On this page
US state law

Colorado AI Act + ISO 42001

SB 26-189 replaced the original law, and the ISO 42001 safe harbor went with it

Reviewed by the ISO42k editorial team · Last reviewed October 9, 2026

Bottom line

The original Colorado AI Act (SB 24-205) named ISO/IEC 42001 and the NIST AI RMF in an affirmative defense. That law never took effect. In May 2026 Colorado repealed it and enacted SB 26-189, which takes effect January 1, 2027, regulates automated decision-making technology in consequential decisions, and contains no framework safe harbor. ISO 42001 is no longer a legal defense in Colorado. It remains the most efficient way to produce the developer documentation, records and oversight processes the new law requires.[1][2][4]

What Colorado's law requires now

SB 26-189 covers automated decision-making technology (ADMT) that materially influences a consequential decision about a consumer in education, employment, housing, financial or lending services, insurance, health care, or essential government services. Tools used only to summarize, organize, translate, draft or route information for human review are excluded.[2][3]

Developers must give deployers documentation of intended and harmful uses, training data categories, known limitations and human-oversight instructions, and notify them of material updates. Deployers must post a point-of-interaction notice, explain an adverse outcome in plain language within 30 days, let consumers access and correct personal data used in the decision and request meaningful human review to the extent commercially reasonable, and keep compliance records for at least three years.[2][3]

Duties from the original law are gone: no risk management program, no impact assessments, and no general duty of care against algorithmic discrimination.[2][3]

Statute
SB 26-189, C.R.S. 6-1-1701 et seq.
Effective
January 1, 2027
Applies to
Developers and deployers of covered ADMT in consequential decisions
Enforcement
Attorney General only; no private right of action
Penalties
Deceptive trade practice under the Colorado Consumer Protection Act
Framework safe harbor
None. ISO 42001 and NIST are not referenced

Key dates

  1. May 2024
    SB 24-205 signed, with an affirmative defense naming ISO/IEC 42001 and the NIST AI RMF[4]
  2. Aug 28, 2025
    SB 25B-004 delays SB 24-205 from Feb 1 to June 30, 2026[9]
  3. Apr 2026
    xAI sues the Colorado AG; DOJ intervenes and enforcement of SB 24-205 is paused[6]
  4. May 14, 2026
    SB 26-189 signed, repealing and replacing SB 24-205[1]
  5. Aug 11, 2026
    AG files proposed ADMT rules[5]
  6. Oct 6, 2026
    AG releases revised draft rules[10]
  7. Oct 26, 2026
    Rulemaking hearing and comment deadline[5]
  8. Jan 1, 2027
    SB 26-189 takes effect; AG rules due by this date[1][2]

Where they overlap

Each row is an SB 26-189 obligation and where an ISO 42001 AI management system produces the process or evidence behind it.[2][7]

Strong(1)Partial(7)Gap(1)
Colorado AI ActISO 42001Coverage
Identify covered ADMT and consequential decisions
4.3, 6.1.4, A.6.2.2
AI system inventory, scope and impact assessment surface which systems materially influence decisions.
Strong
Developer documentation to deployers (6-1-1702)
A.6.2.7, A.8.2, A.7.5, A.10.4
Technical documentation, user information, data provenance and obligations to customers produce most of it; the statute prescribes the content.
Partial
Developer notice of material updates
A.8.2, A.10.4, 8.1
Change control and customer communication exist; the statutory trigger and timing are yours to build in.
Partial
Record keeping for 3+ years (6-1-1703)
7.5, A.6.2.8
Documented information and event logs. Set retention to at least three years for covered systems.
Partial
Point-of-interaction notice (6-1-1704)
A.8.2, A.8.5
Information for users and interested parties; AG rules may add detail.
Partial
Adverse-outcome explanation within 30 days
A.8.5, A.6.2.7
Documentation makes explanations possible. The consumer workflow and deadline are not 42001 requirements.
Partial
Meaningful human review
A.9.2, A.9.3, A.6.2.6
Responsible-use processes and human oversight in operation; the review right itself is statutory.
Partial
Consumer data correction
A.7.4
Data quality controls help, but consumer correction rights belong in your privacy program.
Gap
Track AG rules and legal requirements
4.2, 9.3
Legal requirements of interested parties feed the AIMS and management review.
Partial

Coverage reflects how directly ISO 42001 produces the evidence or process the requirement asks for. It is an editorial assessment, not a legal opinion or a presumption of conformity.

What ISO 42001 won't cover

Under the replacement law, ISO 42001 is an operating model, not a legal shield.

No affirmative defense

SB 26-189 does not reference ISO 42001, NIST or any framework. Certification does not reduce liability under the statute.[2]

Consumer-rights workflows

Adverse-outcome explanations, the 30-day clock, correction and human review requests need consumer-facing processes 42001 doesn't define.[2]

Legal scoping

Whether a tool "materially influences" a consequential decision is a legal determination. 42001 documents your answer; counsel should make it.[3]

Federal uncertainty

Federal litigation and a proposed FTC policy statement challenge Colorado's approach. Watch for changes before January 2027.[6][7]

Using ISO 42001 to get there

  1. 1

    Inventory and classify

    Use the AIMS inventory to flag every system that may materially influence a consequential decision in a covered domain.

  2. 2

    Build the developer documentation pack

    If you develop ADMT, extend A.6.2.7 technical documentation into a deployer-ready pack: intended and harmful uses, training data categories, limitations, oversight instructions.

  3. 3

    Set retention to three years

    Configure documented information and event logs (A.6.2.8) for covered systems to meet the record-keeping duty.

  4. 4

    Stand up consumer workflows

    Add notice, adverse-outcome explanation, correction and human review processes, and bring them into the AIMS as operational controls.

  5. 5

    Monitor the rules and the litigation

    Log the AG's final rules and court developments as legal requirements (4.2) and review them in management review.

Frequently asked questions

Does ISO 42001 certification give a safe harbor under Colorado law?

Not anymore. The original SB 24-205 offered an affirmative defense if a violation was discovered and cured through feedback, red-teaming or internal review while complying with ISO/IEC 42001, the NIST AI RMF or a similar framework, but it was repealed before taking effect. SB 26-189, effective January 1, 2027, has no framework safe harbor.

When does the Colorado AI law take effect?

SB 26-189 applies to consequential decisions made on or after January 1, 2027. The Attorney General's implementing rules are in rulemaking, with a hearing and comment deadline on October 26, 2026.

Are impact assessments still required in Colorado?

No. SB 26-189 removed the risk management program and impact assessment duties. ISO 42001 still requires an AI system impact assessment, which remains useful for scoping covered systems.

Who enforces it, and what are the penalties?

The Colorado Attorney General has exclusive enforcement authority under the Colorado Consumer Protection Act, with a 60-day notice-and-cure period for actions brought before January 1, 2030. There is no private right of action.

Is the Colorado law being challenged?

Yes. xAI sued in April 2026 and the US Department of Justice intervened, and the FTC has proposed a policy statement questioning the approach. Confirm the current status with counsel.

This page is general information, not legal advice. Laws change; confirm obligations with counsel.