Feature Regulatory Compliance
Colorado Rewrote Its AI Law. The New Version Has No Financial Institution Exemption—and the Rules Just Dropped.
Colorado SB 26-189, signed May 2026, repeals and replaces SB 24-205 with a narrower automated decision-making technology law. Financial institutions lost their exemption. The AG proposed rules on August 11. Here's what fintechs and lenders need to do before January 1, 2027.
Table of Contents
TL;DR
- Colorado SB 24-205 (the original Colorado AI Act) was repealed and replaced—not just delayed—by SB 26-189, signed May 14, 2026
- The new law eliminates the financial institution exemption; banks, credit unions, mortgage lenders, and fintechs using automated decision-making in consequential decisions are fully in scope
- The NIST AI RMF and ISO 42001 safe harbor and the small business exemption were both removed
- Colorado AG released proposed ADMT rules on August 11, 2026—comment deadline September 4 for the October hearing
- AML/CFT and sanctions compliance activities are expressly carved out; the compliance burden hits customer-facing credit, insurance, and lending AI
If you followed Colorado’s AI law saga and concluded that the extended deadline gave you more time to do the same thing, that’s only half right. Yes, the deadline is still January 1, 2027. But the law you’ll be complying with on that date is not the law that was on the books when you started tracking this.
On May 14, 2026, Governor Jared Polis signed Senate Bill 26-189—which doesn’t amend or delay SB 24-205. It repeals SB 24-205 and enacts an entirely new statute: the Automated Decision-Making Technology Act. The requirements changed. The exemptions changed. And the comfortable backstop that many financial institutions were counting on—that being a regulated entity subject to existing federal oversight was enough—is gone.
Here’s what actually changed, why it matters more for financial services than any other sector, and what the 12-week sprint to January 1 needs to include.
What Got Repealed
The original Colorado AI Act (SB 24-205) was notable for being the first comprehensive state AI law in the country. It was modeled loosely on the EU AI Act’s risk-based framework and required both developers and deployers of high-risk AI systems to maintain risk management programs, conduct annual impact assessments, provide consumer notifications, and report discovered discrimination to the AG within 90 days.
Two safe harbors made life easier for compliant organizations: companies adhering to recognized frameworks like the NIST AI RMF or ISO 42001 got a compliance presumption, and regulated financial institutions already subject to “substantially similar” obligations under existing federal or state law could rely on that compliance instead of building a parallel Colorado-specific program.
Both are gone.
SB 26-189 strips out the framework safe harbors, the financial institution exemption, and the small business exemption. In their place is a narrower but less escapable statute.
What the New Law Actually Requires
SB 26-189 pivots away from governance-program requirements and toward consumer-facing transparency and rights. The compliance obligations fall primarily on deployers—the organizations using ADMT in consequential decisions—rather than on developers.
The Three Core Deployer Obligations
1. Pre-Use Notice
Before using covered ADMT in a consequential decision, a deployer must provide clear and conspicuous notice that an automated system is or will be involved in the decision. The proposed AG rules released August 11 clarify the format and timing requirements, though some details remain subject to the rulemaking process.
2. 30-Day Adverse Outcome Explanation
When covered ADMT results in an adverse outcome—defined as a denial, termination, material reduction in benefits, or significantly worse pricing—the deployer must provide, within 30 days, a plain-language explanation covering:
- The nature of the decision and the ADMT’s role in making it
- The categories of personal data that influenced the output
- An explanation of the consumer’s rights under the law
The 30-day clock runs from the adverse decision, not from when the consumer asks. This is a proactive obligation, not a response-to-inquiry one. For financial services companies making credit or insurance decisions at volume, this creates a disclosure workflow requirement that needs to be designed into the decisioning process itself.
3. Human Review and Data Correction Rights
Consumers have the right to request meaningful human review of an adverse outcome, to the extent commercially reasonable. They also have the right to access and correct the personal data that was used as input to the ADMT.
The phrase “to the extent commercially reasonable” is doing real work here—and it’s one of the reasons the proposed AG rules matter. How that phrase gets defined in rulemaking will substantially affect what organizations are actually obligated to build.
Developer Obligations
For organizations building or substantially modifying ADMT systems, SB 26-189 requires:
- Technical documentation describing the system’s intended uses, training data categories, known limitations, and instructions for meaningful human review
- Proactive notification to deployers when material updates are made to the system
Developer liability is scoped: developers are responsible to the extent that deployers used the ADMT in a manner that the developer intended, documented, marketed, or configured. If a deployer misuses a system in ways the developer didn’t envision or support, the liability allocation shifts.
Why Financial Services Companies Got Hit Harder
The original SB 24-205 exempted regulated financial institutions from its requirements if they were already subject to “substantially similar obligations” under federal or state law. The implicit assumption was that existing model risk management guidance, fair lending requirements, and OCC/FDIC/Fed supervision created enough of an equivalent compliance framework.
Colorado’s legislature disagreed—or at least didn’t extend that argument to the new statute.
SB 26-189 eliminated the exemption outright, without explanation of why. The result: banks, credit unions, mortgage lenders, auto lenders, insurance companies, and fintechs are now subject to Colorado’s ADMT consumer disclosure requirements regardless of what else they comply with.
For organizations using AI in credit underwriting, loan pricing, deposit account approval, credit card decisioning, or insurance underwriting for Colorado residents—any of which would qualify as a “consequential decision” related to financial or lending services—SB 26-189 obligations apply.
The AML/CFT and Sanctions Carve-Out
There is meaningful good news for compliance-heavy financial institutions. SB 26-189 expressly excludes AML/CFT and sanctions compliance activities from both the definition of ADMT and the definition of consequential decision.
Transaction monitoring systems, sanctions screening tools, and SAR workflows are out of scope. So is the automated model generating BSA/AML risk scores on customers.
What’s in scope: the credit underwriting model, the loan pricing engine, the deposit account approval workflow, the insurance underwriting system—anything that produces an adverse outcome for a Colorado consumer’s access to or terms of financial services.
The AG Proposed Rules: Why September 4 Matters
On August 11, 2026, Colorado AG Phil Weiser released proposed rules implementing SB 26-189. The rules go further than the statute text in specifying what compliance actually looks like operationally.
Key areas the proposed rules address:
- Notice format and timing: what “clear and conspicuous” means in digital and in-person contexts, and at what point in the consumer interaction the notice must appear
- Adverse outcome explanation content: minimum content requirements for the 30-day explanation, including how to describe ADMT’s role without disclosing proprietary model details
- Meaningful human review: what qualifies as meaningful, and whether automated re-review counts
- Consumer rights processes: how organizations must respond to data access and correction requests
The comment period has two tracks:
- September 4, 2026: Comments submitted by this date are considered for revisions presented at the October 26 rulemaking hearing
- October 26, 2026: The hearing date; comments are open through this date
If your organization has operations or customers in Colorado and uses automated decisioning for credit, insurance, or lending, the proposed rules are worth reviewing before September 4—particularly the definitions of “meaningful human review” and the adverse outcome explanation content requirements, both of which will drive significant operational build.
What Financial Services Teams Need to Do Before January 1
Step 1: Map Your ADMT Use Cases
Identify every system that generates predictions, recommendations, classifications, or scores used in decisions about Colorado residents’ access to financial or lending services. This includes:
- Credit underwriting and pricing models
- Deposit account approval workflows
- Insurance underwriting systems
- Loan modification and hardship decisioning
- Account restriction or closure workflows
Exclude AML/CFT and sanctions systems from this inventory—they’re carved out. But document why they’re excluded, not just that they are.
Step 2: Assess the Pre-Use Notice Gap
For each covered ADMT use case, identify where in the consumer interaction the required pre-use notice would need to appear. For applications and onboarding flows, this is usually manageable. For periodic decisions made on existing accounts (loan repricing, credit limit reductions), the notice timing is more complex and may require process redesign.
Step 3: Build the Adverse Outcome Disclosure Workflow
The 30-day explanation requirement creates an operational requirement that doesn’t fit neatly into most existing adverse action workflows. Fair lending adverse action notices handle credit declinations under Reg B/ECOA, but SB 26-189’s requirements are broader: any adverse outcome in any consequential category, with specific ADMT-role disclosure.
For high-volume automated decisioning, this likely means building an automated disclosure generation workflow—one that can pull the relevant data inputs, describe the system’s role in plain language, and trigger a consumer-facing communication within the 30-day window.
Step 4: Design the Human Review Process
The right to “meaningful human review” is going to be operationally significant for high-volume decisioning. Whatever human review means after rulemaking, it needs to be a documented process with a clear owner, a defined scope, and evidence that it happened.
Lenders and insurance companies that make thousands of automated decisions per day will need to think carefully about what “commercially reasonable” human review looks like at scale—and whether they need to lobby that definition during the September/October comment period.
Step 5: Update Developer Agreements
If your organization licenses AI models from third-party vendors and uses them for consequential decisions, SB 26-189 creates documentation requirements that flow upstream. You need the vendor’s technical documentation covering intended uses, training data categories, known limitations, and human review instructions. Review your vendor contracts to confirm these deliverables exist and are contractually required on update.
The Right-to-Cure Window and Enforcement
Until January 1, 2030, SB 26-189 includes a 60-day right-to-cure period after receiving notice of a violation. This doesn’t mean organizations get three years of no-consequence noncompliance—it means a first violation can be remediated before penalty rather than resulting in immediate enforcement.
After January 1, 2030, enforcement is direct with no cure period. The AG has exclusive enforcement authority; there’s no private right of action. Penalties will be determined through rulemaking and will follow Colorado’s consumer protection framework.
The cure window is meaningful, but it shouldn’t be treated as a compliance runway. By January 1, 2027, organizations should have documented processes for pre-use notice, adverse outcome disclosure, and human review—not just aspirational plans.
The Bigger Picture
Colorado’s pivot from SB 24-205 to SB 26-189 reflects a broader legislative trend: state AI laws are getting more specific about consumer-facing rights rather than broader about enterprise governance. The disclosure-and-recourse model is replacing the governance-and-assessment model that the EU AI Act pioneered.
For financial services practitioners, this creates a specific compliance gap. Federal fair lending and model risk management frameworks handle many of the governance requirements—documentation, validation, monitoring—but they don’t map cleanly to proactive 30-day adverse outcome disclosure with explicit ADMT-role explanations. That’s a new obligation, even for organizations running mature model risk programs.
The good news: five months is enough time to build this if you start now. The bad news: it’s not enough time if you’re starting by confirming the law changed.
Colorado’s January 2027 deadline is real, the proposed rules are out, and the comment window closes in 11 days. The sprint is on.
So What?
- Confirm your ADMT inventory: not everything with an algorithm, just the systems generating outputs used in consequential decisions about Colorado residents’ access to financial services
- Submit comments before September 4 if you have concerns about how “meaningful human review” or adverse outcome notice requirements will be defined
- Close the vendor documentation gap: third-party AI vendors need to supply the technical documentation SB 26-189 requires; confirm it’s in your contracts
- Design the 30-day adverse disclosure workflow: this is the operationally heaviest requirement and the one most likely to require technology investment
- The AML/CFT carve-out covers your compliance-oriented AI; the credit, insurance, and lending decisioning systems are in scope
Related reading: Colorado AI Act (SB 205) Compliance Guide (context on the original law SB 26-189 replaced), AI in Consequential Decision-Making: Where Regulators Draw the Compliance Line, AI Model Inventory Management for Regulatory Exams
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What happened to Colorado SB 24-205—the original Colorado AI Act?
Does SB 26-189 still apply to banks and credit unions?
What is 'automated decision-making technology' under SB 26-189?
Are AML and sanctions compliance activities excluded from the law?
What is the deadline to submit comments on the proposed ADMT rules?
What is the right-to-cure period, and how does enforcement work?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
Regulatory Compliance
FTC Safeguards Rule: The 30-Day Breach Notification Clock Non-Banking Financial Institutions Keep Missing
The FTC Safeguards Rule requires non-banking financial institutions to notify the FTC within 30 days of a breach affecting 500+ consumers. Two years in, enforcement is still finding the same deficiencies.
Aug 22, 2026
Regulatory Compliance
How to Test a Bank CIP: Sampling, Evidence, Exceptions, and Conclusions
Customer identification program testing that covers population completeness, CIP attributes, evidence, exceptions, and defensible workpaper conclusions.
Aug 21, 2026
Regulatory Compliance
SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed
The SEC's Tricolor fraud case alleges $1.9B in ABS offerings and an $800M collateral hole. Here are the controls lenders should test now.
Aug 21, 2026