On May 14, 2026 Colorado repealed the AI Act (SB 24-205) and replaced it with the ADMT in Consequential Decisions Act (SB 26-189). The deadline didn’t move. The duties did — most published guidance still describes the old law.
Two states. One deadline. One system.California’s CCPA ADMT regulations require compliance by the same date.
Until 12:00 AM Mountain Time, January 1, 2027 — when Colorado’s ADMT Act (SB 26-189) and HB 26-1263 take effect. California’s CCPA ADMT rules carry the same date.
The current law, in plain language
If you use automated decision-making technology that materially influences a consequential decision — hiring, lending, housing, insurance, education, healthcare — four duties attach. The Attorney General enforces them; there is no private right of action.
Tell the consumer you're using automated decision-making technology before it materially influences a consequential decision about them — not after.
When the outcome goes against someone, give a plain-language explanation of the principal reasons — within 30 days. Plain-language means a consumer can act on it, not a model card.
Provide a meaningful path to human review of an adverse automated decision where that review is technically feasible — a real person with authority to change the outcome.
Retain the records demonstrating compliance for at least three years. If you can't produce them for the AG, you can't prove you complied.
HB 26-1263 governs consumer-facing conversational AI — chatbots and similar tools people talk to directly. It requires clear AI disclosure, safeguards for minor users, crisis-response protocols for self-harm indicators, and privacy/consent tools. A hiring or eligibility screening tool falls under SB 26-189; a public-facing chatbot falls under HB 26-1263. Many organizations have both.
The history people still search for
Colorado passed the nation’s first comprehensive AI law in 2024, then repealed it before it ever took effect. If you built a compliance plan against the original act, here is exactly what survived and what didn’t.
No — but be precise about why you’re doing them. Colorado no longer requires them.We won’t tell you otherwise to sell you something.
They are still required elsewhere — California’s CCPA ADMT regulations mandate documented risk assessments, and the EU AI Act has its own regime — and they remain the first thing boards, insurers, and enterprise customers ask to see in a security review. GOVERNBOX ships impact assessments as best practice and as compliance for the jurisdictions that do require them, never as a Colorado legal duty.
Colorado AI law compliance, explained plainly
Governs automated decision-making technology (“covered ADMT”) that materially influences a consequential decision about a consumer — hiring, lending, housing, insurance, and similar. Requires deployer notices before and after a decision, a path to human review and appeal, developer documentation and transparency, incident reporting, and records retention.
Governs consumer-facing conversational AI — chatbots and similar tools people talk to directly. Requires clear AI disclosure, safeguards for minor users, crisis-response protocols for self-harm indicators, and privacy/consent tools for users and parents.
Most nonprofits and small businesses will find at least one of these applies — a hiring or eligibility screening tool falls under SB 26-189; a public-facing chatbot falls under HB 26-1263. Many organizations have both.
Together these two bills are Colorado’s current AI framework, recentered on automated decision-making technology. The Attorney General’s implementing rules are still being developed, so specifics will keep firming up before the deadline. GOVERNBOX tracks those changes and folds what matters into your crosswalk and regulatory feed — so you don’t find out from a law-firm alert six months late.
No small-business carve-out
Colorado AI law compliance is triggered by what your organization doeswith AI — not your headcount or revenue. If any of the following sound familiar, you’re likely in scope:
What your board should be asking
Built for the deadline
No consultant, no enterprise platform — a guided program built for the accidental AI owner at a nonprofit or small business.
A sector-aware AI use policy and acceptable-use standard for small business or nonprofit teams — grounded in a cited control library, not a generic AI policy template.
See exactly which SB 26-189 and HB 26-1263 requirements your approved policies already cover, and which are gaps — each one traced to the exact statutory citation.
A quarterly Board Report built around the five questions every board asks, plus a shareable governance badge that proves your program to funders.
Track every AI system by likelihood × impact, with an incident log ready the moment Colorado's reporting clock starts.
Common questions
Have a different question? See our full FAQ →
Colorado’s ADMT Act and California’s CCPA ADMT rules both bite on January 1, 2027. Take the free 5-minute AI Readiness Scorecard and see where you stand against both today.
Rulemaking is still underway. Why AI Governance? — see the full 2026 compliance picture →
General information about Colorado’s ADMT in Consequential Decisions Act (SB 26-189), HB 26-1263, and California’s CCPA ADMT regulations — not legal advice. Rulemaking is ongoing. Consult your own counsel to confirm how these apply to your organization.