The Colorado AI Act, Repealed and Rewritten: What Deployers Owe Now
Senate Bill 26-189, Automated Decision-Making Technology, codified at Colorado Revised Statutes title 6, article 1, part 17, which repealed and reenacted Senate Bill 24-205, the Colorado Artificial Intelligence Act
Last updated
Need it signed off?
Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.
Book an evaluation callRegulator
Colorado Attorney General, Colorado Department of Law
Who it applies to
- Deployers: any person doing business in Colorado that deploys a covered ADMT, meaning automated decision-making technology used to materially influence a consequential decision
- Developers: any person doing business in Colorado that builds, sells, licences or substantially modifies a covered ADMT, including a vendor that supplies a component intended to be used inside one
- HIPAA covered entities and their business associates: exempt from sections 6-1-1701 through 6-1-1706 except for consequential decisions relating to employment, but still required to give patients a general notice of the use of advanced technologies and to make specific disclosures where a covered ADMT decides eligibility for financial assistance
- Covered entities that are health care providers under 45 CFR 160.103: the health care exemption applies only where the provider is operating from a location within Colorado
- Not applicable to a medical device under FDA oversight, or to a pharmaceutical or medical device manufacturer's FDA supervised research and development, including clinical investigations under 21 CFR 312
- Insurers subject to Colorado's existing algorithmic discrimination rules in section 10-3-1104.9 are treated as compliant, except for uses relating to insurer employment
Penalties
A violation of part 17 is a deceptive trade practice under the Colorado Consumer Protection Act, enforceable exclusively by the Attorney General. Before acting, the Attorney General must issue a notice of violation and allow sixty days to cure where a cure is deemed possible, unless the violation was knowing or repeated. That cure right is repealed on January 1, 2030. Civil penalty amounts come from the Consumer Protection Act itself rather than from part 17, so check the current figures published by the Colorado Department of Law rather than a secondary summary. There is no new private right of action, and compliance with part 17 is not a defence to a claim under the Colorado Anti-Discrimination Act or ordinary product liability law.
Deadlines
Dates that already bind, and dates still ahead.
| Date | What happens |
|---|---|
| Governor Polis signed SB 24-205, the Colorado Artificial Intelligence Act, the first broad state statute imposing a duty of reasonable care on developers and deployers of high risk AI systems. Compliance was set for February 1, 2026. | |
| SB 25B-004 was signed during a special session, moving the compliance date from February 1, 2026 to June 30, 2026 after lawmakers failed to agree on amendments. | |
| SB 26-189 was signed, repealing and reenacting the Act as an automated decision-making technology statute. The original high risk AI framework never became operative. | |
| HB 26-1195, the psychotherapy artificial intelligence restrictions, took effect for Colorado licensed psychotherapy providers. | |
| SB 26-189 takes effect and applies to consequential decisions made on or after this date. The Attorney General is directed to adopt implementing rules on or before the same date. HB 26-1139, governing AI in utilization review, also takes effect. | |
| The mandatory sixty day right to cure in section 6-1-1706 is repealed, after which the Attorney General may proceed without offering one. |
What changed in 2026
Movement by year, newest first. Where nothing in the text moved, that is recorded too.
2026
The Colorado General Assembly passed SB 26-189 on May 9, 2026 and the Governor signed it on May 14. It repeals and reenacts the Colorado AI Act. Gone are the duty of reasonable care to avoid algorithmic discrimination, the mandatory risk management program, and the annual impact assessments that dominated every 2025 readiness plan. In their place sit disclosure duties, two consumer rights, three year record keeping, and exclusive enforcement by the Attorney General.
The vocabulary changed with the substance. The statute no longer regulates a high risk artificial intelligence system. It regulates a covered ADMT, meaning automated decision-making technology used to materially influence a consequential decision. Health care services are one of seven covered domains.
Two health specific laws passed in the same session. HB 26-1139 was signed on June 2, 2026 and governs AI in utilization review from January 1, 2027. HB 26-1195 was signed on June 3, 2026 and restricts AI in psychotherapy from August 12, 2026. Colorado now has three separate statutes touching health care AI rather than one, which is the practical reason a single governance programme is easier to run than three project plans.
2025
The Act was scheduled to bite on February 1, 2026. It did not. The Governor called a special session in August 2025, lawmakers could not agree on substantive amendments, and SB 25B-004 was signed on August 28, 2025 to push the compliance date to June 30, 2026. Organisations that had built impact assessment programmes to the original text spent the next nine months waiting to find out whether the text would survive. It did not.
The lesson worth keeping is procedural rather than legal: a first mover state statute with a long runway is a statute with a long window in which to be rewritten. Build controls that hold up under any of the plausible texts rather than controls that map to one bill's section numbers.
2024
SB 24-205 was signed on May 17, 2024. It defined a high risk AI system as one that makes, or is a substantial factor in making, a consequential decision, and it put a duty of reasonable care on both developers and deployers. Deployers faced annual impact assessments, a risk management programme aligned to a recognised framework, consumer notice, and a right to appeal to human review. Health care services were a listed consequential decision from the start.
None of that ever became binding. If you are reading a 2024 or 2025 compliance guide to the Colorado AI Act, including a very good one, it is describing a statute that no longer exists.
What does Colorado actually require of AI deployers now?
As of August 2026 the answer is: nothing yet, and from January 1, 2027, four things. SB 26-189 takes effect on January 1, 2027 and applies to consequential decisions made on or after that date. Before then there is no operative Colorado AI statute of general application, because the 2024 Act was repealed before its compliance date ever arrived.
From January 2027 a deployer of a covered ADMT owes a consumer four duties. Give clear and conspicuous notice before the technology is used to materially influence a consequential decision. Within thirty days of an adverse outcome, provide a plain language description of the decision and the technology's role in it. On request after an adverse outcome, provide a route to correct factually inaccurate personal data and an opportunity for meaningful human review and reconsideration, to the extent commercially reasonable. Keep records for at least three years after the decision.
That is a materially lighter regime than the one Colorado wrote in 2024. It is not nothing, and the notice and thirty day clock are operational commitments that have to be built into a workflow rather than written into a policy. We treat that build as part of AI governance and compliance work rather than a legal review deliverable.
What happened to the original Colorado AI Act?
It was delayed twice and then repealed. SB 24-205 was signed in May 2024 with a February 1, 2026 compliance date. It was the first US state statute to impose an EU style duty of care on AI deployers, and it drew immediate objections from Colorado's technology sector and from the Governor himself, who signed it while publicly asking the legislature to revisit it.
A special session in August 2025 failed to produce a compromise and instead produced SB 25B-004, which moved compliance to June 30, 2026. In the 2026 regular session the General Assembly passed SB 26-189, which repealed and reenacted the whole framework. The Governor signed it on May 14, 2026.
The practical consequence for anyone who did the work early: the impact assessment templates and the algorithmic discrimination testing programme are no longer required by Colorado. They are still useful. Colorado's own new statute preserves a fault allocation between developer and deployer, and the Texas statute gives an express safe harbour for substantial compliance with the NIST AI Risk Management Framework. Documentation you built for Colorado is not wasted, it has simply changed jurisdiction.
Which agent decisions count as consequential?
A consequential decision is one that relates to a consumer's access to, eligibility for, selection for or compensation for a covered domain, or that produces differentiated pricing or terms likely to materially limit, delay or effectively deny that access. Health care services are one of the seven covered domains, alongside education, employment, residential real estate, financial and lending services, insurance, and essential government services.
The statute then carves out a great deal of what an operational AI agent actually does. Excluded from consequential decisions are routine scheduling, administrative routing, customer service triage, communication of decisions, and workflow management. Also excluded are cases where the technology summarises, organises or presents information for human review without producing a score, ranking, recommendation, classification or prediction that materially influences an outcome.
So the line falls roughly here:
- A scheduling agent that books appointments is outside the definition, because routine scheduling is expressly excluded.
- An ambient scribe that drafts a note for clinician review is outside it, provided it does not generate a score or classification that drives a decision.
- A triage agent that ranks or classifies patients in a way that changes who gets seen and when is inside it, because a ranking that materially alters access to a health care service is not customer service triage.
- An agent that recommends a coverage or financial assistance outcome is squarely inside it.
Materially influence is defined as an output that is a non de minimis factor and that affects the outcome, including by constraining, ranking, scoring, recommending or classifying. Incidental, trivial or clerical uses do not count. The Attorney General is authorised to write rules with presumptions and illustrative examples for exactly this definition, which is a strong signal that the boundary will move once rules land.
Does the HIPAA exemption cover a health system?
Mostly, and not entirely. Section 6-1-1708(3)(a) says sections 6-1-1701 through 6-1-1706 do not apply to a HIPAA covered entity, or to a covered entity's business associates for services rendered to that covered entity, to the extent the covered entity is doing business in Colorado, except for a consequential decision related to employment or an employment opportunity.
Three qualifications matter more than the headline.
- Employment is carved back in. If you use AI to screen nursing applicants, allocate shifts or inform termination decisions, the full deployer regime applies to you. Hospitals are large employers, and this is the single likeliest place for a Colorado enforcement question to reach a health system.
- You still owe a patient notice. Subsection (3)(c) requires a covered entity to give patients a general notice of its use of advanced technologies, including a covered ADMT. It may be folded into the existing notice describing patient rights and how you provide care, which is the sensible place for it.
- Financial assistance is carved back in. If a covered ADMT determines a patient's eligibility for financial assistance, including discounted care under section 25.5-3-502, you owe a plain language description of the decision and the technology's role, the types of information relied on, how to request correction of materially inaccurate data, and how to request meaningful human review. You may give that either as an advance general disclosure or within thirty calendar days after an adverse outcome.
There is also a drafting point worth flagging to counsel. Subsection (3)(b) says that for a covered entity that is a health care provider under 45 CFR 160.103, subsection (3) applies only if the provider is operating from a location within Colorado. Read literally, an out of state telehealth group treating Colorado residents does not get the benefit of the health care exemption at all. Whether that reading survives Attorney General rulemaking is not settled as of August 2026. If you run a telehealth service into Colorado from elsewhere, do not assume you are exempt.
Two further exemptions are clean. Medical devices under FDA oversight, and FDA supervised research and development including clinical investigations under 21 CFR 312, are outside sections 6-1-1701 through 6-1-1706 entirely. And nothing in part 17 requires a covered entity to disclose protected health information in a way that would violate federal law: where the state disclosure duties conflict with HIPAA, federal law governs and you disclose consistent with it.
What does a deployer actually have to build?
Four artefacts, and none of them is a policy document.
- A point of interaction notice. Clear and conspicuous, given before the covered ADMT is used, telling the consumer it was or will be used and how to get more information. The statute lets you satisfy this with a prominent public notice reasonably proximate to the interaction, so a well placed page linked from the workflow can work.
- An adverse outcome disclosure that fires within thirty days. Plain language description of the decision and the technology's role, a simple process to request more information including the system name, version number and developer and the categories and sources of personal data used, and an explanation of the consumer's rights. Note that you can only pass on the system details you actually received from the developer, which makes the developer documentation duty a procurement requirement rather than a courtesy.
- A correction and human review path. Meaningful human review is defined: a designated individual with authority to approve, modify or override the decision, who considers relevant primary evidence, is trained to conduct the review, does not default to the system output, and has enough information to understand the output's intended use. A rubber stamp does not qualify, and the definition is written so that a reviewer who always agrees with the model is evidence against you.
- Three years of records. Version identifiers, changelogs, documentation of material mitigation changes, kept for at least three years after the decision or longer if other law requires.
One contractual point deserves attention at procurement. Section 6-1-1707 allocates fault between developer and deployer and rejects joint and several liability, and the statute voids attempts to indemnify a party for its own discriminatory acts. Vendor paper written before May 2026 will not reflect any of this. That is a live reason to reopen a contract rather than a theoretical one, and it is the same conversation we run during a vendor selection engagement.
What do HB 26-1139 and HB 26-1195 add?
Colorado's health specific AI laws are narrower in scope and, for some organisations, harder to comply with than the general statute.
HB 26-1139, Use of Artificial Intelligence in Health Care, was signed on June 2, 2026 and takes effect January 1, 2027. It reaches entities conducting utilization review, including carriers, pharmacy benefit managers and managed care entities. Where AI is used to determine coverage, the determination must rest on the patient's own medical and clinical history and individual circumstances rather than solely on a group dataset. A denial or delay based on medical necessity must be reviewed by a licensed clinician competent in the relevant clinical area. Entities must disclose to the applicable state regulator which utilization review functions use AI, how human oversight works, and how the system is audited. It also bars payment for psychotherapy delivered directly by an AI system under Medicaid and the Children's Basic Health Plan.
If that reads familiar, it is because California reached the same place two years earlier through SB 1120. A provider organisation running prior authorization automation or denial management sits on the receiving end of these rules rather than under them, but the payer side changes are the reason your denial patterns will move in 2027.
HB 26-1195, Psychotherapy Artificial Intelligence Restrictions, was signed on June 3, 2026 and took effect on August 12, 2026. It applies to Colorado licensed psychotherapy providers. AI may not conduct therapeutic communication unless the licensed professional is present and actively engaged in real time. AI generated treatment recommendations must be reviewed and approved by the provider before use. Clients must be told at initial contact how AI is used, and written consent is required before a session is recorded or transcribed. Administrative support, accredited training and IRB supervised research are permitted uses.
For a behavioural health practice, HB 26-1195 is the binding constraint today, not SB 26-189. It is already in force, it applies directly to licensees, and it makes consent to recording a documented precondition rather than a courtesy. Note that it interacts with 42 CFR Part 2 as well, which we cover under HIPAA and AI.
How does Colorado compare with the other state AI laws?
Four states now have AI statutes that a US healthcare operator has to read. They are not variations on a theme. They regulate different things, at different times, with different triggers.
| State | Instrument | In force | Core duty for a provider | Enforcer |
|---|---|---|---|---|
| Colorado | SB 26-189 (ADMT), HB 26-1139, HB 26-1195 | Aug 12, 2026 (psychotherapy); Jan 1, 2027 (ADMT and utilization review) | Patient notice of advanced technologies; financial assistance disclosures; full deployer regime for employment decisions | Attorney General |
| California | AB 3030, SB 1120, AB 489, CMIA and CCPA | Jan 1, 2025 onward | Disclaimers on generative AI patient communications unless a licensed provider reviewed them | Licensing boards, DMHC, CDI, Attorney General, CPPA |
| Utah | Title 13 chapters 72, 72a and 75 | May 1, 2024 and May 7, 2025 | Proactive disclosure by licensed clinicians in high risk generative AI interactions | Division of Consumer Protection |
| Texas | TRAIGA (HB 149), SB 1188 | Sep 1, 2025 and Jan 1, 2026 | Disclose AI use to the patient no later than the date treatment is first provided | Attorney General, licensing agencies |
Read across the row and one design falls out. Every state wants the patient told. Only Colorado and California put a structured appeal or human review behind an adverse decision. Only Texas offers an express framework based safe harbour. A single notice and a single human review path, built once and applied everywhere, satisfies all four with room to spare. Four separate state projects do not. The full comparison sits on the California, Utah and Texas pages.
What does enforcement look like in practice?
Narrow and slow, by design. The Attorney General enforces part 17 exclusively through the Colorado Consumer Protection Act, and violations of the disclosure and consumer rights provisions are enforceable by nobody else, notwithstanding anything else in title 6. There is no new private right of action.
Before bringing an action the Attorney General must issue a notice of violation and allow sixty days to cure, where a cure is deemed possible. Knowing or repeated violations do not get that protection. Even in litigation, a cure within sixty days of written notice is a mitigating factor on penalties. From January 2028 the Attorney General must report annually on actions filed, cure periods offered and cure periods missed, which will be the first public read on how the statute is actually being used. The whole cure mechanism repeals on January 1, 2030.
The realistic exposure profile for a health system is therefore not a surprise penalty. It is an employment screening tool that nobody classified as a covered ADMT, discovered during an unrelated complaint, with a sixty day clock and no documentation to show. Which is an argument for an inventory rather than an argument for a lawyer.
If you deploy agents in Colorado, do these things
Six items, in the order they pay off. None of them requires waiting for the Attorney General's rules.
- Inventory every agent against the covered domain list. Tag each one as outside scope (routine scheduling, administrative routing, summarisation for human review), inside scope, or genuinely uncertain. The uncertain pile is the one that matters, and it is usually smaller than people fear.
- Separate the employment uses. The HIPAA exemption does not cover them. Any AI touching recruitment, shift allocation, promotion or discipline gets the full deployer regime from January 1, 2027. Route it through HR governance, not clinical governance.
- Add the advanced technologies notice to your patient rights material. The statute expressly allows this. Doing it now costs one paragraph and closes the one duty that survives the exemption for everybody.
- Find the financial assistance decisions. If any automated system scores, ranks or recommends on charity care or discounted care eligibility, it triggers a named disclosure set with a thirty day clock. This is the single most commonly missed obligation in the statute for hospital finance teams.
- Fix the vendor paper. You cannot disclose a system's version, developer or training data categories unless the developer gives them to you. Put the developer documentation duty and the material update notification into the contract, and check the indemnity clauses against section 6-1-1707.
- If you are a psychotherapy licensee, act now. HB 26-1195 is already in force. Written consent before recording, provider review of AI generated recommendations, and disclosure at initial contact are live obligations today, not 2027 obligations.
Most organisations discover at step one that they have between three and eight agents in production and no single owner for any of them. That is the problem worth solving first, because every duty in this statute presumes somebody can answer which system made which decision on which date. If you want that inventory built and the notice, disclosure and human review paths designed once for all four states rather than four times, that is what our AI governance and compliance engagement produces, usually alongside an AI readiness audit for organisations that are still at the shortlist stage.
Official sources
Primary documents from the issuing authority. Where a summary and the source disagree, the source is right.
- StateSB26-189 Automated Decision-Making Technology, Colorado General Assembly (opens in a new tab)
- StateSB24-205 Consumer Protections for Artificial Intelligence, Colorado General Assembly (opens in a new tab)
- StateSB25B-004 Increase Transparency for Algorithmic Systems, Colorado General Assembly (opens in a new tab)
- StateHB26-1139 Use of Artificial Intelligence in Health Care, Colorado General Assembly (opens in a new tab)
- StateHB26-1195 Psychotherapy Artificial Intelligence Restrictions, Colorado General Assembly (opens in a new tab)
- StateColorado Attorney General, Colorado Department of Law (opens in a new tab)
- NISTAI Risk Management Framework, NIST (opens in a new tab)
Questions we get asked
Is the Colorado AI Act still in effect in 2026?
No. SB 24-205 was repealed and reenacted by SB 26-189, signed on May 14, 2026, and its original obligations never became operative. The replacement statute takes effect on January 1, 2027 and applies to consequential decisions made on or after that date. Any compliance guide describing impact assessments and a duty of reasonable care is describing the repealed version.
Does the Colorado AI law apply to hospitals and medical practices?
Partly. HIPAA covered entities and their business associates are exempt from the main deployer and developer sections, except for consequential decisions relating to employment. They still owe patients a general notice about the use of advanced technologies, and specific disclosures where an automated system determines eligibility for financial assistance or discounted care.
Does an AI scribe or scheduling agent trigger the Colorado statute?
Generally no. Routine scheduling, administrative routing, customer service triage and workflow management are excluded from the definition of a consequential decision, as is a system that summarises or organises information for human review without producing a score, ranking or classification that materially influences an outcome. A triage agent that ranks patients in a way that changes access to care is a different question.
What is a covered ADMT under SB 26-189?
Automated decision-making technology used to materially influence a consequential decision. Materially influence means the output is a non de minimis factor that affects the outcome, including by constraining, ranking, scoring, recommending or classifying. Incidental, trivial and clerical uses are excluded, and the Attorney General may adopt rules with presumptions and worked examples for this definition.
What are the penalties under the Colorado AI law?
A violation is a deceptive trade practice under the Colorado Consumer Protection Act, enforced exclusively by the Attorney General. A sixty day right to cure applies unless the violation was knowing or repeated, and that right is repealed on January 1, 2030. Penalty amounts come from the Consumer Protection Act rather than the AI statute, so check the current figures with the Colorado Department of Law. There is no private right of action.
Do out of state telehealth providers have to comply?
Possibly, and this is unsettled. The health care exemption for a covered entity that is a health care provider applies only where the provider operates from a location within Colorado. Read literally, an out of state group treating Colorado residents falls outside the exemption and inside the general deployer regime. Treat this as an open question until the Attorney General's rules address it.
What should we do before January 2027?
Build an inventory of every agent mapped to the covered domains, pull employment uses out into a separate track because they lose the HIPAA exemption, add the advanced technologies notice to your patient rights material, and identify any automated involvement in financial assistance decisions. Then fix the vendor contracts so you can actually obtain the system details the adverse outcome disclosure requires.
Make it a formal evaluation
Everything we publish is free to read and free to argue with. When the decision has to be signed, dated and defended to a board, we run the evaluation against your own estate. We take no vendor commissions.
- A 30 minute evaluation call with an analyst, no pitch deck.
- A read on the vendors and the rules in play, and the use cases we would not touch yet.
- A written proposal with scope, sequence and a fixed fee.
- No obligation
- Direct with an analyst, not a sales rep
- BAA available before any PHI discussion