The Colorado AI Act, the first comprehensive state artificial intelligence law in the United States, no longer exists in the form most compliance teams spent two years preparing for. According to a February 2026 Gartner press release, enterprise spending on AI governance platforms will reach $492 million this year and pass $1 billion by 2030, much of it driven by exactly this kind of regulatory churn. In May 2026, Colorado repealed its original high-risk AI framework and replaced it with Senate Bill 26-189, a narrower law governing automated decision-making technology (ADMT) that takes effect January 1, 2027. This checklist covers what the new law actually requires, who has to comply, and how to align it with ISO 42001, the EU AI Act, and NIST AI RMF so your controls survive the next change.
The law you prepared for was repealed before it took effect
Start here, because most guidance still online is wrong. Colorado signed SB 24-205 in May 2024 and it was poised to become the country’s first broad AI statute, built around “high-risk artificial intelligence systems” used in consequential decisions. It imposed a duty of care to prevent algorithmic discrimination, mandatory risk management programs, and annual impact assessments. The original February 1, 2026 start date slipped to June 30, 2026, and then the legislature did something more drastic than amend it.
In May 2026, Governor Polis signed SB 26-189, which repealed and replaced the Colorado AI Act outright. As Finnegan’s analysis of the new framework documents, the “high-risk artificial intelligence system” standard, the duty of care, the risk management program mandate, and the impact assessment requirement are all gone from the statute. The original law never took effect at all. If your project plan still has a line item for a Colorado AI impact assessment, delete it.
| WHAT CHANGED Out: high-risk AI classification, duty of care, risk management programs, annual impact assessments, and the affirmative defense for ISO 42001 or NIST AI RMF compliance. In: a transparency and consumer-rights regime built on developer documentation, consumer notice, adverse-outcome explanations, meaningful human review, and three-year recordkeeping. |
Who SB 26-189 covers: developers, deployers, and covered ADMT
The new law drops the AI-specific language and regulates covered automated decision-making technology. ADMT is defined broadly as technology that processes personal data and uses computation to generate an output, including a prediction, recommendation, classification, ranking, or score, that is used to make, guide, or assist a consequential decision. That definition reaches well beyond what most people picture as AI. A rules-based scoring spreadsheet with an inferential step can qualify.
ADMT becomes covered only when it materially influences a consequential decision, meaning its output is a non-de minimis factor in the outcome. Consequential decisions are the high-stakes ones: education enrollment, employment, housing, lending and financial services, insurance, health care, legal services, and essential government services. Routine or clerical uses, identity verification, cybersecurity, and sanctions screening are carved out, and the employment provisions do not reach independent contractors or applicants who are not Colorado residents.
Two roles carry the obligations. A developer builds, sells, licenses, or substantially modifies a covered ADMT. A deployer uses one in Colorado. Many organizations are both. Your first compliance task is deciding which hat you wear for each system, because the duties differ sharply, as Crowell’s breakdown of the three compliance pillars makes clear.
The Colorado AI Act compliance checklist
Two tracks, because the law splits cleanly along the developer and deployer line. Work the one that fits each system, or both. Each item notes the framework control that operationalizes it, so the same work satisfies more than one regime.
If you build or substantially modify ADMT (developer track)
- Produce technical documentation for every covered ADMT. Cover intended uses, known harmful or inappropriate uses, categories of training data, known limitations and risks, and instructions for appropriate use, monitoring, and human review. Maps to ISO 42001 Annex A documentation controls and EU AI Act Article 11.
- Give deployers what they need for their own disclosures. Provide the information a deployer requires to meet its consumer notice and explanation duties, in a form that is reasonably understandable while protecting trade secrets. Maps to EU AI Act Article 13.
- Notify deployers of material updates. Flag intentional modifications and changes to intended use or risk mitigation within a reasonable time. Public release notes plus direct notice can satisfy this. Maps to NIST AI RMF Manage and ISO 42001 Clause 8.
- Keep records for at least three years. Retain version identifiers, changelogs, and material-update documentation. Maps to EU AI Act Article 12 and ISO 42001 Clause 7.5.
If you use ADMT in Colorado (deployer track)
- Give clear pre-use notice. Tell consumers, before or at the point of interaction, that a covered ADMT is being used in the decision. Maps to EU AI Act Article 50 transparency.
- Explain adverse outcomes within 30 days. When a covered ADMT materially influences a decision that produces an adverse outcome, deliver a plain-language description of the decision, the role the ADMT played, how to request more information, and the consumer’s rights. Maps to EU AI Act Article 86.
- Stand up a data-correction process. Let consumers request correction of factually inaccurate personal data used in the decision. Note the obligation does not extend to correcting opinions, scores, or predictions. Maps to EU AI Act Article 10 and ISO 42001 data controls.
- Provide meaningful human review on request. Offer reconsideration by a trained person with authority to approve, modify, or override the decision, who does not simply defer to the system and understands its inputs and limitations, to the extent commercially reasonable. Maps to EU AI Act Article 14 human oversight.
- Retain compliance records for at least three years after each consequential decision. Maps to NIST AI RMF Measure and ISO 42001 Clause 9.
Organizations deploying AI systems should also review the FTC AI claims compliance checklist before making public statements about AI capabilities or performance.
| PRACTITIONER NOTE “Meaningful human review” is not a rubber stamp. The statute requires a reviewer with real authority and enough context to understand the system’s intended use, limitations, inputs, and the main factors behind its output, without forcing disclosure of source code or model weights. Build the reviewer role, the access, and the audit trail now, not in December. |
Mapping SB 26-189 to ISO 42001, the EU AI Act, and NIST AI RMF
Here is the part most checklists skip. SB 24-205 offered an affirmative defense for organizations that complied with a recognized AI risk framework, and that defense was repealed along with the rest of the old law. Framework alignment is no longer a statutory safe harbor in Colorado. It is still the most efficient way to operationalize the new duties, and the controls carry across the other regimes you face, so you build once and reuse. The table below links each SB 26-189 obligation to its nearest control in the three frameworks that matter most.
Implementing the NIST AI RMF helps organizations operationalize many of the governance, inventory, and monitoring practices expected under modern AI regulations.
| SB 26-189 duty | ISO/IEC 42001:2023 | EU AI Act | NIST AI RMF 1.0 |
|---|---|---|---|
| Developer documentation | Annex A system documentation; Cl. 7.5 | Art. 11 + Annex IV | MAP |
| Info to deployers | Annex A info for interested parties | Art. 13 | MAP / GOVERN |
| Material-update notice | Cl. 8.1; Cl. 10 | Art. 72 monitoring | MANAGE |
| Pre-use consumer notice | Annex A transparency controls | Art. 50 | GOVERN |
| 30-day adverse-outcome explanation | Annex A impact information | Art. 86 | MEASURE / MANAGE |
| Data correction rights | Annex A data governance | Art. 10 | MAP / MEASURE |
| Meaningful human review | Cl. 5 leadership; Annex A oversight | Art. 14 | GOVERN |
| Three-year record retention | Cl. 7.5; Cl. 9.1 | Art. 12 | MEASURE |
Mappings show practical alignment, not legal equivalence. ISO/IEC 42001:2023 is the certifiable AI management system standard; NIST AI RMF 1.0 organizes work into the Govern, Map, Measure, and Manage functions; EU AI Act article numbers refer to Regulation (EU) 2024/1689.
Exemptions and sector carve-outs worth knowing
The new law leans on existing sector regimes rather than stacking a second set of rules on top. Several categories are treated as compliant if they follow the disclosure requirements they already live under, and a few are excluded entirely. One important shift from the old law: SB 26-189 narrowed some of the broad federal-entity exemptions, so do not assume a carve-out survived the rewrite without checking, a point Norton Rose Fulbright’s review underscores.
| Category | How SB 26-189 treats it |
|---|---|
| Creditors under ECOA / FCRA | Compliant federal adverse-action notices generally satisfy the explanation duty |
| FERPA-covered educational institutions | Deemed compliant when following FERPA notice and disclosure rules |
| State-regulated insurers (SB 21-169) | Generally deemed compliant in the practice of insurance |
| FDA-regulated medical devices and pharma | Excluded from the law entirely |
| HIPAA-covered entities | Largely exempt, except ADMT used in employment or financial-assistance eligibility |
Enforcement, liability and the litigation cloud
The Colorado Attorney General has exclusive enforcement authority. A violation of the developer or deployer duties is treated as a deceptive trade practice under the Colorado Consumer Protection Act, and there is no private right of action. Before bringing an action prior to January 1, 2030, the AG must give 60 days’ notice and an opportunity to cure where a cure is possible. That cure period does not apply to knowing or repeated violations, and it sunsets on January 1, 2030. The AG must also adopt rules clarifying the adverse-outcome disclosures and the meaning of “materially influence” by January 1, 2027.
Two liability points deserve a board-level flag. First, the law voids any contract clause that tries to indemnify a developer or deployer against its own violations, so review your AI vendor agreements now rather than at renewal. Second, fault is allocated by relative fault between developers and deployers, with no joint and several liability, and a developer is liable only when its system was used as intended, documented, or contracted.
| LITIGATION WATCH: Treat the timeline as firm but not certain. Epstein Becker Green reports that a federal court enjoined enforcement of the prior law in xAI v. Weiser in April 2026, with the US Department of Justice moving to intervene. The January 1, 2027 effective date for SB 26-189 is currently operative, but the litigation is live and could affect it. [VERIFY current status before publication] |
Your 2026 runway: what to do before January
The operational lift is smaller than the old law’s, but it still takes months to do well. Treat the rest of 2026 as preparation time, not a pause.
- Inventory every ADMT. Find each automated system that processes personal data and could materially influence a consequential decision, whether built in-house or procured.
- Classify your role per system. Decide whether you are a developer, a deployer, or both, since the duties diverge.
- Draft the notice and explanation templates. Build pre-use notices and a plain-language adverse-outcome explanation flow, ready to finalize once the AG rules land.
- Operationalize human review. Name reviewers, grant override authority, and give them the system context the statute requires.
- Renegotiate vendor contracts. Secure developer documentation and update-notification commitments, and strip out now-void indemnification clauses.
- Set three-year retention. Establish retention for documentation, version history, and decision records across both tracks.
Inventory is where most programs stall, because AI systems hide in procurement, in shadow IT, and inside other vendors’ products. This is where a purpose-built registry earns its place: Govern365.ai’s AI model registry maps each system to its role under SB 26-189 and to the matching ISO 42001 controls and EU AI Act articles, so a single inventory feeds every regime you report against instead of one spreadsheet per jurisdiction.
Frequently asked questions
Is the Colorado AI Act still in effect?
Not in its original form. SB 24-205, the high-risk AI framework, was repealed and replaced by SB 26-189 in May 2026 and never took effect. The replacement law, governing automated decision-making technology, takes effect January 1, 2027. Any guidance describing impact assessments or a duty of care under Colorado law is now out of date.
Does SB 26-189 still use the term high-risk AI system?
No. The replacement law removed the high-risk AI classification entirely. It regulates covered automated decision-making technology, defined as technology that processes personal data and uses computation to generate output that materially influences a consequential decision.
Who has to comply with the Colorado ADMT law?
Developers that build, sell, license, or substantially modify covered ADMT, and deployers that use it in Colorado for consequential decisions in areas like employment, lending, housing, insurance, health care, education, and government services. Many organizations are both and carry both sets of duties.
Is there a private right of action?
No. The Colorado Attorney General has exclusive enforcement authority, and violations are treated as deceptive trade practices under the Colorado Consumer Protection Act. Before January 1, 2030, the AG must offer a 60-day cure period for violations that can be cured, except knowing or repeated ones.
Does ISO 42001 or NIST AI RMF still provide an affirmative defense?
No. The affirmative defense for compliance with a recognized AI risk framework was repealed along with the old law. Aligning to ISO 42001, NIST AI RMF, or the EU AI Act is still the most efficient way to build the documentation, oversight, and recordkeeping the new law requires, and those controls reuse across other jurisdictions.
What counts as meaningful human review?
A trained person with authority to approve, modify, or override the decision, who considers the relevant evidence rather than defaulting to the system’s output and has enough information to understand its intended use, limitations, and main factors. The law does not require disclosing proprietary source code or model details.
How does the Colorado ADMT law compare to the EU AI Act?
Both regulate automated decisions in high-stakes areas, but the EU AI Act keeps a tiered high-risk regime while Colorado dropped its version. As Gibson Dunn notes, the EU’s high-risk obligations for standalone Annex III systems were provisionally deferred to December 2, 2027 under the Digital Omnibus, pending formal adoption. The two share enough DNA that one well-built control set can serve both.
The takeaway
Colorado just demonstrated the central risk of state-by-state AI regulation: the rules can be rewritten before they ever bite. The smart response is not to chase each version but to build controls that map to the durable frameworks underneath, ISO 42001, the EU AI Act, and NIST AI RMF, so a Colorado checklist doubles as an EU one. Start with the single highest-value step today: inventory every automated system that could materially influence a consequential decision, and tag each one to its role under SB 26-189.
Govern365.ai turns that inventory into a living compliance map across every framework you answer to. Start your 14-day free trial and see your AI systems mapped to Colorado, ISO 42001, and the EU AI Act in one view.
