Colorado AI Act at Six Months: What Actually Got Enforced
Six months of Attorney General guidance, industry pushback, and settlement discussions have narrowed what 'reasonable care' means under Colorado SB24-205. A working line has emerged on consequential-decision scope, ADIA quality, notice mechanics, and the correction and appeal workflow. This is the programme that has consistently satisfied the AG — and the template other states are borrowing.

Colorado at Six Months: What the Real Enforcement Line Looks Like
Colorado SB24-205 — the Colorado AI Act — has now been operational long enough for enforcement priorities and industry practice to have converged on a working line, distinct from the plain statutory reading. Six months of Attorney General guidance, industry pushback, and quiet settlement conversations have given the AI-governance community a much clearer picture of what 'reasonable care' actually means when a real regulator is asking.
Colorado was the first US state to enact a comprehensive AI law aimed at algorithmic discrimination in consequential decisions. Its structure has since been borrowed by proposals in Texas, Connecticut, Virginia, and elsewhere. If you operate an AI system that touches lending, hiring, insurance, housing, education, or essential services in Colorado, the last six months set the template. If you operate in states considering similar laws, Colorado is the operational preview. This piece captures what the first six months actually taught.
What the Statute Actually Requires
The Act applies to developers (those who build or substantially modify high-risk AI systems) and deployers (those who use them to make consequential decisions). High-risk means an AI system that, when deployed, makes or is a substantial factor in making a consequential decision — meaning a decision that has a material legal or similarly significant effect on a consumer's access to education, employment, financial or lending services, essential government services, healthcare, housing, insurance, or legal services.
Developers must disclose enough information about the system for deployers to complete an impact assessment, warn about known limitations and reasonably foreseeable risks, and report to the AG any incident of algorithmic discrimination they become aware of. Deployers must implement a risk management policy, conduct impact assessments before deploying and annually thereafter, notify consumers when the system is used to make a consequential decision, provide an explanation and correction opportunity, and report algorithmic discrimination to the AG. The statute set the framework; the last six months set the meaning of each duty.
Enforcement Priority One: Consequential Decision Scope
The AG's early enforcement priorities have centred on scope disputes: is this system actually making a consequential decision, or is it advisory to a human who is? The statutory 'substantial factor' language sounds like a bright line but is not. Six months of practice has narrowed it.
The working definition: an AI system is a substantial factor in a consequential decision when a reasonable observer would conclude the human decisionmaker relied on the system's output as a primary input, not merely as one of many considerations. A hiring system that scores candidates and a human reviews the top scorers is in scope. A hiring system that generates data the human considers alongside interview notes and reference checks may not be. The line has been enforced most aggressively where the human oversight is theatrical — a reviewer approving 100+ decisions per day cannot credibly claim substantive review. Deployments that want to stay outside scope have to make the human process meaningful in evidence, not just in structure.
Algorithmic Discrimination Impact Assessments in Practice
The Act requires an ADIA (algorithmic discrimination impact assessment) before deployment and at least annually thereafter. The statutory content elements — purpose, benefits, categories of data used, disparate-impact analysis, safeguards, monitoring — read as a checklist. The AG's evaluation has focused on quality of evidence, not presence of headings.
ADIAs that have survived AG review share features: they name the specific decision the system contributes to, quantify performance disaggregated by relevant subgroup (race, ethnicity, sex, age, disability where lawful to collect), describe the training and validation datasets with provenance, document the human oversight mechanisms with named roles and specific override authority, and include a monitoring plan with alert thresholds and remediation ownership. ADIAs that failed AG review typically lacked disaggregated performance data, used third-party model outputs without provenance, or claimed human oversight that inspection found to be pro forma.
The Notice-to-Consumers Mechanics That Worked
The Act requires deployers to notify consumers before or at the time of the consequential decision that a high-risk AI system will be used, and provide specific information about the purpose and the nature of the decision. Six months has shaped what 'notice' means in practice.
Email or in-app notice at the moment of application (before the decision is made) is the accepted default. Notice buried in a terms-of-service update has been rejected. Notice via a linked policy document has been accepted only when the link is specifically flagged in the interaction, not one of many links in a footer. Notice in a language other than English has been required in Denver and other majority-Spanish-speaking areas — Colorado's laws around Spanish-language notice apply here, and the AG has enforced. The notice needs to include a specific description of the system's purpose and nature, and a plain-language explanation of the right to correction if the decision is adverse.
The Right to Correction — And Its Operational Cost
The Act's right to correction requires deployers to allow consumers to correct incorrect personal data used by the system and to appeal an adverse consequential decision. This has generated more operational load than any other provision.
Correction requests come in high volume when the notice is well-designed — consumers do exercise the right when they understand it exists. Handling requires the ability to identify what personal data went into the decision (not always trivial when the system is a black-box vendor model), verify the requester, evaluate the correction, and rerun the decision if the correction is accepted. Appeals require a human reviewer with authority to reverse the decision. Vendors of hiring, credit, and insurance AI systems have had to add correction and appeal APIs that deployers can integrate; deployers that use in-house models have had to build the correction workflow themselves. The successful deployments treat this as a product surface, not a compliance workflow — clear intake, tracked SLA, evidence trail.
The Definition of 'Reasonable Care' the AG Landed On
The Act's overarching duty is to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. What that means concretely has been refined through six months of AG guidance and settlement discussions.
The working definition of reasonable care includes: an inventory of AI systems in use, a risk management policy calibrated to those systems, ADIAs conducted before deployment and updated annually or on material change, consumer notice compliant with the notice mechanics, a correction and appeal workflow that functions, monitoring for disparate impact with alert thresholds, and an incident-response plan for detected discrimination. Absence of any of these has been treated as a breach of reasonable care. Presence of all of them, executed with evidence, has been treated as satisfying the duty even where an individual decision turned out to have disparate impact — the duty is care, not outcome.
The Small-Business Exemption and Its Limits
The Act includes an exemption for deployers with fewer than 50 full-time employees that meet certain conditions. The exemption is narrower than many assumed. It does not exempt developers regardless of size. It does not exempt deployers that use their own data to train or substantially modify a system — such modification tips them into developer obligations. And it does not exempt deployers whose system is deployed in a context (housing, insurance) with sector-specific rules that reach smaller operators.
Small deployers that assumed the exemption applied and did nothing are now, six months in, discovering that a system trained on their own data is a development activity and that the exemption does not cover them. The AG has been willing to work with small businesses in good-faith remediation, but the small-business exemption is not the escape hatch it was initially assumed to be. Confirm your scope by reading the specific exemption criteria against your actual operation, not against a summary of the Act.
How Colorado Interacts with the Federal Landscape
Colorado's AI Act does not preempt federal law, and where federal law occupies the field (EEOC guidance on hiring AI, FTC guidance on advertising claims about AI, CFPB action on lending AI), federal rules apply on top. Six months has produced a working reconciliation: federal rules set floors for specific practices, Colorado sets a broader duty of reasonable care and specific procedural obligations (ADIA, notice, correction), and compliance requires satisfying both.
For most deployers this means the Colorado programme is the anchor and federal rules are additional requirements layered on top for specific sectors. A hiring AI deployer needs the ADIA, the notice, the correction workflow — plus EEOC-aligned validation studies for any test with adverse impact. A lending AI deployer needs the same plus ECOA-aligned adverse action notices. The teams doing this well have built a single AI governance workflow that produces the union of required artefacts, rather than parallel workflows per authority.
The States That Are Copying (and What They're Changing)
Colorado's structure has been the template for several 2026 state proposals. Texas has advanced a variant that narrows the scope somewhat and includes stronger explicit-consent provisions for certain categories. Connecticut's proposal (still in flux at time of writing) extends the small-business exemption threshold and includes provisions specifically around generative AI. Virginia's proposal borrows most of Colorado's ADIA architecture but strengthens the consumer-facing appeal rights.
The common evolution: states are learning from Colorado's six months of enforcement and adjusting for what turned out to matter. Notice mechanics are getting more prescriptive. Correction and appeal workflows are getting explicit timelines. The 'consequential decision' scope is getting narrower and more precise in some states, broader in others. If Colorado is a preview, the takeaway is that the Colorado programme you build now will need customisation as each new state law takes effect — but the core inventory-ADIA-notice-correction spine will remain the foundation.
Reconciling with the EU AI Act
For businesses operating in both Colorado and the EU, the Colorado programme and the EU AI Act programme share more than they differ. Both require an inventory. Both require an impact assessment (ADIA in Colorado, FRIA in the EU). Both require notice to affected persons. Both require human oversight. Both require a monitoring plan. The differences are in specifics: EU requires database registration and conformity assessments that Colorado does not, and Colorado requires consumer correction rights that the EU AI Act does not.
The pragmatic pattern for multi-jurisdictional operators is a unified AI governance workflow with jurisdiction tags. A single inventory records each system's Colorado applicability, EU high-risk classification, and any other jurisdictional flags. A single impact-assessment template covers the union of required elements, and the output artefact is filtered per jurisdiction. This is genuinely one place where a well-built compliance workflow scales — the base activity is the same, and the jurisdictional layer is thin. See the EU AI Act high-risk deadline piece for the counterpart programme.
The Programme to Copy
For deployers building a Colorado AI Act programme now, or reworking one after six months of practice, here is the programme that has consistently satisfied the AG. Maintain a live inventory of AI systems in use with their intended purpose, developer, and consequential-decision classification. Run an ADIA before deployment and annually thereafter, with disaggregated performance data and named human-oversight mechanisms. Send consumer notice at the moment of application in a form that specifically flags the AI use. Provide a functional correction and appeal workflow with tracked SLAs. Monitor for disparate impact with alert thresholds and an incident response plan. Report algorithmic discrimination incidents to the AG within the prescribed window.
Beneath the programme sits a set of habits: read the AG's public guidance as it is issued; treat settlements with peers as case law; over-classify borderline systems as high-risk rather than under-classify; over-document reasoning rather than under-document. The compliance industry has spent six months learning what the Act really requires. If you use that learning, your programme will be defensible; if you rely on the plain text of the statute alone, you will fight enforcement battles others already lost.
Related articles
Automate your privacy compliance
See how TruePrivacy can handle DSRs, consent, and breach response — all in one platform.
Free 14-day trial · No credit card required · Setup in minutes