What the Colorado AI Law Requires Starting January 2027
Colorado's two new AI laws take effect January 1, 2027. The Attorney General's draft rules go to a public hearing on October 26.
Colorado's artificial intelligence (AI) law is two statutes signed in 2026. Senate Bill (SB) 26-189 regulates automated decision-making technology (ADMT) used in consequential decisions about people, and House Bill (HB) 26-1263 sets rules for AI chatbots. Several duties under the Colorado AI law take effect January 1, 2027.
The Colorado Attorney General released a revised draft of the rules for both laws on October 6, 2026. A public hearing follows on October 26 at 10 a.m., and written comments are accepted through that date.
What the Colorado AI Law Requires from January 1, 2027
Several duties in both Colorado statutes begin on January 1, 2027. The attorney general aims to adopt rules for both laws before then, according to a rulemaking summary by the law firm Orrick.
- SB 26-189, "Automated Decision-Making Technology." Signed May 14, 2026, it covers developers and deployers of ADMT that materially influences decisions about education, jobs, housing, lending, insurance, health care and public benefits. It repeals and reenacts the consumer protection provisions of the 2024 Colorado AI Act, SB 24-205.
- HB 26-1263, "Conversational Artificial Intelligence Service Operator Requirements." Signed May 29, 2026, it covers operators of AI chatbots open to the public. Law Week Colorado's report on the hearing notice calls it the Chatbot Safety Act.
Proposed rules for both laws were filed on August 11, 2026, and an interim redline followed on October 6.
How SB 26-189 Covers Automated Decisions
SB 26-189 sets duties for the companies that build and use automated decision-making technology in consequential decisions, and it gives consumers rights to their data and to human review. The act defines ADMT as technology that processes personal data and uses computation to produce outputs, such as predictions, scores or recommendations, that help make decisions about people. A consequential decision concerns access to, eligibility for, or compensation related to education, employment, housing, financial or lending services, insurance, health care, or essential government services and public benefits.
The act applies to developers of ADMT used to materially influence a consequential decision, which it calls "covered ADMT," and to deployers that use covered ADMT. Specified entities are exempt to the extent they comply with other legal obligations.
From January 1, 2027, developers must give deployers technical documentation covering:
- the technology's intended uses
- the categories of data used to train it
- its known limitations
- instructions for appropriate use and human review
Developers must also notify deployers of material updates or modifications.
Deployers must give clear, conspicuous notice at the point where a person interacts with covered ADMT. After an adverse consequential decision, the deployer has 30 days to provide a plain-language description of the technology's role. The attorney general must adopt rules clarifying that disclosure by January 1, 2027.
The act gives consumers three rights:
- request the personal data used by covered ADMT
- request correction of factually incorrect data
- request meaningful human review and reconsideration after an adverse decision
Developers and deployers must both keep the records needed to show compliance for at least 3 years.
The attorney general enforces the act through the Colorado Consumer Protection Act, where a violation counts as a deceptive trade practice. Until January 1, 2030, the attorney general must give 60 days' notice and a chance to cure before filing an action, if a cure is possible. The act creates no new private right of action, though it sets how fault is split between developers and deployers in civil discrimination cases under existing law.
What HB 26-1263 Requires of Chatbot Operators
HB 26-1263 sets duties for operators of public AI chatbots, starting January 1, 2027. The law covers a "conversational artificial intelligence service," an AI system open to the general public that primarily simulates human conversation and interaction. An operator is an entity that develops such a service and makes it publicly available, or offers it to a consumer.
Every operator must:
- use commercially or generally accepted methods to estimate the age of account holders and other users
- tell users the service is artificial intelligence
- keep a protocol for prompts involving suicidal ideation or self-harm
- report protocol information to the attorney general's office every year
- never state that the chatbot's output is provided by, endorsed by or equivalent to services from certain licensed or certified professionals
When an operator knows a user is a minor, it must also:
- provide certain disclosures
- give no points or rewards to encourage engagement
- take technically feasible measures to prevent explicit sexual conduct, intimate digital depictions and statements that simulate emotional dependence
- keep a protocol to stop the service from engaging when a prompt concerns sexual conduct with a minor
- provide privacy and account-setting tools to the minor or to a parent or guardian
Compare these duties with other age rules in the Ban the Bots explainer on AI chatbot age requirements.
What the October Redline Proposes to Change
The Colorado Attorney General's October 6, 2026 redline, a marked-up revision of the August draft rules, proposes changes that could shift again before adoption. Orrick groups the proposals under the redline's three headings.
Materially Influenced Decisions
- A consequential decision would be presumed "materially influenced" when a decision-maker reviews an output about the person, or uses it to screen data, and the output matches the final outcome.
- Deployers could rebut that presumption by showing the output was only a "de minimis factor."
- Tools used solely to summarize, organize or present information for human review would fall outside the definition.
- The redline's example of a materially influenced decision is a credit union denying loans to applicants below a risk-score threshold.
- Deployers would stay responsible when a third party runs the technology for them and they use the output.
Adverse Outcome Disclosures
- The August duty to state the "principal reason(s)" and disclose related inferences or scores would be removed. Deployers would describe the technology's role specifically instead.
- Disclosures would go through every channel the deployer typically uses with consumers, replacing a two-method requirement.
- Deployers would have 15 days, instead of responding immediately, to answer information requests made by hyperlink or phone.
- Colorado-required content could go out as a supplemental disclosure with federal Equal Credit Opportunity Act or Fair Credit Reporting Act notices.
- An exception would cover disclosures that would compromise legally required cybersecurity, fraud prevention, anti-money-laundering or sanctions compliance programs.
Consumer Rights
- Access and correction rights would become rights to request instructions for obtaining and correcting personal data.
- Opinions, predictions, scores and protected evaluations would be excluded from the correction right.
- The requirement to put adverse outcomes on hold pending correction or human review would be deleted.
- Human reviewers could be internal or external but would need actual authority to override the decision.
- The presumption that human review is commercially reasonable when an outcome severely and irreversibly denies a basic human need would be removed.
For someone denied a loan by a lender using covered ADMT, the redline would change the follow-up in two ways. The notice would describe the technology's role instead of the principal reasons, and an answer to a phone request could take up to 15 days.
How to Comment on the Colorado AI Law Rules Before October 26
Written comments on the draft rules are accepted through October 26, 2026, the day of the hearing. Law Week Colorado reports the hearing is hybrid, starting at 10 a.m. at the Department of Law in Denver with remote participation available.
The hearing covers rules for both SB 26-189 and the Chatbot Safety Act. Start at the Colorado Attorney General's AI rulemaking page, which hosts the rulemaking information.
The attorney general has asked for input on two questions:
- how to decide when technology materially influences a decision
- what responsibilities apply when an employer or other entity relies on AI run by a vendor
If you have received a decision about a job, apartment, loan, insurance or public benefits, you can comment on these questions. Consider including these points in a comment:
- whether you were told software played a part in the decision
- whether a person reviewed the decision and had the power to change it
- whether a description of the technology's role, without the principal reasons, would tell you enough to challenge the outcome
- whether a 15-day wait for an answer by phone or link would work for you
- for parents, whether a chatbot their child uses said it was AI and offered privacy or account-setting tools
Tie each point to a real decision: the type of decision, roughly when it happened and what you were told.
Open Questions in the Draft Rules
Three parts of the Colorado rules remain unsettled until the attorney general adopts final rules.
- When ADMT "materially influences" a decision. Commentators flag this as a central open question, and the attorney general has asked for input on it.
- What counts as "commercially reasonable" human review. Commentators flag this too. The redline would require reviewers who can override decisions and would drop the basic-human-need presumption.
- Vendor responsibility. The redline keeps deployers responsible when a third party runs the technology, and the attorney general has asked about employers relying on vendor AI.
Employers, lenders and landlords with compliance questions should take them to a lawyer. Individuals can raise any of these three issues in a written comment by October 26.
Where to Read the Colorado AI Law and Draft Rules
The legislature's bill pages list SB26-189 as Session Law Chapter 131 and HB26-1263 as Chapter 208. For more on the Colorado AI law in context, read the Ban the Bots explainers on AI regulation and on state versus federal AI regulation. To weigh in on the draft rules, find the rulemaking information on the Colorado Attorney General's AI page and send a written comment by October 26.
This explainer is general information about Colorado law and is not legal advice.
Frequently asked questions
▸ What is Colorado's AI law?
▸ When does the Colorado AI law take effect?
▸ Does Colorado's AI law cover chatbots?
▸ What is a consequential decision?
▸ How do I comment on the Colorado attorney general's AI rules?
▸ Can I sue under the Colorado AI law?
Latest related briefings
Trump’s Visa Crackdown: What It Means for U.S. Tech Workers
Trump’s visa crackdown could slow U.S. tech growth, limit job options, and affect families and students aiming for tech careers.
Read analysis REGULATION POLICYIndia’s AI Regulation Debate: What It Means for Daily Life
India’s new AI regulation consultation could change how millions work, learn, and protect their data. Here’s what families and workers should know.
Read analysis REGULATION POLICYAI Regulation Gaps Raise Alarms for Workers and Families
With AI regulation lagging, workers and families face risks to jobs, privacy, and rights. Calls for stronger rules are growing louder in 2026.
Read analysis