AI Policy Wiki
Dashboard

Colorado Revises Its AI Act — What Changed and Why (FPF / Tatiana Rice, May 2026)

high confidence · updated 2026-06-06

Future of Privacy Forum's detailed CAIA → CADMA comparison analysis, written by Tatiana Rice (FPF Senior Director for U.S. Legislation) the week SB 189 was signed. A side-by-side of the 2024 Colorado AI Act versus the 2026 Colorado ADM Act. Includes a downloadable comparison chart and analyzes the reasoning behind each shift.

A Future of Privacy Forum (FPF) analysis by Tatiana Rice, FPF Senior Director for U.S. Legislation, published around May 19, 2026, the week Colorado SB 189 was signed. It provides a section-by-section comparison of the 2024 Colorado AI Act (CAIA) with the 2026 Colorado ADM Act (CADMA), which Governor Jared Polis signed on May 15, 2026, and explains the political and drafting reasons behind each change. A companion FPF Member Comparison Chart accompanies the post as a downloadable reference for state lawmakers, regulated entities, and other state policy offices.

Source: https://fpf.org/blog/colorado-revises-its-ai-act-what-changed-and-why/ Comparison chart: https://fpf.org/wp-content/uploads/2026/05/FPF-Member-Comparison-Final-CAIA-Revisions.pdf Author: Tatiana Rice, Future of Privacy Forum Senior Director for U.S. Legislation Published: ~May 19, 2026

Provenance and framing

Rice describes the original CAIA (2024) as the first U.S. state law to impose EU-AI-Act-style risk-based duties on AI developers and deployers in consequential decisions, and CADMA as its legislative resolution after roughly two years of contentious debate — the only such resolution any state had produced as of May 2026. The analysis frames CADMA as a "fundamental shift from an algorithmic discrimination framework to a transparency-focused one, as well as narrowing the scope of covered AI systems, streamlining disclosures and consumer rights, and replacing governance requirements with liability allocation under existing anti-discrimination laws."

Side-by-side: CAIA (2024) vs CADMA (2026)

Scope of regulated systems

DimensionCAIA (2024)CADMA (2026)
Defined object"High-risk AI systems""Covered automated decision-making technology" (ADMT)
Threshold"Substantial factor in, or capable of altering, consequential decisions"Systems that process personal data AND are actually used to "materially influence" decisions
Decision threshold"Material, legal, or similarly significant effect"Decisions "relate to" a covered domain (lower bar in decision type, higher bar in tech)
Decision types"Provision or denial of, or cost or terms of"Adds "delay" and "alteration"
EmploymentAll employment decisionsHiring decisions only
Small-deployer exemptionYesRemoved
AdvertisingCovered under "access to" consequential decisionsNew exemption added
Legal-compliance exemptionBroadNarrowed to only anti-terrorism and money laundering

Rice notes that CADMA's scope is not easily characterized as simply narrower or broader than CAIA's: the technology threshold is higher, but the decision threshold is lower and the small-deployer exemption is gone.

Liability framework

Rice identifies the liability framework as the most fundamental departure from CAIA.

DimensionCAIA (2024)CADMA (2026)
Duty of care to mitigate algorithmic discriminationYes — statutoryEliminated
Algorithmic discrimination incident reportingYesRemoved
Risk management programsRequiredRemoved
Annual impact assessmentsRequiredRemoved
Affirmative defense via NIST AI RMF complianceYesN/A — no duty of care
Existing CO anti-discrimination lawNot displacedNow the primary liability anchor
Developer liabilityBroaderLimited to intended use
Indemnification of developer by deployerPermittedProhibited
Cure periodNone60 days before penalties

Disclosures and consumer rights

DimensionCAIA (2024)CADMA (2026)
Developer-to-deployer disclosuresFull "disclosures and documentation" of known limitations, biases, risk mitigationNarrowed to general statement on use, limitations, monitoring
Pre-use deployer-to-consumer noticeDetailedNarrowed to "ADMT is being used" + how to get more info
Post-adverse-outcome consumer disclosuresN/A explicitNew requirement — plain-language description of decision, ADMT's role, rights
Consumer rightsApply broadlyLimited to adverse-decision instances
Response time for consumer requestsSpecific time periodRemoved
General consumer-facing AI disclosureRequiredRemoved

Enforcement

  • AG enforcement (no private right of action) — same in both
  • Effective date: January 1, 2027 (vs CAIA's planned February 2026 effective date)
  • 60-day cure period sunsets January 1, 2030 (knowing/repeated violations not curable)

Reasoning behind the change

For each cluster of changes, Rice identifies the political coalition she sees as having prevailed. She attributes the transparency turn to Polis's stated 2024 reservations that CAIA could "tamper innovation and deter competition," a US Chamber of Commerce letter arguing that compliance costs would burden small businesses, and a 2025 deregulatory shift in other state legislatures that left Colorado as an outlier. The constitutional challenge by xAI in April 2026 (see xAI LLC v. Weiser — Complaint (D. Colo. 1:26-cv-01515)) added litigation pressure alongside the legislative pressure.

Rice describes the coalition that retained some obligations — labor, consumer, civil rights, privacy, and public-interest groups supported the law. After failed 2025 negotiations, Polis convened a working group, and Rice characterizes the result as a transparency-plus-discrimination-liability compromise rather than transparency-only. She also points to a drafting change: Senator Rodriguez's CAIA borrowed heavily from data-privacy law terminology, including Colorado Privacy Act language, whereas CADMA was drafted by the Governor's office and moved away from that privacy framework. Rice treats Senator Rodriguez's retirement as a structural factor for future revisions, arguing that without similarly positioned leadership further statutory changes seem unlikely, and that the Attorney General's rulemaking process is where the operative compliance content will be set.

Analysis Rice offers

Rice frames the contrast as a regulatory-philosophy choice: detailed governance requirements (CAIA) favor entities seeking regulatory certainty, while limited transparency plus general application of existing law (CADMA) favors entities preferring to allocate resources to growth, and Polis chose the latter. She argues that documentation now matters more for liability allocation than for safe harbor: because deployer indemnification of the developer is prohibited and developer liability is limited to "intended use," documentation specifications now determine which party bears liability for misuse. Rice identifies the "intended use" standard as the regulatory innovation worth tracking, framing whether other states copy it as a signal about how the deployer-versus-developer responsibility allocation evolves. She closes by framing CADMA's trajectory as "critical data for the debate on whether consequential algorithmic systems require specialized governance frameworks or can be adequately governed through transparency and existing law."

According to Rice's comparison, most governance and risk-management provisions from the 2024 CAIA did not survive; most disclosure provisions did, in narrower form; the small-deployer exemption did not survive; and the "intended use" standard for developer liability is new, having had no predecessor in CAIA.

Relationships