Colorado's attorney general proposed rules on August 11, 2026, to implement a revised AI law that imposes direct obligations on businesses that develop and deploy automated decision-making technology. The law, signed by Governor Jared Polis in May 2026, scraps the state's broader 2024 algorithmic discrimination framework and instead creates a hybrid regulatory model that reaches both upstream developers and downstream users of AI tools in consequential domains like employment, housing, and healthcare.
A third regulatory track emerges
Most state AI laws have followed two distinct paths. The first track targets developers of frontier AI models with safety, transparency, and audit requirements. Illinois, California, and New York have all enacted versions of this approach. The second track addresses specific generative AI use cases - chatbot safety, digital replicas, deepfakes, and synthetic content disclosures.
Colorado's SB 26-189 does not fit either category. Instead, it regulates the use of covered automated decision-making technology (ADMT) across multiple sectors and allocates compliance responsibilities between developers and deployers. This third track matters to a much broader set of organizations than frontier model laws, which apply only to a small group of companies building the most advanced systems, or narrow use-case laws that target discrete harms.
Connecticut followed a similar hybrid approach with its own AI law, SB 5, signed in May 2026. That law combines downstream employment-technology requirements with frontier model and synthetic content provisions. Other states, including New Jersey and South Carolina, have introduced comparable bills.
What developers must disclose
Under the proposed rules, developers of covered ADMT must provide deployers with documentation that includes intended uses, known harmful uses, categories of training data, known limitations, and instructions for monitoring and human review. Developers must also notify deployers of material updates or modifications within a reasonable time. These obligations apply only when the technology was marketed, advertised, or contracted for use in materially influencing consequential decisions.
What deployers must disclose
Deployers must provide consumers with clear notice before using covered ADMT to materially influence a consequential decision. When a consumer experiences an adverse outcome, the deployer has 30 days to deliver a plain-language description of the decision and the technology's role in it, instructions for requesting additional information, and an explanation of the consumer's rights under the law.
Consumers who experience adverse outcomes can request correction of factually incorrect personal data used in the decision and, where commercially reasonable, meaningful human review and reconsideration. The attorney general enforces violations through the Colorado Consumer Protection Act, with a 60-day cure period available through January 1, 2030, for violations the attorney general deems curable.
Fault allocation for discrimination claims
One of the law's most consequential provisions addresses liability in state anti-discrimination actions. A developer is liable only when its covered ADMT was used as intended, documented, marketed, or contracted and materially influenced a consequential decision that gave rise to the violation. A developer is not liable for violations arising from off-contract uses by the deployer. The law voids contractual indemnity for damages resulting from a party's own acts or omissions, though this does not apply to developers whose technology was used in an unintended manner and who met their documentation obligations.
This structure means proper documentation, contracting, and vendor management will be central to compliance. The law does not create joint and several liability except as permitted under existing law, and it does not create a new private right of action.
Why this matters for legal professionals
Colorado's law forces AI governance across the developer-deployer relationship rather than treating it as an upstream model-safety problem or an isolated end-user compliance exercise. Legal teams will need to review vendor contracts for ADMT tools, assess whether their organization's use of AI falls within the covered domains, and build processes for consumer notice, adverse-outcome response, and recordkeeping. The fault allocation framework also raises the stakes for due diligence: a deployer's off-contract use of a covered tool can shift liability entirely. For organizations navigating fragmented state requirements, AI for Legal training can help in-house counsel understand their defined roles and the contractual and technical controls that allocate responsibility across the AI supply chain. As more states model legislation on Colorado's approach, executives will also need AI for Executives & Strategy guidance to align compliance with business operations.
Your membership also unlocks: