Colorado wrote the first comprehensive US state AI law, then repealed it before it ever took effect. If you scoped a build against the old text, half of it is now optional and the other half has changed shape.
Colorado’s original AI Act, SB 24-205, was signed in May 2024 and treated as the template every other state would copy. It never came into force. It was signed, delayed twice — from 1 February 2026 to 30 June 2026 — and then, on 14 May 2026, repealed and replaced by SB 26-189, which stands up an entirely new statute: the Automated Decision-Making Technology Act, the ADMTA. That takes effect on 1 January 2027, subject to the state attorney general completing the required rulemaking by then. If you built or scoped a compliance programme against the old discrimination-impact regime, this is a re-baselining exercise, not a tweak.
From duty of care to disclosure
The old Act was built around a duty of reasonable care to protect consumers from algorithmic discrimination in “high-risk AI systems”. That framing forced the heavy machinery: annual impact assessments, a documented risk-management programme, and notification to the attorney general when you discovered discrimination. The ADMTA drops nearly all of it. It stops regulating “high-risk AI systems” and instead regulates “automated decision-making technology” — ADMT — defined as technology that processes personal data and uses computation to produce predictions, recommendations, classifications, rankings, scores or similar outputs to make or assist a decision about a person.
Free · 4 minutes
Do you know where AI is already being used in your business — and what it can see?
Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.
The trigger is a “consequential decision” that the ADMT materially influences in one of seven domains: education enrolment, employment, financial or lending services, essential government services, health care, housing and insurance. Broadly the same territory as the old Act, but a narrower and more mechanical test. You are no longer asked to reason about risk in the abstract; you are asked whether a specific system materially influences a specific kind of decision, and if so, to disclose and document.
What you can stop building
If your programme was scoped against SB 24-205, the expensive parts are the ones the ADMTA no longer requires. The mandatory annual impact assessment — the artefact most vendors were selling tooling to generate — is gone as a statutory duty. The standing risk-management programme is gone. The duty of care and the discrimination-notification trigger are gone. That does not make impact analysis worthless; if you also operate under other regimes, or you have a genuine reason to test models for disparate outcomes, it may still earn its place. But commissioning bespoke discrimination-impact tooling now, solely to satisfy Colorado, is building a control the statute retired before it drew breath. The discipline is the same one that applies to any build: scope it to what is actually required, not to what the previous draft implied. If you are still working out what “build something” actually means for the obligation in front of you, this is exactly the moment to redraw the line.
What now carries the weight
The burden moves from analysis to paperwork you can be inspected on. Developers must hand deployers documentation: intended uses, reasonably foreseeable harmful uses, the categories of training data, known limitations and risks, instructions for human oversight, and enough information for the deployer to meet its own duties — plus notice when a material update changes any of that. Deployers owe consumers a clear and conspicuous notice before an ADMT influences a consequential decision and, where the outcome is adverse, a plain-language explanation of the decision and the ADMT’s role, delivered within 30 days. And you keep the records: the statute expects compliance documentation retained for three years.
This is a documentation regime, and documentation regimes are won or lost in the data model, not the policy binder. If your systems cannot reconstruct which ADMT touched a given decision, what it produced, and when the developer last pushed a material change, you cannot generate the notice on demand — and the notice, not the impact assessment, is now the thing a regulator asks to see.
The consumer rights you have to wire in
Three consumer rights need real plumbing, not a policy statement. A consumer can request access to the personal data used in the decision, request correction of inaccurate data, and request meaningful human review and reconsideration “to the extent commercially reasonable”. “Meaningful human review” is the phrase to design against: a rubber-stamp queue will not satisfy it, and a genuine review path has to pull the inputs, the output and the ADMT’s role back out of your systems on demand. If you have read California’s own automated-decision-making rules, this will feel familiar — the CCPA’s ADMT duties land in the same window. Build the retrieval and human-review path once and map it to both, rather than standing up two parallel workflows for two states that want the same evidence.
What to keep, what to retire
Re-baseline against three buckets. Keep your ADMT inventory — you still need to know which systems touch consequential decisions, except the inventory is now the spine of the disclosure duty rather than the impact-assessment duty. Keep the developer-to-deployer documentation flow, because the ADMTA makes it a hard requirement with a material-update trigger. Retire, or at least stop expanding, the bespoke annual impact-assessment tooling and discrimination-scoring pipelines built solely for the old Colorado duty. Redirect the effort you were spending on impact analysis into notice generation, adverse-outcome explanations, and the access, correction and review workflow. If you own and oversee this build rather than outsourcing it wholesale, that redirection is a scoping decision you can make cleanly in an afternoon.
One caution on the date. The 1 January 2027 effective date is contingent on the attorney general finishing rulemaking, and this law has already been delayed once and litigated. Treat it as firm enough to build against but soft enough to watch. There is also a cure period that sunsets on 1 January 2030: early enforcement is likely to be forgiving, later enforcement will not be.
The trap here is symmetry. Teams that over-built for the old law will feel virtuous keeping the machinery, and teams that waited will feel vindicated doing nothing. Both are wrong: the law did not get lighter, it got narrower and more evidential — and evidential regimes punish the firm that cannot produce the record on the day it is asked for.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Governance is what happens when nobody is watching.
Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming