The Colorado AI Act (SB 24-205), explained
Updated
The Colorado AI Act (Senate Bill 24-205) is a state consumer-protection law governing high-risk artificial intelligence systems — those that make, or are a substantial factor in making, a consequential decision about a consumer. It requires developers and deployers to use reasonable care to protect consumers from algorithmic discrimination.
Signed into law in 2024, it splits obligations between the parties that build high-risk AI (developers) and the parties that use it to make decisions about people (deployers). Core requirements include documentation and transparency from developers, impact assessments and risk-management programs from deployers, notice and appeal rights for consumers, and disclosure of discovered algorithmic discrimination to the state Attorney General, who enforces the law.
What the Colorado AI Act covers
The Colorado AI Act, enacted as Senate Bill 24-205 and signed into law in 2024, is among the first comprehensive U.S. state laws to regulate AI used in decisions about people. It applies to persons doing business in Colorado that act as a developer or deployer of a high-risk artificial intelligence system.
A high-risk AI system is one that, when deployed, makes or is a substantial factor in making a consequential decision. A consequential decision is one that has a material legal or similarly significant effect on a consumer's access to, or the cost or terms of, a defined set of life opportunities. The law lists specific categories, and systems that fall outside those categories — or that only perform narrow procedural or supportive tasks — are generally not high-risk under the statute.
- Education enrollment or an education opportunity.
- Employment or an employment opportunity.
- A financial or lending service.
- An essential government service.
- Health-care services.
- Housing.
- Insurance.
- A legal service.
Developers versus deployers
The law assigns different duties to the two roles. A developer creates, or substantially and intentionally modifies, a high-risk AI system. A deployer uses a high-risk AI system to make, or as a substantial factor in making, a consequential decision. A single company can be both — for example, one that builds a system and also uses it internally.
Both roles share one overarching obligation: to use reasonable care to protect consumers from any known or reasonably foreseeable risk of algorithmic discrimination. The specific duties below are how each role demonstrates that care.
| Obligation | Developer | Deployer |
|---|---|---|
| Documentation to the other party | Provide deployers documentation on intended uses, known limitations, how the system was evaluated for performance and discrimination, and data governance. | Rely on developer documentation to inform its own use and assessment. |
| Impact assessment | Not required of developers as such. | Complete an impact assessment for each high-risk system, reviewed periodically and after an intentional and substantial modification. |
| Risk-management program | Not required of developers as such. | Implement a risk-management policy and program, which may draw on recognized frameworks such as the NIST AI RMF or ISO/IEC 42001. |
| Public statement | Publish a summary of the high-risk systems developed and how known risks of algorithmic discrimination are managed. | Publish a summary of the high-risk systems deployed and how those risks are managed. |
| Disclosure to the Attorney General | Disclose known or reasonably foreseeable algorithmic discrimination within the statutory window after discovery. | Disclose discovered algorithmic discrimination within the statutory window after discovery. |
| Consumer notice and rights | Not directed at consumers. | Notify consumers of high-risk AI use and provide explanation, correction, and appeal rights for adverse decisions. |
Algorithmic discrimination and reasonable care
The law's central standard is a duty of reasonable care to protect consumers from algorithmic discrimination. Algorithmic discrimination means any condition in which the use of an AI system results in unlawful differential treatment or impact that disfavors an individual or group on the basis of a protected classification — such as age, color, disability, ethnicity, genetic information, limited English proficiency, national origin, race, religion, reproductive health, sex, or veteran status — as recognized under state or federal law.
To give the duty teeth without making it open-ended, the statute creates a rebuttable presumption: a developer or deployer that complies with the specific duties the law lays out is presumed to have used reasonable care. That structure is why the documentation, impact-assessment, disclosure, and consumer-rights requirements matter so much — meeting them is the practical way a regulated party shows it exercised the care the law requires.
Disclosures and consumer rights
The law is explicitly consumer-facing. A deployer must notify a consumer when a high-risk AI system is used to make, or is a substantial factor in making, a consequential decision about them, along with information about the system and how to contact the deployer.
When a high-risk system produces an adverse decision, the deployer owes the consumer additional rights designed to make the decision contestable rather than a black box:
- A statement of the principal reasons for the adverse decision, including the degree to which the AI system contributed and the data used.
- An opportunity to correct any incorrect personal data the system processed in reaching the decision.
- An opportunity to appeal for human review where that is technically feasible.
- Disclosure, where applicable, that the consumer is interacting with an AI system.
Impact assessments and risk-management programs
For deployers, two documents carry much of the compliance weight. The first is an ongoing risk-management program: the law contemplates that a deployer will implement a policy and program to govern its use of high-risk AI, and it points to recognized frameworks — the NIST AI Risk Management Framework and ISO/IEC 42001 among them — as acceptable references for building one.
The second is the impact assessment, completed for each high-risk system and refreshed on a regular cadence and after any intentional and substantial modification. An impact assessment generally examines the system's purpose and intended use, known or reasonably foreseeable risks of algorithmic discrimination and the steps taken to mitigate them, the categories of data processed, and how the system's performance is monitored. Because these obligations recur, deployers tend to treat them as living records tied to specific systems rather than one-time paperwork.
Enforcement, exemptions, and effective date
Enforcement authority sits exclusively with the Colorado Attorney General; the statute does not create a private right of action, so individual consumers cannot sue under it directly. A violation is treated as an unfair or deceptive trade practice under Colorado's consumer-protection law. The Act also provides an affirmative defense for a developer or deployer that discovers and cures a violation through its own testing — including red-teaming — and is otherwise in compliance with a recognized AI risk-management framework, and it authorizes the Attorney General to issue implementing rules.
The law includes exemptions and thresholds — for example, relief for certain smaller deployers that meet defined conditions, and carve-outs for entities and activities already governed by specified federal or sector regulation. On timing, the Act was scheduled to take effect in 2026, and its compliance date has been the subject of subsequent legislative amendment; because that date has moved, confirm the current effective date and the latest amended text before relying on any specific day. Treat the framing here as the statute's structure, not legal advice.
Frequently asked questions
Who does the Colorado AI Act apply to?
It applies to persons doing business in Colorado that develop or deploy a high-risk AI system — one that makes, or is a substantial factor in making, a consequential decision about a consumer. Developers build or substantially modify such systems; deployers use them to make decisions. A single company can be both.
What is a 'consequential decision' under SB 24-205?
A decision that has a material legal or similarly significant effect on a consumer's access to, or the cost or terms of, defined life opportunities: education, employment, financial or lending services, essential government services, health care, housing, insurance, or legal services.
What is algorithmic discrimination?
Any condition in which the use of an AI system results in unlawful differential treatment or impact that disfavors an individual or group on the basis of a protected classification — such as age, disability, ethnicity, national origin, race, religion, sex, or veteran status — under state or federal law. The Act's core duty is reasonable care to protect consumers from it.
Does the Colorado AI Act create a private right of action?
No. Enforcement rests exclusively with the Colorado Attorney General, and violations are treated as unfair or deceptive trade practices under state consumer-protection law. Individual consumers cannot sue under the Act directly, though it grants them notice, explanation, correction, and appeal rights against deployers.
How does it relate to the NIST AI RMF and ISO/IEC 42001?
The Act points to recognized risk-management frameworks — the NIST AI RMF and ISO/IEC 42001 among them — as acceptable references for a deployer's risk-management program, and aligning with such a framework can support the Act's affirmative defense. Those frameworks are voluntary; the Act is binding law in Colorado.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.