Colorado

Colorado AI Act (SB 205)

The most comprehensive AI-specific statute enacted by a US state — a duty of reasonable care for both developers and deployers of high-risk AI systems, built around the concept of a consequential decision.

In forceEffective June 30, 2026
Legal team reviewing duty-of-care obligations under Colorado's AI Act
Photo: Junior Verhelst via Unsplash
Governome Editorial Team2 min readHow we source and review this content.

Colorado's SB 205 is the reference point for comprehensive state-level AI regulation in the US. Where other states have amended existing privacy or employment law to touch on AI, Colorado passed a standalone AI statute built specifically around AI risk — and it's stayed largely stable in substance through multiple amendment rounds, even as its effective date has moved. See our running coverage of the amendment timeline for what's changed procedurally versus what's stayed constant.

The core structure: consequential decisions

The statute doesn't classify systems by the underlying technology — it classifies by consequence. A "high-risk artificial intelligence system" is one that makes, or is a substantial factor in making, a consequential decision: a decision with a material legal or similarly significant effect on a consumer's access to, cost of, or terms of employment, education, lending, housing, healthcare, insurance, or legal services.

Two sets of obligations: developer and deployer

The statute imposes a duty of reasonable care on both sides of the relationship, with different specific obligations:

  • Developers of high-risk AI systems must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination, and must provide deployers with the documentation needed to complete their own impact assessment — including information about the system's intended use, known limitations, and the data used to train it.
  • Deployers — the companies actually using a high-risk system to make consequential decisions — owe the same duty of reasonable care, and must additionally complete and maintain an annual impact assessment for each high-risk system in use, plus provide consumers notice before the system is used to make a consequential decision about them.

Neither obligation is satisfied by the other side's compliance — a deployer using a fully compliant developer's system still owes its own independent duty of care and impact assessment obligation.

The affirmative defense tied to recognized frameworks

The statute creates an affirmative defense for developers and deployers who can demonstrate they discovered and cured a violation through internal testing consistent with a nationally or internationally recognized risk management framework — the NIST AI RMF is the framework most commonly referenced in this context, which is part of why NIST AI RMF adoption carries real practical weight in Colorado specifically, not just as general best practice.

What's moved, what hasn't

Amendment activity has concentrated on the effective date and scope of the small-business exemption. The duty-of-care obligations and the developer/deployer split described above have remained consistent through every round of amendments to date.

Sources & references

  1. Official source
  2. Colorado SB24-205 (full bill text)
Government policy officials in discussion about AI regulation enforcement
Photo: Zac Nielson via Unsplash
Colorado's SB 205 has been amended and delayed more than once since passage. Here's a plain accounting of what changed in the latest round, and which obligations were never in dispute.
Governome Editorial Team · 2 min read