From the journal

Colorado Enacts SB 26-189 on Automated Decision-Making Technology, Effective January 2027

Colorado enacted Senate Bill 26-189 in May 2026, repealing and reenacting the state's automated decision-making technology statute with revised requirements for developers and deployers of AI systems used in consequential decisions. The law supersedes SB 24-205 and takes effect January 1, 2027, with the Colorado Attorney General holding rulemaking authority.

2 min read

Colorado enacted Senate Bill 26-189 in May 2026, repealing and reenacting the automated decision-making technology provisions first introduced by SB 24-205. The law is signed and final; it takes effect January 1, 2027. It governs developers and deployers of AI systems that make or materially influence consequential decisions affecting Colorado consumers across sectors including employment, education, financial services, housing, and healthcare.

SB 24-205, signed in 2024 and effective February 1, 2026, required developers of high-risk AI systems to use reasonable care to protect consumers from algorithmic discrimination and required deployers to publish risk management statements. SB 26-189 replaces those provisions with revised obligations. The Colorado Attorney General holds rulemaking authority under the new statute and has opened a rulemaking proceeding to define compliance standards, including the definitions of 'automated decision-making technology' and 'consequential decision.'

Businesses that deploy AI in hiring, performance evaluation, credit decisioning, insurance underwriting, or housing eligibility determinations for Colorado residents must meet the revised obligations by January 1, 2027. The law binds both the AI system developer, who must use reasonable care to limit known risks of algorithmic discrimination, and the deployer, who must conduct impact assessments and publish a public summary of AI systems deployed. Technology vendors supplying AI systems to Colorado-based deployers carry developer obligations and cannot disclaim them by contract alone.

Final implementing rules have not yet issued from the Colorado Attorney General's office, leaving the precise scope of compliance obligations open to interpretation. At least a dozen other US states have introduced comparable automated decision-making bills in 2025 and 2026, creating overlapping and partially inconsistent obligations. Companies operating nationally must track each state's effective date, scope definitions, and exemption carve-outs individually.

Licentium advises on AI governance and algorithmic accountability requirements across US and international regulatory regimes and coordinates with US-qualified counsel through our partner network. To discuss SB 26-189 compliance planning, contact us. Work we undertake includes: AI regulatory compliance, automated decision-making impact assessments, employment AI audits, state AI statute gap analysis, and multi-jurisdictional regulatory strategy.

Source: Colorado Senate Bill 26-189, signed May 2026

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

Matched-Category Analysis of the Hong Kong Stablecoin Issuer Route and the Singapore Digital Payment Token Service Route

This matter concerns whether current licensing data supports a commercial comparison between Hong Kong’s stablecoin issuer route and Singapore’s digital payment token service route. The question is whether the proposition remains legally accurate as of 12 August 2026. “Commercially useful” is assumed to mean useful for selecting a market-entry and operating model, not proof that either regulator is more permissive.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).