Colorado Artificial Intelligence Act (proposed SB 24-205)
Evidence request list. 19 controls, 19 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Colorado AI Act: Consumer AI Disclosure (6-1-1704)
Any deployer or developer that deploys, offers or makes available an AI system intended to interact with consumers must disclose to each consumer that they are interacting with an AI system, unless it would be obvious to a reasonable person.
- Consumer-facing AI interaction disclosure (chatbot/assistant notice)
- No disclosure of AI interaction to consumers
Colorado AI Act: Defenses, Enforcement and Rules (6-1-1705 to 1707)
A developer/deployer has an affirmative defense if it discovers and cures a violation through internal testing/red-teaming and is otherwise in compliance with the latest NIST AI Risk Management Framework, ISO/IEC 42001, or another nationally/internationally recognised framework (or an AG-designated framework).
- Internal testing/red-teaming + cure records
- Evidence of compliance with a recognised AI framework
- No internal testing or recognised-framework alignment
The Attorney General has exclusive authority to enforce the Act; a violation is an unfair or deceptive trade practice under the Colorado Consumer Protection Act; there is no private right of action.
- Awareness of AG exclusive enforcement + CCPA unfair-practice exposure
- Cure-period procedures
- No legal-exposure assessment for AI deployment
The Attorney General may promulgate rules to implement and administer the Act (documentation, notices, impact-assessment content, risk-management requirements, rebuttable-presumption/affirmative-defense conditions).
- Monitoring of AG implementing rules and updating controls accordingly
- No tracking of AG rulemaking
Colorado AI Act: Definitions and Scope (6-1-1701)
Algorithmic discrimination is any condition in which the use of an AI system results in unlawful differential treatment or impact that disfavours an individual/group on the basis of a protected classification under state or federal law.
- Definition of algorithmic discrimination adopted
- Bias/disparate-impact testing methodology
- No bias-testing for protected classes
A high-risk AI system is one that, when deployed, makes or is a substantial factor in making a consequential decision: a decision with a material legal/similarly significant effect on a consumer's access to or terms of education, employment, financial/lending services, an essential government service, healthcare, housing, insurance, or legal services.
- Inventory of AI systems classified high-risk vs not
- Mapping of consequential-decision use to the eight statutory domains
- High-risk classification not assessed
- Consequential-decision use undocumented
Colorado AI Act: Deployer Duties (6-1-1703)
A deployer of a high-risk AI system must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination; compliance creates a rebuttable presumption of reasonable care.
- Deployer reasonable-care program evidence
- Rebuttable-presumption compliance file
- No deployer reasonable-care program
The deployer must implement a risk-management policy and program governing high-risk AI deployment, that is iterative, regularly reviewed/updated, and reasonable considering a nationally/internationally recognised AI risk-management framework such as the latest NIST AI Risk Management Framework or ISO/IEC 42001, or a framework designated by the Attorney General.
- AI risk-management policy and program aligned to NIST AI RMF / ISO 42001
- Periodic review/update records
- No AI risk-management program
- Program not aligned to a recognised framework
The deployer must complete an impact assessment for each high-risk AI system annually and within 90 days after any intentional and substantial modification; the assessment must cover purpose, intended use, benefits, discrimination risks and mitigation, data categories processed, outputs, monitoring and transparency measures; retained for at least three years.
- Impact assessments (annual + post-modification) with the 1703(3) content
- Three-year retention of assessments
- No/late impact assessments
- Assessments missing discrimination-risk analysis
Before, or as soon as feasible after, a high-risk AI system makes or is a substantial factor in a consequential decision, the deployer must notify the consumer that AI is used, describe the system and the nature of the decision, provide contact information and instructions to access the public statement, and (where applicable) the right to opt out of profiling.
- Consumer notice template + delivery records before consequential decisions
- No pre-decision consumer notice
If a consequential decision is adverse to the consumer, the deployer must provide the principal reasons (including how the AI system contributed and the data used), an opportunity to correct incorrect personal data, and an opportunity to appeal for human review where technically feasible.
- Adverse-decision explanation statements
- Data-correction + human-review appeal mechanism
- No explanation/appeal for adverse AI decisions
The deployer must publish a clear, readily available statement summarising the types of high-risk AI systems currently deployed and how it manages known or foreseeable risks of algorithmic discrimination.
- Published deployer high-risk-AI statement
- No public deployer statement
On discovering that a deployed high-risk AI system has caused algorithmic discrimination, the deployer must notify the Attorney General without unreasonable delay, no later than 90 days.
- Discrimination-discovery + 90-day AG notification procedure
- Disclosure records
- No AG notification process for discrimination
A deployer with fewer than 50 full-time employees that does not use its own data to train the high-risk AI system, and that meets the other statutory conditions, is exempted from the risk-management-program, impact-assessment and public-statement duties.
- Headcount + data-use determination supporting any small-deployer exemption
- Exemption claimed without meeting the conditions
Colorado AI Act: Developer Duties (6-1-1702)
On and after the effective date a developer of a high-risk AI system must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from intended and contracted uses; compliance creates a rebuttable presumption of reasonable care.
- Evidence of reasonable-care measures across the AI lifecycle
- Rebuttable-presumption compliance file
- No documented reasonable-care program
The developer must make available to deployers: a general statement of foreseeable and harmful/inappropriate uses; documentation of training-data summaries, known limitations and discrimination risks, purpose, intended uses; how the system was evaluated for performance and discrimination; data-governance measures; intended outputs; mitigations; and how the system should be used, not used and monitored.
- Developer documentation package / model card to deployers covering 1702(2) elements
- Evaluation + data-governance records
- Incomplete developer documentation
- No evaluation/data-governance disclosure
The developer must make available, to the extent feasible, documentation through artifacts such as model cards, dataset cards or impact assessments necessary for the deployer (or its third party) to complete an impact assessment under 6-1-1703(3).
- Model cards / dataset cards / impact-assessment inputs provided to deployers
- Deployer unable to complete impact assessment due to missing developer artifacts
The developer must publish a clear, readily available statement (website or public use-case inventory) summarising the types of high-risk AI systems it develops/modifies and how it manages known or foreseeable risks of algorithmic discrimination; updated within 90 days of a substantial modification.
- Published developer high-risk-AI statement
- Update log within 90 days of modification
- No public statement / not kept current
On discovering (through testing/analysis or a credible deployer report) that its high-risk AI system has caused or is reasonably likely to have caused algorithmic discrimination, the developer must disclose to the Attorney General and known deployers without unreasonable delay, no later than 90 days.
- Discrimination-discovery monitoring + 90-day AG/deployer notification procedure
- Disclosure records
- No process to detect/report discrimination within 90 days
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Colorado Artificial Intelligence Act (proposed SB 24-205) framework page.