Key point: The draft ADMT rules leave the law’s “materially influence” threshold undefined but propose two competing standards for it, while providing guidance on adverse outcome notices, multiparty AI arrangements, and consumer rights.
On August 11, 2026, the Colorado attorney general’s office filed draft rules with the Colorado Secretary of State to operationalize the Colorado Automated Decision-Making Technology (“ADMT”) Act (SB 189). The filing also included a notice of rulemaking hearing, which contains more information on the potential scope of the rulemaking. The filing of the draft rules triggers the formal rulemaking process. The attorney general’s office will accept written comments until, and hold a formal rulemaking hearing on, October 26, 2026. The office must finalize the rules by the law’s January 1, 2027 effective date.
The draft rules are notable as much for what they cover as what they do not. For example, the rules do not provide a definition for “materially influence” but the notice of rulemaking hearing identifies two different standards that the office is considering. This is a crucial aspect of the rulemaking process as the standard the office chooses (if any) will play a large role in the law’s applicability. The draft rules also briefly touch on multiparty arrangements, including the role of midstream developers (i.e., entities that integrate covered ADMT into their own covered ADMT products). This is a topic not addressed in the underlying law. The rulemaking hearing notice posits numerous questions on this topic, indicating that the office is trying to work through how the law should apply to the practical realities of the AI ecosystem and the different entities that play roles in it.
The draft rules also expand on the requirements for providing adverse outcome notices, including providing illustrative examples of the notices in sector-specific contexts. Finally, the draft rules address how companies must receive and respond to consumer requests, including how they must conduct a meaningful human review and when such a review is commercially reasonable.
In the article below, we first provide a brief overview of the law to provide the context for the draft rules. We then analyze the more notable provisions in the draft rules, including the issues raised in the notice of hearing.
The draft rules also operationalize HB 1263 – the Chatbot Safety Act – which the Colorado legislature passed earlier this year. However, the article below only analyzes the ADMT Act draft rules.
Background of the Law
Applicability
Signed into law on May 14, 2026, the ADMT Act repealed and replaced the existing Colorado AI Act with a framework that is significantly more business friendly. The crux of the law’s applicability is its definition of “covered ADMT,” which is defined as “automated decision-making technology that is used to materially influence a consequential decision.” The law defines each of these concepts.
The law defines ADMT broadly as “a technology that processes personal data and uses computation to generate output, including predictions, recommendations, classifications, rankings, scores, or other information that is used to make, guide, or assist a decision, judgement, or determination concerning an individual.” However, the definition excludes many activities such as anti-malware, calculators, networking, anti-virus, data storage, and spell-checking, among others.
“Materially influence” means “an ADMT output is a non-de minimis factor that is used in making a consequential decision” and “an ADMT output affects the outcome of a consequential decision, including by constraining, ranking, scoring, recommending, classifying, or otherwise meaningfully altering how a consequential decision is made.” It “does not include incidental, trivial or clerical uses.” This definition is vague, particularly because it does not define what constitutes a “non-de minimis factor.”
Finally, the law defines consequential decision as a decision, determination, or action made about a consumer that relates to the provision of or a consumer’s access to, eligibility for, selection for, or compensation for a covered domain or a decision, determination, or action about a consumer that relates to a differentiated price, cost sharing, compensation, or other material terms in a manner that is reasonably likely to materially limit, delay, effectively deny, or otherwise fundamentally alter the consumer’s access, eligibility, or opportunity for a “covered domain.”
The law applies to seven covered domains: (1) an education enrollment or an education opportunity; (2) employment or an employment opportunity that creates or may create an employer-employee relationship; (3) the lease or purchase of residential real estate in Colorado; (4) a financial or lending service; (5) insurance, including underwriting, pricing, coverage, claims adjudication, or other determinations that materially affect access to benefits; (6) health care services; and (7) essential government services and public benefits, including eligibility and renewal determinations.
Obligations
The law divides obligations between developers and deployers, with deployers bearing the primary burden. The law requires developers to provide certain information to deployers about the developer’s covered ADMT’s intended use, any known harmful or inappropriate uses, known limitations, and the categories of data used to train the covered ADMT.
Deployers have three obligations under the law: (1) keep certain records, (2) provide a pre-use notice, and (3) if the deployer’s use of the covered ADMT results in an adverse outcome to a consumer, provide the consumer with a post-adverse outcome disclosure and a limited right to access, correct, and obtain meaningful human review.
The law requires the attorney general to adopt rules on two topics: (1) post-adverse outcome disclosure requirements, and (2) requirements for human review following an adverse outcome from a covered ADMT. The law also gives the attorney general discretionary authority to adopt rules clarifying the “materially influence” standard, as well as broader permissive rulemaking authority over the law as a whole.
Analysis of the Draft Rules
Materially Influence
It is perhaps strange to start an analysis of the draft rules by focusing on a topic that is not actually in the draft rules, but that is where we will begin because it is a gatekeeping issue for the law’s applicability and the notice of hearing shows this is a topic the attorney general’s office clearly is wrestling with. As noted, the law applies where ADMT materially influences a consequential decision. However, the law’s definition of materially influence is vague, which is problematic because the definition is central to the law’s applicability.
Further, on its face, the law’s definition of materially influence departs from other similar-in-kind laws and regulations because it does not refer to the role of the human. For example, California’s ADMT regulations define ADMT as “any technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking.” Similarly, New York City Local Law 144 applies where the automated employment decision tool is used to “substantially assist or replace discretionary decision making for making employment decisions.” The role of the human also is a core concept in the Colorado Privacy Act’s profiling rules.
Although the draft rules do not provide a definition of materially influence, the accompanying notice of hearing identifies two different standards for this definition and asks for comments on them. This signals that, while a definition did not make it into the draft rules, it is a topic the office is looking to add to the final rules.
The first standard defines de minimis factor “as a factor that has only a trifling, trivial, or incidental impact on the outcome of a consequential decision.” Here, a factor is not a de minimis factor “simply because other factors played a more significant role” in the consequential decision. The standard sets out a four-factor analysis to determine when an ADMT output is a de minimis factor. Three of those four factors focus on the role of the human (called the consequential decision maker), including whether they reviewed the output, saw the primary evidence, and exercised independent judgment.
The second standard defines de minimis factor as a factor that “is not a substantial factor in the consequential decision.” Here, a factor can be a de minimis factor if “other relevant factors independent of the ADMT output played a significantly larger role in the consequential decision.” The standard sets out a five-factor analysis to determine when an ADMT output is a de minimis factor. As with the prior standard, three of the factors focus on the role of the human.
Both standards also state that it will be presumed that an ADMT output materially influenced a consequential decision “if it constrains an option set, sets a threshold, or produces a rank, score, classification, recommendation, prediction, or other inference that: (a) pertains to the individual about whom the decision is being made; (b) is reviewed by the decision-maker, or is used to screen data made available to the decision-maker, before or during the decision-making process; and (c) is consistent with the outcome of the consequential decision.” The presumption can be rebutted under certain circumstances although the circumstances differ depending on the standard. The first standard identifies five rebuttal factors, which focus on whether the factor was never considered by the decision maker or had little impact on the decision. The second standard requires a showing that there was an independent review, the outcome was consistent with that independent review, the human had the authority to make the decision, and the human was competent to make the decision.
Comparing the two standards, the first (trivial) standard is narrower (i.e., more use cases would not qualify as de minimis and therefore be subject to the law) and focuses on the role of only that factor. To be a de-minimis factor (and outside the scope of the law), the use of the ADMT would have to be trifling, trivial, or incidental to the outcome of the consequential decision. Stated differently, if the factor is not trivial, then it cannot qualify as de minimis. This standard focuses on the role of this single factor and not a comparison of this factor versus other factors used in the decision.
Comparatively, the second standard (not a substantial factor) is broader (i.e., more use cases would qualify as de minimis and therefore be excluded from the law) and focuses on the role the factor had among other factors. Here, to be de minimis, the factor must not be a substantial factor in the decision. The standard then looks to the role this factor plays as compared to other factors and states that this factor can be de minimis if other factors “played a significantly larger role” in the consequential decision. Further, one of the factors that must be considered is “whether the ADMT output played a significantly smaller role in the consequential decision than the other information.”
Finally, as noted, both standards also would inject the role of the human into the analysis, which is missing from the law’s text.
Ultimately, while this issue does not appear in the text of the draft rules, the attorney general’s decision on what standard to apply will have a significant impact on the entire scope of the law.
Pre-Use Notice
Another topic that the draft rules do not specifically address is the requirement in C.R.S. § 6-1-1704 for deployers to provide consumers with a “clear and conspicuous notice . . . that the deployer used or will use a covered ADMT in a consequential decision affecting the consumer and instructions regarding how the consumer may obtain the additional information described in” the law. The attorney general’s office is not required to promulgate rules on this topic; however, it was viewed as a potential candidate for rulemaking because other laws such as the CCPA’s ADMT regulations and the Illinois and Connecticut employment AI laws also require pre-use notices. That said, the draft rules do have general requirements for all consumer disclosures, such as requiring that notices use straightforward language and avoid technical or legal jargon. However, the office did not, for example, seek to align the law’s requirement with the requirements in the CCPA’s ADMT regulations.
Multiparty Arrangements
Another area the office is clearly wrestling with is how the Colorado ADMT Act should apply to the practical realities of how AI is developed and deployed. This comes up in two ways. First, in the notice of hearing, the office asks for comments on situations in which the deployer does not directly operate the ADMT that materially influences the consequential decision. An example of this in the employment context is where a company relies on an AI vendor’s technology to conduct resume screening and other tasks such as summarizing qualifications and interviews. Here, the company is the deployer, but it is just using the ADMT the AI vendor developed. As such, the company may not be in a position to create a pre-use notice or respond to a consumer request. The notice of hearing raises numerous questions on these (and related) topics under the concept that the office could promulgate rules to help clarify what entities should have what responsibilities and, perhaps, where deployers can rely on their vendors to comply with the law.
The second way this comes up is the role of midstream developers, which the draft rules define as “a party that integrates covered ADMT as a component into its own covered ADMT product and provides its covered ADMT product to another developer or a deployer.”
Under the draft rules, these entities would need to obtain all developer documentation created pursuant to the ADMT law’s requirements by developers of any covered ADMT used as a component of the midstream developer’s technology and make all upstream developer documentation available to any downstream deployer or developer.
Developer Obligations
As noted, developers’ sole obligation under the law is to provide documentation regarding the covered ADMT to deployers. The draft rules expand on these obligations somewhat, and the notice of hearing specifically identifies this as an area for which the office seeks comments. In particular, the office asks whether the topics in the rules should be expanded and whether the rules should identify the means by which the information should be provided.
Deployer Obligations: Adverse Outcome Notices
The ADMT Act provides that if a deployer uses a covered ADMT to materially influence a consequential decision that results in an adverse outcome for a consumer, the deployer must provide the consumer with a post-adverse outcome notice within 30 days of making the decision. The law specifically charges the attorney general’s office with adopting rules “to clarify and implement” this requirement, including sector-specific guidance or illustrative examples tailored to covered domains and guidance on how the requirement interacts with state and federal laws that also require notices.
The draft rules provide extensive guidance on this topic, including how deployers must provide the notice and its timing. With respect to the contents of the notice, the rules significantly elaborate on the law’s notice requirements, including fifteen illustrative examples. The draft rules also provide sector-specific guidance for the notices in the context of education, lease or purchase of residential real estate, financial or lending services, insurance, and employment. Finally, the rules explain how companies should operationalize the requirement to provide instructions and a simple-to-follow process to request more information about the covered ADMT and its inputs.
Deployer Obligations: ADMT Consumer Rights
If a consumer experiences an adverse outcome, the law allows the consumer to request that the deployer provide “instructions for requesting personal data and correcting factually incorrect or materially inaccurate personal data used in a consequential decision that used a covered ADMT consistent with section 6-1-1306” of the Colorado Privacy Act and “an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable.” The law requires the attorney general to adopt rules to clarify and implement this section.
The draft rules provide extensive guidance on how consumers may submit – and how deployers must handle – these requests. Deployers must offer at least two accessible, actively monitored submission methods (including a digital option where the deployer has an online presence, plus a toll-free number or mailing address). Consumers can request the specific personal data used in the consequential decision, including the ADMT’s output and underlying inputs. With respect to the right to correction, if a deployer lacks documentation supporting the data’s accuracy and did not collect it directly from the consumer, the consumer’s own assertion of inaccuracy is sufficient to establish inaccuracy, and, where possible, the deployer must stay the adverse outcome pending correction.
The draft rules explain how deployers should authenticate the identity of consumers making requests. Deployers must use commercially reasonable, risk-calibrated methods (industry-standard approaches like two-factor authentication generally suffice), while avoiding unnecessary data collection, deleting authentication data promptly, and not charging a fee. Deployers must respond within 45 days, and any denial must state specific grounds, explain the authentication efforts made if that is the basis for denial, and include instructions for appeal.
Notably, the draft rules do not discuss the law’s exemptions to these rights.
With respect to the right to meaningful human review, the rules explain the standard that deployers must use, including that an independent reviewer with access to relevant, available primary evidence and sufficient training conduct the review. The draft rules also address when reviews are “commercially reasonable.” Here, the assessment of the extent to which meaningful review is commercially reasonable must consider the: (1) type of review required; (2) magnitude of harm resulting from the adverse outcome; (3) reversibility of the adverse outcome; (4) value provided by the review of available primary evidence; (5) deployer’s size and capacity; (6) marginal cost and technical feasibility of the review; and (7) availability of qualified reviewers. Deployers bear the burden of demonstrating that meaningful human review is not commercially reasonable “using specific evidence.” The rules also provide three illustrative examples.
Finally, deployers must complete the meaningful human review and provide a consumer response within 45 days after the consumer submits the request. Deployers must provide an initial response to the request within ten days, confirming receipt and providing information about how they will process the request. Where possible, deployers should stay the adverse outcome pending the review.
Effective Date
The rules are effective January 1, 2027 – the date the Colorado ADMT law goes into effect.

