What Counts as Meaningful Human Review of an AI Decision?

By Zachariah Crabill, JD · FAIIR, LLC · Updated

The short answer

Under the Colorado ADMT Act, C.R.S. § 6-1-1701(15), meaningful human review is review by a trained individual the deployer designates, with authority to approve, modify, or override a consequential decision, who considers relevant primary evidence, does not default to the system output, and has access to enough information to understand the output's intended use, limitations, inputs, and principal factors. Proposed AG Rule 7.7 would add independence, anti-steering, and documentation requirements.

Key takeaways

  • C.R.S. § 6-1-1701(15) sets four conditions for meaningful human review: primary evidence, training, no defaulting to the system output, and enough information about the output.
  • C.R.S. § 6-1-1705 gives a consumer with an adverse outcome a right to meaningful human review and reconsideration "to the extent commercially reasonable," starting January 1, 2027.
  • Proposed AG Rule 7.7 would require an independent reviewer "whenever feasible," bar ADMT from assisting the review, and presume review is commercially reasonable for severe and irreversible denials of a basic human need.
  • A rubber stamp is a human who sees only the AI output; a meaningful review is one that could change the outcome and is documented with evidence-specific reasons.
  • Small and solo businesses can document why full independence is not feasible, review primary evidence fresh, and record their reasoning; that is practical governance, not a legal safe harbor.

What does Colorado law say meaningful human review is?

The Colorado ADMT Act (SB 26-189) defines meaningful human review as review by an "individual designated by the deployer who has authority to approve, modify, or override a consequential decision" and who meets four conditions (C.R.S. § 6-1-1701(15)). The reviewer:

  1. "considers relevant, available primary evidence";
  2. "is trained to conduct the review";
  3. "does not default to the system output"; and
  4. "has access to sufficient information to understand" the output's intended use, material limitations, and categories of inputs, plus "the principal factors used to generate the output," without requiring disclosure of proprietary source code, model weights, or other trade secrets.

The definition matters because of the consumer right that uses it. When a consumer experiences an adverse outcome from a consequential decision that covered ADMT materially influenced, the deployer must provide, on request, instructions for accessing and correcting personal data and "an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable" (§ 6-1-1705(1)(a)(II)). These duties apply to consequential decisions made on or after January 1, 2027, and the Attorney General must adopt rules implementing § 6-1-1705 by that date (§ 6-1-1705(3)).

What would proposed Rule 7.7 add?

Proposed Rule 7.7 in the AG's draft rules (4 CCR 904-6, filed August 11, 2026) would turn the definition into operating requirements. These rules are proposed, not final. Written comments run through October 26, 2026, and the AG said it would post any pre-hearing changes by September 23, 2026, so check coag.gov/ai for the current text. As drafted, Rule 7.7 would provide:

  • Independence: review "must be conducted by an independent reviewer who did not make the original decision and who is not a subordinate of the original decision-maker, whenever feasible."
  • Subject-matter depth and training: the reviewer's understanding must be commensurate with the consequences of the adverse outcome, and training must cover accuracy and objectivity, the information the ADMT considers, and the subject matter.
  • Authority without steering: the reviewer "must not be subject to steering by the upper management that would influence the reviewer's decision," and must be shielded from retaliation.
  • No AI in the review: "ADMT may not assist in the Meaningful Human Review."
  • Outcome-changing: a meaningful review is "one that could change the Adverse Outcome"; depending on the request, that may mean fixing and re-running the system or weighing new evidence the consumer provides.
  • Commercial reasonableness: seven factors weighed together, including magnitude and reversibility of harm, "The Deployer's size and capacity," marginal cost, and availability of qualified reviewers. Review is presumed commercially reasonable when the harm is "a severe and irreversible denial of a basic human need," and the deployer bears the burden of proving otherwise with specific evidence.
  • Response and timing: confirm receipt within 10 days, complete the review within 45 days, stay the adverse outcome where possible, and give reasons that are "specific to the evidence provided, and not a recitation of the ADMT's general logic."
  • Documentation: a record of the reviewer's identity, authority, and training; timestamps; evidence considered; the reviewer's access to the ADMT's intended use, limitations, inputs, and principal factors; the result; and a written justification.

What is the difference between a rubber stamp and a meaningful review?

A rubber stamp is a human who looks at the AI's answer and signs it; a meaningful review is one where the human could, and sometimes does, reach a different result from the evidence. The table below contrasts the two, drawing on § 6-1-1701(15) and proposed Rule 7.7.

Rubber-stamp review compared with meaningful human review
ElementRubber stampMeaningful review
Starting pointOpens the AI score first and looks for reasons to agreeStarts from the consumer's request and the primary evidence
EvidenceOnly the system outputApplication, records, and anything the consumer submits
Understanding of the toolDoes not know what the score measures or where it failsKnows the intended use, limitations, input categories, and principal factors
AuthorityCan only confirm, or needs a manager's sign-off to reverseCan approve, modify, or override on their own judgment
IndependenceThe person who made the original call, or their direct reportSomeone else, whenever feasible; if not, the constraint is written down
AI involvementAsks the same or another AI tool to re-checkNo ADMT assists the review (proposed Rule 7.7)
Reasons given"The system determined you did not qualify"Reasons tied to the specific evidence reviewed
RecordNone, or a checkboxWho, when, what evidence, result, and written justification

How can a small or solo business approach reviewer independence?

Start by writing down why a fully independent reviewer is or is not feasible, then compensate with process. The statute has no small-business exemption, and proposed Rule 7.7 asks for independence only "whenever feasible" while listing the deployer's size and capacity and the availability of qualified reviewers as factors. A three-person property manager or a solo lender may have no one who is both qualified and outside the original decision. The steps below are practical governance habits, not a legal safe harbor, and nothing here guarantees compliance; talk to counsel about your situation.

  1. Document the constraint. Record who is available to review, why each is or is not independent, and what you considered, such as a partner, a trusted outside professional under a confidentiality agreement, or a peer business.
  2. Review primary evidence de novo. Put the AI output aside and work from the application, the records, and the consumer's submission as if deciding fresh. Proposed Rule 7.7's own example describes reviewing "the Consumer's primary evidence De Novo" when the tool cannot be corrected.
  3. Keep AI out of the review. Do not ask the same tool, or a chatbot, to re-check the decision.
  4. Record your reasoning. Write reasons specific to the evidence, including what would have changed your mind. A later reader should be able to see that the outcome was open.
  5. Separate in time if not in person. If the same person must review, do it as a distinct step on a later day, using the checklist below, not in the same sitting as the original decision.

What should a human review record include?

A one-page record per review is enough for most small deployers. The fields below track § 6-1-1701(15) and the documentation list in proposed Rule 7.7. Keep each record for at least three years after the consequential decision, the deployer record-keeping period in § 6-1-1703.

One-page meaningful human review record template
FieldWhat to record
Decision ID and dateInternal reference and the date of the original consequential decision
Request receivedDate, channel, and the consumer's stated reason and contested information
Original decision-makerName and role of the person or process that made the original call
ADMT usedTool name, developer, and version or model identifier
ReviewerName, role, and written authority to approve, modify, or override
Reviewer trainingDate and topics of the reviewer's most recent training
IndependenceWhether the reviewer is independent; if not, why it was not feasible and what you did instead
Type of reviewSystem check and re-run, reconsideration on corrected data, or de novo review of evidence
Primary evidence consideredEach document or data point reviewed, including what the consumer submitted
Tool information availableWhether the reviewer had the intended use, limitations, input categories, and principal factors
TimestampsReview start and end dates and times
OutcomeApproved, modified, or overrode the output, and the final decision
Written justificationReasons specific to the evidence, not the tool's general logic
Consumer responseDate the response was sent and whether the adverse outcome was stayed

Which FAIIR controls cover human review?

Three controls in the FAIIR framework line up with this work. F5 — Human-in-the-Loop Defined requires a written rule for where a human reviews before output is acted on. A2 — AI Decision Log requires a log of material AI-involved decisions, who reviewed them, and the outcome; the template above can serve as its entries. U5 — Opt-Out Available requires a practical path for a customer to request human handling. For the full list of deployer duties, see the Colorado ADMT Act compliance checklist, and for building the rest of the program, see an AI governance framework for small businesses.

Where FAIIR fits

FAIIR, LLC publishes the FAIIR standard, 41 pass/fail controls benchmarked to the NIST AI Risk Management Framework, and certifies an organization's practices around the AI it uses. Colorado law does not require, create, or recognize any third-party AI certification; a FAIIR certification is documented proof of reasonable care, not a guarantee of compliance. FAIIR, LLC is not a law firm and this post is not legal advice.

Frequently asked questions

What is meaningful human review under the Colorado ADMT Act?

C.R.S. § 6-1-1701(15) defines it as review by an individual the deployer designates who has authority to approve, modify, or override a consequential decision. The reviewer must consider relevant, available primary evidence, be trained, not default to the system output, and have enough information to understand the output's intended use, limitations, input categories, and principal factors.

Do Colorado businesses have to offer human review of every AI decision?

No. Under C.R.S. § 6-1-1705, the right applies when a consumer experiences an adverse outcome from a consequential decision that covered ADMT materially influenced, and the consumer requests it. The deployer must then offer meaningful human review and reconsideration to the extent commercially reasonable, starting January 1, 2027.

Can AI help with the human review?

Under proposed AG Rule 7.7, no: the draft states that ADMT may not assist in the meaningful human review. The rule is proposed, not final, so check coag.gov/ai for the current draft. As a governance matter, keeping the original tool out of the review is also the simplest way to show the reviewer did not default to its output.

What if a small business has no one independent to review the decision?

Proposed Rule 7.7 asks for an independent reviewer whenever feasible and lists the deployer's size and capacity as a commercial-reasonableness factor. A practical approach is to document why independence is not feasible, review the primary evidence fresh without the AI output, and record evidence-specific reasons. That is good governance, not a legal safe harbor, so talk to counsel about your situation.

How long does a business have to complete a human review?

The statute does not set a deadline. Proposed Rule 7.7 would require confirming receipt within 10 days and completing the review and responding within 45 days of the request, and would stay the adverse outcome where possible. Those timelines are proposed and may change before the final rules.

What records should a business keep for each human review?

Proposed Rule 7.7 lists the reviewer's identity, authority, and training; timestamps; the primary evidence available, including what the consumer provided; the reviewer's access to the tool's intended use, limitations, inputs, and principal factors; the result; and a written justification. C.R.S. § 6-1-1703 requires deployers to keep compliance records for at least three years after each consequential decision.

Sources

  1. Colorado SB 26-189 (ADMT Act), signed act
  2. Colorado Attorney General, ADMT and Chatbot Safety rulemaking
  3. Proposed rules, 4 CCR 904-6 (filed Aug. 11, 2026)
  4. NIST AI Risk Management Framework

This article is general information from FAIIR, LLC, which is not a law firm, and is not legal advice. Colorado law does not require or recognize any third-party AI certification, and FAIIR certification is not a government approval or a guarantee of compliance. For advice about your situation, consult a licensed attorney.