Colorado Artificial Intelligence Act (SB24-205)
Complete Legal Breakdown with Rules, Layman Explanations & Citations
Who This Law Applies To
Primary Actors
Developers
People or companies who build or significantly modify AI systems
💡 In Plain English:
If you code an AI system or make major changes to one, you're a Developer.
Citation: CRS § 6-1-1701(7) - "DEVELOPER MEANS A PERSON DOING BUSINESS IN THIS STATE THAT DEVELOPS OR INTENTIONALLY AND SUBSTANTIALLY MODIFIES AN ARTIFICIAL INTELLIGENCE SYSTEM."
Deployers
People or companies who use AI systems to make decisions about Colorado residents
💡 In Plain English:
If you use an AI tool to help decide who gets hired, approved for a loan, accepted to a school, etc., you're a Deployer.
Citation: CRS § 6-1-1701(6) - "DEPLOYER MEANS A PERSON DOING BUSINESS IN THIS STATE THAT DEPLOYS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM."
Geographic Scope
Applies to anyone doing business in Colorado who:
- Develops AI systems that affect Colorado residents, OR
- Uses AI systems to make decisions about Colorado residents
Example: A California-based HR tech company sells resume-screening AI to a Denver company. Both the California developer AND the Denver deployer must comply.
Key Definitions in Plain English
Algorithmic Discrimination
LEGAL DEFINITION:
"ANY CONDITION IN WHICH THE USE OF AN ARTIFICIAL INTELLIGENCE SYSTEM RESULTS IN AN UNLAWFUL DIFFERENTIAL TREATMENT OR IMPACT THAT DISFAVORS AN INDIVIDUAL OR GROUP OF INDIVIDUALS ON THE BASIS OF THEIR ACTUAL OR PERCEIVED AGE, COLOR, DISABILITY, ETHNICITY, GENETIC INFORMATION, LIMITED PROFICIENCY IN THE ENGLISH LANGUAGE, NATIONAL ORIGIN, RACE, RELIGION, REPRODUCTIVE HEALTH, SEX, VETERAN STATUS, OR OTHER CLASSIFICATION PROTECTED UNDER THE LAWS OF THIS STATE OR FEDERAL LAW."
Citation: CRS § 6-1-1701(1)(a)
💡 In Plain English:
When your AI treats people differently based on protected characteristics (race, gender, age, disability, etc.) in a way that violates civil rights laws.
Real-World Examples:
- Violates Law: Resume-screening AI that automatically rejects applicants with "ethnic-sounding" names
- Violates Law: Credit-scoring AI that denies loans more often to people from certain zip codes that correlate with race
- Allowed: AI that offers discounts to senior citizens (age-based but not discriminatory)
High-Risk Artificial Intelligence System
LEGAL DEFINITION:
"ANY ARTIFICIAL INTELLIGENCE SYSTEM THAT, WHEN DEPLOYED, MAKES, OR IS A SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL DECISION."
Citation: CRS § 6-1-1701(9)(a)
💡 In Plain English:
AI that helps make important life decisions OR plays a big role in those decisions.
What Makes a Decision "Consequential"?
The law lists 8 specific areas (Citation: CRS § 6-1-1701(3)):
1. Education
School admissions, financial aid, grade/degree decisions
Example: AI that decides who gets into a university program
2. Employment
Hiring, firing, promotions, compensation
Example: AI that screens resumes or scores job interview recordings
3. Financial/Lending
Loans, credit cards, mortgages, interest rates
Example: AI that approves or denies loan applications
4. Government Services
Benefits, licenses, permits (essential services)
Example: AI that determines food stamp eligibility
5. Healthcare
Medical treatment access, coverage decisions, diagnosis assistance
Example: AI that decides which patients get priority for organ transplants
6. Housing
Rental applications, mortgages, housing allocation
Example: AI that screens tenant applications
7. Insurance
Coverage decisions, pricing, claims processing
Example: AI that sets your car insurance rates
8. Legal Services
Access to legal help, case outcome predictions
Example: AI that determines bail amounts
NOT High-Risk (Exemptions)
Citation: CRS § 6-1-1701(9)(b)
The law specifically excludes these systems:
A. Narrow Procedural Tasks
Example: Spell-checkers, calculators, spreadsheets, anti-virus software, spam filters
B. Detection-Only Systems
Example: AI that flags unusual patterns for human review BUT doesn't replace the human decision
C. Common Technologies
(unless they make consequential decisions)
- • Junk email filters
- • Firewalls, anti-malware, cybersecurity
- • Databases and data storage
- • Web caching and hosting
- • Chatbots with acceptable use policies prohibiting discrimination
⚠️ Important Note:
Even these "safe" technologies become high-risk if used to make consequential decisions. Example: Using a chatbot to screen job applicants = high-risk (even though general chatbots are exempt)
Complete Rules Breakdown
Developer Duties
Rule 1: Use Reasonable Care to Prevent Discrimination
Citation: CRS § 6-1-1702(1)
Developers must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination.
💡 What This Means:
- • Test your AI for bias BEFORE launching
- • Document what data you used to train it
- • Identify potential discrimination risks
- • Take steps to reduce those risks
- • Monitor for discrimination after launch
Rule 2: Provide Documentation to Deployers
Citation: CRS § 6-1-1702(2)
You must give customers comprehensive documentation including:
- General Statement: What your AI is for and what it shouldn't be used for
- Data Disclosure: Training data type, known limitations, bias risks
- Performance Evaluation: How you tested for bias, governance measures
- Usage Instructions: How to use properly and monitor for issues
Rule 3: Public Website Disclosure
Citation: CRS § 6-1-1702(4)
Post on your website:
- • Types of high-risk AI systems you sell
- • How you manage discrimination risks
- • Update within 90 days after major modifications
Rule 4: Report Discrimination to Attorney General
Citation: CRS § 6-1-1702(5)
Timeline: Within 90 days of discovering your AI caused or is likely to cause algorithmic discrimination
You must notify the Colorado Attorney General and all known deployers about what happened, which system, how many people affected, and what you're doing to fix it.
Deployer Duties
Rule 1: Use Reasonable Care
Citation: CRS § 6-1-1703(1)
If you USE high-risk AI, you must take reasonable care to prevent discrimination:
- • Don't blindly trust AI outputs
- • Monitor for bias in YOUR use case
- • Have humans review AI decisions
- • Track outcomes by demographic group
- • Fix issues you discover
Rule 2: Risk Management Policy & Program
Citation: CRS § 6-1-1703(2)
Create a written policy and ongoing program that includes:
- • Principles for AI use
- • Processes for identifying risks
- • Personnel responsible for oversight
- • Documented mitigation measures
Recommended Frameworks: NIST AI Risk Management Framework or ISO/IEC 42001
Rule 3: Impact Assessment (Annual)
Citation: CRS § 6-1-1703(3)
When Required:
- • Before first deployment
- • At least annually thereafter
- • Within 90 days after major modifications
Must Include:
- • Purpose and intended use
- • Known or foreseeable discrimination risks
- • Data inputs and outputs
- • Performance metrics and limitations
- • How you disclose AI use to people
- • Post-deployment monitoring processes
Retention: Keep for 3 years after stopping use
Rule 4: Consumer Notice (Before Decision)
Citation: CRS § 6-1-1703(4)(a)
Before AI makes or substantially influences a consequential decision, notify the person about:
- • That AI is being used
- • Purpose of the AI
- • Type of decision being made
- • Contact info for your company
- • Description of the AI (plain language)
- • How to access your public disclosure
- • Their right to opt-out (if applicable)
Rule 5: Adverse Decision Notice
Citation: CRS § 6-1-1703(4)(b)
If AI contributed to a decision that went AGAINST the person (denied, rejected, etc.), you must provide:
- • Explanation of how much AI influenced the decision
- • What data AI considered and where it came from
- • Right to correct any incorrect personal data
- • Right to appeal with human review
Penalties & Enforcement
Enforcement Authority
Exclusive Enforcer: Colorado Attorney General
Citation: CRS § 6-1-1706(1)
Note: Individuals cannot sue under this law, but can sue under other discrimination laws.
Penalty Structure
Citation: CRS § 6-1-1706(2) + § 6-1-105(1)(hhhh)
Violation Type: Deceptive trade practice under Colorado Consumer Protection Act
Up to $20,000 per violation
Plus potential:
- • Injunctions (court orders to stop)
- • Corrective actions (fix the problem)
Affirmative Defense
Citation: CRS § 6-1-1706(3)
You can get legal protection if you:
- Follow NIST AI RMF, ISO/IEC 42001, or other recognized framework
- Discover violations through user feedback, testing, or internal review
- Fix (cure) the violation promptly
Exemptions & Safe Harbors
Who's Fully Exempt
Insurance Companies
Following Colorado insurance AI rules (CRS § 10-3-1104.9)
Federal System Users
FDA/FAA approved AI systems
Federal Contractors
Defense/NASA work (except employment/housing)
HIPAA Covered Entities
Healthcare recommendations requiring provider action
Small Deployer Exemption
Citation: CRS § 6-1-1703(6)
Who Qualifies:
- • Fewer than 50 employees
- • Don't use own data to train the AI
- • Use AI only for its intended purposes
Exempt From:
- • Risk management policy
- • Impact assessments
- • Public disclosures
Still Must Do:
- • Reasonable care
- • Consumer notices
- • Report discrimination
Compliance Timeline
Key Dates
June 30, 2026: Law takes effect
90 Days After Discovery: Report discrimination
Annually: Impact assessments due
90 Days After Major Modification: Update impact assessment
Implementation Roadmap
6 Months Before (December 2025)
- □ Identify all high-risk AI systems
- □ Classify as developer vs. deployer
- □ Assign responsible personnel
- □ Review exemption eligibility
3 Months Before (March 2026)
- □ Draft risk management policy
- □ Conduct initial impact assessments
- □ Prepare public disclosures
- □ Design consumer notice templates
1 Month Before (May 2026)
- □ Post disclosures on website
- □ Train staff on requirements
- □ Set up monitoring processes
- □ Test discrimination reporting procedures
June 30, 2026 - Launch Day
- ✓ All policies in effect
- ✓ Consumer notices live
- ✓ Website disclosures published
- ✓ Monitoring active
Ongoing
- □ Annual impact assessments
- □ Quarterly risk policy reviews
- □ Monthly discrimination monitoring
- □ 90-day violation reporting (if needed)
Frequently Asked Questions
Does this apply to my company outside Colorado?
Answer: Yes, if you do business in Colorado and your AI affects Colorado residents.
Example: California company sells HR software to Colorado employers → Must comply
What if I just use off-the-shelf AI tools?
Answer: You're likely a "deployer" and must:
- • Do impact assessments
- • Notify consumers
- • Monitor for discrimination
- • Report problems
Small Company Exception: If you have < 50 employees and don't customize the AI, you skip some paperwork but still must notify consumers and prevent discrimination.
Can I just add "AI" to my terms of service?
Answer: No. You must provide specific, timely notice before each consequential decision. Generic terms of service aren't enough.
What's the difference between a developer and deployer?
Developer: You build or significantly modify the AI
Deployer: You use AI to make decisions about people
Can be both: If you build AI AND use it on customers, you have duties under both roles.
Do I need a lawyer?
Recommended but not required. This is a complex law. Key decision points:
- • Determining if your AI is "high-risk"
- • Assessing if exemptions apply
- • Drafting compliant policies
- • Responding to AG inquiries
DIY Possible If:
- • You follow this guide
- • You implement NIST AI RMF or ISO 42001
- • You document everything
- • You're cautious and conservative
Official Sources & Citations
Informational Resource
This resource provides general information about the Colorado Artificial Intelligence Act (SB24-205) and is designed to help you understand the requirements. The information is compiled from publicly available sources and official legislative text. For specific legal advice tailored to your situation, we recommend consulting with a qualified attorney or compliance professional licensed in Colorado.