Feature AI Risk
Colorado SB 26-189 Implementation Roadmap: Building Your ADMT Compliance Program Before January 1, 2027
Colorado SB 26-189, signed May 14, 2026, eliminates the financial institution exemption from SB 24-205 and creates three deployer obligations for covered ADMT. Here is how to build the compliance program your institution needs before the January 1, 2027 effective date.
Table of Contents
TL;DR:
- Colorado SB 26-189, signed May 14, 2026, repeals the original Colorado AI Act and takes effect January 1, 2027.
- The financial institution exemption from SB 24-205 is gone. Banks, fintechs, credit unions, and insurers are now in scope.
- Three deployer obligations: pre-use notice before the decision, post-adverse outcome notice within 30 days, and meaningful human review on request.
- The creditor ECOA/Reg B safe harbor covers notice obligations but not human review or record retention.
Banks thought they had a pass on Colorado’s AI law. They don’t.
The original Colorado AI Act (SB 24-205) gave financial institutions a carved-out exemption — an acknowledgment that banks and insurers already operated under disclosure and oversight frameworks that addressed some of the same risks. On May 14, 2026, Governor Polis signed SB 26-189, which repeals the original law entirely. The financial institution exemption is gone.
SB 26-189 is narrower than SB 24-205 in some respects — it drops the annual risk management program and impact assessment requirements. But it’s now unambiguously applicable to every bank, fintech, credit union, and insurance company deploying covered automated decision-making technology (ADMT) to make consequential decisions affecting Colorado consumers. You have until January 1, 2027. That’s approximately seven months. Here is the compliance roadmap.
What Changed Between SB 24-205 and SB 26-189
| Area | SB 24-205 (repealed) | SB 26-189 (effective Jan 1, 2027) |
|---|---|---|
| Financial institution exemption | Existed — banks, credit unions, state-regulated insurers carved out | Eliminated |
| Risk management program | Required annual impact assessments and risk management programs | Not required |
| Deployer obligations | Broader — risk management, impact assessments, ongoing monitoring | Narrowed to three notice and review obligations |
| Developer documentation | Extensive | Technical documentation for deployers required |
| Effective date | Would have been June 30, 2026 | January 1, 2027 |
The practical shift: SB 24-205 would have imposed program-level obligations. SB 26-189 trades that burden for three focused obligations centered on consumer notice and human review. Less documentation overhead — but the obligations that remain are directly visible to consumers, and the absence of a financial institution exemption means they now apply to the most regulated sector in the economy.
As Cooley’s analysis notes, this marks a significant shift: while SB 26-189 imposes less burdensome obligations than SB 24-205, the elimination of the financial institution exemption “marks a new era in state AI laws for financial institutions.”
What “Covered ADMT” Means in Financial Services
The law applies to covered ADMT — automated decision-making technology that makes or is a substantial factor in making a consequential decision.
Consequential decisions are those that materially affect a consumer’s access, eligibility, or compensation in:
- Financial or lending services (credit approvals, credit limit decisions, pricing)
- Insurance (underwriting, pricing, claims decisions)
- Employment (hiring, promotion, compensation — relevant for financial services employers)
- Real estate (rental eligibility, mortgage approvals)
- Healthcare (relevant for some employee benefits programs)
For most financial institutions, “covered ADMT” likely includes credit underwriting models, fraud decisioning systems that result in account restrictions, insurance pricing algorithms, and automated adverse action systems.
The “substantial factor” test is where gray areas emerge. If your model recommends denial and the human override rate is below 5%, regulators and courts are likely to treat the model as a substantial factor regardless of what your process documentation says. Build your inventory around the practical role of the technology in the decision, not the nominal role in your governance documents.
The Three Deployer Obligations
1. Pre-Use Notice
Before covered ADMT makes or substantially contributes to a consequential decision, you must provide the consumer with clear and conspicuous notice that ADMT is or will be used in the decision process.
What “clear and conspicuous” requires in practice:
- Not buried in a terms-of-service scroll
- Delivered at or before the point of decision — at application intake, before an adverse outcome is communicated
- Plain language, not technical jargon
For creditors, SB 26-189 includes a safe harbor: compliance with existing sector-specific requirements under ECOA and Reg B satisfies the pre-use notice obligation for credit decisions. If you are already providing required adverse action notices and disclosures, you are covered on this point for credit. However, the safe harbor applies only to notice — not to human review or record retention.
2. Post-Adverse Outcome Notice (30-Day Clock)
If covered ADMT materially influences an adverse decision, you must provide an adverse outcome notice within 30 days of the decision. The notice must include:
- The fact that ADMT was used in or substantially contributed to the decision
- The consumer’s right to request meaningful human review
- Contact information for submitting a review request
For financial institutions, this likely maps onto existing adverse action notice workflows — but adds an ADMT disclosure layer. If your adverse action notices do not currently reference the use of automated technology, they need to by January 1, 2027.
The 30-day clock runs from the adverse decision, not from consumer inquiry. You need a workflow that generates the ADMT notice as part of — or immediately following — the adverse decision process.
3. Meaningful Human Review
On request following an adverse ADMT outcome, the consumer has the right to:
- Correct factually inaccurate personal data that was input to the ADMT
- Request meaningful human review and reconsideration of the decision
The qualification — “to the extent commercially reasonable” — gives deployers operational flexibility. But it does not excuse institutions from having any review process. An institution that provides no pathway for human review isn’t commercially reasonable; it simply has no process.
A defensible human review workflow:
- A designated review function that does not simply reroute to the same automated system
- A written process for receiving, documenting, and responding to review requests
- A defined response timeline (not specified in SB 26-189, but 30 days is a reasonable target to parallel the notice obligation)
- Documentation of the review request, any data corrections, the outcome, and the reviewer’s identity
The Creditor Safe Harbor: What It Covers and What It Doesn’t
SB 26-189 provides that creditors complying with ECOA, Reg B, and existing adverse action requirements “shall be considered to comply” with the pre-use and post-adverse outcome notice obligations.
This does not create a financial institution exemption. It creates a notice safe harbor. What it does not cover:
- The meaningful human review obligation
- Record retention requirements (3 years)
- Technical documentation receipt from developers
- Non-credit consequential decisions (employment, insurance for insurers not covered by sector-specific safe harbor language)
A bank that uses automated credit decisioning, follows all ECOA adverse action requirements, but has no documented process for consumer review requests is still non-compliant with SB 26-189.
Record Retention: What 3 Years Looks Like
SB 26-189 requires both developers and deployers to retain records demonstrating compliance for at least 3 years from the date of creation.
For deployers, the compliance record by decision system includes:
- Pre-use notice delivery records (logs, timestamps, customer communication records)
- Adverse outcome notice generation and delivery confirmation
- Human review requests received, processed, and responded to
- Technical documentation received from AI vendors or internal developers
This isn’t aspirational — it’s the evidence file you hand to the Colorado AG’s office if a consumer files a complaint. Design the retention system around that scenario.
Developer Obligations: What to Demand from Your AI Vendors
If your institution deploys third-party AI tools — which most financial institutions do — you are the deployer and the vendor is the developer. SB 26-189 requires developers to provide deployers with technical documentation including:
- Intended uses and limitations of the covered ADMT
- Categories of training data used
- Known limitations of the model
- Instructions for appropriate use and human review implementation
Before January 1, 2027, contact your AI vendors and request this documentation. For contracts up for renewal, add the documentation delivery as a contractual obligation. If a vendor cannot or will not provide it, that is a TPRM gap that warrants escalation — and under SB 26-189, a potential compliance gap if you are deploying that vendor’s ADMT in covered decisions.
6-Step Implementation Roadmap
Step 1: Inventory your covered ADMT Identify every automated system that makes or substantially contributes to consequential decisions affecting Colorado consumers. Use your AI use case inventory as the starting point and apply the SB 26-189 coverage test — consequential decision domain, substantial factor threshold, Colorado consumer nexus.
Step 2: Map decisions to SB 26-189 coverage and safe harbors For each identified system, confirm whether the output qualifies as a consequential decision in a covered domain, whether an ECOA/Reg B creditor safe harbor applies to the notice obligations, and whether the human review obligation applies regardless of safe harbor.
Step 3: Audit existing adverse action notice templates Review current adverse action notice language for ADMT disclosure. If they do not already include a statement that automated technology was used in the decision, update them. Set a target of draft completion by September 1, 2026, to allow for legal review and implementation before the January 1, 2027 deadline.
Step 4: Build the human review workflow Design your review intake process — how consumers submit requests, how requests are routed to a human reviewer, what evidence the reviewer accesses, and how the outcome is documented and communicated. If you use a contact center or servicing team, this is an operational workflow update and training requirement, not just a policy document.
Step 5: Request technical documentation from AI vendors Contact every vendor whose ADMT is included in your covered ADMT inventory. Request the documentation SB 26-189 requires developers to provide. Document receipt and file it in your 3-year compliance record.
Step 6: Implement structured record retention Stand up a compliance evidence file for each covered ADMT system: pre-use notice logs, adverse outcome notice records, human review request/response files, and vendor technical documentation. Set the 3-year minimum retention policy and assign a document custodian.
So What?
Financial institutions have had a window to treat Colorado AI law as someone else’s compliance problem. SB 26-189, effective January 1, 2027, closes it.
The three obligations are not operationally heavy — they are notice and process requirements, not a full governance program. But getting the ADMT inventory right, updating notice templates, and standing up a defensible human review workflow takes time when coordinated across operations, legal, and compliance. Seven months is enough time if you start now. It is not enough time if you wait for Q4.
The AI Risk Assessment Template & Guide includes an AI use case inventory built to identify covered ADMT quickly and a pre-deployment checklist that maps to the documentation SB 26-189 requires deployers to retain. The governance framework discussion in our AI governance program guide covers the operating model for how institutions manage the inventory, review process, and vendor documentation that SB 26-189 requires. For the law change itself, our earlier post on what SB 26-189 means for banks and fintechs covers the legislative context.
The compliance deadline is January 1. The inventory conversation is now.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the effective date of Colorado SB 26-189?
Are financial institutions exempt from Colorado SB 26-189?
What three obligations does SB 26-189 create for deployers?
What is covered ADMT under SB 26-189?
Does the creditor safe harbor fully exempt banks and fintechs from SB 26-189?
What records must deployers retain under SB 26-189?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
Jul 24, 2026
AI Risk
AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval
An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.
Jul 23, 2026
AI Risk
August 2 Is Ten Days Away: What the EU AI Act's High-Risk Deadline Actually Requires from Financial Services AI
The EU AI Act's Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here's what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.
Jul 22, 2026