Glossary
AI governance terms, defined
The vocabulary of Colorado’s ADMT Act (SB 26-189), the Chatbot Safety Act (HB 26-1263), the Attorney General’s proposed rules (4 CCR 904-6), and the FAIIR framework, in plain language. Statutory terms are paraphrased — the statute controls. Informational only, not legal advice.
- 4 CCR 904-6
- 4 CCR 904-6 is the Colorado Attorney General's proposed "Automated Decision-Making Technology & Conversational Artificial Intelligence Service Rules," filed August 11, 2026, to implement the Colorado ADMT Act and the Colorado Chatbot Safety Act. The rules are proposed, not final: written comments are open through October 26, 2026, a rulemaking hearing is set for the same day, and the final rules are intended to take effect January 1, 2027. Check coag.gov/ai for the current draft.Source: Colorado Attorney General, ADMT and chatbot rulemaking
- Accountability (FAIIR pillar)
- Accountability is the second of the five FAIIR pillars and asks who owns an AI system's outcomes, and whether that ownership was written down before anything went wrong. Its seven controls (A1–A7) cover a designated AI officer, an AI decision log, vendor contract review, liability allocation, insurance review, a customer disclosure path, and a named incident-response owner.Source: The FAIIR Framework
- Adverse outcome
- Under the Colorado ADMT Act, an adverse outcome is a decision that denies, terminates, revokes, or materially reduces or restricts a consumer's access to, eligibility for, selection for, compensation for, or provision of an opportunity or service. It also includes a decision that gives a consumer materially less favorable price, cost, compensation, or other material terms than similarly situated consumers, where those terms are reasonably likely to limit, delay, effectively deny, or fundamentally alter access (C.R.S. § 6-1-1701(1)).Source: Colorado SB 26-189 (signed act)
- Adverse-outcome disclosure
- An adverse-outcome disclosure is the notice a deployer must give a consumer within 30 days after a covered ADMT materially influences a consequential decision that results in an adverse outcome for that consumer (C.R.S. § 6-1-1704(3)). The statute requires a plain-language description of the decision and the ADMT's role, a simple process to request more information about the ADMT and the personal data used, and an explanation of the consumer's rights. Under the AG's proposed rules, the disclosure must also state the specific principal reasons for the outcome; saying it was based on "internal standards or policies" is expressly insufficient.Source: Colorado SB 26-189 (signed act)
- AI acceptable use policy
- An AI acceptable use policy (AUP) is a written internal policy that tells employees which AI tools they may use, for which tasks, with which data, and what is prohibited. In the FAIIR standard it is control U1, which requires the policy to be distributed to all employees and acknowledged in writing. Under the Colorado ADMT Act, a consumer-facing conversational tool can fall outside the definition of ADMT only if, among other conditions, it is subject to an acceptable use policy that prohibits using its generated content in a consequential decision (C.R.S. § 6-1-1701(2)(b)(III)).Source: The FAIIR Framework
- AI governance
- AI governance is the set of policies, roles, records, and review practices an organization uses to decide which AI systems it uses, for what, and under whose oversight. For a small business it typically means an owner accountable for AI, a list of the AI tools in use, written rules on data and permitted uses, and a way to catch and fix problems.
- AI incident
- An AI incident is an event in which an AI system's output or behavior causes, or nearly causes, harm, such as an inaccurate output reaching a customer, confidential data being exposed through an AI tool, or an AI-influenced decision being made in error. The FAIIR standard does not treat every AI mistake as an incident; control R2 requires each organization to write its own definition of what counts, and R3 requires a playbook for responding.Source: The FAIIR Framework
- Algorithmic discrimination
- Algorithmic discrimination is unlawful differential treatment or impact that disfavors people on the basis of a protected characteristic, such as race, sex, age, or disability, where an AI or automated system contributes to the result. It was a defined term, with a related duty of care, in Colorado's 2024 AI Act (SB 24-205); the Colorado ADMT Act (SB 26-189) drops that definition and duty and instead confirms that developers and deployers can be liable under existing anti-discrimination law, including the Colorado Anti-Discrimination Act, for consequential decisions materially influenced by a covered ADMT (C.R.S. § 6-1-1707).Source: Colorado SB 26-189 (signed act)
- Automated decision-making technology (ADMT)
- Under the Colorado ADMT Act, automated decision-making technology (ADMT) is technology that processes personal data and uses computation to generate output, such as predictions, recommendations, classifications, rankings, or scores, that is used to make, guide, or assist a decision about an individual (C.R.S. § 6-1-1701(2)). The definition excludes everyday tools like spell-checkers, databases, and firewalls, and excludes a tool used solely to summarize, organize, translate, draft, route, or present information for human review of administrative processing.Source: Colorado SB 26-189 (signed act)
- Colorado ADMT Act
- The Colorado ADMT Act is Senate Bill 26-189, signed May 14, 2026, which repeals and reenacts C.R.S. §§ 6-1-1701 to -1709 and replaces Colorado's 2024 AI Act (SB 24-205). It takes effect January 1, 2027, and applies to consequential decisions made on or after that date, requiring developers to document covered ADMT and deployers to give notices, adverse-outcome disclosures, data access and correction, meaningful human review where commercially reasonable, and three years of records. The Attorney General enforces it exclusively as a deceptive trade practice, and it creates no private right of action.Source: Colorado SB 26-189 (signed act)
- Colorado Chatbot Safety Act
- The Colorado Chatbot Safety Act is House Bill 26-1263, which sets duties for operators of consumer-facing conversational AI services starting January 1, 2027. Operators must, among other things, disclose that the service is AI, protect minors, follow suicide and self-harm response protocols, and not represent outputs as coming from a licensed health-care, legal, or mental-health professional. Annual reports to the Attorney General begin July 1, 2027.Source: Colorado HB 26-1263 (signed act)
- Consequential decision
- Under the Colorado ADMT Act, a consequential decision is a decision, determination, or action about a consumer that relates to access to, eligibility for, selection for, compensation for, or pricing and material terms of one of seven covered domains: education, employment, the lease or purchase of Colorado residential real estate, financial or lending services, insurance, health-care services, and essential government services or public benefits (C.R.S. § 6-1-1701(3), (6)). Routine or low-stakes actions, such as scheduling, customer-service triage, advertising, and fraud prevention, are excluded.Source: Colorado SB 26-189 (signed act)
- Conversational AI service
- Under the Colorado Chatbot Safety Act, a conversational artificial intelligence service is an AI system accessible to the general public that primarily simulates human conversation and interaction through adaptive text, visual, or audio communication (C.R.S. § 6-1-1701(3.5), as added by HB 26-1263). Exclusions include tools primarily for commerce or customer support, business-productivity and internal-only tools, and narrow single-topic tools that cannot generate sexually explicit content or maintain dialogue about suicide or self-harm.Source: Colorado HB 26-1263 (signed act)
- Covered ADMT
- Under the Colorado ADMT Act, a covered ADMT is automated decision-making technology that is used to materially influence a consequential decision (C.R.S. § 6-1-1701(5)). Only covered ADMT triggers the Act's developer and deployer duties.Source: Colorado SB 26-189 (signed act)
- De minimis factor
- A de minimis factor is an input to a decision too minor to count; under the Colorado ADMT Act, an ADMT output that is only a de minimis factor does not "materially influence" a consequential decision (C.R.S. § 6-1-1701(13)). The Attorney General is weighing two proposed standards and has adopted neither: Standard 1 treats a factor as de minimis only if its impact is "trifling, trivial, or incidental," while Standard 2 treats a factor as de minimis if it is not a substantial factor in the decision.Source: Colorado Attorney General, ADMT and chatbot rulemaking
- Deployer
- Under the Colorado ADMT Act, a deployer is a person doing business in Colorado that deploys a covered ADMT (C.R.S. § 6-1-1701(7)); under the AG's proposed rules, to deploy means to use covered ADMT in a way that materially influences a consequential decision. Deployers owe the Act's consumer-facing duties: pre-use notice, adverse-outcome disclosure, data access and correction, meaningful human review where commercially reasonable, and three years of records.Source: Colorado SB 26-189 (signed act)
- Developer
- Under the Colorado ADMT Act, a developer is a person doing business in Colorado that develops or makes commercially available a covered ADMT, develops a component designed or marketed for use in a covered ADMT, or intentionally and substantially modifies an ADMT so that it becomes covered (C.R.S. § 6-1-1701(8)). Developers must give deployers documentation of intended and known harmful or inappropriate uses, training-data categories, known limitations, and instructions for monitoring and human review (§ 6-1-1702).Source: Colorado SB 26-189 (signed act)
- FAIIR
- FAIIR (Foundation of AI Integrity & Regulation) is a private, voluntary standard for how organizations deploy and use AI, published by FAIIR, LLC, an independent Colorado standards company that is not a law firm and does not give legal advice. The standard has 41 pass/fail controls across five pillars, is benchmarked to the NIST AI Risk Management Framework, and complements rather than replaces SOC 2 and ISO/IEC 42001.Source: The FAIIR Framework
- FAIIR certification
- FAIIR certification is an annual, firm-specific attestation, based on evidence the organization submits, that its AI practices meet the FAIIR standard's controls; it certifies an organization's practices, not an AI model. It is documented proof of reasonable care, not a government approval and not a guarantee of legal compliance. Colorado law does not require, create, or recognize any third-party AI certification.Source: The FAIIR Framework
- Fitness for Purpose (FAIIR pillar)
- Fitness for Purpose is the first of the five FAIIR pillars and asks whether each AI tool is actually suited to the task it is used for. Its eight controls (F1–F8) include a use-case register, written out-of-scope boundaries, documented accuracy thresholds, a bias check, defined human-in-the-loop points, model and version tracking, a fallback procedure, and an annual fitness review.Source: The FAIIR Framework
- Five pillars (FAIIR)
- The five pillars are the structure of the FAIIR standard, spelled out by its acronym: Fitness for Purpose (8 controls), Accountability (7), Integrity of Data (9), Informed Use (7), and Risk Management (10), for 41 pass/fail controls in total.Source: The FAIIR Framework
- Human-in-the-loop
- Human-in-the-loop is a design in which a person reviews, approves, or can override an AI system's output before it is acted on. It is not the same as the Colorado ADMT Act's "meaningful human review," which is a specific after-the-fact right a consumer can request following an adverse outcome. FAIIR control F5 requires a written rule, for each high-stakes use case, on where a human reviews before AI output is acted on.Source: The FAIIR Framework
- Informed Use (FAIIR pillar)
- Informed Use is the fourth of the five FAIIR pillars and asks whether the employees and customers affected by an AI system know it is being used. Its seven controls (U1–U7) cover an AI acceptable use policy, employee training, customer disclosure, consent where required, a path to human handling, labeling of AI-generated content, and an incident disclosure plan.Source: The FAIIR Framework
- Integrity of Data (FAIIR pillar)
- Integrity of Data is the third of the five FAIIR pillars and asks what data goes into AI tools, where it goes, and how long it stays there. Its nine controls (I1–I9) include a data classification map, rules for which data each AI tool may receive, a no-personal-data default absent a data processing agreement, training-data opt-out settings, vendor retention terms, and confirmed deletion when a tool is retired.Source: The FAIIR Framework
- ISO/IEC 42001
- ISO/IEC 42001:2023 is the international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an artificial intelligence management system (AIMS) within an organization. It applies to any organization, of any size, that provides or uses AI-based products or services, and it follows the same management-system structure as ISO/IEC 27001.Source: ISO/IEC 42001:2023, AI management systems
- Materially influence
- Under the Colorado ADMT Act, an ADMT output materially influences a consequential decision when it is a non-de minimis factor used in making the decision and it affects the outcome, including by constraining, ranking, scoring, recommending, classifying, or otherwise meaningfully altering how the decision is made (C.R.S. § 6-1-1701(13)). Incidental, trivial, or clerical uses do not count. The Attorney General may clarify the term by rule and is currently weighing two proposed standards.Source: Colorado SB 26-189 (signed act)
- Meaningful human review
- Under the Colorado ADMT Act, meaningful human review is review of a consequential decision by a trained individual the deployer designates, who has authority to approve, modify, or override it, considers relevant available primary evidence, does not default to the system output, and has enough information to understand the output's intended use, limitations, inputs, and principal factors (C.R.S. § 6-1-1701(15)). A consumer who receives an adverse outcome may request it to the extent commercially reasonable (§ 6-1-1705). Under the AG's proposed rules, the reviewer should be independent of the original decision-maker whenever feasible, and ADMT may not assist in the review.Source: Colorado SB 26-189 (signed act)
- Midstream developer
- Under the AG's proposed rules, a midstream developer is a party that integrates covered ADMT as a component into its own covered ADMT product and provides that product to another developer or a deployer (4 CCR 904-6, Rule 2.2). Proposed Rule 4.2 would require a midstream developer to reasonably obtain the upstream developer documentation for each component and make it available to its downstream customers, for example a company that builds an AI application on a third-party large language model.Source: Colorado AG proposed rules, 4 CCR 904-6 (Aug 11, 2026 draft)
- NIST AI Risk Management Framework (AI RMF)
- The NIST AI Risk Management Framework (AI RMF 1.0), released by the U.S. National Institute of Standards and Technology on January 26, 2023, is a voluntary framework for building trustworthiness into the design, development, use, and evaluation of AI systems. It is organized around four functions: Govern, Map, Measure, and Manage. NIST added a Generative AI Profile (NIST AI 600-1) on July 26, 2024.Source: NIST AI Risk Management Framework
- Operator (chatbot)
- Under the Colorado Chatbot Safety Act, an operator is a person or entity that develops and makes publicly available a conversational AI service, or that offers one to a consumer (C.R.S. § 6-1-1701(15.5), as added by HB 26-1263). There is no size threshold, so offering the service is enough; an app store or search engine is not an operator merely because it provides access to one.Source: Colorado HB 26-1263 (signed act)
- Pre-use notice
- A pre-use notice is the clear and conspicuous notice a deployer must give a consumer, before using a covered ADMT to materially influence a consequential decision, that it uses or will use covered ADMT in a decision affecting them, with instructions for getting more information (C.R.S. § 6-1-1704(1)). The statute calls it a point-of-interaction notice, and a deployer can satisfy it with a prominent public notice reasonably accessible at points of consumer interaction, such as a link near the transaction (§ 6-1-1704(2)).Source: Colorado SB 26-189 (signed act)
- Risk Management (FAIIR pillar)
- Risk Management is the fifth of the five FAIIR pillars and the audit-trail pillar: it asks whether an organization would detect an AI problem, contain it, and be able to prove what it did. Its ten controls (R1–R10) include a risk register, an incident definition and playbook, monitoring, vendor failure plans, insurance, retention of AI logs for at least three years, an annual compliance attestation, a change log, and a breach notification procedure.Source: The FAIIR Framework
- SOC 2
- SOC 2 is an AICPA attestation report, issued by a CPA firm, on a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy, evaluated against the AICPA's Trust Services Criteria. It addresses information-security controls generally rather than how an organization chooses and oversees its uses of AI.Source: AICPA & CIMA, SOC 2
- Use-case register
- A use-case register is a written inventory of every AI system an organization uses and the specific tasks each one is authorized for. It is FAIIR control F1, the starting point of the standard, and requires at least one line per tool.Source: The FAIIR Framework