9 minutes read

What Colorado’s Revised AI Law Means for Businesses

What Colorado's Revised AI Law Means for Businesses - icon

Table of Contents

Introduction

Colorado’s original Colorado AI Act (SB 24-205) was signed on May 17, 2024, establishing one of the most comprehensive state-level AI regulation frameworks in the country. After facing constitutional challenges, including the xAI LLC v. Weiser lawsuit and a delayed effective date, the Colorado legislature passed SB 26-189 on May 14, 2026, which repealed and replaced the original framework.

The revised Colorado AI framework no longer uses the term “high-risk AI systems.” Instead, it regulates automated decision-making technology: any system that processes personal data and uses computation to generate predictions, classifications, scores, or recommendations that materially influence consequential decisions about individuals.

Enforcement of both the original Colorado AI Act and SB 26-189 is currently stayed by a federal court injunction pending constitutional challenges, so practical enforcement is unlikely before late 2027. The statute itself is framed as consumer protection for automated decision systems, not an algorithm-design mandate. Compared to the EU AI Act, which imposes design-time requirements and conformity assessments for high-risk AI systems, Colorado’s approach focuses squarely on transparency and consumer protections rather than dictating how AI systems must be built.

Update Timeline: Key Dates, Bills, and Litigation

Colorado’s AI landscape between 2024 and 2027 has been unusually dynamic, with multiple bills, delays, and lawsuits directly affecting when and how businesses must comply.

  • May 17, 2024: Governor Polis signs SB 24-205 (the original Colorado AI Act), with an initial effective date of February 1, 2026.
  • August 2025: SB 25B-004 delays the effective date to June 30, 2026.
  • April 27, 2026: A federal court grants an injunction staying enforcement of SB 24-205, extended to any replacing or amending legislation, while constitutional challenges proceed.
  • May 14, 2026: SB 26-189 is signed into law, repealing SB 24-205 and establishing the new ADMT framework with a statutory effective date of January 1, 2027.
  • Juneโ€“August 2026: The Colorado attorney general opens pre-rulemaking comment periods and files proposed rules (4 CCR 904-6).

Beyond SB 26-189, Colorado signed companion AI bills in 2026: HB 1263 (chatbot and minor protections, effective January 1, 2027), HB 1139 (AI in health insurance decisions, effective January 1, 2027), and HB 1195 (AI for mental health professionals, effective August 12, 2026). These staggered dates mean businesses in regulated sectors face overlapping compliance windows.

What Changed: Comparing the Original Colorado AI Act and SB 26-189

The shift from SB 24-205 to SB 26-189 represents a move from broad AI governance mandates to targeted transparency and consumer notice. Companies have a lighter compliance burden under the revised AI law than under the original act, but the remaining obligations are still enforceable and carry real penalties.

  • The original Colorado AI Act focused on high-risk AI systems and required formal risk management programs aligned with frameworks such as the NIST AI RMF. It mandated a risk management policy, annual impact assessments, and a statutory duty to prevent algorithmic discrimination in consequential decisions.
  • SB 26-189 removes these internal governance mandates. There are no mandatory impact assessments, no prescribed AI risk management framework, and the law eliminates extensive algorithmic discrimination duties from the original act. The revised law removes algorithmic discrimination obligations as a standalone compliance requirement, though existing law under anti-discrimination statutes still applies.
  • What SB 26-189 keeps or adds: The revised law mandates consumer notice before using automated decision-making technology in consequential decisions, requires detailed adverse-action notices, grants consumers the right to request meaningful human review, and imposes a three-year record retention requirement for both developers and deployers.
  • The revised law also broadens terminology to “automated decision-making technology,” which covers a wider range of automated tools than traditional AI systems while still focusing only on those that materially influence consequential decisions.

Key Concepts: ADMT, Consequential Decisions, and Material Influence

Three cornerstone terms define when Colorado’s revised AI law applies to a business. Getting these right determines whether you have obligations.

  • Automated decision-making technology (ADMT): Any system-including machine learning, statistical models, or rule-based analytics-that processes personal data to generate scores, classifications, predictions, or recommendations used to assist or guide decisions about individuals.
  • Consequential decision: This refers to a decision that impacts access to, eligibility for, selection for, or compensation within areas such as employment, housing, education, financial and lending services, insurance, health care, and essential government services. The revised law specifically governs automated decision-making technology that affects these consequential decisions.
  • The new law specifically regulates automated decision-making technology that influences these consequential decisions.
  • Material influence: The ADMT output must meaningfully shape the outcome, not merely serve as a trivial input. Even if a human has the final say, a system that functions as a substantial factor in the decision (like AI-scored resumes in hiring shortlists) counts.

Concrete examples: a bank using an AI credit model to approve or deny loan applications, a health insurer using a risk score to set premiums, a property manager using automated tenant screening to rank applicants, or a large online retailer using an algorithm to decide store-credit limits. Each of these involves a consequential decision where ADMT can materially influence eligibility or terms.

meeting

Who Must Comply: Developers vs. Deployers and Jurisdiction

SB 26-189 uses a shared-responsibility model. Developers (who build ADMT) and deployers (who use it in decision flows) each have distinct duties, and being located outside Colorado does not automatically exempt a business.

  • A developer is any business that creates, trains, or substantially modifies covered ADMT and offers it for use, including SaaS providers and AI developers serving Colorado customers. If a deployer substantially modifies a tool, that deployer may also become a developer.
  • A deployer is any organization, employer, lender, insurer, healthcare provider, school, government entity, or online business that uses ADMT to make or materially influence a consequential decision about individuals in Colorado.
  • Coverage is based on the impact on Colorado consumers, residents, or job applicants, not on where the company or data center is located. A non-Colorado Shopify merchant making automated lending or hiring decisions involving Colorado residents can still be a deployer.
  • Contractual liability between developers and deployers is now based on a fault-based model, meaning each party is responsible for obligations within its own role. Ordinary back-office tools like spam filters, basic analytics, and many cybersecurity or fraud tools are generally outside scope unless their output directly drives covered consequential decisions.
Make Your Shopify Store GDPR & Cookie Compliant in Minutes
Automatically manage cookie consent, block tracking before user approval, and stay compliant with GDPR, CCPA, LGPD, UK GDPR and Google Consent Mode v2 โ€” without coding.

Core Duties Under Colorado’s Revised AI Law

This section distills what businesses must do under SB 26-189. Obligations fall into three categories: notices and transparency, human review, and record-keeping.

  • Pre-use notice: Deployers must provide consumer notice before using automated decision-making technology. This means clear, prominent public notice at the point of consumer interaction explaining that an automated system is being used and, in broad terms, how it works, before the ADMT materially influences a consequential decision.
  • Adverse-action notice: When ADMT materially influences a negative outcome (credit denial, job rejection, insurance rate increase), deployers must disclose the adverse outcome within 30 days. Consumers are entitled to explanations of adverse outcomes from automated decisions, including what personal data was used and how the ADMT contributed to the adverse consequential decision. Consumers are also entitled to clear, plain-language notices about automated decision-making.
  • Human review: After an adverse decision, consumers can request meaningful human review. A trained human must be able to review the AI-assisted decision, correct materially inaccurate personal data, and override the ADMT output where appropriate, to the extent commercially reasonable. Consumers can also request access to personal data used in decisions and have the right to correct inaccurate personal data.
  • Record retention: A three-year record retention requirement is mandated for automated decision-making technology. Developers must retain records for three years, including versions of deployed ADMT and documentation provided to deployers. Deployers must retain records for three years post-decision, covering logs of when and how ADMT was used in consequential decisions and records of corrections taken in response to a consumer request.
  • Developer duties: Developers must provide documentation on intended uses and contracted uses to deployers, including training data categories, known limitations, and instructions for appropriate use. Developers must notify deployers of material updates that change the risk profile or intended use.

Sector-Specific Rules: Health, Insurance, Mental Health, and Youth Chatbots

Beyond SB 26-189, Colorado adopted three narrower AI laws that add extra requirements in specific industries and stack on top of the general ADMT duties.

  • HB 1263 (chatbot safety): Signed May 29, 2026, effective January 1, 2027. Requires certain AI chatbots to estimate user age, disclose that they are AI, and restrict explicit content for minors. This affects consumer-facing AI tools and youth-oriented platforms that must label AI-generated content.
  • HB 1139 (AI in health insurance): Signed June 2, 2026, effective January 1, 2027. Prohibits purely automated coverage decisions under health care policies and requires human review and clear communication of AI involvement in benefit determinations.
  • HB 1195 (AI in mental health services): Signed June 3, 2026, effective August 12, 2026. Limits the use of AI chatbots in therapeutic contexts, requires explicit patient consent, and sets standards for professional oversight of AI systems used in mental health care.
  • Businesses in these sectors must treat SB 26-189 as a baseline and then layer on domain-specific obligations, adjusting consent flows, disclosures, and professional supervision accordingly.
A Google-Approved Consent Platform for Shopify
Pandectes is an official Google Certified Consent Management Platform and is fully compatible with Google Consent Mode v2 and global privacy regulations.

What This Means for Ecommerce and Shopify Businesses

Most Shopify stores using AI tools for personalization, product recommendations, and marketing are not directly regulated under Colorado’s definition of consequential decisions. But there are important edge cases that deserve attention.

  • AI-driven decisions about who sees which product, or dynamic pricing experiments that do not affect formal eligibility or access to essential services, usually fall outside the law’s scope.
  • ADMT used for store-branded credit offers, buy-now-pay-later eligibility, high-value loyalty tiers that function like credit, or employment decisions for warehouse or customer-support staff in Colorado can be covered and should be treated as consequential decisions.
  • Shopify merchants should inventory AI tools embedded in hiring apps, lending or financing plugins, insurance-like warranties, and customer-support chatbots, and identify whether any of them materially influence a consequential decision for Colorado shoppers or staff.
  • Even where Colorado’s AI Act does not apply, merchants still must comply with privacy and consent rules (GDPR, CCPA, LGPD) for tracking and profiling. A consent management platform like Pandectes can centralize cookie banners, consent tracking, and Google Consent Mode while businesses prepare for emerging AI transparency standards.

Practical Compliance Roadmap for Businesses

Here is a step-by-step checklist that any company, from a regional bank to an online retailer, can follow over the next 12โ€“18 months to prepare for Colorado’s AI Act and related AI governance trends.

  • Inventory your AI and ADMT: Map all AI systems and automated tools that use personal data, and flag any that influence employment decisions, credit, housing, insurance, health care, education, or essential government services for Colorado residents.
  • Classify roles: Determine whether you are a developer, deployer, or both for each system. Document vendors and collect existing technical documentation from AI providers as required under SB 26-189.
  • Draft consumer notices: Write or update notices that explain AI use in plain language. Align adverse-action letters with both the CO AI Act and existing fair credit and employment laws. Design simple workflows for meaningful human review and data correction.
  • Update vendor contracts: Include clauses on documentation delivery, cooperation with attorney general investigations, record retention expectations, and notification of material model updates that change foreseeable risks or risk profiles.
  • Integrate AI compliance into existing privacy programs: Connect consent management and opt-out workflows with ADMT records so that cookie banners, consent logs, and AI documentation can be correlated during audits. Businesses already managing CCPA 2026 updates have a head start.
worker scanning

The Role of the Colorado Attorney General and Enforcement Risk

The Colorado Attorney General is at the center of AI enforcement in the state, holding exclusive enforcement authority under both the original Colorado AI Act and SB 26-189. No private right of action is provided under the law.

  • Violations of the revised AI Act are treated as deceptive trade practices under the Colorado Consumer Protection Act, with potential civil penalties up to $20,000 per violation. The attorney general agreed to prioritize rulemaking before launching enforcement actions.
  • The attorney general must complete formal rulemaking to define operational details, such as what must appear in adverse-action notices and how to measure “commercially reasonable” human review. AG Phil Weiser has indicated enforcement will not begin until these rules are finalized, and an AI litigation task force may assist in monitoring compliance.
  • A 60-day opportunity to cure violations is required before enforcement for most non-knowing or first-time violations before January 1, 2030. This cure period gives prepared organizations a chance to remediate issues before penalties are imposed.
  • While private lawsuits under the AI Act itself are not allowed, AI-related practices can still trigger claims under federal law (employment discrimination, credit discrimination) or state privacy violations. Neither President Trump nor the federal government has preempted state AI laws at this point, so disciplined documentation and defensible processes remain critical. Nothing in this article should constitute legal advice or be treated as attorney advertising; businesses should consult qualified counsel for specific questions.

Conclusion

Colorado’s revised AI law, embodied in SB 26-189, marks a significant shift toward transparency and consumer protection while easing the compliance burden on businesses compared to the original act. By focusing on automated decision-making technology that materially influences consequential decisions, the law sets clear responsibilities for developers and deployers, emphasizing notice, human oversight, and record-keeping. With enforcement pending rulemaking and set to take effect January 1, 2027, businesses operating in Colorado should proactively prepare to align with these requirements to protect consumers and ensure compliance in this evolving regulatory landscape.

Make Your Shopify Store Fully GDPR & CCPA Compliant Today
Pandectes GDPR Compliance App for Shopify
Share
Subscribe to learn more
pandectes