社会ガイド

Colorado AI Act (SB 24-205) Explained

The Colorado AI Act (SB 24-205) is the first broad US state law regulating high-risk AI systems: it requires developers and deployers of AI used in consequential decisions, such as hiring, lending, housing, health care and education, to use reasonable care to protect consumers from algorithmic discrimination.

  • 4 分で読めます
  • 最終更新日
このページでは4 分で読めます
  1. 概要
  2. ディープダイブ
  3. 戦略的影響
  4. The Future of Colorado AI Act (SB 24-205) Explained
  5. 現実世界の実装
  6. リスクとガードレール
  7. 実装ロードマップ
  8. 探検を続けましょう
  9. よくある質問

概要

It matters because it sets out concrete duties, including impact assessments, risk management programs and consumer notices, that other states and companies are watching as a possible model.

ディープダイブ

Colorado Governor Jared Polis signed SB 24-205, Consumer Protections for Artificial Intelligence, in May 2024 with stated reservations, urging lawmakers to refine it. The law was originally set to take effect on February 1, 2026. In an August 2025 special session, the legislature passed a bill delaying the effective date to June 30, 2026. Amendments have remained under debate, so check the current text and status before relying on it. The law targets high-risk AI systems, meaning systems that make, or are a substantial factor in making, a consequential decision. Consequential decisions are those with a material effect on access to, or the cost or terms of, education, employment, financial or lending services, essential government services, health care, housing, insurance or legal services. Algorithmic discrimination means that the use of an AI system results in unlawful differential treatment or impact that disfavors people based on protected characteristics such as age, color, disability, ethnicity, genetic information, national origin, race, religion, sex or veteran status. Uses aimed at testing for or reducing discrimination, or at increasing diversity, are carved out. Developers must provide deployers with documentation on intended uses, training data summaries, known risks and mitigation, publish a summary of their high-risk systems, and report known discrimination risks to the Attorney General and deployers within 90 days of discovering them. Deployers must maintain a risk management policy, complete impact assessments at least annually and after substantial modifications, notify consumers, and provide explanations, correction and appeal after adverse decisions. Some small deployers are exempt from parts of this. Only the Colorado Attorney General enforces the law; there is no private right of action. Discovering and curing violations while following a recognized framework such as the NIST AI Risk Management Framework or ISO/IEC 42001 supports an affirmative defense. Compared with the EU AI Act, Colorado's law is narrower: it focuses on discrimination in consequential decisions rather than creating banned practices, conformity assessments and large fines.

戦略的影響

リスクと安全性

AI による壊滅的な被害も日常的な被害も、誰がリスクを理解し、誰が行動できるかにかかっています。

より明確な判決

国民と専門家のリテラシーは、強力な安全政策が政治的に可能かどうかを左右します。

誇大広告を打ち破る

明確な説明は、誇大広告、研究室の PR、曖昧な倫理劇場に囚われることを減らします。

The Future of Colorado AI Act (SB 24-205) Explained

The Colorado law has been delayed and remains the subject of active debate over its scope, cost for small businesses and the definition of consequential decisions, so further amendments are possible. Other states have considered similar bills, with mixed results, and federal discussions about limiting or preempting state AI rules add uncertainty. Regardless of the final details, the practices it requires, including AI inventories, impact assessments and consumer notice, are becoming standard expectations in AI governance and are useful preparation for organizations operating in several jurisdictions.

現実世界の実装

A Colorado university using an AI model to help rank admissions applicants would be a deployer and would need a risk management program, annual impact assessments and a notice to applicants that AI is part of the decision.

A software company selling a resume-screening tool to Colorado employers would be a developer and would need to give those employers documentation on the tool's intended uses, known limitations and discrimination risks.

A landlord's tenant-screening system that denies an applicant would trigger the duty to explain the principal reasons, allow the applicant to correct inaccurate data and offer an appeal, with human review where technically feasible.

A customer service chatbot on a Colorado company's website would need to disclose that the consumer is talking with AI, unless that would be obvious to a reasonable person.

リスクとガードレール

  • 能力が複雑になる一方で、実存的なリスクを SF として扱います。

  • 高度な自律性の下での調整による表面製品の安全性を混乱させる。

  • 英語以外や専門家ではない聴衆には、低品質の情報源しか提供されません。

実装ロードマップ

  1. 製品の危害、誤使用、制御不能/調整不良のリスクを分離します。

  2. どのような証拠がタイムラインと重大度についてのあなたの見方を変えるかを尋ねてください。

  3. マーケティング上の主張よりも、一次情報源と具体的な評価を優先します。

  4. 意識だけでなく、キャリア、政策、資金、スキルなど、行動経路を 1 つ特定します。

探検を続けましょう

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Colorado AI Act (SB 24-205) Explained quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

クイズを開始する

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

よくある質問

What is Colorado AI Act (SB 24-205) Explained?

The Colorado AI Act (SB 24-205) is the first broad US state law regulating high-risk AI systems: it requires developers and deployers of AI used in consequential decisions, such as hiring, lending, housing, health care and education, to use reasonable care to protect consumers from algorithmic discrimination. It matters because it sets out concrete duties, including impact assessments, risk management programs and consumer notices, that other states and companies are watching as a possible model.

Under SB 24-205, what makes an AI system high-risk?

The law defines high-risk systems by their role in consequential decisions such as employment, lending or housing.

To what date did the August 2025 special session delay the law's effective date?

The original date was February 1, 2026; the special session moved it to June 30, 2026.

Who enforces the Colorado AI Act?

The law gives enforcement authority to the Attorney General and creates no private right of action.

Which is a deployer duty rather than a developer duty?

Deployers, the organizations using the system on consumers, carry impact assessment and consumer notice duties.

What must happen after an adverse consequential decision made with a high-risk system?

The law requires explanation, correction of inaccurate data and appeal with human review if technically feasible.