← Back to Sia website
Sia RegAI  /  Blog  /  Colorado SB26-189
Analysis · US state AI law

Colorado SB26-189: the 2027 ADMT compliance checklist.

Published July 26, 2026Reviewed July 26, 20264-minute readBy Cyril Sayada

Colorado replaced its earlier high-risk AI framework with a more specific law for automated decision-making technology used in consequential decisions. The operational centre is a shared chain of documentation: developers describe the system and its limits; deployers connect that information to notices, adverse outcomes and meaningful human review.

Direct answer: SB26-189 became law on 14 May 2026 and its principal developer and deployer requirements begin 1 January 2027. Start with the decision, not the model: determine whether technology processes personal data and materially influences access to education, employment, housing, lending, insurance, health care or essential government services.

What is covered?

The enacted law defines automated decision-making technology, or ADMT, broadly enough to include technology that processes personal data and uses computation to generate predictions, recommendations, classifications, rankings, scores or other information that makes, guides or assists a decision concerning a person.

The second gate is whether the decision is consequential. Covered domains include:

  • education enrolment and opportunities;
  • employment and employment opportunities;
  • housing and real-estate transactions;
  • financial and lending services;
  • insurance;
  • health-care services; and
  • essential government services and public benefits.

Do not classify from a vendor's product name. Document the actual data, output, decision stage, human authority, domain and effect on the person.

Developer obligations

A developer of covered ADMT must give deployers usable technical documentation. The law's enacted summary identifies the system's intended uses, categories of training data, known limitations and instructions for appropriate use and human review. Developers must also notify deployers about material updates or modifications.

Turn that into a controlled release package containing:

  • intended and known harmful uses;
  • input and training-data categories;
  • known limitations, risks and prohibited contexts;
  • performance information relevant to the covered decision;
  • monitoring and meaningful-human-review instructions;
  • information the deployer needs for consumer notices; and
  • a material-change log with effective dates.

Deployer obligations

Deployers need a clear and conspicuous notice at the point of interaction with covered ADMT. When the technology produces a consequential decision with an adverse outcome, the deployer must provide a plain-language description of its role within 30 calendar days.

The law also gives consumers routes to request relevant personal data, correction of factually inaccurate personal data, and meaningful human review and reconsideration after an adverse outcome. The control design therefore needs more than an appeal mailbox. It should identify a reviewer with authority, the information available to that reviewer, the review standard, the target response time and how the final disposition is recorded.

Records and enforcement

Developers and deployers must retain records needed to demonstrate compliance for at least three years. Colorado's Attorney General enforces the law through the Colorado Consumer Protection Act; a violation is treated as a deceptive trade practice. The act does not create a new private right of action. Before 1 January 2030, the Attorney General generally provides a 60-day notice and opportunity to cure when a cure is considered possible.

What changed—and what did not

  • Changed: the enacted 2026 law repeals and reenacts the 2024 framework around ADMT and consequential decisions.
  • Changed: developer documentation, deployer notice, adverse-outcome explanation and human-review controls now form the core workflow.
  • Not changed: existing civil-rights, consumer, employment, insurance and sector laws still apply independently.
  • Not created: SB26-189 does not establish a new private cause of action.
  • Not universal: the statute includes entity and activity-specific exemptions that require a fact-specific check.

Implementation sequence

  1. Build a decision inventory across the seven covered domains.
  2. Record whether the system makes, guides, assists or merely supports each decision.
  3. Assign developer, deployer and vendor-management responsibilities.
  4. Collect the technical-documentation package and log gaps.
  5. Design point-of-interaction and adverse-outcome notices.
  6. Create correction, human-review and reconsideration procedures.
  7. Set a three-year minimum evidence-retention rule.
  8. Monitor Attorney General rulemaking on post-adverse-outcome disclosures.

How Sia RegAI can support the workflow

RegReview can monitor the enacted law, Attorney General rules and relevant sector sources, then route changes to the decision owners they affect. RegMatcher can map the statutory requirements to the ADMT inventory, model documentation, notices, appeal procedures and retention controls, with a reviewer recording whether coverage is full, partial or absent. The legal scope decision and any adverse decision remain accountable human judgments.

Primary source

This analysis is general information, not legal advice. Review the signed act, exemptions, forthcoming rules and the facts of the specific decision process.

Map one consequential-decision workflow before 2027.

Connect the legal source to system documentation, notice, reviewer and retained evidence.