Colorado Releases Draft Regulations for AI Law and Chatbot Safety Act (Disclosure, Human Review Requirements, and More)

Weekly Update, Vol. 109.

Key Takeaways

  • Colorado's proposed AI law regulations detail how businesses must comply with disclosure and transparency requirements when automated decision-making technology is used in consequential areas like employment, housing, and health care starting January 1, 2027.
  • Deployers must provide detailed explanations following adverse outcomes, including the specific role the automated system played in the decision and the principal reasons for the outcome, with generic statements about "internal policies" deemed insufficient.
  • Colorado developers must give deployers comprehensive documentation about their systems, including intended uses, known limitations, training data categories, and instructions for appropriate human review.
  • Human review following an adverse outcome must involve a trained reviewer with actual authority to override the decision, and the reviewer cannot use automated decision-making technology to assist in the review process.
  • The Chatbot Safety Act regulations require conversational AI services to clearly disclose to minors that they are interacting with AI, with the disclaimer remaining continuously visible throughout screen-based conversations.
  • If you're a subscriber, click here for the full edition of this update. Or, click here to learn more about our MultiState.ai+ subscription.

Colorado lawmakers substantially rewrote the state's landmark artificial intelligence law earlier this year, replacing its broader anti-discrimination framework with a narrower set of requirements focused on transparency, that apply only when automated decision-making technology (ADMT) is used in certain "consequential areas." Proposed regulations released this month by the Office of the Attorney General detail how the new law will be implemented, providing businesses with more specific instructions on compliance. They also set requirements for conversational AI services to implement a chatbot bill passed this session.

Colorado's new AI law (CO SB 189) applies when ADMT is used to materially influence consequential decisions involving areas such as employment, education, housing, lending, insurance, health care, and government benefits. Beginning January 1, 2027, developers must provide deployers with documentation about their systems, including intended uses, known limitations and risks, training-data categories, and instructions for appropriate use and human review. Deployers, meanwhile, must notify consumers when covered ADMT is used and provide additional disclosures following an adverse outcome, including an explanation of the decision and the role played by the automated system. The law also gives affected consumers rights, in certain circumstances, to seek meaningful human review of a decision.

Defining Key Terms

Automated Decision-Making Technology (ADMT)

Automated decision-making technology refers to systems that use algorithms, machine learning, or artificial intelligence to make or materially influence decisions without direct human involvement. Under Colorado SB 189, ADMT is regulated when it is used to materially influence consequential decisions in areas such as employment, education, housing, lending, insurance, health care, and government benefits. The law requires developers and deployers of ADMT to provide transparency, documentation, and safeguards to ensure consumers understand how these systems affect decisions that impact their lives.

US map of companion chatbot legislation in 2026 with dark blue for introduced and teal for enacted states as of August 17 2026

Frequently Asked Questions

What disclosures must Colorado businesses provide to consumers when using automated decision-making technology under SB 189?

Under Colorado's proposed AI regulations, deployers must notify consumers when ADMT is used to materially influence consequential decisions and provide detailed disclosures following adverse outcomes. These disclosures must explain the decision in plain language, describe the role the ADMT played, identify the principal reasons for the outcome with specificity, and reveal any personal data, inferences, scores, or missing information that led to the decision. All notices must be accessible to people with disabilities, available in languages the deployer ordinarily uses, and readable across devices including mobile.

What documentation do AI developers need to provide to deployers under Colorado SB 189?

Developers must provide deployers with comprehensive documentation that gives a meaningful understanding of the ADMT's limitations, known risks, and circumstances where it should not be used. This includes identifying intended and inappropriate uses for consequential decisions, describing training data categories in sufficient detail, providing instructions for data requirements and performance monitoring, and explaining methods for determining the reasoning behind outputs. For midstream developers who incorporate another developer's ADMT into their own product, they must make reasonable efforts to obtain required documentation from upstream developers and pass necessary information downstream.

When is meaningful human review required under Colorado's AI law and what does it involve?

Meaningful human review is required following an adverse outcome when it is commercially reasonable, with the presumption flipping for severe and irreversible denials of basic human needs. The reviewer must be independent when feasible, possess subject-matter knowledge and training on the ADMT, have actual authority to approve, modify, or override the decision, and cannot use ADMT to assist in the review. Deployers must acknowledge requests within 10 days, complete review within 45 days, and stay the adverse outcome during review when possible.

What are the chatbot disclosure requirements for minors under Colorado HB 1263?

Once an operator determines or estimates a user is a minor, they must clearly disclose that the user is interacting with AI rather than a human. For screen-based services, the disclaimer must remain continuously visible throughout the conversation, be visually distinct and at least as large as other interface text, and appear in the same language as the conversation or account settings. Operators must also implement safeguards to prevent fostering emotional dependence or isolation, allow minors to control whether prior interaction information is retained, and establish protocols for responding to suicidal ideation and self-harm.

What does "materially influence" mean for determining when Colorado's AI law applies to automated decision-making?

Colorado SB 189 defines material influence as an ADMT output being a "non-de minimis factor" in a consequential decision, but the proposed regulations have not yet resolved the specific threshold. The Attorney General's Office is considering two competing standards: one treating an output as non-de minimis unless its impact is merely trifling, trivial, or incidental, and another allowing an output to be de minimis if other independent factors played a significantly larger role. This determination is significant because it establishes the threshold for coverage under the law.

Next
Next

AI Workforce Protection Bills Emerge as States Weigh Job Displacement Risks