"An algorithm doesn't wake up one morning and decide to discriminate. But it can be trained on historical data that already reflects discrimination — and then faithfully reproduce those patterns at scale, faster and more invisibly than any human could."
That's the problem Colorado's SB 24-205 — the Artificial Intelligence Act (ADAI) — was written to address. The law targets high-risk AI systems: those that make or meaningfully influence consequential decisions about real people's lives in domains like hiring, lending, housing, insurance, healthcare, education, and legal services.
What the Law Requires
Colorado draws a line between two types of actors and assigns each distinct duties.
Developers — those who create or substantially modify high-risk AI systems — must use reasonable care to protect consumers from algorithmic discrimination. That means documenting known risks, providing deployers with meaningful information about the system's intended use and limitations, and maintaining records that support transparency.
Deployers — those who put high-risk AI systems to work in consequential decisions — carry the heavier operational burden. They must implement a risk management program, notify consumers when AI is used to make a consequential decision about them, provide a meaningful explanation of the outcome, and offer a path to appeal, correction, or human review.
The Colorado AG enforces the law. The original compliance date of February 1, 2026 was pushed to June 30, 2026 (SB25B-004), giving organizations additional runway — but the deadline is firm.
The 5-Question Compliance Check
Before June 30, 2026, every organization using AI in consequential decisions should be able to answer these questions honestly:
- Do we use AI in any consequential decisions — hiring, lending, insurance, healthcare, housing, education, government services?
- Have we documented what data trained those systems and what groups it may over- or under-represent?
- Do we test outcomes across protected classes — race, gender, age, disability — and track disparities over time?
- Can we explain a decision to someone affected by it in plain language, and offer them a meaningful path to appeal?
- Are our vendor contracts updated to require AI bias audits, disclosure of training data practices, and notification of model changes?
If any answer is "no" or "we're not sure," that's the gap to close before the deadline.
Colorado Isn't Alone
Colorado is the most comprehensive state AI fairness law to date, but it isn't operating in isolation. New York City's Automated Employment Decision Tools (AEDT) law has required independent bias audits and public audit summaries for hiring tools since July 2023. California applied existing civil rights law to AI systems, with enforcement effective October 1, 2025. And the federal EO directing agencies to challenge "burdensome" state AI regulations creates regulatory uncertainty — but Colorado's law remains in force.
What Organizations Should Do Now
- Inventory every AI tool that influences a consequential decision — including tools embedded in HR platforms, underwriting software, and patient intake systems
- Build an AI risk file for each high-risk system: purpose, training data sources, known limitations, outcome testing results
- Define escalation paths — who receives an appeal, how long review takes, what "human oversight" actually looks like in practice
- Update vendor contracts to require bias audit rights, training data disclosures, and notification when models are significantly updated
- Train decision-makers on how to explain AI-assisted outcomes to the people affected by them
What Individuals Should Know
If you live in Colorado and an AI system influences a decision about your job application, loan, insurance rate, or medical care, you have the right to know AI was used, receive a meaningful explanation, and request human review. You don't need a lawyer to ask — a written request to the company's privacy or compliance team is enough to start.
The compliance question is no longer "Can we use AI?" — it's "Can we prove it's fair?" Where does your organization stand today?
Privacy Pulse — where law, technology, and human dignity meet.