Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

Colorado SB 26-189 Implementation Roadmap: Building Your ADMT Compliance Program Before January 1, 2027

Colorado SB 26-189, signed May 14, 2026, eliminates the financial institution exemption from SB 24-205 and creates three deployer obligations for covered ADMT. Here is how to build the compliance program your institution needs before the January 1, 2027 effective date.

By Rebecca Leung · June 11, 2026 ·
Table of Contents

TL;DR:

  • Colorado SB 26-189, signed May 14, 2026, repeals the original Colorado AI Act and takes effect January 1, 2027.
  • The financial institution exemption from SB 24-205 is gone. Banks, fintechs, credit unions, and insurers are now in scope.
  • Three deployer obligations: pre-use notice before the decision, post-adverse outcome notice within 30 days, and meaningful human review on request.
  • The creditor ECOA/Reg B safe harbor covers notice obligations but not human review or record retention.

Banks thought they had a pass on Colorado’s AI law. They don’t.

The original Colorado AI Act (SB 24-205) gave financial institutions a carved-out exemption — an acknowledgment that banks and insurers already operated under disclosure and oversight frameworks that addressed some of the same risks. On May 14, 2026, Governor Polis signed SB 26-189, which repeals the original law entirely. The financial institution exemption is gone.

SB 26-189 is narrower than SB 24-205 in some respects — it drops the annual risk management program and impact assessment requirements. But it’s now unambiguously applicable to every bank, fintech, credit union, and insurance company deploying covered automated decision-making technology (ADMT) to make consequential decisions affecting Colorado consumers. You have until January 1, 2027. That’s approximately seven months. Here is the compliance roadmap.

What Changed Between SB 24-205 and SB 26-189

AreaSB 24-205 (repealed)SB 26-189 (effective Jan 1, 2027)
Financial institution exemptionExisted — banks, credit unions, state-regulated insurers carved outEliminated
Risk management programRequired annual impact assessments and risk management programsNot required
Deployer obligationsBroader — risk management, impact assessments, ongoing monitoringNarrowed to three notice and review obligations
Developer documentationExtensiveTechnical documentation for deployers required
Effective dateWould have been June 30, 2026January 1, 2027

The practical shift: SB 24-205 would have imposed program-level obligations. SB 26-189 trades that burden for three focused obligations centered on consumer notice and human review. Less documentation overhead — but the obligations that remain are directly visible to consumers, and the absence of a financial institution exemption means they now apply to the most regulated sector in the economy.

As Cooley’s analysis notes, this marks a significant shift: while SB 26-189 imposes less burdensome obligations than SB 24-205, the elimination of the financial institution exemption “marks a new era in state AI laws for financial institutions.”

What “Covered ADMT” Means in Financial Services

The law applies to covered ADMT — automated decision-making technology that makes or is a substantial factor in making a consequential decision.

Consequential decisions are those that materially affect a consumer’s access, eligibility, or compensation in:

  • Financial or lending services (credit approvals, credit limit decisions, pricing)
  • Insurance (underwriting, pricing, claims decisions)
  • Employment (hiring, promotion, compensation — relevant for financial services employers)
  • Real estate (rental eligibility, mortgage approvals)
  • Healthcare (relevant for some employee benefits programs)

For most financial institutions, “covered ADMT” likely includes credit underwriting models, fraud decisioning systems that result in account restrictions, insurance pricing algorithms, and automated adverse action systems.

The “substantial factor” test is where gray areas emerge. If your model recommends denial and the human override rate is below 5%, regulators and courts are likely to treat the model as a substantial factor regardless of what your process documentation says. Build your inventory around the practical role of the technology in the decision, not the nominal role in your governance documents.

The Three Deployer Obligations

1. Pre-Use Notice

Before covered ADMT makes or substantially contributes to a consequential decision, you must provide the consumer with clear and conspicuous notice that ADMT is or will be used in the decision process.

What “clear and conspicuous” requires in practice:

  • Not buried in a terms-of-service scroll
  • Delivered at or before the point of decision — at application intake, before an adverse outcome is communicated
  • Plain language, not technical jargon

For creditors, SB 26-189 includes a safe harbor: compliance with existing sector-specific requirements under ECOA and Reg B satisfies the pre-use notice obligation for credit decisions. If you are already providing required adverse action notices and disclosures, you are covered on this point for credit. However, the safe harbor applies only to notice — not to human review or record retention.

2. Post-Adverse Outcome Notice (30-Day Clock)

If covered ADMT materially influences an adverse decision, you must provide an adverse outcome notice within 30 days of the decision. The notice must include:

  • The fact that ADMT was used in or substantially contributed to the decision
  • The consumer’s right to request meaningful human review
  • Contact information for submitting a review request

For financial institutions, this likely maps onto existing adverse action notice workflows — but adds an ADMT disclosure layer. If your adverse action notices do not currently reference the use of automated technology, they need to by January 1, 2027.

The 30-day clock runs from the adverse decision, not from consumer inquiry. You need a workflow that generates the ADMT notice as part of — or immediately following — the adverse decision process.

3. Meaningful Human Review

On request following an adverse ADMT outcome, the consumer has the right to:

  • Correct factually inaccurate personal data that was input to the ADMT
  • Request meaningful human review and reconsideration of the decision

The qualification — “to the extent commercially reasonable” — gives deployers operational flexibility. But it does not excuse institutions from having any review process. An institution that provides no pathway for human review isn’t commercially reasonable; it simply has no process.

A defensible human review workflow:

  • A designated review function that does not simply reroute to the same automated system
  • A written process for receiving, documenting, and responding to review requests
  • A defined response timeline (not specified in SB 26-189, but 30 days is a reasonable target to parallel the notice obligation)
  • Documentation of the review request, any data corrections, the outcome, and the reviewer’s identity

The Creditor Safe Harbor: What It Covers and What It Doesn’t

SB 26-189 provides that creditors complying with ECOA, Reg B, and existing adverse action requirements “shall be considered to comply” with the pre-use and post-adverse outcome notice obligations.

This does not create a financial institution exemption. It creates a notice safe harbor. What it does not cover:

  • The meaningful human review obligation
  • Record retention requirements (3 years)
  • Technical documentation receipt from developers
  • Non-credit consequential decisions (employment, insurance for insurers not covered by sector-specific safe harbor language)

A bank that uses automated credit decisioning, follows all ECOA adverse action requirements, but has no documented process for consumer review requests is still non-compliant with SB 26-189.

Record Retention: What 3 Years Looks Like

SB 26-189 requires both developers and deployers to retain records demonstrating compliance for at least 3 years from the date of creation.

For deployers, the compliance record by decision system includes:

  • Pre-use notice delivery records (logs, timestamps, customer communication records)
  • Adverse outcome notice generation and delivery confirmation
  • Human review requests received, processed, and responded to
  • Technical documentation received from AI vendors or internal developers

This isn’t aspirational — it’s the evidence file you hand to the Colorado AG’s office if a consumer files a complaint. Design the retention system around that scenario.

Developer Obligations: What to Demand from Your AI Vendors

If your institution deploys third-party AI tools — which most financial institutions do — you are the deployer and the vendor is the developer. SB 26-189 requires developers to provide deployers with technical documentation including:

  • Intended uses and limitations of the covered ADMT
  • Categories of training data used
  • Known limitations of the model
  • Instructions for appropriate use and human review implementation

Before January 1, 2027, contact your AI vendors and request this documentation. For contracts up for renewal, add the documentation delivery as a contractual obligation. If a vendor cannot or will not provide it, that is a TPRM gap that warrants escalation — and under SB 26-189, a potential compliance gap if you are deploying that vendor’s ADMT in covered decisions.

6-Step Implementation Roadmap

Step 1: Inventory your covered ADMT Identify every automated system that makes or substantially contributes to consequential decisions affecting Colorado consumers. Use your AI use case inventory as the starting point and apply the SB 26-189 coverage test — consequential decision domain, substantial factor threshold, Colorado consumer nexus.

Step 2: Map decisions to SB 26-189 coverage and safe harbors For each identified system, confirm whether the output qualifies as a consequential decision in a covered domain, whether an ECOA/Reg B creditor safe harbor applies to the notice obligations, and whether the human review obligation applies regardless of safe harbor.

Step 3: Audit existing adverse action notice templates Review current adverse action notice language for ADMT disclosure. If they do not already include a statement that automated technology was used in the decision, update them. Set a target of draft completion by September 1, 2026, to allow for legal review and implementation before the January 1, 2027 deadline.

Step 4: Build the human review workflow Design your review intake process — how consumers submit requests, how requests are routed to a human reviewer, what evidence the reviewer accesses, and how the outcome is documented and communicated. If you use a contact center or servicing team, this is an operational workflow update and training requirement, not just a policy document.

Step 5: Request technical documentation from AI vendors Contact every vendor whose ADMT is included in your covered ADMT inventory. Request the documentation SB 26-189 requires developers to provide. Document receipt and file it in your 3-year compliance record.

Step 6: Implement structured record retention Stand up a compliance evidence file for each covered ADMT system: pre-use notice logs, adverse outcome notice records, human review request/response files, and vendor technical documentation. Set the 3-year minimum retention policy and assign a document custodian.

So What?

Financial institutions have had a window to treat Colorado AI law as someone else’s compliance problem. SB 26-189, effective January 1, 2027, closes it.

The three obligations are not operationally heavy — they are notice and process requirements, not a full governance program. But getting the ADMT inventory right, updating notice templates, and standing up a defensible human review workflow takes time when coordinated across operations, legal, and compliance. Seven months is enough time if you start now. It is not enough time if you wait for Q4.

The AI Risk Assessment Template & Guide includes an AI use case inventory built to identify covered ADMT quickly and a pre-deployment checklist that maps to the documentation SB 26-189 requires deployers to retain. The governance framework discussion in our AI governance program guide covers the operating model for how institutions manage the inventory, review process, and vendor documentation that SB 26-189 requires. For the law change itself, our earlier post on what SB 26-189 means for banks and fintechs covers the legislative context.

The compliance deadline is January 1. The inventory conversation is now.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the effective date of Colorado SB 26-189?
Colorado SB 26-189 was signed by Governor Polis on May 14, 2026, and takes effect January 1, 2027. It repeals and replaces SB 24-205, Colorado's original AI law, which would have taken effect June 30, 2026.
Are financial institutions exempt from Colorado SB 26-189?
No. SB 26-189 eliminates the financial institution exemption that existed under the original SB 24-205. Banks, credit unions, fintechs, and insurance companies doing business in Colorado that deploy covered ADMT in consequential decisions are in scope starting January 1, 2027.
What three obligations does SB 26-189 create for deployers?
SB 26-189 requires deployers of covered ADMT to: (1) provide a pre-use notice to consumers before a consequential decision is made using the ADMT; (2) provide a post-adverse outcome notice within 30 days if the ADMT materially influenced an adverse decision; and (3) provide a meaningful human review process upon request, to the extent commercially reasonable.
What is covered ADMT under SB 26-189?
Covered ADMT is automated decision-making technology that makes or is a substantial factor in making a consequential decision. Consequential decisions include those materially affecting a consumer's access, eligibility, or compensation in employment, education, real estate, financial or lending services, insurance, and healthcare.
Does the creditor safe harbor fully exempt banks and fintechs from SB 26-189?
No. Creditors that comply with existing adverse action requirements under ECOA and Reg B satisfy the pre-use and post-adverse outcome notice obligations for credit decisions. But the safe harbor does not cover the human review obligation, record retention requirements, or ADMT documentation from developers. Financial institutions must still build a human review process and retention system.
What records must deployers retain under SB 26-189?
Deployers must retain records demonstrating compliance for at least 3 years. This includes pre-use notice delivery logs, adverse outcome notice records, human review request and response files, and technical documentation received from AI developers or vendors.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.