Colorado ADMT Act Checklist: What Deployers Need by January 1, 2027

By Zachariah Crabill, JD · FAIIR, LLC · Updated

The short answer

The Colorado ADMT Act (SB 26-189) takes effect January 1, 2027. Businesses that use automated decision-making technology to materially influence consequential decisions in seven domains must give pre-use notice, send adverse-outcome disclosures within 30 days, offer data access and correction, offer meaningful human review where commercially reasonable, and keep records for three years. The Colorado Attorney General enforces it; there is no small-business exemption.

Key takeaways

  • The Colorado ADMT Act (SB 26-189) applies to consequential decisions made on or after January 1, 2027, and replaces the 2024 Colorado AI Act (SB 24-205).
  • A deployer has five duties: pre-use notice, a 30-day adverse-outcome disclosure, data access and correction, meaningful human review where commercially reasonable, and three-year records.
  • Tools used solely to summarize, organize, translate, draft, route, or present information for human review of administrative processing are excluded from the definition of ADMT.
  • The Attorney General's proposed rules (4 CCR 904-6) are not final; written comments and the rulemaking hearing are both set for October 26, 2026.
  • Only the Attorney General can enforce the Act, violations are deceptive trade practices under the Colorado Consumer Protection Act, and the 60-day cure provision sunsets January 1, 2030.

The Colorado ADMT Act (SB 26-189, signed May 14, 2026) takes effect January 1, 2027 and applies to consequential decisions made on or after that date. It repeals and reenacts C.R.S. §§ 6-1-1701 to -1709, replacing the 2024 Colorado AI Act (SB 24-205). If your business uses software that scores, ranks, or recommends outcomes for people in areas like hiring, lending, insurance, or residential real estate, this checklist walks through what the statute requires deployers to do and what records show you did it.

Does the Colorado ADMT Act apply to your business?

The Act applies to a deployer: a person doing business in Colorado that uses a covered ADMT. Covered ADMT is technology that processes personal data and whose output is used to materially influence a consequential decision in one of seven domains (§ 6-1-1701). "Consumer" includes employees, Colorado-resident job applicants, and anyone whose access or eligibility in Colorado is evaluated in a consequential decision.

The seven covered domains

  • Education enrollment or an education opportunity
  • Employment or an employment opportunity that creates or may create an employer–employee relationship
  • The lease or purchase of residential real estate in Colorado
  • Financial or lending services
  • Insurance, including underwriting, pricing, coverage, and claims
  • Health-care services
  • Essential government services and public benefits

Legal services, which appeared in the 2024 law, is not on the list.

What does "materially influence" mean?

An output materially influences a decision when it is a non-de minimis factor used in making the decision and it affects the outcome, including by constraining, ranking, scoring, recommending, or classifying (§ 6-1-1701(13)). Incidental, trivial, or clerical uses do not count. The Attorney General is weighing two ways to define "de minimis" in rules: a "trifling, trivial, or incidental" test and a "not a substantial factor" test. Neither is final.

What is excluded?

  • Summarize-and-draft tools. A tool used solely to summarize, organize, translate, draft, route, or present information for human review of administrative processing is not ADMT (§ 6-1-1701(2)(b)(II)). Note the full phrase: the exclusion is narrower than any drafting tool.
  • General chat tools kept out of decisions. Consumer-facing conversational technology is not ADMT if it is not contracted, marketed, configured, or intended for consequential decisions and is subject to an acceptable use policy that prohibits using its content in one (§ 6-1-1701(2)(b)(III)).
  • Routine processes. Routine scheduling, customer service triage, communication of decisions, advertising, and marketing are not consequential decisions (§ 6-1-1701(3)(b)).
  • HIPAA entities, except employment. HIPAA covered entities and their business associates are largely exempt, but not for employment decisions; covered entities must still give patients a general notice of advanced technologies (§ 6-1-1708(3), as enacted by SB 26-189).
  • Insurers. Insurers subject to § 10-3-1104.9 are deemed compliant in the practice of insurance (§ 6-1-1708(1), as enacted by SB 26-189).

There is no small-business exemption. A ten-person property manager using a tenant-screening score is treated the same as a national lender.

What are the five deployer duties under the ADMT Act?

The statute requires deployers to give notice before use, explain adverse outcomes, honor data and review requests, and keep records. Each duty below lists the section and the artifact that would show you met it.

1. Pre-use notice — § 6-1-1704(1)–(2)

Before using covered ADMT in a consequential decision, a deployer must give a clear and conspicuous notice that it uses or will use covered ADMT, with instructions for getting more information. Subsection (2) says a prominent public notice, reasonably accessible at points of consumer interaction (such as a link near the application), satisfies the duty. Evidence: the notice text, dated screenshots of where it appears, and the approval record.

2. Adverse-outcome disclosure within 30 days — § 6-1-1704(3)

If covered ADMT materially influences a decision that results in an adverse outcome, the deployer must provide, within 30 days: a plain-language description of the decision and the role the ADMT played; a simple process to request more information (including the tool's name, version number, developer, and the types, categories, and sources of personal data used); and an explanation of the consumer's rights. A creditor's ECOA or FCRA adverse-action notice can satisfy this duty if it also covers these elements (§ 6-1-1704(6)). Evidence: a disclosure template, a send log with decision and delivery dates, and the vendor documentation that supplied the version and data details.

3. Data access and correction — § 6-1-1705(1)(a)(I)

After an adverse outcome, a consumer may request instructions for obtaining the personal data used and correcting data that is factually incorrect or materially inaccurate. The duty does not extend to correcting opinions, predictions, or scores (§ 6-1-1705(1)(c)). Evidence: a written intake procedure, a request log with response dates, and a data map showing which inputs feed each tool.

4. Meaningful human review — § 6-1-1705(1)(a)(II)

The consumer may also request meaningful human review and reconsideration "to the extent commercially reasonable." The statute defines the reviewer as someone the deployer designates with authority to approve, modify, or override the decision, who considers relevant primary evidence, is trained, does not default to the system output, and has access to enough information to understand the output's intended use, limitations, inputs, and principal factors (§ 6-1-1701(15)). Evidence: reviewer designations, training records, and a review log. See how to design meaningful human review.

5. Three-year records — § 6-1-1703

Deployers must keep records reasonably necessary to demonstrate compliance for at least three years after each consequential decision. Records may include ADMT version identifiers, changelogs, and documentation of material mitigation changes. Evidence: a retention schedule, a decision log, and a version-and-change log for each tool.

Developers owe deployers documentation under § 6-1-1702: intended uses and uses to avoid, training-data categories to the extent known, known limitations and risks, and monitoring and human-review instructions. Contract clauses that shift liability for a party's own discriminatory acts are void (§ 6-1-1707(7)). Our AI vendor due diligence questions cover what to ask for.

What would the proposed Attorney General rules add?

The Attorney General's proposed rules, 4 CCR 904-6, filed August 11, 2026, would add detail to each duty. They are proposed, not final. The AG said it would post any pre-hearing changes by September 23, 2026; check coag.gov/ai for the current version before relying on any rule number.

  • Rule 3.2: every consumer notice in plain language and accessible, following WCAG 2.2 for online content.
  • Rule 4.2: a "Midstream Developer" that builds on another company's ADMT would pass upstream documentation down to its customers.
  • Rule 6: adverse-outcome disclosures would need specific principal reasons ("internal standards or policies" is expressly insufficient), the effective date, a simple process for more information, and at least two delivery methods where available.
  • Rule 7: consumer requests answered within 45 days, at least two request methods, and no requirement to create a new account.
  • Rule 7.7: the reviewer would be independent (not the original decision-maker or that person's subordinate, whenever feasible), trained, given meaningful authority, and shielded from steering and retaliation; "ADMT may not assist in the Meaningful Human Review." Review is presumed commercially reasonable when the harm is "a severe and irreversible denial of a basic human need," and the deployer's size and capacity is one factor.

How is the Colorado ADMT Act enforced?

Only the Colorado Attorney General enforces the Act. A violation is a deceptive trade practice under the Colorado Consumer Protection Act, with penalties of up to $20,000 per violation under the Consumer Protection Act (C.R.S. § 6-1-112). Before acting, the Attorney General must send a notice of violation and allow 60 days to cure, but only where the Attorney General deems a cure possible, and not for knowing or repeated violations. The cure provision sunsets January 1, 2030. The Act creates no private right of action (§ 6-1-1709), but existing claims, including under the Colorado Anti-Discrimination Act, remain available, and complying with the Act is not a defense under other law.

The 2024 law's duty of care regarding algorithmic discrimination, impact assessments, risk-management-program mandate, and Attorney General discrimination notices do not carry over.

What should an ADMT Act readiness checklist include?

A readiness checklist pairs each statutory duty with a document you can produce on request. The FAIIR control column shows where each item sits in the FAIIR framework.

Mapping of SB 26-189 deployer duties to evidence and FAIIR controls. Mapping is for governance organization only; it is not a legal determination.
Checklist itemStatuteEvidence artifactFAIIR control
Inventory AI tools and document which ones are covered ADMT, and why§ 6-1-1701(2), (5), (13)Use-case register with domain and material-influence analysis per toolF1 Use-Case Register; F2 Out-of-Scope Boundaries
Name an owner for ADMT complianceSupports all duties (not itself a statutory requirement)Written designation by roleA1 AI Officer Designated
Publish a pre-use notice at points of interaction§ 6-1-1704(1)–(2)Notice text, dated screenshots, approval recordU3 Customer Disclosure; A6 Customer Disclosure Path
Send adverse-outcome disclosures within 30 days§ 6-1-1704(3)Disclosure template; send log with decision and delivery datesU3 Customer Disclosure; A2 AI Decision Log
Collect developer documentation, including version numbers§ 6-1-1702; § 6-1-1704(3)(b)Vendor documentation file; contract review recordA3 Vendor Contract Review; A4 Liability Allocation; F6 Model/Version Tracking
Handle data access and correction requests§ 6-1-1705(1)(a)(I)Intake procedure; request log; data map of inputsI1 Data Classification Map; I2 AI-Permitted Data Rules
Offer meaningful human review and reconsideration§ 6-1-1705(1)(a)(II); § 6-1-1701(15)Reviewer designations, training records, review logF5 Human-in-the-Loop; U5 Opt-Out Available; U2 Employee Training
Make notices accessible§ 6-1-1704(8)Accessibility check of notices and request formsU3 Customer Disclosure
Keep records for three years after each decision§ 6-1-1703Retention schedule; decision log; change logR7 Audit Log Retention; A2 AI Decision Log; R9 Change Log

What are the key ADMT Act dates?

Sources: SB 26-189 and the Attorney General's notice of proposed rulemaking.
DateWhat happens
May 14, 2026SB 26-189 signed
August 11, 2026Attorney General files proposed rules 4 CCR 904-6
October 26, 2026Rulemaking hearing (10:00 a.m., hybrid) and deadline for written comments (11:59 p.m. MT), both extended if the hearing continues
January 1, 2027Act takes effect for consequential decisions made on or after this date; SB 24-205 repealed; final rules intended to take effect
January 1, 203060-day cure provision sunsets

Written comments go through the Attorney General's comment portal. If your business also runs a customer-facing chatbot, a separate law applies; see our Colorado Chatbot Safety Act guide.

Where FAIIR fits

The FAIIR standard's 41 pass/fail controls are mapped to the ADMT Act's deployer duties and benchmarked to the NIST AI Risk Management Framework, so the evidence above can be organized once and reviewed annually. Colorado law does not require, create, or recognize any third-party AI certification, and FAIIR certification is documented proof of reasonable care, not a guarantee of compliance.

Frequently asked questions

Does the Colorado ADMT Act apply to small businesses?

Yes, if the business is a deployer. SB 26-189 has no small-business exemption, so any business doing business in Colorado that uses covered ADMT to materially influence a consequential decision has the five deployer duties. Under the proposed rules, a deployer's size and capacity would be one factor in deciding whether meaningful human review is commercially reasonable.

Is using ChatGPT to draft emails covered by the Colorado ADMT Act?

Usually not, but look at how the tool is used rather than what it is. Section 6-1-1701(2)(b)(II) excludes tools used solely to summarize, organize, translate, draft, route, or present information for human review of administrative processing, and § 6-1-1701(3)(b) says routine tasks such as customer-service triage and communicating a decision are not consequential decisions. A tool that drafts an email and plays no part in deciding an outcome is unlikely to be covered ADMT. The analysis changes if the tool's output scores, ranks, or recommends an outcome in a consequential decision, so document how each tool is actually used.

Can a consumer sue a business under the Colorado ADMT Act?

No. Section 6-1-1709 says the Act creates no new private right of action, and only the Colorado Attorney General enforces it. Existing claims under other laws, such as the Colorado Anti-Discrimination Act, remain available.

Are the Colorado Attorney General's ADMT rules final?

No. The rules in 4 CCR 904-6 were proposed on August 11, 2026, with written comments due and a hearing held on October 26, 2026. The final rules are intended to take effect January 1, 2027. Check coag.gov/ai for the current draft.

Does FAIIR certification make a business compliant with the ADMT Act?

No. Colorado law does not require, create, or recognize any third-party AI certification. The FAIIR standard is mapped to the ADMT Act's deployer duties and helps a business organize evidence of reasonable care, but compliance depends on what the business actually does.

How is the ADMT Act different from the 2024 Colorado AI Act?

SB 26-189 replaces SB 24-205 effective January 1, 2027. It drops the duty of care regarding algorithmic discrimination, impact assessments, the risk-management-program mandate, and Attorney General discrimination notices, and it removes legal services from the covered domains. It focuses instead on notice, adverse-outcome disclosure, data correction, human review, and records.

Sources

  1. Colorado General Assembly, SB 26-189
  2. Colorado Attorney General, ADMT and Chatbot Safety rulemaking
  3. Proposed rules 4 CCR 904-6 (August 11, 2026 draft)
  4. Colorado Attorney General, ADMT rulemaking comment portal
  5. NIST AI Risk Management Framework

This article is general information from FAIIR, LLC, which is not a law firm, and is not legal advice. Colorado law does not require or recognize any third-party AI certification, and FAIIR certification is not a government approval or a guarantee of compliance. For advice about your situation, consult a licensed attorney.