How the first comprehensive US state AI law was delayed, enjoined, and then repealed and replaced before it ever took effect — and what actually applies now.

This article is educational guidance, not legal advice. AI law in the United States is changing quickly and varies by state and sector. Confirm current statutory text, effective dates, and rulemaking with primary sources and qualified counsel before making compliance decisions.

Colorado's Senate Bill 24-205 was the first comprehensive, cross-sector artificial intelligence law passed by a US state. Signed in May 2024, it built a risk-based framework around “high-risk” AI systems and a duty of reasonable care to avoid algorithmic discrimination — an approach widely compared to the EU AI Act. It never took effect in that form. After two delays, a federal court order pausing enforcement, and a 2026 legislative rewrite, the original Act was repealed and replaced by SB 26-189, a narrower transparency-and-consumer-rights statute that becomes effective January 1, 2027.

This article walks through both frameworks: what SB 24-205 required, why it was reset, and the operational duties that SB 26-189 now imposes on organizations that use automated tools to make consequential decisions about Coloradans.

Timeline: what happened and when

Date Event
May 2024 Governor Polis signs SB 24-205, the Colorado Artificial Intelligence Act. Original effective date: February 1, 2026.
Aug 28, 2025 SB25B-004 (special session) delays the effective date to June 30, 2026 to allow further amendment.
Early 2026 A federal court temporarily suspends enforcement of SB 24-205 amid litigation (a challenge brought by xAI, with US DOJ involvement).
May 14, 2026 Governor Polis signs SB 26-189, repealing and replacing the Act with a new ADMT-focused framework.
Jan 1, 2027 SB 26-189 substantive obligations and Attorney General rules take effect.
Practical takeaway: SB 24-205's “high-risk AI” duty-of-care regime never became enforceable. If you are planning Colorado compliance today, build to SB 26-189, not to the original 2024 text.

What SB 24-205 originally required (now superseded)

It is worth understanding the original design, because vendor materials and older guidance still describe it, and because several other states modeled proposals on it. SB 24-205 regulated developers and deployers of “high-risk artificial intelligence systems” — systems that are a substantial factor in making a “consequential decision” in areas such as employment, housing, credit, insurance, education, health care, legal services, and essential government services.

The centerpiece was a duty of reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. To operationalize that duty, the Act imposed:

  • Developer obligations: disclose to deployers the intended uses, known limitations, and known or foreseeable risks of algorithmic discrimination, and provide documentation to support deployers' impact assessments.
  • Deployer obligations: implement a risk management program, conduct annual impact assessments, provide consumer notice when a high-risk system is used to make a consequential decision, and offer an opportunity to correct data and appeal.
  • Attorney General notification: report discovered algorithmic discrimination to the Colorado AG (and, for developers, to known deployers) within 90 days.
  • A rebuttable presumption of reasonable care (a partial safe harbor) for parties that complied with the statute and any AG rules.

Enforcement was exclusively by the Colorado Attorney General, with violations treated as deceptive trade practices and no private right of action. Business groups argued the impact-assessment and reasonable-care obligations were burdensome and ambiguous, which drove the delays and, ultimately, the rewrite.

SB 26-189: the framework that actually applies

SB 26-189 keeps the consumer-protection goal but drops the EU-style risk-management architecture. It regulates “covered automated decision-making technology” (ADMT) — systems that use computation or machine learning to process personal data and materially influence a consequential decision — rather than a broad “high-risk AI” category.

Scope and consequential decisions

“Consequential decisions” cover the familiar life-impact domains: employment, housing, credit and lending, insurance, health care, education, and essential government services. The law carves out a long list of routine tools that do not materially influence such decisions on their own — for example firewalls, spam and malware filters, spell-checkers, calculators, databases and spreadsheets, web hosting, scheduling, customer-service triage, advertising, product recommendations, search, and content moderation.

The four core operational duties

Instead of impact assessments and a duty of care, SB 26-189 imposes four concrete, operational duties on deployers that use covered ADMT for consequential decisions:

  1. Consumer notice: provide clear and conspicuous notice before using covered ADMT to make, or materially influence, a consequential decision.
  2. Adverse-decision disclosure: within 30 days of an adverse outcome, give the consumer a plain-language explanation of the decision and of the ADMT's role in it.
  3. Data correction: allow individuals to request correction of inaccurate personal data used in the decision.
  4. Human review: provide meaningful human review and reconsideration to the extent commercially reasonable.

Developer documentation

Developers (vendors) must give deployers documentation covering intended uses, known risks, the categories of training data, usage instructions, and human-oversight guidance, and must retain relevant records for three years. Notably, the law voids contract clauses that attempt to indemnify a party for its own ADMT-related discriminatory acts — limiting a common vendor risk-shifting tactic.

Sector safe harbors and exemptions

SB 26-189 is designed to sit alongside existing sector rules rather than duplicate them. Broadly:

Sector How SB 26-189 treats it
Financial services Adverse-action notices already required under ECOA/FCRA can satisfy the disclosure duty.
Insurance Compliance with Colorado's existing insurance algorithmic-discrimination rules can satisfy requirements.
Health care HIPAA-regulated entities largely exempt, except employment decisions and financial-assistance determinations.
Medical devices / pharma FDA-regulated activities excluded.
Education FERPA-compliant notices and processes can satisfy requirements.

Enforcement

  • Enforced exclusively by the Colorado Attorney General; violations are deceptive trade practices.
  • No private right of action — consumers cannot sue directly.
  • A 60-day notice-and-cure period applies before most enforcement actions (not for knowing or repeated violations). The cure right sunsets on January 1, 2030.
  • The Colorado AG is authorized to issue implementing rules ahead of the January 1, 2027 effective date.

What teams should do now

  1. Inventory automated tools that influence consequential decisions about Colorado residents (hiring, lending, insurance, housing, benefits, education, health).
  2. Build the four operational capabilities: pre-use notice, a 30-day adverse-decision explanation workflow, a data-correction path, and a human-review escalation route.
  3. Update vendor contracts: require the developer documentation package and remove indemnification clauses that would be voided.
  4. Track Colorado AG rulemaking through 2026, and watch the parallel federal preemption effort (see our US federal AI landscape article) that could affect state-law enforcement.
If you already built to SB 24-205's impact-assessment model, most of that work is still useful — documentation, notices, and human oversight map cleanly onto SB 26-189's lighter duties, even though the formal risk-assessment mandate is gone.