Complete AI Training
Sign inGet my AI kit

Your job's AI kit

Get your AI kit

Tell us who you are and what you do. We show you your kit right away and email you the link: skills, prompts, AI agents, MCP servers and courses for your job.

500+ jobs ready, and we make a kit for any other job. No payment needed to look.

Share

AI news ·

Colorado reenacts AI law with expanded scope and focus on adverse outcomes

Colorado's reenacted AI law targets adverse automated decisions in six domains, requiring compliance by January 1, 2027. It replaces original high-risk rules with broader mandates.

Colorado reenacted its artificial intelligence law in May 2026, replacing the state's original high-risk AI system rules with a broader statute that targets adverse outcomes from automated decision-making in education, employment, housing, financial services, insurance, health care, and government services. Organizations doing business in Colorado must comply by January 1, 2027, requiring new governance structures to identify and manage AI-driven consequential decisions.

The reenactment follows months of revision and delay. Colorado first enacted its 2024 AI law with a February 2026 effective date, then pushed it to June 2026 while an AI Policy Working Group proposed changes. The working group's March 2026 recommendations led to the repeal of the original law and the passage of S.B. 26-189. A federal constitutional challenge to the original law, which the United States joined, was stayed pending the reenactment. The new statute shifts emphasis from regulating "high-risk" systems to policing adverse outcomes in specific domains.

Shift from High-Risk Systems to Automated Decision-Making Technology

The 2026 law abandons the "high-risk artificial intelligence system" definition in favor of automated decision-making technology. It defines the term as "a technology that processes personal data and uses computation to generate output, including predictions, recommendations, classifications, rankings, scores, or other information that is used to make, guide, or assist a decision, judgment, or determination concerning an individual." The definition excludes tools like anti-malware, calculators, databases, spell-checking, and web hosting, as well as any technology subject to an acceptable use policy that prohibits its use in consequential decisions. Organizations must evaluate each AI tool against these exclusions to determine whether it falls under the law.

The law also narrows the domains where AI decisions matter. It covers six "covered domains": education, employment, housing, financial services, insurance, health care, and government services and public benefits. Legal services, which appeared in the 2024 statute, was removed. A "consequential decision" is defined with two prongs: one covering access, eligibility, or compensation in a covered domain, and another addressing differentiated pricing or terms that are "reasonably likely to materially limit, delay, effectively deny, or otherwise fundamentally alter" access or opportunity.

The "Materially Influence" Test and Expanded Coverage

Colorado's new law uses a materially influence standard to decide which AI-driven decisions fall within its scope. An AI output materially influences a consequential decision when it is a "non-de minimis factor" in making the decision or when it "affects the outcome" by constraining, ranking, scoring, recommending, classifying, or otherwise meaningfully altering how the decision is made. This test sweeps more broadly than the original law's "substantial factor" test and goes beyond California's regulation, which only applies when AI "replaces" or "substantially replaces" human decision-making. The Colorado attorney general may adopt clarifying rules, but organizations cannot rely on a human-in-the-loop defense to sidestep the law if the AI meaningfully shapes the outcome.

The statute carves out nine exceptions for low-stakes or routine activities, including scheduling, classroom personalization, administrative routing, customer service triage, communication of decisions, and workflow management. Also excluded are uses for advertising, marketing, differentiated product recommendations, search, content moderation, cybersecurity, spam filtering, anti-money laundering, fraud prevention, and identity verification. These exclusions help focus the law on decisions that can deny, terminate, revoke, or materially reduce access to a covered domain.

Notice and Documentation Requirements

Deployers of covered AI technologies must provide advance notice to individuals about their use of automated decision-making and a post-adverse outcome notice when a decision materially harms someone. The adverse outcome notice must explain how AI was involved, tell the individual how to correct inaccurate information, and inform them of a right to request meaningful human review and reconsideration. As organizations deploy more automated decision-making technology, legal teams must understand when AI outputs materially influence consequential decisions and ensure compliance with these notice obligations. The Colorado attorney general must issue rules before the law takes effect to clarify disclosure requirements across different covered domains and their interaction with federal and state laws, such as the Fair Credit Reporting Act's existing notice mandates.

AI developers also face new obligations. Developers doing business in Colorado must document the intended uses of their systems, reasonably foreseeable harmful uses, categories of training data, limitations on the tool, and instructions for appropriate use, monitoring, and human review. While the requirement directly applies only to Colorado-based developers, the interconnected nature of AI supply chains means developers outside the state will likely need to supply similar documentation to customers who deploy AI in Colorado. Organizations procuring AI tools will request this documentation to satisfy their own compliance duties.

The Colorado reenactment accelerates the state-level regulatory patchwork that mirrors what happened with data-breach notification and privacy laws. Legal professionals advising businesses that use AI will need to build governance programs that identify in-scope decisions, document how AI is used, and deliver required notices. These governance frameworks must track evolving attorney general rules and decisions across all six covered domains. Professionals can deepen their expertise through the AI Learning Path for Regulatory Affairs Specialists, which covers policy automation and risk monitoring essential for meeting Colorado's mandate. The cost of non-compliance isn't just fines-it's the operational disruption of retrofitting compliance after an adverse outcome triggers scrutiny.

Share