The Colorado AI Act, SB 24-205, takes effect June 30, 2026 after the legislature's special-session delay bill SB 25B-004, signed August 28, 2025, pushed the date back five months — and deployers of high-risk artificial intelligence in lending and insurance still owe reasonable care against algorithmic discrimination, annual impact assessments, and consumer notice under the statute as amended. The delay changed the calendar, not the compliance architecture.
3G Times publishes information, not legal advice; the Act's applicability turns on an entity's role and the decision's materiality, and Colorado-specific questions belong with qualified counsel.
What does the Colorado AI Act actually regulate?
The Act targets algorithmic discrimination in "consequential decisions" — determinations with material legal or similarly significant effects on consumers, expressly including lending, insurance underwriting, housing, employment, education enrollment, and access to healthcare services. It assigns duties to two roles: developers, who build or substantially modify the system, and deployers, who use it to make decisions about Colorado consumers. A fintech that licenses a third-party underwriting model and applies it to applicants is a deployer; the same fintech becomes a developer if it materially retrains or re-engineers the model. Enforcement sits with the Colorado Attorney General — the statute created no private right of action, though nothing in it displaces claims under other laws.
Who owes what, in one table
| Duty | Developer | Deployer |
|---|---|---|
| Reasonable care to avoid algorithmic discrimination | Yes, including pre-release testing | Yes, including use consistent with intended purpose |
| Impact assessments | Own the system's development documentation | Annual assessment per system, retained and disclosed to AG on request |
| Consumer notice | Indirect, via deployer-facing documentation | Statement when AI is used in the decision, with purpose and contact |
| Documentation to counterparties | Disclose known risks and intended uses to deployers | Maintain deployment records, notices, and assessment files |
| Adverse-decision explanation | Support deployers' reason generation | Provide the principal reasons on request, in plain language |
What changed with the five-month delay?
Two things, one procedural and one substantive in effect. Procedurally, SB 25B-004 moved the effective date to June 30, 2026, after the 2025 regular session's amendment efforts stalled and stakeholders — including fintech and insurance trade groups — negotiated further refinements. Substantively, the delay concentrates risk in the 2026 legislative session: the General Assembly returns with unfinished business, and further amendment remains live. Compliance teams should therefore build to the statute as it stands while tracking each new reading, because the impact-assessment file is robust to amendment in a way that point-in-time checklists are not.
What should the June 30 file contain?
The impact assessment is the statute's center of gravity for deployers. A defensible one documents the system's purpose and the decision it drives; the populations it scores, with demographic reach; the testing performed for discrimination risk — including the vendor's pre-release testing, demanded through procurement; known risks and mitigations; the monitoring design post-deployment; and the human oversight arrangements. Alongside it sit the consumer notice (deployed at decision time, stating that an AI system contributes to the decision), the adverse-reason pathway, and the retention program — assessments and notices kept for the statutory period and producible to the Attorney General. Data protection runs through it: processing must comply with the Colorado Privacy Act where that law applies, which imports data-minimization and purpose-limitation duties into the assessment's evidence.
How does the Act interact with federal fair-lending law?
Overlap, not conflict. The Act's algorithmic-discrimination standard is a Colorado consumer-protection duty; federal fair-lending law — the Equal Credit Opportunity Act and its implementing regulation — reaches credit decisions on protected bases through a separate, older machinery of disparate treatment and disparate impact analysis. A deployer running both regimes on one underwriting model does the work once and files it twice: the impact assessment's testing evidence, segmentation data, and remediation record map almost line-for-line onto what fair-lending exams request, and the Act's "reasonable care" posture is evidenced by the same monitoring cadence. The differences that remain are real but narrow: the Act covers consequential decisions beyond credit, defines its roles by system function rather than creditor status, and routes enforcement through the Attorney General rather than the federal banking agencies. Institutions already running model-risk and fair-lending monitoring under SR 11-7-grade programs will find the June 30 file mostly assembles itself from artifacts that exist; the gap is usually documentation form, not substance — Colorado wants the assessment as a standing document with dated updates, not a folder of monitoring decks.
What does this mean in practice?
- Run one assessment per consequential system per year. A single underwriting engine serving two products is one system; two engines bought from different vendors are two files.
- Pull the vendor's SB 24-205 documentation now. Developer duties flow through contracts — intended-use statements, testing evidence, and update notifications belong in the procurement template with delivery dates.
- Wire reasons to notices. The plain-language explanation duty assumes the reason pipeline exists; test it on real denials before June 30, not after.
- Watch the 2026 session. Further amendments are the stated purpose of the delay; a named owner should brief the file's owners within a week of any bill movement.
Colorado remains the most comprehensive state algorithmic-discrimination statute on the calendar, and its June 30, 2026 date is now the anchor of the American compliance year. Deployers who treat the delay as runway rather than reprieve will meet it with the one thing regulators read first: the file.
Do small deployers get scaled obligations?
The Act contains no small-business exemption, but its duties are framed in reasonableness rather than fixed costs, which scales in practice: a single-system deployer using a vendor model, one annual assessment built from the vendor's testing evidence, and a working notice-and-reasons pathway is the defensible minimum posture. The scale-up risk sits in procurement — smaller deployers inherit the documentation gaps of vendors who never built it.
Frequently asked questions
Does the Colorado AI Act allow private lawsuits?
No. Enforcement belongs to the Colorado Attorney General, and the Act itself creates no private right of action. That does not immunize deployers from other theories — unfair-practices, fair-lending, or contract claims — which is why the impact-assessment file doubles as civil-defense evidence.
Is a fintech using a vendor's scoring model a deployer or developer?
A deployer, while it uses the system as licensed. It becomes a developer if it substantially modifies the model — material retraining on its own data, architectural changes — which is why procurement language should draw the modification line explicitly and reserve retraining decisions for documented review.
What if the system never touches Colorado consumers?
The Act is written around Colorado consumers, so genuinely out-of-state deployment falls outside it. But "genuinely" is the operative word: national onboarding funnels and nationwide marketing make residency exclusions hard to prove, and most deployers default to compliance rather than geo-fencing their risk.
For more context, read EU AI Act Before August 2026: Credit-Scoring Deployers, FRIAs, and the Human-Oversight File.
For more context, read utah ai policy act sb 149.
For more context, read illinois bipa 2024 amendments.

