Colorado Senate Bill 26-189 is a signed act that repeals and reenacts Part 17 of Article 1 of Title 6 of the Colorado Revised Statutes, replacing the 2024 Colorado AI Act. Governor Jared Polis signed it on May 14, 2026. The bill substitutes the 2024 Act's risk-based-duty framework — which had been the first U.S. state law on algorithmic discrimination in consequential decisions and was modeled on the EU AI Act — with a disclosure-and-transparency framework over Automated Decision-Making Technology (ADMT). It retains liability under existing Colorado anti-discrimination law and adds developer-to-deployer documentation duties, consumer notices, post-adverse-outcome disclosures, a right to meaningful human review, and attorney-general-only enforcement. Source page text is drawn from the full bill text in Raw Sources/Colorado SB 26-189 (Signed Act).md.
| Jurisdiction | Colorado |
| Bill ID | SB 26-189 |
| Concerning | The use of automated decision-making technology in consequential decisions |
| Lead Senate sponsors | Sen. Rodriguez, Sen. Coleman |
| Lead House sponsors | Rep. Duran, Rep. Bacon |
| Co-sponsors | 21 senators + 25 representatives (bipartisan) |
| Signed | May 14, 2026 by Gov. Jared Polis |
| Effective | January 1, 2027 (developer duties); AG rules due Jan 1, 2027 |
| Action | Repeals and reenacts CRS Part 17 of Article 1 of Title 6 (replacing the 2024 Colorado AI Act) |
Key definitions (§6-1-1701)
The act defines Automated Decision-Making Technology (ADMT) as technology that processes personal data and uses computation to generate output — predictions, recommendations, classifications, rankings, or scores — used to make, guide, or assist a decision concerning an individual. Excluded are anti-malware, anti-virus, calculators, databases, data storage, firewalls, networking, spam filters, spell-check, web hosting, and spreadsheets without ML, foundation models, or LLMs; tools used solely for human-reviewed summarization, organization, translation, drafting, or routing; and natural-language consumer-communication systems if not contracted or marketed for consequential decisions and subject to an acceptable use policy prohibiting consequential-decision output.
Covered ADMT is ADMT used to materially influence a consequential decision. A consequential decision is one relating to a covered domain: education, employment, residential housing in Colorado, financial or lending services, insurance (underwriting, pricing, coverage, claims), health-care services, and essential government services and public benefits. Excluded from "consequential decision" are low-stakes or routine decisions; advertising, marketing, search, and content moderation; manual-analysis spreadsheets; summarization and organization tools; cybersecurity, spam, and system reliability; AML, BSA, USA PATRIOT, Red Flags Rule, and sanctions compliance (excluding facial recognition); fraud prevention; and routine academic administration.
ADMT output materially influences a decision when it is a non-de-minimis factor and affects the outcome by constraining, ranking, scoring, recommending, classifying, or meaningfully altering the decision; incidental, trivial, or clerical uses do not qualify. Meaningful human review is review by a deployer-designated individual with authority to approve, modify, or override, who considers primary evidence, is trained, does not default to system output, and has access to understand the output's intended use, material limitations, input categories, and principal factors — without disclosure of source code, model weights, or trade secrets.
Core duties
Developer duties (§6-1-1702), effective Jan 1, 2027
A developer must make available to each deployer of a covered ADMT, in a form understandable to the deployer and protecting trade secrets: a general statement of intended uses and known harmful or inappropriate uses; a description of data categories (including personal data) used to train, to the extent known; known limitations, including known risks and circumstances in which the covered ADMT should not be used; instructions for appropriate use, monitoring, and meaningful human review; and information reasonably necessary for the deployer to comply with §6-1-1704. The developer must give notice of material updates and intentional or substantial modifications within a reasonable time (public release notes plus direct notice suffices), and must retain records — system version identifiers, changelogs, and notices — for 3 years.
Deployer duties (§§6-1-1703, 6-1-1704)
Prior to using a covered ADMT to materially influence a consequential decision, a deployer must give point-of-interaction notice: clear and conspicuous notice to the consumer plus instructions for obtaining additional information. Compliance via a prominent public notice reasonably proximate to the interaction or transaction satisfies this requirement.
Following an adverse outcome, the deployer must, within 30 days, provide post-adverse-outcome disclosures: a plain-language description of the consequential decision and the ADMT's role; instructions and a simple-to-follow process to request additional information (covered ADMT name, version, developer, and the types, categories, and sources of personal data used); and an explanation of consumer rights under §6-1-1705 and how to exercise them. The deployer must retain records for 3 years and must make notices and disclosures reasonably accessible to consumers with disabilities and limited English proficiency. By January 1, 2027, the attorney general is to adopt rules clarifying post-adverse-outcome disclosure content and sector-specific guidance.
Consumer rights (§6-1-1705)
Consumers have the right to request and receive instructions for requesting personal data and for correcting factually incorrect or materially inaccurate personal data, and the right to an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable. AG rules on these rights are due January 1, 2027.
Enforcement (§6-1-1706)
Enforcement is solely by the attorney general under the Colorado Consumer Protection Act, and violations are deceptive trade practices. A 60-day right to cure applies before any AG enforcement action; cure may be denied if the violation is knowing or repeated, and the cure period sunsets January 1, 2030. The act creates no private right of action, but does not limit existing rights under the Colorado Anti-Discrimination Act, the Colorado Consumer Protection Act, product liability, or other applicable law. Beginning January 2028, the AG reports annually on the number of actions, completed actions, and cure periods offered, met, and not met.
Liability allocation (§6-1-1707)
Developers and deployers may be held liable in actions alleging unlawful discrimination under state anti-discrimination laws (the Colorado Anti-Discrimination Act) arising from a consequential decision materially influenced by a covered ADMT. Fault is allocated based on relative fault, with no joint-and-several liability unless permitted under existing law. Developer liability is bounded: a developer is liable only to the extent the covered ADMT was used in a manner that was intended, documented, marketed, configured, or contracted by the developer.
Indemnification clauses are void as against public policy if they purport to indemnify the indemnitee from liability for its own acts or omissions related to ADMT in consequential decisions violating Colorado anti-discrimination law, with a carve-out for developers regarding unintended uses if §6-1-1702 compliance is met. Compliance with Part 17 is not a defense to non-compliance with applicable law, and ADMT use does not excuse any obligation or liability under state or federal law.
Sector carve-outs
Under §6-1-1708, insurers and affiliated entities subject to CRS 10-3-1104.9 are in compliance with Part 17 in the practice of insurance. For FERPA-subject deployers (§§6-1-1704(9), 6-1-1705(2)), existing FERPA notice and correction processes satisfy the act. Federal credit and lending notice compliance under ECOA and FCRA can satisfy the notice requirements (§6-1-1704(6)).
Comparison to the 2024 Colorado AI Act
SB 26-189 drops several elements of the 2024 Act and retains others, returning the operative liability backbone to general anti-discrimination law (where it sat before 2024) while layering ADMT-specific disclosure and human-review duties on top. The risk-classification model, the algorithmic impact assessment regime, the bias-audit regime, and the deployer's affirmative duty of care are removed; the developer-to-deployer documentation duty, consumer notices, post-adverse-outcome disclosures, the right to correction and human review, the AG-only enforcement model, and the 60-day right to cure are retained, in some cases with adjustments. The act adds indemnification limits and explicitly excludes joint-and-several liability except where existing law permits it.
| Provision | 2024 CO AI Act | SB 26-189 (2026) |
|---|---|---|
| Risk classification (EU-AI-Act-style) | Yes — "high-risk" ADMT triggers heightened duties | Dropped. No risk tiers. |
| Algorithmic impact assessments | Required for high-risk systems | Dropped. |
| Pre-deployment bias audits | Required | Dropped. |
| Affirmative duty to avoid discrimination (deployer duty of care beyond existing anti-discrimination law) | Yes | Dropped. Existing anti-discrimination law remains operative; no new duty of care. |
| Developer documentation to deployer | Yes | Retained (with adjustments). |
| Consumer notice (point-of-interaction) | Yes | Retained, with public-posting alternative. |
| Post-adverse-outcome disclosures | Yes | Retained, with 30-day deadline + AG rules on content. |
| Right to correction + human review | Yes | Retained as a substantive consumer right with AG rules. |
| Private right of action | No (AG-only) | Same — explicitly AG-only. |
| Right to cure | Yes (60 days) | Retained, with sunset Jan 1 2030. |
| Indemnification limits | Not specifically addressed | Added — indemnification clauses for own-acts violations are void. |
| Joint-and-several liability | Existing law | Explicitly excluded unless permitted under existing law. |
The removed elements were the components that aligned the 2024 Act with the EU AI Act's risk-based duty approach. Colorado had been the U.S. state most explicitly modeled on that approach, and SB 26-189 ends that alignment. The retained and added elements distinguish the new framework from a pure transparency-only regime: it channels liability under the existing Colorado Anti-Discrimination Act with fault-allocation and developer-deployer apportionment rules; creates a substantive consumer right to meaningful human review whose definition bars defaulting to system output; voids indemnification clauses that would shift own-acts liability; imposes mandatory documentation duties flowing from developer to deployer and into the AG's enforcement record; and sets explicit non-defenses, providing that compliance is not a defense and that ADMT use does not excuse obligations under federal or state law.
Relationships
- supersedes: Colorado AI Act (SB 24-205) (2024 framework)
- supports: Colorado SB 26-189 (2026 — replaces 2024 Colorado AI Act) (legislation page)
- related: Jared Polis, California SB 53, New York RAISE Act, Illinois SB 315 (frontier safety framework with mandatory third-party audits), State-Level AI Regulation, California Effect, AI and Tort Liability, AI Political Cleavages, EU AI Act (Regulation 2024/1689)
- contradicts: EU-AI-Act risk-based duty model (the 2024 CO AI Act explicitly tracked the EU approach; SB 26-189 abandons it)
Provenance
Raw Sources/Colorado SB 26-189 (Signed Act).md— full bill text (24 pages, extracted from PDF May 17 2026)- Colorado SB 26-189 (2026 — replaces 2024 Colorado AI Act) — wiki legislation page