The Colorado AI Act is a consumer protection law enacted in Colorado in 2024 that regulates the use of high-risk artificial intelligence systems. It is among the first comprehensive state-level statutes in the United States aimed at addressing algorithmic discrimination in AI decision-making. The law imposes obligations on both developers and deployers of AI systems that make consequential decisions about consumers, such as those affecting employment, housing, education, and financial services.
The Act defines a "high-risk AI system" as any AI system that makes, or is a substantial factor in making, a consequential decision. Consequential decisions include those with significant impacts on consumers, such as hiring, promotion, credit, insurance, and access to public accommodations. The law does not apply to AI systems used solely for certain narrow purposes, such as anti-fraud, cybersecurity, or internal business operations, unless they significantly affect consumers.
Background and Legislative Context
Colorado's legislative effort emerged amid growing public concern about the societal impacts of artificial intelligence, particularly in areas like machine learning and generative AI. While federal AI regulation remained fragmented, several states began proposing their own rules. Colorado's law was introduced in the 2024 legislative session and passed with bipartisan support, reflecting a broader trend of state-level AI governance.
The Act was signed into law by Governor Jared Polis on May 17, 2024, making Colorado the first state to enact a comprehensive AI discrimination law. It is scheduled to take effect on February 1, 2026, giving stakeholders time to comply.
Key Provisions
Developer Obligations
Developers of high-risk AI systems must take reasonable care to protect consumers from known or foreseeable risks of algorithmic discrimination. They are required to implement a risk management framework that includes:
- Establishing a governance structure to oversee AI development.
- Documenting the design, training, and testing processes.
- Conducting impact assessments to identify potential discriminatory outcomes.
- Providing disclosures to deployers about the system's capabilities and limitations.
Developers must also make available to deployers information necessary to comply with the law, including a statement of the system's intended uses and any known limitations.
Deployer Obligations
Deployers - entities that use high-risk AI systems - must also implement a risk management framework. They are required to:
- Conduct impact assessments before deploying a high-risk AI system.
- Notify consumers when an AI system is used in a consequential decision.
- Provide consumers with an opportunity to appeal an adverse decision and request human review.
- Maintain records of AI system usage and impact assessments for at least three years.
Deployers must also disclose to consumers the nature of the AI system and the decision-making process, including the logic used and the potential for discrimination.
Enforcement and Penalties
The Colorado Attorney General has exclusive authority to enforce the Act. The law does not create a private right of action, meaning individuals cannot sue directly. Instead, the Attorney General can investigate violations and bring civil actions, seeking injunctive relief and civil penalties of up to $50,000 per violation, with a maximum of $500,000 for a series of violations.
Impact Assessments
A central requirement of the Act is the performance of impact assessments. These assessments must evaluate the AI system's purpose, intended uses, and potential for algorithmic discrimination. They must also consider the system's design, training data, and validation methods, as well as any post-deployment monitoring and mitigation measures.
Impact assessments must be updated when there are significant changes to the AI system or its use. Deployers must retain assessments for at least three years and provide them to the Attorney General upon request.
Exemptions and Safe Harbors
The Act includes several exemptions. Small businesses - those with fewer than 50 employees and that do not use the AI system to make consequential decisions on more than 25,000 consumers annually - are exempt from certain requirements, though they must still comply with basic transparency obligations.
Additionally, the Act provides a safe harbor for developers and deployers that take reasonable care to comply with the law. If a violation occurs despite such care, the Attorney General may choose not to pursue enforcement, provided the entity corrects the violation within 60 days of notice.
Relationship to Other Laws
The Colorado AI Act does not preempt other state or federal laws. It is designed to complement existing anti-discrimination statutes, such as the Civil Rights Act and the Fair Housing Act. The law explicitly states that it does not create a private right of action, but it does not prevent individuals from pursuing claims under other applicable laws.
The Act also includes a provision that allows the Attorney General to adopt rules to implement the law, though as of early 2025, no such rules have been finalized.
Industry Reactions
Business groups, including technology trade associations, expressed mixed reactions. Some praised the law for providing clarity and a compliance framework, while others criticized it as overly burdensome and duplicative of existing regulations. Consumer advocacy groups generally supported the Act, viewing it as a necessary step to protect vulnerable populations from AI-driven discrimination.
Several companies, including major AI developers like OpenAI and Anthropic, have publicly stated their support for responsible AI regulation, though they have also called for federal standards to avoid a patchwork of state laws. The Act's impact on the broader AI industry remains to be seen, but it is likely to influence similar legislation in other states.
Implementation Timeline
The Act was signed in May 2024, with an effective date of February 1, 2026. This extended timeline was intended to give developers and deployers ample time to adjust their practices. The Colorado Attorney General's office has indicated that it will issue guidance before the effective date to help entities understand their obligations.
Future Outlook
The Colorado AI Act represents a significant milestone in AI governance. As large language models and other AI technologies become more integrated into everyday life, the need for clear legal frameworks grows. The Act's focus on algorithmic discrimination sets a precedent for other jurisdictions, and it may serve as a model for federal legislation. However, its success will depend on effective enforcement and the willingness of companies to embrace transparency and fairness in AI development.