This checker maps your answers to the text of the repealed Colorado SB 24-205 as codified at Colorado Revised Statutes § 6-1-1701 et seq. It uses the statute’s own definitions of developer (§ 6-1-1701(7)), deployer (§ 6-1-1701(8)), high-risk artificial intelligence system (§ 6-1-1701(9)), consequential decision (§ 6-1-1701(3)), and substantial factor (§ 6-1-1701(11)). Every obligation surfaced in the output is tied to the SB 24-205 section that created it, so you can see which of your existing controls carry over to the narrower SB 26-189 duties.
Nothing you type leaves your browser. There is no login, no email gate, and no server-side storage. The classification logic is deterministic — the same answers always produce the same result, with each obligation tied to its statute section.
What happened to the Colorado AI Act (SB 24-205)?
SB 24-205 (C.R.S. § 6-1-1701 et seq.), signed on 17 May 2024, was the first US comprehensive state AI consumer-protection law. Its effective date was moved from 1 February 2026 to 30 June 2026 by SB 25B-004, a federal court order blocked its enforcement on 27 April 2026, and in May 2026 Colorado repealed it and replaced it with SB 26-189, a narrower law on automated decision-making technology (ADMT) that takes effect on 1 January 2027.
When does Colorado’s AI law take effect now?
The replacement law, SB 26-189, takes effect on 1 January 2027. The SB 24-205 dates of 1 February 2026 and 30 June 2026 no longer apply because SB 24-205 was repealed.
What does SB 26-189 require?
Based on published summaries of the enacted bill: developers must give deployers documentation on intended uses, known limitations and risks, categories of training data and instructions for appropriate use; deployers must give consumers clear notice when ADMT is used in a consequential decision, explain adverse outcomes in plain language within 30 days, and offer correction of inaccurate personal data and meaningful human review where commercially reasonable; both keep records for at least three years. The Colorado Attorney General enforces it (no private right of action), with a 60-day cure period until 1 January 2030. Confirm details against the enacted text with counsel.
Does this checker reflect SB 26-189?
Not yet. The interactive checker below maps your answers to the repealed SB 24-205 framework (impact assessments, risk-management policy, notices and appeals). Many teams built programs on it, and those controls largely cover SB 26-189’s narrower notice, explanation and documentation duties — but the output is a baseline, not a determination under SB 26-189.
Who is a developer vs. a deployer under SB 24-205 (repealed)?
A developer, defined in § 6-1-1701(7), is a person doing business in Colorado that develops, or intentionally and substantially modifies, a high-risk AI system. A deployer, defined in § 6-1-1701(8), is a person doing business in Colorado that deploys a high-risk AI system. The same organization can be both for different systems. Developer duties sit in § 6-1-1702; deployer duties in § 6-1-1703.
What counts as a "consequential decision" under SB 24-205 (repealed)?
Under § 6-1-1701(3), a consequential decision is a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of, education enrollment or opportunity, employment or employment opportunity, financial or lending services, essential government services, healthcare services, housing, insurance, or a legal service. Marketing, entertainment, and non-consumer-facing back-office AI is not consequential.
What was the SB 24-205 substantial-factor test?
Under § 6-1-1701(11), an AI system is a substantial factor in a consequential decision if it (a) assists in making the decision, (b) is capable of altering the outcome of the decision, and (c) is used to generate content, decisions, predictions, or recommendations that serve as a principal basis for the decision. Human reviewers rubber-stamping AI output does not remove the substantial-factor status.
What was the SB 24-205 small-business exemption?
Under § 6-1-1703(6), a deployer with fewer than 50 full-time employees that (a) does not use its own data to train the high-risk AI system, (b) uses the system for its intended uses as disclosed by the developer, and (c) makes any developer-provided impact assessment available to consumers, is exempt from the § 6-1-1703(2) risk-management-policy duty and the § 6-1-1703(3) impact-assessment duty. The small-business deployer still owes all consumer-notice, appeal, public-statement, and Attorney General reporting duties.
What are the penalties for violating SB 24-205 (repealed)?
Violations of the Colorado AI Act are treated as unfair or deceptive trade practices under the Colorado Consumer Protection Act. Under § 6-1-112 the AG can seek civil penalties of up to $20,000 per violation. Each affected consumer can constitute a separate violation. Enforcement is exclusive to the Colorado Attorney General under § 6-1-1706 — there is no private right of action. § 6-1-1706(3) provides an affirmative defense where the developer or deployer discovers the violation through required feedback, adversarial testing, or internal review, cures the violation, and is otherwise in compliance with a nationally or internationally recognized AI risk management framework such as NIST AI RMF or ISO/IEC 42001.
How did SB 24-205 compare to the EU AI Act?
Both regulated high-risk AI, but the Colorado Act was narrower and consumer-focused. The EU AI Act (Regulation (EU) 2024/1689) has four risk tiers, applies extraterritorially to any AI placed on the EU market, imposes conformity assessments, requires CE marking for high-risk systems, and can fine up to €35M or 7% of global turnover. SB 24-205 had effectively two tiers (high-risk vs. everything else), applied only to persons doing business in Colorado, required impact assessments and consumer notices, and capped penalties at $20,000 per violation. SB 24-205 has since been repealed; its replacement, SB 26-189, is narrower still (notice, explanation and documentation duties rather than impact assessments).
What is an impact assessment under SB 24-205 § 6-1-1703(3) (repealed)?
The impact assessment required by § 6-1-1703(3) must include: (1) a statement of the purpose, intended use cases, and deployment context of the high-risk AI system; (2) the categories of data the system processes and the categories of outputs the system produces; (3) an analysis of whether the deployment of the system poses any known or reasonably foreseeable risks of algorithmic discrimination and, if so, the nature of that discrimination and the steps taken to mitigate it; (4) an overview of the categories of data processed as inputs and outputs; (5) any metrics used to evaluate the performance and known limitations of the system; (6) a description of the transparency measures taken; and (7) a description of the post-deployment monitoring and user safeguards provided.
Does this checker replace legal advice?
No. This is a self-service preliminary check based on the plain text of the repealed SB 24-205 as codified at C.R.S. § 6-1-1701 et seq. It is useful for internal triage and for reusing existing controls, but it is not a determination under SB 26-189. Treat the output as a structured starting point for counsel, not a substitute for it.
These vendors run AI governance programs mapped to NIST AI RMF, ISO/IEC 42001, and the EU AI Act. Check each profile for documented support of consumer notices, adverse-decision explanations, and developer documentation — the core SB 26-189 duties.
Embed this tool
Paste this snippet on your site to embed the Colorado AI Act checker. Attribution to aicompliancevendors.com is required.
<iframe src="https://aicompliancevendors.com/tools/colorado-ai-act-compliance-checker?embed=1" width="100%" height="820" style="border:1px solid #e5e7eb;border-radius:12px" loading="lazy" title="Colorado AI Act Compliance Checker"></iframe>