Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Regulatory Compliance

Colorado Replaced Its AI Law: SB 26-189 Targets Automated Decision-Making — What Financial Institutions Need Before January 1, 2027

Colorado's SB 24-205 was repealed and replaced by SB 26-189 before it ever took effect. The new law drops the high-risk AI framework for a consumer-focused ADMT regime — and eliminates the prudential regulator exemption banks were counting on.

By Rebecca Leung · June 30, 2026 ·
Table of Contents

TL;DR

  • Colorado repealed SB 24-205 and replaced it with SB 26-189, signed May 14, 2026 — effective January 1, 2027
  • The new law drops the “high-risk AI systems” framework in favor of “covered ADMT” — automated decision-making technology influencing credit, insurance, employment, and housing decisions
  • Eliminated: impact assessments, anti-discrimination duty, risk management programs. New: pre-use consumer notices, 30-day adverse outcome explanations, human review rights
  • No GLBA exemption — banks and fintechs supervised by federal regulators are in scope for lending, insurance, and employment ADMT affecting Colorado consumers

The Colorado AI Act your compliance team may have been preparing for doesn’t exist anymore.

Governor Polis signed Senate Bill 26-189 on May 14, 2026, repealing SB 24-205 before it ever took effect — and replacing Colorado’s landmark AI law with a substantially different framework. The “high-risk AI systems” compliance structure is gone. A new consumer-facing disclosure regime applies to automated decision-making in lending, insurance, employment, and healthcare, effective January 1, 2027.

For financial institutions, the change cuts both ways. Several of the most operationally demanding requirements from SB 24-205 — annual impact assessments, anti-discrimination duty, documented risk management programs — were eliminated. But the requirements that remain are consumer-facing obligations that need operational implementation before January. And the GLBA exemption that banks were relying on is gone entirely.

With six months until the effective date, here’s what changed and what you need to build.


What Happened to SB 24-205

SB 24-205 was always contentious. Governor Polis signed it in May 2024 but simultaneously wrote that he anticipated the General Assembly would “refine” it — essentially signaling he’d signed it reluctantly. The compliance calendar shifted twice:

  • Original effective date: February 1, 2026
  • Extended to: June 30, 2026 (special legislative session, August 2025)
  • Final status: Repealed by SB 26-189, signed May 14, 2026

SB 24-205’s core compliance obligations — duty of reasonable care, annual impact assessments, anti-discrimination requirements, risk management programs — never triggered. If your compliance team built a preparedness framework around SB 24-205, the specifics of that framework need to be reassessed against the new law.

The original Colorado AI Act compliance guide on this site documents what SB 24-205 required. Those obligations no longer apply.


What SB 26-189 Does Instead

SB 26-189 is narrower than SB 24-205 in what it requires structurally but more targeted in its consumer-facing obligations. Instead of a broad “reasonable care” standard applied to “high-risk AI systems,” SB 26-189 focuses on covered automated decision-making technology (ADMT) and imposes specific notice, explanation, and documentation requirements on deployers and developers.

”Covered ADMT” — The New Core Concept

A system qualifies as covered ADMT if it meets three criteria:

  1. It processes personal data using AI or machine-learning methods
  2. It produces a decision, recommendation, or score that materially influences a consequential decision
  3. That consequential decision falls within one of six covered sectors: employment, education, housing, credit or lending, insurance, or healthcare

The “materially influences” framing is the key scoping question. Purely automated decisioning systems — where the AI output is the decision — clearly qualify. But AI tools that generate options or recommendations that a human genuinely evaluates before deciding may fall outside scope. The law is targeting automated pipelines that effectively determine outcomes, not AI that supports human judgment.

Financial services applications in scope (most institutions):

  • Automated credit decisioning (approval/denial without human review)
  • AI-driven credit limit adjustments or reductions
  • Automated insurance pricing and underwriting
  • AI adverse action determination systems
  • Loan officer AI tools where the AI recommendation routinely drives the decision

Applications requiring scoping analysis:

  • AI tools that generate a recommended decision for a loan officer who exercises genuine discretion
  • Fraud detection flags that humans review and act on
  • Portfolio analytics tools that produce inputs for human credit committee review

Each system needs individual scoping analysis before January 1, 2027. The scoping determination should be documented — both because you’ll want the record if the AG ever asks, and because it drives your implementation priorities.


Who’s In Scope: The Financial Institution Question

SB 24-205 included a safe harbor for financial institutions “subject to examination by a state or federal prudential regulator under any published guidance or regulations that apply to the use of high-risk systems.” In practice, most banks and federally supervised fintechs interpreted this as potential protection — though the language was widely criticized as ambiguous.

SB 26-189 eliminates that exemption entirely.

There is no GLBA entity-level carve-out. There is no prudential regulator safe harbor. Banks, credit unions, and fintechs using covered ADMT for Colorado consumers are in scope, regardless of OCC, FDIC, CFPB, or Federal Reserve oversight.

This is one of the most significant practical changes in the new law for financial institutions. If your legal team’s SB 24-205 analysis concluded the prudential regulator exemption provided protection, that analysis needs to be redone.

One dimension to track alongside this: the CFPB Reg B final rule, which takes effect July 21, 2026, removes federal disparate impact liability for credit decisions. SB 26-189 does not import a disparate impact standard — its obligations are procedural (notices, explanations, human review), not substantive (anti-discrimination). But both rules are running simultaneously, and your credit AI program needs to account for what each requires independently.


SB 24-205 vs. SB 26-189: What Actually Changed

RequirementSB 24-205SB 26-189
Core frameworkHigh-risk AI systemsCovered ADMT
Anti-discrimination dutyRequiredEliminated
Annual impact assessmentsRequiredEliminated
Risk management programsRequiredEliminated
Pre-use consumer noticeRequiredStill required
Adverse outcome explanationRequiredStill required (30-day window)
Human review rightsRequiredStill required
Developer technical documentationRequiredStill required
Prudential regulator safe harborMurky exemptionNo exemption
Private right of actionNoneNone
Enforcement authorityColorado AGColorado AG
Effective dateRepealedJanuary 1, 2027

The eliminated requirements represent a genuine reduction in compliance burden. The retained requirements — notices, explanations, human review, developer documentation — are consumer-facing obligations that require operational infrastructure, not just policy documents.


What Financial Institutions Must Implement by January 1, 2027

1. Pre-Use Consumer Notice

Deployers must provide “clear and conspicuous” notice to consumers at the point of interaction when covered ADMT will be used to make or influence a consequential decision about them. The notice must precede the ADMT’s involvement.

In practice: If your loan application uses automated credit decisioning, the consumer must receive notice before the ADMT processes their application. A disclosure buried in the application’s terms and conditions won’t satisfy the “conspicuous” standard. The notice must be visible and prominent within the application flow itself.

Map every consumer touchpoint where covered ADMT applies and design the notice delivery mechanism for each channel — web application, mobile app, in-branch kiosk, call center interaction.

2. Adverse Outcome Explanation (30-Day Window)

When covered ADMT results in an adverse outcome for a Colorado consumer, the deployer must provide, within 30 days:

  • A plain-language description of the ADMT’s role in the decision
  • A general explanation of how the decision was reached
  • Information about the consumer’s right to request human review and to appeal

In practice: Your existing adverse action notification process — already required under ECOA/Regulation B — addresses some of this. But the SB 26-189 ADMT explanation is a separate, additive requirement with different content. The two notifications need to be coordinated and both need to be delivered. The Reg B adverse action notice doesn’t satisfy SB 26-189’s ADMT explanation, and vice versa.

Build the 30-day ADMT explanation into your adverse action workflow, alongside (not instead of) your existing regulatory notifications.

3. Human Review Rights

Consumers must have access to meaningful human review of adverse decisions where it is technically feasible. Deployers must build and document this process.

In practice: If your automated denial process doesn’t have a functional human review pathway, build one. “Technically feasible” will be read in light of your institution’s size and resources — a large bank offering no human review pathway will have a harder argument than a small fintech with genuine technical constraints. Document the rationale for any human review limitations.

4. Developer Technical Documentation

Developers of covered ADMT must provide deployers with technical documentation covering:

  • Intended uses of the system
  • Categories of training data used
  • Known limitations and failure modes
  • Instructions for appropriate use and activation of human review

In practice: If you’re buying covered ADMT from a vendor, your contracts need to require this documentation before deployment. If you’re building ADMT in-house, your model development process must produce it. Neither of these is a quick fix — vendor contracts take time to negotiate, and model documentation requirements need to be built into development workflows.

Start the vendor documentation conversation now. Add it to your next vendor questionnaire update. The AI fair lending and algorithmic decisioning guidance covers the model documentation requirements that overlap with SB 26-189’s developer documentation mandate.


Documentation Retention

SB 26-189 requires three-year retention of ADMT compliance documentation — notices delivered, adverse outcome explanations, human review requests and outcomes, and developer documentation received. Build the retention framework into your implementation rather than treating it as an afterthought.


Enforcement and Penalties

The Colorado Attorney General has exclusive enforcement authority. There is no private right of action under SB 26-189 — individual consumers cannot sue you directly for violations.

Before initiating enforcement, the AG must provide a 60-day notice-to-cure for most violations, giving deployers and developers an opportunity to correct. This right to cure expires January 1, 2030.

Violations are classified as deceptive trade practices under the Colorado Consumer Protection Act. Civil penalties can reach $20,000 per violation. Given that the law applies per-consumer-per-decision, a systematic failure in the notice or explanation process could accumulate quickly.


So What? Your Six-Month Implementation Checklist

January 1, 2027 is six months away. Here’s how to structure the work:

July 2026 — Inventory and Scoping

  • Identify all AI systems used to make or influence credit, insurance, employment, or housing decisions affecting Colorado residents
  • Apply the ADMT definition test to each: personal data + material influence + consequential decision in covered sector?
  • Flag systems where the scoping question is genuinely unclear — get legal analysis now, not in December

August 2026 — Gap Analysis and Vendor Review

  • Review AI vendor contracts for developer documentation requirements — almost certainly missing in most agreements
  • Draft vendor questionnaires requesting SB 26-189 technical documentation packages (intended uses, training data categories, known limitations, human review instructions)
  • Map your current adverse action process and identify where the 30-day ADMT explanation must be added
  • Assess prudential regulator exemption assumptions — if prior analysis relied on SB 24-205’s safe harbor, redo it

September–October 2026 — Implementation Planning

  • Draft pre-use consumer notice language for each covered ADMT application flow
  • Design the adverse outcome explanation workflow, timing triggers, and documentation requirements
  • Design or document the human review pathway for adverse decisions

November–December 2026 — Testing and Finalization

  • Test notice delivery across application channels: web, mobile, in-branch, call center
  • Run end-to-end scenario: covered ADMT adverse outcome → 30-day explanation workflow → human review pathway
  • Finalize employee training on consumer rights under SB 26-189
  • Confirm three-year retention mechanism is operational

For teams building out AI governance programs to track covered ADMT alongside model inventory and risk tiering, the AI Risk Assessment Template & Guide includes a use case inventory with risk classification that can be extended to flag Colorado ADMT scope — and is already mapped to the Colorado AI Act alongside NIST AI RMF, OCC model risk guidance, and CFPB ECOA requirements.


The Practical Bottom Line

Colorado didn’t walk back AI regulation — it rewrote it. The new law is less burdensome in some ways (no impact assessments, no anti-discrimination duty) and more targeted in others (specific consumer notice obligations, 30-day explanation timelines, human review requirements). For financial institutions, the elimination of the prudential regulator safe harbor is the headline change that determines whether you’re in scope at all.

Six months is sufficient to implement the notice, explanation, and documentation requirements — if you start the vendor conversations and scoping analysis now rather than in Q4.

The firms that treat SB 26-189 as “just like SB 24-205 but delayed” are the ones who’ll arrive at January 2027 with policies that reference a repealed law and consumer notice processes that were never built.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What happened to Colorado SB 24-205?
SB 24-205 was repealed and replaced by SB 26-189 before it ever took effect. Governor Polis signed SB 26-189 on May 14, 2026. SB 24-205 had a February 1, 2026 effective date, which was pushed to June 30, 2026 by a 2025 special session; SB 26-189 then repealed it entirely and replaced it with a different legal framework focused on automated decision-making technology (ADMT) rather than high-risk AI systems.
What is 'covered ADMT' under SB 26-189?
Covered ADMT refers to automated decision-making technology that processes personal data to produce decisions, recommendations, or outputs that materially influence consequential decisions in six sectors: employment, education, housing, credit or lending, insurance, and healthcare. The focus is on AI systems influencing specific consequential outcomes for individuals — not AI tools in general.
Are banks and fintechs covered under SB 26-189?
Yes. SB 26-189 eliminated the murky prudential regulator exemption that existed in SB 24-205. Banks, credit unions, and fintechs using covered ADMT to make or influence credit decisions, loan approvals, insurance pricing, or financial service eligibility for Colorado consumers are in scope — regardless of federal regulatory oversight. There is no GLBA entity-level exemption.
What consumer disclosures does SB 26-189 require from deployers?
Deployers must provide: (1) clear, conspicuous pre-use notice that the consumer will be subject to covered ADMT; (2) within 30 days after an adverse outcome, a plain-language description of the ADMT's role, a general explanation of how the decision was reached, and information about the consumer's right to appeal and request human review.
What developer documentation does SB 26-189 require?
Developers of covered ADMT must provide deployers with technical documentation covering: intended uses of the system, categories of training data, known limitations and failure modes, and instructions for appropriate use and human review. This documentation must be provided before deployment. Deployers who use ADMT without receiving this documentation bear their own compliance risk.
What are the penalties for violating SB 26-189?
Violations are treated as deceptive trade practices under the Colorado Consumer Protection Act, with civil penalties up to $20,000 per violation. The Colorado Attorney General has exclusive enforcement authority — no private right of action exists. The AG must provide a 60-day notice-to-cure before enforcement (this right-to-cure period expires January 1, 2030).
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.