SB 24-205, Repealed and Replaced by SB 26-189
The one-paragraph answer
The Colorado AI Act was repealed before it ever took effect. SB 24-205, signed in May 2024, was the first comprehensive US state AI law. It never became operative. Its start date slipped from February 1, 2026 to June 30, 2026, a federal magistrate stayed its enforcement in April 2026, and Governor Polis signed SB 26-189 on May 14, 2026, repealing it outright and replacing it with the Automated Decision-Making Technology Act, effective January 1, 2027. The duty of care, the mandatory impact assessments, the high-risk classification, and the rebuttable presumption for NIST AI RMF alignment are all gone. What replaces them is a narrower disclosure-and-rights regime. If your compliance roadmap still contains a Colorado high-risk workstream, it is aimed at a statute that no longer exists.
Two years of compliance spend, aimed at a law that never arrived. That is the pain the Colorado AI Act is causing right now, and it is a more instructive pain than the one anybody planned for.
Organisations built high-risk AI classification schemes, drafted impact-assessment templates, and adopted the NIST AI RMF specifically to earn Colorado's rebuttable presumption of reasonable care. Then the statute was repealed. The instinct is to conclude that AI regulation is theatre and to stand down. That is the wrong lesson, and acting on it is how a company ends up exposed.
The obligations did not vanish. They moved. Connecticut's SB 5 takes effect October 1, 2026. Texas HB 149 phases in through 2026 and 2027. Illinois SB 315 lands on frontier developers. California's stack is already live. Five federal agencies are enforcing against AI misuse under statutes that predate AI by decades. And Colorado itself still regulates automated decisions, just on a different theory. The work that was done for Colorado, the AI inventory, the documented risk process, the named accountable owner, the human review path, transfers almost entirely. The classification scheme does not.
The sequence matters, because it is the clearest map anyone has of how state AI regulation is actually going to unfold.
May 2024. Governor Jared Polis signs SB 24-205, the first comprehensive US state AI law. He attaches a signing letter asking the legislature to revisit it before it takes effect, flagging in particular that the statute imported a disparate-impact theory of algorithmic discrimination into a technology law, regulating outcomes regardless of intent.
August 2025. With the February 1, 2026 effective date approaching and no revision agreed, Polis calls a special session. Lawmakers cannot reach a compromise. The only thing they can agree on is delay. SB 25B-004 pushes the effective date to June 30, 2026.
December 11, 2025. The White House signs an executive order establishing an AI Litigation Task Force inside the Department of Justice, charged with challenging state AI laws.
April 9, 2026. xAI, developer of Grok, sues in the US District Court for the District of Colorado, challenging SB 24-205 on constitutional grounds including compelled speech under the First Amendment. DOJ intervenes in support.
April 27, 2026. A federal magistrate stays enforcement of the Colorado AI Act after the Attorney General stipulates to the stay, citing the pending legislative rewrite.
May 14, 2026. Polis signs SB 26-189, the Automated Decision-Making Technology Act. It repeals SB 24-205 and replaces it. Introduction to signature took roughly two weeks. The replacement takes effect January 1, 2027.
June 30, 2026. The deferred effective date of the Colorado AI Act arrives. The law it would have activated no longer exists.
The new law is narrower, and the narrowing is the point. It regulates automated decision-making technology that materially influences a consequential decision, and it builds duties around disclosure and individual rights rather than around a duty of care.
Deployers must notify a consumer when covered ADMT will materially influence a consequential decision about them, before the decision is made.
A consumer who receives an adverse outcome is entitled to a plain-language explanation of the decision within 30 days. Not a score. An explanation a person can act on.
The consumer can request that a human review the decision. "Meaningful" is doing real work in that sentence; a rubber stamp on the model's output is not review.
The consumer can request access to, and correction of, factually inaccurate personal data used in the decision.
Developers must supply deployers with the documentation deployers need to meet their own obligations.
Three-year record-keeping. Enforcement by the Colorado Attorney General, with a 60-day pre-enforcement cure period that sunsets January 1, 2030. No private right of action.
Four things went, and each removal tells you something about where state AI law is heading.
The duty of care is gone. SB 24-205 made a company directly liable for foreseeable algorithmic discrimination. SB 26-189 does not. Colorado no longer has a state-specific statutory duty of care for AI outcomes.
The high-risk classification scheme is gone. No tiering exercise, no Annex-style list. The trigger is now whether ADMT materially influences a consequential decision.
Mandatory annual impact assessments are gone. The single most expensive obligation in the original statute.
The rebuttable presumption is gone. This is the one worth pausing on. SB 24-205 gave organisations aligned to a recognised risk framework, explicitly including the NIST AI RMF, a rebuttable presumption that they had used reasonable care. That provision was the single largest driver of voluntary NIST AI RMF and ISO/IEC 42001 adoption in the United States. It no longer exists in Colorado law.
That does not make the frameworks worthless. It makes their value commercial and evidentiary rather than statutory. Alignment still answers the buyer, the insurer, the board, and the federal agency. It just no longer buys you a specific Colorado legal defence, because the defence, and the law it defended against, are both gone.
The Colorado AI Act matters now for the opposite of the reason it mattered in 2024. It is the clearest case study available of how the first wave of comprehensive state AI regulation actually ended, and the lessons are directly operational.
The EU-style risk-tiering model is in retreat in the United States. Colorado copied the EU AI Act's architecture and could not make it survive contact with its own legislature, a constitutional challenge, and a federal administration actively litigating against state AI laws. States drafting now are watching that. Expect disclosure-and-rights regimes, not high-risk classification schemes.
Federal pressure is a real variable in state compliance planning. The DOJ AI Litigation Task Force, the FTC's preemption argument, and the preemption provision in the Great American AI Act draft are not background noise. They changed a state law. Any roadmap that treats state AI statutes as fixed points is mispricing the risk.
Build the durable layer, not the statute-specific layer. Organisations that built an AI inventory, a documented risk process, a named accountable owner, and a human review path still have all of it. Organisations that built a Colorado high-risk classification taxonomy have a filing cabinet. The distinction is the whole lesson.
And Colorado still regulates. SB 26-189 takes effect January 1, 2027. If you make automated decisions about Colorado consumers, you have obligations. They are just different ones.
The academic literature on Colorado AI Act is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“concerns about their impact on individual and societal wellbeing, particularly due to the lack of transparency and accountability”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“the understanding of how such principles can be operationalized in designing, executing, monitoring, and evaluating AI applications is limited”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about Colorado AI Act arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, Colorado AI Act becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
No. It was repealed by SB 26-189 on May 14, 2026, and it never took effect at any point. Any guidance telling you otherwise, including earlier versions of this page, is out of date.
SB 26-189, the Automated Decision-Making Technology Act, from January 1, 2027. Pre-use notice, adverse-outcome explanation within 30 days, meaningful human review on request, data access and correction, developer documentation, and three-year records. Enforcement by the Attorney General, with a 60-day cure period through 2029.
The presumption is gone. The work is not. Framework alignment still answers the enterprise buyer, the insurance underwriter, the audit committee, and the federal agency, and it is still the fastest route to a defensible position under Connecticut, Texas, and the EU AI Act. What you lost is a specific Colorado legal defence against a specific Colorado cause of action, and that cause of action was repealed alongside it.
Not certain. Reporting indicates enforcement questions remain live pending resolution of the federal litigation, and the same federal preemption pressure that shaped the repeal has not gone away. Plan for the January 1, 2027 obligations, and watch the docket.
No, and reading it that way is the expensive mistake. Connecticut, Texas, Illinois, and California all have live obligations. Five federal agencies enforce against AI misuse today under existing statutes. The EU AI Act binds any company touching EU users. What collapsed in Colorado was one architecture, the EU-style high-risk tiering model, not the direction of travel.
The Colorado AI Act repeal is exactly the scenario the Library is built for. The 6-Step Review Process™ produces an AI inventory, a documented risk process, a named accountable owner, and a human review path, none of which depended on Colorado's classification scheme and all of which transfer directly to Connecticut, Texas, the EU AI Act, and federal agency scrutiny. Clients who built to the framework rather than to the statute lost nothing when the statute went.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning Colorado AI Act that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including Colorado AI Act, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →