Colorado's AI Act: Enforcement Without a Private Right of Action
9 min read · updated August 11, 2026
Colorado’s AI Act creates duties of reasonable care for developers and deployers of high-risk AI systems, and then hands the entire job of enforcing them to one office. No consumer denied a loan or a job by a covered system can sue under the Act. That single design choice is what determines the shape of the compliance problem.
Who can bring a claim
Senate Bill 24-205, signed on 17 May 2024, added a new part 17 to article 1 of title 6 of the Colorado Revised Statutes — sections 6-1-1701 through 6-1-1707. The enforcement section, section 6-1-1706, does two things that are usually kept apart. It declares that a violation of the part is an unfair or deceptive trade practice under the Colorado Consumer Protection Act, which is how the Act borrows a remedy without writing one. And it gives the Attorney General exclusive authority to enforce, stating that the part does not create a private right of action. The Colorado General Assembly publishes the enrolled text of SB 24-205 and it is worth reading section 6-1-1706 rather than a summary of it, because the two halves interact in a way that surprises people.
The Colorado Consumer Protection Act does have a private right of action of its own, at section 6-1-113. A reader who sees “deemed an unfair or deceptive trade practice” often assumes the private route comes along with the label. It does not. The exclusivity language in section 6-1-1706 is what closes that door: the deceptive-trade- practice characterisation supplies the Attorney General’s remedies and penalty scale, not a cause of action for the individual affected.
How the Attorney General route works
Because a violation is treated as a deceptive trade practice, the remedies are the Consumer Protection Act’s remedies. That includes injunctive relief and civil penalties, with the ceiling in section 6-1-112 running to twenty thousand dollars per violation. What “per violation” means for a system that makes thousands of consequential decisions a day is not settled by the statute and has not been tested, and anyone quoting an aggregate exposure figure is multiplying an untested unit by a guessed count.
The Act also gives the Attorney General rulemaking authority over the documentation, the notices, the impact assessments and the affirmative defence in section 6-1-1706. That authority is more consequential than the penalty ceiling, because it is what will convert several deliberately open-textured phrases — “reasonable care”, “consequential decision”, “substantial factor” — into something a compliance team can build against. Until rules exist, a deployer is reasoning from statutory text alone.
The practical consequence of exclusive public enforcement is that exposure is lumpy rather than diffuse. A statute with a private right of action produces a steady stream of individual claims and, eventually, class actions; the cost arrives continuously and is roughly proportional to the number of affected people. A statute enforced only by an Attorney General produces nothing at all until an office with finite investigators opens a matter, and then produces a single concentrated event with an investigative demand, a document production, and usually an assurance of discontinuance. Compliance spending that would be irrational against the first pattern — heavy documentation, retained evidence, a defensible file — is exactly right against the second, because what you are buying is the ability to answer an investigative demand quickly and consistently.
The affirmative defence
Section 6-1-1706 also creates an affirmative defence for a developer or deployer that discovers and cures a violation through its own internal testing or red-teaming, and that is otherwise in compliance with a recognised risk management framework — the statute names the National Institute of Standards and Technology’s AI Risk Management Framework and ISO/IEC 42001, and permits the Attorney General to designate others by rule.
This is unusual drafting and it is easy to over-read. It is an affirmative defence, which means it is raised and proved by the party asserting it, after a violation has been alleged; it is not a safe harbour that keeps you out of scope. It also has two limbs, and adopting a framework satisfies only one of them. The other limb is that you found the problem yourself and fixed it. An organisation that certified against ISO/IEC 42001 and then learned of a discriminatory outcome from a complaint rather than from its own testing has half a defence.
The self-reporting duty
The part that most changes day-to-day behaviour is not the penalty; it is the duty in part 17 to notify the Attorney General when a developer or deployer discovers, or is informed by a deployer, that a high-risk system has caused or is reasonably likely to have caused algorithmic discrimination. The statute sets ninety days from discovery. Because enforcement is exclusively public, this duty is the main mechanism by which the enforcing office learns anything at all — there is no plaintiffs’ bar generating a docket for it to read.
That inverts the usual incentive analysis around internal testing. In a private-right-of-action regime, discovery of a problem creates documents a plaintiff can obtain. Here, discovery of a problem creates a reporting obligation to the only party that can act on it, and simultaneously creates the factual predicate for the affirmative defence — but only if the cure follows. The organisations that will do badly under this statute are the ones that test, find something, and do neither.
Where private exposure still comes from
“No private right of action” is a statement about this statute and nothing else. The conduct part 17 regulates is, in most cases, already actionable somewhere:
- Federal anti-discrimination law. A hiring or credit system producing disparate outcomes remains exposed under Title VII, the Age Discrimination in Employment Act, the Americans with Disabilities Act or the Equal Credit Opportunity Act, each of which has its own private route. See AI and hiring law and adverse action notices when a model denies credit.
- State anti-discrimination law. Colorado’s own Anti-Discrimination Act is untouched by part 17 and is not enforced exclusively by the Attorney General.
- Contract. The developer-to-deployer information duties in part 17 are, in practice, negotiated into supply contracts. A failure to supply what the statute requires becomes a breach claim between the parties even though neither can sue under the Act.
- The consumer-notice route. Part 17 requires notices to consumers about adverse consequential decisions and an opportunity to correct data and appeal. Getting those wrong tends also to get a general consumer-protection statute wrong, and those are not AG-exclusive.
So the correct reading of the exclusivity provision is narrow. It removes one channel of liability and concentrates another. It does not make an algorithmic discrimination problem cheap, and treating it as though it does is how a compliance programme ends up defending the wrong claim.
The effective date has already moved once, which matters for anyone budgeting against it: see the Colorado AI Act’s effective date for the current position and the legislative history behind it, and the split of duties between developer and deployer for what is actually being enforced.