Colorado · AI Laws

Colorado ADMT Act (SB 189): Requirements, Exemptions and Deadlines

What Colorado ADMT Act requires, maintained by Stauss PLLC. Last reviewed July 2026.

What You Need to Know

SB 189 repeals and replaces the 2024 Colorado AI Act with a disclosure-based regime — no duty of care, no risk management programs, no impact assessments. What remains for deployers is a pre-use notice, a 30-day post-adverse-outcome disclosure, three-year recordkeeping, and access, correction and human review rights that trigger only after an adverse decision. But whether you are covered at all turns on a chain of nested definitions, and “consumer” reaches beyond Colorado residents to anyone whose opportunity in Colorado is evaluated by a business operating there. It takes effect January 1, 2027.

Official law text
Key dates6
DateWhat happens
June 16, 2026Attorney general opened pre-rulemaking
July 13, 2026Informal public input closed
End of summer 2026Draft rules and formal notice-and-comment expected
January 1, 2027SB 189 takes effect, applying to consequential decisions made on or after that date
January 1, 2027Attorney general rules on post-adverse-outcome disclosures and human review due
January 1, 203060-day right to cure sunsets
Background

The Colorado AI Act (SB 205) became law in May 2024 as the first state law to create obligations for developers and deployers of high-risk AI systems — systems that make, or are a substantial factor in making, consequential decisions affecting employment, housing, health care, financial services and other high-stakes areas. It imposed a duty to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination, backed by risk management programs, impact assessments, annual reviews, and disclosure obligations running from developers to deployers and from deployers to consumers.

The law was set to take effect February 1, 2026, but came under sustained pressure. The 2025 regular session considered amendments and reached no agreement. An August 2025 special session extended the effective date to June 30, 2026 and did nothing else. In October 2025 Governor Polis appointed a workgroup to draft revisions; in March 2026 he announced it had agreed a framework to replace the Act outright. SB 189 was introduced, passed both chambers and was signed in May 2026.

The New Framework

SB 189 is substantially more business-friendly than the law it replaces. It removes the high-risk AI system framework, the algorithmic discrimination provisions, the duty of care and its rebuttable presumption, risk management programs, impact assessments, annual reviews, attorney general notices, and the requirement to disclose that a consumer is interacting with an AI system.

In their place is a disclosure regime built around a new term. "High-risk AI system" is gone; the operative concept is now automated decision-making technology, or ADMT. Developers owe documentation to deployers. Deployers owe a pre-use notice, a post-adverse-outcome disclosure within 30 days, three-year recordkeeping, and a limited set of consumer rights that arise only when a decision goes against someone.

The tradeoff is complexity. The bill carries many intertwined definitions and numerous exceptions, and the practical question for most businesses is not what the obligations are but whether they apply at all.

What Counts As Covered ADMT

The pivotal phrase is "covered ADMT" — automated decision-making technology used to materially influence a consequential decision. Each element carries its own definition, and each of those definitions carries further qualifications.

ADMT itself is defined broadly: technology that processes personal data and uses computation to generate output — predictions, recommendations, classifications, rankings, scores — used to make, guide or assist a decision concerning an individual. The definition then excludes a long list of ordinary tools: anti-malware, anti-virus, calculators, databases, data storage, firewalls, networking, spam and robocall filtering, spell-checking, web caching and hosting, and spreadsheets that require human analysis and do not use machine learning, foundation models or LLMs.

Two exclusions deserve particular attention. Tools used solely to summarize, organize, translate, draft, route or present information for human review or administrative processing fall outside the definition. And there is a chat feature exemption: technology that communicates with consumers in natural language to provide information, make referrals or recommendations, answer questions or generate content is excluded — but only if it is not contracted, advertised, marketed, configured or intended to be used in a consequential decision, and only if it is subject to an acceptable use policy prohibiting generated content from being used in one.

"Materially influence" means the output is a non-de minimis factor used in making a consequential decision and affects the outcome, including by constraining, ranking, scoring, recommending, classifying or otherwise meaningfully altering how the decision is made. Incidental, trivial and clerical uses are expressly excluded. The standard is vague, and the attorney general has permissive rulemaking authority to clarify it.

Who It Applies To

A developer is a person doing business in Colorado that develops, offers, sells, leases, licenses or otherwise makes a covered ADMT commercially available; develops a component forming a substantial part of one; or substantially modifies an ADMT. Businesses that develop and use ADMT solely for internal research, where it is not used in consequential decisions, are excluded. A deployer is simply a person doing business in Colorado that deploys a covered ADMT.

A consequential decision is one relating to a consumer's access to, eligibility for, selection for or compensation for a covered domain — or one relating to differentiated pricing or material terms in a way reasonably likely to materially limit, delay, effectively deny or fundamentally alter that access. Nine exemptions apply, covering low-stakes and routine uses, advertising and content tools, basic spreadsheets, tools that only summarize or organize, narrow procedural tasks, security activities, Bank Secrecy Act and sanctions- related technology, fraud prevention, and routine academic administration.

Seven covered domains are identified: employment, education, housing, financial and lending services, insurance, health care, and essential government services and benefits.

The definition of consumer is where the reach becomes wider than it first appears. It starts from the Colorado Privacy Act's definition — a Colorado resident acting only in an individual or household context — then expands to include employees, job applicants who are Colorado residents, and any individual whose access to, eligibility for or opportunity in Colorado is evaluated in a consequential decision by a business operating there. The practical effect is to cover both people physically present in Colorado and people outside the state whose Colorado opportunities are being assessed.

Developer Obligations

A developer's obligations run to deployers, not consumers. For each covered ADMT, the developer must supply a general statement of intended uses and known harmful or inappropriate uses; a description of the categories of data, including personal data, used to train it, to the extent known; known limitations, including risks and circumstances in which it should not be used; and instructions for appropriate use, monitoring and meaningful human review where applicable.

This information can be delivered through public release notes, provided the developer gives direct notice of those notes to each deployer. Developers must update the information for material changes and notify deployers of material updates, intentional modifications and changes to intended use or risk mitigation within a reasonable time. Records demonstrating compliance must be retained for at least three years. Trade secret information does not have to be produced.

Deployer Obligations

Deployers carry considerably more than developers, though far less than the Colorado AI Act required. There are three strands: recordkeeping, notice, and consumer rights.

Records necessary to demonstrate compliance must be kept for three years, running from the date of each consequential decision — a rolling obligation attaching to every individual decision made with covered ADMT.

Notice comes in two forms. A pre-use notice is required before a covered ADMT is used to materially influence a consequential decision. It must be clear and conspicuous, state that covered ADMT was or will be used, and explain how to obtain further information. A deployer can satisfy this with a prominent public notice reasonably accessible at points of consumer interaction, positioned reasonably proximate to the interaction in which a decision may occur.

A post-adverse-outcome disclosure is required within 30 days where covered ADMT materially influences a decision producing an adverse outcome — a decision denying, terminating, revoking or materially restricting access, eligibility, selection or compensation, or producing materially less favourable terms than those offered to similarly situated consumers. It must give a plain-language description of the decision and the ADMT's role in it, instructions for requesting further information, and an explanation of the consumer's rights. The attorney general must adopt rules clarifying these requirements before January 1, 2027.

Businesses already issuing post-adverse notices under ECOA or FCRA need not duplicate them, provided the existing notice covers what SB 189 requires. No notice is required where it would be prohibited by federal law or would compromise the confidentiality or integrity of cybersecurity, fraud prevention, anti-money laundering, counter-terrorist financing or sanctions compliance programs required by law. Specific rules apply to FERPA-regulated entities.

Consumer Rights

The rights under SB 189 are narrow and conditional. They arise only after an adverse consequential decision — they are not ongoing rights — and they are tied to the Colorado Privacy Act, which means the CPA's exceptions carry across.

A consumer who receives an adverse outcome may request the personal data used by the covered ADMT in making the decision, request correction of factually incorrect personal data, and request meaningful human review and reconsideration of the decision.

The correction right is carved out from certain CPA exceptions — for employment data, public utility and authority data, state higher education data, and state and local government data held for noncommercial purposes. Those carveouts do not extend to the right of access. The practical tension is obvious: a consumer may have a right to correct data they have no corresponding right to see. The right to correct also does not require correction of opinions, predictions, scores or protected evaluations.

Meaningful human review means review by a trained individual with authority to approve, modify or override the decision, who does not defer to the system's output and can review the system's purpose, limits and the data used. It is required only to the extent commercially reasonable, which gives deployers room to argue it was not feasible in a given context.

Exemptions

Insurers subject to C.R.S. § 10-3-1104.9 are exempt. Those not complying with that provision must still give notice of their use of covered ADMT. The exemption does not extend to an insurer's role as an employer.

HIPAA covered entities are exempt from every provision except the liability provision, subject to three conditions: they must give patients general notice of the use of advanced technologies including covered ADMT, which can be folded into existing notices; where covered ADMT determines eligibility for financial assistance, they must provide a disclosure and information on requesting meaningful human review; and nothing requires disclosure of protected health information. As with insurers, the exemption does not cover their role as employers.

Medical devices subject to FDA regulation are likewise exempt from all provisions except liability. And nothing in SB 189 requires disclosure of nonpublic personal information in violation of the GLBA.

Enforcement

The Colorado attorney general is the sole public enforcer, acting through the Colorado Consumer Protection Act, under which a violation constitutes a deceptive trade practice. There is no private right of action.

Before bringing an action the attorney general must give 60 days' notice and an opportunity to cure, where a cure is deemed possible. No cure period is required for knowing or repeated violations. The right to cure sunsets on January 1, 2030 — the most notable change from the workgroup's draft, insisted on by Senate Majority Leader Rodriguez.

Liability

SB 189 addresses how fault is allocated between developers and deployers in civil actions alleging unlawful discrimination under existing law — not under SB 189 itself, which creates no private right of action. The provision reflects that developers and deployers may hold very different levels of knowledge and control over how an ADMT behaves in a particular deployment.

More consequentially for commercial practice, any contract clause purporting to indemnify, defend or hold harmless a developer or deployer against ADMT discrimination liability is void as contrary to public policy. Liability for ADMT-related discrimination cannot be contracted away or shifted — a provision with direct implications for AI vendor agreements and terms of service.

Rulemaking Status

SB 189 requires the attorney general to adopt rules on two topics before the law takes effect: post-adverse-outcome disclosure requirements, and requirements for human review following an adverse outcome. The attorney general also has discretionary authority to clarify the "materially influence" standard, and broader permissive authority over the law as a whole.

Pre-rulemaking began on June 16, 2026. The attorney general published a considerations paper setting out five guiding principles — promote consumer rights, clarify ambiguities, facilitate efficient and expeditious compliance, harmonize, and allow for innovation — together with targeted questions on definitions, post-adverse-outcome disclosures, consumer rights and pre-use notice. Informal public input closed on July 13, 2026. Draft rules and a formal notice-and-comment period are expected by the end of summer 2026.

Two signals matter for planning. The attorney general's willingness to clarify the "materially influence" and "commercially reasonable" standards through rulemaking is welcome, since both are ambiguous on the face of the statute and deployers would benefit from illustrative examples. And the eventual pre-use notice rules are likely to matter well beyond Colorado: Illinois and Connecticut already require pre-use notice in the employment context, and California's ADMT regulations require it in certain circumstances. The considerations paper signals a willingness to align with those regimes, which would shape how multistate compliance is designed.

Our coverage1

Analyzing Colorado's New ADMT Law (SB 189)

Our full webinar deck covering every obligation and exemption.

Download the deck

Tracking Colorado ADMT Act? We write about it as the law changes.

Subscribe →

Questions about Colorado ADMT Act?

Stauss PLLC advises companies on state privacy, AI, and data broker compliance.

Contact Stauss PLLC

Follow Colorado ADMT Act

Our analysis, by email, as the law moves.

Subscribe

This page is provided for general informational purposes only, is not legal advice, and does not create an attorney-client relationship. State laws change frequently; coverage reflects this tool’s most recent update. Contact Stauss PLLC to confirm how these requirements apply to your organization.