Colorado Chatbot Safety Act (HB 26-1263): A Business Guide
By Zachariah Crabill, JD · FAIIR, LLC · Updated
The short answer
The Colorado Chatbot Safety Act (HB 26-1263) applies starting January 1, 2027 to any operator that offers a consumer-facing conversational AI service, with no size threshold. Operators must estimate user age, disclose that users are talking to AI, protect minors, run suicide and self-harm protocols, never present outputs as coming from a licensed health-care, legal, or mental-health professional or dietitian, and report annually from July 1, 2027.
Key takeaways
- Under HB 26-1263, offering a consumer-facing conversational AI service to a consumer is enough to make a business an operator; there is no size threshold.
- Some exclusions, including narrow-topic bots and consumer-device voice assistants, apply only if the bot cannot generate sexual content or maintain self-harm dialogue.
- Operators may not use any term in advertising, interface, or outputs suggesting a chatbot's output is provided by, endorsed by, or equivalent to a licensed health-care, legal, or mental-health professional or dietitian.
- The operator duties apply January 1, 2027, and annual reports to the Colorado Attorney General begin July 1, 2027.
- The Attorney General's proposed Rules 8–13 in 4 CCR 904-6 would add detail on exclusions, age assurance, disclosures, minors, impersonation, and reporting, but they are not final.
Colorado's Chatbot Safety Act, HB 26-1263, was signed May 29, 2026, and its operator duties apply January 1, 2027. It covers "conversational artificial intelligence services": AI systems accessible to the general public that primarily simulate human conversation through adaptive text, visual, or audio communication. If your website, app, or phone line uses a chatbot that talks with the public, this guide explains who the statute treats as an operator, which bots may fall outside it, and what the duties look like in practice.
Who counts as an "operator" under the Chatbot Safety Act?
An operator is a person or entity that either develops and makes publicly available a conversational AI service, or offers one to a consumer (§ 6-1-1701(15.5)). Offering is enough. A retailer, gym, or property manager that embeds a vendor's chatbot on its website can be an operator even though it built nothing. The statute sets no size threshold. App stores and search engines are not operators solely because they provide access to a chatbot.
Under the proposed rules, "accessible to the general public" would include free, subscription, and paywalled services, but not internal-only workforce deployments in restricted, authenticated environments.
Which chatbots are excluded from the Chatbot Safety Act?
The statute lists twelve kinds of software that are not conversational AI services (§ 6-1-1701(3.5)(b)). The ones most businesses will look at are:
- Commerce and customer support: software primarily designed for product recommendations, shopping, ordering, payments, delivery, returns, customer support, or customer service.
- Narrow, discrete topics: bots designed for a narrow topic that cannot generate sexually explicit outputs or maintain dialogue about suicidal ideation or self-harm.
- Business tools: software primarily designed and marketed to businesses for operations, productivity, analysis, internal research, training, or technical assistance.
- Internal tools: software a business uses solely for internal purposes.
- Voice assistants on consumer devices, but only if they cannot generate sexually explicit outputs or encourage self-harm dialogue.
- Health care: bots used by or on behalf of HIPAA covered entities or their business associates, or by entities subject to the Health Care Availability Act.
- Developer and research tools are excluded without further conditions.
- Video-game and theme-park features are excluded where their dialogue is limited to the game or park.
- School educational tools and features inside other software are excluded only if not designed to simulate emotional companionship or encourage emotionally dependent interaction.
The technical-capability condition attaches only to the narrow-topic and voice-assistant exclusions; the commerce and customer-support exclusion does not carry it. Where it applies, a bot that is narrow in purpose but runs on a general-purpose model that could be steered into sexual content or sustained self-harm conversation may not qualify. Proposed Rule 8.2 gives narrow-topic examples: "a status update about a purchase, answering a billing question, or scheduling an appointment," including menu-based and rule-based bots that meet the same capability limits.
| Bot type | Likely status | What to document |
|---|---|---|
| Order-status, returns, or support bot on a store site | Likely excluded (commerce/customer support), if that is its primary design | Design scope, system instructions, and marketing that show a support purpose |
| Appointment-scheduling or billing FAQ bot on a general-purpose model | Possibly excluded (narrow topic), only if it cannot produce sexual content or sustain self-harm dialogue | Topic restrictions, guardrails, and test results showing those outputs are blocked |
| Menu- or button-based bot with fixed responses | Likely excluded under proposed Rule 8.2, with the same capability limits | Screenshots of the fixed flows; confirmation that no free-text generation exists |
| Employee HR or knowledge-base assistant behind login | Likely excluded (internal use) | Access controls showing it is workforce-only and not consumer-facing |
| B2B productivity tool sold to companies | Likely excluded (business tool), weighed on all the circumstances | Who it is marketed to, whether any consumer can sign up, and its functions |
| Patient chatbot run by or for a HIPAA covered entity | Likely excluded (HIPAA exclusion) | Covered-entity or business-associate status and who the bot is provided on behalf of |
| Open-ended "Ask our AI anything" assistant on a public site | Likely covered | Your operator analysis and the duty-by-duty readiness plan |
| Law firm or advice-style intake bot using free-text generation | Likely covered unless tightly limited to a narrow topic with the capability limits | Scope limits, disclosure design, and professional-impersonation review |
| Companion, persona, or character chatbot | Likely covered, with the minor-protection duties most relevant | Age-estimation method, minor safeguards, and crisis protocol |
What does the Chatbot Safety Act require operators to do?
Starting January 1, 2027, § 6-1-1708 (as enacted by HB 26-1263) gives operators six sets of duties.
Estimate user age
Operators must use commercially reasonable or generally accepted methods to estimate the age of account holders or users, and may not willfully disregard clear and convincing information that a user is a minor (§ 6-1-1708(2)).
Disclose that the user is talking to AI
Operators must clearly and conspicuously disclose that the service is AI at the start of a user's first interaction each day, at least every three hours in a continuous interaction (or persistently), and whenever a user asks whether it is human (§ 6-1-1708(3)). In plain terms: if someone asks "are you an AI?", the honest answer is required.
Protect minors
When an operator knows a user is a minor, it must provide AI disclosures, avoid points or rewards given at unpredictable intervals to drive engagement, take technically feasible measures to block sexual content, take reasonable measures against responses that simulate emotional dependence or isolation, comply with Colorado privacy law, and offer privacy and account tools to the minor and a parent or guardian (§ 6-1-1708(2)).
Run a suicide and self-harm protocol
Operators must have a protocol for responding to prompts about suicidal ideation or self-harm that refers users to a crisis service provider, such as a suicide hotline or crisis text line (not law enforcement), with escalation procedures for repeated or severe crisis indicators (§ 6-1-1708(4)).
Do not impersonate licensed professionals
Operators may not use any term, letter, or phrase in a chatbot's advertising, interface, or outputs stating that output is provided by, endorsed by, or equivalent to services of a licensed health-care professional, licensed legal professional, licensed, certified, or registered mental-health professional, or qualified dietitian (§ 6-1-1708(5)).
Report annually
Beginning July 1, 2027, operators must report annually to the Attorney General the number of crisis-referral notifications issued in the prior calendar year, their self-harm detection and prevention protocols, and any additional metrics the Attorney General requires, with no user identifiers (§ 6-1-1708(6)).
Why does the professional-impersonation ban matter for law firms and clinics?
The ban reaches branding, not only answers. A bot named "AI Lawyer," "Dr. Bot," or "your virtual therapist" risks the statute's language about outputs being provided by or equivalent to a licensed professional, even if every individual answer carries a disclaimer. Proposed Rule 12.2 lists the factors the Attorney General would weigh: whether the operator has controls to prevent chatbot profile names containing terms such as "therapy," "therapist," "psychologist," "doctor," "lawyer," or "dietitian" where the name is likely to cause a reasonable user to believe the bot is provided by, endorsed by, or equivalent to a licensed professional; controls on outputs; and how the bot is advertised.
- Law firms: a public intake bot that answers open-ended questions is likely a covered service. Avoid names and marketing that suggest attorney-equivalent advice, and set out-of-scope rules for the bot. Professional-conduct rules apply separately.
- Clinics: a chatbot used by or on behalf of a HIPAA covered entity is likely excluded, but wellness, coaching, and nutrition apps outside HIPAA are not, and "AI therapist" or "AI dietitian" branding is exactly what the ban targets.
- Any business: marketing copy counts. Review landing pages, app-store listings, and ads, not just the chat window.
What would the proposed Rules 8–13 add?
The Attorney General's proposed rules, 4 CCR 904-6, were filed August 11, 2026. They are proposed, not final; comments are due and the hearing is held October 26, 2026. Check coag.gov/ai for the current draft.
- Rule 8 (exclusions): narrow-topic examples; totality-of-circumstances factors for business tools; factors for "emotional companionship" such as assignable names, avatars, and memory of past conversations.
- Rule 9 (age assurance): methods must be privacy-protective and tested; government ID cannot be the sole method, self-declaration alone is not enough, and ISO/IEC 27566-1:2025 is incorporated as one accepted framework. Operator size and resources would be considered.
- Rule 10 (disclosure): a persistent on-screen disclaimer would stay visible without scrolling and use a font no smaller than the largest other text on the interface.
- Rule 11 (minors): minors' privacy settings would default to the most protective option, including no memory across sessions and no training on their data.
- Rule 12 (impersonation): the profile-name, output, and advertising factors above.
- Rule 13 (annual report): operator size tier by monthly active users, crisis referrals with a conversation denominator, protocol descriptions, and age-estimation metrics, submitted through a form at coag.gov/ai.
HB 26-1263 places these duties in part 17 of the Colorado Consumer Protection Act, the same part as the ADMT Act, and SB 26-189 makes a violation of part 17 a deceptive trade practice. If your chatbot also feeds consequential decisions such as hiring or lending, read our Colorado ADMT Act checklist.
What should a chatbot readiness checklist include?
| Readiness item | Source | Evidence | FAIIR control |
|---|---|---|---|
| Inventory every public-facing bot and record your operator and exclusion analysis | § 6-1-1701(3.5), (15.5) | Use-case register entry with the analysis and reviewer | F1 Use-Case Register |
| Set topic limits and ban professional-advice framing | § 6-1-1708(5); proposed Rule 12.2 | Written out-of-scope rules; name and marketing review | F2 Out-of-Scope Boundaries |
| Build AI disclosures (daily, three-hour or persistent, on request) | § 6-1-1708(2)(a), (3); proposed Rule 10 | Screenshots; transcript showing the answer to "are you human?" | U3 Customer Disclosure in Place |
| Define when a conversation goes to a human | Governance practice (not itself a statutory requirement) | Escalation rule with named roles | F5 Human-in-the-Loop Defined |
| Define crisis indicators and write the referral and escalation playbook | § 6-1-1708(4); proposed Rule 13.3 | Incident definition; crisis playbook; referral resources | R2 Incident Definition; R3 Incident Response Playbook |
| Monitor outputs and retest safeguards after model updates | § 6-1-1708(2)(c)–(d); proposed Rules 11.3–11.4 | Monitoring log; test results; change log | R4 Monitoring in Place; F6 Model/Version Tracking; R9 Change Log |
| Choose and document an age-estimation method | § 6-1-1708(2); proposed Rule 9 | Method description and accuracy testing | F1 Use-Case Register; R1 Risk Register |
| Set protective privacy defaults for minors | § 6-1-1708(2)(g)–(h); proposed Rule 11.5 | Settings documentation; data-use rules | I2 AI-Permitted Data Rules; I4 Training Data Opt-Out |
| Collect data for the annual report | § 6-1-1708(6); proposed Rule 13 | Referral counts; retained protocol versions | A2 AI Decision Log; R7 Audit Log Retention |
What are the key Chatbot Safety Act dates?
| Date | What happens |
|---|---|
| May 29, 2026 | HB 26-1263 signed |
| August 12, 2026 | Act takes effect (duties themselves start later) |
| October 26, 2026 | Rulemaking hearing and written-comment deadline for 4 CCR 904-6 |
| January 1, 2027 | Operator duties apply |
| July 1, 2027 | First annual report to the Attorney General |
Where FAIIR fits
The FAIIR framework maps disclosure, scope boundaries, human escalation, incident response, and monitoring to controls that a business can evidence and review each year. Colorado law does not require, create, or recognize any third-party AI certification; FAIIR certification is documented proof of reasonable care, not a guarantee of compliance with HB 26-1263.
Frequently asked questions
Does the Colorado Chatbot Safety Act apply to a customer service chatbot?
Often not. HB 26-1263 excludes software primarily designed for commerce-related or transactional help, including customer support and customer service. A bot marketed as customer support but able to hold open-ended conversations on any topic is harder to place, so document its design and limits.
Is a small business that uses a vendor's chatbot an operator?
It can be. The statute defines an operator to include anyone who offers a conversational AI service to a consumer, and it sets no size threshold. If the bot fits no exclusion, the business offering it on its site is likely an operator even though a vendor built it.
Can a chatbot be called "AI Lawyer" or "AI Therapist" in Colorado?
That branding is risky. Section 6-1-1708(5) bars any term in a chatbot's advertising, interface, or outputs stating that output is provided by, endorsed by, or equivalent to services of a licensed legal, health-care, or mental-health professional or dietitian. Proposed Rule 12.2 names profile terms like "lawyer" and "therapist" as a factor.
When is the first Chatbot Safety Act annual report due?
Annual reporting to the Colorado Attorney General begins July 1, 2027. The report covers crisis-referral counts and self-harm protocols, with no user identifiers. Proposed Rule 13 would add details such as operator size tier and age-estimation metrics.
Is the Chatbot Safety Act the same as the Colorado ADMT Act?
No. The ADMT Act (SB 26-189) governs technology that materially influences consequential decisions such as hiring or lending, while HB 26-1263 governs consumer-facing conversational AI. The ADMT Act takes effect January 1, 2027, the Chatbot Safety Act's operator duties apply from the same date, and the Attorney General is writing rules for both in 4 CCR 904-6.
Does FAIIR certification satisfy the Chatbot Safety Act?
No. Colorado law does not require, create, or recognize any third-party AI certification. FAIIR controls such as U3 disclosure and R3 incident response help a business organize evidence, but meeting the statute depends on how the chatbot actually works.
Sources
This article is general information from FAIIR, LLC, which is not a law firm, and is not legal advice. Colorado law does not require or recognize any third-party AI certification, and FAIIR certification is not a government approval or a guarantee of compliance. For advice about your situation, consult a licensed attorney.