Subject to Both: Reconciling Colorado's AI Act With the EU AI Act
11 min read · updated August 11, 2026
The instinct when facing two AI statutes at once is to find the stricter one and build to it. That instinct is wrong here, and the reason is worth spelling out: Colorado and the EU do not differ in strictness. They differ in what they are about.
Two statutes with different shapes
Colorado Senate Bill 24-205 was signed on 17 May 2024 and codified in the Colorado Consumer Protection Act. Its original effective date was 1 February 2026; that date was moved during a special legislative session in August 2025, to 30 June 2026. The bill and its history are on the Colorado General Assembly’s site.
Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in tranches: prohibitions and AI literacy from 2 February 2025, general-purpose model obligations from 2 August 2025, the Annex III high-risk regime from 2 August 2026, and the Article 6(1) product route from 2 August 2027. The text is at EUR-Lex.
The structural difference is not tiering versus non-tiering, though that is how it is usually described. It is that the EU wrote a product safety statute and Colorado wrote a consumer protection statute. Every strange feature of each one follows from that. The EU has conformity assessment, notified bodies, CE marking, a public database, post-market monitoring and market surveillance authorities because that is what the New Legislative Framework does to any product. Colorado has a duty of reasonable care, a rebuttable presumption, an affirmative defence and enforcement exclusively by the Attorney General as a deceptive trade practice because that is what a consumer protection act does to any commercial conduct.
The trigger tests do not line up
Colorado’s trigger is functional. A high-risk artificial intelligence system is one that, when deployed, makes or is a substantial factor in making a consequential decision; a consequential decision is one with a material legal or similarly significant effect on the provision or denial to a consumer of, or the cost or terms of, education enrolment or opportunity, employment or employment opportunity, a financial or lending service, an essential government service, health-care services, housing, insurance, or a legal service. One test, applied to what the system does to a person.
The EU’s trigger is enumerative and then filtered. Annex III lists eight areas, and Article 6(3) then removes systems that do not pose a significant risk of harm to health, safety or fundamental rights, including where the system performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment, or performs a preparatory task — with the important exception that a system always counts as high-risk where it performs profiling of natural persons.
Overlay them and you get three regions rather than a subset relationship. The overlap is large: employment, credit, education, essential services and insurance appear in both. But Colorado reaches health-care services and legal services in terms that the EU handles through other instruments — medical devices, professional regulation — rather than Annex III. And the EU reaches biometrics, critical infrastructure, law enforcement, migration and the administration of justice, none of which is in Colorado’s consequential-decision list at all.
The pair that causes the most trouble is the filter. A system that scores applications and hands a ranked list to a human recruiter may plausibly fall within Article 6(3) as improving the result of a human activity or performing a preparatory task — a determination the provider must document and register under Article 6(4). The same system is squarely a “substantial factor” in a consequential decision under Colorado’s definition, which is drafted to catch assistance to a human decision-maker rather than only replacement of one. A team that concludes “not high-risk” once and applies that conclusion to both regimes has made the single most common error available here.
One is about discrimination; one is not
This is the difference that actually determines what you build, and it is the one most compliance mappings miss because it is not in the structure — it is in the theory.
Colorado’s entire operative duty is a duty of reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination, where algorithmic discrimination means unlawful differential treatment or impact disfavouring an individual or group on the basis of a protected classification. Everything else in the statute — the developer documentation, the deployer risk management programme, the impact assessment, the consumer notices, the Attorney General notification — is instrumentation for that one duty. If your system cannot discriminate, Colorado has very little to say to you.
The EU AI Act is not primarily a discrimination statute. Bias is addressed — Article 10(2)(f) and (g) require examination of possible biases and measures to detect, prevent and mitigate them, and Article 10(5) permits processing special categories of personal data where strictly necessary for bias detection and correction, subject to safeguards. But the Chapter III Section 2 requirements are dominated by things Colorado never mentions: a risk management system running across the lifecycle under Article 9, technical documentation under Article 11, automatic logging under Article 12, information to deployers under Article 13, human oversight designed into the system under Article 14, accuracy, robustness and cybersecurity under Article 15, and a quality management system under Article 17.
The consequence: a company that satisfies Colorado in full has done perhaps a third of the EU work and none of the conformity assessment. A company that satisfies the EU in full has strong evidence for Colorado’s reasonable care standard but has not necessarily done the specific things Colorado asks for, in particular the annual impact assessment and the consumer-facing notice and appeal machinery. Neither is a superset. Anyone who tells you the EU regime “covers” Colorado has compared the page counts rather than the duties.
Where the paperwork genuinely overlaps
There is real overlap, and it is worth exploiting because these artefacts are expensive.
- The system inventory. Both regimes require you to know which systems you have, what decisions they touch, and which role you occupy for each. Neither can be started without it, and it is the same document.
- Impact assessments. Colorado requires deployers to complete an impact assessment annually and within 90 days of an intentional and substantial modification. The EU’s nearest equivalent is the fundamental rights impact assessment in Article 27 — but note the asymmetry: Article 27 binds only deployers that are public bodies, private entities providing public services, and deployers of the creditworthiness and life and health insurance pricing systems in Annex III. A private employer deploying a hiring tool owes Colorado an impact assessment and does not owe an Article 27 FRIA. The document can be one document; the trigger cannot be one trigger.
- Recognised frameworks. Colorado’s rebuttable presumption of reasonable care and its affirmative defence are keyed to compliance with a nationally or internationally recognised risk management framework, naming the NIST AI Risk Management Framework and ISO/IEC 42001. The EU offers no such presumption from those frameworks — its presumption of conformity comes from harmonised standards under Article 40, which CEN-CENELEC JTC 21 is still producing. An ISO/IEC 42001 management system is worth building because it does most of the organisational work for both, but it buys a legal presumption in Colorado and buys nothing legally in the EU.
- Adverse-decision disclosure. Colorado requires a deployer that uses a covered system to make an adverse consequential decision to disclose the principal reasons, and to give the consumer an opportunity to correct incorrect personal data and to appeal for human review where technically feasible. The EU has two partial analogues: Article 26(11) requires deployers of Annex III systems making decisions about natural persons to inform them, and Article 86 gives a right to explanation of individual decision-making. GDPR Article 22 is a third layer with a different trigger again.
What to build if you are subject to both
The argument of this page is that you should build to the EU’s evidence requirements and to Colorado’s theory of harm, and treat the two as orthogonal axes rather than as more and less of the same thing.
Building to the EU’s evidence requirements means the artefacts exist and are current: a risk management file, technical documentation, logs retained for their required period, a record of the human oversight design, and a quality management system that says who does what. These are heavy and they are also what any regulator on either side of the Atlantic asks for first, because they are the only way to answer questions about a system after the fact.
Building to Colorado’s theory of harm means the discrimination question is asked as a first-class engineering question and not as a section of a compliance document: outcomes are measured by protected class where lawful to do so, disparities are investigated rather than noted, and the results are written down before anybody asks. That is also the material the EU’s Article 10 requires, so the work is not wasted — but the EU will not make you do it with the same urgency, and Colorado’s Attorney General notification duty on discovering algorithmic discrimination will.
Two things remain genuinely unresolved and should be watched rather than planned around. Colorado has been amended once already and further amendment has been actively pursued; the shape of the statute on its effective date is not certain. And federal preemption of state AI legislation has been proposed repeatedly in the United States and has not been enacted; if it ever is, the Colorado half of this analysis changes and the EU half does not. What would settle the first is the Colorado legislature; the second, Congress. Neither has, and a compliance plan that assumes either outcome is a bet rather than a plan.