Colorado’s AI Act: the Separate Developer and Deployer Duties
10 min read · updated August 11, 2026
Coverage of Colorado’s AI Act usually describes one undivided set of duties. The statute has two, they attach to different parties for different reasons, and the most expensive mistake available under this Act is assuming you are only in one of them.
Two roles, defined by what you did
Senate Bill 24-205 defines a developer as a person doing business in Colorado that develops, or intentionally and substantially modifies, an artificial intelligence system. A deployer is a person doing business in Colorado that deploys a high-risk artificial intelligence system. The enacted text is at the Colorado General Assembly.
Neither definition turns on the size of the company or on whether it trained anything from scratch. The developer definition turns on whether you built or substantially modified the system; the deployer definition turns on whether you put a high-risk system into use in a consequential decision. A company that fine-tunes a third-party model and uses it to screen applicants is squarely both, and owes both sets of duties simultaneously.
What a developer owes
The developer section imposes the reasonable-care duty and then lists what a developer must provide to satisfy the presumption that it met it. The obligations sort into three groups.
Documentation to the deployer. Before making the system available, and updated as it changes, a developer must give deployers a general statement describing the reasonably foreseeable uses and known harmful or inappropriate uses; high-level summaries of the type of data used to train the system; known or reasonably foreseeable limitations, including known or reasonably foreseeable risks of algorithmic discrimination arising from intended uses; the purpose of the system, its intended benefits and uses; and any other documentation reasonably necessary for a deployer to understand the outputs and monitor performance for risks of algorithmic discrimination.
Documentation to support an impact assessment. Separately, the developer must make available the documentation a deployer needs to complete its own assessment: how the system was evaluated for performance and mitigation of algorithmic discrimination before being offered; the data governance measures used to cover training datasets and to examine their suitability, possible biases and appropriate mitigation; the intended outputs; the measures taken to mitigate known or reasonably foreseeable risks; and how the system should be used, not used, and monitored when it is used to make or is a substantial factor in making a consequential decision.
Public and regulator-facing duties. The developer must publish on its website a statement summarising the types of high-risk systems it has developed or currently makes available, and how it manages known or reasonably foreseeable risks of algorithmic discrimination, kept accurate. And it must disclose to the Attorney General, and to known deployers or other developers, any known or reasonably foreseeable risk of algorithmic discrimination arising from the intended uses, within ninety days after discovering it or after receiving a credible report from a deployer.
The last one is the sharpest edge in the developer column. Ninety days runs from a credible report received, not from your own confirmation of it, which means a developer needs an intake path for deployer reports and a decision record showing when the clock started.
What a deployer owes
The deployer section imposes the same reasonable-care duty and then lists a different set, oriented around the individual affected rather than around the supply chain.
- A risk management policy and programme governing the deployment, which must specify the processes and personnel used to identify and mitigate algorithmic discrimination, and must be reasonable in view of a recognised framework — the statute names the NIST AI Risk Management Framework and ISO/IEC 42001, or another nationally or internationally recognised framework, or one designated by the Attorney General. It must be an iterative programme planned and reviewed over the system’s life cycle.
- An impact assessment, annually and within ninety days of an intentional and substantial modification, with enumerated contents and a three-year retention period. This has its own page.
- Notice to the consumer before or at the time the system is used to make, or be a substantial factor in making, a consequential decision — including the purpose and the nature of the decision, the deployer’s contact details, a plain description of the system, and information about the right to opt out of profiling under the Colorado Privacy Act where applicable. The required contents are set out in the consumer notice page.
- Adverse-decision disclosure and remedy. Where the decision is adverse to the consumer, the deployer must state the principal reason or reasons, including the degree to and manner in which the system contributed, the type of data processed and its source; give an opportunity to correct incorrect personal data the system processed; and give an opportunity to appeal for human review where technically feasible.
- A public statement on the website summarising the types of high-risk systems currently deployed, how known risks are managed, and the nature, source and extent of information collected and used.
- Notification to the Attorney General within ninety days of discovering, through the required monitoring, that the system has caused algorithmic discrimination.
The small-deployer exemption relieves a deployer with fewer than fifty full-time equivalent employees of the risk management programme, the impact assessment and the website statement, on conditions — notably that it does not use its own data to train the system. It does not relieve the reasonable-care duty, the consumer notice, or the adverse-decision disclosure. That distinction is frequently reported wrongly.
The modification rule that puts you in both
Because “developer” includes a person who intentionally and substantially modifies an AI system, and “intentional and substantial modification” means a deliberate change that materially increases the risk of algorithmic discrimination, an organisation that adapts a purchased model can cross into the developer column without buying anything or shipping anything to a customer.
The consequences are not symmetrical with what it already had to do. A company in both roles owes the developer’s documentation duties — but to whom, when the only deployer is itself? The statute does not answer that cleanly, and it is one of the genuinely unresolved points in the Act. The conservative reading is that the documentation must exist and be capable of production, because the public statement duty and the ninety-day Attorney General disclosure duty attach to the developer role regardless of whether there is an external deployer to give it to. A narrower reading is that the disclosure obligations are conditioned on making the system available to others and do not attach to purely internal modification. Absent rulemaking or a decision on the point, both readings are arguable and the difference is the website statement and the regulator notification — neither of them trivial.
What this means for the contract
The Act does not permit either party to contract out of its duties, but it does make one party’s compliance depend on the other’s documents. A deployer cannot complete an impact assessment without the developer’s data-governance, evaluation and intended-use material, and cannot meet the ninety-day modification trigger without notice that a modification happened.
The clauses that follow are therefore practical rather than defensive: a warranty that the developer’s Colorado documentation set will be provided and kept current; a notification obligation for any intentional and substantial modification, with enough lead time to run an assessment inside ninety days; a right to the developer’s evaluation results rather than a summary of them; and a defined channel for the deployer to make a credible report of discrimination, since that report starts the developer’s own clock. General drafting guidance is in the AI contract clauses page.