Colorado AI Act — SB 24-205, repealed and replaced by SB 26-189
NOT IN FORCE. Enforcement of SB 24-205 was paused by a federal court on 2026-04-27 following a constitutional challenge by xAI in which the US Department of Justice intervened. SB 26-189, signed 2026-05-14, repeals it and re-enacts a narrower notice-and-disclosure regime for automated decision-making technology, effective 2027-01-01. The controls listed here describe the duties SB 24-205 imposed and are kept because organisations prepared against them; they are not current obligations, and no mapping to SB 26-189 has been done. Verified 2026-09-19.
11 controls, mapped to the evidence that satisfies each
| Control | Title | Requirement | Satisfied by |
|---|---|---|---|
| 6-1-1702 | Developer duty of care | Documentation of known harms and reasonably foreseeable misuse supplied to deployers. | D1 |
| 6-1-1702(2) | Developer documentation to deployers | Developers make available to deployers documentation describing intended and known harmful uses, training data summaries, known limitations, discrimination risks, and how the system should be used, not used, and monitored. | D1 |
| 6-1-1702(3) | Developer impact-assessment support | Developers make available to deployers, to the extent feasible, the artifacts (such as model cards or dataset cards) the deployer needs to complete its own impact assessment. | D1 |
| 6-1-1703(4)(a) | Consumer notice before a consequential decision | Deployers notify a consumer before a high-risk system is used to make, or substantially factor into, a consequential decision about them, in plain language and an accessible format. | D1 |
| 6-1-1703(5) | Deployer public risk-management statement | Deployers publish, on their website, the types of high-risk systems they deploy, how they manage discrimination risk, and the nature, source and extent of information collected. | D1 |
| 6-1-1704 | AI interaction disclosure | Deployers ensure a consumer is told they are interacting with an AI system, unless that would already be obvious to a reasonable person. | D1 |
| 6-1-1703(3) | Deployer impact assessment | Deployers complete an impact assessment for each high-risk system at least annually and within 90 days of a substantial modification, covering purpose, discrimination-risk analysis, data categories, performance metrics, transparency measures and post-deployment monitoring. | D2 |
| 6-1-1703(1) | Deployer duty of reasonable care | Deployers of a high-risk AI system use reasonable care to protect consumers from known or reasonably foreseeable algorithmic discrimination. | D4 |
| 6-1-1702(5) | Developer discrimination disclosure | A developer discloses to the Attorney General and to known deployers, without unreasonable delay, any known or reasonably foreseeable algorithmic discrimination risk it discovers or is credibly told about. | D6 |
| 6-1-1703(2) | Deployer risk management policy and program | Deployers implement and iteratively review a risk management policy and program specifying the principles, processes and personnel used to identify, document and mitigate discrimination risk. | D6 |
| 6-1-1703(4)(b) | Adverse decision explanation, correction and appeal | Where a consequential decision is adverse, deployers disclose the principal reasons and data sources, and give the consumer an opportunity to correct the data and appeal, with human review where technically feasible. | D6 |
What this mapping is, and what it is not
It is a reading of a published instrument, with each control cited to its source, mapped to the kind of evidence that would satisfy it. It is not legal advice, not a certification, and not a statement that any organisation complies with anything. Where an instrument is not yet in force, this page says so rather than selling urgency.