Colorado's AI Act: the Documentation Deployers Must Keep
9 min read · updated August 11, 2026
Almost everything published about deployer documentation under the Colorado AI Act describes a regime that never came into force. The impact assessments, the risk management programme and the three-year retention rule attached to them were repealed in May 2026, before the statute’s twice-delayed effective date arrived.
The position as it now stands
Three legislative events, in order, and the dates are the whole story.
- SB 24-205, signed in May 2024, created the Colorado Artificial Intelligence Act at C.R.S. § 6-1-1701 et seq., with duties on developers and deployers of high-risk artificial intelligence systems and an original effective date of 1 February 2026. The Colorado General Assembly’s page for SB 24-205 carries the enacted text.
- SB 25B-004, signed on 28 August 2025 during a special session called to amend the Act, changed one thing: it moved the effective date to 30 June 2026. No substantive amendment passed. The bill page for SB 25B-004 records the history.
- SB 26-189, signed on 14 May 2026, repealed and reenacted the framework. It replaces the high-risk AI system model with an automated decision-making technology model, drops the duty of care against algorithmic discrimination together with the risk-management-programme and impact-assessment obligations, and sets an effective date of 1 January 2027. The bill page for SB 26-189 is the primary text.
So a deployer in Colorado in August 2026 is subject to neither regime: the first was repealed before it applied and the second does not apply until 2027. That is an unusual answer to give, and it is the correct one.
What SB 24-205 would have required
Worth knowing, because contracts signed in 2024 and 2025 reference it, because vendor questionnaires still ask about it, and because several other states drafted from it. The deployer duties sat in § 6-1-1703 and were built around a reasonable-care standard, with a rebuttable presumption of reasonable care available to a deployer that complied with the enumerated requirements. Those requirements generated documents:
- A risk management policy and programme governing the deployer’s use of high-risk systems, which had to be an iterative programme, regularly reviewed and updated, and reasonable in light of a recognised framework — the statute named the NIST AI Risk Management Framework and ISO/IEC 42001 as reference points.
- An impact assessment for each high-risk system, completed annually and within ninety days after any intentional and substantial modification, covering purpose and intended use cases, known or reasonably foreseeable risks of algorithmic discrimination and mitigations, categories of data used as inputs and produced as outputs, performance metrics and limitations, transparency measures and post-deployment monitoring.
- Retention of the most recent impact assessment, all records concerning it, and all prior impact assessments for at least three years following the final deployment of the system.
- Consumer notices before a consequential decision, and a statement of the principal reasons for an adverse one, with rights to correct input data and to appeal for human review where technically feasible; a public statement summarising the systems deployed; and notification to the Attorney General within ninety days of discovering that a system had caused algorithmic discrimination.
The design was explicit about why the paperwork existed: the records were how a deployer would establish the rebuttable presumption and support the affirmative defence if the Attorney General brought an action. Documentation was the defence, which is why the repeal changes more than a filing requirement.
What SB 26-189 requires instead
The replacement is a disclosure statute rather than a risk-management one. It regulates automated decision-making technology — broadly, technology that processes personal data to generate recommendations, rankings or scores used in decisions about an individual — where it is used in consequential decisions in areas including employment, housing, financial services, insurance, health care, education and government services.
For deployers, the obligations that generate records are these. Clear and conspicuous notice to the consumer that covered ADMT is or will be used in a consequential decision. Where the outcome is adverse, an understandable explanation, which the statute frames on a thirty-day basis. Rights for the consumer to access the personal data used, to correct factual inaccuracies in it, and to obtain meaningful human review to the extent commercially reasonable — which in turn requires designating people with the training and the authority to change the outcome. Developers separately owe deployers documentation on intended uses, categories of training data, known limitations and instructions supporting that human review.
On retention, the General Assembly’s own summary of SB 26-189 describes a duty on both developers and deployers to retain the records necessary to demonstrate compliance for at least three years. The period survives; what it attaches to does not. Enforcement remains with the Attorney General under the Colorado Consumer Protection Act, with no private right of action, and the Attorney General is directed to make rules ahead of the 1 January 2027 effective date — those rules, not the statute alone, will decide what a compliance record actually has to contain.
The gap between the two regimes
The two statutes ask for different evidence because they are aimed at different wrongs, and conflating them is the practical risk for anyone who built to the 2024 text.
SB 24-205 asked a deployer to prove it had managed a risk: the artefacts were assessments, mitigations and reviews, and their function was to show reasonable care before anything went wrong. SB 26-189 asks a deployer to prove it told the consumer and handled the consequences: the artefacts are notices, explanations, data access and correction records, and human review decisions, and their function is to show the process a particular individual received.
A file full of impact assessments does not demonstrate that a specific applicant got a notice and an explanation within thirty days. Nor does the reverse. If you built the 2024 artefacts, keep them — they are useful evidence in other forums — but do not assume they discharge the 2027 duties.
What a deployer should keep anyway
Colorado’s repeal removed one state’s documentation mandate. It did not remove the exposure the documentation was there to answer, and three of those survive untouched.
Federal anti-discrimination law is unaffected: Title VII, the ADEA and the ADA apply to a hiring outcome regardless of how it was produced, which is the ground being fought over in the Workday litigation. Other jurisdictions still impose the records — New York City’s bias audit and notice regime is in force and asks for a published audit, and Illinois and California have their own instruments. And a deployer operating in the EU faces deployer obligations under the AI Act that are closer in spirit to what Colorado repealed than to what replaced it.
A minimum that stays useful across all of those: which system version decided what, for whom, on what date; what the consumer was told and when; what data the decision used and where it came from; whether a human reviewed it, who, and with what authority to change it; and the reason the tool is fit for the decision it is being used for. That set is defensible under a disclosure statute, a discrimination claim and a European conformity file alike. It is also, not coincidentally, close to what SB 24-205 asked for — which is a reasonable clue that the drafters were not inventing the requirement out of nothing.