A Future of Privacy Forum (FPF) analysis by Tatiana Rice, FPF Senior Director for U.S. Legislation, published around May 19, 2026, the week Colorado SB 189 was signed. It provides a section-by-section comparison of the 2024 Colorado AI Act (CAIA) with the 2026 Colorado ADM Act (CADMA), which Governor Jared Polis signed on May 15, 2026, and explains the political and drafting reasons behind each change. A companion FPF Member Comparison Chart accompanies the post as a downloadable reference for state lawmakers, regulated entities, and other state policy offices.
Source: https://fpf.org/blog/colorado-revises-its-ai-act-what-changed-and-why/ Comparison chart: https://fpf.org/wp-content/uploads/2026/05/FPF-Member-Comparison-Final-CAIA-Revisions.pdf Author: Tatiana Rice, Future of Privacy Forum Senior Director for U.S. Legislation Published: ~May 19, 2026
Provenance and framing
Rice describes the original CAIA (2024) as the first U.S. state law to impose EU-AI-Act-style risk-based duties on AI developers and deployers in consequential decisions, and CADMA as its legislative resolution after roughly two years of contentious debate — the only such resolution any state had produced as of May 2026. The analysis frames CADMA as a "fundamental shift from an algorithmic discrimination framework to a transparency-focused one, as well as narrowing the scope of covered AI systems, streamlining disclosures and consumer rights, and replacing governance requirements with liability allocation under existing anti-discrimination laws."
Side-by-side: CAIA (2024) vs CADMA (2026)
Scope of regulated systems
| Dimension | CAIA (2024) | CADMA (2026) |
|---|---|---|
| Defined object | "High-risk AI systems" | "Covered automated decision-making technology" (ADMT) |
| Threshold | "Substantial factor in, or capable of altering, consequential decisions" | Systems that process personal data AND are actually used to "materially influence" decisions |
| Decision threshold | "Material, legal, or similarly significant effect" | Decisions "relate to" a covered domain (lower bar in decision type, higher bar in tech) |
| Decision types | "Provision or denial of, or cost or terms of" | Adds "delay" and "alteration" |
| Employment | All employment decisions | Hiring decisions only |
| Small-deployer exemption | Yes | Removed |
| Advertising | Covered under "access to" consequential decisions | New exemption added |
| Legal-compliance exemption | Broad | Narrowed to only anti-terrorism and money laundering |
Rice notes that CADMA's scope is not easily characterized as simply narrower or broader than CAIA's: the technology threshold is higher, but the decision threshold is lower and the small-deployer exemption is gone.
Liability framework
Rice identifies the liability framework as the most fundamental departure from CAIA.
| Dimension | CAIA (2024) | CADMA (2026) |
|---|---|---|
| Duty of care to mitigate algorithmic discrimination | Yes — statutory | Eliminated |
| Algorithmic discrimination incident reporting | Yes | Removed |
| Risk management programs | Required | Removed |
| Annual impact assessments | Required | Removed |
| Affirmative defense via NIST AI RMF compliance | Yes | N/A — no duty of care |
| Existing CO anti-discrimination law | Not displaced | Now the primary liability anchor |
| Developer liability | Broader | Limited to intended use |
| Indemnification of developer by deployer | Permitted | Prohibited |
| Cure period | None | 60 days before penalties |
Disclosures and consumer rights
| Dimension | CAIA (2024) | CADMA (2026) |
|---|---|---|
| Developer-to-deployer disclosures | Full "disclosures and documentation" of known limitations, biases, risk mitigation | Narrowed to general statement on use, limitations, monitoring |
| Pre-use deployer-to-consumer notice | Detailed | Narrowed to "ADMT is being used" + how to get more info |
| Post-adverse-outcome consumer disclosures | N/A explicit | New requirement — plain-language description of decision, ADMT's role, rights |
| Consumer rights | Apply broadly | Limited to adverse-decision instances |
| Response time for consumer requests | Specific time period | Removed |
| General consumer-facing AI disclosure | Required | Removed |
Enforcement
- AG enforcement (no private right of action) — same in both
- Effective date: January 1, 2027 (vs CAIA's planned February 2026 effective date)
- 60-day cure period sunsets January 1, 2030 (knowing/repeated violations not curable)
Reasoning behind the change
For each cluster of changes, Rice identifies the political coalition she sees as having prevailed. She attributes the transparency turn to Polis's stated 2024 reservations that CAIA could "tamper innovation and deter competition," a US Chamber of Commerce letter arguing that compliance costs would burden small businesses, and a 2025 deregulatory shift in other state legislatures that left Colorado as an outlier. The constitutional challenge by xAI in April 2026 (see xAI LLC v. Weiser — Complaint (D. Colo. 1:26-cv-01515)) added litigation pressure alongside the legislative pressure.
Rice describes the coalition that retained some obligations — labor, consumer, civil rights, privacy, and public-interest groups supported the law. After failed 2025 negotiations, Polis convened a working group, and Rice characterizes the result as a transparency-plus-discrimination-liability compromise rather than transparency-only. She also points to a drafting change: Senator Rodriguez's CAIA borrowed heavily from data-privacy law terminology, including Colorado Privacy Act language, whereas CADMA was drafted by the Governor's office and moved away from that privacy framework. Rice treats Senator Rodriguez's retirement as a structural factor for future revisions, arguing that without similarly positioned leadership further statutory changes seem unlikely, and that the Attorney General's rulemaking process is where the operative compliance content will be set.
Analysis Rice offers
Rice frames the contrast as a regulatory-philosophy choice: detailed governance requirements (CAIA) favor entities seeking regulatory certainty, while limited transparency plus general application of existing law (CADMA) favors entities preferring to allocate resources to growth, and Polis chose the latter. She argues that documentation now matters more for liability allocation than for safe harbor: because deployer indemnification of the developer is prohibited and developer liability is limited to "intended use," documentation specifications now determine which party bears liability for misuse. Rice identifies the "intended use" standard as the regulatory innovation worth tracking, framing whether other states copy it as a signal about how the deployer-versus-developer responsibility allocation evolves. She closes by framing CADMA's trajectory as "critical data for the debate on whether consequential algorithmic systems require specialized governance frameworks or can be adequately governed through transparency and existing law."
According to Rice's comparison, most governance and risk-management provisions from the 2024 CAIA did not survive; most disclosure provisions did, in narrower form; the small-deployer exemption did not survive; and the "intended use" standard for developer liability is new, having had no predecessor in CAIA.
Relationships
- supports: Colorado SB 26-189 (2026 — replaces 2024 Colorado AI Act) — primary external analysis of the signed act
- supports: Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) — comparison to predecessor
- supports: xAI LLC v. Weiser — Complaint (D. Colo. 1:26-cv-01515) — Rice cites the xAI constitutional challenge as a precipitating pressure
- depends-on: State-Level AI Regulation — uses the broader state-track analysis as backdrop
- related: California SB 53 — Transparency in Frontier AI Act, New York RAISE Act (S. 8828), Illinois SB 315 (frontier safety framework with mandatory third-party audits), Future of Privacy Forum (FPF), Regulatory Typology: Self-Regulation, Co-Regulation, Traditional Government Regulation, Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race, AI Bias and Discrimination, AI Liability, AI Transparency