On August 11, 2026 the Colorado Department of Law's Consumer Protection Section filed proposed rules at 4 CCR 904-6 with the Colorado Secretary of State, together with a statement of basis, specific statutory authority, and purpose and a notice of rulemaking hearing. The package implements two statutes in one instrument: Senate Bill 26-189, the Automated Decision-Making Technology Act signed May 14, 2026, and House Bill 26-1263, the Chatbot Safety Act signed May 29, 2026. Rules 1 through 7 address the ADMT Act, Rules 8 through 13 the Chatbot Safety Act, Rule 2 and Rule 3 both, and Rule 14 sets out two incorporations by reference. This page summarizes the proposed rule text and the statement of basis; the rules are a draft issued for notice and comment, not adopted law.
| Issuer | Colorado Department of Law, Consumer Protection Section |
| Rule citation | 4 CCR 904-6 |
| Filed | August 11, 2026, with the Colorado Secretary of State |
| Implements | C.R.S. §§ 6-1-1701 to 6-1-1709 (SB 26-189 and HB 26-1263) |
| Statutory authority | C.R.S. §§ 6-1-108(1), 6-1-1704(4), 6-1-1705(3), 6-1-1706(5), 6-1-1707 |
| Structure | 14 rules |
| Status | Proposed; issued for notice and comment |
Statutory authority
The Department grounds the package in five provisions. Section 6-1-108(1) authorizes the attorney general to promulgate rules necessary to administer the Colorado Consumer Protection Act, of which Part 17 is a part. Section 6-1-1707, as enacted by SB 24-205, gives rulemaking authority for implementing and enforcing Part 17. Section 6-1-1704(4) and section 6-1-1705(3), both as amended by SB 26-189, require rules clarifying the post-adverse-outcome disclosure requirements and the consumer-rights requirements respectively; these are the only mandatory rulemakings in the package. Section 6-1-1706(5), as amended by SB 26-189, supplies discretionary rulemaking authority over the whole of Part 17, and is the authority cited for every chatbot rule, since the Chatbot Safety Act itself requires no rulemaking.
The statement of basis cites the Anti-Discrimination in AI Act once as "SB 24-204" and twice as "SB24-205" in describing what SB 26-189 repealed and reenacted. The bill number of the 2024 Colorado AI Act is SB 24-205. The discrepancy is reproduced as filed.
Definitions (Rule 2)
Rule 2 defines terms used across both halves of the package. Several narrow or extend statutory language.
Accessible to the General Public, the threshold in the definition of a conversational artificial intelligence service, covers services made available to consumers directly through a product or service, including free services with or without gated sign-up, subscription services, and services behind a paywall. It excludes an artificial intelligence system made available as an internal-only workforce deployment through restricted, authenticated environments that are not consumer-facing.
Continuous Conversational Artificial Intelligence Service Interaction, which governs the three-hour disclosure interval, means a sequence of exchanges that regularly persists regardless of temporary pauses in activity, and may occur within a single conversational thread or across multiple threads or chatbot profiles.
Evidence-Based Method, used for the statutory requirement that operators measure suicidal ideation and self-harm by evidence-based methods, means a method validated through empirical research and scientifically tested for reliability, validity, sensitivity, and specificity. The rule names four examples: the Columbia-Suicide Severity Rating Scale, item 9 of the Patient Health Questionnaire, the Ask Suicide-Screening Questions, and the SAFE-T protocol.
Repeated or severe crisis indicators, the trigger for the statute's escalation procedures, means indications of suicidal ideation or self-harm risk that either recur throughout a user's interactions or reflect a heightened level of risk as assessed using an evidence-based method.
Age Category establishes six groupings used in the annual report: under 13; at least 13 but under 16; at least 16 but under 18; at least 18 but under 25; over 25; and not relevant, which covers organizational or entity accounts. Alert and Complaint distinguish operator-detected from externally reported potential violations. Midstream Developer covers a party that integrates covered ADMT as a component into its own covered ADMT product and supplies that product to another developer or a deployer. Makes Publicly Available reaches supply to a third party through sale, licensing, or other means.
ADMT rules (Rules 3 to 7)
Rule 3 sets requirements for every notice, disclosure, response, and communication under both acts: plain language avoiding technical or legal jargon; accessibility to consumers and users with disabilities, following the Web Content Accessibility Guidelines version 2.2 for online material; availability in the languages the deployer or operator ordinarily uses, and in the language of any prior interaction with that person; delivery through a readily accessible interface and in a readable format on all devices including small screens; and content that is not unfair, deceptive, false, or misleading.
Rule 4 addresses multiparty arrangements. A midstream developer must reasonably obtain all upstream developer documentation created under § 6-1-1704 for any covered ADMT used as a component of its technology, and must make that documentation available to downstream deployers and developers. The rule's worked example is a company that integrates third-party foundation models into an AI application sold to customers who input their own data.
Rule 5 clarifies developer disclosure. The general statement of intended uses must describe both the types of consequential decisions the ADMT is intended for and those for which it is not intended or is known to be inappropriate or harmful. Instructions to deployers should specify the data types the ADMT requires, methods for monitoring it including aggregate-data analysis, and means of determining the reasoning and primary factors behind an output that materially influenced a decision. The description of training-data categories must indicate whether the data would be sensitive data, biometric identifiers, or biometric data under § 6-1-1301 et seq. A developer may withhold information only if it is a trade secret as defined in § 7-74-102(4) or is protected from disclosure by law, must state the legal authority for withholding, and must still satisfy § 6-1-1702 in a way that does not reveal trade secrets.
Rule 6 governs post-adverse-outcome disclosures. The disclosure must be in writing via at least two methods where the deployer has two ways of reaching the consumer, in an easy-to-read font of not less than 12 point for postal delivery, and must be provided within thirty days of the decision. Content requirements are illustrated with sector examples: the disclosure must name the decision ("Bank ABC closed your checking account"), describe the specific purpose and role of the covered ADMT alongside any human reviewers, give the effective date of the adverse outcome where applicable, and state the principal reasons with specificity — reliance on "the deployer's internal standards or policies" is expressly insufficient, while credit score and length of employment are sufficient. Where a principal reason rests on an inference, the disclosure must identify the inference and the underlying personal data; where it rests on a profile or risk score, it must disclose the consumer's score and the data behind it, illustrated by a security-deposit example citing a risk score of 82 out of 100.
Rule 7 implements the consumer rights. A deployer must not require a consumer to create a new account to make a request, may collect personal data through the request process only as reasonably necessary to authenticate and respond, must not charge a fee for authentication, and must respond within 45 days. A request for additional information about the covered ADMT and its inputs may not be conditioned on authentication. Where a consumer corrects personal data, reconsideration means the decision-making process is re-performed using the corrected data and the result sent to the consumer; an adverse outcome must be stayed pending correction where possible.
Rule 7.7 defines meaningful human review. The reviewer must be independent of the original decision-maker and not their subordinate whenever feasible, must have subject-matter understanding commensurate with the harm at stake, must be trained in accuracy and objectivity as well as the ADMT's factors, must be free from steering by upper management and shielded from retaliation, and ADMT may not assist in the review. A meaningful review is one that could change the adverse outcome; the reviewer must first determine which type of review could do so, distinguishing cases where the ADMT malfunctioned (correct it and re-run the decision) from cases where the ADMT lacked relevant information or was applied outside its intended use (weigh the consumer's additional primary evidence). Commercial reasonableness is assessed on seven non-dispositive factors: the type of review required, the magnitude of harm, the reversibility of the outcome, the value of reviewing available primary evidence, the deployer's size and capacity, the marginal cost and technical feasibility, and the availability of qualified reviewers. Where the harm is a severe and irreversible denial of a basic human need, meaningful human review is presumed commercially reasonable, rebuttable only by evidence that review is technically or financially impossible or could not change the outcome; the deployer bears the burden of showing review is not commercially reasonable.
Conversational AI rules (Rules 8 to 13)
Rule 8 interprets the statutory exemptions from the definition of a conversational artificial intelligence service. The "narrow and discrete topic" exemption is read as covering outputs generated from completion of a bounded task such as a purchase status update, a billing answer, or appointment scheduling, and expressly extends to menu- or button-based and protocol- or rule-based chatbots, provided they cannot produce the sexual content described in § 6-1-1708(2)(c) and (2)(d) or engage in dialogue on suicidal ideation or self-harm. The business-use exemption turns on whether the service has an interface generally available to any consumer, whether it is marketed primarily to businesses rather than the public, and whether its design is structured around specific business functions.
For the educational-tool and embedded-feature exemptions, the rule sets out what the Department will weigh in deciding whether a service is "designed to simulate emotional companionship": anthropomorphic design features such as personalized dialogue and the ability to assign a chatbot a name, gender, avatar, or fictional backstory; whether training, production, and deployment prioritized, promoted, or failed to address sycophantic behavior or outputs simulating empathy and offering continual validation; and whether the service can recall and respond to users' characteristics, preferences, and past conversations. For "designed to encourage emotionally dependent interaction" it weighs features designed to increase emotional intensity across sessions, prioritize emotionally immersive responses, or create reinforcement loops encouraging users to return for reassurance; whether the operator tests safeguards such as prompts toward real-world supports and reminders that the service is not human; whether safeguards remained effective after model updates; and whether the operator promptly remediated weaknesses found in testing or real-world safety incidents.
Rule 9 sets nine cumulative conditions on any commercially reasonable or generally accepted age-estimation method. It must collect only data necessary for age assurance of that user, not share or repurpose it, and delete it after the minimum time required for compliance; maximize user choice, and it "must not use as a sole method of age assurance a method that requires a user to provide government-issued identification"; be reasonably effective at identifying users under 18, perform with measurable consistency, and be tested with quantifiable accuracy rates in line with industry standard rates; use operating system, app store, and device signals transmitted under applicable law without willfully disregarding contradicting evidence; re-assess age estimates on new signals including user-provided information, account settings, parental controls, device settings, previous interactions, contextual information derived through conversations, behavioral indicators, and payment methods; include a process for receiving and responding to reports that a user is a minor or falsified their age; not rely solely on self-declaration, general terms of use, or online payment methods available to minors; not use a method with known or documented risks without reasonable mitigation; and include reasonably effective measures to detect fraudulent or misused information.
Four methods are listed as generally accepted: an age-assurance method satisfying ISO/IEC 27566 on age assurance systems; a cryptographic technique such as a zero-knowledge proof demonstrating minority from verified data without revealing other information; matching a scan of a government-issued identity document against a live photo or video using facial recognition; and assessment of a user's digital footprint originating from a verified email address. Commercial reasonableness is judged on the totality of circumstances including the operator's size and financial resources and the cost and effectiveness of available techniques. An inconclusive outcome cannot support a determination that the user is not a minor.
For willful disregard, the Department will apply the factors in 4 CCR 904-3, Rule 6.13 plus seven more: failure to ascertain or verify age; ignoring system flags such as an under-18 estimate, self-reported age, account settings, parental controls, device settings, previous interactions, behavioral indicators, or payment methods; failure to address parental complaints and user or law-enforcement reports; failure to act on behavioral signals processed by the language model, including direct statements of minor status, recurring discussion of grade-level and high-school situations, age-specific activities, or a user consistently occupying a child role in described parent–child interactions; failure to consider evidence contradicting an operating system, app store, or device signal under § 6-30-102; and design choices that nudge users toward inaccurate age estimation, such as age-reporting tools that pre-fill a birth date over 18. The draft prints the behavioral-signals factor twice, as items 4 and 5.
Rule 10 specifies disclosure form. A persistent visible disclaimer must remain continuously visible throughout the conversation without scrolling, clicking, hovering, or other affirmative action; be visually distinct from the conversation, including a font size not smaller than the largest font size of other interface text; and appear in the language of the conversation or the account's language setting. An intermittent audio disclaimer must play in the conversation's language, at a higher volume than the conversation, and repeat at intervals reasonably calculated to keep the user aware, as well as whenever the user asks whether they are speaking to a human. In assessing whether intervals are reasonable the Department will consider whether the operator tested users' understanding and whether disclosures support safer decision-making, whether they are delivered at meaningful points in the user experience, and whether changes followed testing and product updates.
Rule 11 elaborates the minor-protection duties. "Points or similar rewards" is read to include leaderboards, points, badges, and login streaks; features requiring users to play a game, answer trivia, spin a wheel, or use similar games to receive rewards; and access to additional features based on session length, return frequency, or platform time — the Department may consider whether the reward increases, sustains, or extends session length, return frequency, or platform time through variable reinforcement.
The "technically feasible measures" standard for sexual content is assessed on whether comparable safeguards are already used in the industry; whether commercially available technologies could substantially reduce the risk; whether alternative safeguards could meaningfully reduce it, "including substantially altering the Conversational Artificial Intelligence Service or choosing not to deploy" it; whether technological advances warrant periodic reassessment; whether the operator periodically tested safeguards using realistic scenarios involving minors and addressed weaknesses promptly; whether it monitored for prohibited conduct including acting on user reports; and whether it documented that a measure was evaluated and tested, that limitations were identified, that alternatives were considered, and that further safeguards were not technically feasible.
The lower "reasonable measures" standard for emotional dependence is assessed on periodic testing against realistic minor scenarios covering six specific behaviors: suggesting the user is interacting with a human; claiming a minor–adult romantic relationship; encouraging a minor to withdraw from parents, guardians, or trusted adults or to prioritize the service over real-world supports; encouraging a minor to keep conversations secret; portraying the service as a child's primary, exclusive, or preferred relationship or as uniquely capable of understanding or caring for the minor; and using expressions of loneliness, abandonment, guilt, or emotional distress to encourage continued engagement. Also weighed are whether safeguards survived model updates and safety-system changes, whether the operator monitored for such responses, and whether it promptly remediated identified weaknesses.
Rule 11.5 adds a default the statute does not state: a minor's privacy and account settings "shall default to the most protective setting for any account", and specifically to not retaining information from prior sessions and not using the minor's personal data for training. A savings provision preserves data retained for the minimum period necessary to meet a legal, regulatory, or safety obligation including fraud prevention, platform integrity, safeguarding the minor, or cooperation with law enforcement; exempts deidentified or aggregated data; and states that nothing in the rule requires modification, retraining, or alteration of any underlying model, model weights, or training corpus.
Rule 12 interprets the false-representation prohibition through the beliefs of a reasonable user. The Department will weigh whether the operator implemented controls reasonably designed to prevent creation of service profiles with names including terms such as "therapy", "therapist", "psychologist", "doctor", "lawyer", "dietitian", or similar words, titles, or abbreviations likely to cause a reasonable user to believe the service is provided by, endorsed by, or equivalent to one of the four statutory professional categories; controls against outputs producing the same belief; and whether the operator's advertising or promotion would produce it.
Rule 13 sets the annual report's content and format. An operator must report which of five size tiers it occupies by monthly active users: over 10 million; 5 to 10 million; 1 to 5 million; 500,000 to 1 million; and fewer than 500,000. The crisis-referral count required by statute must be accompanied by a denominator — the total number of conversations over the same reporting period — and by a referral-accuracy figure giving the share of referrals directed to user outputs that actually involved suicidal ideation or self-harm risk as identified under an evidence-based method. Figures must be aggregate and free of user identifiers, subject to the statutory trade-secret limitation.
The protocol descriptions must be detailed enough for the Department to evaluate each function, and the rule lists twelve illustrative elements for the detection-and-response protocol, among them when crisis resources are provided and which, at what point and on what criteria a situation is elevated to human review, the circumstances under which the operator contacts emergency services or law enforcement and the safeguards on that decision, any circumstances in which risk is detected but no resource is provided and no human involved, the specific identification methods including automated classification and keyword matching, the risk tiers distinguished, how ambiguous or non-imminent indicators are handled, how the protocol incorporates clinical best practices, how risk that escalates across repeated interactions over time is evaluated, and how genuine risk is distinguished from figurative or hypothetical language. A separate description covers measures preventing responses that facilitate suicide or self-harm, including output filtering, training or fine-tuning, refusal behavior, post-generation review, testing and improvement, and handling of circumvention attempts. The operator must also describe how it tests, monitors, and improves the protocols, including the specific efficacy and reliability metrics used and their values over time. The Department may require underlying documentation, source materials, records, or a demonstration sufficient to verify any element, with a 30-day compliance window.
Rule 13.4 adds age-estimation and sexual-content metrics beyond the statutory list: the distribution of users by age category, disaggregated by service where an operator runs more than one; a general description of age-estimation methods and how the operator avoids willfully disregarding clear and convincing information that a user is a minor; a description of the minor-protection methods including how they account for risks accumulating through continuous interaction; the number of third-party reports that a user is a minor, how many were resolved each way or left undetermined, the average and median time to determination, and the number and percentage of users initially estimated to be adults but later determined minors and the reverse; and, for each of the four prohibited sexual-content categories, the number of third-party reports, their determination outcomes, the number of instances the operator identified without a report, and the average and median time to resolution.
Reports are due on or before July 1, 2027 for calendar year 2027 and on or before July 1 each year thereafter for the preceding calendar year, submitted through a form on the attorney general's website. A report prepared for another jurisdiction satisfies the requirement if reasonably similar in scope and effect, with an appendix supplying any omitted information; internal documents may be substituted on the same terms.
Rule 14 incorporates two external documents by reference under § 24-4-103(12.5): the Web Content Accessibility Guidelines version 2.2 of December 12, 2024 from the World Wide Web Consortium, into Rule 3.2, excluding later amendments; and ISO/IEC 27566-1:2025 on age assurance systems, into Rule 9.2. Both are available for public inspection at the Department of Law in Denver. The statement of basis does not mention Rule 14.
Process
The statement of basis records that the proposed rules are issued for notice and comment with opportunity for public participation prior to adoption, and that the Department "intends to take stakeholder input sincerely", which may result in additional rules, amendments, significant changes, or portions not detailed in the statement. It directs interested persons to the mailing list and updates at coag.gov/ai. The attorney general's rulemaking page states that formal written comments are accepted from August 11 through October 26, 2026 at 11:59 p.m. MST, with comments intended to inform revisions presented at the hearing requested by October 5, 2026, and that any person may request a cost-benefit analysis within five days of publication in the Colorado Register under § 24-4-103(2.5) (Source: coag.gov).
Provenance
Two documents filed the same day are summarized here: the proposed rules themselves and the statement of basis, specific statutory authority, and purpose. A third document filed alongside them, the notice of rulemaking hearing, has not been retrieved. A pre-rulemaking considerations paper published in June 2026 preceded the filing.
The filed draft carries several typographic irregularities, preserved as filed in the raw sources: the behavioral-signals factor is printed twice at Rule 9.2(E)(4) and (5); Rule 13.4(A) cites "section 6-1-1708(6)(IV)" for what the act numbers § 6-1-1708(6)(a)(IV); Rule 13.2(A)(1) cross-refers to "Rule 13.3" for requirements it is itself stating; and Rule 14.1 refers to "regular deployer hours" where "business hours" is evidently meant.
Relationships
- supports: Colorado HB 26-1263 (Chatbot Safety Act) — the implementing rules for the Chatbot Safety Act
- supports: Colorado SB 26-189 (2026 — replaces 2024 Colorado AI Act) — the implementing rules for the ADMT Act
- depends-on: Colorado SB 26-189 (Signed Act, May 14 2026) — the statute supplying most of the rulemaking authority
- depends-on: Colorado HB 26-1263 (Chatbot Safety Act, Enrolled Act) — the statute the chatbot rules implement
- related: Colorado AI Act (SB 24-205) — the 2024 act repealed and reenacted by SB 26-189
- instance-of: Age Verification — Rule 9 is a state age-assurance standard with an explicit no-sole-government-ID constraint
- instance-of: Algorithmic Accountability and Bias Audits — Rules 5 to 7 set documentation, explanation, and human-review requirements
- related: AI Companions — Rules 8 and 11 define emotional companionship and dependence for regulatory purposes
Sources
- (Source: coag.gov) — Automated Decision-Making Technology & Conversational Artificial Intelligence Service Rules, 4 CCR 904-6, proposed text of Rules 1 to 14
- (Source: coag.gov) — Statement of Basis, Specific Statutory Authority, and Purpose: authority chain, rule-by-rule purposes, signing dates
- (Source: coag.gov) — Colorado Attorney General AI rulemaking page: filing date, comment window, cost-benefit-analysis procedure