Colorado AI Compliance Guide: SB 26-189 (ADMT Act)
Colorado's original AI Act (SB24-205) was repealed and replaced by SB 26-189 before it ever took effect. The new Automated Decision-Making Technology Act is effective January 1, 2027 — and the obligations it creates are different from what most compliance teams are expecting.
Published by InsidePartners · Updated July 2026
1. What Changed — and Why It Matters
Colorado's original AI law, SB24-205 (the Colorado Artificial Intelligence Act, or CAIA), was signed in May 2024 and was set to take effect June 30, 2026. It was built around preventing algorithmic discrimination — requiring impact assessments, a risk-management program, and a duty of reasonable care, with an affirmative defense available to companies that complied.
That law never took effect. Enforcement was stayed in federal court in April 2026. On May 14, 2026, Governor Polis signed SB26-189, which repealed and replaced SB24-205 entirely. The new law is formally titled the Automated Decision-Making Technology (ADMT) Act and carries an effective date of January 1, 2027.
The structural shift is significant. SB24-205 asked: "Can you prove your AI system doesn't produce a discriminatory result?" SB 26-189 asks a different set of questions: "Did you tell the person an automated tool was being used? Did you notify them when it produced an adverse outcome? Can they get a human to review it?" The obligation moved from risk-management documentation to transparency and consumer rights.
Key Facts at a Glance
- Signed: May 14, 2026 (Chapter 131)
- Effective: January 1, 2027
- Replaces: SB24-205 (CAIA), which never took effect
- Enforcer: Colorado Attorney General only — no private right of action
- Cure period: 60 days (applicable before January 1, 2030)
- Terminology shift: "high-risk AI system" → "automated decision-making technology (ADMT)"
2. What Is "Automated Decision-Making Technology"?
SB 26-189 defines automated decision-making technology (ADMT) as any system that processes personal data using computation, including machine learning, statistics, or other data-processing techniques, to make or substantially assist in making a consequential decision. The definition is intentionally broad — it covers scoring tools, recommendation engines, and any AI that meaningfully shapes an outcome affecting a consumer.
The law retains the developer/deployer split from SB24-205. Developers build or substantially modify ADMT; deployers use it in consequential decisions. Most mid-market companies are deployers — they use ADMT built by vendors (Salesforce, HubSpot, screening software providers, and others) to make decisions about their customers, tenants, applicants, or employees.
3. What Are "Consequential Decisions"?
The law applies when ADMT is used to make or substantially assist in making a consequential decision — one that significantly affects a Colorado consumer's access to, or the cost or terms of, any of the following:
Employment
Hiring, firing, promotions, compensation, performance evaluations
Housing
Rental applications, lease terms, mortgage approvals, property management decisions
Education
Admissions, scholarships, disciplinary actions, accommodations
Healthcare
Treatment recommendations, diagnostic support, care prioritization, insurance coverage
Financial Services
Loan approvals, credit decisions, interest rates, fraud detection
Insurance
Coverage decisions, premium pricing, claims processing, risk assessments
Government Services
Benefits eligibility, licensing, permit approvals, public assistance programs
Legal Services
Case assessments, document review, risk analysis, client intake decisions
If your business uses automated tools to make or substantially assist in any of these decisions affecting Colorado consumers, SB 26-189 applies to you.
4. The Three Core Obligations
SB 26-189 creates three primary compliance duties for deployers, plus consumer data rights. None of these are satisfied by a policy document — they must be built into operational workflows.
1. Pre-Use Notice
Before using ADMT to make or substantially assist in a consequential decision, you must provide the consumer with clear notice that includes:
- The purpose of the ADMT
- The nature of the consequential decision being made
- A plain-language description of the system
- How the consumer can access and correct the personal data used as input
2. Adverse-Decision Notice
Within 30 days of making an adverse consequential decision in which ADMT materially contributed, you must notify the affected consumer of the adverse outcome, that ADMT was used, and how they can request human review. This is a hard deadline, not a best-effort target.
3. Meaningful Human Review
On request, you must provide a meaningful opportunity for human review of the consequential decision — to the extent commercially reasonable. The human reviewer must have the ability to overturn the automated outcome. "Meaningful" means a real person with real authority, not a rubber stamp on an AI recommendation.
Consumer Data Rights
Consumers have the right to access and correct the personal data that was used as input to an ADMT system in a consequential decision. You must have a process for receiving, evaluating, and responding to these requests.
5. Why Compliance Is an Operational Problem, Not a Legal One
The shift from SB24-205 to SB 26-189 is a shift in who carries the compliance burden. The original law focused heavily on developers — build a risk-management program, document your model, align with NIST. The new law focuses on deployers and the moment of consumer interaction.
That means compliance under SB 26-189 isn't primarily a documentation exercise. It's a workflow problem. The pre-use notice has to be delivered at the right point in the customer or applicant journey. The adverse-decision notice has to be triggered automatically — within 30 days — when an ADMT system materially contributed to a denial. The human-review path has to be staffed and reachable.
For most mid-market companies, none of this exists yet. The tenant screening software runs in the background. The applicant tracking system scores candidates automatically. The loan decision engine flags files for denial. None of these systems were configured with SB 26-189 notices in mind, because the law didn't exist when they were deployed. Compliance requires going back into those workflows and wiring in the notice triggers, the documentation, and the review paths.
The Documentation Gap — Still Applies
Most mid-market companies still don't have a complete inventory of the automated tools touching consequential decisions. You cannot build a notice workflow around a tool you haven't mapped. The starting point for SB 26-189 compliance is the same as it was for SB24-205: know where your automated decision-making actually lives.
6. Developer vs. Deployer: Know Your Role
SB 26-189 retains the two-tier structure of SB24-205. Developers build or substantially modify ADMT and must provide documentation to deployers. Deployers use ADMT in consequential decisions and bear the primary obligations toward consumers.
| Aspect | Developer | Deployer |
|---|---|---|
| Definition | Builds or substantially modifies ADMT systems | Uses ADMT for consequential decisions |
| Key Requirements | Technical documentation, known limitations disclosure, documentation retention | Pre-use notice, adverse-decision notice, meaningful human review, consumer data access |
| Primary Duty | Inform deployers; provide documentation | Fulfill obligations to consumers at the point of decision |
| Documentation | Retain for 3 years; provide to deployers on request | Retain records of decisions and notices for 3 years |
Most mid-market companies are Deployers — they use ADMT built by others (screening platforms, HR software, CRMs, insurance underwriting tools) rather than building custom AI systems. This guide focuses on Deployer obligations, which represent the bulk of SB 26-189 compliance work for typical businesses.
7. Enforcement — AG Only, With a Cure Period
SB 26-189 is enforced exclusively by the Colorado Attorney General through the state's consumer protection laws. There is no private right of action — consumers cannot sue you directly for violations.
Before January 1, 2030, companies have a 60-day cure period after receiving notice of a violation. If you remediate within 60 days, enforcement action cannot be initiated. After 2030, the cure period expires and violations are immediately actionable.
Before January 1, 2030
- ✓ AG enforces via consumer protection laws
- ✓ 60-day cure period after violation notice
- ✓ No private right of action
- ✓ Penalties: civil consumer protection fines
After January 1, 2030
- ⚠ Cure period expires
- ⚠ Violations immediately actionable
- ⚠ AG enforcement without notice period
- ⚠ Same civil penalty exposure
Ready to Map Your Automated Decision-Making?
Our Process Heatmap Audit identifies every automated tool touching a consequential decision in your operations and maps the notice and human-review workflows SB 26-189 requires.
8. The Solution: SB 26-189–Enhanced Process Heatmap Audit
Our Process Heatmap Audit has been updated to address SB 26-189 compliance requirements. Here's what we deliver:
ADMT Inventory
Every automated tool touching a consequential decision — including embedded AI in third-party vendor platforms — mapped to the specific decisions it influences.
Notice Workflow Design
Pre-use and adverse-decision notice templates and workflow triggers, designed for your specific systems and decision points — not generic policy language.
Human-Review Path Architecture
Design and implementation of a staffed, documented human-review process for each consequential decision category — including who owns the review and how the outcome is recorded.
Consumer Data Access Process
A documented, operable process for receiving, evaluating, and responding to consumer requests to access and correct personal data used in automated decisions.
Prioritized Remediation Roadmap
A clear sequence of what to address first — ranked by decision volume, adverse-outcome frequency, and compliance gap severity — so your team is working on what matters most before January 1, 2027.
Residential Property Managers: See Our Industry Guide
Tenant screening and leasing decisions are explicitly covered as "consequential decisions" under SB 26-189. We've published a detailed guide on what the new law means operationally for property management portfolios.
Read: What Colorado's SB 26-189 Means for Residential Property Managers →Related Reading
SB 26-189 Takes Effect January 1, 2027
Our Process Heatmap Audit maps every automated decision in your operations, designs the notice and human-review workflows SB 26-189 requires, and gives you a sequenced implementation plan.
Free consultation. We'll assess your ADMT exposure and compliance gaps.