Skip to content
Wednesday, August 26, 2026
3G TIMESFINTECH LAW · LEGAL TECH · COMPLIANCE
Home / Regulation
Regulation

Colorado AI Act After the Delay: What Deployers of Underwriting Models Must Build by June 30

SB 25B-004 pushed the Colorado AI Act to June 30, 2026, and the five-month reprieve is best spent building the impact-assessment file the statute already requires.

William Elliott, · January 22, 2026 · 7 min read
ShareXFacebookLinkedInTelegramEmail
Timeline infographic of Colorado AI Act compliance milestones to June 2026

The Colorado AI Act, SB 24-205, takes effect June 30, 2026 after the legislature's special-session delay bill SB 25B-004, signed August 28, 2025, pushed the date back five months — and deployers of high-risk artificial intelligence in lending and insurance still owe reasonable care against algorithmic discrimination, annual impact assessments, and consumer notice under the statute as amended. The delay changed the calendar, not the compliance architecture.

3G Times publishes information, not legal advice; the Act's applicability turns on an entity's role and the decision's materiality, and Colorado-specific questions belong with qualified counsel.

What does the Colorado AI Act actually regulate?

The Act targets algorithmic discrimination in "consequential decisions" — determinations with material legal or similarly significant effects on consumers, expressly including lending, insurance underwriting, housing, employment, education enrollment, and access to healthcare services. It assigns duties to two roles: developers, who build or substantially modify the system, and deployers, who use it to make decisions about Colorado consumers. A fintech that licenses a third-party underwriting model and applies it to applicants is a deployer; the same fintech becomes a developer if it materially retrains or re-engineers the model. Enforcement sits with the Colorado Attorney General — the statute created no private right of action, though nothing in it displaces claims under other laws.

Who owes what, in one table

Insurance distribution deserves a separate mention because the Act's earliest intense readers were insurers, not lenders. Underwriting models for coverage eligibility and pricing are consequential decisions in the same sense, and the impact-assessment discipline maps onto the actuarial governance insurers already keep — with the difference that Colorado's file is consumer-facing in its notice elements and regulator-facing in its retention. Insurers and their fintech distribution partners should align on who holds the file, since the deployer of record owes it.

DutyDeveloperDeployer
Reasonable care to avoid algorithmic discriminationYes, including pre-release testingYes, including use consistent with intended purpose
Impact assessmentsOwn the system's development documentationAnnual assessment per system, retained and disclosed to AG on request
Consumer noticeIndirect, via deployer-facing documentationStatement when AI is used in the decision, with purpose and contact
Documentation to counterpartiesDisclose known risks and intended uses to deployersMaintain deployment records, notices, and assessment files
Adverse-decision explanationSupport deployers' reason generationProvide the principal reasons on request, in plain language

What changed with the five-month delay?

Two things, one procedural and one substantive in effect. Procedurally, SB 25B-004 moved the effective date to June 30, 2026, after the 2025 regular session's amendment efforts stalled and stakeholders — including fintech and insurance trade groups — negotiated further refinements. Substantively, the delay concentrates risk in the 2026 legislative session: the General Assembly returns with unfinished business, and further amendment remains live. Compliance teams should therefore build to the statute as it stands while tracking each new reading, because the impact-assessment file is robust to amendment in a way that point-in-time checklists are not.

What should the June 30 file contain?

The impact assessment is the statute's center of gravity for deployers. A defensible one documents the system's purpose and the decision it drives; the populations it scores, with demographic reach; the testing performed for discrimination risk — including the vendor's pre-release testing, demanded through procurement; known risks and mitigations; the monitoring design post-deployment; and the human oversight arrangements. Alongside it sit the consumer notice (deployed at decision time, stating that an AI system contributes to the decision), the adverse-reason pathway, and the retention program — assessments and notices kept for the statutory period and producible to the Attorney General. Data protection runs through it: processing must comply with the Colorado Privacy Act where that law applies, which imports data-minimization and purpose-limitation duties into the assessment's evidence.

How does the Act interact with federal fair-lending law?

Overlap, not conflict. The Act's algorithmic-discrimination standard is a Colorado consumer-protection duty; federal fair-lending law — the Equal Credit Opportunity Act and its implementing regulation — reaches credit decisions on protected bases through a separate, older machinery of disparate treatment and disparate impact analysis. A deployer running both regimes on one underwriting model does the work once and files it twice: the impact assessment's testing evidence, segmentation data, and remediation record map almost line-for-line onto what fair-lending exams request, and the Act's "reasonable care" posture is evidenced by the same monitoring cadence. The differences that remain are real but narrow: the Act covers consequential decisions beyond credit, defines its roles by system function rather than creditor status, and routes enforcement through the Attorney General rather than the federal banking agencies. Institutions already running model-risk and fair-lending monitoring under SR 11-7-grade programs will find the June 30 file mostly assembles itself from artifacts that exist; the gap is usually documentation form, not substance — Colorado wants the assessment as a standing document with dated updates, not a folder of monitoring decks.

What does this mean in practice?

Colorado remains the most comprehensive state algorithmic-discrimination statute on the calendar, and its June 30, 2026 date is now the anchor of the American compliance year. Deployers who treat the delay as runway rather than reprieve will meet it with the one thing regulators read first: the file.

Do small deployers get scaled obligations?

The Act contains no small-business exemption, but its duties are framed in reasonableness rather than fixed costs, which scales in practice: a single-system deployer using a vendor model, one annual assessment built from the vendor's testing evidence, and a working notice-and-reasons pathway is the defensible minimum posture. The scale-up risk sits in procurement — smaller deployers inherit the documentation gaps of vendors who never built it.

Frequently asked questions

Does the Colorado AI Act allow private lawsuits?

No. Enforcement belongs to the Colorado Attorney General, and the Act itself creates no private right of action. That does not immunize deployers from other theories — unfair-practices, fair-lending, or contract claims — which is why the impact-assessment file doubles as civil-defense evidence.

Is a fintech using a vendor's scoring model a deployer or developer?

A deployer, while it uses the system as licensed. It becomes a developer if it substantially modifies the model — material retraining on its own data, architectural changes — which is why procurement language should draw the modification line explicitly and reserve retraining decisions for documented review.

What if the system never touches Colorado consumers?

The Act is written around Colorado consumers, so genuinely out-of-state deployment falls outside it. But "genuinely" is the operative word: national onboarding funnels and nationwide marketing make residency exclusions hard to prove, and most deployers default to compliance rather than geo-fencing their risk.

Frequently Asked Questions

Does the Colorado AI Act allow private lawsuits?
No. Enforcement belongs to the Colorado Attorney General and the Act creates no private right of action, though other theories — fair-lending, unfair-practices, contract — remain available, which is why the assessment file doubles as defense evidence.
Is a fintech using a vendor's scoring model a deployer or developer?
A deployer while it uses the system as licensed; it becomes a developer upon substantial modification such as material retraining or architectural change. Procurement language should draw that line explicitly.
What if the system never touches Colorado consumers?
The Act is written around Colorado consumers, so genuinely out-of-state deployment falls outside it. National onboarding funnels make residency exclusions hard to prove, and most deployers default to compliance rather than geo-fencing.