Feature AI Risk
Colorado Rewrites Its AI Law: What SB 26-189 Means for Banks and Fintechs
Colorado's SB 26-189, signed May 14, 2026, replaces the original Colorado AI Act and eliminates the financial institution safe harbor. Here's what the new automated decision-making law requires before January 1, 2027.
Table of Contents
TL;DR:
- Colorado signed SB 26-189 on May 14, 2026, replacing the original Colorado AI Act with a narrower framework for “automated decision-making technology” — effective January 1, 2027.
- The new law eliminates the financial institution safe harbor. Banks, fintechs, credit unions, and lenders doing business in Colorado are now squarely in scope.
- Deployers face three obligations: pre-use consumer notice, a 30-day post-adverse outcome notice, and the right to request human review.
- ECOA and FCRA provide a partial carve-out for credit decisions, but the notice and human review requirements are separate obligations that those statutes don’t satisfy on their own.
The Financial Institution Safe Harbor Is Gone
When Colorado passed SB 24-205 in 2024, most financial institutions exhaled. The original Colorado AI Act included a safe harbor: if you were subject to examination by a state or federal prudential regulator under published guidance on AI use, you were in full compliance. Banks and fintechs regulated by the OCC, Federal Reserve, FDIC, CFPB, or Colorado Division of Banking could plausibly argue they were off the hook.
That safe harbor no longer exists.
On May 14, 2026, Governor Jared Polis signed SB 26-189, which repeals and replaces SB 24-205 entirely. The replacement law is narrower in some ways — it drops the original law’s governance framework requirements, annual impact assessments, and extensive algorithmic discrimination duties — but it explicitly pulls financial institutions into its scope by eliminating the exemption. Banks, credit unions, fintechs, and lenders doing business in Colorado now have a clear compliance obligation under the new framework.
If your team stopped tracking Colorado’s AI law after the 2024 passage, this post is the update you missed.
What Happened to the Original Colorado AI Act
SB 24-205 was widely criticized from the moment it passed. Compliance teams, legal departments, and industry groups argued that the law was unworkable: the risk management program requirements were vague, the annual impact assessment obligations were operationally burdensome, and the definitions — particularly “high-risk artificial intelligence system” and “algorithmic discrimination” — created significant legal uncertainty.
The business community pushed back hard. Governor Polis had raised concerns about the original bill even while signing it, encouraging the legislature to revisit. The Colorado legislature did exactly that, and SB 26-189 is the result: a substantially scaled-back version that retains the consumer-facing notice and rights structure but drops the upstream governance, bias prevention, and impact assessment requirements that made SB 24-205 difficult to operationalize.
The replacement has fewer requirements. But it covers more financial institutions than the original, because the safe harbor is gone.
What SB 26-189 Actually Requires
The Trigger: Automated Decision-Making Technology + Consequential Decisions
The law applies when a “deployer” — an entity that uses covered ADMT to make or assist decisions about Colorado consumers — uses that technology in connection with a “consequential decision” in one of seven covered domains:
- Education
- Employment (decisions that may create an employer–employee relationship)
- Residential real estate (leasing or purchasing in Colorado)
- Financial and lending services
- Insurance (including underwriting, pricing, coverage, and claims)
- Health care services
- Essential government services and public benefits
For financial services teams, “financial and lending services” is the operative domain. A consequential decision is any decision, determination, or action relating to access, eligibility, selection, or compensation in that domain.
ADMT is defined broadly: technology that processes personal data and uses computation to generate outputs — predictions, recommendations, classifications, rankings, or scores — that are used to make, guide, or assist decisions about individuals. That covers credit scoring models, fraud detection algorithms, loan underwriting engines, dynamic fee pricing tools, and customer service routing systems that affect eligibility or service access.
The Three Deployer Obligations
1. Pre-Use Consumer Notice
Before using covered ADMT to materially influence a consequential decision, you must provide “clear and conspicuous notice” to the consumer. The notice must inform them that ADMT is being used and explain how to get additional information.
This does not require individual notification before every credit decision — the law permits “prominent public notice that is reasonably accessible during the consumer interaction,” which can include a link or disclosure proximate to the transaction. Think: a disclosure in your loan application flow, your account opening process, or your customer portal.
The practical implication: if you have AI-assisted credit decisions, risk pricing, or eligibility determinations affecting Colorado consumers, you need a disclosure. If you don’t have one, you need to build it before January 1, 2027.
2. Post-Adverse Outcome Notice (30-Day Window)
If your ADMT materially influences an adverse decision — a loan denial, a materially reduced benefit, or significantly worse pricing than what a similarly situated consumer would receive — you must notify the consumer within 30 days of that decision. The notice must include:
- A plain-language description of the covered ADMT’s role in the decision
- How the consumer can request more information about the system and the types, categories, and sources of personal data used (to the extent provided by your developer)
- A description of the consumer’s rights under the statute and how to exercise them
This is different from and in addition to your ECOA adverse action notice obligations. ECOA tells borrowers why they were denied. SB 26-189 tells them that an automated system was involved and how to get more information about it.
3. Consumer Rights: Human Review
Consumers have the right to access and correct their personal data used in the consequential decision and to request meaningful human review of the decision “to the extent commercially reasonable.” This phrase does significant legal work — it’s not an absolute guarantee of human review, but it’s an obligation that requires you to have a process for receiving and responding to such requests.
For high-volume automated decisioning (think: real-time fraud detection with automated account closure), the “commercially reasonable” standard may allow significant limitations. But you need a written policy and a documented process, not a vague assurance.
Developer Obligations
If you’re not just deploying AI but also building or licensing ADMT to deployers, SB 26-189 imposes separate obligations. Developers must provide deployers with documentation covering:
- Intended uses of the ADMT
- Known limitations
- Categories of training data used
- Instructions for appropriate use and how to support human review
Developers must retain these records for at least three years and update them when material changes occur. They are not required to disclose trade secrets, but the documentation obligation applies when the ADMT was “marketed, advertised, configured, contracted, sold, or licensed” for use in consequential decisions.
For fintechs using third-party AI vendors — a credit scoring model from a fintech vendor, a fraud engine from a risk SaaS platform — this means your vendor contracts should require SB 26-189-compliant documentation. Add it to your vendor questionnaire now.
The ECOA and FCRA Credit Decision Carve-Out
SB 26-189 acknowledges the existing federal framework for credit decisions. Creditors complying with the Equal Credit Opportunity Act (ECOA), Regulation B, and the Fair Credit Reporting Act (FCRA) for credit-related decisions are noted as having certain carve-outs from the law’s requirements.
This does provide meaningful relief for traditional credit underwriting decisions. If your adverse action notice already satisfies Regulation B and your credit bureau disclosures satisfy FCRA, you won’t be required to stack a completely separate SB 26-189 adverse outcome notice on top for the same credit decision.
But the carve-out has limits. First, it covers “credit-related decisions” specifically — not all financial and lending decisions that may involve ADMT. Dynamic fee pricing, deposit account closure, customer tiering, and service eligibility decisions may not fit cleanly into the credit carve-out. Second, the pre-use notice and human review rights are separate requirements that ECOA doesn’t address. You need to review each obligation independently before relying on the federal framework to satisfy it.
What This Looks Like for Fintech AI Systems
Here’s a practical inventory of AI systems fintechs commonly operate and how they map to SB 26-189:
| ADMT System | Domain | Consequential? | Action Needed |
|---|---|---|---|
| Credit underwriting model | Financial/lending | Yes — loan approval/denial | Pre-use notice + adverse outcome notice + human review process (ECOA carve-out may apply) |
| Fraud detection / account freeze | Financial/lending | Yes — account access | Pre-use notice + adverse outcome notice within 30 days |
| Dynamic pricing / fee engine | Financial/lending | Depends — materially worse pricing | Pre-use notice + adverse outcome notice if pricing is materially adverse |
| Customer service routing (tier/eligibility) | Financial/lending | Depends | Pre-use notice if routing affects access to benefits or services |
| KYC/identity verification | Financial/lending | Yes — account opening access | Pre-use notice + adverse outcome notice if denied |
| AML transaction monitoring (auto-block) | Financial/lending | Yes — service disruption | Pre-use notice + adverse outcome notice + human review |
The common thread: if an AI system determines or materially influences whether a Colorado consumer gets access to, is eligible for, or receives a specific price or benefit in connection with a financial service, it is likely ADMT being used for a consequential decision.
Compliance Checklist for January 1, 2027
Before the effective date, your team needs to:
- Inventory your ADMT systems — identify every AI or algorithmic system that makes or materially influences decisions about Colorado consumers in financial services. This is your starting point.
- Assess which decisions are “consequential” — access, eligibility, selection, or compensation in financial and lending services. Document your analysis.
- Draft pre-use notices — clear, conspicuous disclosure that ADMT is being used, proximate to the interaction. Work with legal to draft language for each touchpoint.
- Build a 30-day adverse outcome notification workflow — who receives the complaint, who drafts the notice, what language does it include, what does your developer documentation say about the system’s role?
- Stand up a human review request process — even if “commercially reasonable” limits the scope, you need a documented intake, evaluation, and response process.
- Audit vendor contracts for SB 26-189 documentation requirements — does your AI vendor provide the documentation SB 26-189 requires? Add it to your next vendor questionnaire cycle.
- Assess the ECOA/FCRA carve-out — for credit decisions specifically, document why existing adverse action procedures satisfy SB 26-189’s requirements, or identify gaps.
- Flag Colorado-specific obligations to your AI governance program — the AI Risk Assessment Template includes a use case inventory and pre-deployment checklist where these obligations should be mapped to each system.
So What?
The original Colorado AI Act got a lot of attention when it passed in 2024, but most financial institutions assumed the safe harbor covered them. SB 26-189 removes that assumption. With an effective date of January 1, 2027, you have seven months — enough time to get this right if you start now, not enough time if you treat it as a 2026 Q4 problem.
The obligations under SB 26-189 are narrower than the original law — no governance framework, no annual impact assessments — but they’re operationally real. Pre-use notices require legal review. Adverse outcome notification workflows require process design. Human review policies require documented procedures.
The AI systems that matter most are the ones already at the top of your risk register: credit decisioning, fraud detection, account access controls, and dynamic pricing. If you don’t have an AI use case inventory, this is the moment to build one.
For teams starting from scratch on AI governance documentation, the AI Risk Assessment Template & Guide includes a use case inventory tab with risk tiering logic, a pre-deployment checklist across 11 risk domains, and a vendor questionnaire designed to capture exactly the documentation SB 26-189 requires from developers — so your compliance work and your governance program feed the same artifact. You can get it at buy.stripe.com/3cI7sE4kX7tF23jcTk6J200.
Related Reading
- California ADMT Regulations: What Fintechs Using AI for Credit, Fraud, and Customer Profiling Must Document Now
- EU AI Act High-Risk AI in Financial Services: What Banks and Fintechs Must Document by August 2, 2026
- AI Governance Framework for Financial Services: A Practical Guide for Risk and Compliance Teams
Sources: Colorado SB 26-189 text | Cooley: The New Colorado AI Act: What Financial Institutions Need to Know | Finnegan: Colorado Replaces Landmark AI Act — Overview of SB 26-189 Framework | Consumer Finance Monitor: Colorado Rewrites Its Landmark AI Law | ArentFox Schiff: Colorado Replaces Its Landmark AI Act With New Framework
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is Colorado SB 26-189?
Are financial institutions exempt from Colorado SB 26-189?
What is 'automated decision-making technology' under SB 26-189?
What does the 30-day adverse outcome notice require?
Does ECOA or FCRA compliance satisfy the SB 26-189 credit decision requirements?
When does SB 26-189 take effect?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
Jul 24, 2026
AI Risk
AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval
An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.
Jul 23, 2026
AI Risk
August 2 Is Ten Days Away: What the EU AI Act's High-Risk Deadline Actually Requires from Financial Services AI
The EU AI Act's Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here's what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.
Jul 22, 2026