Colorado AI Act + ISO 42001
SB 26-189 replaced the original law, and the ISO 42001 safe harbor went with it
Bottom line
The original Colorado AI Act (SB 24-205) named ISO/IEC 42001 and the NIST AI RMF in an affirmative defense. That law never took effect. In May 2026 Colorado repealed it and enacted SB 26-189, which takes effect January 1, 2027, regulates automated decision-making technology in consequential decisions, and contains no framework safe harbor. ISO 42001 is no longer a legal defense in Colorado. It remains the most efficient way to produce the developer documentation, records and oversight processes the new law requires.[1][2][4]
What Colorado's law requires now
SB 26-189 covers automated decision-making technology (ADMT) that materially influences a consequential decision about a consumer in education, employment, housing, financial or lending services, insurance, health care, or essential government services. Tools used only to summarize, organize, translate, draft or route information for human review are excluded.[2][3]
Developers must give deployers documentation of intended and harmful uses, training data categories, known limitations and human-oversight instructions, and notify them of material updates. Deployers must post a point-of-interaction notice, explain an adverse outcome in plain language within 30 days, let consumers access and correct personal data used in the decision and request meaningful human review to the extent commercially reasonable, and keep compliance records for at least three years.[2][3]
Duties from the original law are gone: no risk management program, no impact assessments, and no general duty of care against algorithmic discrimination.[2][3]
- Statute
- SB 26-189, C.R.S. 6-1-1701 et seq.
- Effective
- January 1, 2027
- Applies to
- Developers and deployers of covered ADMT in consequential decisions
- Enforcement
- Attorney General only; no private right of action
- Penalties
- Deceptive trade practice under the Colorado Consumer Protection Act
- Framework safe harbor
- None. ISO 42001 and NIST are not referenced
Key dates
- May 2024SB 24-205 signed, with an affirmative defense naming ISO/IEC 42001 and the NIST AI RMF[4]
- Aug 28, 2025SB 25B-004 delays SB 24-205 from Feb 1 to June 30, 2026[9]
- Apr 2026xAI sues the Colorado AG; DOJ intervenes and enforcement of SB 24-205 is paused[6]
- May 14, 2026SB 26-189 signed, repealing and replacing SB 24-205[1]
- Aug 11, 2026AG files proposed ADMT rules[5]
- Oct 6, 2026AG releases revised draft rules[10]
- Oct 26, 2026Rulemaking hearing and comment deadline[5]
- Jan 1, 2027SB 26-189 takes effect; AG rules due by this date[1][2]
Where they overlap
Each row is an SB 26-189 obligation and where an ISO 42001 AI management system produces the process or evidence behind it.[2][7]
| Colorado AI Act | ISO 42001 | Coverage |
|---|---|---|
| Identify covered ADMT and consequential decisions | 4.3, 6.1.4, A.6.2.2 AI system inventory, scope and impact assessment surface which systems materially influence decisions. | Strong |
| Developer documentation to deployers (6-1-1702) | A.6.2.7, A.8.2, A.7.5, A.10.4 Technical documentation, user information, data provenance and obligations to customers produce most of it; the statute prescribes the content. | Partial |
| Developer notice of material updates | A.8.2, A.10.4, 8.1 Change control and customer communication exist; the statutory trigger and timing are yours to build in. | Partial |
| Record keeping for 3+ years (6-1-1703) | 7.5, A.6.2.8 Documented information and event logs. Set retention to at least three years for covered systems. | Partial |
| Point-of-interaction notice (6-1-1704) | A.8.2, A.8.5 Information for users and interested parties; AG rules may add detail. | Partial |
| Adverse-outcome explanation within 30 days | A.8.5, A.6.2.7 Documentation makes explanations possible. The consumer workflow and deadline are not 42001 requirements. | Partial |
| Meaningful human review | A.9.2, A.9.3, A.6.2.6 Responsible-use processes and human oversight in operation; the review right itself is statutory. | Partial |
| Consumer data correction | A.7.4 Data quality controls help, but consumer correction rights belong in your privacy program. | Gap |
| Track AG rules and legal requirements | 4.2, 9.3 Legal requirements of interested parties feed the AIMS and management review. | Partial |
Coverage reflects how directly ISO 42001 produces the evidence or process the requirement asks for. It is an editorial assessment, not a legal opinion or a presumption of conformity.
What ISO 42001 won't cover
Under the replacement law, ISO 42001 is an operating model, not a legal shield.
No affirmative defense
SB 26-189 does not reference ISO 42001, NIST or any framework. Certification does not reduce liability under the statute.[2]
Consumer-rights workflows
Adverse-outcome explanations, the 30-day clock, correction and human review requests need consumer-facing processes 42001 doesn't define.[2]
Legal scoping
Whether a tool "materially influences" a consequential decision is a legal determination. 42001 documents your answer; counsel should make it.[3]
Federal uncertainty
Federal litigation and a proposed FTC policy statement challenge Colorado's approach. Watch for changes before January 2027.[6][7]
Using ISO 42001 to get there
- 1
Inventory and classify
Use the AIMS inventory to flag every system that may materially influence a consequential decision in a covered domain.
- 2
Build the developer documentation pack
If you develop ADMT, extend A.6.2.7 technical documentation into a deployer-ready pack: intended and harmful uses, training data categories, limitations, oversight instructions.
- 3
Set retention to three years
Configure documented information and event logs (A.6.2.8) for covered systems to meet the record-keeping duty.
- 4
Stand up consumer workflows
Add notice, adverse-outcome explanation, correction and human review processes, and bring them into the AIMS as operational controls.
- 5
Monitor the rules and the litigation
Log the AG's final rules and court developments as legal requirements (4.2) and review them in management review.
Frequently asked questions
Does ISO 42001 certification give a safe harbor under Colorado law?
Not anymore. The original SB 24-205 offered an affirmative defense if a violation was discovered and cured through feedback, red-teaming or internal review while complying with ISO/IEC 42001, the NIST AI RMF or a similar framework, but it was repealed before taking effect. SB 26-189, effective January 1, 2027, has no framework safe harbor.
When does the Colorado AI law take effect?
SB 26-189 applies to consequential decisions made on or after January 1, 2027. The Attorney General's implementing rules are in rulemaking, with a hearing and comment deadline on October 26, 2026.
Are impact assessments still required in Colorado?
No. SB 26-189 removed the risk management program and impact assessment duties. ISO 42001 still requires an AI system impact assessment, which remains useful for scoping covered systems.
Who enforces it, and what are the penalties?
The Colorado Attorney General has exclusive enforcement authority under the Colorado Consumer Protection Act, with a 60-day notice-and-cure period for actions brought before January 1, 2030. There is no private right of action.
Is the Colorado law being challenged?
Yes. xAI sued in April 2026 and the US Department of Justice intervened, and the FTC has proposed a policy statement questioning the approach. Confirm the current status with counsel.
Related frameworks
This page is general information, not legal advice. Laws change; confirm obligations with counsel.