Colorado's AI Act Mandates Bias Audits for 'High-Risk' Employment Systems, Setting National Standard
Colorado has replaced its original AI legislation with a new transparency-focused framework, requiring employers to disclose AI use in hiring and provide human review for adverse decisions.
By Factlen Editorial Team
- Worker Advocates & Civil Rights Groups
- Argue that strict transparency, bias audits, and the right to human review are essential to prevent algorithms from scaling historical biases in hiring and compensation.
- Employer & Industry Coalitions
- Support the shift from heavy engineering audits to operational transparency, emphasizing the need for workable regulations that don't paralyze HR departments.
- AI Developers & Vendors
- Focused on the division of liability between the creators of AI models and the companies deploying them, advocating for clear safe harbors.
- State Regulators
- Aiming to balance consumer protection with technological innovation, utilizing exclusive Attorney General enforcement to guide corporate behavior.
What's not represented
- · Small Business HR Departments
- · Job Applicants Outside Protected Classes
Why this matters
As AI takes over resume screening and performance evaluations, the 'black box' of algorithmic hiring is finally being opened. Colorado's new law gives workers the right to know when AI is judging them and the power to appeal those decisions to a human, effectively creating a national standard for workplace AI rights.
Key points
- Colorado's revised AI Act (SB 26-189) takes effect January 1, 2027, replacing the state's original 2024 legislation.
- Employers must provide pre-use notices when automated decision-making technology influences hiring, promotion, or compensation.
- Job applicants and employees have the right to request 'meaningful human review' if an AI system contributes to an adverse career outcome.
- While formal annual impact assessments were removed, the requirement to explain AI decisions effectively forces companies to audit their tools for bias.
The era of the unregulated algorithmic human resources department is coming to a close. For the past five years, companies have rapidly integrated artificial intelligence into their hiring workflows, using automated tools to screen resumes, analyze video interviews, and predict candidate retention. While these tools offer unprecedented efficiency, they have also sparked widespread concern about embedded bias and opaque decision-making processes.[3]
Now, Colorado is setting a national benchmark for how businesses must govern these tools. The state has enacted a comprehensive legal framework that forces employers to pull back the curtain on their automated employment systems, ensuring that the drive for corporate efficiency does not come at the cost of algorithmic fairness.[1]
At the heart of Colorado's regulatory push is the concept of "Automated Decision-Making Technology" (ADMT). The law targets systems that materially influence "consequential decisions"—a legal threshold that explicitly includes hiring, compensation, promotions, and terminations. If an algorithm is a substantial factor in deciding whether a candidate gets an interview or an employee gets a raise, it falls squarely under the state's regulatory umbrella.[2]

The journey to this framework has been politically and legally turbulent. In May 2024, Colorado made headlines by passing Senate Bill 24-205, a sweeping piece of legislation modeled heavily on the European Union's AI Act. That original law mandated that companies implement formal risk management programs and conduct rigorous annual impact assessments—essentially mandatory bias audits—for any high-risk AI system.
However, the 2024 law faced intense pushback from the tech industry and business coalitions. Critics argued that the engineering-heavy requirements were unworkable for small and midsize businesses, threatening to stifle innovation and duplicate emerging federal standards. Facing the prospect of the law taking effect in 2026, state lawmakers convened a special working group to rethink the approach.[1]
The result was a dramatic legislative pivot. In May 2026, Governor Jared Polis signed Senate Bill 26-189, which officially repealed the original 2024 act before it ever went into force, replacing it with a more streamlined, operationally focused framework. Scheduled to take effect on January 1, 2027, the new law shifts the regulatory burden away from backend engineering audits and toward frontline consumer transparency.[2]

Under the revised statute, the core mandate for employers is disclosure. Companies must provide a clear "pre-use notice" to job applicants and employees whenever an AI tool will be used to evaluate them for a consequential decision. The goal is to eliminate the stealth use of algorithms in the hiring process, ensuring candidates know when a machine is reading their resume or analyzing their assessment.
Under the revised statute, the core mandate for employers is disclosure.
The transparency requirements extend beyond the initial screening. If a candidate is rejected or an employee is denied a promotion based on an ADMT recommendation, the employer is legally required to provide a "post-adverse-outcome disclosure." This notice must explain the role the AI system played in the decision, giving the affected individual visibility into the automated logic that shaped their career trajectory.[1][2]
Crucially, the law grants workers and applicants the right to appeal these algorithmic judgments. Consumers—which the statute explicitly defines to include Colorado-based employees and job seekers—can request a "meaningful human review" of any adverse decision materially influenced by AI. This ensures that a human manager retains ultimate override authority, preventing algorithms from having the final, uncontested say.
While the formal requirement for an annual "impact assessment" was stripped from the final bill, legal experts warn that the practical reality still demands rigorous bias auditing. Employers cannot accurately explain an adverse outcome or ensure meaningful human review if they do not fundamentally understand how their AI vendor's algorithm weights different variables. Consequently, companies are still being forced to audit their systems for algorithmic discrimination to avoid liability.[3]
A major compliance trap for organizations is the rise of "Shadow AI." This occurs when middle managers or HR staff independently adopt generative AI tools or unauthorized software to evaluate performance or write job descriptions without centralized IT approval. Because the law applies to the actual use of ADMT in consequential decisions, these unsanctioned tools can unknowingly trigger strict notice and disclosure obligations for the entire company.[3]
Colorado's framework does not exist in a vacuum; it is part of a rapidly solidifying national patchwork. New York City's Local Law 144 already strictly mandates independent bias audits for automated employment decision tools, and California is finalizing its own automated decision-making regulations under the CCPA.[3]

For multi-state employers, segmenting hiring processes by geographic borders is becoming a logistical impossibility. Instead of building separate HR workflows for Colorado, New York, and California, Fortune 500 companies are increasingly adopting the strictest state requirements as their baseline national standard.[1]
The Colorado Attorney General's office is currently drafting the specific administrative rules that will govern the law's implementation, with final guidelines expected before the January 2027 effective date. These rules will clarify exactly what constitutes "meaningful human review" and how detailed the adverse-outcome explanations must be.[2]
As the 2027 deadline approaches, the message to the corporate world is unambiguous: the black box of AI hiring is being forced open. By shifting the focus to transparency, accountability, and human oversight, Colorado is ensuring that the future of work remains fundamentally human, even as it becomes increasingly automated.[3]
How we got here
May 2024
Governor Polis signs SB 24-205, the nation's first comprehensive state-level AI regulation, modeled on the EU AI Act.
August 2025
Following intense industry pushback, a special legislative session delays the original law's effective date to June 2026.
May 2026
Colorado passes SB 26-189, repealing the original act and replacing it with a transparency-focused framework.
January 2027
The new automated decision-making technology framework officially takes effect for employers.
Viewpoints in depth
Worker Advocates' View
Focus on the necessity of the appeals process and human review.
Labor advocates view the shift from mandatory impact assessments to operational transparency as a compromise, but they celebrate the explicit inclusion of employees as protected 'consumers.' They argue that without the right to 'meaningful human review,' algorithms would inevitably scale historical biases in hiring and compensation, locking marginalized groups out of economic opportunities.
Employer Coalitions' View
Focus on the relief of SB 26-189 replacing the more burdensome SB 24-205.
Business groups argue that the original law's EU-style risk management programs were incompatible with US business practices and would have paralyzed small business HR departments. They view the new transparency model as a more practical way to achieve fairness, allowing companies to innovate with AI while maintaining clear accountability through disclosure and human oversight.
AI Vendors' View
Focus on the documentation burden and the division of liability.
Developers of AI hiring tools are navigating a shifting landscape where they must provide deployers (employers) with enough technical transparency to fulfill their legal obligations. Vendors are advocating for clear safe harbors, arguing they should not be held liable if an employer misuses a compliant AI tool or modifies it in a way that introduces algorithmic discrimination.
What we don't know
- How the Colorado Attorney General will specifically define the technical requirements for 'meaningful human review' in the upcoming rulemaking.
- Whether the federal government will advance legislation to preempt state-level AI laws, potentially overriding Colorado's framework.
- How strictly regulators will penalize 'Shadow AI' usage where individual employees adopt tools without corporate knowledge.
Key terms
- Automated Decision-Making Technology (ADMT)
- Any computational process, including AI, that makes or materially influences a consequential decision.
- Consequential Decision
- A decision that has a material legal or significant effect on a person's life, such as hiring, compensation, or housing.
- Algorithmic Discrimination
- Unlawful differential treatment or impact that disfavors individuals based on protected characteristics like race, age, or disability, caused by an AI system.
- Meaningful Human Review
- The process where a human evaluator reviews an AI-driven decision, possessing the authority and training to alter or reverse the outcome.
- Shadow AI
- The use of artificial intelligence systems or tools within an organization without explicit approval or oversight from the IT or compliance departments.
Frequently asked
When does the new Colorado AI law take effect?
Senate Bill 26-189 takes effect on January 1, 2027, replacing the original 2024 legislation before it went into force.
Does this law only apply to companies headquartered in Colorado?
No. It applies to any company using covered AI systems to make consequential employment decisions about Colorado residents, regardless of where the company is based.
What is 'Shadow AI' and why is it a risk?
Shadow AI refers to employees or managers using unauthorized AI tools (like public generative AI) for work tasks. If used for hiring or performance reviews, these tools can unknowingly trigger the law's strict disclosure requirements.
Can candidates sue employers for violating this law?
No. The law does not include a private right of action. It is enforced exclusively by the Colorado Attorney General, who treats violations as deceptive trade practices.
Sources
[1]ForbesEmployer & Industry Coalitions
Japanese Wine Is Having A Moment. Here's What You Need To Know
Read on Forbes →[2]Blank Rome LLPState Regulators
Colorado Enacts SB 189, Replacing 2024 AI Act
Read on Blank Rome LLP →[3]Factlen Editorial TeamWorker Advocates & Civil Rights Groups
Synthesis by Factlen editorial team
Read on Factlen Editorial Team →
Every angle. Every day.
Get careers work stories with full source coverage and perspective breakdowns delivered to your inbox.



