Nearly two years after passing one of the nation’s first AI governance laws, Colorado is set to substantially revise the law before it finally takes effect. On May 12, 2026, the Colorado General Assembly passed SB 26-189, which pares back many of the demanding features of the original law, including requirements for annual impact assessments and other disclosure obligations, and shifts liability from the developer to the employer making decisions using the covered technology.
The Colorado Artificial Intelligence Act
In 2024, Colorado enacted the Colorado Artificial Intelligence Act (the “CAIA”), set to go into effect on June 30, 2026, and designed to regulate the development and deployment of high-risk AI systems that are used to make, or are a substantial factor in making, consequential decisions affecting consumers. Consequential decisions include those with a material effect on opportunities in education, employment, financial and lending services, essential government services, health care, housing, insurance and legal services.
The CAIA imposed obligations on both developers and users of AI systems. The CAIA required developers to make information available to users to support responsible use of high-risk AI systems, while users were expected to implement risk-management processes, conduct impact assessments, provide consumer-facing disclosures, and take reasonable care to protect consumers from algorithmic discrimination.
In the ensuing years, the CAIA became a point of contention for certain businesses that argued that the compliance obligations, and in particular the impact assessment mandate, would be overly burdensome, with xAI going so far as to sue the state over alleged First Amendment violations in connection with the law.
New Requirements under SB 26-189
SB 26-189 signals a change in course by Colorado when it comes to AI regulation. The legislation will repeal and replace key portions of the original CAIA with a narrower and more implementation-focused framework.
Most significantly, SB 26-189 shifts companies’ obligations from the front-end of implementation to justify use of certain technology to the practical result of implementation, operating more akin to compliance laws that require consistent practices, disclosure of information, and provides an opportunity to correct practices that do not comply.
For example, the bill eliminates the annual impact assessment mandate. Users of AI systems will no longer be required to assess high-risk AI systems on the front-end for the risk of algorithmic discrimination. Instead, the bill imposes certain disclosure obligations for automated decision-making technologies, or ADMTs, that kick in after implementation of the technology.
The bill defines covered ADMTs as technologies that process personal data and use computation to generate predictions, recommendations, classifications, rankings, scores or similar metrics, that are then used to materially influence consequential decisions in a covered domain, which includes education, employment, financial and lending services, essential government services, health care, housing, insurance and legal services. Consequently, immaterial uses of ADMTs would not be subject to the CAIA. Uses of ADMTs unrelated to the covered domains would also fall outside the purview of the CAIA.
For covered ADMTs falling within the scope of the law, users must provide advanced notice to consumers that a covered ADMT will be used in an interaction. If a covered ADMT influences a consequential decision and results in an outcome adverse to the consumer, the user must provide the consumer with certain information within 30 days, including a description of the decision, the role of the covered ADMT, and an explanation of the consumer’s rights under the CAIA. The user must give instructions to the consumer on how to obtain additional information about the covered ADMT and the personal data used by the covered ADMT. Users must keep records of consequential decisions made using ADMT for a minimum of three years.
SB 26-189 also modifies enforcement by providing a 60-day right to cure for AI deployers that violate the law, with that cure period scheduled to sunset after three years. The bill further specifies that the CAIA does not create a private right of action, so, similar to other regulatory law, only the State of Colorado can enforce the CAIA.
Although the CAIA was scheduled to go into effect on June 30, 2026, SB 26-189 pushes the implementation date to January 1, 2027. In addition, the Colorado Attorney General disclosed in court filings that he will not enforce the CAIA while the legislature works to amend the law. Even so, companies should take steps now to move toward compliance with the revised law.
Key Takeaways
Though Colorado has not abandoned AI regulation altogether, the new bill signals a more targeted regulatory approach by the state. Companies using AI in employment, lending, health care, insurance, education, housing, legal, and government-services contexts should take steps now to build toward compliance.
- Companies should inventory where AI is being used to make or materially support consequential decisions. For most companies, the highest-priority review should begin with AI systems used in the employment context.
- Companies should map AI-related governance responsibilities across their legal, compliance, technology, human resources, procurement, privacy, and business functions. Although SB 26-189 reduces certain formal assessment burdens, holistic approaches are likely needed to maintain oversight and accountability of AI systems and practices.
- Boards and relevant committees should ensure that management has processes for identifying covered AI systems, evaluating use cases, approving deployment, monitoring vendor claims, and responding to consumer requests.
- Similarly, companies should consider whether AI governance is sufficiently integrated into broader enterprise risk management and disclosure controls. Although SB 26-189 is a state consumer-protection law, its subject matter overlaps with issues that boards are increasingly monitoring, such as technology risk, cybersecurity, privacy, employment practices, discrimination risk, vendor management, and regulatory compliance.
While the new legislation may make the CAIA more manageable, the law still puts a significant onus on companies to monitor AI use. Please reach out to your V&E team with any questions or to discuss how the CAIA may affect your business.
This information is provided by Vinson & Elkins LLP for educational and informational purposes only and is not intended, nor should it be construed, as legal advice.