Skip to content

Colorado narrowed its AI Act and moved it to 2027. Does your agent make consequential decisions?

SB 26-189 swaps risk programmes for notices, adverse-decision explanations, human review and records. Here is how to tell if your agent is covered.

By Published Updated 7 min read
AI agents in operations, 7 min read — Small glowing spheres moving along a path that splits before a glass gate, with a few passing through to a waiting point of light.

The short answer

Only if it materially influences a decision about someone's job, loan, housing, insurance, education, health care or government services. Colorado's SB 26-189, signed in May 2026 and effective 1 January 2027, requires notice, an explanation within 30 days of an adverse outcome, a route to human review and three years of records. Drafting and routing tools are largely outside it.

Key takeaways

  • Colorado's SB 26-189 replaced the 2024 AI Act's risk-management programmes and impact assessments with disclosure, adverse-outcome explanations, human review and record-keeping.
  • The law applies from 1 January 2027 to automated decision tools that materially influence a consequential decision in covered domains such as employment, lending, housing, insurance and health care.
  • Tools used only to summarise, draft, translate or route information for a person to review are excluded, which covers many back-office agents.
  • A deployer must explain an adverse outcome within 30 days and offer meaningful human review by a trained person with authority to override.
  • Design for the rule now: keep the agent's output as a recommendation, log the version and inputs, and name the reviewer, whatever happens to enforcement.

What changed in Colorado

Colorado rewrote its AI law in May 2026 and pushed its start to 1 January 2027. Governor Polis signed SB 26-189 on 14 May 2026, replacing the 2024 Colorado AI Act before it took effect.1 The original law, due to apply from 30 June 2026, required deployers of high-risk AI to run risk-management programmes and impact assessments. The new one drops both.1

In their place sit four duties for organisations that use automated decision-making technology in consequential decisions: notice before use, an explanation after an adverse outcome, consumer rights to correct data and seek human review, and record-keeping.2 Developers must give deployers documentation on intended uses, known harmful uses, training data categories and how to oversee the tool.1

This is a summary for operators building agents, not legal advice. If you make decisions about Colorado residents, read the bill with counsel.

Is your agent covered?

Your agent is covered only if two things are true: it works in a covered domain, and its output materially influences a consequential decision about a person. Both tests have to pass.

Covered domains

The domains are education, employment, residential real estate, financial or lending services, insurance, health care and essential government services.3 A consequential decision concerns someone's access to, eligibility for, selection for or compensation in one of those areas. It also covers differentiated pricing or terms likely to deny or materially limit that access.3 For employers, Buchalter reads that as reaching hiring, termination, promotion and pay, and lists scheduling too.2 Lathrop GPM notes a carve-out for low-stakes or routine decisions, including scheduling, so check routine rostering tools with counsel.3

Materially influences

An automated tool materially influences a decision when its output is a substantial factor in the outcome: it constrains, ranks, scores, recommends or classifies in a way that changes how the decision is made.3 Incidental, trivial or clerical uses are excluded, and the Attorney General is to write rules on what the phrase means in practice.3

What is excluded

Tools used solely to summarise, organise, translate, draft, route or present information for a person to review are outside the definition.3 So are informational chatbots that are not marketed or contracted for consequential decisions and sit under a policy forbidding that use.3

Our view: most first agents in finance and operations land on the excluded side. An invoice-matching agent that drafts entries for a clerk, or a support agent answering order questions, decides nothing about a person's job, credit or home. A screening agent that ranks job applicants, or a lending agent that scores applications, is squarely inside.

Three agents, one test

Likely outside

  • Invoice matching that drafts entries for approval
  • Order-status replies
  • Lead routing to a salesperson

Depends on design

  • Tenant enquiry triage that filters who gets a viewing
  • Interview scheduling that drops some applicants
  • Pricing quotes that vary terms by applicant

Likely covered

  • Applicant screening or ranking
  • Credit or underwriting scores
  • Eligibility checks for benefits or care
Illustrative. Our reading of the summaries by Hunton, Buchalter and Lathrop GPM; not legal advice.

What a covered deployer has to do

A covered deployer has four jobs, and each one maps to something you can build into the agent's workflow.

  • Notice before use. Tell people clearly, before the decision, that an automated tool is or will be used, and how to get more information. A prominent public notice at the point of interaction can satisfy this.3
  • Explanation after an adverse outcome. Within 30 days, give a plain-language description of the decision, the tool's role and how to request more detail, including the tool's name, version, developer and the categories of personal data used.3
  • Correction and human review. The person can ask how to correct factually wrong personal data and request meaningful human review and reconsideration, where commercially reasonable.3
  • Records. Keep what you need to show compliance for at least three years after each decision, including version identifiers and change logs.2

Meaningful human review has teeth. The reviewer must be trained, consider the relevant evidence, hold authority to override the outcome and not simply defer to the system.2 A recruiter who clicks approve on an AI ranking without looking does not meet it.

When does it apply, and is it enforced?

The law takes effect on 1 January 2027, but enforcement is less certain than the date suggests. In April 2026 a federal court stayed enforcement of the 2024 law during a constitutional challenge, and the Attorney General said he would not enforce it, or any law replacing it, until rulemaking ends.2 That was the position in Buchalter's May alert; check the current status before you plan around it.

Enforcement, when it comes, sits with the Attorney General under Colorado's consumer protection law, with no private right of action. A notice of violation and a 60-day cure period come first, unless the violation was knowing or repeated.3 Anti-discrimination law applies regardless, and indemnities that try to shift liability for your own discriminatory acts onto a vendor are void.3

Our view: build the controls now anyway. They are the same controls you need to defend a decision under existing anti-discrimination law, and they cost far less to design in than to retrofit.

How does this compare with the EU's Article 50?

They regulate different things. The EU AI Act's Article 50 is a transparency rule: from 2 August 2026, people must be told when they are talking to an AI system unless that is obvious, and synthetic content must be marked, with a grace period to 2 December 2026 for machine-readable marking.4 It applies to a chatbot whatever it decides. Fines reach €15 million or 3% of worldwide turnover, whichever is higher.4

Colorado's law cares about decisions, not conversations. A support chatbot can trigger Article 50 and sit outside Colorado's scope. A back-office scoring model that never talks to anyone can fall under Colorado and outside Article 50. Our guide to Article 50 disclosure covers the EU side.

QuestionColorado SB 26-189EU Article 50
What triggers itTool materially influences a consequential decisionPeople interact with AI, or see synthetic content
From when1 January 20272 August 2026
Main dutyNotice, adverse-outcome explanation, human reviewDisclose the AI; mark generated content
RecordsAt least three years per decisionBurden of showing compliance sits with you
Enforced byState Attorney General, 60-day cure firstNational authorities; fines up to €15M or 3%4

Sources: Hunton, Buchalter and Lathrop GPM summaries of SB 26-189; Cloud Security Alliance research note on Article 50.34

Designing an agent that stays on the right side

Keep the agent's output a recommendation, keep a person in the decision, and log enough to explain it later. Five design rules cover most of the work.

  1. Draft, do not decide. Where the work touches a covered domain, the agent prepares and a named person decides. That may keep the tool outside the definition and makes review real if it is inside.
  2. Log the decision trail. Store the input, the output, the model and prompt version and who approved, for three years.
  3. Template the adverse-outcome letter. Name the tool, its version and the data categories, so the 30-day explanation is a mail merge, not an investigation.
  4. Train the reviewer and give them the override. Record when they disagree with the agent; a review log with no overrides is a warning sign.
  5. Scope the agent's permissions. An agent that can only draft cannot decide by accident. Our guide to least privilege in ERP and CRM shows how.

Every workflow on our AI automation page keeps people on the exception queue and the approval step. Colorado's rewrite turns that habit into a legal expectation for decisions about people.

Sources

  1. Hunton, Colorado AI Act amended and effective date delayed (May 2026)
  2. Buchalter, Colorado rewrites its AI law: what employers must know about SB 26-189 (May 2026)
  3. Lathrop GPM, Colorado enacts new law regulating automated decision-making technology (Jun 2026)
  4. Cloud Security Alliance, research note on EU AI Act Article 50 transparency (Jul 2026)

Questions readers ask

  • It applies to developers and deployers that do business in Colorado, and it protects consumers whose access or eligibility in Colorado is evaluated, including Colorado job applicants. A company based elsewhere that screens Colorado applicants or lends to Colorado residents with an automated tool should assume it may be covered and check with counsel.

Keep reading

Free, in two minutes. Enter your domain and we'll score it against three competitors across six engines.

No account needed. The report is emailed within 24 hours.