From the journal

Colorado Legislature Passes SB 189 Repealing and Replacing the Colorado AI Act, 12 May 2026

On 12 May 2026, the Colorado General Assembly passed SB 189, which repeals the Colorado Artificial Intelligence Act (SB 24-205) and replaces it with a disclosure-focused statute covering automated decision-making technology. The bill drops the duty of care, risk management programmes, and impact assessment duties. Governor Polis is expected to sign. The new statute takes effect on 1 January 2027.

2 min read

The Colorado Senate passed SB 189 by a 34 to 1 vote. The House passed it by 57 to 6. The bill now goes to Governor Jared Polis, who is expected to sign. SB 189 repeals the Colorado Artificial Intelligence Act enacted as SB 24-205. The replacement takes effect on 1 January 2027.

SB 189 governs developers and deployers of automated decision-making technology (ADMT). The bill removes the prior duty of care, the risk management programme mandate, and the algorithmic impact assessment requirement. The new text relies on disclosure, recordkeeping, and consumer notice. It defines covered consequential decisions and the persons who deploy them.

Developers training general-purpose models for resale fall outside the consequential-decision deployer category but remain subject to documentation duties. Employers using AI for hiring, lenders using AI for credit, insurers using AI for underwriting, and housing providers using AI for tenant screening fall within deployer obligations. The bill narrows private rights and centres enforcement with the Colorado Attorney General.

SB 189's 1 January 2027 effective date precedes the next legislative session by ten days. The Attorney General retains rulemaking authority over notice form and content. Existing automated-decision systems in operation when the bill takes effect receive transitional treatment under recordkeeping provisions. Federal AI legislation, if enacted, may preempt portions of SB 189.

Licentium advises AI deployers and digital asset clients on US state AI compliance and works with US counsel on multi-state filings. Contact us to assess Colorado, California, Texas, and Illinois AI duties together. Work we undertake includes consequential-decision mapping, ADMT inventory, consumer notice drafting, recordkeeping policies, and multi-state AI compliance opinions.

Source: Colorado General Assembly, bill repealing and replacing the Colorado Artificial Intelligence Act (SB 24-205), passed by both chambers on 12 May 2026, https://leg.colorado.gov/bills/sb24-205, confirmed 14 May 2026.

The information provided is not legal, tax, investment, or accounting advice and should not be used as such. It is for discussion purposes only. Seek guidance from your own legal counsel and advisors on any matters. The views presented are those of the author and not any other individual or organization. Some parts of the text may be automatically generated. The author of this material makes no guarantees or warranties about the accuracy or completeness of the information.

AI Regulatory

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).

Illia Prokopiev

Stablecoin regulation in the US, Hong Kong and Singapore

Stablecoin and digital-token regulation now combines market-entry authorization with continuous financial-crime controls in daily operations. The question is whether the United States’ proposed payment-stablecoin customer identification program, Hong Kong’s narrow first licensing round, and Singapore’s digital payment token (DPT) directory support a bank-like compliance characterization. They do, with material limits. The more accurate proposition is that compliance is moving beyond approval into continuous financial-institution-grade operations.