Colorado ADMT: What Changed in 2026
Colorado SB26-189 was signed on 14 May 2026. It repeals and reenacts the prior SB24-205 framework with revised automated decision-making technology (ADMT) requirements, which begin on 1 January 2027. See the General Assembly record and Attorney General update.
The 2026 change is substantive, not just a postponed deadline. Do not carry forward the former framework's high-risk definitions, impact-assessment deadlines or affirmative-defence tests without reviewing the enacted replacement.
The Colorado Attorney General is conducting rulemaking for the revised law. Draft rules are not final rules. Check the current rulemaking page when preparing notices and procedures.
SB26-189 uses the concept of covered automated decision-making technology: ADMT used to materially influence a consequential decision. The enacted law addresses decisions concerning education, employment, housing, financial or lending services, insurance, health care, and essential government services and public benefits. Review the statutory definitions and exclusions for the specific use case.
A human making the final decision does not, by itself, establish that ADMT is outside scope. Record how the technology affects the decision and have qualified counsel assess the material-influence test.
Application date: The revised ADMT requirements begin on 1 January 2027. The former February or June 2026 dates and the claimed September 2026 impact-assessment deadline are not the current SB26-189 timetable.
Developer and Deployer Review
Assess whether the organisation develops covered ADMT, deploys it, or has both roles. The relevant technology, use and decision matter; using an AI API alone does not establish a statutory role or obligation.
Developer documentation: The enacted summary identifies technical information for deployers about intended uses, training-data categories, limitations and appropriate use and human review. Developers must also communicate material updates. Validate the required content against the law for the relevant system.
Deployer processes: Review the notice requirements and the rights to information, correction of inaccurate personal data, and meaningful human review and reconsideration after an adverse consequential decision. Build the relevant consumer-facing procedures before the requirements apply.
Implementation needs named owners for receiving developer information, maintaining notices, handling consumer requests and retaining the relevant records. Collecting a vendor document is only one part of that work.
Map roles separately for each system and decision. An organisation can perform more than one role, but an example business model is not enough to establish which provisions apply.
Review jurisdictional scope, exclusions and applicable sectoral law with counsel. Record the basis for the decision rather than inferring coverage solely from the organisation's headquarters.
Framework Evidence and the Former Safe Harbour
The former SB24-205 framework discussed an affirmative defence linked to risk-management frameworks. SB26-189 repeals and reenacts that regime. Treat the former safe-harbour test as historical, not as a current route to statutory protection.
Framework Evidence
NIST AI RMF and ISO/IEC 42001 can organise governance evidence. Framework adoption or certification does not establish a defence, exemption or compliance outcome under the revised Colorado law. Check each current requirement separately.
Choose governance practices for the risks and operating context. Existing records may help with implementation, but they need a fresh mapping to SB26-189. See the ISO 42001 guide and NIST AI RMF guide for framework context.
Investigation and Corrective Action
Documenting feedback, testing, investigation and corrective action remains useful governance practice. These activities are not presented here as the former statutory safe-harbour test or as proof of protection under SB26-189.
Assign an owner to investigate reported problems, record decisions and verify corrective actions. Choose a review cadence appropriate to the system. This is implementation advice, not a claim that SB26-189 imposes the former framework's discovery-and-cure conditions.
Browse available tools for available implementation resources. The previous assessment is unavailable.
ADMT Implementation Records
The table below lists implementation records to discuss when reviewing SB26-189. It is not a complete legal checklist or a statement that a NIST subcategory or ISO clause satisfies Colorado law.
| ADMT review topic | Implementation record | Boundary |
|---|---|---|
| Scope and roles | System and decision inventory | Validate statutory definitions and exclusions |
| Developer information | Documentation and material-update record | Check the required content for the relevant covered ADMT |
| Consumer notices | Notice content and point-of-interaction record | Review law and applicable final rules |
| Consumer requests | Information, correction and human-review workflow | Confirm scope, response duties and exceptions |
| Retention | Record register and retention procedure | The enacted summary specifies at least three years for compliance records |
Confirm the required files, formats and framework mappings against the current ACT package before payment. Public samples do not establish paid-package contents. AI Controls Starter unified controls matrix AI Controls Professional
Colorado AI Act vs EU AI Act
If your organization operates in both the US and EU markets, you need both. Here's how they compare.
| Dimension | Colorado ADMT | EU AI Act |
|---|---|---|
| Geographic scope | Review Colorado scope and exclusions | Review EU territorial scope and role |
| Covered activity | ADMT materially influencing consequential decisions | Risk and role assessment under the EU AI Act |
| Regulator | Colorado Attorney General | AI Office and Member State authorities |
| Framework evidence | Not a substitute for SB26-189 analysis | Not a substitute for applicable AI Act requirements |
| Application dates | 1 January 2027 | General: 2 August 2026; Annex III: 2 December 2027; Annex I product high-risk: 2 August 2028 |
Colorado ADMT requirements begin on 1 January 2027. The EU AI Act is generally applicable from 2 August 2026, with Annex III high-risk rules from 2 December 2027 and Annex I product high-risk rules from 2 August 2028. Keep each jurisdiction's scope and application date separate. See EU AI Compass for EU orientation.
Colorado's revised law focuses on covered ADMT in consequential decisions. The EU AI Act uses a separate risk and role structure. Shared governance records may be useful, but a cross-framework template is not evidence that both laws have been satisfied.
Impact Assessment in Practice
Do not use the former September 2026 impact-assessment deadline as a current SB26-189 requirement. Assess the revised law directly. A documented impact review can still help the organisation understand how a decision affects people.
For an internal impact review, consider the system purpose, affected groups, data, possible harms, testing, mitigation, oversight and responsible owner. Select review triggers based on the operating context. This is suggested governance practice, not an asserted SB26-189 assessment template or annual-report mandate.
Existing impact-assessment records may be useful inputs. Review their coverage against the revised law before reusing them, and do not assume that an ISO or NIST mapping establishes legal equivalence.
The enacted bill summary states that developers and deployers retain records needed to demonstrate compliance for at least three years. Identify the relevant records and retention procedure with counsel; do not carry forward the former annual incident-related impact-report claim.
One practical consideration for the assessment process: involve your legal counsel early. The impact assessment creates a written record of risks you've identified and mitigations you've implemented. If a consumer later alleges algorithmic discrimination, the assessment becomes both your strongest defense (we identified and mitigated this risk) and your biggest liability (we identified this risk and our mitigation was inadequate). Legal privilege considerations may affect how you structure the assessment process. Some organizations conduct the assessment under attorney-client privilege and produce a separate, compliance-ready version for regulatory purposes. Discuss this with your counsel before starting.
Illustrative 12-Week ADMT Implementation Plan
If you're starting from scratch today, here's what the next 12 weeks look like.
Weeks 1–2: Scope review. Identify relevant ADMT uses and consequential decisions. Record roles, affected people and the questions that need legal review. Use the current definitions rather than the former high-risk AI categories.
Weeks 3–5: Evidence review. Collect developer information, assess decision impacts and identify missing implementation records. These are suggested planning activities, not a statutory assessment timetable.
Weeks 6–8: Consumer-facing procedures. Review notices, information and correction requests, and human review and reconsideration after adverse consequential decisions. Validate the procedures against the enacted law and applicable final rules.
Weeks 9–10: Control implementation. Assign owners and test the procedures. Reuse suitable NIST or ISO governance records where helpful, without claiming safe-harbour eligibility or certification as a legal outcome.
Weeks 11–12: Evidence assembly. Check that notices, request-handling records, developer information and retention arrangements can be retrieved and reviewed. Document unresolved issues and have counsel confirm readiness against the applicable requirements.
Test a representative consumer request from receipt through review, response and record retention. Record failures and owners for correction. The twelve-week plan is an illustrative implementation sequence, not a legal deadline or a guarantee of readiness.
Review product mappings against SB26-189 before relying on them. Before buying ACT-1 or ACT-2 for Colorado work, ask Move78 to confirm the delivered edition, included artifacts and current-law mapping scope. A product comparison is not verification that every current obligation is covered.
Compare AI Controls Starter and AI Controls Professional →