Skip to content
RiskTemplates · The Daily Brief Tuesday, August 25, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Feature Regulatory Compliance

Colorado Rewrote Its AI Law. The New Version Has No Financial Institution Exemption—and the Rules Just Dropped.

Colorado SB 26-189, signed May 2026, repeals and replaces SB 24-205 with a narrower automated decision-making technology law. Financial institutions lost their exemption. The AG proposed rules on August 11. Here's what fintechs and lenders need to do before January 1, 2027.

By Rebecca Leung · August 24, 2026 ·
Table of Contents

TL;DR

  • Colorado SB 24-205 (the original Colorado AI Act) was repealed and replaced—not just delayed—by SB 26-189, signed May 14, 2026
  • The new law eliminates the financial institution exemption; banks, credit unions, mortgage lenders, and fintechs using automated decision-making in consequential decisions are fully in scope
  • The NIST AI RMF and ISO 42001 safe harbor and the small business exemption were both removed
  • Colorado AG released proposed ADMT rules on August 11, 2026—comment deadline September 4 for the October hearing
  • AML/CFT and sanctions compliance activities are expressly carved out; the compliance burden hits customer-facing credit, insurance, and lending AI

If you followed Colorado’s AI law saga and concluded that the extended deadline gave you more time to do the same thing, that’s only half right. Yes, the deadline is still January 1, 2027. But the law you’ll be complying with on that date is not the law that was on the books when you started tracking this.

On May 14, 2026, Governor Jared Polis signed Senate Bill 26-189—which doesn’t amend or delay SB 24-205. It repeals SB 24-205 and enacts an entirely new statute: the Automated Decision-Making Technology Act. The requirements changed. The exemptions changed. And the comfortable backstop that many financial institutions were counting on—that being a regulated entity subject to existing federal oversight was enough—is gone.

Here’s what actually changed, why it matters more for financial services than any other sector, and what the 12-week sprint to January 1 needs to include.


What Got Repealed

The original Colorado AI Act (SB 24-205) was notable for being the first comprehensive state AI law in the country. It was modeled loosely on the EU AI Act’s risk-based framework and required both developers and deployers of high-risk AI systems to maintain risk management programs, conduct annual impact assessments, provide consumer notifications, and report discovered discrimination to the AG within 90 days.

Two safe harbors made life easier for compliant organizations: companies adhering to recognized frameworks like the NIST AI RMF or ISO 42001 got a compliance presumption, and regulated financial institutions already subject to “substantially similar” obligations under existing federal or state law could rely on that compliance instead of building a parallel Colorado-specific program.

Both are gone.

SB 26-189 strips out the framework safe harbors, the financial institution exemption, and the small business exemption. In their place is a narrower but less escapable statute.


What the New Law Actually Requires

SB 26-189 pivots away from governance-program requirements and toward consumer-facing transparency and rights. The compliance obligations fall primarily on deployers—the organizations using ADMT in consequential decisions—rather than on developers.

The Three Core Deployer Obligations

1. Pre-Use Notice

Before using covered ADMT in a consequential decision, a deployer must provide clear and conspicuous notice that an automated system is or will be involved in the decision. The proposed AG rules released August 11 clarify the format and timing requirements, though some details remain subject to the rulemaking process.

2. 30-Day Adverse Outcome Explanation

When covered ADMT results in an adverse outcome—defined as a denial, termination, material reduction in benefits, or significantly worse pricing—the deployer must provide, within 30 days, a plain-language explanation covering:

  • The nature of the decision and the ADMT’s role in making it
  • The categories of personal data that influenced the output
  • An explanation of the consumer’s rights under the law

The 30-day clock runs from the adverse decision, not from when the consumer asks. This is a proactive obligation, not a response-to-inquiry one. For financial services companies making credit or insurance decisions at volume, this creates a disclosure workflow requirement that needs to be designed into the decisioning process itself.

3. Human Review and Data Correction Rights

Consumers have the right to request meaningful human review of an adverse outcome, to the extent commercially reasonable. They also have the right to access and correct the personal data that was used as input to the ADMT.

The phrase “to the extent commercially reasonable” is doing real work here—and it’s one of the reasons the proposed AG rules matter. How that phrase gets defined in rulemaking will substantially affect what organizations are actually obligated to build.

Developer Obligations

For organizations building or substantially modifying ADMT systems, SB 26-189 requires:

  • Technical documentation describing the system’s intended uses, training data categories, known limitations, and instructions for meaningful human review
  • Proactive notification to deployers when material updates are made to the system

Developer liability is scoped: developers are responsible to the extent that deployers used the ADMT in a manner that the developer intended, documented, marketed, or configured. If a deployer misuses a system in ways the developer didn’t envision or support, the liability allocation shifts.


Why Financial Services Companies Got Hit Harder

The original SB 24-205 exempted regulated financial institutions from its requirements if they were already subject to “substantially similar obligations” under federal or state law. The implicit assumption was that existing model risk management guidance, fair lending requirements, and OCC/FDIC/Fed supervision created enough of an equivalent compliance framework.

Colorado’s legislature disagreed—or at least didn’t extend that argument to the new statute.

SB 26-189 eliminated the exemption outright, without explanation of why. The result: banks, credit unions, mortgage lenders, auto lenders, insurance companies, and fintechs are now subject to Colorado’s ADMT consumer disclosure requirements regardless of what else they comply with.

For organizations using AI in credit underwriting, loan pricing, deposit account approval, credit card decisioning, or insurance underwriting for Colorado residents—any of which would qualify as a “consequential decision” related to financial or lending services—SB 26-189 obligations apply.

The AML/CFT and Sanctions Carve-Out

There is meaningful good news for compliance-heavy financial institutions. SB 26-189 expressly excludes AML/CFT and sanctions compliance activities from both the definition of ADMT and the definition of consequential decision.

Transaction monitoring systems, sanctions screening tools, and SAR workflows are out of scope. So is the automated model generating BSA/AML risk scores on customers.

What’s in scope: the credit underwriting model, the loan pricing engine, the deposit account approval workflow, the insurance underwriting system—anything that produces an adverse outcome for a Colorado consumer’s access to or terms of financial services.


The AG Proposed Rules: Why September 4 Matters

On August 11, 2026, Colorado AG Phil Weiser released proposed rules implementing SB 26-189. The rules go further than the statute text in specifying what compliance actually looks like operationally.

Key areas the proposed rules address:

  • Notice format and timing: what “clear and conspicuous” means in digital and in-person contexts, and at what point in the consumer interaction the notice must appear
  • Adverse outcome explanation content: minimum content requirements for the 30-day explanation, including how to describe ADMT’s role without disclosing proprietary model details
  • Meaningful human review: what qualifies as meaningful, and whether automated re-review counts
  • Consumer rights processes: how organizations must respond to data access and correction requests

The comment period has two tracks:

  • September 4, 2026: Comments submitted by this date are considered for revisions presented at the October 26 rulemaking hearing
  • October 26, 2026: The hearing date; comments are open through this date

If your organization has operations or customers in Colorado and uses automated decisioning for credit, insurance, or lending, the proposed rules are worth reviewing before September 4—particularly the definitions of “meaningful human review” and the adverse outcome explanation content requirements, both of which will drive significant operational build.


What Financial Services Teams Need to Do Before January 1

Step 1: Map Your ADMT Use Cases

Identify every system that generates predictions, recommendations, classifications, or scores used in decisions about Colorado residents’ access to financial or lending services. This includes:

  • Credit underwriting and pricing models
  • Deposit account approval workflows
  • Insurance underwriting systems
  • Loan modification and hardship decisioning
  • Account restriction or closure workflows

Exclude AML/CFT and sanctions systems from this inventory—they’re carved out. But document why they’re excluded, not just that they are.

Step 2: Assess the Pre-Use Notice Gap

For each covered ADMT use case, identify where in the consumer interaction the required pre-use notice would need to appear. For applications and onboarding flows, this is usually manageable. For periodic decisions made on existing accounts (loan repricing, credit limit reductions), the notice timing is more complex and may require process redesign.

Step 3: Build the Adverse Outcome Disclosure Workflow

The 30-day explanation requirement creates an operational requirement that doesn’t fit neatly into most existing adverse action workflows. Fair lending adverse action notices handle credit declinations under Reg B/ECOA, but SB 26-189’s requirements are broader: any adverse outcome in any consequential category, with specific ADMT-role disclosure.

For high-volume automated decisioning, this likely means building an automated disclosure generation workflow—one that can pull the relevant data inputs, describe the system’s role in plain language, and trigger a consumer-facing communication within the 30-day window.

Step 4: Design the Human Review Process

The right to “meaningful human review” is going to be operationally significant for high-volume decisioning. Whatever human review means after rulemaking, it needs to be a documented process with a clear owner, a defined scope, and evidence that it happened.

Lenders and insurance companies that make thousands of automated decisions per day will need to think carefully about what “commercially reasonable” human review looks like at scale—and whether they need to lobby that definition during the September/October comment period.

Step 5: Update Developer Agreements

If your organization licenses AI models from third-party vendors and uses them for consequential decisions, SB 26-189 creates documentation requirements that flow upstream. You need the vendor’s technical documentation covering intended uses, training data categories, known limitations, and human review instructions. Review your vendor contracts to confirm these deliverables exist and are contractually required on update.


The Right-to-Cure Window and Enforcement

Until January 1, 2030, SB 26-189 includes a 60-day right-to-cure period after receiving notice of a violation. This doesn’t mean organizations get three years of no-consequence noncompliance—it means a first violation can be remediated before penalty rather than resulting in immediate enforcement.

After January 1, 2030, enforcement is direct with no cure period. The AG has exclusive enforcement authority; there’s no private right of action. Penalties will be determined through rulemaking and will follow Colorado’s consumer protection framework.

The cure window is meaningful, but it shouldn’t be treated as a compliance runway. By January 1, 2027, organizations should have documented processes for pre-use notice, adverse outcome disclosure, and human review—not just aspirational plans.


The Bigger Picture

Colorado’s pivot from SB 24-205 to SB 26-189 reflects a broader legislative trend: state AI laws are getting more specific about consumer-facing rights rather than broader about enterprise governance. The disclosure-and-recourse model is replacing the governance-and-assessment model that the EU AI Act pioneered.

For financial services practitioners, this creates a specific compliance gap. Federal fair lending and model risk management frameworks handle many of the governance requirements—documentation, validation, monitoring—but they don’t map cleanly to proactive 30-day adverse outcome disclosure with explicit ADMT-role explanations. That’s a new obligation, even for organizations running mature model risk programs.

The good news: five months is enough time to build this if you start now. The bad news: it’s not enough time if you’re starting by confirming the law changed.

Colorado’s January 2027 deadline is real, the proposed rules are out, and the comment window closes in 11 days. The sprint is on.


So What?

  • Confirm your ADMT inventory: not everything with an algorithm, just the systems generating outputs used in consequential decisions about Colorado residents’ access to financial services
  • Submit comments before September 4 if you have concerns about how “meaningful human review” or adverse outcome notice requirements will be defined
  • Close the vendor documentation gap: third-party AI vendors need to supply the technical documentation SB 26-189 requires; confirm it’s in your contracts
  • Design the 30-day adverse disclosure workflow: this is the operationally heaviest requirement and the one most likely to require technology investment
  • The AML/CFT carve-out covers your compliance-oriented AI; the credit, insurance, and lending decisioning systems are in scope

Related reading: Colorado AI Act (SB 205) Compliance Guide (context on the original law SB 26-189 replaced), AI in Consequential Decision-Making: Where Regulators Draw the Compliance Line, AI Model Inventory Management for Regulatory Exams

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What happened to Colorado SB 24-205—the original Colorado AI Act?
SB 24-205 was repealed and replaced by SB 26-189, signed by Governor Polis on May 14, 2026. SB 26-189 is not just a delay—it substantially rewrites the law's scope, requirements, and enforcement structure. Key changes: the financial institution exemption was eliminated, the NIST AI RMF and ISO 42001 safe harbor was removed, the small business exemption was removed, and the obligations shifted from broad AI governance requirements to targeted consumer disclosures and rights around automated decision-making.
Does SB 26-189 still apply to banks and credit unions?
Yes—and more broadly than before. The original SB 24-205 contained an exemption for regulated financial institutions already subject to substantially similar obligations under federal or state law. SB 26-189 eliminates that exemption entirely. Banks, credit unions, mortgage lenders, and fintechs that use automated decision-making in consequential decisions affecting Colorado consumers are covered, regardless of what other federal frameworks they comply with.
What is 'automated decision-making technology' under SB 26-189?
ADMT is defined as technology that processes personal data and uses computation to generate output—predictions, recommendations, classifications, rankings, or scores—that are used to make, guide, or assist a decision about an individual. A 'consequential decision' relates to access to, eligibility for, or compensation related to financial or lending services, employment, housing, insurance, healthcare, education, or essential government services. Credit decisioning, loan pricing, deposit account approval, and insurance underwriting AI all fit the definition.
Are AML and sanctions compliance activities excluded from the law?
Yes. SB 26-189 expressly excludes AML/CFT and sanctions compliance activities from the definitions of ADMT and consequential decision. Transaction monitoring systems, sanctions screening tools, and SAR filing workflows are carved out. This is significant for fintechs and financial institutions whose highest-volume AI use cases are compliance-oriented rather than customer-facing.
What is the deadline to submit comments on the proposed ADMT rules?
Colorado AG Phil Weiser released proposed ADMT rules on August 11, 2026. Comments must be submitted by September 4, 2026, to be included in any proposed revisions presented at the October 26, 2026 rulemaking hearing. Written comments are accepted through October 26, 2026. Financial services industry groups and individual companies with Colorado-resident customers should review the draft rules and consider whether to submit comments, particularly on the definition of 'meaningful human review' and notice format requirements.
What is the right-to-cure period, and how does enforcement work?
The Colorado AG has exclusive enforcement authority under SB 26-189—there is no private right of action. Until January 1, 2030, companies receive a 60-day right to cure after receiving notice of a violation. After 2030, enforcement is direct without a cure period. Penalties will follow Colorado's consumer protection framework once finalized through rulemaking.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.