Factlen ExplainerTech GovernancePolicy ShiftJul 12, 2026, 1:50 PM· 7 min read

The End of AI Laissez-Faire: How Colorado's New Automated Decision-Making Law Rewrites U.S. Tech Governance

Colorado has repealed its landmark 2024 AI Act, replacing it with a narrower but highly consequential law focused on automated decision-making technology. The new framework shifts the burden from broad risk assessments to decision-by-decision transparency, setting a new standard for how U.S. employers and tech vendors share liability for algorithmic bias.

By Factlen Editorial Team

Enterprise Deployers 30%AI Developers 25%State Regulators 25%Compliance Advisors 20%
Enterprise Deployers
Focus on the operational burden of explaining individual decisions and managing human appeals.
AI Developers
Concerned about shared liability mandates and the inability to contractually indemnify themselves against deployer misuse.
State Regulators
Prioritize actionable consumer transparency and direct accountability over abstract algorithmic audits.
Compliance Advisors
Emphasize the need for robust data governance and clear documentation to navigate the new shared liability framework.

What's not represented

  • · Individual consumers who have been denied opportunities by AI systems
  • · Federal policymakers seeking to preempt state-level AI regulations

Why this matters

As the federal government stalls on AI regulation, state-level laws are becoming the de facto national standard. Colorado's pivot means any company using AI to hire, lend, or provide housing must now be prepared to explain and defend every individual automated decision to consumers, fundamentally changing how enterprise software is built and bought.

Key points

  • Colorado has repealed its 2024 AI Act, replacing it with the narrower Automated Decision-Making Technology (ADMT) Act.
  • The new law abandons broad algorithmic impact assessments in favor of decision-by-decision consumer transparency.
  • Consumers denied opportunities by AI tools now have the right to demand a human review of the decision.
  • The law voids contracts that attempt to shield developers or deployers from liability for discriminatory acts.
  • The ADMT Act is scheduled to take effect on January 1, 2027, pending ongoing federal litigation.
Jan. 1, 2027
Effective date of the ADMT Act
30 days
Window to explain an adverse decision
3 years
Record retention requirement

Colorado was the first state in the nation to pass a comprehensive artificial intelligence law in 2024, setting a high-water mark for tech regulation in the United States. The legislation was heralded as a necessary check on the rapid deployment of algorithmic systems in daily life. But in a dramatic legislative pivot, the state has scrapped the landmark framework entirely before it even took effect, opting instead for a more targeted approach to algorithmic accountability that shifts the focus from the technology itself to the decisions it makes.[1][2]

In May 2026, Governor Jared Polis signed Senate Bill 26-189, known as the Automated Decision-Making Technology (ADMT) Act. The new legislation officially repeals the 2024 Colorado AI Act and replaces it with a fundamentally different approach to tech governance. By narrowing the scope of what is regulated and changing how compliance is measured, the ADMT Act sets a new, pragmatic standard for how the United States will regulate algorithmic systems in the workplace and the broader economy.[1][4]

The original 2024 law was heavily modeled on the European Union's broad, system-level AI Act. It required massive upfront compliance from tech companies, including mandatory algorithmic impact assessments, extensive risk-management frameworks, and a freestanding duty of care to prevent algorithmic discrimination in any 'high-risk' AI system. The goal was to force companies to audit their tools for bias before they were ever deployed in the real world, creating a proactive shield against discriminatory outcomes in housing, employment, and finance.[1]

But that proactive approach met a buzzsaw of opposition. Tech companies and business groups argued the requirements were unworkable, overly broad, and would stifle innovation by placing disproportionate burdens on smaller developers. The tension boiled over in April 2026, when Elon Musk's xAI sued in federal court to block the law on constitutional grounds. Crucially, the U.S. Department of Justice intervened on xAI's side, marking an unprecedented federal effort under the Trump administration to preempt state-level AI rules and force a unified national framework.[1][3]

The 2026 ADMT Act shifts the regulatory burden from proactive system audits to reactive, decision-by-decision accountability.
The 2026 ADMT Act shifts the regulatory burden from proactive system audits to reactive, decision-by-decision accountability.

Facing a protracted legal battle and an industry revolt, Colorado lawmakers changed tactics to salvage their regulatory ambitions. The new ADMT Act abandons the attempt to regulate 'artificial intelligence' as a broad, abstract category, which had proven nearly impossible to define without capturing benign software. Instead, the law focuses narrowly on specific use cases where automated software materially influences a 'consequential decision.' This shift acknowledges that the danger lies not in the underlying math of a large language model, but in how that model is applied to human lives.[2]

Under the new framework, a consequential decision is defined as any determination that materially affects a consumer's access to essential opportunities. This explicitly includes decisions regarding employment, education admissions, housing, lending, insurance, healthcare, or essential government services. By drawing these boundaries, the law ensures that routine technologies—like spam filters, basic spreadsheets, web caching, and anti-malware software—are explicitly excluded from the regulatory burden, provided they do not use machine learning to make these high-stakes determinations about individuals.[4]

The ADMT Act shifts the regulatory burden from proactive system audits to reactive, decision-by-decision accountability. Legal analysts note that the law operates more like the 1970 Fair Credit Reporting Act (FCRA) than a traditional tech regulation, prioritizing transparency over architectural mandates. Instead of forcing developers to prove a system is perfectly unbiased in a vacuum through complex impact assessments, companies must now prove they can explain, justify, and correct its specific outputs when applied to real people.[1]

The ADMT Act shifts the regulatory burden from proactive system audits to reactive, decision-by-decision accountability.

This creates a massive operational shift for businesses that rely on automated systems. If an employer uses an algorithmic tool to screen resumes and a candidate is rejected, the employer must provide a plain-language explanation of the tool's role in that adverse outcome within 30 days. This requirement forces companies to deeply understand the software they purchase, effectively ending the era where human resources departments could blindly trust a vendor's 'black box' algorithm to sort applicants without understanding the underlying criteria.

Consumers are granted sweeping new rights under the transparency regime. Following an adverse outcome, they can access the specific data the AI used to evaluate them, demand corrections to factual inaccuracies, and, most importantly, request a human review of the automated decision. This ensures that no individual is permanently locked out of a job, a housing lease, or a financial loan solely by the unappealable judgment of a machine, restoring a critical layer of human oversight to automated bureaucracies.

Under the new law, consumers denied a job or loan by an automated system have the right to request a human review.
Under the new law, consumers denied a job or loan by an automated system have the right to request a human review.

As compliance advisors point out, the legal and operational risk for employers hasn't decreased under the new law—it has simply relocated downstream. Companies must now build the internal infrastructure to explain and defend every single AI-assisted rejection or denial on a case-by-case basis. This means establishing dedicated teams to handle consumer data access requests, manage the strict 30-day explanation windows, and conduct the mandatory human reviews whenever an applicant or customer appeals an algorithm's choice.

The law also tackles the thorny issue of shared liability between the tech vendors who build the AI systems—known as developers—and the companies that use them, known as deployers. Previously, developers often used complex indemnification contracts to shield themselves from liability if their tools produced discriminatory outcomes in the real world, leaving the deploying employer or bank to face the legal consequences alone. The ADMT Act fundamentally rewrites this dynamic to ensure accountability is shared across the supply chain.

Under SB 26-189, any contract clauses that attempt to shield a party from liability for its own discriminatory acts are explicitly voided and rendered unenforceable. If an employer uses an AI tool 'off-label' or ignores the developer's clear guidelines, the employer bears the full legal risk for any resulting bias. But if the tool discriminates while being used exactly as the developer intended, documented, and marketed, the developer shares the blame and cannot contractually indemnify themselves against the civil rights violations.[3]

To facilitate this shared accountability, developers are now legally required to provide deployers with exhaustive technical documentation before a system is sold or licensed. This documentation must outline the system's known limitations, provide high-level summaries of the training data used, and deliver strict instructions for appropriate use and monitoring. In the event of a discrimination claim, this documentation will serve as the critical dividing line for liability, determining whether the vendor built a biased tool or the employer misused a neutral one.[4]

The rapid evolution of Colorado's tech governance framework.
The rapid evolution of Colorado's tech governance framework.

The Colorado Attorney General's office has already opened the pre-rulemaking process, gathering public comment to shape the specific enforcement mechanisms ahead of the law's January 1, 2027 effective date. Regulators are particularly focused on defining the practical boundaries of the law, such as what constitutes a 'commercially reasonable' human review and exactly how detailed the post-decision explanations must be. While the law does not include a private right of action, the Attorney General has exclusive authority to enforce its provisions and levy penalties.

While federal litigation over state AI laws continues to cast a shadow, Colorado's pivot provides a pragmatic blueprint for the rest of the country. By focusing on direct consumer transparency and human appeals rather than abstract algorithmic audits, the ADMT Act ensures that the era of the unquestioned 'black box' decision is coming to an end. For the enterprise software industry, the message is clear: if an algorithm is going to make a decision about a human life, a human must be ready to explain it.[3]

How we got here

  1. May 2024

    Colorado passes the nation's first comprehensive AI law (SB 24-205), focusing on high-risk systems.

  2. April 2026

    Elon Musk's xAI sues to block the 2024 law, joined by the U.S. Department of Justice seeking federal preemption.

  3. May 2026

    Gov. Jared Polis signs SB 26-189, repealing the 2024 law and replacing it with the narrower ADMT Act.

  4. July 2026

    The Colorado Attorney General opens the pre-rulemaking public comment period for the new law.

  5. January 2027

    The new Colorado ADMT Act is scheduled to take full effect.

Viewpoints in depth

Enterprise Deployers

Employers and service providers face a massive operational shift toward decision-by-decision accountability.

For companies that use AI to screen resumes or approve loans, the new law relocates regulatory risk downstream. Instead of relying on upfront system audits, deployers must now be prepared to explain and defend every single AI-assisted rejection. This requires building new internal infrastructure to handle consumer data access requests, manage 30-day explanation windows, and facilitate human reviews of adverse outcomes.

AI Developers

Tech vendors must navigate strict documentation requirements and a new shared liability framework.

Developers can no longer use contracts to completely shield themselves from liability if their tools produce discriminatory outcomes. The law voids indemnification clauses for discriminatory acts, meaning developers are on the hook if their system is used exactly as intended but still exhibits bias. To protect themselves, vendors must provide exhaustive technical documentation detailing the known limitations, training data summaries, and strict instructions for appropriate use.

State Regulators

Officials prioritize actionable consumer transparency over abstract algorithmic compliance.

Faced with intense industry pushback and federal lawsuits over the original 2024 law, Colorado regulators pivoted to a more pragmatic approach. By modeling the ADMT Act on the Fair Credit Reporting Act, they aim to give consumers direct, actionable rights—like the ability to correct inaccurate data and demand human review—rather than relying on opaque, system-level risk management programs that are difficult to enforce.

What we don't know

  • How the ongoing federal litigation by xAI and the DOJ will impact the law's January 2027 enforcement date.
  • Exactly how the Colorado Attorney General will define 'commercially reasonable' human review during the rulemaking process.
  • Whether other states will adopt Colorado's ADMT framework or continue pursuing broader EU-style AI regulations.

Key terms

Automated Decision-Making Technology (ADMT)
Technology that processes personal data to generate predictions or scores used to guide decisions about individuals.
Consequential Decision
A determination that materially affects a consumer's access to essential opportunities like jobs, housing, or loans.
Deployer
An organization, such as an employer or bank, that uses an AI system to make decisions about consumers.
Developer
The company or entity that creates, trains, or substantially modifies an AI system.
Algorithmic Discrimination
Unlawful differential treatment of individuals based on protected characteristics caused by an AI system's outputs.

Frequently asked

What is a 'consequential decision' under the new law?

It is any determination that materially affects a consumer's access to essential opportunities, such as employment, housing, lending, healthcare, insurance, or government services.

Does the law apply to basic software like spreadsheets?

No. Routine technologies like anti-malware, calculators, and basic spreadsheets are explicitly excluded, provided they do not use machine learning to make decisions.

Can individuals sue companies directly under this law?

No. The law does not include a private right of action and is enforced exclusively by the Colorado Attorney General.

How does the law handle liability between developers and employers?

It creates a shared liability framework. Developers are responsible if the tool discriminates when used as intended, while employers bear the risk if they use the tool 'off-label' or fail to provide required consumer notices.

Sources

Source coverage

4 outlets

4 viewpoints surfaced

Enterprise Deployers 30%AI Developers 25%State Regulators 25%Compliance Advisors 20%
  1. [1]Goodwin LawAI Developers

    Colorado Enacts Law Repealing and Replacing Landmark Colorado AI Act

    Read on Goodwin Law
  2. [2]DLA PiperCompliance Advisors

    Colorado repeals and replaces AI Act with narrower ADMT law

    Read on DLA Piper
  3. [3]Factlen Editorial TeamState Regulators

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team
  4. [4]Mayer BrownCompliance Advisors

    Colorado Enacts New ADMT Law Replacing Colorado AI Act

    Read on Mayer Brown
Stay informed

Every angle. Every day.

Get meta stories with full source coverage and perspective breakdowns delivered to your inbox.