The End of AI Laissez-Faire: How Colorado's New Automated Decision-Making Law Rewrites U.S. Tech Governance
Colorado has repealed its landmark 2024 AI Act, replacing it with a narrower but highly consequential law focused on automated decision-making technology. The new framework shifts the burden from broad risk assessments to decision-by-decision transparency, setting a new standard for how U.S. employers and tech vendors share liability for algorithmic bias.
By Lila Morgan
- Enterprise Deployers
- Focus on the operational burden of explaining individual decisions and managing human appeals.
- AI Developers
- Concerned about shared liability mandates and the inability to contractually indemnify themselves against deployer misuse.
- State Regulators
- Prioritize actionable consumer transparency and direct accountability over abstract algorithmic audits.
- Compliance Advisors
- Emphasize the need for robust data governance and clear documentation to navigate the new shared liability framework.
Perspectives this story doesn't cover
- Individual consumers who have been denied opportunities by AI systems
- Federal policymakers seeking to preempt state-level AI regulations
Colorado was the first state in the nation to pass a comprehensive artificial intelligence law in 2024, setting a high-water mark for tech regulation in the United States. The legislation was heralded as a necessary check on the rapid deployment of algorithmic systems in daily life. But in a dramatic legislative pivot, the state has scrapped the landmark framework entirely before it even took effect, opting instead for a more targeted approach to algorithmic accountability that shifts the focus from the technology itself to the decisions it makes.[1][2]
In May 2026, Governor Jared Polis signed Senate Bill 26-189, known as the Automated Decision-Making Technology (ADMT) Act. The new legislation officially repeals the 2024 Colorado AI Act and replaces it with a fundamentally different approach to tech governance. By narrowing the scope of what is regulated and changing how compliance is measured, the ADMT Act sets a new, pragmatic standard for how the United States will regulate algorithmic systems in the workplace and the broader economy.[1][4]
The original 2024 law was heavily modeled on the European Union's broad, system-level AI Act. It required massive upfront compliance from tech companies, including mandatory algorithmic impact assessments, extensive risk-management frameworks, and a freestanding duty of care to prevent algorithmic discrimination in any 'high-risk' AI system. The goal was to force companies to audit their tools for bias before they were ever deployed in the real world, creating a proactive shield against discriminatory outcomes in housing, employment, and finance.[1]
But that proactive approach met a buzzsaw of opposition. Tech companies and business groups argued the requirements were unworkable, overly broad, and would stifle innovation by placing disproportionate burdens on smaller developers. The tension boiled over in April 2026, when Elon Musk's xAI sued in federal court to block the law on constitutional grounds. Crucially, the U.S. Department of Justice intervened on xAI's side, marking an unprecedented federal effort under the Trump administration to preempt state-level AI rules and force a unified national framework.[1][3]
Facing a protracted legal battle and an industry revolt, Colorado lawmakers changed tactics to salvage their regulatory ambitions. The new ADMT Act abandons the attempt to regulate 'artificial intelligence' as a broad, abstract category, which had proven nearly impossible to define without capturing benign software. Instead, the law focuses narrowly on specific use cases where automated software materially influences a 'consequential decision.' This shift acknowledges that the danger lies not in the underlying math of a large language model, but in how that model is applied to human lives.[2]
Under the new framework, a consequential decision is defined as any determination that materially affects a consumer's access to essential opportunities. This explicitly includes decisions regarding employment, education admissions, housing, lending, insurance, healthcare, or essential government services. By drawing these boundaries, the law ensures that routine technologies—like spam filters, basic spreadsheets, web caching, and anti-malware software—are explicitly excluded from the regulatory burden, provided they do not use machine learning to make these high-stakes determinations about individuals.[4]
The ADMT Act shifts the regulatory burden from proactive system audits to reactive, decision-by-decision accountability. Legal analysts note that the law operates more like the 1970 Fair Credit Reporting Act (FCRA) than a traditional tech regulation, prioritizing transparency over architectural mandates. Instead of forcing developers to prove a system is perfectly unbiased in a vacuum through complex impact assessments, companies must now prove they can explain, justify, and correct its specific outputs when applied to real people.[1]
The ADMT Act shifts the regulatory burden from proactive system audits to reactive, decision-by-decision accountability.
This creates a massive operational shift for businesses that rely on automated systems. If an employer uses an algorithmic tool to screen resumes and a candidate is rejected, the employer must provide a plain-language explanation of the tool's role in that adverse outcome within 30 days. This requirement forces companies to deeply understand the software they purchase, effectively ending the era where human resources departments could blindly trust a vendor's 'black box' algorithm to sort applicants without understanding the underlying criteria.
Consumers are granted sweeping new rights under the transparency regime. Following an adverse outcome, they can access the specific data the AI used to evaluate them, demand corrections to factual inaccuracies, and, most importantly, request a human review of the automated decision. This ensures that no individual is permanently locked out of a job, a housing lease, or a financial loan solely by the unappealable judgment of a machine, restoring a critical layer of human oversight to automated bureaucracies.
As compliance advisors point out, the legal and operational risk for employers hasn't decreased under the new law—it has simply relocated downstream. Companies must now build the internal infrastructure to explain and defend every single AI-assisted rejection or denial on a case-by-case basis. This means establishing dedicated teams to handle consumer data access requests, manage the strict 30-day explanation windows, and conduct the mandatory human reviews whenever an applicant or customer appeals an algorithm's choice.
The law also tackles the thorny issue of shared liability between the tech vendors who build the AI systems—known as developers—and the companies that use them, known as deployers. Previously, developers often used complex indemnification contracts to shield themselves from liability if their tools produced discriminatory outcomes in the real world, leaving the deploying employer or bank to face the legal consequences alone. The ADMT Act fundamentally rewrites this dynamic to ensure accountability is shared across the supply chain.
Under SB 26-189, any contract clauses that attempt to shield a party from liability for its own discriminatory acts are explicitly voided and rendered unenforceable. If an employer uses an AI tool 'off-label' or ignores the developer's clear guidelines, the employer bears the full legal risk for any resulting bias. But if the tool discriminates while being used exactly as the developer intended, documented, and marketed, the developer shares the blame and cannot contractually indemnify themselves against the civil rights violations.[3]
To facilitate this shared accountability, developers are now legally required to provide deployers with exhaustive technical documentation before a system is sold or licensed. This documentation must outline the system's known limitations, provide high-level summaries of the training data used, and deliver strict instructions for appropriate use and monitoring. In the event of a discrimination claim, this documentation will serve as the critical dividing line for liability, determining whether the vendor built a biased tool or the employer misused a neutral one.[4]
The Colorado Attorney General's office has already opened the pre-rulemaking process, gathering public comment to shape the specific enforcement mechanisms ahead of the law's January 1, 2027 effective date. Regulators are particularly focused on defining the practical boundaries of the law, such as what constitutes a 'commercially reasonable' human review and exactly how detailed the post-decision explanations must be. While the law does not include a private right of action, the Attorney General has exclusive authority to enforce its provisions and levy penalties.
While federal litigation over state AI laws continues to cast a shadow, Colorado's pivot provides a pragmatic blueprint for the rest of the country. By focusing on direct consumer transparency and human appeals rather than abstract algorithmic audits, the ADMT Act ensures that the era of the unquestioned 'black box' decision is coming to an end. For the enterprise software industry, the message is clear: if an algorithm is going to make a decision about a human life, a human must be ready to explain it.[3]
The stakes
As the federal government stalls on AI regulation, state-level laws are becoming the de facto national standard. Colorado's pivot means any company using AI to hire, lend, or provide housing must now be prepared to explain and defend every individual automated decision to consumers, fundamentally changing how enterprise software is built and bought.
The essentials
- Colorado has repealed its 2024 AI Act, replacing it with the narrower Automated Decision-Making Technology (ADMT) Act.
- The new law abandons broad algorithmic impact assessments in favor of decision-by-decision consumer transparency.
- Consumers denied opportunities by AI tools now have the right to demand a human review of the decision.
- The law voids contracts that attempt to shield developers or deployers from liability for discriminatory acts.
- The ADMT Act is scheduled to take effect on January 1, 2027, pending ongoing federal litigation.
Perspectives explored
Enterprise Deployers
Employers and service providers face a massive operational shift toward decision-by-decision accountability.
For companies that use AI to screen resumes or approve loans, the new law relocates regulatory risk downstream. Instead of relying on upfront system audits, deployers must now be prepared to explain and defend every single AI-assisted rejection. This requires building new internal infrastructure to handle consumer data access requests, manage 30-day explanation windows, and facilitate human reviews of adverse outcomes.
AI Developers
Tech vendors must navigate strict documentation requirements and a new shared liability framework.
Developers can no longer use contracts to completely shield themselves from liability if their tools produce discriminatory outcomes. The law voids indemnification clauses for discriminatory acts, meaning developers are on the hook if their system is used exactly as intended but still exhibits bias. To protect themselves, vendors must provide exhaustive technical documentation detailing the known limitations, training data summaries, and strict instructions for appropriate use.
State Regulators
Officials prioritize actionable consumer transparency over abstract algorithmic compliance.
Faced with intense industry pushback and federal lawsuits over the original 2024 law, Colorado regulators pivoted to a more pragmatic approach. By modeling the ADMT Act on the Fair Credit Reporting Act, they aim to give consumers direct, actionable rights—like the ability to correct inaccurate data and demand human review—rather than relying on opaque, system-level risk management programs that are difficult to enforce.
Sources
[1]Goodwin LawAI DevelopersColorado Enacts Law Repealing and Replacing Landmark Colorado AI Act
Read on Goodwin Law →
[2]DLA PiperCompliance AdvisorsColorado repeals and replaces AI Act with narrower ADMT law
Read on DLA Piper →
[3]Factlen Editorial TeamState RegulatorsSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
[4]Mayer BrownCompliance AdvisorsColorado Enacts New ADMT Law Replacing Colorado AI Act
Read on Mayer Brown →
Comments
More in Content Types
See all →Network Theory
How the Random Surfer Model and Eigenvector Centrality Actually Rank Web Pages
6 sources
Economic Metrics
Measuring the Tails: How the Palma Ratio's Top 10% Focus Compares to the Gini Coefficient and Theil Index
7 sources
Intellectual Property
Function, Source, and Expression: How Intellectual Property Law Separates Patents, Trademarks, and Copyrights
5 sources
Epidemiology
How the Nine Bradford Hill Criteria Separate Causation from Correlation in Observational Data
6 sources
Every angle. Every day.
Get Content Types stories with full source coverage and perspective breakdowns delivered to your inbox.




