Skip to main content
Back to Local AI Laws
Effective January 1, 2027

Colorado AI Act (SB 26-189): Complete Compliance Guide

First comprehensive state AI law. High-risk AI definitions, impact assessments, consumer rights. Avoid $20,000 per violation penalties.

High-Risk AI Categories

Employment & Education

Examples:
  • AI resume screening
  • Candidate ranking algorithms
  • Performance evaluation AI
  • Student admissions AI
Requirements:

Impact assessment, bias testing, human review option

Financial Services

Examples:
  • Credit scoring AI
  • Loan approval algorithms
  • Insurance underwriting AI
  • Fraud detection systems
Requirements:

Explainability, adverse action notices, appeal process

Healthcare

Examples:
  • Diagnostic AI
  • Treatment recommendation systems
  • Patient triage algorithms
  • Insurance claim AI
Requirements:

Clinical validation, HIPAA compliance, physician oversight

Housing

Examples:
  • Tenant screening AI
  • Rental application scoring
  • Property valuation algorithms
  • Eviction prediction AI
Requirements:

Fair housing compliance, discrimination testing, transparency

Legal Services

Examples:
  • Bail recommendation AI
  • Sentencing algorithms
  • Legal research AI
  • Contract analysis tools
Requirements:

Human oversight, explainability, audit trails

6-Step Compliance Roadmap

1

Determine if Your AI is High-Risk

AI making consequential decisions about employment, credit, housing, education, healthcare, insurance, or legal services

Deadline: Before deployment
$20,000 per violation
2

Conduct Impact Assessment

Document: intended uses, training data categories, known limitations, human review instructions

Deadline: Annually + when material changes
$20,000 per violation
3

Implement Risk Management Program

Policies for: consumer notice, post-adverse-outcome disclosure, record retention, consumer rights

Deadline: Before January 1, 2027
$20,000 per violation
4

Provide Consumer Disclosures

Notify consumers: AI is being used, purpose, how to request human review, how to access and correct data

Deadline: At point of interaction
$20,000 per violation
5

Enable Opt-Out Rights

Consumers can opt out of AI profiling and request human review of AI decisions

Deadline: Within 30 days of adverse outcome
$20,000 per violation
6

Maintain Documentation

Impact assessments, testing results, consumer complaints, opt-out requests, incident reports

Deadline: Ongoing (3 years retention)
Audit failures

Colorado AI Act FAQ

When does the Colorado AI Act take effect?

January 1, 2027. SB 26-189 was signed May 14, 2026, repealing and reenacting the prior SB 24-205 framework. You should start compliance now: prepare technical documentation, implement consumer notice processes, and establish record retention. The Attorney General can begin enforcement on the effective date.

Does the Colorado AI Act apply to companies outside Colorado?

Yes, if you deploy high-risk AI systems that impact Colorado consumers. Similar to GDPR and CCPA, the law has extraterritorial reach. If you serve Colorado customers and use AI for consequential decisions, you must comply regardless of where your company is located.

What is an "impact assessment" under the Colorado AI Act?

Technical documentation that developers must provide to deployers, covering: (1) Intended uses of covered ADMT, (2) Categories of training data, (3) Known limitations and risks, (4) Instructions for appropriate use and human review. Must be provided before deployment and updated on material changes.

How do I know if my AI system is "high-risk"?

Your system is covered ADMT if it processes personal data and uses computation to generate output that materially influences a consequential decision about: employment, education, financial services, healthcare, housing, insurance, or essential government services. Examples: AI resume screening (employment), credit scoring (financial), tenant screening (housing). If unsure, consult with legal counsel.

What are the penalties for violating the Colorado AI Act?

$20,000 per violation. Each instance of non-compliance is a separate violation. Examples: Using high-risk AI without impact assessment, failing to provide consumer disclosures, not honoring opt-out requests, inadequate bias testing. Violations can accumulate quickly - 100 consumers without disclosure = $2M in potential penalties.

Can I use the same impact assessment for multiple AI systems?

No. Each high-risk AI system requires its own impact assessment. However, you can use a template approach: create a master framework, then customize for each system's specific purpose, data sources, risks, and safeguards. HAIEC provides impact assessment templates to streamline this process.

What is the difference between Colorado AI Act and EU AI Act?

Colorado AI Act: State law, applies to Colorado consumers, $20K per violation, effective January 1, 2027. EU AI Act: EU regulation, applies to EU market, up to 6% revenue fines, phased implementation 2024-2027. Both require impact assessments for high-risk AI, but EU AI Act has stricter requirements and broader scope. If you serve both markets, comply with the stricter EU requirements.

Check Your Colorado AI Act Compliance

Free assessment. Get instant compliance status and impact assessment template.

Free Compliance Check