Colorado AI Rules Detail Disclosure, Review Requirements
Proposed regulations clarify how businesses must handle automated decisions and chatbot interactions under two state laws taking effect in 2027.
Colorado's Department of Law has released proposed regulations implementing two artificial intelligence laws scheduled to take effect January 1, 2027, establishing specific operational requirements for companies using automated decision-making technology and conversational AI systems.
The regulations, filed August 11, flesh out the Automated Decision-Making Technology in Consequential Decisions Act and the Conversational Artificial Intelligence Services Act. Both laws were enacted earlier this year, with the ADMT Act signed in May and the Chatbot Safety Act signed July 1. A formal rulemaking hearing is scheduled for October 26, 2026, with public comments accepted through that date.
Automated decision-making requirements
The proposed rules establish concrete timelines and procedures for companies deploying automated systems that materially influence consequential decisions in employment, financial services, housing, insurance, and education. When such systems produce an adverse outcome, deployers must provide written disclosure within 30 days using at least two communication methods.
These disclosures must explain the decision in plain language, describe the automated system's role, detail the principal reasons for the adverse outcome including any automatic denial factors and risk scores, and provide instructions for exercising consumer rights. The Attorney General will consider companies already providing adverse action notices under the Equal Credit Opportunity Act or Fair Credit Reporting Act as satisfying Colorado's requirements if they include the required automated decision-making content.
Consumers gain specific rights under the framework: they may request the personal data used in automated consequential decisions, correct factually inaccurate information, and demand meaningful human review. Deployers must acknowledge requests within 10 days and complete human reviews within 45 days. Reviewers must be independent, possess relevant expertise, and hold genuine authority to override automated decisions without assistance from the automated system itself.
The rules introduce a "midstream developer" category for companies that integrate third-party automated decision-making models into their own products. These entities must obtain and pass along all developer documentation from upstream providers to downstream deployers.
Chatbot safety provisions
Operators of conversational AI services accessible to the general public face distinct obligations. They must disclose that users are interacting with AI rather than humans, with minor users receiving persistent visible disclaimers throughout conversations. All users must see disclosures at the start of each day's first interaction, at least once every three hours during continuous sessions, and whenever they ask whether the chatbot is human.
Age estimation becomes mandatory, with self-declarations alone deemed insufficient. Acceptable methods include zero-knowledge proofs, facial recognition matched to government identification, and digital footprint assessment. Operators cannot willfully disregard signals that a user is a minor, including behavioral signals processed by the AI itself.
For minor users, operators must disable engagement-maximizing features such as leaderboards, badges, and login streaks. Privacy settings must default to maximum protection, including not retaining prior session information or using minor user data for model training. Operators must submit detailed annual reports to the Colorado Attorney General beginning July 1, 2027.
Why it matters
These regulations represent one of the most detailed state-level attempts to operationalize AI governance requirements. Financial services companies and other businesses operating in Colorado face potentially significant compliance burdens, particularly around disclosure requirements that may exceed current federal adverse action notice standards. The rules' approach to human review and data disclosure could expose proprietary model attributes while creating operational challenges for high-volume decision-making processes. Companies have until early October to submit formal comments that could shape the final requirements.
These details were first reported by the Consumer Financial Services Law Monitor.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call

