The Colorado Department of Law released proposed rules on August 11, 2026, that significantly expand the operational requirements of two AI statutes taking effect January 1, 2027. The rules, which cover the Automated Decision-Making Technology Act and the Chatbot Safety Act, go beyond the statutes' disclosure and consumer-rights framework to demand decision-level explainability, data-source traceability, and staffed human-review processes.
The comment period runs through October 26, 2026, with a public rulemaking hearing that same day. Comments submitted by September 4 will be considered for a revised draft, with interim updates expected by September 23. The Department has also specifically asked for public input on how to define when automated decision-making technology "materially influences" a consequential decision.
Scope of the two laws
The ADMT Act governs automated decision-making technology used in consequential decisions affecting access to education, employment, housing, financial services, insurance, health care, and essential government services. In employment, "consumer" includes Colorado-resident employees and job applicants.
The Chatbot Safety Act targets general-purpose, consumer-facing conversational AI services. It imposes age-estimation, disclosure, minor-protection, crisis-response, and annual-reporting duties. Rulemaking is mandatory for the ADMT Act but discretionary for the Chatbot Safety Act; the Attorney General chose to address both in the same package.
The proposed rules carve out ordinary infrastructure and certain low-risk functions from ADMT coverage, including routing, translation, summarization, scheduling, customer-service triage, advertising, marketing, search, and content moderation.
Material influence and adverse outcome notices
The most consequential unresolved issue is when ADMT "materially influences" a decision. Rather than adopting a single definition, the Department proposes two possible standards and asks the public which to adopt. Both versions include a rebuttable presumption of material influence where an output constrains options, sets a threshold, or produces a rank or score related to the individual, and is reviewed by the decision-maker or used to screen data the decision-maker sees.
Under the proposed rules, deployers must provide detailed disclosures within 30 days when covered ADMT materially influences an adverse outcome. Notices must identify the decision, explain the ADMT's purpose, describe the roles of the ADMT and human reviewers, and state the principal reasons for the outcome with specificity. Generic references to internal policies would not suffice.
Additional explanation is required when a decision relies on an inference, profile, risk score, automatic-denial factor, or incomplete information. This could prove difficult in applicant-screening, lending, housing, and insurance contexts where systems automatically screen out incomplete applications.
Consumer rights and human review
Deployers would need to make detailed system information available to consumers, including the system name and version, the developer, and the types and sources of personal data used. Where data came through an intermediary, the deployer may need to identify both the intermediary and the original source - a requirement that could strain relationships with data brokers and aggregators.
The proposed rules would make human review a staffed, documented process. Reviewers must be independent of the original decision-maker where feasible, trained, authorized to change the outcome, and able to conduct the review without ADMT assistance. Deployers would need to acknowledge human-review requests within 10 days and complete reviews within 45 days, staying the adverse outcome where possible.
Chatbot operator obligations
Covered chatbot operators would face age-assurance requirements that go beyond self-declaration. Government-issued identification could not serve as the sole verification method, and operators would need to reassess age when new signals indicate a different likely age. Operators must also report metrics on age distributions, age-estimation methods, crisis-referral outcomes, and resolution times.
Internal-only workforce deployments behind authentication appear to fall outside the general-public scope, and narrow task-specific bots may remain outside the Act where limited to bounded functions.
Practical implications for compliance teams
Organizations using ADMT in covered domains should expect compliance work extending well beyond legal and privacy teams. The proposed rules require participation from product, HR, risk, compliance, data governance, security, and vendor management.
Key steps include inventorying covered use cases, mapping vendor systems and data inputs, confirming whether outputs materially influence decisions, building adverse-outcome notice templates, creating consumer-request workflows, negotiating vendor support for decision-level explanations, and designating trained human reviewers. For legal professionals tracking regulatory developments, AI for Legal covers how these requirements affect compliance obligations. Government professionals can find relevant analysis under AI for Government, given the rules' impact on essential services and public benefits.
Why this matters for legal, government, and IT professionals
The proposed rules suggest Colorado's AI framework will demand significantly more compliance infrastructure than the statutes alone indicate. Organizations should use the comment period to assess compliance gaps, engage vendors, and identify requirements that may be difficult or impossible to implement as drafted. The September 4 deadline for comments to be considered in a revised draft is the first practical milestone.
Your membership also unlocks: