Colorado Regulators Release Proposed Rulebook for AI-Assisted Hiring and Employment Decisions
The Colorado Attorney General's office has published draft rules detailing how employers must disclose algorithmic hiring decisions, conduct human reviews, and manage vendor accountability.
By Bo Feng
- Employer Advocates
- Focus on the reduced burden compared to the 2024 law, but express concern over vendor explainability requirements.
- Consumer Privacy Advocates
- Emphasize the need for strict age-assurance and independent human review to prevent algorithmic discrimination.
- AI Developers
- Highlight the technical challenges of providing 'principal reasons' for complex neural network outputs.
Colorado regulators have released the operational manual for how employers must handle artificial intelligence in hiring, promotions, and compensation. On August 11, 2026, the Colorado Attorney General's office published proposed rules implementing the state's new Automated Decision-Making Technology Act. The draft framework shifts the compliance burden from proactive risk audits to decision-by-decision accountability, requiring companies to explain exactly how algorithms influence their workforce choices.[1][2]
The proposed rules arrive three months after Governor Jared Polis signed Senate Bill 26-189, which repealed and replaced the state's landmark 2024 AI law before it ever took effect. The original statute had drawn intense opposition from the technology industry and the federal government for its prescriptive mandates, including mandatory risk management programs and annual bias audits.[5][6]
In its place, the new framework—set to take effect on January 1, 2027—adopts a narrower but highly operational approach. Rather than demanding systemic audits, the law focuses on transparency, consumer rights, and targeted obligations for developers and deployers of automated systems. The August 11 draft rules flesh out these requirements, detailing what employers must tell rejected applicants and what records they must keep to prove compliance.[3][4]
At the core of the proposed rulebook is the definition of "Covered ADMT." The regulations target technology that processes personal data and uses computation to generate outputs—such as predictions, recommendations, or scores—that materially influence consequential decisions. In the workplace, this encompasses resume screeners, automated interview evaluators, and algorithmic performance management tools.[2]
The most immediate operational shift for employers involves adverse outcome disclosures. Under the draft rules, if an employer uses an AI tool to reject a job applicant or deny a promotion, the company must provide a plain-language explanation of the principal reasons the algorithm produced that result. The disclosure must detail how the tool used the individual's data and how it materially influenced the final decision.[1][3]
This requirement creates a strict vendor accountability chain. The rules stipulate that an AI deployer cannot comply with the disclosure mandate if it cannot explain the mechanism behind the algorithm's output. As a practical consequence, if a third-party software vendor relies on a "black box" model and cannot produce the principal reasons behind an individual score, employers will be legally barred from using that tool for consequential decisions in Colorado.[1][2]
To facilitate this transparency, the rules impose new duties on "midstream developers"—companies that integrate third-party AI models into their own human resources software and sell them to employers. These developers must obtain and pass along all technical documentation from upstream providers to the downstream deployers, ensuring that the companies actually making the hiring decisions have the information necessary to explain them.[3]
Beyond disclosure, the proposed rules operationalize the statutory right to "meaningful human review." Applicants who receive an adverse AI-assisted decision can demand that a human evaluate the outcome. The draft manual specifies that this review must be conducted by a qualified individual who is truly independent and has the authority to overturn the algorithmic recommendation.[1][3]
Applicants also gain the right to correct inaccurate personal data that the automated system relied upon. If an AI tool rejects a candidate based on a flawed data scrape or an incorrect assumption about their employment history, the employer must provide a mechanism for the applicant to dispute and rectify the underlying information before the decision becomes final.[2][4]
Applicants also gain the right to correct inaccurate personal data that the automated system relied upon.
To enforce these rights, the Attorney General's office is mandating rigorous recordkeeping. Employers must retain documentation of consequential decisions for at least three years. This includes logging the specific version identifiers of the automated tools used, maintaining changelogs of any updates to the algorithms, and documenting material changes to the company's risk mitigation strategies.
The August 11 filing is a consolidated rulemaking that also implements the Chatbot Safety Act, a companion law signed in July 2026. While the ADMT Act governs consequential decisions, the Chatbot Safety Act targets general-purpose, consumer-facing conversational AI services offered to the public.[2][3]
For employers, the intersection of these two laws requires careful mapping of their technology stack. Internal workforce-only chatbots deployed behind employee authentication portals generally fall outside the Chatbot Safety Act's scope. However, public-facing recruiting chatbots that interact with external job seekers may trigger the new regulatory requirements.[1][2]
Operators of covered conversational AI must implement commercially reasonable age-assurance methods to estimate user age, and the draft rules explicitly state that self-declaration alone is insufficient. Furthermore, operators must clearly disclose that users are interacting with artificial intelligence rather than a human, and they must maintain active suicide and self-harm response protocols.[2][3]
The draft rules leave one critical question unresolved, explicitly asking the public to help choose between two competing tests for determining when an AI tool is regulated at all. This definitional choice will dictate whether common, low-level screening software—such as basic keyword matching algorithms—lands inside or outside the regulatory perimeter.[1]
The Colorado Attorney General's office has opened a formal public comment period that runs through October 26, 2026. Regulators have prioritized comments submitted by October 5 for inclusion in any revisions presented at the formal rulemaking hearing.[1][7]
For multi-state employers and human resources vendors, the stakes extend far beyond Colorado's borders. Because the state is the first to draft a comprehensive operational manual for AI in hiring, these rules are widely expected to establish a de facto national standard. Software developers are likely to build their compliance architectures to satisfy Colorado's requirements, effectively exporting the state's transparency and human-review mandates to workplaces nationwide.[2]
Key points
- Colorado regulators released draft rules detailing how employers must handle AI in hiring, promotions, and compensation.
- Employers must provide rejected applicants with the principal reasons an AI tool produced an adverse decision.
- Applicants gain the right to demand an independent human review of AI-assisted outcomes and correct inaccurate data.
- The rules also implement the Chatbot Safety Act, requiring age assurance and self-harm protocols for public-facing conversational AI.
Why this matters
Colorado is the first state to draft a comprehensive operational manual for AI in hiring. Because software vendors will likely build their platforms to meet these strict transparency and human-review standards, the rules are expected to establish a de facto national baseline for how algorithms evaluate job applicants.
Key terms
- Automated Decision-Making Technology (ADMT)
- Technology that processes personal data to generate outputs like scores or predictions used to assist human decisions.
- Consequential Decision
- A decision that materially affects an individual's access to employment, education, housing, financial services, or essential government benefits.
- Midstream Developer
- A company that integrates third-party AI models into its own products and sells them to other businesses.
- Meaningful Human Review
- The process where a qualified human independently evaluates an AI-assisted adverse decision upon an applicant's request.
Frequently asked
When do the new Colorado AI rules take effect?
The Automated Decision-Making Technology Act and the Chatbot Safety Act both take effect on January 1, 2027.
Does this apply to all AI tools used by a business?
No. It specifically targets AI that materially influences consequential decisions, such as hiring, promotions, and compensation, as well as public-facing chatbots.
What happens if an AI vendor cannot explain how its tool makes decisions?
Under the proposed rules, employers cannot legally use an AI tool for consequential decisions in Colorado if the vendor cannot provide the principal reasons behind its outputs.
Are internal HR chatbots regulated by the Chatbot Safety Act?
Internal workforce-only deployments behind authentication generally fall outside the Chatbot Safety Act, though public-facing recruiting bots may be covered.
Sources
[1]Fisher PhillipsEmployer AdvocatesColorado Releases Proposed Rulebook for AI-Assisted Hiring and Employment Decisions: 8 Things Employers Need to Know
Read on Fisher Phillips →
[2]Seyfarth ShawAI DevelopersColorado's Proposed ADMT & Chatbot Safety Rules
Read on Seyfarth Shaw →
[3]Consumer Financial Services Law MonitorAI DevelopersColorado Proposes Rules for Automated Decision-Making Technology and Chatbot Safety
Read on Consumer Financial Services Law Monitor →
[4]Davis PolkAI DevelopersColorado Attorney General's Office invited public comment on draft rules for the ADMTA
Read on Davis Polk →
[5]McDermott Will & EmeryEmployer AdvocatesColorado has significantly narrowed what was set to become the nation's first comprehensive AI governance law
Read on McDermott Will & Emery →
[6]SkaddenEmployer AdvocatesColorado Repeals and Replaces Its AI Act
Read on Skadden →
[7]Colorado Attorney General's OfficeConsumer Privacy AdvocatesColorado Automated Decision-Making Technology and Chatbot Safety Acts: 2026 Rulemaking Comments
Read on Colorado Attorney General's Office →
Comments
Every angle. Every day.
Get careers work stories with full source coverage and perspective breakdowns delivered to your inbox.
