Up nextNext guide
California SB 53 and Frontier AI Transparency
Society
Society GUIDE
The Colorado AI Act (SB 24-205) is the first broad US state law regulating high-risk AI systems: it requires developers and deployers of AI used in consequential decisions, such as hiring, lending, housing, health care and education, to use reasonable care to protect consumers from algorithmic discrimination.
It matters because it sets out concrete duties, including impact assessments, risk management programs and consumer notices, that other states and companies are watching as a possible model.
Colorado Governor Jared Polis signed SB 24-205, Consumer Protections for Artificial Intelligence, in May 2024 with stated reservations, urging lawmakers to refine it. The law was originally set to take effect on February 1, 2026. In an August 2025 special session, the legislature passed a bill delaying the effective date to June 30, 2026. Amendments have remained under debate, so check the current text and status before relying on it. The law targets high-risk AI systems, meaning systems that make, or are a substantial factor in making, a consequential decision. Consequential decisions are those with a material effect on access to, or the cost or terms of, education, employment, financial or lending services, essential government services, health care, housing, insurance or legal services. Algorithmic discrimination means that the use of an AI system results in unlawful differential treatment or impact that disfavors people based on protected characteristics such as age, color, disability, ethnicity, genetic information, national origin, race, religion, sex or veteran status. Uses aimed at testing for or reducing discrimination, or at increasing diversity, are carved out. Developers must provide deployers with documentation on intended uses, training data summaries, known risks and mitigation, publish a summary of their high-risk systems, and report known discrimination risks to the Attorney General and deployers within 90 days of discovering them. Deployers must maintain a risk management policy, complete impact assessments at least annually and after substantial modifications, notify consumers, and provide explanations, correction and appeal after adverse decisions. Some small deployers are exempt from parts of this. Only the Colorado Attorney General enforces the law; there is no private right of action. Discovering and curing violations while following a recognized framework such as the NIST AI Risk Management Framework or ISO/IEC 42001 supports an affirmative defense. Compared with the EU AI Act, Colorado's law is narrower: it focuses on discrimination in consequential decisions rather than creating banned practices, conformity assessments and large fines.
Catastrophic and everyday AI harms both depend on who understands the risks and who can act.
Public and professional literacy shapes whether strong safety policy is politically possible.
Clear explanations reduce capture by hype, lab PR, and vague ethics theater.
The Colorado law has been delayed and remains the subject of active debate over its scope, cost for small businesses and the definition of consequential decisions, so further amendments are possible. Other states have considered similar bills, with mixed results, and federal discussions about limiting or preempting state AI rules add uncertainty. Regardless of the final details, the practices it requires, including AI inventories, impact assessments and consumer notice, are becoming standard expectations in AI governance and are useful preparation for organizations operating in several jurisdictions.
A Colorado university using an AI model to help rank admissions applicants would be a deployer and would need a risk management program, annual impact assessments and a notice to applicants that AI is part of the decision.
A software company selling a resume-screening tool to Colorado employers would be a developer and would need to give those employers documentation on the tool's intended uses, known limitations and discrimination risks.
A landlord's tenant-screening system that denies an applicant would trigger the duty to explain the principal reasons, allow the applicant to correct inaccurate data and offer an appeal, with human review where technically feasible.
A customer service chatbot on a Colorado company's website would need to disclose that the consumer is talking with AI, unless that would be obvious to a reasonable person.
Treating existential risk as sci-fi while capability compounds.
Confusing surface product safety with alignment under high autonomy.
Leaving non-English and non-expert audiences with only low-quality sources.
Separate product harms, misuse, and loss-of-control / misalignment risks.
Ask what evidence would change your view on timelines and severity.
Prefer primary sources and concrete evals over marketing claims.
Identify one action path: career, policy, funding, or skills — not only awareness.
Free newsletter
Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.
One email each weekday. Unsubscribe in one click. We never sell or share your address.
Test yourself
Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.
Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation
The Colorado AI Act (SB 24-205) is the first broad US state law regulating high-risk AI systems: it requires developers and deployers of AI used in consequential decisions, such as hiring, lending, housing, health care and education, to use reasonable care to protect consumers from algorithmic discrimination. It matters because it sets out concrete duties, including impact assessments, risk management programs and consumer notices, that other states and companies are watching as a possible model.
The law defines high-risk systems by their role in consequential decisions such as employment, lending or housing.
The original date was February 1, 2026; the special session moved it to June 30, 2026.
The law gives enforcement authority to the Attorney General and creates no private right of action.
Deployers, the organizations using the system on consumers, carry impact assessment and consumer notice duties.
The law requires explanation, correction of inaccurate data and appeal with human review if technically feasible.
Keep learning
More guides picked for this topic
Up nextNext guide
California SB 53 and Frontier AI Transparency
Society