Colorado Repeals Landmark AI Act, Scrapping Mandatory Risk Assessments and Pre-Use Impact Reports
Colorado has abruptly repealed the nation's first comprehensive AI regulation, replacing its proactive risk-management mandates with a lighter-touch, disclosure-based framework.
By Factlen Editorial Team
- AI Developers & Industry Groups
- Argue that proactive risk assessments were unworkable and stifled innovation, favoring the new disclosure-based model.
- Corporate Deployers & Employers
- Face a new burden of decision-by-decision accountability, shifting legal risk from the software creators to the businesses using the tools.
- Federal Policymakers
- View state-level risk regimes as a threat to a unified national AI strategy, actively intervening to preempt fragmented laws.
- Consumer Protection Advocates
- View the repeal of the duty of care and algorithmic discrimination bans as a significant loss for civil rights and marginalized groups.
What's not represented
- · Marginalized Communities
- · Small Business Deployers
Why this matters
Colorado's abrupt reversal signals the end of proactive, EU-style algorithmic auditing in the US, replacing it with a reactive, disclosure-based model. For businesses, this shifts the legal burden downstream: employers and lenders—not just AI developers—must now be prepared to explain and defend every individual AI-assisted rejection or denial.
Key points
- Colorado repealed its landmark 2024 AI Act weeks before it was set to take effect, replacing it with the Automated Decision-Making Technology Act.
- The new law eliminates mandatory risk management programs, impact assessments, and the explicit duty of care to avoid algorithmic discrimination.
- The regulatory focus shifts to transparency, requiring companies to notify consumers when AI materially influences consequential decisions.
- Deployers of AI systems must provide explanations for adverse outcomes within 30 days and offer a pathway for meaningful human review.
- The repeal was driven by intense industry opposition, a federal lawsuit by x.AI, and intervention by the US Department of Justice.
- The shift relocates legal risk downstream, forcing employers and lenders to defend individual AI-assisted decisions rather than relying on system-level compliance.
Colorado made history in May 2024 by passing the nation's first comprehensive artificial intelligence regulation, setting a high-water mark for state-level tech governance. But mere weeks before the landmark Colorado Artificial Intelligence Act was set to take effect, the state abruptly dismantled its own creation. On May 14, 2026, Governor Jared Polis signed Senate Bill 26-189, repealing the original framework and replacing it with a significantly lighter-touch regime. The reversal marks a watershed moment in US technology policy, signaling the immense legal and political pressure state legislatures face when attempting to regulate frontier AI systems.[1]
The repealed legislation, known as SB 24-205, was heavily inspired by the European Union's AI Act. It was designed as a proactive, risk-based regime aimed at preventing algorithmic discrimination before it could harm consumers. The law targeted "high-risk" AI systems—defined as any machine-based system that served as a substantial factor in making consequential decisions. These consequential areas included employment, housing, healthcare, insurance, lending, and essential government services, casting a wide net over how businesses integrated machine learning into their daily operations.[7]
Under the original framework, the compliance burden was heavy and front-loaded. Developers and deployers of these high-risk systems were bound by a strict legal duty of care to avoid algorithmic discrimination. To prove they were meeting this standard, companies were required to establish formal risk management programs, conduct rigorous annual impact assessments, and maintain extensive documentation regarding their training data and system architecture. If a system demonstrated a risk of bias, companies were mandated to report those findings directly to the Colorado Attorney General.[3][5]

Almost immediately after its passage, the law faced intense and sustained opposition from the technology sector. Industry groups and AI developers argued that the requirements were technically unworkable and legally ambiguous. Critics warned that the broad definition of "high-risk" would capture routine software functions, stifling innovation and placing a disproportionate, crushing compliance burden on smaller startups that lacked the resources to conduct continuous algorithmic audits.[1][5]
The simmering industry frustration reached a boiling point in April 2026, when x.AI, the artificial intelligence company founded by Elon Musk, filed a federal lawsuit seeking to enjoin the law's enforcement. The lawsuit argued that the Colorado AI Act's sweeping mandates violated constitutional protections and overstepped state authority by attempting to regulate interstate commerce and dictate the fundamental architecture of algorithmic models.[1][5]
The state-level retreat was ultimately forced by an unprecedented federal intervention. In a highly unusual move, the US Department of Justice intervened in the x.AI lawsuit to challenge the Colorado law alongside the private developer. This federal action aligned with a December 2025 executive order from the Trump administration, which established an AI Litigation Task Force specifically charged with identifying and challenging state-level AI regulations that threatened to create a fragmented, state-by-state compliance patchwork.[1][7]
Facing a costly, multi-front legal battle against both a major AI developer and the federal government, Colorado lawmakers opted to surrender the risk-based regime. The Colorado Attorney General agreed to suspend enforcement of the original act pending a legislative rewrite. Within a matter of weeks, the state legislature drafted, passed, and sent the replacement bill, the Automated Decision-Making Technology Act (ADMT Act), to the governor's desk, effectively erasing two years of regulatory groundwork.[1][5]

Facing a costly, multi-front legal battle against both a major AI developer and the federal government, Colorado lawmakers opted to surrender the risk-based regime.
Taking effect on January 1, 2027, the new ADMT Act fundamentally alters the philosophy of AI regulation in the state. The revised statute abandons the concept of algorithmic discrimination entirely. It strips away the proactive mandates, eliminating the requirements for formal risk management programs, annual impact assessments, and the explicit duty of care. In their place, the law establishes a reactive, disclosure-based model focused on consumer transparency rather than algorithmic auditing.[3]
The scope of the new law is also significantly narrower. It replaces the broad "high-risk AI system" classification with a more targeted focus on "Automated Decision-Making Technology" (ADMT). Under the new definitions, ADMT only falls under regulatory scrutiny if it processes personal data and is used to "materially influence" a consequential decision. This subtle shift in language excludes routine technologies, internal research models, and low-stakes use cases from the compliance perimeter, offering a major concession to enterprise software developers.[2][5]
For consumers, the new framework trades systemic algorithmic safety for individualized transparency rights. Companies deploying ADMT must provide clear, conspicuous disclosures to consumers before the technology is used to make a consequential decision. If the AI system contributes to an "adverse outcome"—such as denying a loan, rejecting a job application, or reducing healthcare benefits—the company must provide a detailed explanation of the decision within 30 days.[3]
Crucially, the ADMT Act grants consumers the right to request a meaningful human review of any adverse outcome materially influenced by AI. Consumers also gain the right to access and correct inaccurate personal data that the automated system relied upon to make its determination. However, unlike earlier drafts of privacy legislation in other states, the Colorado law does not grant consumers a blanket right to opt out of the use of automated decision-making entirely.[2][6]

While developers of foundation models may celebrate the reduced compliance burden, the new law fundamentally shifts legal risk downstream to the companies actively deploying the technology. Under the repealed law, employers and lenders could theoretically rely on system-level compliance and developer-provided impact assessments to shield themselves from liability. Now, the ADMT Act enforces decision-by-decision accountability. Deploying companies must be prepared to consistently explain and defend the specific inputs and constraints that led to every individual AI-assisted rejection.[4][6]
To enforce this new dynamic, the ADMT Act strictly regulates how liability is shared between the creators of AI models and the businesses that use them. The law explicitly voids contractual clauses that attempt to indemnify a party for its own violations. Developers are only held liable to the extent that the ADMT was used exactly as intended, documented, and marketed. If a hospital or bank uses an AI tool in a novel way that the developer did not authorize, the deploying organization bears the full legal responsibility for any resulting harm.[2][3]
Enforcement of the new regime remains exclusively in the hands of the Colorado Attorney General. The legislature explicitly declined to include a private right of action, meaning consumers cannot directly sue companies for violating the ADMT Act. Instead, the Attorney General's office will oversee compliance, offering companies a 60-day notice-and-cure period to rectify transparency failures or documentation errors before imposing financial penalties. This cure period will remain in effect until January 2030, giving the industry a multi-year runway to adapt.[4]

Colorado's rapid reversal effectively ends the prospect of a fragmented, EU-style risk management regime taking root across individual US states. By aligning with California's disclosure-centric approach, Colorado has helped solidify a distinctly American model of AI governance—one that prioritizes post-incident transparency and individual recourse over proactive algorithmic auditing. As the 2027 effective date approaches, companies operating nationwide now have a clearer, albeit less stringent, baseline for integrating automated decision-making into the economy.[7]
How we got here
May 2024
Colorado passes the original AI Act (SB 24-205), becoming the first state to enact comprehensive AI regulation.
December 2025
The federal government issues an Executive Order establishing an AI Litigation Task Force to challenge conflicting state laws.
April 2026
AI developer x.AI files a federal lawsuit to enjoin the enforcement of the Colorado AI Act.
Early May 2026
The US Department of Justice intervenes in the lawsuit, joining the challenge against the state law.
May 14, 2026
Governor Jared Polis signs SB 26-189, officially repealing the original act and replacing it with a disclosure-based framework.
January 1, 2027
The new Automated Decision-Making Technology Act is scheduled to take effect.
Viewpoints in depth
AI Developers' View
The original law was technically unworkable and threatened to halt state-level innovation.
Industry groups and major developers like x.AI argued that the repealed law's broad definition of "high-risk" systems would have captured routine software functions. They contended that requiring continuous algorithmic audits and impact assessments placed an impossible compliance burden on smaller startups, effectively locking them out of the market. The new transparency-focused model is viewed as a pragmatic compromise that allows innovation to continue while keeping consumers informed.
Corporate Deployers' View
The new law shifts the legal and operational risk downstream to the businesses using AI.
While developers celebrate the repeal, employment and legal analysts warn that the new framework relocates the risk rather than eliminating it. Employers, lenders, and healthcare providers can no longer rely on upfront system compliance or developer indemnification. Instead, they face decision-by-decision accountability, requiring them to build internal infrastructure capable of explaining exactly why an AI system rejected a specific applicant or denied a specific claim within a strict 30-day window.
Federal Policymakers' View
State-level AI regulations threaten to create a fragmented, unmanageable national compliance landscape.
The intervention by the US Department of Justice highlights a growing federal intolerance for state-by-state AI governance. Driven by the December 2025 Executive Order, federal authorities view laws like the original Colorado AI Act as conflicting with a unified national strategy. By challenging the law in federal court, the administration signaled its intent to aggressively preempt state legislatures from imposing substantive risk-management regimes that could complicate interstate commerce and national tech dominance.
What we don't know
- How the Colorado Attorney General will define 'meaningful human review' in practice during the upcoming rulemaking process.
- Whether the federal AI Litigation Task Force will target other state-level AI regulations, such as those in California or Illinois.
- How smaller businesses will build the technical infrastructure required to provide 30-day explanations for complex algorithmic decisions.
Key terms
- Automated Decision-Making Technology (ADMT)
- A technology that processes personal data and uses computation to generate outputs that materially influence consequential decisions about individuals.
- Consequential Decision
- A determination that significantly affects a consumer's access to essential services like employment, housing, healthcare, lending, or education.
- Adverse Outcome
- A situation where an AI system's output results in a consumer being denied a service, opportunity, or favorable terms.
- Meaningful Human Review
- A process where a human evaluator reviews the inputs and constraints of an automated decision, providing an opportunity to correct errors or override the AI's determination.
Frequently asked
When does the new Colorado AI law take effect?
The Automated Decision-Making Technology Act (SB 26-189) takes effect on January 1, 2027.
Does the new law ban algorithmic discrimination?
No. The new law explicitly removes the "duty of care" to avoid algorithmic discrimination that was present in the repealed legislation, focusing instead on transparency and disclosure.
Can consumers opt out of AI decision-making in Colorado?
No. Unlike some privacy frameworks, the new law does not grant consumers a blanket right to opt out of automated systems, though it does guarantee a right to meaningful human review of adverse outcomes.
Who enforces the new AI regulations?
Enforcement authority rests exclusively with the Colorado Attorney General. There is no private right of action, meaning individual consumers cannot sue companies for violations.
Sources
[1]SkaddenAI Developers & Industry Groups
Colorado Repeals and Replaces Its AI Act
Read on Skadden →[2]Wilson SonsiniFederal Policymakers
Colorado Governor Signs SB 189, Repealing and Replacing the Colorado AI Act
Read on Wilson Sonsini →[3]FinneganConsumer Protection Advocates
Colorado Replaces Landmark AI Act: An Overview of the New SB 26-189 Framework
Read on Finnegan →[4]Jackson LewisCorporate Deployers & Employers
Colorado Enacts Artificial Intelligence Legislation Affecting AI Systems Developers, Deployers
Read on Jackson Lewis →[5]Davis Wright TremaineAI Developers & Industry Groups
Colorado Repeals and Replaces AI Act Amid Industry Pushback
Read on Davis Wright Tremaine →[6]Colorado Attorney General's OfficeConsumer Protection Advocates
Automated Decision-Making Technology Act
Read on Colorado Attorney General's Office →[7]Carpe Datum LawFederal Policymakers
Colorado Repeals AI Act, Pivots to Disclosure Model
Read on Carpe Datum Law →
More in ai
See all 5 stories →AI Regulation
How 42 State Attorneys General Are Using Consumer Law to Regulate OpenAI
6 sources
Silicon Sovereignty
$1 Trillion AI Chip Selloff Follows Wave of Custom Silicon Shipments, Reshaping Compute Market
7 sources
Macroeconomics
Federal Reserve Raises US Growth Forecast, Citing Surging AI Infrastructure Investment
4 sources
Every angle. Every day.
Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.










