· Last updated: October 9, 2026
Colorado's Attorney General holds a formal rulemaking hearing on October 26, 2026, and written comments close that night. It is the last big checkpoint before the state's rewritten AI law starts on January 1, 2027. If your business uses AI to make "consequential decisions" about Colorado consumers in employment, lending, housing, healthcare, insurance, education, or essential government services, this is the date to plan around.
Here is why there is confusion. Colorado passed a sweeping AI Act in 2024, then spent most of 2026 unwinding it. xAI sued the state in April, a federal court suspended enforcement within weeks, and on May 14 the governor signed a bill that repeals the original law and replaces it with a narrower one. If what you know about Colorado's AI law is more than a few months old, it is probably out of date.
How we got here
- 2024: Colorado enacts SB 24-205, the original Colorado AI Act. It requires developers and deployers of "high-risk" AI systems to use risk-management programs, run impact assessments, and exercise reasonable care to prevent algorithmic discrimination. Its original start date was February 1, 2026.
- August 28, 2025: SB25B-004, signed in a special session, pushes the original law's effective date to June 30, 2026.
- April 9, 2026: xAI sues Colorado in the U.S. District Court for the District of Colorado (X.AI LLC v. Weiser). Law-firm summaries list four grounds: the law compels speech and regulates protected AI design (First Amendment), it reaches conduct outside the state and burdens interstate commerce, its terms are unconstitutionally vague (due process), and its carve-outs amount to unequal treatment (equal protection).
- April 24, 2026: The U.S. Department of Justice moves to intervene. The same day, xAI and the Attorney General file a joint motion to suspend enforcement.
- April 27, 2026: The court grants the joint motion and suspends enforcement of the original law.
- May 14, 2026: Governor Polis signs SB 26-189. Its official title is "Concerning the use of automated decision-making technology in consequential decisions." It repeals and reenacts the 2024 AI provisions as the Automated Decision-Making Technology Act (ADMT Act). The duty of care, the risk-management programs, and the impact assessments are gone. A disclosure-and-transparency framework takes their place.
- August 11, 2026: The Attorney General files draft implementing rules (4 CCR 904-6) for public comment.
- October 6, 2026: The Attorney General's office releases a revised draft of the rules.
- October 26, 2026: Formal rulemaking hearing. Written comments close at 11:59 p.m. Mountain Time, and the comment period runs longer if the hearing continues.
- January 1, 2027: The statute's main duties begin. The Attorney General is required to have the rules adopted by then.
What the ADMT Act requires
The new law is narrower than its predecessor, but it still adds real work. Two groups have separate duties.
Developers must give deployers documentation covering:
- the system's intended uses and known harmful or inappropriate uses
- the categories of training data
- known limitations and risks
- instructions for appropriate use, monitoring, and meaningful human review
Developers must also tell deployers about material updates. Both developers and deployers must keep compliance records for at least three years.
Deployers are the businesses using the AI to decide things about consumers. Before using covered ADMT in a consequential decision, they must give a clear notice that the tool is in use. A prominent public notice can satisfy this if it is accessible where consumers interact with the business. After an adverse outcome, a deployer has 30 days to give the consumer a plain-language description of the decision and the ADMT's role in it.
Consumers can, after an adverse outcome, ask how to access their personal data and correct inaccurate information. They can also ask for meaningful human review and reconsideration, to the extent that is commercially reasonable.
If you handle consumer data in Colorado more broadly, remember that the ADMT Act is separate from the Colorado Privacy Act. Our Colorado Privacy Act guide covers that law.
Enforcement
Only the Colorado Attorney General can enforce the Act, under the Colorado Consumer Protection Act, so violations are treated as deceptive trade practices. The Act creates no private right of action. It does, however, address how fault is divided between developers and deployers in existing discrimination lawsuits, so it is not irrelevant to private litigation.
Before January 1, 2030, the Attorney General must generally give 60 days' notice and a chance to cure where a cure is possible. One law-firm summary notes that no cure right applies to knowing or repeated violations.
What the draft rules add
The August 11 draft fills in operational detail the statute leaves open. These timelines come from the August draft, and the October 6 revision changed the rules on adverse-outcome contents, reviewer standards, and how consumer rights are structured. Check the current text before you build processes around a specific number.
- Data and correction requests: 45 days to respond after receipt.
- Human review requests: 10 days to acknowledge, and 45 days to complete the review and respond.
- Adverse-outcome notices: they must explain the decision, the ADMT's role, any human involvement, and the principal reasons, and the draft includes sector-specific guidance and examples.
- Vendors and midstream developers: the draft creates a "midstream developer" role for a party that builds third-party covered ADMT into its own product. It must pass upstream documentation along to deployers and other developers.
The Attorney General's hearing notice also asks for comment on deployers that rely on vendor-built tools, such as AI resume screening. The draft does not define a separate "ADMT vendor" term, and how responsibility is split between deployer and vendor is still under discussion. If you buy AI for hiring or lending rather than building it, watch this closely. The draft also leaves "materially influence" open and asks for comment on competing standards.
The litigation wildcard
The April stay was granted against the original law. According to several law-firm summaries, it also covers successor legislation such as SB 26-189. We could not read the order itself, so confirm the exact wording on the docket.
Those summaries describe the sequence like this. xAI must file its preliminary injunction motion within 28 days after the state finalizes its rules. Enforcement stays suspended until 14 days after the court rules on that motion. The Attorney General has also said he does not intend to enforce the original law or its successor until rulemaking is complete.
The case is stayed, not dismissed, and it remains pending. In practice, the statutory date of January 1, 2027 and the date enforcement can really begin may differ. Plan for January 1, and check the docket before you treat either date as firm. For the federal angle, see our guide to the Trump AI executive order and state-law preemption.
What businesses should do now
- Comment by October 26 if the vendor-responsibility question affects you. It is the part of the draft rules most open to change.
- Inventory where you use AI for consequential decisions. Employment, lending, housing, healthcare, insurance, and education are the likeliest categories.
- Draft your pre-use notice now. A prominent public notice can satisfy the requirement, but it needs to exist before January 1, 2027.
- Build the 30-day adverse-outcome explanation process, including a plain-language template. This is a new workflow, not a policy tweak. Our AI risk and compliance guide can help you place it in your wider program.
- Talk to your AI vendors early about who handles notice, documentation, and human review once the vendor rules settle.
- Do not reuse old CAIA work as-is. The duty of care and impact-assessment requirements are gone, so rebuilding around disclosure is a different job.
How Colorado compares
Colorado's ADMT Act is lighter than the original law it replaced. It reads more like a disclosure regime than a risk-management mandate.
California's CPPA regulations on automated decisionmaking technology are effective January 1, 2026, but businesses using ADMT for significant decisions must comply starting January 1, 2027. Risk-assessment duties began January 1, 2026. Those rules include pre-use notice, opt-out, and access rights. The two states' ADMT start dates therefore land on the same day. Read our CPRA ADMT regulations guide for the California side.
Colorado's retreat from the duty-of-care model may signal where other states land. For a broader view, see our California AI regulations guide and our overview of New York's AI law package.
Compliance checklist
▢ Decide whether you are a developer, a deployer, or both under the ADMT Act
▢ Inventory AI systems used for consequential decisions
▢ Draft and publish a pre-use notice before January 1, 2027
▢ Build a 30-day adverse-outcome explanation process and template
▢ Review vendor contracts for notice, documentation, and human-review duties
▢ Submit public comment by October 26, 2026 if the vendor question affects you
▢ Confirm three-year compliance-record retention
▢ Track the Attorney General's final rules and the xAI docket
FAQ
Is the original Colorado AI Act still in effect?
No. SB 26-189 repealed and reenacted it on May 14, 2026. A federal court had already suspended its enforcement after xAI sued.
When does Colorado's new AI law take effect?
The main duties start January 1, 2027, and the Attorney General must adopt the implementing rules by then. The formal hearing is October 26, 2026. Enforcement may begin later, depending on the rulemaking and the xAI case.
Does the ADMT Act require risk assessments like the original law did?
No. The duty of care, the risk-management programs, and the impact assessments were removed. The ADMT Act focuses on notice, transparency, and consumer rights, including human review.
Can consumers sue under the ADMT Act?
No. Only the Colorado Attorney General can enforce it, and there is no private right of action.
What should I do if I use a third-party AI vendor for hiring or lending decisions?
Watch how the final rules split responsibility between deployers and vendors, since that question is still open for comment. Start the contract conversation with your vendor now.
Tracking AI rules that states rewrite mid-year is a moving target. Our AI governance guide is built to help. Book a demo to talk through your consequential-decision AI exposure across Colorado, California, and other states.



