Colorado SB 189: What the New AI Law Changes from SB 205
On May 14, 2026, Governor Jared Polis signed SB26-189 into law. SB 189 repeals and reenacts Colorado’s earlier AI consumer protection framework enacted as SB24-205.
The key change is a shift from SB 205’s broader regulation of “high-risk artificial intelligence systems” to a narrower regime focused on developers and deployers of covered automated decision-making technology (ADMT) that materially influences a consequential decision.
Below are the key changes introduced by SB 189.
Applicability: From High-Risk AI Systems to Covered ADMT
SB 205 applies to high-risk artificial intelligence systems. A high-risk artificial intelligence system is an AI system that, when deployed, makes or is a substantial factor in making a consequential decision.
SB 189 instead applies to ADMT used to materially influence a consequential decision.
ADMT means technology that processes personal data and uses computation to generate output, including predictions, recommendations, classifications, rankings, scores, or other information used to make, guide, or assist a decision, judgment, or determination concerning an individual.
SB 189, therefore, applies to “covered ADMT,” defined as automated decision-making technology that materially influences a consequential decision.
“Materially influence” means that an ADMT output is a non-de minimis factor used in making a consequential decision and affects the outcome of that decision, including by constraining, ranking, scoring, recommending, classifying, or otherwise meaningfully altering how the decision is made. It does not include incidental, trivial, or clerical uses.
This shift narrows the scope of applicable systems, meaning organizations may be able to exclude more low-impact or support-only tools from compliance requirements, focus controls on ADMT that actually affect high-stakes outcomes, and reduce the number of workflows that require consumer notices, post-adverse-outcome disclosures, and human review processes.
Changes to Key Definitions
SB 189 removes or replaces several definitions used under SB 205, including:
- Algorithmic discrimination
- Artificial intelligence system
- High-risk artificial intelligence system
- Substantial factor
SB 189 adds definitions for:
- Automated decision-making technology
- Covered ADMT
- Covered domain
- Consequential decision
- Materially influence
- Adverse outcome
- Meaningful human review
- Personal data
Replacing “substantial factor” with “materially influence” clarifies and narrows the coverage trigger, allowing organizations to determine what is in scope and limit compliance to systems that meaningfully drive consequential decisions.
The definition of personal data, which has been added to SB 189, also narrows the statute’s reach to decisioning tools that use data about identifiable individuals, making coverage and compliance obligations more targeted for organizations.
Covered Entities
Under SB 205, covered entities are developers and deployers of high-risk artificial intelligence systems. SB 189 instead applies to developers and deployers of covered ADMT.
A deployer is a person who does business in Colorado and deploys covered ADMT.
The definition of developer has also been amended. Under SB 189, the developer includes a person doing business in Colorado that develops, offers, sells, leases, licenses, or otherwise makes commercially available covered ADMT.
It also includes persons who develop components designed, marketed, intended, documented, advertised, configured, or contracted to be used as part of covered ADMT, as well as those who intentionally and substantially modify ADMT such that it becomes covered ADMT.
The definitions of “deployer” and “developer” have therefore been significantly amended to reflect the law’s altered scope.
Exemptions Under SB 189
SB 205 provided exemptions for certain small deployers and sectors, including insurance, banks, and credit unions.
SB 189 includes statutory or sector exemptions and limitations covering areas including:
- Insurance;
- Governmental entities;
- HIPAA-related activities;
- FDA-regulated medical devices and products; and
- Activities subject to the Gramm-Leach-Bliley Act (GLBA).
Changes to Developer Obligations
Under SB 205, developers had a duty of reasonable care to protect consumers from known or foreseeable risks of algorithmic discrimination arising from intended and contracted uses of high-risk AI systems. Developers were also required to provide deployers with information and documentation necessary to comply with the law.
The duty of reasonable care to consumers is removed from SB 189.
Instead, developers of covered ADMT who previously materially influenced consequential decisions must comply with specific disclosure, notification, and record-keeping requirements.
Mandatory Disclosures to Deployers
Developers must provide deployers with documentation that includes information relating to:
- Intended use;
- Training data;
- Limitations and risks;
- Instructions; and
- Compliance information.
Notifications of Updates
Developers must notify deployers within a reasonable timeframe regarding material updates and substantial, intentional modifications, as well as changes to the technology’s intended use, limitations, or risk mitigations.
Developers can satisfy this requirement by publishing public release notes, provided they give deployers direct notice of the release.
These requirements apply where the ADMT is marketed, advertised, sold, or configured to materially influence or make a consequential decision, or where the developer becomes aware that the technology is being used to make consequential decisions in a manner consistent with its intended or contracted use.
Changes to Deployer Obligations
SB 205 required deployers to exercise reasonable care to avoid algorithmic discrimination.
Deployers were also required to implement and maintain a risk management policy and program for high-risk AI systems and complete impact assessments.
The provisions regarding reasonable care to consumers, risk management programs and governance, and impact assessments are removed from SB 189.
Instead, SB 189 requires deployers to provide per-use notices and post-adverse-outcome disclosures.
Pre-Use Notice Requirements
Before a deployer uses covered ADMT to materially influence a consequential decision, the affected consumer must be notified.
The notice must be clear, conspicuous, and prominent. Deployers can meet this requirement by posting a publicly accessible notice or link near where the consumer interaction or transaction occurs.
The notice must state that ADMT is or will be used and provide instructions explaining how the consumer can obtain more information.
Post-Adverse-Outcome Disclosures
If the use of ADMT results in an adverse outcome for a consumer, the deployer must provide specified disclosures within 30 days. These include:
- A plain-language explanation of the decision and the specific role the ADMT played;
- A simple process through which the consumer can request additional details, such as the ADMT’s name, version, developer, and the types and sources of personal data used; and
- An explanation of the consumer’s legal rights under the law and how to exercise them.
SB 189 also prevents duplicate notifications and protects sensitive data by exempting trade secrets and allowing entities operating under existing federal frameworks, including ECOA, FCRA, and FERPA, to use their existing systems for compliance.
Record Retention
SB 205 did not contain a requirement to retain records.
Under SB 189, developers are required to retain compliance records for at least three years, or longer where required by other laws.
These records must include system version identifiers, changelogs, and documentation or notices of material updates.
Changes to Consumer Rights
Under SB 205, following an adverse consequential decision involving a high-risk AI system, consumers were provided with information about the system’s use and the principal reasons for the decision.
Consumers were also given the opportunity to correct inaccurate personal data and to appeal an adverse consequential decision. Where technically feasible, that appeal had to allow for human review.
SB 189 changes this framework.
Following an adverse outcome from a consequential decision materially influenced by covered ADMT, the deployer must, upon request, provide consumers with instructions for requesting the personal data it processes and for correcting factually incorrect or materially inaccurate personal data, consistent with the Colorado Privacy Act.
Consumers must also be provided an opportunity for meaningful human review and reconsideration, to the extent commercially reasonable.
Meaningful human review requires review by an individual designated by the deployer who has the authority to approve, modify, or override a consequential decision. The reviewer must:
- Consider relevant, available primary evidence;
- Be trained to conduct the review;
- Not default to the system output; and
- Have sufficient information to understand the output’s intended use, material limitations, categories of inputs, and the principal factors used to generate the output.
This does not require disclosure of proprietary source code, model weights, or other trade secrets.
SB 189, therefore, replaces SB 205’s appeal-and-human-review “if technically feasible” construct with a defined “meaningful human review” standard.
It also adds clearer instructions for requesting or correcting relevant personal data and removes the prior requirement to inform consumers about the Colorado Privacy Act profiling opt-out right.
Attorney General Enforcement and Right to Cure
Under both frameworks, the Colorado Attorney General has enforcement authority.
SB 205 did not provide a statutory right to cure. Instead, an affirmative defense was available where an entity discovered and cured certain violations through feedback or internal review and otherwise complied with specified frameworks.
SB 189 replaces the affirmative-defense approach with an explicit pre-enforcement cure right.
Where a violation is deemed capable of being cured, SB 189 provides a 60-day right to cure following notice of the violation.
Developer and Deployer Liability
SB 205 did not contain a standalone provision allocating liability between developers and deployers.
SB 189 establishes an express discrimination-liability framework for covered ADMT.
A developer or deployer may be held liable in actions alleging unlawful discrimination arising from a consequential decision materially influenced by covered ADMT.
The law provides for the allocation of fault between developers and deployers. Developer liability is limited to intended or contracted uses involving material influence, while deployer liability is preserved for the deployer’s independent acts or omissions.
SB 189 also limits indemnification by invalidating certain contractual provisions that require one party to indemnify or defend another for that other party’s own acts or omissions associated with discrimination liability arising from covered ADMT.
These provisions clarify liability between developers and deployers and restrict blanket indemnities from being triggered, improving risk apportionment.
What SB 189 Means for Organizations
SB 189 represents a shift from the broader regulation of high-risk AI systems under SB 205 to a more targeted framework focused on covered ADMT that materially influences consequential decisions.
For organizations that had been preparing for SB 205, this means reassessing which systems are in scope, determining where ADMT materially influences consequential decisions, reviewing developer and deployer obligations, and updating consumer notice and human review processes where necessary.
The new framework also places greater emphasis on documentation, record retention, and the allocation of responsibility between developers and deployers.
As organizations prepare for SB 189, understanding where automated decision-making technology is deployed and how it affects consequential decisions will be central to determining which obligations apply.