Skip to content

Colorado AI Act (SB 24-205)

Colorado SB 24-205 (as deferred by SB25B-004, applying from 30 June 2026) covers consumer disclosure of AI interaction, deployer impact assessments, risk-management programmes and notification of algorithmic discrimination to the Attorney General within 90 days.

Registry id colorado
Kind regulation
Jurisdiction US-CO
Instrument Colorado SB 24-205, Consumer Protections for Artificial Intelligence (as amended)
Catalog versions 2026-09 from 2026-06-30 (current) — As deferred by SB25B-004
Verified against instrument no — see the banner above
Roles (frameworks.colorado.role) deployer, developer
Incident deadline rules standard: 90 days
Retention floors none at classification level
Obligations 4

Alternative rules: the incident’s classification picks the rule when it names one, else standard applies.

Rule Deadline from became_aware_at
standard 90 days

Deadlines are computed and shown, never enforced — see incidents.

Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.

Disclosure of interaction with an AI system

Section titled “Disclosure of interaction with an AI system”

consumer-ai-disclosure · C.R.S. 6-1-1704 · applies from 2026-06-30

Can serve as evidence toward disclosing to consumers that they are interacting with an AI system. Written from public summaries of the instrument; check the published text before relying on this. Applies to: profile flag core.interacts_with_natural_persons.

Statement Basis Resolver Does not show
People were told they were dealing with an AI before the first substantive turn. recomputed notice.before_first_turn Counts conversations through the Brutor portal (notice records); other clients must render their own notice.
The notice text and the surface it is shown on are declared and sealed. declared notice.text_declared The text is declared by the operator; whether it is understood is not evaluated.

deployer-impact-assessment · C.R.S. 6-1-1703(3) · applies from 2026-06-30

Can serve as evidence toward an impact assessment for a high-risk AI system making consequential decisions, repeated at least annually and after substantial modification. Written from public summaries of the instrument; check the published text before relying on this. Applies to: profile flag core.automated_decisions_about_persons.

Statement Basis Resolver Does not show
A current impact assessment is on file. recomputed evidence.pointer_on_file {"kind": "impact_assessment"} A pointer to a document produced outside the platform; its content is not evaluated.

Deployer risk management policy and programme

Section titled “Deployer risk management policy and programme”

deployer-risk-management · C.R.S. 6-1-1703(2) · applies from 2026-06-30

Can serve as evidence toward a risk management policy and programme governing deployment of a high-risk AI system. Written from public summaries of the instrument; check the published text before relying on this. Applies to: profile flag core.automated_decisions_about_persons.

Statement Basis Resolver Does not show
A risk management policy and programme is declared. declared profile.field_declared {"path": "frameworks.colorado.risk_management_reference"} Organisational duty; the programme is not evaluated.
A human can override or stop the system. recomputed oversight.override_available Shows the controls exist and are assigned, not that the assigned people are competent.

Notification of algorithmic discrimination to the Attorney General

Section titled “Notification of algorithmic discrimination to the Attorney General”

ag-notification · C.R.S. 6-1-1703(7) · applies from 2026-06-30

Can serve as evidence toward notifying the Attorney General within 90 days of discovering that a high-risk system caused algorithmic discrimination. Written from public summaries of the instrument; check the published text before relying on this. Applies to: profile flag core.automated_decisions_about_persons.

Statement Basis Resolver Does not show
An incident register is kept and no open incident is past its deadline. recomputed incidents.register_exists Shows incidents someone entered; an incident nobody recorded cannot be counted.
Discovered algorithmic discrimination was notified within 90 days. recomputed incidents.reported_within_deadline {"framework": "colorado"} Deadlines are computed and shown, not enforced; awareness time is operator-entered.