Colorado advances detailed AI regulations targeting high-risk systems and consumer-facing chatbots

Colorado’s proposed rules for the Automated Decision-Making Technology Act and Chatbot Safety Act set a new benchmark for operational transparency and consumer rights, forcing AI deployers to re-evaluate their compliance strategies ahead of 2027 implementation.

Colorado has moved a step closer to enforcing one of the country’s more detailed state-level AI regimes. On 11 August 2026, the Colorado Department of Law released proposed rules to implement the Automated Decision-Making Technology Act and the separate Chatbot Safety Act, both of which are due to take effect on 1 January 2027. The draft rules are not final, and the state is accepting comments until 4 September, with a particular focus on how to define covered automated decision-making technology.

The proposal matters because it goes well beyond the statutes’ broad language. According to the Attorney General’s office, the ADMT Act is aimed at high-risk systems used in consequential decisions affecting areas such as employment, housing, lending, insurance, health care and public benefits. The Chatbot Safety Act, meanwhile, targets consumer-facing conversational AI services and requires age estimation, disclosure, safeguards for minors, crisis response and annual reporting. The new draft rules seek to turn those general duties into operational requirements.

A central point of uncertainty is when a system is deemed to “materially influence” a decision. The draft does not settle on a single test. Instead, it offers two possible standards and asks which should be adopted. Both would presume material influence where a system constrains options, sets a threshold or produces a rank, score, classification or inference that is then reviewed by the decision-maker and aligns with the final outcome. The practical effect is to push organisations towards keeping records showing that a human applied independent judgement.

The disclosure obligations would also be more demanding than many deployers are likely to expect. Under the draft, people who suffer an adverse outcome would be entitled to a detailed notice within 30 days, including the decision involved, the purpose of the system, the role of any human reviewer and the principal reasons for the result. The rules also call for more explanation where the outcome depends on an inference, profile, risk score or incomplete data. In sectors such as hiring, housing, lending and insurance, that could require clearer data lineage and stronger vendor disclosures than many firms currently receive.

The consumer-rights provisions are similarly exacting. Deployers would have to identify the system, its version, its developer and the categories and sources of personal data used, including original sources where information arrived through intermediaries. Requests would have to be handled within short timeframes, and consumers would be entitled to see the personal data and ADMT inputs used in relation to them in a form that can be understood and challenged. The rules also set out a structured model for meaningful human review, including staffing, training, documentation and, where possible, an independent reviewer with the authority to change the outcome.

For chatbot operators, the draft creates a different but still significant compliance burden. According to the Attorney General’s office, the Chatbot Safety Act is narrower in scope than the ADMT regime, but the proposed rules would still require age-assurance methods that do more than rely on self-declaration, ban sole reliance on government-issued identification, and require operators to reassess age when new signals suggest a change. They would also have to report metrics on age distribution, estimation methods, crisis referrals, response times and changes in determinations. In practical terms, the draft suggests that Colorado expects not just policy updates, but new technical and reporting infrastructure before the 2027 effective date.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.