regulations us colorado

Colorado's AI Act Timeline Has Moved Again — Here's What Actually Changed

The effective date has shifted, but the parts of the law generating the most compliance questions haven't moved at all.

Government policy officials in discussion about AI regulation enforcement
Photo: Zac Nielson via Unsplash

If you've lost track of Colorado's AI Act timeline, you're not alone — it's been amended more than once since the legislature passed SB 205, and each round of changes gets reported as if the whole law were in flux. It isn't. The effective date has moved; the core developer-and-deployer obligations for high-risk AI systems have not.

What actually changed

The amendment activity has concentrated on three things: the effective date itself, the scope of the small-business exemption, and clarifications to the notice requirements owed to consumers affected by a covered decision. None of the rounds so far have touched the underlying definition of a "high-risk artificial intelligence system" or removed the duty of reasonable care that both developers and deployers owe under the statute.

That distinction matters more than the headline. Companies that treated the delay as a reason to deprioritize the underlying compliance work are going to be doing that work under time pressure instead of on their own schedule — the substantive requirements were never the part that was uncertain.

The obligations that haven't moved

Two duties have stayed constant through every amendment round:

  • Developers of high-risk AI systems owe a duty of reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination, and must provide deployers with the information needed to complete an impact assessment.
  • Deployers owe the same duty of reasonable care and must complete and maintain an annual impact assessment for each high-risk system, plus provide notice to consumers before a high-risk system is used to make, or is a substantial factor in making, a consequential decision about them.

If your organization deploys — rather than builds — high-risk AI systems (which describes most companies using third-party HR, lending, or insurance-adjacent AI tools), the deployer obligations are the ones to plan around, and they require cooperation from your vendors that's easier to negotiate into a contract before the law is enforced than after.

What we'd actually do with this

Don't wait for the next amendment round to start the impact assessment process. The assessment itself — mapping what the system does, what data it uses, what the known risk of algorithmic discrimination looks like, and what mitigations are in place — is useful risk management regardless of which effective date ends up in the final text. Treat the moving date as noise and the underlying obligations as the signal.

We'll update this page directly, in place, the next time the statute or its implementing regulations change — that's the point of tracking regulatory status as data rather than as a series of one-off news posts. See our full Colorado AI Act tracker for the current effective date and the complete text of the deployer obligations.

Sources & references

  1. Colorado SB24-205 (full bill text)
Legal team reviewing duty-of-care obligations under Colorado's AI Act
Photo: Junior Verhelst via Unsplash

regulations us colorado

Colorado AI Act (SB 205)

Colorado's SB 205 imposes duties of reasonable care on both developers and deployers of high-risk AI systems, with impact assessment and consumer notice requirements tied to consequential decisions.
Governome Editorial Team · 2 min read
Risk management team analyzing AI system risk factors in a meeting
Photo: Christina @ wocintechchat.com M via Unsplash
The NIST AI RMF is a voluntary, four-function framework for managing AI risk. It carries real legal weight in the US — Colorado's AI Act ties an affirmative defense directly to it.
Governome Editorial Team · 2 min read