Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

Colorado Rewrites Its AI Law: What SB 26-189 Means for Banks and Fintechs

Colorado's SB 26-189, signed May 14, 2026, replaces the original Colorado AI Act and eliminates the financial institution safe harbor. Here's what the new automated decision-making law requires before January 1, 2027.

By Rebecca Leung · June 4, 2026 ·
Table of Contents

TL;DR:

  • Colorado signed SB 26-189 on May 14, 2026, replacing the original Colorado AI Act with a narrower framework for “automated decision-making technology” — effective January 1, 2027.
  • The new law eliminates the financial institution safe harbor. Banks, fintechs, credit unions, and lenders doing business in Colorado are now squarely in scope.
  • Deployers face three obligations: pre-use consumer notice, a 30-day post-adverse outcome notice, and the right to request human review.
  • ECOA and FCRA provide a partial carve-out for credit decisions, but the notice and human review requirements are separate obligations that those statutes don’t satisfy on their own.

The Financial Institution Safe Harbor Is Gone

When Colorado passed SB 24-205 in 2024, most financial institutions exhaled. The original Colorado AI Act included a safe harbor: if you were subject to examination by a state or federal prudential regulator under published guidance on AI use, you were in full compliance. Banks and fintechs regulated by the OCC, Federal Reserve, FDIC, CFPB, or Colorado Division of Banking could plausibly argue they were off the hook.

That safe harbor no longer exists.

On May 14, 2026, Governor Jared Polis signed SB 26-189, which repeals and replaces SB 24-205 entirely. The replacement law is narrower in some ways — it drops the original law’s governance framework requirements, annual impact assessments, and extensive algorithmic discrimination duties — but it explicitly pulls financial institutions into its scope by eliminating the exemption. Banks, credit unions, fintechs, and lenders doing business in Colorado now have a clear compliance obligation under the new framework.

If your team stopped tracking Colorado’s AI law after the 2024 passage, this post is the update you missed.

What Happened to the Original Colorado AI Act

SB 24-205 was widely criticized from the moment it passed. Compliance teams, legal departments, and industry groups argued that the law was unworkable: the risk management program requirements were vague, the annual impact assessment obligations were operationally burdensome, and the definitions — particularly “high-risk artificial intelligence system” and “algorithmic discrimination” — created significant legal uncertainty.

The business community pushed back hard. Governor Polis had raised concerns about the original bill even while signing it, encouraging the legislature to revisit. The Colorado legislature did exactly that, and SB 26-189 is the result: a substantially scaled-back version that retains the consumer-facing notice and rights structure but drops the upstream governance, bias prevention, and impact assessment requirements that made SB 24-205 difficult to operationalize.

The replacement has fewer requirements. But it covers more financial institutions than the original, because the safe harbor is gone.

What SB 26-189 Actually Requires

The Trigger: Automated Decision-Making Technology + Consequential Decisions

The law applies when a “deployer” — an entity that uses covered ADMT to make or assist decisions about Colorado consumers — uses that technology in connection with a “consequential decision” in one of seven covered domains:

  1. Education
  2. Employment (decisions that may create an employer–employee relationship)
  3. Residential real estate (leasing or purchasing in Colorado)
  4. Financial and lending services
  5. Insurance (including underwriting, pricing, coverage, and claims)
  6. Health care services
  7. Essential government services and public benefits

For financial services teams, “financial and lending services” is the operative domain. A consequential decision is any decision, determination, or action relating to access, eligibility, selection, or compensation in that domain.

ADMT is defined broadly: technology that processes personal data and uses computation to generate outputs — predictions, recommendations, classifications, rankings, or scores — that are used to make, guide, or assist decisions about individuals. That covers credit scoring models, fraud detection algorithms, loan underwriting engines, dynamic fee pricing tools, and customer service routing systems that affect eligibility or service access.

The Three Deployer Obligations

1. Pre-Use Consumer Notice

Before using covered ADMT to materially influence a consequential decision, you must provide “clear and conspicuous notice” to the consumer. The notice must inform them that ADMT is being used and explain how to get additional information.

This does not require individual notification before every credit decision — the law permits “prominent public notice that is reasonably accessible during the consumer interaction,” which can include a link or disclosure proximate to the transaction. Think: a disclosure in your loan application flow, your account opening process, or your customer portal.

The practical implication: if you have AI-assisted credit decisions, risk pricing, or eligibility determinations affecting Colorado consumers, you need a disclosure. If you don’t have one, you need to build it before January 1, 2027.

2. Post-Adverse Outcome Notice (30-Day Window)

If your ADMT materially influences an adverse decision — a loan denial, a materially reduced benefit, or significantly worse pricing than what a similarly situated consumer would receive — you must notify the consumer within 30 days of that decision. The notice must include:

  • A plain-language description of the covered ADMT’s role in the decision
  • How the consumer can request more information about the system and the types, categories, and sources of personal data used (to the extent provided by your developer)
  • A description of the consumer’s rights under the statute and how to exercise them

This is different from and in addition to your ECOA adverse action notice obligations. ECOA tells borrowers why they were denied. SB 26-189 tells them that an automated system was involved and how to get more information about it.

3. Consumer Rights: Human Review

Consumers have the right to access and correct their personal data used in the consequential decision and to request meaningful human review of the decision “to the extent commercially reasonable.” This phrase does significant legal work — it’s not an absolute guarantee of human review, but it’s an obligation that requires you to have a process for receiving and responding to such requests.

For high-volume automated decisioning (think: real-time fraud detection with automated account closure), the “commercially reasonable” standard may allow significant limitations. But you need a written policy and a documented process, not a vague assurance.

Developer Obligations

If you’re not just deploying AI but also building or licensing ADMT to deployers, SB 26-189 imposes separate obligations. Developers must provide deployers with documentation covering:

  • Intended uses of the ADMT
  • Known limitations
  • Categories of training data used
  • Instructions for appropriate use and how to support human review

Developers must retain these records for at least three years and update them when material changes occur. They are not required to disclose trade secrets, but the documentation obligation applies when the ADMT was “marketed, advertised, configured, contracted, sold, or licensed” for use in consequential decisions.

For fintechs using third-party AI vendors — a credit scoring model from a fintech vendor, a fraud engine from a risk SaaS platform — this means your vendor contracts should require SB 26-189-compliant documentation. Add it to your vendor questionnaire now.

The ECOA and FCRA Credit Decision Carve-Out

SB 26-189 acknowledges the existing federal framework for credit decisions. Creditors complying with the Equal Credit Opportunity Act (ECOA), Regulation B, and the Fair Credit Reporting Act (FCRA) for credit-related decisions are noted as having certain carve-outs from the law’s requirements.

This does provide meaningful relief for traditional credit underwriting decisions. If your adverse action notice already satisfies Regulation B and your credit bureau disclosures satisfy FCRA, you won’t be required to stack a completely separate SB 26-189 adverse outcome notice on top for the same credit decision.

But the carve-out has limits. First, it covers “credit-related decisions” specifically — not all financial and lending decisions that may involve ADMT. Dynamic fee pricing, deposit account closure, customer tiering, and service eligibility decisions may not fit cleanly into the credit carve-out. Second, the pre-use notice and human review rights are separate requirements that ECOA doesn’t address. You need to review each obligation independently before relying on the federal framework to satisfy it.

What This Looks Like for Fintech AI Systems

Here’s a practical inventory of AI systems fintechs commonly operate and how they map to SB 26-189:

ADMT SystemDomainConsequential?Action Needed
Credit underwriting modelFinancial/lendingYes — loan approval/denialPre-use notice + adverse outcome notice + human review process (ECOA carve-out may apply)
Fraud detection / account freezeFinancial/lendingYes — account accessPre-use notice + adverse outcome notice within 30 days
Dynamic pricing / fee engineFinancial/lendingDepends — materially worse pricingPre-use notice + adverse outcome notice if pricing is materially adverse
Customer service routing (tier/eligibility)Financial/lendingDependsPre-use notice if routing affects access to benefits or services
KYC/identity verificationFinancial/lendingYes — account opening accessPre-use notice + adverse outcome notice if denied
AML transaction monitoring (auto-block)Financial/lendingYes — service disruptionPre-use notice + adverse outcome notice + human review

The common thread: if an AI system determines or materially influences whether a Colorado consumer gets access to, is eligible for, or receives a specific price or benefit in connection with a financial service, it is likely ADMT being used for a consequential decision.

Compliance Checklist for January 1, 2027

Before the effective date, your team needs to:

  • Inventory your ADMT systems — identify every AI or algorithmic system that makes or materially influences decisions about Colorado consumers in financial services. This is your starting point.
  • Assess which decisions are “consequential” — access, eligibility, selection, or compensation in financial and lending services. Document your analysis.
  • Draft pre-use notices — clear, conspicuous disclosure that ADMT is being used, proximate to the interaction. Work with legal to draft language for each touchpoint.
  • Build a 30-day adverse outcome notification workflow — who receives the complaint, who drafts the notice, what language does it include, what does your developer documentation say about the system’s role?
  • Stand up a human review request process — even if “commercially reasonable” limits the scope, you need a documented intake, evaluation, and response process.
  • Audit vendor contracts for SB 26-189 documentation requirements — does your AI vendor provide the documentation SB 26-189 requires? Add it to your next vendor questionnaire cycle.
  • Assess the ECOA/FCRA carve-out — for credit decisions specifically, document why existing adverse action procedures satisfy SB 26-189’s requirements, or identify gaps.
  • Flag Colorado-specific obligations to your AI governance program — the AI Risk Assessment Template includes a use case inventory and pre-deployment checklist where these obligations should be mapped to each system.

So What?

The original Colorado AI Act got a lot of attention when it passed in 2024, but most financial institutions assumed the safe harbor covered them. SB 26-189 removes that assumption. With an effective date of January 1, 2027, you have seven months — enough time to get this right if you start now, not enough time if you treat it as a 2026 Q4 problem.

The obligations under SB 26-189 are narrower than the original law — no governance framework, no annual impact assessments — but they’re operationally real. Pre-use notices require legal review. Adverse outcome notification workflows require process design. Human review policies require documented procedures.

The AI systems that matter most are the ones already at the top of your risk register: credit decisioning, fraud detection, account access controls, and dynamic pricing. If you don’t have an AI use case inventory, this is the moment to build one.

For teams starting from scratch on AI governance documentation, the AI Risk Assessment Template & Guide includes a use case inventory tab with risk tiering logic, a pre-deployment checklist across 11 risk domains, and a vendor questionnaire designed to capture exactly the documentation SB 26-189 requires from developers — so your compliance work and your governance program feed the same artifact. You can get it at buy.stripe.com/3cI7sE4kX7tF23jcTk6J200.


Sources: Colorado SB 26-189 text | Cooley: The New Colorado AI Act: What Financial Institutions Need to Know | Finnegan: Colorado Replaces Landmark AI Act — Overview of SB 26-189 Framework | Consumer Finance Monitor: Colorado Rewrites Its Landmark AI Law | ArentFox Schiff: Colorado Replaces Its Landmark AI Act With New Framework

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is Colorado SB 26-189?
Colorado SB 26-189 is a replacement AI law signed by Governor Polis on May 14, 2026. It repeals and replaces the original Colorado AI Act (SB 24-205) with a narrower framework focused on 'automated decision-making technology' (ADMT) used to make consequential decisions about consumers. It takes effect January 1, 2027.
Are financial institutions exempt from Colorado SB 26-189?
No. The original Colorado AI Act (SB 24-205) included a safe harbor for financial institutions subject to examination by state or federal prudential regulators. SB 26-189 eliminates that exemption entirely. Banks, credit unions, fintechs, and lenders doing business in Colorado are subject to the new law.
What is 'automated decision-making technology' under SB 26-189?
SB 26-189 defines ADMT broadly as technology that processes personal data and uses computation to generate outputs — predictions, recommendations, classifications, rankings, or scores — that are used to make, guide, or assist decisions about individuals. This covers credit scoring models, fraud detection algorithms, dynamic pricing systems, and loan underwriting tools.
What does the 30-day adverse outcome notice require?
If your covered ADMT materially influences an adverse decision — a loan denial, a materially reduced benefit, or significantly worse pricing — you must provide the consumer within 30 days with a plain-language description of the ADMT's role, an explanation of how to request more information about the system and the data used, and a description of the consumer's rights and how to exercise them.
Does ECOA or FCRA compliance satisfy the SB 26-189 credit decision requirements?
Partially. Creditors complying with ECOA, Regulation B, and the FCRA for credit-related decisions are noted in SB 26-189 as having certain carve-outs. However, the law still applies to other consequential decisions in the financial and lending services domain beyond traditional credit decisions, and the pre-use notice and human review rights are separate requirements that ECOA alone does not satisfy.
When does SB 26-189 take effect?
January 1, 2027. You have approximately seven months to map your ADMT systems, draft pre-use notices, build adverse outcome notification workflows, and verify developer documentation for your AI vendors.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.