Free tool
Colorado AI Act (SB 24-205) Compliance Checker
Classify your AI system under Colorado Revised Statutes § 6-1-1701 et seq. and generate a gap report tied to every developer and deployer duty. Effective 1 February 2026.
The Colorado AI Act becomes enforceable on 1 February 2026. SB 24-205 is the first US comprehensive state AI consumer-protection law. This free tool runs entirely in your browser, cites every obligation to its statute section, and produces a downloadable report you can hand to counsel or your board.
Answer 11 questions
Nothing leaves your browser. Sources cite Colorado Revised Statutes § 6-1-1701 et seq.
How this Colorado AI Act checker works
This checker maps your answers to the text of Colorado SB 24-205 as codified at Colorado Revised Statutes § 6-1-1701 et seq. It uses the statute’s own definitions of developer (§ 6-1-1701(7)), deployer (§ 6-1-1701(8)), high-risk artificial intelligence system (§ 6-1-1701(9)), consequential decision (§ 6-1-1701(3)), and substantial factor (§ 6-1-1701(11)). Every obligation surfaced in the output is tied to the statute section that creates it, so the downloadable report is defensible when handed to counsel or an internal auditor.
Nothing you type leaves your browser. There is no login, no email gate, and no server-side storage. The classification logic is pure deterministic TypeScript published under src/lib/colorado-ai-act.ts in the open-source repository. You can inspect exactly how each answer maps to each obligation.
When to use this Colorado AI Act tool
- You are a US employer using AI for hiring, promotion, or workforce management and you employ Colorado residents.
- You are a lender, insurer, healthcare provider, housing platform, or education provider serving Colorado consumers with any AI-assisted decisioning.
- You are a SaaS AI developer selling into Colorado-based enterprises and you need to prepare the § 6-1-1702(2)(a) documentation your deployer customers will ask for.
- You are on a compliance team and you need a defensible one-page classification to justify budget for impact assessments and risk-management programs before 1 February 2026.
- You already comply with the EU AI Act, ISO/IEC 42001, or NIST AI RMF and you want to confirm what the Colorado-specific delta actually costs.
Colorado AI Act timeline
| Date | Event | Citation |
|---|---|---|
| 17 May 2024 | Governor Polis signs SB 24-205 into law. | Source |
| 2024–2025 | Colorado AI Impact Task Force convened; Attorney General authorized to issue rules under § 6-1-1707. | Source |
| 1 February 2026 | Effective date. All developer and deployer duties under §§ 6-1-1702, 6-1-1703, 6-1-1704 become enforceable. | Source |
Colorado AI Act frequently asked questions
What is the Colorado AI Act (SB 24-205)?
Colorado SB 24-205, codified at Colorado Revised Statutes § 6-1-1701 et seq., is the first US comprehensive state AI consumer-protection law. Governor Polis signed it on 17 May 2024. It regulates developers and deployers of high-risk AI systems that make, or are a substantial factor in making, consequential decisions concerning Colorado consumers in eight enumerated categories: employment, education, financial or lending services, essential government services, healthcare services, housing, insurance, and legal services.
When does the Colorado AI Act take effect?
The Act becomes enforceable on 1 February 2026. Governor Polis has publicly stated that the effective date may be delayed by future amendments, but until any amendment is enacted the 1 February 2026 date is the legal baseline. Rulemaking by the Colorado Attorney General under § 6-1-1707 may add specificity before the effective date.
Who is a developer vs. a deployer under the Colorado AI Act?
A developer, defined in § 6-1-1701(7), is a person doing business in Colorado that develops, or intentionally and substantially modifies, a high-risk AI system. A deployer, defined in § 6-1-1701(8), is a person doing business in Colorado that deploys a high-risk AI system. The same organization can be both for different systems. Developer duties sit in § 6-1-1702; deployer duties in § 6-1-1703.
What counts as a "consequential decision" under the Act?
Under § 6-1-1701(3), a consequential decision is a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of, education enrollment or opportunity, employment or employment opportunity, financial or lending services, essential government services, healthcare services, housing, insurance, or a legal service. Marketing, entertainment, and non-consumer-facing back-office AI is not consequential.
What is the substantial-factor test?
Under § 6-1-1701(11), an AI system is a substantial factor in a consequential decision if it (a) assists in making the decision, (b) is capable of altering the outcome of the decision, and (c) is used to generate content, decisions, predictions, or recommendations that serve as a principal basis for the decision. Human reviewers rubber-stamping AI output does not remove the substantial-factor status.
What is the small-business exemption?
Under § 6-1-1703(6), a deployer with fewer than 50 full-time employees that (a) does not use its own data to train the high-risk AI system, (b) uses the system for its intended uses as disclosed by the developer, and (c) makes any developer-provided impact assessment available to consumers, is exempt from the § 6-1-1703(2) risk-management-policy duty and the § 6-1-1703(3) impact-assessment duty. The small-business deployer still owes all consumer-notice, appeal, public-statement, and Attorney General reporting duties.
What are the penalties for violating the Colorado AI Act?
Violations of the Colorado AI Act are treated as unfair or deceptive trade practices under the Colorado Consumer Protection Act. Under § 6-1-112 the AG can seek civil penalties of up to $20,000 per violation. Each affected consumer can constitute a separate violation. Enforcement is exclusive to the Colorado Attorney General under § 6-1-1706 — there is no private right of action. § 6-1-1706(3) provides an affirmative defense where the developer or deployer discovers the violation through required feedback, adversarial testing, or internal review, cures the violation, and is otherwise in compliance with a nationally or internationally recognized AI risk management framework such as NIST AI RMF or ISO/IEC 42001.
How does the Colorado AI Act compare to the EU AI Act?
Both regulate high-risk AI, but the Colorado Act is narrower and consumer-focused. The EU AI Act (Regulation (EU) 2024/1689) has four risk tiers, applies extraterritorially to any AI placed on the EU market, imposes conformity assessments, requires CE marking for high-risk systems, and can fine up to €35M or 7% of global turnover. The Colorado Act has effectively two tiers (high-risk vs. everything else), applies only to persons doing business in Colorado, requires impact assessments and consumer notices, and caps penalties at $20,000 per violation. Many organizations that comply with the EU AI Act will find Colorado compliance is a lighter lift built on the same evidence.
What is an impact assessment under § 6-1-1703(3)?
The impact assessment required by § 6-1-1703(3) must include: (1) a statement of the purpose, intended use cases, and deployment context of the high-risk AI system; (2) the categories of data the system processes and the categories of outputs the system produces; (3) an analysis of whether the deployment of the system poses any known or reasonably foreseeable risks of algorithmic discrimination and, if so, the nature of that discrimination and the steps taken to mitigate it; (4) an overview of the categories of data processed as inputs and outputs; (5) any metrics used to evaluate the performance and known limitations of the system; (6) a description of the transparency measures taken; and (7) a description of the post-deployment monitoring and user safeguards provided.
Does this checker replace legal advice?
No. This is a self-service preliminary check based on the plain text of SB 24-205 as codified at C.R.S. § 6-1-1701 et seq. The output is a defensible first-pass classification suitable for internal triage, vendor scoping, and budget planning. Rules promulgated by the Colorado Attorney General under § 6-1-1707 may add specificity before the 1 February 2026 effective date. Treat the checker output as a structured starting point for counsel, not a substitute for it.
Official sources
- SB 24-205 — Colorado General Assembly bill page
- Signed bill text (PDF)
- Colorado Attorney General — Artificial Intelligence resources
- Deep dive: how to prepare for the Colorado AI Act (aicompliancevendors.com)
- Colorado AI law tracker (ailawsbystate.com)
Related free tools
Classify AI under Regulation (EU) 2024/1689 with Articles 5, 6, 50, Annex III citations.
Build a Fundamental Rights Impact Assessment aligned to EU AI Act Article 27.
14 pre-filled risks mapped to NIST AI RMF, ISO 42001, OWASP LLM Top 10, and EU AI Act Article 9.
Range estimates for SOC 2, ISO 42001, EU AI Act, and NIST AI RMF programs. Priced vendor comparisons.
Vendors that help with Colorado AI Act compliance
The Attorney General’s § 6-1-1706(3) affirmative defense explicitly credits organizations that are “otherwise in compliance with a nationally or internationally recognized AI risk management framework.” The following vendors run programs mapped to NIST AI RMF, ISO/IEC 42001, and the EU AI Act and can be repurposed as your Colorado AI Act evidence trail:
Paste this snippet on your site to embed the Colorado AI Act compliance checker. Attribution to aicompliancevendors.com is required.
<iframe src="https://aicompliancevendors.com/tools/colorado-ai-act-compliance-checker?embed=1" width="100%" height="820" style="border:1px solid #e5e7eb;border-radius:12px" loading="lazy" title="Colorado AI Act Compliance Checker"></iframe>