In May we reported that Colorado had scrapped its AI Act and started over, and said the second draft would matter enormously. The second draft now exists, it has a bill number, and on 11 August 2026 the Attorney General filed the rules that will make it operational.
It is time to be specific about what survived and what did not — because the summary you will read elsewhere (“Colorado modernised its AI law”) leaves out the part that actually changed.
What Happened Between May and Now
The original Colorado AI Act (SB 24-205), signed in 2024, was due to take effect 30 June 2026. It required developers and deployers of high-risk AI to use reasonable care to protect consumers from algorithmic discrimination, backed by impact assessments and disclosure duties.
It never got there, and it died from two directions at once.
The lawsuit. On 9 April 2026, xAI sued Attorney General Philip Weiser in federal court in Colorado, arguing the Act was unconstitutionally vague, violated the First Amendment by compelling it to reshape Grok’s training and outputs to match state-preferred positions on contested subjects, and breached the Equal Protection Clause. Roughly two weeks later the Department of Justice intervened on xAI’s side — the first time the federal government has moved to invalidate a state AI law, acting under the President’s December 2025 preemption executive order. On 27 April, a magistrate judge granted a joint motion staying enforcement.
The replacement. On 1 May, Senate Majority Leader Robert Rodriguez introduced SB 26-189. It passed the House 57–6 and the Senate 34–1, and Governor Polis signed it on 14 May 2026. It repeals and reenacts the AI Act as the Automated Decision-Making Technology Act. Alongside it, Colorado passed HB 26-1263, the Chatbot Safety Act. Both take effect 1 January 2027.
The Substitution Nobody Announced
Here is the sentence worth reading twice: the new framework imposes disclosure, consumer rights and human review obligations, while removing many of the governance, bias assessment and public reporting requirements from the 2024 version.
The 2024 law asked a substantive question — is this system producing discriminatory outcomes, and did you take reasonable care to find out? The 2026 law asks a procedural one — did you tell the person, and can they appeal?
Those are not the same regulation wearing different clothes. A duty of reasonable care against algorithmic discrimination creates an obligation to look at your outcomes in aggregate, across protected classes, and to act on what you find. Disclosure and appeal rights operate one consumer at a time, and only for the consumers who notice, understand the notice, and file.
A system that denies a protected group at twice the rate of everyone else, while sending every rejected applicant a clear letter and offering each of them a human reviewer, is fully compliant with the ADMT Act and would have been squarely in trouble under its predecessor.
That is the trade Colorado made. It is defensible — the vagueness objections to “algorithmic discrimination” and “reasonable care” were real, and a law that gets enjoined protects nobody. But it should be described accurately. Colorado did not fix its AI law. It replaced a civil rights instrument with a due process instrument.
What the ADMT Act Actually Requires
The proposed rules — 4 CCR 904-6 — carry the operational detail, and it is more substantial than the headline suggests.
Developers must give deployers meaningful, accurate information about intended uses, known limitations and risks, monitoring instructions, and the categories of data used to train the system. Trade secrets may be withheld only if a legal basis is identified and substitute information provided. “Midstream developers” who fine-tune or integrate someone else’s model must obtain upstream documentation and pass it down — a genuinely useful provision that attaches accountability to the model supply chain rather than only its last link.
Deployers face the consumer-facing duties:
- Adverse outcome notices within 30 days, sent by at least two communication methods, in plain language, stating the ADMT’s role, the principal reasons for denial including automatic denial factors and risk scores, and how to exercise rights.
- Communications must be accessible to people with disabilities, provided in the languages the deployer ordinarily uses, and device-readable.
- Consumers may request the personal data used, correct factually inaccurate data, and demand meaningful human review.
- Acknowledge within 10 days; complete human review within 45.
The human review standard is the strongest thing in the rules. The reviewer must be independent, have relevant expertise, and hold genuine authority to override the decision — and the ADMT cannot assist in its own review. There is a presumption that meaningful human review is commercially reasonable where an adverse outcome is a severe and irreversible denial of a basic human need.
“Genuine authority to override” is a direct shot at rubber-stamp review, which is how most human-in-the-loop requirements are quietly defeated. Whether it holds depends entirely on enforcement.
Existing ECOA and FCRA notices can satisfy the requirement if augmented with ADMT-specific content — sensible, and a sign the drafters were thinking about compliance cost.
The Sleeper: The Chatbot Safety Act
HB 26-1263 has received almost no coverage and is arguably the more aggressive of the two laws.
Age assurance. Operators must use commercially reasonable methods to estimate user age, and self-declaration is explicitly insufficient. The listed acceptable methods include zero-knowledge proofs, facial recognition matched against government ID, and digital footprint assessment.
That list should stop you. Zero-knowledge proofs are the privacy-preserving option and it is genuinely good that they appear first. The other two are not. “Facial recognition with government ID matching” means handing your face and your papers to a chatbot operator, and “digital footprint assessment” means the operator profiles your behaviour to guess your age — surveillance deployed as a child protection measure. This is precisely the trap we described in the UK Online Safety Act age verification regime and in OpenAI’s age prediction for teenagers.
Disclosure. Users must be told they are talking to an AI: at the first interaction each day, at least every three hours during a continuous session, whenever asked whether the chatbot is human, and — for minors — via a persistent visible disclaimer throughout. Colorado is answering, for one product category, the question we raised when an AI had been answering 911 calls for three years without telling anyone.
Engagement features. For minors, the rules prohibit leaderboards, badges, login streaks and session-length-tied features, and require minor accounts to default to the most protective settings — no session history retention, no use for model training. That is a design code for chatbots, and it lands very close to New Jersey’s Kids Code Act.
Reporting. Operators file annual reports to the AG by 1 July 2027, covering monthly active user tiers, crisis referral counts and accuracy metrics, self-harm protocols, age-estimation methods, and metrics on minors encountering prohibited content.
Menu-driven and narrow rule-based bots are exempt if they cannot produce sexually explicit content or engage in self-harm dialogue. Internal workforce-only deployments are exempt.
Nothing Is Enforceable Yet — And the Lawsuit Is Waiting
AG Weiser has said his office will not enforce until rulemaking concludes, which must happen before 1 January 2027.
And the stay has a trigger built into it. The magistrate’s order requires xAI to file a preliminary injunction motion, and if necessary an amended complaint, within 28 days of final adoption of implementing rules or any legislation replacing the Act.
So the sequence is fixed: rules are finalised, and 28 days later the constitutional fight restarts — now against a law whose discrimination provisions have already been stripped out, with the DOJ still in the case. Colorado gave up the provision most vulnerable to a First Amendment attack. Whether that was enough to survive the second round is the open question, and the answer will shape what every other state believes it can pass.
Contrast this with the EU AI Act’s Article 50 transparency duties, which went live on 2 August and are being enforced now. Colorado’s equivalent is a proposed rule with a comment period, a January date, and a lawsuit queued behind it.
What To Do
- Comment before Friday if you want to be heard early. Written comments submitted by 4 September 2026 are considered for the revised draft, which posts 23 September. The formal rulemaking hearing is 26 October, with comments accepted through it. Details are at coag.gov/ai. Rulemaking comment windows are the least-contested venue in privacy — industry always shows up, and almost nobody else does.
- Push back on the age-assurance menu specifically. If you comment on one thing, make it this: zero-knowledge proofs should be the default, not one option among three, and “digital footprint assessment” should not be an approved method of protecting children.
- Coloradans: from 1 January 2027, ask for the reasons. If you are denied a job, a loan, an apartment, or insurance, you are entitled to a plain-language notice naming the principal reasons, the automatic denial factors, and any risk score — and to human review with real authority to reverse it. Ask in writing; they must acknowledge in 10 days and finish in 45.
- Correct the data before you appeal. The right to correct factually inaccurate inputs is the most useful right in this statute and the one nobody uses. A wrong address, employer or account status is far easier to fix than an argument about a model.
- If you deploy ADMT, start on the supply chain now. The midstream developer provision means you need documentation from whoever built the model you fine-tuned. That takes months to obtain and there are four of them left.
- Do not read Colorado as the national floor any more. It was, and now it is a disclosure regime with an enforcement stay. The states doing substantive work on AI harm right now are elsewhere, and the venue that matters most is the one with a comment deadline this week.


