates covered ADMT as a component into its own covered ADMT product and supplies it downstream — and "Financial or Lending Service". Rule 3 requires every notice and disclosure to use plain language, follow the Web Content Accessibility Guidelines version 2.2 online, appear in the languages the deployer ordinarily uses, and render readably on small screens. Rule 4 obliges midstream developers to obtain and pass through all upstream developer documentation. Rule 5 requires the developer's intended-use statement to name both the consequential decisions the ADMT is intended for and those for which it is known to be inappropriate, requires training-data descriptions to indicate whether the data is sensitive, biometric-identifier, or biometric data, and permits withholding only for trade secrets as defined in § 7-74-102(4) or legally protected material, with the legal authority stated (Colorado 4 CCR 904-6 — ADMT and Conversational AI Service Proposed Rules (2026)).
Rule 6 sets the form, timing, and content of post-adverse-outcome disclosures: written delivery by at least two methods where available, not less than 12-point font for postal delivery, within thirty days, and principal reasons stated with specificity — reliance on "the deployer's internal standards or policies" is expressly insufficient. Where a reason rests on an inference or a risk score, the disclosure must identify the inference or disclose the score and the underlying personal data. Rule 7 sets a 45-day response deadline, bars requiring a new account or charging an authentication fee, and requires that an adverse outcome be stayed pending correction of incorrect data where possible. Rule 7.7 defines meaningful human review: an independent reviewer who did not make the original decision and is not a subordinate of the original decision-maker wherever feasible, with subject-matter understanding commensurate with the harm, shielded from steering and retaliation, and without ADMT assistance in the review. Commercial reasonableness is weighed on seven non-dispositive factors, and where the harm is a severe and irreversible denial of a basic human need, review is presumed commercially reasonable with the deployer bearing the burden of rebuttal (Colorado 4 CCR 904-6 — ADMT and Conversational AI Service Proposed Rules (2026)).
Two acts of the same session assign different content to C.R.S. § 6-1-1708. This act enacts § 6-1-1708 as the insurer compliance provision and § 6-1-1709 as the no-private-right-of-action provision (Colorado SB 26-189 (Signed Act, May 14 2026)), while HB 26-1263, signed fifteen days later, adds § 6-1-1708 as the Chatbot Safety Act (Colorado HB 26-1263 (Chatbot Safety Act, Enrolled Act)). The Department of Law's proposed rules describe the covered statutes as "sections 6-1-1701 through 6-1-1709" while citing § 6-1-1708 throughout for the chatbot duties. How the revisor of statutes resolved the collision is not stated in any of the three documents.
Reactions
In signing the bill, Polis stated that "This is a big step in the right direction for Colorado, and a model for the rest of the country. Replacing the old law that hasn't taken effect yet will boost Colorado innovation and entrepreneurship" (Source: governorsoffice.colorado.gov). Bill sponsors — Senate Majority Leader Robert Rodriguez, Senate President James Coleman, House Majority Leader Monica Duran, and Assistant Majority Leader Jennifer Bacon — described the law as one that "strikes an appropriate balance of protecting consumers while not being onerous on developers," and said it was produced through an AI taskforce bringing together "consumers, advocates, developers and more." The press release framed the law as bipartisan, safety-fostering, and protective of the business environment, a framing that contrasts with the Colorado Attorney General reading emphasizing preserved anti-discrimination liability and the state-AI-regulation reading that SB 189 represents a retreat. Polis signed SB26-189 alongside SB26-137 (Measures to Reduce Administrative Burdens, providing for five-year DORA rule reviews), and the press release's packaging of the two as "breaking down barriers and reducing regulation" presents SB 189 as part of a broader deregulatory consolidation rather than a standalone AI policy action.
CBS News Colorado reported the signing on May 14, 2026 (Source: cbsnews.com).
Position within the state AI-regulation landscape
Colorado was the U.S. state most explicitly modeled on the EU's risk-classification approach, and SB 189's replacement of substantive duties with transparency-focused obligations weakens that track. The retreat is partial rather than transparency-only: the law preserves liability under existing Colorado anti-discrimination law and voids indemnification workarounds.
As of May 2026, the broader U.S. state AI-regulation landscape included several distinct tracks:
- A frontier-transparency approach in California and New York: CA SB 53 and the NY RAISE Act, both signed, transparency-first, and targeted at large frontier developers.
- An anti-discrimination and deployer-duty track: the CO AI Act (superseded by SB 189) and IL SB 3444 (in flux following OpenAI's May 13 disavowal of its liability safe harbor).
- An SB-53-style frontier-safety effort in Illinois: Illinois SB 315 (frontier safety framework with mandatory third-party audits), endorsed by OpenAI and Anthropic on May 14–15.
In relation to the California effect, the California–New York axis appears more durable than the Colorado track, a contrast relevant to state-level AI regulation.
Relationships
- supersedes: Colorado AI Act (SB 24-205) (2024 framework)
- depends-on: Colorado 4 CCR 904-6 — ADMT and Conversational AI Service Proposed Rules (2026) — the proposed rules implementing §§ 6-1-1704(4) and 6-1-1705(3)
- related: Colorado HB 26-1263 (Chatbot Safety Act) (the Chatbot Safety Act, codified in the same Part 17 and implemented through the same 4 CCR 904-6 rulemaking filed August 11, 2026), Jared Polis (signer; created if needed), California SB 53 (parallel state-level effort), New York RAISE Act, Illinois SB 315 (frontier safety framework with mandatory third-party audits) (created), State-Level AI Regulation, California Effect, AI and Tort Liability
- contradicts: The risk-based duty model of the EU AI Act and the original 2024 Colorado AI Act
Sources
- Colorado SB 26-189 (Signed Act, May 14 2026) — full bill text and provision-by-provision summary (the primary anchor; extracted from the May 14 2026 signed-act PDF on May 17 2026).
- Colorado 4 CCR 904-6 — ADMT and Conversational AI Service Proposed Rules (2026) — the proposed 4 CCR 904-6 implementing rules and the Department of Law's statement of basis (filed August 11, 2026).
- (Source: cbsnews.com) — CBS News Colorado, May 14, 2026.
- (Source: governorsoffice.colorado.gov) — Polis press release on signing (May 13, 2026).
- (Source: leg.colorado.gov) — Colorado General Assembly SB26-189 bill page (status: Passed); summary mirrors the substantive operative provisions in Colorado SB 26-189 (Signed Act, May 14 2026).
- Colorado AI Act (SB 24-205) — superseded predecessor.