Frameworks / CO_SB24_205

Colorado AI Act — SB 24-205, repealed and replaced by SB 26-189

State of Colorado · US-CO · effective 2027-01-01 · CO_SB24_205 · not in force

NOT IN FORCE. Enforcement of SB 24-205 was paused by a federal court on 2026-04-27 following a constitutional challenge by xAI in which the US Department of Justice intervened. SB 26-189, signed 2026-05-14, repeals it and re-enacts a narrower notice-and-disclosure regime for automated decision-making technology, effective 2027-01-01. The controls listed here describe the duties SB 24-205 imposed and are kept because organisations prepared against them; they are not current obligations, and no mapping to SB 26-189 has been done. Verified 2026-09-19.

11 controls, mapped to the evidence that satisfies each

Every control links to the dimension whose evidence would satisfy it. That mapping is the working link between an obligation written in law or a standard and a document somebody has to produce. Each row has its own address: link to a single control.
ControlTitleRequirementSatisfied by
6-1-1702Developer duty of careDocumentation of known harms and reasonably foreseeable misuse supplied to deployers.D1
6-1-1702(2)Developer documentation to deployersDevelopers make available to deployers documentation describing intended and known harmful uses, training data summaries, known limitations, discrimination risks, and how the system should be used, not used, and monitored.D1
6-1-1702(3)Developer impact-assessment supportDevelopers make available to deployers, to the extent feasible, the artifacts (such as model cards or dataset cards) the deployer needs to complete its own impact assessment.D1
6-1-1703(4)(a)Consumer notice before a consequential decisionDeployers notify a consumer before a high-risk system is used to make, or substantially factor into, a consequential decision about them, in plain language and an accessible format.D1
6-1-1703(5)Deployer public risk-management statementDeployers publish, on their website, the types of high-risk systems they deploy, how they manage discrimination risk, and the nature, source and extent of information collected.D1
6-1-1704AI interaction disclosureDeployers ensure a consumer is told they are interacting with an AI system, unless that would already be obvious to a reasonable person.D1
6-1-1703(3)Deployer impact assessmentDeployers complete an impact assessment for each high-risk system at least annually and within 90 days of a substantial modification, covering purpose, discrimination-risk analysis, data categories, performance metrics, transparency measures and post-deployment monitoring.D2
6-1-1703(1)Deployer duty of reasonable careDeployers of a high-risk AI system use reasonable care to protect consumers from known or reasonably foreseeable algorithmic discrimination.D4
6-1-1702(5)Developer discrimination disclosureA developer discloses to the Attorney General and to known deployers, without unreasonable delay, any known or reasonably foreseeable algorithmic discrimination risk it discovers or is credibly told about.D6
6-1-1703(2)Deployer risk management policy and programDeployers implement and iteratively review a risk management policy and program specifying the principles, processes and personnel used to identify, document and mitigate discrimination risk.D6
6-1-1703(4)(b)Adverse decision explanation, correction and appealWhere a consequential decision is adverse, deployers disclose the principal reasons and data sources, and give the consumer an opportunity to correct the data and appeal, with human review where technically feasible.D6

What this mapping is, and what it is not

It is a reading of a published instrument, with each control cited to its source, mapped to the kind of evidence that would satisfy it. It is not legal advice, not a certification, and not a statement that any organisation complies with anything. Where an instrument is not yet in force, this page says so rather than selling urgency.

Talk to the person who built this

If you assess clients against this instrument, the mapping is the part you can check line by line. There is no sales team: this is founder-led, so it reaches the founder directly. Tenant access is $500 a month, and free early access to the method, the corpus and the router is on offer first if that is useful. If it is not a fit, saying so costs you one reply.

Start a conversation

What are you trying to show, and to whom — an auditor, a client, a regulator, your own board?

Your address is used to reply and nothing else. It is not published, not sold, and not added to a mailing list.

Colorado AI Act: 11 controls, each cited