Colorado matters because it has enacted a cross-sector law that expressly reaches employment and employment opportunities. But the useful starting point is timing, not alarm. Employers are not looking at an immediate ban on workplace AI, and the statute does not automatically cover every system that contains an algorithm or a language model. Coverage depends on what the technology does, what data it processes, and whether its output materially influences a defined consequential decision.

The current framework is also not the same law Colorado enacted in 2024. Senate Bill 26-189, signed May 14, 2026, repealed and reenacted Part 17 of the Colorado Consumer Protection Act. The replacement statute moved away from the earlier law’s high-risk-AI terminology and its general risk-management and impact-assessment duties. It now centers on covered automated decision-making technology, developer documentation, deployer notices, data correction, recordkeeping, and meaningful human review after specified adverse outcomes.

What the law is—and when it operates

SB 26-189 is the enacted Automated Decision-Making Technology Act, codified through a repeal and reenactment of Colorado Revised Statutes sections 6-1-1701 through 6-1-1709. Most of the act takes effect January 1, 2027, and it applies to consequential decisions made on or after that date. Certain rulemaking, appropriations, and procedural provisions took effect upon passage so the state could prepare for implementation.

The Colorado Attorney General has exclusive authority to enforce the new Part 17 through the Colorado Consumer Protection Act. A violation is treated as a deceptive trade practice. The act does not create a new private right of action, although it expressly preserves existing rights and remedies under anti-discrimination, consumer-protection, product-liability, and other law.

When workplace technology can fall within the law

An automated decision-making technology, or ADMT, is technology that processes personal data and uses computation to generate an output—such as a prediction, recommendation, classification, ranking, or score—used to make, guide, or assist a decision about an individual. It becomes a “covered ADMT” when it is used to materially influence a consequential decision.

For employment, a consequential decision is a decision, determination, or action about a consumer relating to employment or an employment opportunity that creates or may create an employer-employee relationship. The definition reaches access, eligibility, selection, and compensation, as well as materially less favorable differentiated terms that are reasonably likely to materially limit or alter access or opportunity.

“Materially influence” supplies an important boundary. The output must be a non-de minimis factor used in the decision and must affect the outcome—for example by ranking, scoring, recommending, classifying, constraining, or otherwise meaningfully altering how the decision is made. Incidental, trivial, and clerical uses do not qualify. That makes a résumé-ranking score used to determine interview selection a more obvious candidate for coverage than software used only to route completed forms to the correct recruiter.

The statute reinforces that boundary with exclusions. Low-stakes or routine processes such as routine scheduling, administrative routing, communication of decisions, and workflow management are not consequential decisions when they do not materially influence employment eligibility, selection, denial, compensation, or access. Tools used only to summarize, organize, draft, translate, route, or present information for human review are excluded from ADMT, and summarization or presentation does not become a consequential decision unless the system produces an inference, recommendation, score, or similar output that materially influences the result.

The people and roles employers need to identify

  • A consumer includes an employee, a job applicant who is a Colorado resident, and an individual whose access to or opportunity in Colorado is evaluated in a consequential decision by a person doing business in Colorado.
  • A deployer is a person doing business in Colorado that deploys a covered ADMT. An employer using a vendor’s scoring or recommendation system in a covered decision will often need to evaluate itself in this role.
  • A developer includes a person doing business in Colorado that develops or commercially provides a covered ADMT or covered component, or intentionally and substantially modifies an ADMT so that it becomes covered. A company can therefore be more than a customer if it substantially changes a tool or builds a covered system itself.
  • An adverse outcome includes denial, termination, revocation, or material restriction of access, eligibility, selection, or compensation, as well as materially less favorable differentiated compensation or other material terms meeting the statute’s threshold. In employment, rejection, termination, or a materially worse compensation decision may qualify; ordinary inconvenience does not necessarily do so.

Employer and deployer obligations

Before a deployer uses covered ADMT to materially influence a consequential decision, it must give the consumer clear and conspicuous notice that covered ADMT was or will be used and explain how to obtain the additional information required by the act. The statute allows a prominent public notice reasonably accessible at points of consumer interaction, including a nearby link or posting, to satisfy this obligation.

If the covered use produces an adverse outcome, the deployer must provide a disclosure within 30 days after making the decision. The disclosure must describe the consequential decision and the ADMT’s role in plain language; give a simple process for requesting information including the system name, version where applicable, developer, and the types, categories, and sources of personal data used to the extent the developer supplied that information; and explain the consumer’s statutory rights and how to exercise them.

After that adverse outcome, the consumer may request instructions for obtaining personal data and correcting factually incorrect or materially inaccurate personal data used in the decision. The law does not require correction of opinions, predictions, scores, or protected evaluations. The consumer may also request meaningful human review and reconsideration, to the extent commercially reasonable.

Meaningful review is not a ceremonial approval. The reviewer must have authority to approve, modify, or override the decision; consider relevant available primary evidence; be trained; avoid defaulting to the system output; and have enough information to understand the system’s intended use, material limitations, input categories, and principal factors. The statute protects source code, model weights, and trade secrets from mandatory disclosure, but withholding required information must itself be disclosed where the act provides.

Deployers must retain records reasonably necessary to demonstrate compliance for at least three years after the consequential decision, or longer when another law requires it. The statute lists system-version identifiers, changelogs, and mitigation documentation as examples. Notices and disclosures must be reasonably accessible to people with disabilities and limited English proficiency, consistently with applicable law.

Developer duties that matter in procurement

Beginning January 1, 2027, developers must provide deployers reasonably understandable documentation that protects trade secrets and legally protected information. It must cover intended uses and known harmful or inappropriate uses; known training-data categories; known limitations, risks, and circumstances in which the system should not be used; instructions for appropriate use, monitoring, and meaningful human review where applicable; and information reasonably necessary for deployer compliance. If information is withheld, the developer must notify the deployer.

Developers must also notify deployers within a reasonable time about material updates, intentional and substantial modifications, and changes to intended use, limitations, or risk mitigation. They may use public release notes only if deployers receive direct notice of the release. Developer duties are tied to covered uses the system was marketed, configured, contracted, sold, or licensed to perform; they are not unlimited responsibility for every downstream improvisation.

For employment buyers, this turns documentation into a procurement issue. A vendor’s assurance that a product is “compliant” is not a substitute for identifying the intended use, versions, input categories, limitations, review instructions, and update-notice process. The act also allocates fault between developers and deployers in existing discrimination actions and makes contractual terms purporting to indemnify a party for its own covered anti-discrimination violations contrary to public policy and void, subject to the statute’s qualifications.

What employers can prepare before 2027

  1. Inventory systems used in recruiting, screening, interview selection, hiring, promotion, compensation, discipline, termination, and access to employment opportunities. Record what each system outputs and how that output changes the decision.
  2. Separate administrative assistance from material influence. Document whether a tool only routes or summarizes information, or whether it scores, ranks, recommends, predicts, or constrains outcomes in a non-de minimis way.
  3. Map the people in scope. Identify Colorado-resident applicants, employees, and decisions concerning opportunities in Colorado, rather than assuming the rule follows only the employer’s headquarters.
  4. Review vendor contracts and documentation. Ask for intended-use statements, limitations, training-data categories, version identifiers, monitoring instructions, human-review support, update notices, and the information needed for post-outcome explanations.
  5. Assign operational ownership. HR, employment counsel, procurement, privacy, compliance, and technology teams should know who determines coverage, issues notices, handles rights requests, and preserves the decision record.
  6. Design the notice and response workflow. Decide where point-of-interaction notice will appear, how an adverse outcome will trigger the 30-day disclosure, and how requests for data, correction, and review will be authenticated and routed.
  7. Prepare genuine human escalation. Identify trained reviewers with actual override authority and access to primary evidence and system documentation. A rubber-stamp process does not match the statutory definition.
  8. Build three-year recordkeeping around the decision, system version, relevant documentation, notices, and material changes, while checking whether employment, privacy, or other law requires a longer period.
  9. Monitor final rulemaking. Treat the August draft as a serious implementation signal, but do not hard-code every proposed form, channel, or deadline as though it were final law.

What the law does not mean

  • It is not an AI hiring ban. The act regulates defined uses and outcomes; it does not categorically prohibit covered workplace systems.
  • Not every HR tool is covered. Coverage requires personal-data processing, computational output, a consequential decision, and material influence, and the statute contains express exclusions.
  • Enacted does not mean every substantive duty is operative today. Most requirements attach to consequential decisions made on or after January 1, 2027.
  • The current act does not impose the original 2024 law’s general impact-assessment and risk-management-program structure.
  • Colorado is not New York City Local Law 144. Colorado does not create the same bias-audit-and-public-summary regime, and its definitions, rights, covered decisions, and enforcement model differ.

Enforcement, cure, and other legal exposure

The Attorney General exclusively enforces the duties in Part 17. Before January 1, 2030, the Attorney General generally must issue a notice of violation and allow 60 days to cure if the Attorney General considers a cure possible. That cure process is unavailable as a guaranteed safe harbor: the Attorney General need not offer it for a knowing violation or repeated violations, and the temporary cure provision repeals January 1, 2030.

Compliance with the ADMT Act is not a defense to violating another law. The statute specifically says using ADMT does not excuse discrimination or other state or federal obligations. It also permits liability under existing Colorado anti-discrimination law and allocates fault between a developer and deployer according to their relative responsibility. Employers should therefore treat Part 17 as one layer of the legal analysis, not a replacement for employment-discrimination, disability, privacy, wage, or consumer-reporting requirements.

What could still change before January 1, 2027

The statute is enacted, and its current applicability date is January 1, 2027. The implementation details remain subject to rulemaking, and the legislature could amend the statute again. On August 11, 2026, the Colorado Department of Law filed proposed ADMT and chatbot-safety rules. The draft addresses consumer communications, developer documentation, adverse-outcome disclosures, rights-request procedures, and meaningful human review, including employment examples. It proposes more detailed communication channels, response periods, and review records than the statute states on its face.

Those provisions remain proposals. The Attorney General’s published schedule says a revised proposed draft will be circulated no later than September 23, 2026, with a formal hearing and comment deadline currently set for October 26, 2026. Employers can use the draft to identify likely workflow demands, but final procedures should be checked against the adopted text.

Bottom line

Colorado’s 2027 framework gives employers a focused operational preparation list: identify systems that materially influence employment decisions, secure usable documentation from vendors, prepare notices and post-outcome explanations, establish data-correction and genuine human-review paths, and retain a defensible record. It does not require employers to label every workplace tool “high risk,” and it does not preserve the former statute’s general assessment program.

The most important near-term task is to distinguish the enacted statute from the still-changing rules. Bot Labor Law will update the Colorado record as the Attorney General revises and finalizes implementation requirements.