What Counts as Meaningful Human Review of an AI Decision?
By Zachariah Crabill, JD · FAIIR, LLC · Updated
The short answer
Under the Colorado ADMT Act, C.R.S. § 6-1-1701(15), meaningful human review is review by a trained individual the deployer designates, with authority to approve, modify, or override a consequential decision, who considers relevant primary evidence, does not default to the system output, and has access to enough information to understand the output's intended use, limitations, inputs, and principal factors. Proposed AG Rule 7.7 would add independence, anti-steering, and documentation requirements.
Key takeaways
- C.R.S. § 6-1-1701(15) sets four conditions for meaningful human review: primary evidence, training, no defaulting to the system output, and enough information about the output.
- C.R.S. § 6-1-1705 gives a consumer with an adverse outcome a right to meaningful human review and reconsideration "to the extent commercially reasonable," starting January 1, 2027.
- Proposed AG Rule 7.7 would require an independent reviewer "whenever feasible," bar ADMT from assisting the review, and presume review is commercially reasonable for severe and irreversible denials of a basic human need.
- A rubber stamp is a human who sees only the AI output; a meaningful review is one that could change the outcome and is documented with evidence-specific reasons.
- Small and solo businesses can document why full independence is not feasible, review primary evidence fresh, and record their reasoning; that is practical governance, not a legal safe harbor.
What does Colorado law say meaningful human review is?
The Colorado ADMT Act (SB 26-189) defines meaningful human review as review by an "individual designated by the deployer who has authority to approve, modify, or override a consequential decision" and who meets four conditions (C.R.S. § 6-1-1701(15)). The reviewer:
- "considers relevant, available primary evidence";
- "is trained to conduct the review";
- "does not default to the system output"; and
- "has access to sufficient information to understand" the output's intended use, material limitations, and categories of inputs, plus "the principal factors used to generate the output," without requiring disclosure of proprietary source code, model weights, or other trade secrets.
The definition matters because of the consumer right that uses it. When a consumer experiences an adverse outcome from a consequential decision that covered ADMT materially influenced, the deployer must provide, on request, instructions for accessing and correcting personal data and "an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable" (§ 6-1-1705(1)(a)(II)). These duties apply to consequential decisions made on or after January 1, 2027, and the Attorney General must adopt rules implementing § 6-1-1705 by that date (§ 6-1-1705(3)).
What would proposed Rule 7.7 add?
Proposed Rule 7.7 in the AG's draft rules (4 CCR 904-6, filed August 11, 2026) would turn the definition into operating requirements. These rules are proposed, not final. Written comments run through October 26, 2026, and the AG said it would post any pre-hearing changes by September 23, 2026, so check coag.gov/ai for the current text. As drafted, Rule 7.7 would provide:
- Independence: review "must be conducted by an independent reviewer who did not make the original decision and who is not a subordinate of the original decision-maker, whenever feasible."
- Subject-matter depth and training: the reviewer's understanding must be commensurate with the consequences of the adverse outcome, and training must cover accuracy and objectivity, the information the ADMT considers, and the subject matter.
- Authority without steering: the reviewer "must not be subject to steering by the upper management that would influence the reviewer's decision," and must be shielded from retaliation.
- No AI in the review: "ADMT may not assist in the Meaningful Human Review."
- Outcome-changing: a meaningful review is "one that could change the Adverse Outcome"; depending on the request, that may mean fixing and re-running the system or weighing new evidence the consumer provides.
- Commercial reasonableness: seven factors weighed together, including magnitude and reversibility of harm, "The Deployer's size and capacity," marginal cost, and availability of qualified reviewers. Review is presumed commercially reasonable when the harm is "a severe and irreversible denial of a basic human need," and the deployer bears the burden of proving otherwise with specific evidence.
- Response and timing: confirm receipt within 10 days, complete the review within 45 days, stay the adverse outcome where possible, and give reasons that are "specific to the evidence provided, and not a recitation of the ADMT's general logic."
- Documentation: a record of the reviewer's identity, authority, and training; timestamps; evidence considered; the reviewer's access to the ADMT's intended use, limitations, inputs, and principal factors; the result; and a written justification.
What is the difference between a rubber stamp and a meaningful review?
A rubber stamp is a human who looks at the AI's answer and signs it; a meaningful review is one where the human could, and sometimes does, reach a different result from the evidence. The table below contrasts the two, drawing on § 6-1-1701(15) and proposed Rule 7.7.
| Element | Rubber stamp | Meaningful review |
|---|---|---|
| Starting point | Opens the AI score first and looks for reasons to agree | Starts from the consumer's request and the primary evidence |
| Evidence | Only the system output | Application, records, and anything the consumer submits |
| Understanding of the tool | Does not know what the score measures or where it fails | Knows the intended use, limitations, input categories, and principal factors |
| Authority | Can only confirm, or needs a manager's sign-off to reverse | Can approve, modify, or override on their own judgment |
| Independence | The person who made the original call, or their direct report | Someone else, whenever feasible; if not, the constraint is written down |
| AI involvement | Asks the same or another AI tool to re-check | No ADMT assists the review (proposed Rule 7.7) |
| Reasons given | "The system determined you did not qualify" | Reasons tied to the specific evidence reviewed |
| Record | None, or a checkbox | Who, when, what evidence, result, and written justification |
How can a small or solo business approach reviewer independence?
Start by writing down why a fully independent reviewer is or is not feasible, then compensate with process. The statute has no small-business exemption, and proposed Rule 7.7 asks for independence only "whenever feasible" while listing the deployer's size and capacity and the availability of qualified reviewers as factors. A three-person property manager or a solo lender may have no one who is both qualified and outside the original decision. The steps below are practical governance habits, not a legal safe harbor, and nothing here guarantees compliance; talk to counsel about your situation.
- Document the constraint. Record who is available to review, why each is or is not independent, and what you considered, such as a partner, a trusted outside professional under a confidentiality agreement, or a peer business.
- Review primary evidence de novo. Put the AI output aside and work from the application, the records, and the consumer's submission as if deciding fresh. Proposed Rule 7.7's own example describes reviewing "the Consumer's primary evidence De Novo" when the tool cannot be corrected.
- Keep AI out of the review. Do not ask the same tool, or a chatbot, to re-check the decision.
- Record your reasoning. Write reasons specific to the evidence, including what would have changed your mind. A later reader should be able to see that the outcome was open.
- Separate in time if not in person. If the same person must review, do it as a distinct step on a later day, using the checklist below, not in the same sitting as the original decision.
What should a human review record include?
A one-page record per review is enough for most small deployers. The fields below track § 6-1-1701(15) and the documentation list in proposed Rule 7.7. Keep each record for at least three years after the consequential decision, the deployer record-keeping period in § 6-1-1703.
| Field | What to record |
|---|---|
| Decision ID and date | Internal reference and the date of the original consequential decision |
| Request received | Date, channel, and the consumer's stated reason and contested information |
| Original decision-maker | Name and role of the person or process that made the original call |
| ADMT used | Tool name, developer, and version or model identifier |
| Reviewer | Name, role, and written authority to approve, modify, or override |
| Reviewer training | Date and topics of the reviewer's most recent training |
| Independence | Whether the reviewer is independent; if not, why it was not feasible and what you did instead |
| Type of review | System check and re-run, reconsideration on corrected data, or de novo review of evidence |
| Primary evidence considered | Each document or data point reviewed, including what the consumer submitted |
| Tool information available | Whether the reviewer had the intended use, limitations, input categories, and principal factors |
| Timestamps | Review start and end dates and times |
| Outcome | Approved, modified, or overrode the output, and the final decision |
| Written justification | Reasons specific to the evidence, not the tool's general logic |
| Consumer response | Date the response was sent and whether the adverse outcome was stayed |
Which FAIIR controls cover human review?
Three controls in the FAIIR framework line up with this work. F5 — Human-in-the-Loop Defined requires a written rule for where a human reviews before output is acted on. A2 — AI Decision Log requires a log of material AI-involved decisions, who reviewed them, and the outcome; the template above can serve as its entries. U5 — Opt-Out Available requires a practical path for a customer to request human handling. For the full list of deployer duties, see the Colorado ADMT Act compliance checklist, and for building the rest of the program, see an AI governance framework for small businesses.
Where FAIIR fits
FAIIR, LLC publishes the FAIIR standard, 41 pass/fail controls benchmarked to the NIST AI Risk Management Framework, and certifies an organization's practices around the AI it uses. Colorado law does not require, create, or recognize any third-party AI certification; a FAIIR certification is documented proof of reasonable care, not a guarantee of compliance. FAIIR, LLC is not a law firm and this post is not legal advice.
Frequently asked questions
What is meaningful human review under the Colorado ADMT Act?
C.R.S. § 6-1-1701(15) defines it as review by an individual the deployer designates who has authority to approve, modify, or override a consequential decision. The reviewer must consider relevant, available primary evidence, be trained, not default to the system output, and have enough information to understand the output's intended use, limitations, input categories, and principal factors.
Do Colorado businesses have to offer human review of every AI decision?
No. Under C.R.S. § 6-1-1705, the right applies when a consumer experiences an adverse outcome from a consequential decision that covered ADMT materially influenced, and the consumer requests it. The deployer must then offer meaningful human review and reconsideration to the extent commercially reasonable, starting January 1, 2027.
Can AI help with the human review?
Under proposed AG Rule 7.7, no: the draft states that ADMT may not assist in the meaningful human review. The rule is proposed, not final, so check coag.gov/ai for the current draft. As a governance matter, keeping the original tool out of the review is also the simplest way to show the reviewer did not default to its output.
What if a small business has no one independent to review the decision?
Proposed Rule 7.7 asks for an independent reviewer whenever feasible and lists the deployer's size and capacity as a commercial-reasonableness factor. A practical approach is to document why independence is not feasible, review the primary evidence fresh without the AI output, and record evidence-specific reasons. That is good governance, not a legal safe harbor, so talk to counsel about your situation.
How long does a business have to complete a human review?
The statute does not set a deadline. Proposed Rule 7.7 would require confirming receipt within 10 days and completing the review and responding within 45 days of the request, and would stay the adverse outcome where possible. Those timelines are proposed and may change before the final rules.
What records should a business keep for each human review?
Proposed Rule 7.7 lists the reviewer's identity, authority, and training; timestamps; the primary evidence available, including what the consumer provided; the reviewer's access to the tool's intended use, limitations, inputs, and principal factors; the result; and a written justification. C.R.S. § 6-1-1703 requires deployers to keep compliance records for at least three years after each consequential decision.
Sources
This article is general information from FAIIR, LLC, which is not a law firm, and is not legal advice. Colorado law does not require or recognize any third-party AI certification, and FAIIR certification is not a government approval or a guarantee of compliance. For advice about your situation, consult a licensed attorney.