State guide
Colorado AI Governance Guide for Local Governments
A practical starting point for Colorado cities, counties, school districts, special districts, public libraries, public-safety agencies, and other local public entities evaluating, purchasing, or using AI-enabled systems.
Disclaimer
This resource is for policy and governance education only. It is not legal advice. Local governments should consult their attorney or legal counsel before making procurement, compliance, or deployment decisions.
On this page
- Colorado is in an implementation period
- At a glance
- State AI policy context
- What counts as a covered use
- Public records and AI-assisted work
- Retention and the three-year ADMT rule
- Facial recognition used by local government
- School facial-recognition limits
- Digital accessibility for public-facing AI
- Election deepfake disclosures
- Coverage under SB 26-189
- Developer documentation and updates
- Notice and adverse-outcome disclosures
- Correction and meaningful human review
- Enforcement, existing law, and contracts
- Conversational AI services from 2027
- Attorney General rulemaking in progress
- Correction to outdated summaries
- Colorado governance examples
- Recommended first 90 days
- Questions for counsel and records officers
- Colorado-specific procurement questions
- Implementation tracker
- Corrections and source updates
- Scope of this guide
- Official sources
Colorado is in an implementation period.
Senate Bill 26-189 repealed and reenacted Colorado’s earlier artificial-intelligence framework. Its principal requirements apply to consequential decisions made on or after January 1, 2027.[1][2]
The law now focuses on covered automated decision-making technology, developer documentation, deployer notices, adverse-outcome explanations, factual correction, meaningful human review, and records. It does not preserve the earlier law’s general impact-assessment and risk-management-program structure.[1][2]
On August 11, 2026, the Colorado Attorney General filed proposed implementing rules. They remain proposed, not final, as of September 22, 2026. Local governments should monitor the rulemaking and confirm the final requirements before January 1, 2027.[3][4]
Separate Colorado duties concerning facial recognition, school facial-recognition contracts, public records, records retention, and digital accessibility already require attention.[6][7][8][9][10]
Colorado Legislative Council’s September 8 final fiscal note reports that a federal court has temporarily restricted Attorney General enforcement of the state AI framework while rulemaking and litigation in X. AI LLC v. Weiser continue. The law remains enacted; the litigation affects enforcement timing rather than the statutory text or January 1, 2027 application date.[19]
Status summary
Enactment, operative duties, and enforcement are separate questions
Status summary
Enactment, operative duties, and enforcement are separate questions
SB 26-189 is enacted. Its principal developer, deployer, notice, recordkeeping, correction, and review duties apply to consequential decisions made on or after January 1, 2027. Separately, Colorado Legislative Council’s final fiscal note reports that a federal court ordered the Attorney General not to initiate enforcement of SB 24-205 or legislation amending it until the Attorney General completes rulemaking and the court issues a ruling in X. AI LLC v. Weiser. The fiscal note states that implementation and enforcement timing will depend on court actions.[19]
This litigation does not make the enacted text disappear and should not be treated as permission to ignore implementation. It does mean January 1, 2027 should not be presented as an unconditional enforcement date. Officials should confirm the current court and Attorney General status with counsel before relying on any enforcement statement.
At a glance
What Colorado local officials should know
At a glance
What Colorado local officials should know
The old Colorado AI Act summary is no longer a reliable checklist
January 1, 2027 is the central implementation date
Local-government coverage requires a use-specific legal analysis
SB 26-189 defines a deployer as a person doing business in Colorado that deploys covered automated decision-making technology. It expressly includes essential government services and public benefits among the covered domains, and it includes employees and Colorado-resident job applicants within the consumer definition.[2]
The act does not create a simple “all municipalities are covered” rule or a general local-government exemption. Counsel should determine how the definitions apply to the particular public entity, vendor relationship, system, and decision. As an operational precaution, local entities should prepare for coverage when technology materially influences essential-service, public-benefit, employment, education, housing, financial, insurance, or health-care decisions.
Facial-recognition duties already apply directly to state and local agencies
Colorado’s facial-recognition law requires notices of intent, accountability reports, testing, meaningful human review for significant decisions, training, and auditable records. It also imposes additional restrictions on law-enforcement uses.[6]
Accessibility belongs inside AI procurement
Colorado’s technology-accessibility rules apply to state and local public entities. Public-facing AI interfaces, notices, explanations, request forms, and alternative-access processes should be reviewed as information and communication technology, not treated as ordinary vendor marketing pages.[9][10][20][21]
Public-record and retention questions begin before deployment
Prompts, outputs, recommendations, notices, correction requests, review records, logs, and vendor communications may require classification under the Colorado Open Records Act, applicable retention schedules, litigation holds, and use-specific law. Not every AI interaction is automatically public, confidential, permanent, or disposable.[8]
State AI policy context
Overlapping layers of Colorado AI governance
State AI policy context
Overlapping layers of Colorado AI governance
- SB 26-189, the enacted automated decision-making framework for covered consequential decisions beginning January 1, 2027.
- HB 26-1263, the enacted conversational-AI safety framework for operators beginning January 1, 2027.
- Existing facial-recognition requirements that directly govern state and local agencies.
- School-specific facial-recognition limits that restrict covered public-school contracts and require local policy, notice, access, and oversight controls.
- Public-records, retention, accessibility, anti-discrimination, employment, education, due-process, privacy, security, and sector-specific duties that continue to apply according to the use.
- State executive-branch GenAI policy and guidance, which may offer a useful governance model but should not be presented as a statewide mandate for municipalities.
- Pending federal litigation affecting enforcement, which does not repeal SB 26-189 but may affect when the Attorney General can enforce it.
Colorado’s Artificial Intelligence Impact Task Force produced policy research and recommendations and is now undergoing sunset review. Its reports may provide background, but they are not local-government requirements and the task force should not be described as an active regulatory authority.[13]
Local-government meaning
One label is not a coverage analysis
Local-government meaning
One label is not a coverage analysis
A Colorado local government should not use one label — “AI,” “chatbot,” “decision support,” or “facial recognition” — as a substitute for a coverage analysis. Different systems may trigger different duties based on:
- the public entity and department involved;
- the system's intended and actual use;
- whether personal data is processed;
- whether the output materially influences a consequential decision;
- whether the use involves facial recognition or biometric processing;
- whether the system is offered directly to the public;
- whether minors, students, applicants, employees, patients, benefit recipients, tenants, or other protected populations are affected;
- whether a vendor develops, operates, hosts, or changes the system; and
- which records, accessibility, security, civil-rights, employment, education, and appeal requirements apply independently.
What applies now
Colorado public records and AI-assisted government work
What applies now
Colorado public records and AI-assisted government work
The Colorado Open Records Act generally requires most public records to be available for inspection, subject to statutory exceptions. The Colorado Secretary of State describes a public record as including most writings made, maintained, or kept by a government office and recognizes electronic delivery of records.[8]
What this may mean for AI
Depending on their purpose, content, custody, and relationship to public business, relevant records may include:
- prompts submitted by employees or contractors;
- generated drafts or final outputs used in agency work;
- recommendations, rankings, scores, flags, or classifications;
- system and model version identifiers;
- input-data descriptions;
- notices and adverse-outcome explanations;
- correction, reconsideration, and appeal requests;
- human-review notes and final actions;
- incident reports, test results, monitoring records, and audit logs;
- vendor documentation, release notes, and material-update notices; and
- messages or records held in a vendor-hosted environment.
This does not mean every prompt, temporary output, or technical log is automatically a public record or must be kept permanently. The records custodian and counsel should classify records according to the applicable statute, exemption, retention schedule, legal hold, and operational need.
Questions for the records custodian
- 01Which AI-related records document the organization, functions, policies, decisions, procedures, operations, or other public business of the entity?
- 02Which records are transitory, drafts, duplicates, or working material, and which form part of the official record?
- 03Which records contain confidential, privileged, security-sensitive, personnel, student, health, criminal-justice, or other protected information?
- 04Can the agency search, export, review, redact, and produce relevant records without depending entirely on the vendor?
- 05Does the contract preserve records when a request, audit, investigation, appeal, or litigation hold is pending?
- 06Which local retention schedule has been approved for the entity, and how does it map to each AI record category?
Recommended governance action
Add an AI-records section to the system inventory. For each system, record the likely official records, custodian, repository, retention rule, export method, confidentiality issues, and disposition process. Do not allow default vendor deletion settings to determine the public entity’s retention practice.
What applies now
Records retention and the future three-year ADMT requirement
What applies now
Records retention and the future three-year ADMT requirement
Colorado public entities should follow the retention schedule and records-management authority applicable to the entity. Colorado State Archives maintains records-management resources, and the Colorado Municipal Records Retention Schedule is used by municipalities after approval for the particular municipality.[14]
Beginning January 1, 2027, a covered deployer under SB 26-189 must retain records reasonably necessary to demonstrate compliance for at least three years after the consequential decision, or longer when other state or federal law requires. The act identifies system-version information, change logs, and documentation of material mitigation changes as examples.[2]
Practical implication
The three-year ADMT period is a statutory floor for covered compliance records, not a universal destruction date. Employment, student, benefit, public-record, audit, litigation-hold, grant, contract, or other rules may require a different or longer period.
Minimum inventory fields
- system and vendor;
- department and owner;
- intended use;
- actual decision or workflow supported;
- affected population;
- covered-domain assessment;
- system and model version;
- developer documentation received;
- material updates and dates;
- inputs and personal-data categories;
- outputs and decision weight;
- notice location;
- adverse-outcome workflow;
- correction and review pathway;
- records custodian;
- retention schedule and legal holds;
- accessibility owner;
- last test and review date; and
- suspension or termination authority.
What applies now
Facial recognition used by local government
What applies now
Facial recognition used by local government
Colorado’s enacted facial-recognition law directly addresses state and local government agencies, including public institutions of higher education.[6]
An agency that uses or intends to develop, procure, or use a facial-recognition service must file a notice of intent with the applicable reporting authority and identify the proposed purpose. For a local agency, the reporting authority is generally the city council, county commission, or other local body vested with legislative power. After the notice, the agency must prepare and adopt an accountability report addressing the proposed use.[6]
The law also requires, among other things:
- operational testing before deployment in contexts involving decisions with legal or similarly significant effects;
- meaningful human review of covered significant decisions;
- periodic training for people operating the system or processing data obtained from it;
- records sufficient for public reporting and compliance auditing; and
- additional restrictions for law-enforcement surveillance, identification, tracking, protected activity, probable-cause determinations, image manipulation, and criminal-defendant notice.
Local-government action
Do not purchase or pilot facial recognition as an ordinary software feature. Route the proposal through counsel, the governing body or designated reporting authority, procurement, public safety leadership when relevant, records, privacy, security, accessibility, and community-engagement review before activation.
Questions to ask
- 01Does the product perform face detection, face analysis, verification, identification, matching, clustering, or another operation that may fall within the statutory definition?
- 02Has the required notice of intent been filed with the correct reporting authority?
- 03Has the accountability report been adopted, disclosed, and updated as required?
- 04Has the system been tested under the agency's intended operational conditions and affected population?
- 05What threshold, candidate list, confidence measure, and human-review procedure will be used?
- 06Can a human reviewer reject the result and examine primary evidence?
- 07What records support public reporting and audit?
- 08Do the law-enforcement restrictions apply?
- 09Does a school-specific restriction also apply?
What applies now
School facial-recognition limits
What applies now
School facial-recognition limits
SB 25-143 removed the former July 1, 2025 sunset from Colorado’s school facial-recognition contracting restriction and created limited exceptions. The act requires notice when facial-recognition software is used and requires each school district to develop a policy with access, oversight, and authorized-personnel controls.[7]
The listed exceptions include certain existing contracts, curriculum-related uses, and narrowly described safety uses involving a significant threat, a missing student believed to remain on school grounds, or a person ordered to stay off school property. The act also restricts processing of biometric identifiers without consent and authorizes injunctive relief for violations.[7]
School-district governance questions
- 01Does any safety, attendance, device, testing, library, visitor-management, or camera product contain facial-recognition functionality?
- 02Is the feature enabled, disabled, or capable of remote activation?
- 03Does an exception actually cover the intended use?
- 04Has the district adopted the required policy and designated authorized personnel?
- 05What notice, consent, access, deletion, incident, and oversight procedures apply?
- 06Can the district prove that biometric processing remains within the authorized purpose?
Do not treat a vendor’s description of a feature as conclusive legal classification.
What applies now
Digital accessibility for public-facing AI
What applies now
Digital accessibility for public-facing AI
Colorado’s technology-accessibility framework applies to state and local public entities, including local departments, agencies, special districts, and instrumentalities. Colorado OIT’s official guidance explains that the standards apply to technology in use and to technology created, purchased, or updated. HB 21-1110 established the state and public-entity accessibility requirements, while HB 24-1454 provided only a limited good-faith immunity period that ended July 1, 2025; it did not eliminate the underlying accessibility duty.[9][10][20][21]
Public-facing AI may include:
- chatbots and virtual assistants;
- application or benefit-screening portals;
- employment and recruiting interfaces;
- resident request or complaint tools;
- translation, transcription, and document-generation services;
- AI-generated notices, letters, forms, and PDFs;
- automated telephone or voice services;
- maps, dashboards, and data visualizations; and
- correction, reconsideration, appeal, and human-review request forms.
Procurement and implementation implications
- 01Treat accessibility as a mandatory product and contract requirement, not post-launch remediation.
- 02Require accessibility documentation, testing access, defect reporting, remediation timelines, and cooperation with accommodation requests.
- 03Test the full workflow, including authentication, notices, generated content, forms, attachments, error messages, and escalation to a person.
- 04Provide an effective alternative-access route when a barrier is identified.
- 05Confirm that model or interface updates do not silently break accessibility.
SB 26-189 separately requires its notices and disclosures to be reasonably accessible to consumers with disabilities and people with limited English proficiency, consistent with applicable law.[2]
What applies now
Election deepfakes: a narrow but relevant disclosure law
What applies now
Election deepfakes: a narrow but relevant disclosure law
Colorado’s HB 24-1147 requires specified disclaimers on covered communications that are generated or substantially altered by artificial intelligence and falsely depict what a candidate or officeholder said or did. The law provides civil remedies and penalties in the circumstances it covers.[15]
What this does not mean
The law is not a universal disclosure rule for every AI-assisted local-government communication. Election officials, public-information staff, elected officials, campaigns, and counsel should determine whether a particular communication falls within the statute and should maintain authentication and rapid-response procedures for false election content.
What changes on January 1, 2027
Coverage under SB 26-189
What changes on January 1, 2027
Coverage under SB 26-189
SB 26-189 regulates covered automated decision-making technology, or covered ADMT.[2]
An ADMT is technology that:
- processes personal data;
- uses computation to generate an output such as a prediction, recommendation, classification, ranking, score, or other information; and
- uses that output to make, guide, or assist a decision, judgment, or determination about an individual.
It becomes covered ADMT when it is used to materially influence a consequential decision. Material influence requires more than an incidental, trivial, or clerical role: the output must be a non-de minimis factor and affect the outcome by constraining, ranking, scoring, recommending, classifying, or otherwise meaningfully altering how the decision is made.[2]
Covered domains
Consequential decisions concern access to, eligibility for, selection for, compensation for, provision of, price of, or other material terms in:
- education enrollment or opportunity;
- employment or an employment opportunity;
- lease or purchase of residential real estate in Colorado;
- financial or lending services;
- insurance;
- health-care services; or
- essential government services and public benefits, including eligibility and renewal determinations.
Potential local-government examples
Use-specific legal review may be warranted for systems that influence:
- hiring, promotion, discipline, termination, compensation, or applicant screening;
- enrollment, placement, scholarship, or education-opportunity decisions;
- housing applications, tenant selection, or housing assistance;
- utility, emergency-assistance, transportation, recreation, or other essential-service eligibility;
- public-benefit applications, renewals, prioritization, or fraud flags;
- patient financial assistance or health-service access in a covered public-health setting; and
- another decision that may fit a listed covered domain.
Uses the act excludes
The enacted text excludes specified infrastructure and low-impact uses. Examples include:
- calculators, ordinary databases, data storage, firewalls, networking, spell-checking, web hosting, and certain spreadsheets;
- a tool used solely to summarize, organize, translate, draft, route, or present information for human review of administrative processing;
- certain public-facing conversational tools that provide information, referrals, recommendations, answers, or content when they are not intended, configured, marketed, or contracted for consequential decisions and are governed by an acceptable-use policy prohibiting that use;
- routine scheduling, classroom personalization, administrative routing, customer-service triage, communication of decisions, and workflow management that do not materially influence a covered outcome;
- narrow procedural or data-processing functions that do not generate a prediction or inference about a consumer or materially influence the decision; and
- specified cybersecurity, fraud-prevention, sanctions, anti-money-laundering, and similar activities.
Coverage test for local officials
- 01Does the technology process personal data about an individual?
- 02Does it generate a score, ranking, recommendation, classification, prediction, or comparable output?
- 03Is that output used to make, guide, or assist a decision about the individual?
- 04Is the decision within a listed covered domain?
- 05Is the output a non-trivial factor that affects the result or how the decision is made?
- 06Does a statutory exclusion or sector-specific accommodation apply?
- 07Is the public entity, vendor, or another party the developer, deployer, operator, or more than one of these?
Record the reasoning. Do not classify a system solely from the vendor’s product name.
What changes on January 1, 2027
Developer documentation and material updates
What changes on January 1, 2027
Developer documentation and material updates
Beginning January 1, 2027, a covered developer must make specified documentation reasonably understandable to deployers while protecting trade secrets and legally protected information.[2]
The documentation includes:
- intended uses;
- known harmful or inappropriate uses;
- categories of training data, including personal data, to the extent known;
- known limitations, risks, and circumstances in which the system should not be used;
- instructions for appropriate use, monitoring, and meaningful human review when applicable; and
- information reasonably necessary for the deployer to meet its statutory duties.
Developers must also give deployers notice of material updates, intentional and substantial modifications, and relevant changes to intended use, limitations, or risk mitigation within a reasonable time. Covered developers must retain specified compliance records for at least three years.[2]
Procurement implication
A promise that a system is “compliant” is not enough. The contract should require the documentation the public entity needs, identify when and how updates will be delivered, preserve version history, and provide a remedy when the vendor withholds information needed for lawful deployment.
What changes on January 1, 2027
Deployer notice and adverse-outcome disclosures
What changes on January 1, 2027
Deployer notice and adverse-outcome disclosures
Before covered ADMT materially influences a consequential decision, a deployer must provide clear and conspicuous notice that covered ADMT was or will be used and explain how the individual may obtain additional information. A prominent public notice reasonably accessible at the point of interaction may satisfy the advance-notice requirement.[2]
When covered ADMT materially influences a consequential decision that results in an adverse outcome, the deployer must provide, within 30 days:
- a plain-language description of the decision and the role of the covered ADMT;
- a simple process for requesting additional information;
- available information concerning the system name, version, developer, and types, categories, and sources of personal data used; and
- an explanation of the individual's correction and meaningful-human-review rights and how to exercise them.
The notices and disclosures must be reasonably accessible to people with disabilities and people with limited English proficiency, consistent with applicable law.[2]
Important implementation point
A general AI statement buried in a privacy policy may not support the operational needs of the statute. The entity should map the notice to the actual point of interaction, decision, delivery channel, responsible office, affected language, accessibility requirement, and records process.
What changes on January 1, 2027
Correction, meaningful human review, and reconsideration
What changes on January 1, 2027
Correction, meaningful human review, and reconsideration
After an adverse outcome involving covered ADMT, a consumer may request instructions for obtaining and correcting factually incorrect or materially inaccurate personal data used in the decision. The statute does not require correction of opinions, predictions, scores, or protected evaluations.[2]
The consumer may also request meaningful human review and reconsideration to the extent commercially reasonable.[2]
Under the enacted definition, meaningful human review is conducted by a trained person who:
- has authority to approve, modify, or override the consequential decision;
- considers relevant and available primary evidence;
- does not default to the system output; and
- has enough information to understand the output's intended use, material limitations, input categories, and principal factors without requiring disclosure of protected source code, model weights, or trade secrets.
Local-government workflow
For each covered decision, designate:
- the office receiving a request;
- acceptable submission channels;
- the person authenticating the requester;
- the system and data owner;
- the reviewer and backup reviewer;
- the reviewer's decision authority;
- the primary evidence available;
- the deadline and communication channel;
- the record of the review and result; and
- the process for correcting source data and rerunning or reconsidering the decision when appropriate.
A person who merely restates the model’s score without authority, training, primary evidence, or the ability to change the outcome is not a meaningful reviewer.
What changes on January 1, 2027
Enforcement, existing law, and contracts
What changes on January 1, 2027
Enforcement, existing law, and contracts
The Colorado Attorney General has exclusive authority to enforce the disclosure, recordkeeping, and consumer-rights provisions of SB 26-189 through the Colorado Consumer Protection Act. A violation is treated as a deceptive trade practice. The act does not create a new private right of action.[2]
Before January 1, 2030, the Attorney General generally must provide a 60-day notice and opportunity to cure when a cure is considered possible. That cure process is not required for a knowing or repeated violation.[2]
The act preserves existing rights and remedies under anti-discrimination, consumer-protection, product-liability, and other law. Compliance with SB 26-189 is not a defense to a separate violation.[2]
The act also addresses allocation of fault between developers and deployers in actions alleging unlawful discrimination under existing law. A contract provision that purports to indemnify a party against liability for its own acts or omissions in specified Colorado anti-discrimination violations involving covered ADMT is contrary to public policy and void.[2]
Current enforcement litigation
Colorado Legislative Council’s September 8, 2026 final fiscal note reports that, on April 27, 2026, a federal court ordered the Attorney General not to initiate enforcement of SB 24-205 or legislation amending it until the Attorney General completes rulemaking and the court issues a ruling in X. AI LLC v. Weiser. The fiscal note further states that the timing of implementation and enforcement will depend on court actions.[19]
This is an enforcement-status issue, not a repeal of SB 26-189. Because the order and litigation may change, local officials should verify the current case posture and Attorney General position immediately before making a compliance or enforcement representation.
Procurement implication
Counsel should review indemnity, defense, insurance, limitation-of-liability, audit, documentation, update, incident, and cooperation terms in light of the enacted allocation rules. Do not assume that a broad vendor indemnity transfers the public entity’s own statutory or civil-rights responsibility.
What changes on January 1, 2027
Conversational AI services beginning January 1, 2027
What changes on January 1, 2027
Conversational AI services beginning January 1, 2027
HB 26-1263 applies to operators that develop and make publicly available, or offer to consumers, conversational artificial-intelligence services that primarily simulate human conversation through adaptive text, visual, or audio communications.[5]
The statutory definition includes significant exclusions. Depending on the product’s design and use, excluded services may include certain commerce-related or transactional assistance and customer-service tools; narrow-topic tools that cannot generate specified sexual content or sustain self-harm dialogue; tools designed for internal business use; certain healthcare uses; certain limited educational tools; and conversational features embedded in another application that are not designed to simulate emotional companionship. Counsel should review the enacted text before classifying a municipal chatbot.[5]
The act includes requirements concerning:
- disclosure that the user is interacting with artificial intelligence rather than a person;
- commercially reasonable or generally accepted age-estimation methods;
- additional protections for known minor users and account holders;
- protocols for suicidal ideation or self-harm prompts;
- restrictions on representations that outputs are equivalent to or endorsed by specified licensed professionals; and
- annual reporting to the Attorney General concerning the self-harm protocol.
Local-government meaning
A city or county that simply purchases a vendor chatbot should not assume that every operator duty belongs only to the vendor. Counsel should examine whether the public entity, vendor, integrator, or more than one party develops, controls access to, makes publicly available, or offers the service.
At minimum, a local chatbot contract should identify:
- who is the statutory operator;
- where the AI disclosure appears;
- whether accounts or profiles are created;
- whether the service is available to minors;
- what age-assurance, privacy, safety, escalation, and reporting controls apply;
- what the bot is prohibited from representing;
- how emergency or self-harm prompts are handled;
- which transcripts and safety events are retained;
- how the public entity can suspend the service; and
- how operator compliance is documented.
Do not confuse the chatbot-safety law with SB 26-189. A public chatbot may be subject to one, both, or neither framework depending on how it is offered and whether it materially influences a consequential decision.
Pending rulemaking
Attorney General rulemaking in progress
Pending rulemaking
Attorney General rulemaking in progress
On August 11, 2026, the Colorado Attorney General filed proposed Automated Decision-Making Technology and Conversational Artificial Intelligence Service rules. As of September 22, 2026, the rules remain proposed. Formal comments are being accepted through October 26, 2026. The Attorney General requested comments by September 4 for consideration in a revised proposed draft expected no later than September 23.[3][4]
Proposed rules — not final as of September 22, 2026
The draft rules would add detailed requirements concerning plain-language and accessible communications, delivery methods, adverse-outcome explanations, consumer-request interfaces, authentication, correction, human review, and chatbot safeguards. These provisions may change during rulemaking and should not be presented as final requirements.[3][4]
Preparation that is useful even while the rules are pending
- 01Identify all potentially covered systems and decisions.
- 02Obtain developer documentation and version information.
- 03Draft point-of-interaction notices.
- 04Build accessible and multilingual communication workflows.
- 05Create a simple intake route for data, correction, and human-review requests.
- 06Identify qualified reviewers with authority to change decisions.
- 07Test whether records can support a specific adverse-outcome explanation.
- 08Confirm the ability to authenticate a requester without excessive data collection.
- 09Schedule a final rule-to-process comparison before January 1, 2027.
Do not lock final notice language or operational deadlines until the final rules are reviewed.
Important correction
Outdated Colorado summaries are no longer accurate
Important correction
Outdated Colorado summaries are no longer accurate
Do not describe Colorado's current framework primarily as an “impact-assessment law.”
SB 26-189 repealed and reenacted the earlier framework. The enacted 2026 law focuses on covered ADMT, developer documentation, material-update notices, deployer records, point-of-interaction notice, adverse-outcome explanations, factual correction, meaningful human review, Attorney General enforcement, and allocation of fault under existing anti-discrimination law.[1][2]
Risk assessments and impact assessments may still be valuable governance practices, may be required by another law or policy, and remain part of Colorado executive-branch GenAI governance. They should not be presented as a universal SB 26-189 requirement.[11][12]
Colorado governance examples
Models and local examples — not statewide mandates
Colorado governance examples
Models and local examples — not statewide mandates
State executive-branch GenAI policy
Colorado OIT’s AI guide states that GenAI efforts and use cases for covered state agencies, including third-party vendor projects, must go through OIT risk assessment. State-agency responsibilities include system intake, inventory, security and privacy review, risk-tiered testing, monitoring, and controls for sensitive information.[11][12]
Important qualification
This is a state executive-branch governance model. Do not describe the OIT intake process as a legal requirement for every city, county, school district, or special district.
Practical lessons
- Use a single intake route for AI-enabled products and features.
- Include vendor features and material changes.
- Connect risk classification to testing and approval frequency.
- Do not allow employees to accept consumer software terms on behalf of the public entity.
- Protect nonpublic information and require human validation of official work.
City of Boulder: capacity building and responsible experimentation
In January 2026, Boulder announced its participation in a three-year municipal emerging-technology initiative. The city described plans to build staff capacity, create responsible-use policies and procedures, identify service opportunities, and pilot community-focused applications while protecting privacy, equity, transparency, and public trust.[16]
Boulder’s digital-accessibility plan separately describes a citywide program with leadership, a cross-department steering committee, third-party software assessments, accessibility review in renewals, contract language, testing, remediation, and alternative access.[17]
Practical lessons
- Combine experimentation with governance capacity.
- Give one team responsibility for coordination without removing departmental ownership.
- Integrate accessibility and vendor review into renewals.
- Use pilots to test service value, risk controls, resident experience, and exit criteria before broad deployment.
Colorado school guidance
The Colorado Department of Education maintains an AI resource page for schools and districts and links to the Colorado Roadmap for AI in K-12 Education and related policy materials.[18]
Important qualification
Educational guidance and roadmaps are not substitutes for FERPA, district policy, collective-bargaining obligations, accessibility requirements, facial-recognition restrictions, SB 26-189 coverage analysis, or counsel’s review.
Recommended first 90 days
A sequenced starting plan
Recommended first 90 days
A sequenced starting plan
Days 1–30: Inventory and classify
- 01Inventory AI, ADMT, facial-recognition, biometric, and chatbot features across departments.
- 02Include embedded, optional, beta, and vendor-activated features inside existing software.
- 03Identify systems affecting employment, education, housing, finance, insurance, health care, essential services, or public benefits.
- 04Record what personal data is processed and what output is generated.
- 05Determine whether the output merely assists administration or materially influences a result.
- 06Identify facial-recognition uses and confirm notice, accountability-report, testing, training, human-review, and records status.
- 07Identify public-facing interfaces subject to accessibility review.
- 08Assign a business owner, records custodian, technical owner, counsel contact, accessibility owner, and reviewer for each potentially consequential system.
Days 31–60: Repair contracts and workflows
- 01Obtain each developer's intended-use, training-data-category, limitation, monitoring, and human-review documentation.
- 02Add material-update notice, version history, audit, export, retention, accessibility, language-access, incident, and cooperation terms.
- 03Draft point-of-interaction notices for potentially covered uses.
- 04Create the adverse-outcome explanation workflow.
- 05Create the personal-data access and factual-correction workflow.
- 06Designate human reviewers with training, evidence access, independence, and authority to change outcomes.
- 07Confirm which party is developer, deployer, chatbot operator, records custodian, and system host.
- 08Review indemnity and liability terms with counsel.
Days 61–90: Test and approve
- 01Test whether the entity can reconstruct a consequential decision from source data, system version, output, human action, and final result.
- 02Run a sample adverse-outcome notice and correction request end to end.
- 03Test the human-review process with an error, missing fact, atypical case, and disputed inference.
- 04Test notices and request channels for disability access, mobile use, and the languages in which the entity serves the public.
- 05Confirm that covered records can be retained for at least three years and longer when required.
- 06Establish an escalation and suspension procedure.
- 07Train procurement, HR, benefits, education, IT, records, public-safety, communications, and service-delivery staff.
- 08Schedule a final update when the Attorney General adopts final rules and before January 1, 2027.
For counsel and records officers
Questions for the city or county attorney and records officer
For counsel and records officers
Questions for the city or county attorney and records officer
- 01Does this public entity qualify as a developer, deployer, operator, or another regulated party for this use?
- 02Does the system process personal data and generate a covered output about an individual?
- 03Does the output materially influence a consequential decision in a covered domain?
- 04Does an exclusion, FERPA process, HIPAA accommodation, insurance provision, credit-notice rule, or other sector-specific rule apply?
- 05Which anti-discrimination, employment, education, due-process, housing, benefits, health, accessibility, privacy, or appeal laws apply independently?
- 06Which prompts, outputs, notices, requests, reviews, logs, and vendor communications are public records?
- 07Which CORA exceptions or confidentiality provisions apply?
- 08Which retention schedule applies, and is the three-year ADMT period longer or shorter than another requirement?
- 09Does the facial-recognition law apply to any component?
- 10Does the school facial-recognition restriction apply?
- 11Does the public entity or vendor qualify as the operator of a conversational AI service?
- 12Can the entity lawfully and practically provide required explanations without disclosing protected information?
- 13Is the human-review process meaningful and authorized under the statute and any existing appeal process?
- 14Are notices and request channels accessible to people with disabilities and limited English proficiency?
- 15Do contract terms preserve responsibility, evidence, cooperation, and remedies consistent with Colorado law?
Colorado-specific procurement questions
Questions to work through before buying or renewing
Colorado-specific procurement questions
Questions to work through before buying or renewing
- 01AI and ADMT features — Does the product include machine learning, a foundation model, a large language model, automated ranking, scoring, prediction, recommendation, classification, generation, facial recognition, biometric analysis, or conversational AI? Identify every base, optional, beta, and planned feature.
- 02Intended and prohibited uses — What uses does the vendor intend, document, advertise, configure, contract for, and prohibit?
- 03Consequential decisions — Is the system intended or reasonably likely to influence employment, education, housing, finance, insurance, health care, essential services, or public benefits?
- 04Decision weight — Does the output constrain, rank, score, recommend, classify, predict, or otherwise meaningfully alter the decision? Can staff ignore or override it in practice?
- 05Developer and deployer roles — Which party is the statutory developer and which is the deployer? Does an integrator or subcontractor hold an additional role?
- 06Operator role for chatbots — Who develops, controls, makes publicly available, or offers the conversational service? Who owns the statutory disclosure, age, safety, privacy, and reporting duties?
- 07Developer documentation — Will the vendor provide intended uses, known harmful or inappropriate uses, training-data categories, limitations, risks, non-use circumstances, monitoring instructions, and human-review instructions?
- 08Information needed for compliance — Will the vendor provide the information reasonably necessary for the public entity to issue notices, explain adverse outcomes, answer requests, and conduct meaningful review?
- 09Material updates — What constitutes a material update or intentional and substantial modification? How soon must the vendor notify the entity, and can the entity test or reject it before production use?
- 10Version identification — Can the entity identify the product, model, configuration, system version, and applicable change log used for an individual decision?
- 11Personal data and inputs — What personal-data categories, sources, derived attributes, proxies, profiles, and inferences are processed?
- 12Data correction — Can factually incorrect or materially inaccurate personal data be located, corrected at the source, propagated to downstream systems, and used in reconsideration?
- 13Adverse-outcome explanation — Can the entity explain the decision, the system's role, relevant input categories and sources, developer, version, and available rights within the required period?
- 14Meaningful human review — What primary evidence, limitations, input categories, principal factors, training, and override controls will a reviewer receive?
- 15Records and retention — Can the system retain and export compliance records for at least three years after a covered decision and longer when required by another law, schedule, audit, request, appeal, or hold?
- 16CORA search and export — Can the agency search, review, redact, and export records in usable formats without vendor discretion or unreasonable delay?
- 17Facial recognition — Does any component detect, analyze, verify, identify, match, or cluster faces? What statutory notice, accountability, testing, training, human-review, law-enforcement, or school restriction applies?
- 18Accessibility — Does the vendor provide current accessibility-conformance documentation, testing access, remediation commitments, release testing, alternative-access support, and contract remedies?
- 19Language access — Can notices, explanations, forms, and support be delivered accurately in the languages used by the public entity?
- 20Security and sensitive data — What safeguards apply to student, employee, benefit, health, criminal-justice, biometric, location, financial, and other sensitive information?
- 21Training and reuse — Will prompts, inputs, outputs, resident data, employee data, or derived information be used to train, fine-tune, evaluate, or improve the vendor's or another party's models?
- 22Subcontractors and model providers — Which cloud, model, data, moderation, analytics, and support providers receive data or influence outputs? What change notice applies?
- 23Testing and monitoring — What performance, subgroup, operational, drift, failure, and accessibility testing is available for the entity's actual use and population?
- 24Incidents and complaints — What events must be reported, within what time, and what evidence must be preserved?
- 25Suspension — Can the entity disable an AI, ADMT, facial-recognition, or chatbot feature without terminating the full platform?
- 26Termination and portability — What records, configurations, notices, requests, reviews, and audit evidence are returned, retained, deleted, or certified destroyed at termination?
- 27Liability and cooperation — Do indemnity, defense, insurance, limitation, fault-allocation, and cooperation terms comply with Colorado law and preserve remedies for each party's own conduct?
- 28Public explanation — Can the entity accurately explain the system's purpose, scope, data, limitations, decision role, oversight, accessibility, and complaint process to residents?
Proportionate review
Apply the most detailed review to systems that materially influence consequential decisions, facial-recognition uses, biometric processing, public-safety uses, and services involving minors or sensitive data. Lower-risk internal tools may receive a proportionate review, but security, data use, records access, accessibility, system changes, and vendor accountability should still be addressed.
Implementation tracker
Track the work and the evidence
Implementation tracker
Track the work and the evidence
| Action | Owner | Status | Evidence |
|---|---|---|---|
| Inventory AI, ADMT, facial-recognition, and chatbot systems | — | Not started / In progress / Complete | — |
| Classify covered domains and material influence | — | Not started / In progress / Complete | — |
| Confirm developer, deployer, and operator roles | — | Not started / In progress / Complete | — |
| Obtain developer documentation | — | Not started / In progress / Complete | — |
| Review facial-recognition compliance | — | Not started / In progress / Complete | — |
| Map public records and retention | — | Not started / In progress / Complete | — |
| Draft point-of-interaction notices | — | Not started / In progress / Complete | — |
| Build adverse-outcome explanations | — | Not started / In progress / Complete | — |
| Build correction and human-review process | — | Not started / In progress / Complete | — |
| Test accessibility and language access | — | Not started / In progress / Complete | — |
| Amend contracts | — | Not started / In progress / Complete | — |
| Review final Attorney General rules (pending rulemaking) | — | Not started / In progress / Complete | — |
| Train staff before January 1, 2027 | — | Not started / In progress / Complete | — |
Help improve this guide
Corrections and source updates
Help improve this guide
Corrections and source updates
This guide has been checked against the official sources listed below. Colorado records professionals, procurement officials, accessibility leaders, IT staff, school-district staff, municipal attorneys, public-safety practitioners, and other public-sector experts are invited to submit corrections, newer official sources, final rulemaking materials, or implementation examples.
Disclaimer
Scope of this guide
Disclaimer
Scope of this guide
This guide provides general policy and governance information. It is not legal advice, a comprehensive statement of Colorado law, or a substitute for review by a city, county, school-district, special-district, public-safety, or agency attorney. Laws, regulations, proposed rules, guidance, records schedules, and bill statuses may change. Officials should verify current requirements, final Attorney General rules, local authority, and the facts of a particular use before acting.
Official sources
Where to verify each claim
Official sources
Where to verify each claim
- [1] Colorado General Assembly — SB 26-189, Automated Decision-Making Technology
https://leg.colorado.gov/bills/SB26-189
- [2] Colorado Session Laws, Chapter 131 — SB 26-189 signed act
https://leg.colorado.gov/laws/session-laws/SB26-189/131/download
- [3] Colorado Attorney General — ADMT and Chatbot Safety Rulemaking
https://coag.gov/ai/
- [4] Colorado Attorney General — Proposed ADMT and Conversational AI Service Rules, filed August 11, 2026
https://coag.gov/app/uploads/2026/08/2026.08.11-ADMT-Chatbot-Act-Rulemaking.docx
- [5] Colorado General Assembly — HB 26-1263, Conversational AI Service Operator Requirements
https://leg.colorado.gov/bills/HB26-1263
- [6] Colorado General Assembly — SB 22-113, Artificial Intelligence Facial Recognition
https://leg.colorado.gov/bills/SB22-113
- [7] Colorado General Assembly — SB 25-143, Extend Prohibition on School Facial Recognition
https://leg.colorado.gov/bills/SB25-143
- [8] Colorado Secretary of State — Colorado Open Records Act
https://www.coloradosos.gov/pubs/info_center/cora.html
- [9] Colorado OIT — Digital Accessibility Law for Colorado State and Local Government
https://oit.colorado.gov/accessibility-law
- [10] Colorado OIT — Plain Language Guide to the State Technology Accessibility Rules
https://oit.colorado.gov/accessibility-rules
- [11] Colorado OIT — Guide to Artificial Intelligence
https://oit.colorado.gov/ai
- [12] Colorado OIT — Statewide GenAI Agency Responsibilities
https://oit.colorado.gov/standards-policies-guides/guide-to-artificial-intelligence/state-agency-responsibilities
- [13] Colorado General Assembly — Artificial Intelligence Impact Task Force
https://leg.colorado.gov/committees/2026A/interim/ArtificialIntelligenceImpactTaskForce
- [14] Colorado State Archives — Records Management
https://archives.colorado.gov/records-management
- [15] Colorado General Assembly — HB 24-1147, Candidate Election Deepfake Disclosures
https://leg.colorado.gov/bills/HB24-1147
- [16] City of Boulder — Emerging-Technologies Municipal Program
https://bouldercolorado.gov/news/boulder-joins-national-program-explore-how-emerging-technologies-can-support-fair-transparent
- [17] City of Boulder — Digital Accessibility Plan
https://bouldercolorado.gov/digital-accessibility-plan
- [18] Colorado Department of Education — Artificial Intelligence Guidance for Schools and Districts
https://ed.cde.state.co.us/artificialintelligence
- [19] Colorado Legislative Council Staff — SB 26-189 Final Fiscal Note, September 8, 2026
https://leg.colorado.gov/bill_files/117715/download
- [20] Colorado General Assembly — HB 21-1110, Colorado Laws for Persons with Disabilities
https://leg.colorado.gov/bills/HB21-1110
- [21] Colorado General Assembly — HB 24-1454, Grace Period for Noncompliance with Digital Accessibility Standards
https://leg.colorado.gov/bills/HB24-1454
Download
Colorado Local AI Governance Checklist
Checklist download in development.