Colorado’s AI Law Never Took Effect. Here Is What Actually Applies to Employers on January 1, 2027
Executive Summary
- Colorado SB 24-205, the law every HR vendor told you to prepare for, was enacted in 2024 but never became operative. Its compliance date slipped from February 1, 2026 to June 30, 2026, a federal court stayed enforcement on April 27, 2026, and the legislature repealed and reenacted the framework before any obligation ever attached.
- The successor is SB 26-189, signed May 14, 2026 and codified at C.R.S. 6-1-1701 through 6-1-1709. The act takes effect January 1, 2027 and applies to consequential decisions made on or after that date, which gives employers roughly five months from today.
- The new law is lighter but not empty. The duty of reasonable care, the risk management program, and impact assessments did not carry forward. Pre use notice, a plain language explanation within 30 days of an adverse outcome, correction and human review on request, and three year recordkeeping did.
- The old law relieved deployers with fewer than 50 full time employees of the risk management program. The enrolled text of SB 26-189 contains no employee count threshold and no small business exemption, so a 12 person company and a 12,000 person company face the same notice and explanation duties.
- Violations are deceptive trade practices enforceable exclusively by the Attorney General, with no new private right of action, subject to a 60 day cure that sunsets January 1, 2030. Separately, the act expressly preserves discrimination claims under the Colorado Anti Discrimination Act and voids contract terms that indemnify a developer or deployer for its own acts.
In this article
- What happened to Colorado’s AI law
- Why the original AI Act never took effect
- What SB 26-189 actually requires of employers
- Does this reach an employer outside Colorado?
- What Colorado dropped, and why small employers should not celebrate
- Penalties, enforcement, and the 60 day cure window
- Colorado is not the only clock running
- Why federal retreat does not lower your risk
- What to do between now and January 1, 2027
- Turning this into a governance program instead of a fire drill
1. What happened to Colorado’s AI law
Colorado repealed and reenacted its landmark AI Act as a narrower disclosure law before the original ever became operative. If your HR team spent late 2025 preparing for a June 30, 2026 compliance deadline, that deadline no longer exists. A new one does, and it is January 1, 2027.
Here is the short version. Colorado SB 24-205, Consumer Protections for Artificial Intelligence, was signed May 17, 2024, but no obligation under it ever attached. Its compliance date moved from February 1, 2026 to June 30, 2026, a federal court stayed enforcement in April 2026, and the legislature repealed and reenacted the framework as SB 26-189 on May 14, 2026. The successor act takes effect January 1, 2027 and applies to consequential decisions made on or after that date.
That sequence matters because most of the compliance guidance still circulating online describes a statute that no longer exists. Vendor checklists built around impact assessments and algorithmic discrimination risk management programs were written against SB 24-205. What replaced them is a shorter list of duties that is, in one important respect, harder for a small employer to ignore, because the successor dropped the small employer carve out the old law contained.
This article is for the company that uses AI somewhere in the hiring or employment lifecycle and has no compliance department. If you use an applicant tracking system that ranks or scores candidates, a resume screening tool, a video interview assessment, or a performance analytics product, you are in scope even if nobody at your company would call what you do artificial intelligence.
2. Why the original AI Act never took effect
Three separate events killed SB 24-205: a legislative delay, a federal lawsuit joined by the United States, and a repeal. Each one is worth understanding, because together they explain why the replacement law looks the way it does.
The delay came first. The original act was sponsored by Senator Robert Rodriguez with Representatives Manny Rutinel and Brianna Titone, and signed by Governor Jared Polis on May 17, 2024. It set an implementation date of February 1, 2026. Colorado then held a special legislative session in August 2025 that failed to produce a substantive amendment, and Governor Polis signed SB 25B-004 on August 28, 2025, pushing implementation to June 30, 2026.
The lawsuit came next. On April 9, 2026, X.AI LLC filed suit against Colorado Attorney General Philip Weiser in the United States District Court for the District of Colorado, X.AI LLC v. Weiser, No. 1:26-cv-01515, seeking to enjoin the AI Act before its June 30 date on First Amendment, Commerce Clause, Due Process, and Equal Protection grounds. On April 24, 2026, the United States moved to intervene as a plaintiff and the court granted intervention the same day. On April 27, 2026, the court granted a joint motion of the parties staying enforcement.
The repeal finished the job. Governor Polis signed SB 26-189 on May 14, 2026, sponsored by Senators Rodriguez and James Coleman with Representatives Monica Duran and Jennifer Bacon. It repeals and reenacts the 2024 provisions as a framework built around automated decision making technology rather than high risk AI systems. Colorado spent two years as the country’s most watched AI compliance jurisdiction and never enforced a single provision of the law that earned it that reputation.
3. What SB 26-189 actually requires of employers
SB 26-189 requires employers who use covered automated decision making technology to give notice before use, explain adverse outcomes within 30 days, honor correction and human review requests, and keep records for three years. Every item is operational rather than analytical, the biggest practical difference from the repealed law.
The trigger is a covered ADMT, defined in the signed act at C.R.S. 6-1-1701(5) as automated decision making technology used to materially influence a consequential decision. The covered domains are education, employment or an employment opportunity that creates or may create an employer employee relationship, the lease or purchase of residential real estate in Colorado, financial or lending services, insurance, health care services, and essential government services and public benefits. Employment is squarely in scope, and the definition reaches the ordinary HR technology stack rather than exotic AI products.
One useful limit sits inside the definition. Consequential decision expressly excludes low stakes or routine decisions and business processes that do not materially influence eligibility, selection, denial, or compensation, which is what keeps routine administration outside the law.
The four deployer duties
Pre use notice, at 6-1-1704(1). Before using a covered ADMT to materially influence a consequential decision, you must give clear and conspicuous notice that you used or will use it, plus instructions on how the person can obtain more information. Subsection (2) lets you satisfy this by maintaining a prominent public notice reasonably accessible at points of consumer interaction.
Post adverse outcome disclosure, at 6-1-1704(3). Within 30 days after making the decision, you must provide a plain language description of the decision and the role the ADMT played, plus a simple to follow process to request further detail including the tool name, version number, and developer. For a hiring team, that means your rejection workflow now has a content requirement attached to it.
Correction and human review on request, at 6-1-1705(1). When someone experiences an adverse outcome, they may request, and you must then provide, instructions for correcting factually incorrect or materially inaccurate personal data and an opportunity for meaningful human review and reconsideration to the extent commercially reasonable. Note the trigger. These are response duties, not things you push out automatically. Meaningful is doing work in that sentence, and a reviewer who rubber stamps the system output is not performing review.
Recordkeeping, at 6-1-1703. You must retain records reasonably necessary to demonstrate compliance for not less than three years after the date of the consequential decision, which may include ADMT version identifiers, changelogs, and documentation of material mitigation changes.
Developers have their own duties, and you may be both
Section 6-1-1702 puts a separate obligation on developers. On and after January 1, 2027, a developer must give each deployer a statement of intended and known harmful uses, a description of data categories, instructions for appropriate use, monitoring, and meaningful human review, plus the information reasonably necessary for the deployer to meet its own disclosure duties, along with notice of material updates and three year record retention.
That matters to employers twice over. The documentation is what makes your own compliance possible, so ask for it now rather than in December. And an employer that builds or substantially configures its own screening tool may be acting as a developer as well as a deployer, owing both sets of duties.
The Colorado Attorney General is directed to adopt rules on or before January 1, 2027, running alongside the compliance date. Expect the operational detail on notice timing and format to arrive through those rules rather than the statute itself.
GOVERNANCE INSIGHT
The hard part is the inventory, not the notice.
Writing a pre use notice takes an afternoon. Knowing every place a scoring, ranking, or filtering feature touches a hiring or employment decision takes weeks, because most of those features arrived inside products you already owned. Employers that miss this law will miss it through an unknown tool, not an unwritten notice.
4. Does this reach an employer outside Colorado?
Yes, and the statute says so in unusually direct terms. The definition of consumer at C.R.S. 6-1-1701(4)(b) provides that consumer “includes an employee, a job applicant who is a Colorado resident, and any individual whose access to, eligibility for, or opportunity in Colorado is evaluated in a consequential decision by a person doing business in Colorado.”
Read that carefully, because the drafting does two things at once. A job applicant who is a Colorado resident is covered as such. The broader catch all clause, covering anyone whose opportunity in Colorado is evaluated, is qualified by the phrase “by a person doing business in Colorado.” So the reach is wide but not unlimited, and an employer with no Colorado business connection at all has a real argument to make.
For a remote first employer, the practical test is still not where your office is. It is whether a Colorado resident applies for your job and gets screened, scored, ranked, or filtered by a tool before a human looks at the file. If that person receives an adverse outcome, the notice, explanation, correction, and human review duties attach. Remote postings draw applicants from every state, and no employer controls where its applicants live.
The act does carve out several sectors at 6-1-1708. HIPAA covered entities and their business associates are excluded from the operative sections, but the exclusion expressly does not apply to a consequential decision related to employment or an employment opportunity, and for health care providers it applies only if the provider operates from a location within Colorado. There are also accommodations for creditors that already send adverse action notices under the Equal Credit Opportunity Act and Regulation B, for FERPA covered institutions, for insurers regulated under C.R.S. 10-3-1104.9, for FDA regulated medical devices, and for information protected by the Gramm Leach Bliley Act. A medical practice outside the law for patient facing uses is still a covered employer when it screens applicants.
5. What Colorado dropped, and why small employers should not celebrate
Colorado did not carry forward the three heaviest obligations in the 2024 act: the duty of reasonable care to protect against algorithmic discrimination, the mandatory risk management program, and the impact assessment requirement. For a small HR team, those were the expensive items, and their absence from the successor framework is genuinely good news.
The problem is what came with the trade. SB 24-205 contained a real small employer accommodation: deployers with fewer than 50 full time employees were relieved of the risk management program requirement if they did not customize the system with their own data, limited use to what the developer disclosed, and made the developer’s impact assessment available. That was the single provision most often cited to small businesses as their reason to relax.
SB 26-189 has no headcount threshold. The enrolled act contains no reference to full time employee counts and no small business exemption, and the carve outs it does contain are sectoral rather than size based. The obligations that survived apply to everyone in a covered domain. A 12 person staffing agency and a 12,000 person enterprise owe the same pre use notice, the same 30 day explanation, and the same three year records.
Read the trade honestly. Colorado replaced a demanding law that partially excused small employers with a modest law that does not excuse them at all. Your total burden probably went down. Your probability of being covered went up.
6. Penalties, enforcement, and the 60 day cure window
Section 6-1-1706 gives the Attorney General exclusive enforcement authority, makes a violation a deceptive trade practice, and creates no new private right of action. The disclosure and consumer rights provisions are “enforceable exclusively by the attorney general,” and a companion amendment adds a violation of the new part 17 to the deceptive trade practices list at C.R.S. 6-1-105.
The penalty exposure therefore runs through the Consumer Protection Act rather than the AI statute. Under C.R.S. 6-1-112(1)(a), a person who violates the act pays a civil penalty of not more than $20,000 for each violation, and the statute provides that a violation constitutes a separate violation with respect to each consumer or transaction involved. Do the arithmetic on a rejection workflow that processes a few hundred Colorado applicants without the required disclosure and the theoretical ceiling becomes serious quickly.
Before bringing an action, the Attorney General must issue a notice of violation where a cure is deemed possible, and may sue if the violation is not cured within 60 days of receipt. Three limits on that safety valve deserve attention. No cure period is required where the Attorney General demonstrates a knowing or repeated violation. A timely cure is only a mitigating factor when a violation surfaces during an enforcement action. And the entire cure subsection is repealed effective January 1, 2030, along with the annual reporting the Attorney General must give on enforcement actions and cure periods starting in January 2028.
No private right of action is not the same as no lawsuits
The absence of a private right of action under this part does not insulate an employer from private discrimination litigation, and section 6-1-1707 says so explicitly. A developer or deployer may be held liable in an action alleging unlawful discrimination under state anti discrimination laws, including the Colorado Anti Discrimination Act, arising from a consequential decision materially influenced by a covered ADMT. The act also provides that using an ADMT in a consequential decision “does not excuse, justify, or provide a defense to” any obligation or liability under state or federal law, and that compliance with part 17 is not itself a defense to noncompliance with other law.
Two structural provisions there belong in front of whoever signs your vendor contracts. Fault is allocated between deployers and developers based on relative fault, with no joint and several liability beyond what existing law allows. More importantly, contract terms purporting to indemnify, defend, or hold harmless a developer or deployer against liability for its own acts in violation of the Colorado Anti Discrimination Act are stripped of effect. You cannot buy your way out with an indemnity clause, which makes vendor selection and monitoring the real controls.
The realistic enforcement picture for 2027 is an Attorney General finishing rulemaking and looking for clear, documentable failures. Missing notice on a public job application page is exactly that. It is visible from outside the company, requires no discovery to prove, and is trivially cheap to fix in advance.
7. Colorado is not the only clock running
Colorado is one of several state clocks, and two of them have already struck. Illinois and California imposed enforceable obligations on employers using AI before Colorado’s new law was even signed, and Connecticut enacted a comprehensive framework in May 2026 with staggered dates beginning October 1, 2026.
The Transparency Coalition reported on July 21, 2026 that 84 new AI related laws had been enacted across 27 states so far in 2026, already exceeding the 73 laws adopted across 27 states in all of 2025. Any multistate employer building a compliance program around a single state is building it wrong.
| Jurisdiction | Status and date | Core employer duty | Enforcement |
|---|---|---|---|
| Colorado SB 26-189 | Signed May 14, 2026. Effective January 1, 2027, for consequential decisions made on or after that date | Pre use notice, 30 day adverse outcome explanation, correction and human review on request, three year records | Attorney General exclusively. No new private right of action. Deceptive trade practice, so up to $20,000 per violation under C.R.S. 6-1-112(1)(a) |
| Illinois HB 3773 | In force January 1, 2026 | Civil rights violation to use AI that has a discriminatory effect, to use ZIP code as a proxy for a protected class, or to fail to give notice that AI is used for covered employment decisions | Illinois Human Rights Act process. Department of Human Rights notice rules were withdrawn and remained pending as of late July 2026 |
| California FEHA regulations | In force October 1, 2025 | Automated decision systems can violate FEHA by disparate impact. Four year retention of automated decision system records | Civil Rights Department, under FEHA, which reaches employers with five or more employees. Vendors administering a system may be treated as agents |
| Connecticut SB 5 | Signed May 29, 2026. Staggered dates beginning October 1, 2026, with employment notice obligations reported to apply to deployments on or after October 1, 2027 | Framework for automated employment related decision technology, including disclosure and pre decision notice | State enforcement. Confirm the current staggered dates before relying on them, since implementation detail is still settling |
| Texas HB 149 | In force January 1, 2026 | Prohibits developing or deploying AI with intent to unlawfully discriminate. Disparate impact alone does not establish intent. No impact assessment or applicant disclosure duty for private employers | Attorney General exclusively, no private right of action. $10,000 to $12,000 curable, $80,000 to $200,000 uncurable, $2,000 to $40,000 per day continuing |
| NYC Local Law 144 | In force since 2023 | Independent bias audit of automated employment decision tools, published results, candidate notice | Department of Consumer and Worker Protection. $500 for a first violation and each additional violation the same day, then $500 to $1,500 per subsequent violation, with each day of noncompliant use a separate violation |
Two features of that table should shape your plan. The requirements are not contradictory: notice, documentation, and human review appear in nearly every regime, so one well built program satisfies most of them. But the states disagree sharply on liability standards. Texas requires intent to discriminate, while Illinois and California reach discriminatory effect without intent. An employer operating in both cannot design to the lower standard.
Getting your AI governance in order
Dynamic Comply helps small and medium sized businesses build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001.
8. Why federal retreat does not lower your risk
Federal agencies have pulled back from AI enforcement while private litigation has moved forward, which means the total legal risk to employers has shifted rather than shrunk. Reading the federal retreat as permission is the most expensive mistake available in this area right now.
The retreat is real. The EEOC removed its AI related technical assistance documents on January 27, 2025. On April 23, 2025, Executive Order 14281, Restoring Equality of Opportunity and Meritocracy, directed federal agencies to deprioritize disparate impact liability. On December 11, 2025, Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, directed the Attorney General to establish an AI Litigation Task Force within 30 days to challenge state AI laws. The intervention in the Colorado case was that policy in action.
None of that changed the statutes. Title VII, the ADEA, and the ADA remain fully enforceable by private plaintiffs regardless of agency priorities. Executive orders do not preempt state law, and no federal AI statute currently displaces the state regimes above. We covered the federal side in our analysis of the 2026 federal AI procurement rules.
Meanwhile the private litigation risk has grown. In Mobley v. Workday, No. 3:23-cv-00770 in the Northern District of California, the court granted preliminary certification of a nationwide ADEA collective on May 16, 2025, covering applicants aged 40 and over denied employment recommendations through the platform beginning September 24, 2020. The court’s reasoning treated an AI screening vendor as a potential agent of the employers using it, a theory that depends on neither a state AI statute nor EEOC priorities.
The honest summary: your regulator based risk is concentrated at the state level, your litigation based risk is federal, private, and rising, and neither is addressed by waiting.
9. What to do between now and January 1, 2027
Work in this order: inventory your tools, classify which ones influence consequential decisions, fix the notice and explanation workflows, define what human review means at your company, and set up records. Roughly five months remain, and a company without a compliance department can complete this with a few hours a week if the sequence is right.
Weeks 1 to 3: find the tools
List every system that touches recruiting, hiring, promotion, discipline, scheduling, or performance. For each one, ask the vendor a single written question: does this product score, rank, filter, match, or recommend people, and does that output reach a human decision maker. Get the answer in writing. Most companies discover between three and eight systems in scope, and at least one of them is a feature that was added to an existing contract without a new purchase.
Ask a second question at the same time. Section 6-1-1702 requires developers to hand deployers the documentation you need to write your own disclosures, starting January 1, 2027. Request it now. A vendor that cannot produce intended use documentation, data category descriptions, and human review instructions is a vendor that will make your compliance impossible in December. Do not accept a broad indemnity in place of that documentation, because Colorado strips effect from contract terms that indemnify a party against liability for its own discriminatory acts.
Weeks 4 to 6: classify and cut
Separate tools that materially influence an outcome from tools that only do administration. Calendar scheduling and interview transcription usually fall outside. Candidate ranking, assessment scoring, and automated screen outs fall inside. This is also the moment to turn off anything you cannot justify, the cheapest compliance measure that exists.
Weeks 7 to 10: fix the two workflows
Add the pre use notice to the job application page and any candidate portal where the interaction begins. Then rebuild the rejection workflow so an adverse outcome triggers a plain language explanation within 30 days. These are template changes to systems you already operate, not new software purchases.
Weeks 11 to 14: define human review and set records
Write down who reviews an adverse outcome on request, what authority that person has to override the system, and what they must look at. A reviewer without override authority is not conducting meaningful review. Then set a three year retention rule covering the decision, the system version, and the review record. If you also hire in California, adopt that state’s four year period and you satisfy both.
One deliberate omission here is a bias audit. Colorado does not require one. New York City does for covered tools, and Illinois and California expose you to effect based liability an audit helps you understand. Sequence it after the items above unless you hire in New York City, where it moves to the front.
10. Turning this into a governance program instead of a fire drill
The employers who handle this well will not build a Colorado program. They will build one AI governance program and map it to each jurisdiction, because the building blocks Colorado requires are the same ones every other regime asks for in different language.
Those blocks are an inventory of AI systems, a classification of which ones make consequential decisions, disclosure and explanation to affected people, and human accountability with records to prove it. The NIST AI Risk Management Framework organizes this as Govern, Map, Measure, and Manage. ISO/IEC 42001 organizes it as an auditable management system. Both get you to the same operational place, and both are how you answer an enterprise customer’s AI questionnaire without starting from scratch each time.
The practical argument is cost per jurisdiction. Building to Colorado alone covers one state. Building an inventory, a classification standard, a disclosure practice, and a review record costs modestly more and covers Colorado, Illinois, California, Connecticut, Texas, New York City, and whatever the next state enacts. Given 84 AI laws across 27 states in the first half of 2026 alone, only the second approach has a stable cost curve.
For the underlying regulatory context on how state AI audit and transparency laws are developing, our explainer on Illinois SB 315 and the first state AI audit law covers the developer side of the same trend that produced Colorado’s deployer obligations.
The last thing worth saying is about posture. Colorado’s two year detour taught employers that AI compliance deadlines move, and some concluded the right response is to wait. The deadlines did move. The direction did not. Every revision so far has expanded the number of employers covered while reducing the analytical burden on each one, which is precisely the shape of a regime becoming permanent.
Talk to Ross about your AI governance needs
Every business has different AI governance requirements. Let us talk about yours.
Frequently Asked Questions
Is the Colorado AI Act still in effect in 2026?
No. Colorado SB 24-205 was enacted in 2024 but never became operative. Its compliance date moved from February 1, 2026 to June 30, 2026, a federal court stayed enforcement on April 27, 2026 in X.AI LLC v. Weiser, and the legislature repealed and reenacted the framework as SB 26-189, signed May 14, 2026. The successor act takes effect January 1, 2027 and applies to consequential decisions made on or after that date.
Does Colorado SB 26-189 apply to small businesses?
Yes. Unlike the 2024 act, which relieved deployers with fewer than 50 full time employees of the risk management program requirement, the enrolled text of SB 26-189 contains no employee count threshold and no small business exemption. A 12 person employer owes the same pre use notice, 30 day adverse outcome explanation, and three year recordkeeping as a large enterprise. The carve outs at C.R.S. 6-1-1708 are sectoral, and the HIPAA carve out expressly does not apply to a consequential decision related to employment or an employment opportunity.
What are the penalties for violating Colorado’s AI law?
A violation of part 17 is a deceptive trade practice, which brings it under the Colorado Consumer Protection Act penalty of not more than $20,000 per violation at C.R.S. 6-1-112(1)(a), with each affected consumer or transaction treated as a separate violation. The Attorney General enforces exclusively and must issue a notice of violation with 60 days to cure where a cure is possible, though no cure period is required for knowing or repeated violations, and the cure subsection is repealed effective January 1, 2030.
Does Colorado’s AI law apply to employers based in other states?
Yes, in most cases. The statutory definition of consumer at C.R.S. 6-1-1701(4)(b) expressly includes a job applicant who is a Colorado resident, and also reaches any individual whose opportunity in Colorado is evaluated in a consequential decision by a person doing business in Colorado. A remote first employer in another state that screens a Colorado resident with a tool that scores, ranks, or filters candidates owes the notice, explanation, correction, and human review duties for that decision.
If there is no private right of action, can an employee still sue over an AI hiring decision?
Yes. SB 26-189 creates no new private right of action, but C.R.S. 6-1-1707 expressly preserves discrimination claims under state anti discrimination law, including the Colorado Anti Discrimination Act, arising from a consequential decision materially influenced by a covered ADMT. The act also provides that using an ADMT does not excuse, justify, or provide a defense to liability under other law, and it strips effect from contract terms indemnifying a developer or deployer against liability for its own discriminatory acts.
Do I need a bias audit to comply with SB 26-189?
No. Colorado SB 26-189 does not require a bias audit, and the impact assessment requirement from the repealed 2024 act did not carry forward. New York City Local Law 144 does require an independent bias audit for covered automated employment decision tools, and Illinois HB 3773 and California’s FEHA regulations create effect based liability that a bias audit helps you manage, so audits remain worth sequencing after your notice and documentation work.
About the author
Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm based in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.
Related articles
This article is provided for general informational purposes and reflects the state of the law as of August 2026. It is not legal advice. Regulations in this area are changing quickly. Confirm current requirements and consult qualified counsel before making decisions for your organization.