Policy

Colorado AI Rules Detail Disclosure, Review Requirements

Proposed regulations clarify how businesses must handle automated decisions and chatbot interactions under two state laws taking effect in 2027.

Omega Editorial· August 14, 2026· 3 min read

Colorado's Department of Law has released proposed regulations implementing two artificial intelligence laws scheduled to take effect January 1, 2027, establishing specific operational requirements for companies using automated decision-making technology and conversational AI systems.

The regulations, filed August 11, flesh out the Automated Decision-Making Technology in Consequential Decisions Act and the Conversational Artificial Intelligence Services Act. Both laws were enacted earlier this year, with the ADMT Act signed in May and the Chatbot Safety Act signed July 1. A formal rulemaking hearing is scheduled for October 26, 2026, with public comments accepted through that date.

Automated decision-making requirements

The proposed rules establish concrete timelines and procedures for companies deploying automated systems that materially influence consequential decisions in employment, financial services, housing, insurance, and education. When such systems produce an adverse outcome, deployers must provide written disclosure within 30 days using at least two communication methods.

These disclosures must explain the decision in plain language, describe the automated system's role, detail the principal reasons for the adverse outcome including any automatic denial factors and risk scores, and provide instructions for exercising consumer rights. The Attorney General will consider companies already providing adverse action notices under the Equal Credit Opportunity Act or Fair Credit Reporting Act as satisfying Colorado's requirements if they include the required automated decision-making content.

Consumers gain specific rights under the framework: they may request the personal data used in automated consequential decisions, correct factually inaccurate information, and demand meaningful human review. Deployers must acknowledge requests within 10 days and complete human reviews within 45 days. Reviewers must be independent, possess relevant expertise, and hold genuine authority to override automated decisions without assistance from the automated system itself.

The rules introduce a "midstream developer" category for companies that integrate third-party automated decision-making models into their own products. These entities must obtain and pass along all developer documentation from upstream providers to downstream deployers.

Chatbot safety provisions

Operators of conversational AI services accessible to the general public face distinct obligations. They must disclose that users are interacting with AI rather than humans, with minor users receiving persistent visible disclaimers throughout conversations. All users must see disclosures at the start of each day's first interaction, at least once every three hours during continuous sessions, and whenever they ask whether the chatbot is human.

Age estimation becomes mandatory, with self-declarations alone deemed insufficient. Acceptable methods include zero-knowledge proofs, facial recognition matched to government identification, and digital footprint assessment. Operators cannot willfully disregard signals that a user is a minor, including behavioral signals processed by the AI itself.

For minor users, operators must disable engagement-maximizing features such as leaderboards, badges, and login streaks. Privacy settings must default to maximum protection, including not retaining prior session information or using minor user data for model training. Operators must submit detailed annual reports to the Colorado Attorney General beginning July 1, 2027.

Why it matters

These regulations represent one of the most detailed state-level attempts to operationalize AI governance requirements. Financial services companies and other businesses operating in Colorado face potentially significant compliance burdens, particularly around disclosure requirements that may exceed current federal adverse action notice standards. The rules' approach to human review and data disclosure could expose proprietary model attributes while creating operational challenges for high-volume decision-making processes. Companies have until early October to submit formal comments that could shape the final requirements.

These details were first reported by the Consumer Financial Services Law Monitor.

#ai regulation#automated decision-making#colorado#chatbot safety#financial services compliance#consumer protection

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Policy

Policy· 3 min read

China AI Exports Could Weather Full US Decoupling, Citi Says

Analysts estimate even an extreme scenario would put less than 10% of Chinese exports at risk, though open-weight model restrictions pose uncertainty.

Via AI Watch · Aug 14, 2026
Policy· 3 min read

Federal AI Adoption Fails When Workforce Readiness Lags Technology

Half of federal leaders doubt their staffing can meet mission goals, yet commercial change management models ignore government's unique constraints.

Via AI Watch · Aug 14, 2026
Policy· 2 min read

Open-Source AI Models Face Looming Federal Oversight

Trump administration signals frontier open models may require government review as capabilities advance, despite current exemptions.

Via AI Watch · Aug 14, 2026