Defines algorithmic discrimination as AI use violating anti-discrimination laws, including the Colorado Anti-Discrimination Act and major federal acts. Requires developers of high-risk AI systems to provide detailed documentation, including intended uses and risks, to deployers by 2027. Obligates deployers to implement risk management policies and conduct annual impact assessments for high-risk AI systems starting 2027 to mitigate algorithmic discrimination risks. Mandates deployers to disclose to consumers the use and impact of high-risk AI systems when making consequential decisions, ensuring transparency and providing an appeals process. Empowers the attorney general to enforce compliance, investigate violations, and potentially adopt rules for implementing the statute. Exempts certain small developers and deployers from specific obligations and outlines conditions under which information may be withheld. Does not apply to certain AI systems acquired by federal agencies or those necessary to comply with federal law.
Paper
Full text
Colorado SB 25-318 (AI Consumer Protections)
ETO AGORA · U.S. state and local documents · 2025
Summary
Defines algorithmic discrimination as AI use violating anti-discrimination laws, including the Colorado Anti-Discrimination Act and major federal acts.
Requires developers of high-risk AI systems to provide detailed documentation, including intended uses and risks, to deployers by 2027.
Obligates deployers to implement risk management policies and conduct annual impact assessments for high-risk AI systems starting 2027 to mitigate algorithmic discrimination risks.
Mandates deployers to disclose to consumers the use and impact of high-risk AI systems when making consequential decisions, ensuring transparency and providing an appeals process.
Empowers the attorney general to enforce compliance, investigate violations, and potentially adopt rules for implementing the statute.
Exempts certain small developers and deployers from specific obligations and outlines conditions under which information may be withheld.
Does not apply to certain AI systems acquired by federal agencies or those necessary to comply with federal law.
Amends Colorado Revised Statutes 6-1-1701, introducing and modifying various subsections and adding new provisions.
Be it enacted by the General Assembly of the State of Colorado: SECTION 1. In Colorado Revised Statutes, 6-1-1701, amend (1)(a), (3), (5), (6), (7), (10), and (11)(a) introductory portion; repeal and reenact, with amendments, (9)(b); and add (2.7), (10.3), (11.7), (13), and (14) as follows:
Defines "algorithmic discrimination" as AI use violating local, state, or federal anti-discrimination laws, including specific acts.
6-1-1701. Definitions. As used in this part 17, unless the context otherwise requires: (1)(a) "Algorithmic discrimination" means the use of an artificial intelligence system THAT results in A VIOLATION OF ANY APPLICABLE LOCAL, STATE, OR FEDERAL ANTI-DISCRIMINATION LAW, INCLUDING: (I) THE COLORADO ANTI-DISCRIMINATION ACT, PARTS 3 TO 8 OF ARTICLE 34 OF TITLE 24; (II) THE "CIVIL RIGHTS ACT OF 1964", 42 U.S.C. SEC. 2000a ET SEQ.; (III) THE "AMERICANS WITH DISABILITIES ACT OF 1990", 42 U.S.C. SEC. 12101 ET SEQ.; (IV) THE "AGE DISCRIMINATION IN EMPLOYMENT ACT OF 1967", 29 U.S.C. SEC. 621 ET SEQ.; (V) THE "GENETIC INFORMATION NONDISCRIMINATION ACT OF 2008", 42 U.S.C. SEC. 2000ff ET SEQ.; AND (VI) THE "PREGNANT WORKERS FAIRNESS ACT", 42 U.S.C. SEC. 2000gg ET SEQ.
(2.7) "COMPETITIVE DECISION" MEANS A DECISION REGARDING A CONSUMER WHERE A FAVORABLE DECISION HAS BEEN MADE REGARDING ANOTHER CONSUMER AND THAT FAVORABLE DECISION NECESSARILY ENTAILS AN ADVERSE DECISION FOR THE CONSUMER, SUCH AS A DECISION REGARDING A JOB OPPORTUNITY FOR WHICH THERE ARE NO REMAINING OPENINGS.
Defines "consequential decision" as one significantly affecting education, employment, finance, government services, healthcare, housing, insurance, or legal services.
(3)(a) "Consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of: (I) Education enrollment or an education opportunity; (II) Employment or an employment opportunity; (III)(A) A LOAN, FINANCING, OR CREDIT FOR AN INDIVIDUAL FOR PERSONAL, FAMILY, OR HOUSEHOLD PURPOSES FROM A FINANCIAL LENDING OR CREDIT SERVICE; (B) CONSUMER CREDIT TRANSACTIONS, AS DEFINED IN SECTION 5-1-301 (12); OR (C) BANKING OR CREDIT UNION SERVICES FOR AN INDIVIDUAL, INCLUDING BANKING TRANSACTIONS, AS DEFINED IN SECTION 11-101-401 (9), BUT EXCLUDING BANKING OR CREDIT UNION SERVICES PRIMARILY RELATING TO SECURITIES, AS DEFINED IN SECTION 11-51-201 (17); DERIVATIVES TRANSACTIONS, AS DEFINED IN 17CFR 270.18f-4, AS THAT SECTION EXISTED ON JULY 1, 2025; OR SERVICES PROVIDED TO AN INDIVIDUAL WHO IS AN ACCREDITED INVESTOR, AS DEFINED IN 17 CFR 230.501, AS THAT SECTION EXISTED ON JULY 1, 2025; (IV) An essential government service, WHICH IS A SERVICE THAT IS PROVIDED BY THE STATE; A MUNICIPALITY, TOWNSHIP, COUNTY, OR HOME RULE COUNTY; OR A SUBDIVISION OR AGENCY OF GOVERNMENT AND WHICH IS NEEDED TO SUPPORT THE CONTINUING OPERATION OF THE GOVERNMENT AGENCY OR TO PROVIDE FOR OR SUPPORT THE HEALTH, SAFETY, AND WELFARE OF THE PUBLIC, INCLUDING MEDICARE, MEDICAID, COMPLIANCE MONITORING, ENFORCEMENT OF LAWS, PERMITTING, AND LICENSING; (V) Health-care services; (VI) Housing, WITH RESPECT TO THE PURCHASE OR RENTING OF A PRIMARY RESIDENCE, INCLUDING SHORT-TERM TENANCY AND TRANSITIONAL HOUSING IF IT SERVES AS A CONSUMER'S PRIMARY RESIDENCE; (VII) Insurance; or (VIII) A legal service.
Defines an "adverse" consequential decision based on negative impacts on employment or consumer goods and services.
(b) A CONSEQUENTIAL DECISION IS "ADVERSE" IF THE CONSEQUENTIAL DECISION RESULTS IN: (I) THE DENIAL, CANCELLATION, TERMINATION, OR REVOCATION OF EMPLOYMENT OR OF A GOOD, A SERVICE, OR OTHER THING OF VALUE TO THE CONSUMER; (II) AN UNFAVORABLE CHANGE TO THE TERMS OF EXISTING EMPLOYMENT OR THE TERMS OF ACCESS TO A GOOD, A SERVICE, OR OTHER THING OF VALUE TO THE CONSUMER; (III) THE DENIAL OR REFUSAL TO GRANT EMPLOYMENT OR A GOOD, A SERVICE, OR OTHER THING OF VALUE ON SUBSTANTIALLY THE SAME TERMS AS THOSE ORIGINALLY REPRESENTED TO AND EXPECTED BY THE CONSUMER; OR (IV) AN OFFER OF EMPLOYMENT OR A GOOD, A SERVICE, OR OTHER THING OF VALUE TO THE CONSUMER ON MATERIAL TERMS THAT ARE MATERIALLY LESS FAVORABLE THAN THE MOST FAVORABLE TERMS AVAILABLE TO A SUBSTANTIAL PROPORTION OF CONSUMERS FROM OR THROUGH THAT DEPLOYER.
Defines "deploy" and "deployer" regarding high-risk AI systems and outlines exceptions for developer liability.
(5) "Deploy" means to use a high-risk artificial intelligence system OR AN ARTIFICIAL INTELLIGENCE SYSTEM DESCRIBED IN SECTION 6-1-1704.
(6) "Deployer" means a person doing business in this state, OR AN AGENT OF THAT PERSON, that deploys a high-risk artificial intelligence system OR AN ARTIFICIAL INTELLIGENCE SYSTEM DESCRIBED IN SECTION 6-1-1704.
(7)(a) "Developer" means a person doing business in this state, OR AN AGENT OF THAT PERSON, THAT: (I) DEVELOPS AN ARTIFICIAL INTELLIGENCE SYSTEM; OR (II) MODIFIES AN ARTIFICIAL INTELLIGENCE SYSTEM THAT MAKES, OR IS A SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL DECISION.
(b) EXCEPT AS PROVIDED IN SECTION 6-1-1704, A PERSON IS NOT SUBJECT TO THE OBLIGATIONS OR LIABILITY OF A DEVELOPER UNDER THIS PART 17 IF THE PERSON OFFERS THE ARTIFICIAL INTELLIGENCE SYSTEM WITH OPEN MODEL WEIGHTS OR, ON AND AFTER JANUARY 1, 2027, SO LONG AS THE DEVELOPER: (I) DOES NOT ENGAGE IN ANY MATERIAL CONDUCT OR MAKE ANY MATERIAL STATEMENT OR REPRESENTATION TO VENDORS, DEPLOYERS, OTHER DEVELOPERS, OR THE GENERAL PUBLIC, INCLUDING MARKETING OR ADVERTISING, THAT PROMOTES THE USE OF THE ARTIFICIAL INTELLIGENCE SYSTEM IN MAKING CONSEQUENTIAL DECISIONS OR THAT IS MATERIALLY INCONSISTENT WITH THE STATEMENTS DESCRIBED IN SUBSECTION (7)(b)(II) OF THIS SECTION; OR (II) STATES IN ALL CONTRACTS WITH DEPLOYERS, VENDORS, AND OTHER DEVELOPERS APPLICABLE TO THE ARTIFICIAL INTELLIGENCE SYSTEM, AND IN THE TERMS OF SERVICE, END USER LICENSE AGREEMENT, OR OTHER SIMILAR LEGAL DOCUMENTATION APPLICABLE TO THE ARTIFICIAL INTELLIGENCE SYSTEM, THAT: (A) THE ARTIFICIAL INTELLIGENCE SYSTEM IS NOT DESIGNED TO ENABLE DEPLOYERS, OTHER DEVELOPERS, OR VENDORS TO USE THE SYSTEM IN MAKING, OR BEING A SUBSTANTIAL FACTOR IN MAKING, CONSEQUENTIAL DECISIONS; (B) DEPLOYERS, OTHER DEVELOPERS, OR VENDORS SHALL NOT USE OR ENGAGE IN CONDUCT THAT ENABLES OR ENCOURAGES THE USE OF THE ARTIFICIAL INTELLIGENCE SYSTEM IN MAKING, OR BEING A SUBSTANTIAL FACTOR IN MAKING, CONSEQUENTIAL DECISIONS; (C) IF A DEPLOYER USES THE ARTIFICIAL INTELLIGENCE SYSTEM TO MAKE, OR BE A SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL DECISION, THE DEPLOYER IS RESPONSIBLE FOR ENSURING THAT THEIR USE OF THE ARTIFICIAL INTELLIGENCE SYSTEM COMPLIES WITH ALL APPLICABLE STATE AND FEDERAL LAWS, INCLUDING THIS PART 17; AND (D) IF A DEPLOYER, A VENDOR, OR OTHER DEVELOPER MODIFIES THE ARTIFICIAL INTELLIGENCE SYSTEM SO THAT IT CAN BE USED TO MAKE, OR BE A SUBSTANTIAL FACTOR IN MAKING, CONSEQUENTIAL DECISIONS, THE PARTY MAKING THE MODIFICATION MAY BE CONSIDERED A DEVELOPER FOR PURPOSES OF THIS PART 17.
Excludes specified technologies from "high-risk AI systems" unless involved in making consequential decisions.
(9)(b) "HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM" DOES NOT INCLUDE THE FOLLOWING TECHNOLOGIES UNLESS THE TECHNOLOGIES, WHEN DEPLOYED, MAKE, OR ARE A SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL DECISION: (I) A TECHNOLOGY THAT: (A) PERFORMS A NARROW PROCEDURAL TASK OF A LIMITED NATURE, INCLUDING A TECHNOLOGY THAT CLASSIFIES INCOMING DOCUMENTS INTO CATEGORIES, IS USED TO DETECT DUPLICATES AMONG A LARGE NUMBER OF APPLICATIONS, CATEGORIZES DOCUMENTS BASED ON WHEN THEY WERE RECEIVED, RENAMES FILES ACCORDING TO STANDARDIZED NAMING CONVENTIONS, OR AUTOMATES THE EXTRACTION OF METADATA FOR INDEXING; (B) IMPROVES A PREVIOUSLY COMPLETED HUMAN ACTIVITY WITHOUT BEING A SUBSTANTIAL FACTOR IN ANY DECISIONS RESULTING FROM THE PRIOR HUMAN ACTIVITY, INCLUDING IMPROVING THE LANGUAGE USED IN PREVIOUSLY DRAFTED DOCUMENTS; OR (C) DETECTS DECISION-MAKING PATTERNS OR DEVIATIONS FROM PREEXISTING DECISION-MAKING PATTERNS FOLLOWING A PREVIOUSLY COMPLETED HUMAN ASSESSMENT, WHICH ASSESSMENT THE TECHNOLOGY IS NOT MEANT TO REPLACE OR INFLUENCE WITHOUT SUFFICIENT HUMAN REVIEW, INCLUDING A TECHNOLOGY THAT ANALYZES A PARTICULAR DECISION-MAKER'S PREEXISTING PATTERN OF DECISIONS AND FLAGS POTENTIAL INCONSISTENCIES OR ANOMALIES; (II) TOOLS FOR FILTERING ROBOCALLS, JUNK OR SPAM EMAIL, OR MESSAGES; (III) SPELL-CHECKING TOOLS; (IV) CALCULATORS; (V) INTERNET OR COMPUTER NETWORK INFRASTRUCTURE OPTIMIZATION, DIAGNOSTIC, OR MAINTENANCE TOOLS, SUCH AS DOMAIN NAME REGISTRATION, WEBSITE HOSTING, CONTENT DELIVERY, WEB CACHING, NETWORK TRAFFIC MANAGEMENT, OR SYSTEM DIAGNOSTIC TOOLS; (VI) DATABASES, SPREADSHEETS, OR OTHER SIMILAR TOOLS THAT DO NO MORE THAN ORGANIZE DATA ALREADY IN THE POSSESSION OF THE USER OF THE TECHNOLOGY; (VII) CYBERSECURITY AND DATA SECURITY MEASURES, INCLUDING FIREWALLS, ANTIVIRUS SOFTWARE, INTRUSION DETECTION AND PREVENTION TOOLS, AND MALWARE DETECTION TOOLS; (VIII) TECHNOLOGIES USED TO PERFORM, ASSIST, OR ADMINISTER OFFICE SUPPORT FUNCTIONS AND OTHER ANCILLARY BUSINESS OPERATIONS, SUCH AS ORDERING OFFICE SUPPLIES, MANAGING MEETING SCHEDULES, OR AUTOMATING INVENTORY TRACKING; (IX) ANTI-FRAUD SYSTEMS OR TOOLS USED TO PREVENT, DETECT, OR RESPOND TO UNLAWFUL AND MALICIOUS CONDUCT OR TO COMPLY WITH FEDERAL OR STATE LAW; OR (X) TECHNOLOGY THAT COMMUNICATES WITH CONSUMERS IN NATURAL LANGUAGE FOR THE PURPOSE OF PROVIDING THOSE CONSUMERS WITH INFORMATION, REFERRALS OR RECOMMENDATIONS, OR ANSWERS TO QUESTIONS AND THAT IS SUBJECT TO AN ACCEPTABLE USE POLICY.
Defines "Open Model Weights" as AI systems accessible to the public without license restrictions or fees.
(10)"MODEL WEIGHTS" MEANS THE NUMERICAL PARAMETERS WITHIN A MODEL THAT ARE GENERATED BY OR ARE A COMPONENT OF AN ARTIFICIAL INTELLIGENCE SYSTEM AND THAT HELP DETERMINE THE MODEL'S OUTPUT IN RESPONSE TO INPUTS. (10.3) "OPEN MODEL WEIGHTS" MEANS, WITH RESPECT TO AN ARTIFICIAL INTELLIGENCE SYSTEM, THAT THE DEVELOPER: (a) PLACES THE ARTIFICIAL INTELLIGENCE SYSTEM IN THE PUBLIC DOMAIN WITHOUT ANY LICENSE OR RESERVATION OF RIGHTS OR MAKES THE ARTIFICIAL INTELLIGENCE SYSTEM AVAILABLE UNDER A LICENSE THAT ALLOWS ANY MEMBER OF THE PUBLIC TO COPY, DISTRIBUTE, MODIFY, AND USE THE ARTIFICIAL INTELLIGENCE SYSTEM'S MODEL WEIGHTS WITHOUT PERMISSION, PAYMENT, ROYALTIES, OR FEES; AND (b) PROVIDES SUFFICIENTLY DETAILED INFORMATION ABOUT OTHER COMPONENTS OF THE MODEL, ARTIFICIAL INTELLIGENCE SYSTEM, OR TRAINING DATA FOR A PERSON SKILLED IN ARTIFICIAL INTELLIGENCE TO CORRECTLY INTERPRET THE MODEL WEIGHTS AND UTILIZE THEM EFFECTIVELY IN OTHER ARTIFICIAL INTELLIGENCE SYSTEMS.
(11)(a) "Substantial factor" means, EXCEPT AS PROVIDED IN SECTION 6-1-1703 (6.7), a factor that: (11.7) "TIME-LIMITED DECISION" MEANS A DECISION RELATING TO A GOOD, A SERVICE, OR AN OPPORTUNITY THAT HAS AN END OR EXPIRATION DATE THAT IS ESTABLISHED PRIOR TO THE COMMENCEMENT OF THE DECISION-MAKING PROCESS.
(13) "UNITARY BUSINESS" MEANS A SINGLE ECONOMIC ENTERPRISE MADE UP EITHER OF SEPARATE PARTS OF A SINGLE ENTITY OR OF AN AFFILIATED GROUP OF ENTITIES THAT ARE SUFFICIENTLY INTERDEPENDENT, INTEGRATED, AND INTERRELATED THROUGH THEIR ACTIVITIES SO AS TO PROVIDE A SYNERGY AND MUTUAL BENEFIT THAT PRODUCES A SHARING OR EXCHANGE OF VALUE AMONG THEM AND A SIGNIFICANT FLOW OF VALUE TO THE SEPARATE PARTS.
(14) "VENDOR" MEANS A PERSON THAT KNOWINGLY SELLS, OFFERS FOR SALE, OR DISTRIBUTES AN ARTIFICIAL INTELLIGENCE SYSTEM TO A DEPLOYER OR TO ANOTHER VENDOR.
Requires high-risk AI system developers to provide documentation and information for impact assessments starting January 1, 2027.
SECTION 2. In Colorado Revised Statutes, 6-1-1702, amend (2) introductory portion, (2)(a), (2)(c)(III), (3)(a), (4), (6), and (7); repeal (1) and (5); and add (8) and (9) as follows: 6-1-1702. Developer duty to avoid algorithmic discrimination - required documentation - applicability - exempt developers. (1)
(2) On and after JANUARY 1, 2027, except as provided in subsection (6) of this section, a developer of a high-risk artificial intelligence system shall make available to the EACH deployer or other developer of the high-risk artificial intelligence system: (a) A general statement describing the INTENDED uses and known harmful or inappropriate uses of the high-risk artificial intelligence system; (c) Documentation describing: (III) The intended INPUTS AND outputs of the high-risk artificial intelligence system;
(3)(a) Except as provided in subsection (6) of this section, a developer that offers, sells, leases, licenses, gives, or otherwise makes available to a deployer or other developer a high-risk artificial intelligence system on or after JANUARY 1, 2027, shall make available to the deployer or other developer, to the extent feasible, the documentation and information, through artifacts such as model cards, dataset cards, or other impact assessments, necessary for a deployer, or for a third party contracted by a deployer, to complete an impact assessment pursuant to section 6-1-1703 (3).
Requires developers to disclose and update information on high-risk AI systems and manage algorithmic discrimination risks.
(4)(a) On and after JANUARY 1, 2027, a developer shall make available, in a manner that is clear and readily available on the developer's website or in a public use case inventory, a statement summarizing: (I) The types of high-risk artificial intelligence systems that the developer has developed and currently makes available to a deployer or other developer; and (II) How the developer manages known or reasonably foreseeable risks of algorithmic discrimination that may arise from the development of the types of high-risk artificial intelligence systems described in accordance with subsection (4)(a)(I) of this section.
(b) A developer shall update the statement described in subsection (4)(a) of this section as necessary to ensure that the statement remains accurate.
Requires developers to maintain records for high-risk AI systems and allows the attorney general to request disclosures.
(6) Nothing in subsections (2) to (4) of this section requires a developer to disclose a trade secret, information OTHERWISE protected from disclosure by APPLICABLE state or federal law, or information that would create a security risk to the developer. IF A DEVELOPER WITHHOLDS INFORMATION FROM A DISCLOSURE PURSUANT TO THIS SUBSECTION (6), THE DEVELOPER SHALL NOTIFY THE PERSON THAT WOULD OTHERWISE HAVE A RIGHT TO RECEIVE THE INFORMATION, STATE THE BASIS FOR WITHHOLDING THE INFORMATION, AND PROVIDE ALL INFORMATION TO WHICH THE BASIS FOR WITHHOLDING DOES NOT APPLY. THE NOTIFICATION MUST COMPLY WITH THE REQUIREMENTS OF SECTION 6-1-1703 (4)(c).
(7)(a) A DEVELOPER SHALL MAINTAIN ALL DOCUMENTATION, DISCLOSURES, AND OTHER RECORDS REQUIRED BY SUBSECTIONS (2) TO (4) OF THIS SECTION WITH RESPECT TO EACH HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM THROUGHOUT THE PERIOD DURING WHICH THE DEVELOPER SELLS, MARKETS, DISTRIBUTES, OR MAKES AVAILABLE THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM AND FOR AT LEAST THREE YEARS FOLLOWING THE LAST DATE ON WHICH THE DEVELOPER SELLS, MARKETS, DISTRIBUTES, OR MAKES AVAILABLE THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM.
(b) On and after JANUARY 1, 2027, the attorney general may require that a developer disclose to the attorney general, no later than ninety days after the request and in a form and manner prescribed by the attorney general, the statement or documentation described in subsection (2) of this section OR THE RECORDS MAINTAINED PURSUANT TO SUBSECTION (7)(a) OF THIS SECTION. The attorney general may evaluate such THE statement, or documentation, OR RECORDS to ensure compliance with this part 17, and the statement, or documentation, is OR RECORDS ARE not subject to disclosure under the "Colorado Open Records Act", part 2 of article 72 of title 24. In a disclosure REQUIRED pursuant to this subsection (7), a developer may designate the statement, or documentation, OR RECORDS as including proprietary information or a trade secret OR INFORMATION OTHERWISE PROTECTED FROM DISCLOSURE BY THE "COLORADO OPEN RECORDS ACT", PART 2 OF ARTICLE 72 OF TITLE 24. To the extent that any information contained in the statement, or documentation, OR RECORDS includes information subject to attorney-client privilege or work-product protection, the disclosure does not constitute a waiver of the privilege or protection.
Exempts certain AI system developers making limited consequential decisions or producing consumer report outputs under FCRA compliance.
(8) SUBSECTIONS (2)(c), (2)(d), AND (4) OF THIS SECTION DO NOT APPLY TO A DEVELOPER THAT: (a) MEETS THE REQUIREMENTS OF SECTIONS 24-48.5-112 (1)(g)(III) AND (1)(g)(IV); AND (b) SELLS, DISTRIBUTES, OR OTHERWISE MAKES AVAILABLE TO DEPLOYERS HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEMS THAT DEPLOYERS USE TO MAKE: (I) BEGINNING APRIL 1, 2027, AND BEFORE MARCH 31, 2028, TEN THOUSAND OR FEWER CONSEQUENTIAL DECISIONS IN THE PRECEDING CALENDAR YEAR; (II) BEGINNING APRIL 1, 2028, AND BEFORE MARCH 31, 2029, FIVE THOUSAND OR FEWER CONSEQUENTIAL DECISIONS IN THE PRECEDING CALENDAR YEAR; AND (III) BEGINNING APRIL 1, 2029, AND BEFORE MARCH 31, 2030, TWO THOUSAND FIVE HUNDRED OR FEWER CONSEQUENTIAL DECISIONS IN THE PRECEDING CALENDAR YEAR.
(9) NOTHING IN THIS SECTION APPLIES TO A DEVELOPER OF AN ARTIFICIAL INTELLIGENCE SYSTEM TO THE EXTENT THAT: (a) THE ARTIFICIAL INTELLIGENCE SYSTEM PRODUCES OR CONSISTS OF A SCORE, A MODEL, AN ALGORITHM, OR SIMILAR OUTPUT THAT IS A CONSUMER REPORT, AS DEFINED BY AND SUBJECT TO THE "FAIR CREDIT REPORTING ACT", 15 U.S.C. SEC. 1681a (d)(1), RELATED REGULATIONS, AND PART 1 OF ARTICLE 18 OF TITLE 5; AND (b) THE DEVELOPER ADHERES TO THE "FAIR CREDIT REPORTING ACT", 15 U.S.C. SEC. 1681 ET SEQ., INCLUDING 15 U.S.C. SECS. 1681e AND 1681g.
Requires deployers to implement a risk management policy for high-risk AI systems starting January 2027.
SECTION 3. In Colorado Revised Statutes, 6-1-1703, amend (2)(a) introductory portion, (3)(a), (3)(b)(II), (3)(b)(III), (3)(b)(V), (3)(g), (4)(a) introductory portion, (4)(a)(II), (4)(b), (5)(a) introductory portion, (6), (8), and (9); repeal (1), (3)(c), (3)(f), and (7); and add (4)(d), (6.3), (6.5), (6.7), and (10) as follows: 6-1-1703. Deployer duty to avoid algorithmic discrimination - risk management policy and program - definitions.
(2)(a) On and after JANUARY 1, 2027, and except as provided in SUBSECTIONS (6) AND (8) of this section, a deployer of a high-risk artificial intelligence system shall implement a risk management policy and program to govern the deployer's deployment of the high-risk artificial intelligence system. The risk management policy and program must specify and incorporate the principles, processes, and personnel that the deployer uses to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination. The risk management policy and program must be an iterative process planned, implemented, and regularly and systematically reviewed and updated over the life cycle of a high-risk artificial intelligence system, requiring regular, systematic review and updates. A risk management policy and program implemented and maintained pursuant to this subsection (2) must be reasonable considering:
(3)(a) Except as provided in subsections (3)(d), (3)(e), and (6) (3)(d), (3)(e), (5), (6), AND (8) of this section, a deployer, or a third party contracted by the deployer, that deploys a high-risk artificial intelligence system on or after JANUARY 1, 2027, shall complete an impact assessment for the high-risk artificial intelligence system: (I) PRIOR TO THE FIRST DEPLOYMENT OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM OR JANUARY 1, 2027, WHICHEVER OCCURS LATER; and (II) ANNUALLY FOR AS LONG AS THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IS DEPLOYED.
(b) An impact assessment completed pursuant to this subsection (3) must include, at a minimum, and to the extent reasonably known by or available to the deployer: (II) An analysis of whether the deployment of the high-risk artificial intelligence system poses any known or reasonably foreseeable risks of: (A) Algorithmic discrimination and, if so, the nature of the algorithmic discrimination and the steps that have been taken to mitigate the risks; (B) LIMITING ACCESSIBILITY FOR INDIVIDUALS WHO ARE PREGNANT, BREASTFEEDING, OR DISABLED AND, IF SO, WHAT REASONABLE ACCOMMODATIONS THE DEPLOYER MAY PROVIDE THAT WOULD MITIGATE ANY SUCH LIMITATIONS ON ACCESSIBILITY; (C) AN UNFAIR OR DECEPTIVE TRADE PRACTICE DESCRIBED IN SECTION 6-1-105; (D) A VIOLATION OF STATE OR FEDERAL LABOR LAWS, INCLUDING LAWS PERTAINING TO WAGES, OCCUPATIONAL HEALTH AND SAFETY, AND THE RIGHT TO ORGANIZE; OR (E) A VIOLATION OF THE "COLORADO PRIVACY ACT", PART 13 OF THIS ARTICLE 1, IF APPLICABLE; (III) A description of the categories AND SOURCES of data THAT the high-risk artificial intelligence system processes as inputs and the outputs THAT the high-risk artificial intelligence system produces; (V) A DESCRIPTION OF any metrics used to evaluate the performance and known limitations of the high-risk artificial intelligence system, INCLUDING THE SYSTEM'S VALIDITY AND RELIABILITY; (c) BEGINNING JANUARY 1, 2027, a deployer, or a third party contracted by the deployer, must review the deployment of each high-risk artificial intelligence system deployed by the deployer ANNUALLY to ensure that the high-risk artificial intelligence system is not causing algorithmic discrimination.
Requires deployers to provide consumers detailed disclosures before deploying high-risk AI systems for consequential decisions.
(4)(a) On and after MAY 1, 2026, EXCEPT AS PROVIDED IN SUBSECTION (6) OF THIS SECTION, BEFORE EACH time that a deployer deploys a high-risk artificial intelligence system to make, or be a substantial factor in making, a consequential decision concerning a consumer, the deployer shall: (II) Provide to the consumer a statement disclosing: (A) The purpose of the high-risk artificial intelligence system and the nature of the consequential decision; (B) THE TRADE NAME OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM AND THE NAME OF THE DEVELOPER OR DEVELOPERS OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM; (C) The contact information for the deployer; (D) A description, in plain language, of the high-risk artificial intelligence system, and WHICH DESCRIPTION MUST, AT A MINIMUM, INCLUDE THE RESPECTIVE ROLES OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM AND ANY HUMAN COMPONENTS OF THE DECISION-MAKING PROCESS; THE PERSONAL ASPECTS CONCERNING THE CONSUMER'S ECONOMIC SITUATION, HEALTH, PERSONAL PREFERENCES, INTERESTS, RELIABILITY, BEHAVIOR, LOCATION, OR MOVEMENTS THAT THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM EVALUATES, ANALYZES, OR PREDICTS; THE METHOD BY WHICH THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM EVALUATES, ANALYZES, OR PREDICTS THOSE PERSONAL ASPECTS; HOW THOSE PERSONAL ASPECTS ARE RELEVANT TO THE CONSEQUENTIAL DECISIONS FOR WHICH THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IS USED; AND INFORMATION SUFFICIENT FOR CONSUMERS WITH DISABILITIES OR OTHER CONSUMERS ENTITLED TO ACCOMMODATION UNDER APPLICABLE LAW TO DETERMINE WHETHER THEY WILL REQUIRE ACCOMMODATION AND, IF SO, HOW TO REQUEST THE ACCOMMODATION; AND (E) Instructions on how to access the statement required by subsection (5)(a) of this section; and
Requires deployers of high-risk AI systems to notify consumers of adverse decisions and provide correction opportunities.
(b) On and after MAY 1, 2026, a deployer that has deployed a high-risk artificial intelligence system to make, or be a substantial factor in making, a consequential decision concerning a consumer shall, if the consequential decision is adverse to the consumer, provide to the consumer, WITHOUT UNREASONABLE DELAY AND NO LATER THAN THIRTY DAYS AFTER THE DECISION: (I) A SINGLE NOTICE THAT DISCLOSES: (A) THE MAIN REASON OR REASONS FOR THE CONSEQUENTIAL DECISION, including the degree to which, and manner in which, the high-risk artificial intelligence system contributed to the consequential decision AND THE CATEGORIES AND SOURCES OF DATA THAT ADVERSELY AFFECTED THE OUTPUT OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN MAKING, OR BEING A SUBSTANTIAL FACTOR IN MAKING, THE CONSEQUENTIAL DECISION, INCLUDING ANY CATEGORIES AND SOURCES OF SENSITIVE DATA, AS DEFINED IN SECTION 6-1-1303 (24); (B) INFORMATION ON WHETHER AND HOW THE CONSUMER CAN EXERCISE THEIR RIGHTS DESCRIBED IN SUBSECTION (4)(b)(II) OF THIS SECTION AND, IF APPLICABLE, SUBSECTION (4)(b)(III) OF THIS SECTION AND SECTION 6-1-1306 (1)(b) WITH RESPECT TO ANY PERSONAL DATA processed by the high-risk artificial intelligence system; (C) A COPY of the NOTICE PROVIDED TO THE CONSUMER PURSUANT TO THIS SUBSECTION (4)(b)(I); (II) An opportunity to correct any incorrect personal data that the high-risk artificial intelligence system processed in making, or as a substantial factor in making, the consequential decision IN THE SAME MANNER AS DESCRIBED IN SECTION 6-1-1306 (1)(c); and (III) FOR A CONSEQUENTIAL DECISION THAT IS NOT A COMPETITIVE DECISION, NOT A TIME-LIMITED DECISION, AND IS ADVERSE BASED ON INCORRECT PERSONAL DATA OR UNLAWFUL INFORMATION OR INFERENCES, an opportunity to appeal an THE adverse consequential decision concerning the consumer arising from the deployment of a high-risk artificial intelligence system, which appeal must, if technically feasible, allow for human review.
Prohibits using high-risk AI for consequential decisions without accurate compliance disclosures, effective January 1, 2027.
(d) A DEPLOYER SHALL NOT USE A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM TO MAKE, OR BE A SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL DECISION IF THE DEPLOYER CANNOT PROVIDE ACCURATE DISCLOSURES THAT SATISFY THE REQUIREMENTS OF SUBSECTIONS (4)(a) AND (4)(b)(I) OF THIS SECTION. (5)(a) On and after JANUARY 1, 2027, except as provided in subsection (6) of this section, a deployer shall make available, in a manner that is clear and readily available on the deployer's website, a statement summarizing: (6) Subsections (2), (4)(b)(II), (4)(b)(III), and (5) of this section do not apply to a deployer if, at the time the deployer deploys a THE high-risk artificial intelligence system and at all times while the high-risk artificial intelligence system is deployed: (a) The deployer: (I) BEGINNING JANUARY 1, 2027, AND BEFORE MARCH 31, 2028, employs fewer than fifty FIVE HUNDRED full-time equivalent employees and WORLDWIDE; (II) BEGINNING APRIL 1, 2028, AND BEFORE MARCH 31, 2029, EMPLOYS FEWER THAN TWO HUNDRED FIFTY FULL-TIME EQUIVALENT EMPLOYEES WORLDWIDE; AND (III) BEGINNING APRIL 1, 2029, EMPLOYS FEWER THAN ONE HUNDRED FULL-TIME EQUIVALENT EMPLOYEES WORLDWIDE; (a.5) Does THE DEVELOPER AND DEPLOYER DO not use the deployer's own data to train the high-risk artificial intelligence system; (b) The high-risk artificial intelligence system: (I) Is used for the intended uses that are disclosed to the deployer as required by section 6-1-1702 (2)(a); and (II) Continues learning based on data derived from sources other than the deployer's own data; and (c) The deployer makes available to consumers any impact assessment that: (I) The developer of the high-risk artificial intelligence system has completed and provided to the deployer; and (II) Includes information that is substantially similar to the information in the impact assessment required under subsection (3)(b) of this section.
Exempts deployers using high-risk AI for recruitment if specific employment criteria and requirements are met.
(6.3) NOTHING IN THIS SECTION APPLIES TO A DEPLOYER'S USE OF A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM TO THE EXTENT THAT: (a) THE DEPLOYER USES THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN CONSEQUENTIAL DECISIONS SOLELY RELATING TO THE RECRUITMENT, SOURCING, OR HIRING OF EXTERNAL CANDIDATES FOR EMPLOYMENT; (b) THE REQUIREMENTS OF SUBSECTIONS (6)(b) AND (6)(c) OF THIS SECTION ARE MET WITH RESPECT TO THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM; AND (c) THE DEPLOYER, AT THE TIME IT DEPLOYS THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM AND AT ALL TIMES WHILE THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IS DEPLOYED: (I) BEGINNING APRIL 1, 2026, AND BEFORE MARCH 31, 2027, EMPLOYS ANY NUMBER OF EMPLOYEES; (II) BEGINNING APRIL 1, 2027, AND BEFORE MARCH 31, 2029, EMPLOYS FEWER THAN FIVE HUNDRED FULL-TIME EQUIVALENT EMPLOYEES WORLDWIDE; (III) BEGINNING APRIL 1, 2029, AND BEFORE MARCH 31, 2030, EMPLOYS FEWER THAN TWO HUNDRED FIFTY FULL-TIME EQUIVALENT EMPLOYEES WORLDWIDE; AND (IV) BEGINNING APRIL 1, 2030, EMPLOYS FEWER THAN FIFTEEN FULL-TIME EQUIVALENT EMPLOYEES WORLDWIDE. (6.5) FOR PURPOSES OF SUBSECTIONS (6) AND (6.3) OF THIS SECTION, IF A DEPLOYER IS PART OF A UNITARY BUSINESS AND DEPLOYS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM THAT IS PROVIDED OR MADE AVAILABLE TO THE DEPLOYER THROUGH, OR THAT IS PAID IN WHOLE OR IN PART BY, ANOTHER ENTITY WITHIN THE UNITARY BUSINESS, THE CALCULATION OF THE NUMBER OF FULL-TIME EQUIVALENT EMPLOYEES WITH RESPECT TO THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IS BASED ON THE TOTAL NUMBER OF EMPLOYEES ACROSS THE UNITARY BUSINESS.
Applies specific subsections only to high-risk AI systems making consequential decisions without meaningful human involvement.
(6.7)(a) SUBSECTIONS (2), (3), (4)(b)(II), AND (4)(b)(III) OF THIS SECTION APPLY ONLY TO HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEMS THAT MAKE, OR ARE THE PRINCIPAL BASIS IN MAKING, CONSEQUENTIAL DECISIONS. (b)(I) AS USED IN THIS SUBSECTION (6.7), UNLESS THE CONTEXT OTHERWISE REQUIRES, "PRINCIPAL BASIS" MEANS THE USE OF THE OUTPUT OF A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM TO MAKE A CONSEQUENTIAL DECISION WITHOUT MEANINGFUL HUMAN INVOLVEMENT. (II) AS USED IN THIS SUBSECTION (6.7)(b), "MEANINGFUL HUMAN INVOLVEMENT" MEANS THAT A HUMAN: (A) ENGAGES IN A MEANINGFUL CONSIDERATION OF AVAILABLE DATA THAT IS USED OR PRODUCED AS OUTPUT BY THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM; AND (B) HAS THE AUTHORITY TO CHANGE OR INFLUENCE THE OUTCOME OF THE CONSEQUENTIAL DECISION. (7) Nothing in subsections (2) to (5) of this section requires a deployer to disclose a trade secret or information OTHERWISE protected from disclosure by APPLICABLE state or federal law. To the extent that a deployer withholds information FROM A DISCLOSURE pursuant to this subsection (8), the deployer shall notify the PERSON THAT WOULD OTHERWISE HAVE A RIGHT TO RECEIVE THE INFORMATION, STATE THE basis for the withholding, AND PROVIDE ALL INFORMATION TO WHICH THE BASIS FOR WITHHOLDING DOES NOT APPLY. NOTIFICATION THAT A DEPLOYER PROVIDES PURSUANT TO THIS SUBSECTION (8) MUST SATISFY THE REQUIREMENTS OF SUBSECTION (4)(c) OF THIS SECTION.
Requires deployers to maintain records of high-risk AI systems for three years post-deployment.
(9)(a) A DEPLOYER SHALL MAINTAIN ALL DOCUMENTATION, DISCLOSURES, AND OTHER RECORDS REQUIRED BY SUBSECTIONS (2) TO (5) OF THIS SECTION THROUGHOUT THE PERIOD DURING WHICH THE DEPLOYER DEPLOYS THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM AND FOR AT LEAST THREE YEARS FOLLOWING THE FINAL DEPLOYMENT OF EACH HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM BY THE DEPLOYER. (b) On and after February 1, 2026 JANUARY 1, 2027, the attorney general may require that a deployer, or a third party contracted by the deployer, disclose to the attorney general, no later than ninety days after the request and in a form and manner prescribed by the attorney general, the risk management policy implemented pursuant to subsection (2) of this section, the impact assessment completed pursuant to subsection (3) of this section, or the records maintained pursuant to subsection (3)(f) (9)(a) of this section. The attorney general may evaluate the risk management policy, impact assessment, or records to ensure compliance with this part 17, and the risk management policy, impact assessment, and records are not subject to disclosure under the "Colorado Open Records Act", part 2 of article 72 of title 24. In a disclosure pursuant to this subsection (9), a deployer may designate the statement, or documentation, OR RECORDS as including proprietary information or a trade secret OR INFORMATION OTHERWISE PROTECTED FROM DISCLOSURE BY APPLICABLE STATE OR FEDERAL LAW. To the extent that any information contained in the risk management policy, impact assessment, or records includes information subject to attorney-client privilege or work-product protection, the disclosure does not constitute a waiver of the privilege or protection. (10) NOTHING IN THIS SECTION CREATES A PRIVATE RIGHT OF ACTION OR PROVIDES A CONSUMER WITH ANY NEW OR ADDITIONAL RIGHTS UNDER ANY OTHER LAW, NOR DOES THIS SECTION LIMIT OR RESTRICT ANY PREEXISTING RIGHTS OR REMEDIES TO CONSUMERS OR PROVIDE ANY NEW OR ADDITIONAL DEFENSES TO DEPLOYERS, WITH RESPECT TO ANY OTHER LAW.
Requires AI system deployers to disclose AI interactions to consumers starting January 1, 2027.
SECTION 4. In Colorado Revised Statutes, 6-1-1704, amend (1) as follows: 6-1-1704. Disclosure of an artificial intelligence system to consumer. (1) On and after JANUARY 1, 2027, except as provided in subsection (2) of this section, a deployer or other developer that deploys, offers, sells, leases, licenses, gives, or otherwise makes available an artificial intelligence system that is intended to interact with consumers shall DISCLOSE to each consumer who interacts with the artificial intelligence system that the consumer is interacting with an artificial intelligence system.
Allows developers to conduct AI research before deployment and tackle security incidents, technical errors, and legal claims.
SECTION 5. In Colorado Revised Statutes, 6-1-1705, amend (1)(f), (1)(h), (3), (6), and (8)(a); repeal (1)(d), (2), (4), and (5); and add (1)(d.5), (1)(j), (1)(k), and (10) as follows: 6-1-1705. Compliance with other legal obligations - definitions. (1) Nothing in this part 17 restricts a developer's, a deployer's, or other person's ability to: (d) Investigate, establish, exercise, prepare for, or defend legal claims; (d.5) PROSECUTE OR DEFEND LEGAL CLAIMS DURING ONGOING OR IMMINENTLY ANTICIPATED LEGAL PROCEEDINGS, INCLUDING COMPLYING WITH THE RULES OF PROCEDURE, RULES OF EVIDENCE, OR OTHER APPLICABLE RULES OR ORDERS BEFORE A COURT, AN ADMINISTRATIVE ENFORCEMENT AGENCY, OR OTHER LEGAL TRIBUNAL OF COMPETENT JURISDICTION; (f) EXCEPT FOR USES of facial recognition technology OTHERWISE PROHIBITED BY APPLICABLE LAW, prevent, detect, protect against, or respond to security incidents OR ILLEGAL OR TORTIOUS ACTIVITY SUCH AS identity theft OR fraud OR investigate, report, or prosecute the persons responsible for THAT ILLEGAL OR TORTIOUS ACTIVITY; (h) Conduct research, testing, and development activities regarding an artificial intelligence system or model, other than testing conducted under real-world conditions, before the artificial intelligence system or model is USED TO MAKE, OR IS USED AS A SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL DECISION OR IS OTHERWISE placed on the market, deployed, or put into service, as applicable; or (j) EFFECTUATE A PRODUCT RECALL; OR (k) IDENTIFY AND REPAIR TECHNICAL ERRORS THAT IMPAIR EXISTING OR INTENDED FUNCTIONALITY.
Specifies Part 17 exemptions for AI systems used by federal entities or complying with federal law.
(2) AN ACT TAKEN BY A DEVELOPER, A DEPLOYER, OR OTHER PERSON TO COMPLY WITH THEIR OBLIGATIONS UNDER THIS PART 17 SHALL NOT BE CONSTRUED AS A WAIVER OF ANY EVIDENTIARY PRIVILEGE RECOGNIZED UNDER THE LAWS OF THIS STATE, AND NOTHING IN THIS PART 17 SHALL BE CONSTRUED AS LIMITING OR EXPANDING THE SCOPE OF ANY EVIDENTIARY PRIVILEGE RECOGNIZED under the laws of this state. (6) Nothing in this part 17 applies to any artificial intelligence system TO THE EXTENT that THE ARTIFICIAL INTELLIGENCE SYSTEM: (a) Is acquired by or for the federal government or any federal agency or department, including the United States department of commerce, the United States department of defense, or the national aeronautics and space administration; (b) IS NECESSARY TO COMPLY WITH APPLICABLE FEDERAL LAW; OR (c) HAS BEEN SPECIFICALLY APPROVED BY A FEDERAL AGENCY OR DEPARTMENT FOR USE IN MAKING A CONSEQUENTIAL DECISION.
Requires financial institutions to audit, mitigate discrimination, and notify consumers about high-risk AI system usage.
(8)(a) A bank, out-of-state bank, credit union chartered by the state of Colorado, federal credit union, out-of-state credit union, or any affiliate or subsidiary thereof is in full compliance with this part 17 if the bank, out-of-state bank, credit union chartered by the state of Colorado, federal credit union, out-of-state credit union, or affiliate or subsidiary is subject to examination by a state or federal prudential regulator under any published guidance or regulations that apply to the use of high-risk artificial intelligence systems, and the guidance or regulations, AT A MINIMUM, REQUIRE THE BANK, OUT-OF-STATE BANK, CREDIT UNION CHARTERED BY THE STATE OF COLORADO, FEDERAL CREDIT UNION, OUT-OF-STATE CREDIT UNION, OR AFFILIATE OR SUBSIDIARY TO: (I) Regularly audit the bank's, out-of-state bank's, credit union chartered by the state of Colorado's, federal credit union's, out-of-state credit union's, or affiliate's or subsidiary's use of high-risk artificial intelligence systems for compliance with state and federal anti-discrimination laws and regulations applicable to the bank, out-of-state bank, credit union chartered by the state of Colorado, federal credit union, out-of-state credit union, or affiliate or subsidiary; and (II) Mitigate any algorithmic discrimination caused by the use of a high-risk artificial intelligence system or any risk of algorithmic discrimination that is reasonably foreseeable as a result of the use of a high-risk artificial intelligence system; AND (III) NOTIFY AFFECTED CONSUMERS THAT THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IS BEING USED AND OF THE CATEGORIES AND SOURCES OF PERSONAL DATA IT PROCESSES WHEN IT MAKES, OR IS A SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL DECISION. (10) IF A DEVELOPER OR DEPLOYER WITHHOLDS INFORMATION PURSUANT TO A PROVISION IN THIS SECTION FOR WHICH DISCLOSURE WOULD OTHERWISE BE REQUIRED BY THIS PART 17, THE DEVELOPER OR DEPLOYER SHALL NOTIFY THE PERSON THAT WOULD OTHERWISE HAVE A RIGHT TO RECEIVE THE INFORMATION, STATE THE BASIS FOR WITHHOLDING THE INFORMATION, CITE THE PROVISION THAT AUTHORIZES THE WITHHOLDING OF THE INFORMATION, AND PROVIDE ALL INFORMATION TO WHICH THE BASIS FOR WITHHOLDING DOES NOT APPLY. THE NOTIFICATION MUST COMPLY WITH THE REQUIREMENTS OF SECTION 6-1-1703 (4)(c).
Grants exclusive enforcement authority to the Colorado Attorney General for AI-related violations starting January 1, 2027.
SECTION 6. In Colorado Revised Statutes, 6-1-1706, amend (1), (2), (3)(a) introductory portion, (3)(a)(III), (3)(b) introductory portion, (3)(b)(III), (4), and (5); repeal (3)(a)(I); and add (3)(a.5) and (3)(c) as follows: 6-1-1706. Enforcement by attorney general. (1) Notwithstanding section 6-1-103, the attorney general has exclusive authority to enforce this part 17 AND MAY INVESTIGATE AND ENFORCE VIOLATIONS OF THIS PART 17 BEGINNING ON JANUARY 1, 2027. (2) Except as provided in subsection (3) of this section, a EACH violation of the requirements established in this part 17 constitutes an unfair trade practice pursuant to section 6-1-105 (1)(hhhh). (3) In any action commenced by the attorney general to enforce this part 17, it is an affirmative defense that the developer, deployer, or other person: (a) DISCOVERED A CURABLE violation of this part 17 as a result of: (III) An internal review process; (a.5) CURED THE VIOLATION DESCRIBED IN SUBSECTION (3)(a) OF THIS SECTION WITHIN SEVEN DAYS AFTER ITS DISCOVERY; (b) WAS AT ALL RELEVANT TIMES otherwise in compliance with THIS PART 17 AND: (III) Any risk management framework for artificial intelligence systems that the attorney general, in the attorney general's discretion, if HAS designated AND publicly DISSEMINATED; AND (c) DEMONSTRATES THAT THE VIOLATION OF THIS PART 17 WAS INADVERTENT, AFFECTED FEWER THAN ONE THOUSAND CONSUMERS, AND WAS NOT THE RESULT OF NEGLIGENCE ON THE PART OF THE DEVELOPER, THE DEPLOYER, OR OTHER PERSON ASSERTING THE DEFENSE. (4) A developer, a deployer, or other person bears the burden of demonstrating that the requirements DESCRIBED in subsection (3) of this section FOR ESTABLISHING AN AFFIRMATIVE DEFENSE have been satisfied. (5) Nothing in this part 17, including the enforcement authority granted to the attorney general under this section, preempts or otherwise affects any right, claim, remedy, presumption, or defense available at law or in equity. AN affirmative defense established under this part 17 applies only to an enforcement action brought by the attorney general pursuant to this section and does not apply to any right, claim, remedy, presumption, or defense available at law or in equity.
Authorizes the attorney general to adopt rules for implementing and enforcing AI-related provisions in section 6-1-1707.
SECTION 7. In Colorado Revised Statutes, amend 6-1-1707 as follows: 6-1-1707. Rules. (1) The attorney general may ADOPT rules as necessary for the purpose of implementing and enforcing this part 17, including: (a) The documentation and requirements for developers pursuant to section 6-1-1702 (2); (b) The contents of and requirements for the notices and disclosures required by sections 6-1-1702 (3); 6-1-1703 (3) AND (4); and 6-1-1704; (c) The content and requirements of the risk management policy and program required by section 6-1-1703 (2); (d) The content and requirements of the impact assessments required by section 6-1-1703; (3); (e) The requirements for the affirmative defense set forth in section 6-1-1706 (3), including the process by which the attorney general will recognize any other nationally or internationally recognized risk management framework for artificial intelligence systems; AND (f) CLARIFICATION OF WHAT CONSTITUTES A "CONSEQUENTIAL DECISION", AS DEFINED IN SECTION 6-1-1701 (3).
Specifies the act's effective date, contingent on referendum results if a petition is filed.
SECTION 8. Act subject to petition - effective date. This act takes effect at 12:01 a.m. on the day following the expiration of the ninety-day period after final adjournment of the general assembly; except that, if a referendum petition is filed pursuant to section 1 (3) of article V of the state constitution against this act or an item, section, or part of this act within such period, then the act, item, section, or part will not take effect unless approved by the people at the general election to be held in November 2026 and, in such case, will take effect on the date of the official declaration of the vote thereon by the governor.