What happened
The National Law Review reports that Colorado’s Department of Law filed proposed rules on August 11 to implement two AI laws scheduled to take effect January 1, 2027. The draft rules would create detailed notice, data-access, correction, and independent human-review duties for employers using automated decision-making technology in hiring, promotion, termination, and other consequential employment decisions. The rules remain subject to the state rulemaking process and have not been independently confirmed here as final.
The National Law Review reports that Colorado’s Department of Law filed proposed Automated Decision-Making Technology and Conversational Artificial Intelligence Service rules with the secretary of state on August 11, 2026. The article says the draft rules are intended to implement two laws signed by Gov. Jared Polis in May: Senate Bill 26-189, the Automated Decision-Making Technology in Consequential Decisions Act, and House Bill 26-1263, the Chatbot Safety Act. Both laws and the proposed rules are described as scheduled to take effect January 1, 2027. The article makes clear that the rules are an initial draft and are not final.
The proposed requirements focus heavily on employment decisions. According to the National Law Review, employers using covered automated decision-making technology would have to disclose its use before making a consequential decision, including decisions about hiring or termination. If the decision produces an adverse outcome, the employer would need to describe the system’s specific purpose, the role it played, the role of human reviewers or other systems, and the principal reasons for the result. The article says explanations could not be so broad or vague that the affected person could not understand how the decision was made.
The National Law Review reports that affected employees and applicants could request additional information about the data considered by the system. The draft rules would require descriptions of data categories, such as credit, health, or criminal-history information, and identification of each data source by name. If information came through an aggregator, the disclosure would reportedly have to trace the chain to the original source and identify intermediaries. The article says this could require employers to review contracts with background-check companies, assessment platforms, and data brokers.
The draft rules would also specify how people could exercise their rights. The National Law Review reports that an adverse-outcome notice would need a clearly labeled link to a request mechanism, plus a mailing address or toll-free number. Employers would need at least two submission methods, monitor them through people capable of processing requests, and allow submissions at any time. The article further says individuals could request specific personal data used in the decision, including rankings, scores, classifications, recommendations, predictions, and other inferences, and that incorrect information would generally need to be corrected in existing systems.
Source details: natlawreview.com ↗
Why it matters
If adopted, the rules would make it harder for employers to treat AI employment tools as opaque vendor products. Employers could need to explain how a system influenced an adverse outcome, identify the sources of personal data used, correct inaccurate information, and arrange a genuinely independent reviewer with authority to override the result. The requirements could affect compliance systems, vendor contracts, recordkeeping, and the practical ability of workers and applicants to challenge AI-assisted decisions.
The proposed rules would shift responsibility toward the employer that deploys an AI system, rather than allowing the employer to rely entirely on a vendor’s general description of the technology. The National Law Review’s account suggests that an employer could fail to comply if it cannot explain how the system materially influenced a decision, how it used a person’s data, or what the principal reasons for the adverse outcome were. In practice, that could push employers to document inputs, outputs, weighting, human involvement, and decision pathways before using automated tools in high-impact settings.
The data-source provisions could have significant operational consequences. Employers that obtain information from multiple vendors or intermediaries may need to reconstruct where personal data originated and what transformations occurred before the data reached an automated assessment. That could affect procurement, contract language, audit rights, data-retention practices, and the ability to respond quickly to a worker’s request. The National Law Review reports these obligations as features of the proposal; the article does not provide independent testing of how employers or vendors would be able to meet them.
The human-review provisions are designed to require more than a nominal human sign-off. According to the National Law Review, a reviewer would need to be independent, have authority to approve, modify, or override the decision, and possess subject-matter knowledge proportionate to the harm involved. The reviewer generally should not be the original decision-maker or that person’s subordinate. The article reports proposed deadlines of ten days to confirm receipt of a request and 45 days to complete the review.
The rules could also make review more demanding when the decision threatens a basic human need. The National Law Review reports that the draft would create a rebuttable presumption that review is commercially reasonable when an adverse outcome causes a severe and irreversible denial of such a need. The employer would bear the burden of showing technical or financial impossibility, or that review could not change the result. The article suggests that employment termination or nonrenewal of an essential position could implicate this standard, but the final scope and legal interpretation remain unknown.
What to watch next
The key uncertainty is what Colorado will include in its final rules and how the state will interpret commercial reasonableness, especially for smaller employers and decisions that affect a person’s livelihood. Employers using screening, assessment, background-check, or other automated tools will need to monitor the rulemaking, map data flows, and prepare review procedures. Workers and applicants will also need clear information about when a decision involved AI and how to request correction or reconsideration.
The immediate issue is the state’s rulemaking process. The National Law Review describes the filing as an initial draft released for comment, so the final text may change the definitions, deadlines, exemptions, documentation requirements, or standards for human review. This article does not independently confirm the filing through a publicly cited state document, and it does not report the number or substance of public comments. Readers should therefore treat the described duties as proposed obligations, not enforceable rules already in effect.
Employers using AI in recruiting, performance management, promotion, termination, or related decisions will need to determine whether their tools fall within the final definition of automated decision-making technology and consequential decision. Practical preparation could include inventorying systems, documenting how scores or recommendations affect outcomes, identifying all personal-data sources, and assessing whether vendors can support correction and explanation requests. These are compliance implications drawn from the proposed framework, not requirements that the source establishes as currently binding.
The meaning of meaningful human review will be especially important. The proposed framework distinguishes between a malfunction and a deeper problem with the system’s factors, data, or intended use. The National Law Review reports that a malfunction could lead to correcting the tool and rerunning the process, while a challenge to the system itself could require additional evidence and reconsideration of the outcome. It remains unclear how regulators will evaluate reviewer independence, training, documentation, and the authority to override decisions in real cases.
The final rules will also determine how the proposal interacts with other state and federal employment, privacy, consumer-protection, and anti-discrimination requirements. The source does not provide enforcement history, projected compliance costs, examples of actual disputes, or responses from employers, workers, technology vendors, or civil-rights organizations. Those are meaningful unknowns. Until the rulemaking concludes, the most reliable conclusion is that Colorado is proposing a detailed accountability framework for AI-assisted employment decisions, not that the framework has been finalized or tested.

