AI Compliance

    Colorado AI Compliance Guide: SB 26-189 (ADMT Act)

    Colorado's original AI Act (SB24-205) was repealed and replaced by SB 26-189 before it ever took effect. The new Automated Decision-Making Technology Act is effective January 1, 2027 — and the obligations it creates are different from what most compliance teams are expecting.

    Published by InsidePartners · Updated July 2026

    1. What Changed — and Why It Matters

    Colorado's original AI law, SB24-205 (the Colorado Artificial Intelligence Act, or CAIA), was signed in May 2024 and was set to take effect June 30, 2026. It was built around preventing algorithmic discrimination — requiring impact assessments, a risk-management program, and a duty of reasonable care, with an affirmative defense available to companies that complied.

    That law never took effect. Enforcement was stayed in federal court in April 2026. On May 14, 2026, Governor Polis signed SB26-189, which repealed and replaced SB24-205 entirely. The new law is formally titled the Automated Decision-Making Technology (ADMT) Act and carries an effective date of January 1, 2027.

    The structural shift is significant. SB24-205 asked: "Can you prove your AI system doesn't produce a discriminatory result?" SB 26-189 asks a different set of questions: "Did you tell the person an automated tool was being used? Did you notify them when it produced an adverse outcome? Can they get a human to review it?" The obligation moved from risk-management documentation to transparency and consumer rights.

    Key Facts at a Glance

    • Signed: May 14, 2026 (Chapter 131)
    • Effective: January 1, 2027
    • Replaces: SB24-205 (CAIA), which never took effect
    • Enforcer: Colorado Attorney General only — no private right of action
    • Cure period: 60 days (applicable before January 1, 2030)
    • Terminology shift: "high-risk AI system" → "automated decision-making technology (ADMT)"

    2. What Is "Automated Decision-Making Technology"?

    SB 26-189 defines automated decision-making technology (ADMT) as any system that processes personal data using computation, including machine learning, statistics, or other data-processing techniques, to make or substantially assist in making a consequential decision. The definition is intentionally broad — it covers scoring tools, recommendation engines, and any AI that meaningfully shapes an outcome affecting a consumer.

    The law retains the developer/deployer split from SB24-205. Developers build or substantially modify ADMT; deployers use it in consequential decisions. Most mid-market companies are deployers — they use ADMT built by vendors (Salesforce, HubSpot, screening software providers, and others) to make decisions about their customers, tenants, applicants, or employees.

    3. What Are "Consequential Decisions"?

    The law applies when ADMT is used to make or substantially assist in making a consequential decision — one that significantly affects a Colorado consumer's access to, or the cost or terms of, any of the following:

    Employment

    Hiring, firing, promotions, compensation, performance evaluations

    Housing

    Rental applications, lease terms, mortgage approvals, property management decisions

    Education

    Admissions, scholarships, disciplinary actions, accommodations

    Healthcare

    Treatment recommendations, diagnostic support, care prioritization, insurance coverage

    Financial Services

    Loan approvals, credit decisions, interest rates, fraud detection

    Insurance

    Coverage decisions, premium pricing, claims processing, risk assessments

    Government Services

    Benefits eligibility, licensing, permit approvals, public assistance programs

    Legal Services

    Case assessments, document review, risk analysis, client intake decisions

    If your business uses automated tools to make or substantially assist in any of these decisions affecting Colorado consumers, SB 26-189 applies to you.

    4. The Three Core Obligations

    SB 26-189 creates three primary compliance duties for deployers, plus consumer data rights. None of these are satisfied by a policy document — they must be built into operational workflows.

    1. Pre-Use Notice

    Before using ADMT to make or substantially assist in a consequential decision, you must provide the consumer with clear notice that includes:

    • The purpose of the ADMT
    • The nature of the consequential decision being made
    • A plain-language description of the system
    • How the consumer can access and correct the personal data used as input

    2. Adverse-Decision Notice

    Within 30 days of making an adverse consequential decision in which ADMT materially contributed, you must notify the affected consumer of the adverse outcome, that ADMT was used, and how they can request human review. This is a hard deadline, not a best-effort target.

    3. Meaningful Human Review

    On request, you must provide a meaningful opportunity for human review of the consequential decision — to the extent commercially reasonable. The human reviewer must have the ability to overturn the automated outcome. "Meaningful" means a real person with real authority, not a rubber stamp on an AI recommendation.

    Consumer Data Rights

    Consumers have the right to access and correct the personal data that was used as input to an ADMT system in a consequential decision. You must have a process for receiving, evaluating, and responding to these requests.

    5. Why Compliance Is an Operational Problem, Not a Legal One

    The shift from SB24-205 to SB 26-189 is a shift in who carries the compliance burden. The original law focused heavily on developers — build a risk-management program, document your model, align with NIST. The new law focuses on deployers and the moment of consumer interaction.

    That means compliance under SB 26-189 isn't primarily a documentation exercise. It's a workflow problem. The pre-use notice has to be delivered at the right point in the customer or applicant journey. The adverse-decision notice has to be triggered automatically — within 30 days — when an ADMT system materially contributed to a denial. The human-review path has to be staffed and reachable.

    For most mid-market companies, none of this exists yet. The tenant screening software runs in the background. The applicant tracking system scores candidates automatically. The loan decision engine flags files for denial. None of these systems were configured with SB 26-189 notices in mind, because the law didn't exist when they were deployed. Compliance requires going back into those workflows and wiring in the notice triggers, the documentation, and the review paths.

    The Documentation Gap — Still Applies

    Most mid-market companies still don't have a complete inventory of the automated tools touching consequential decisions. You cannot build a notice workflow around a tool you haven't mapped. The starting point for SB 26-189 compliance is the same as it was for SB24-205: know where your automated decision-making actually lives.

    6. Developer vs. Deployer: Know Your Role

    SB 26-189 retains the two-tier structure of SB24-205. Developers build or substantially modify ADMT and must provide documentation to deployers. Deployers use ADMT in consequential decisions and bear the primary obligations toward consumers.

    AspectDeveloperDeployer
    DefinitionBuilds or substantially modifies ADMT systemsUses ADMT for consequential decisions
    Key RequirementsTechnical documentation, known limitations disclosure, documentation retentionPre-use notice, adverse-decision notice, meaningful human review, consumer data access
    Primary DutyInform deployers; provide documentationFulfill obligations to consumers at the point of decision
    DocumentationRetain for 3 years; provide to deployers on requestRetain records of decisions and notices for 3 years

    Most mid-market companies are Deployers — they use ADMT built by others (screening platforms, HR software, CRMs, insurance underwriting tools) rather than building custom AI systems. This guide focuses on Deployer obligations, which represent the bulk of SB 26-189 compliance work for typical businesses.

    7. Enforcement — AG Only, With a Cure Period

    SB 26-189 is enforced exclusively by the Colorado Attorney General through the state's consumer protection laws. There is no private right of action — consumers cannot sue you directly for violations.

    Before January 1, 2030, companies have a 60-day cure period after receiving notice of a violation. If you remediate within 60 days, enforcement action cannot be initiated. After 2030, the cure period expires and violations are immediately actionable.

    Before January 1, 2030

    • ✓ AG enforces via consumer protection laws
    • ✓ 60-day cure period after violation notice
    • ✓ No private right of action
    • ✓ Penalties: civil consumer protection fines

    After January 1, 2030

    • ⚠ Cure period expires
    • ⚠ Violations immediately actionable
    • ⚠ AG enforcement without notice period
    • ⚠ Same civil penalty exposure

    Ready to Map Your Automated Decision-Making?

    Our Process Heatmap Audit identifies every automated tool touching a consequential decision in your operations and maps the notice and human-review workflows SB 26-189 requires.

    8. The Solution: SB 26-189–Enhanced Process Heatmap Audit

    Our Process Heatmap Audit has been updated to address SB 26-189 compliance requirements. Here's what we deliver:

    ADMT Inventory

    Every automated tool touching a consequential decision — including embedded AI in third-party vendor platforms — mapped to the specific decisions it influences.

    Notice Workflow Design

    Pre-use and adverse-decision notice templates and workflow triggers, designed for your specific systems and decision points — not generic policy language.

    Human-Review Path Architecture

    Design and implementation of a staffed, documented human-review process for each consequential decision category — including who owns the review and how the outcome is recorded.

    Consumer Data Access Process

    A documented, operable process for receiving, evaluating, and responding to consumer requests to access and correct personal data used in automated decisions.

    Prioritized Remediation Roadmap

    A clear sequence of what to address first — ranked by decision volume, adverse-outcome frequency, and compliance gap severity — so your team is working on what matters most before January 1, 2027.

    Residential Property Managers: See Our Industry Guide

    Tenant screening and leasing decisions are explicitly covered as "consequential decisions" under SB 26-189. We've published a detailed guide on what the new law means operationally for property management portfolios.

    Read: What Colorado's SB 26-189 Means for Residential Property Managers →

    SB 26-189 Takes Effect January 1, 2027

    Our Process Heatmap Audit maps every automated decision in your operations, designs the notice and human-review workflows SB 26-189 requires, and gives you a sequenced implementation plan.

    Complete ADMT inventory
    Pre-use notice workflow design
    Adverse-decision notice triggers
    Human-review path architecture
    Consumer data access process
    Prioritized remediation roadmap

    Free consultation. We'll assess your ADMT exposure and compliance gaps.