Complete Guide Colorado SB 24-205 ⚠ June 30, 2026 Deadline

Colorado SB 205 Compliance for Small & Mid-Market Businesses

Colorado Senate Bill 24-205 is America's first comprehensive state AI law. It takes effect June 30, 2026 — the closest AI compliance deadline in the country. If your AI system makes or influences decisions about hiring, credit, housing, healthcare, insurance, or education for Colorado residents, you're in scope. Penalties reach $20,000 per violation. The good news: following NIST AI RMF creates a rebuttable presumption of compliance.

Create a workspace → Guided intake → See a Sample Plan

12 questions · 5 minutes · Instant score · No account required

TL;DR — Three Things You Must Know
Scope & Applicability

Does SB 205 apply to you? The consequential decision test

Colorado SB 205 is narrower than the EU AI Act. It only covers AI systems that make or substantially factor into "consequential decisions" in specific domains. Most AI tools — chatbots, writing assistants, analytics dashboards — are out of scope. The question is whether your AI touches decisions with material effects on individuals.

The seven covered domains under Senate Bill 24-205, §6-1-1702 (Colorado General Assembly):

👔
Employment
Hiring, promotion, scheduling, performance, termination
🎓
Education
Educational opportunity, enrollment, academic assessment
💳
Credit & Finance
Loan approval, interest rates, credit limits and terms
🏠
Housing
Rental approval, housing terms, pricing decisions
🏥
Healthcare
Treatment decisions, access to services, coverage
🛡️
Insurance
Coverage decisions, pricing, claims assessment
⚖️
Legal Services
Access to legal services and representation

Use these three questions to determine if SB 205 applies to you:

01

Do you use AI in any of the seven covered domains?

Do you use AI tools for hiring, credit evaluation, housing applications, healthcare triage, insurance underwriting, educational assessments, or legal service eligibility — for any customers, employees, or applicants in Colorado?

Yes → Proceed to Question 2   No → SB 205 does not apply to your current AI stack
02

Does the AI's output have a material effect on individual outcomes?

The test is whether the AI influences whether someone gets a job, a loan, housing, coverage, care, or a degree. If the AI is purely internal analytics with no effect on individual decisions, you are likely out of scope.

Yes → Proceed to Question 3 No → Likely out of scope (document your reasoning)
03

Is the AI a "substantial factor" in that decision?

Does the AI rank, score, recommend, or filter before a human decides? Even if a human makes the final call, if the AI's output meaningfully shapes the pool of options presented to the decision-maker, it is likely a substantial factor and SB 205 applies.

Yes → SB 205 applies. Full compliance required by June 30, 2026.

The "substantial factor" test — broader than you think

The AI does not need to make the final decision alone to be in scope. Under SB 205 §6-1-1703, an AI system "substantially factors into" a consequential decision if it generates recommendations, scores, or outputs that meaningfully inform what the human decision-maker sees and acts on. Classic examples: CV screening AI that ranks candidates before a recruiter reviews them; credit scoring AI that generates recommendations before an underwriter approves; insurance triage AI that flags claims for manual review. All three involve human final decisions — but all three are covered under the substantial factor test. Source: SB 24-205, Colorado General Assembly.

Deployer Obligations

High-risk deployer checklist: what SB 205 requires

If you have a high-risk AI system (one that substantially factors into consequential decisions), these are your four categories of obligations as a deployer under Colorado SB 205. All four must be in place before June 30, 2026.

📋

Risk Management Program

Use "reasonable care" to protect Colorado consumers from known or reasonably foreseeable risks of algorithmic discrimination. A documented, implemented risk management program is required — not just a policy document.

  • Written policy specifying who owns AI decisions and how risks are assessed
  • Defined governance: data owner, system owner, compliance reviewer roles assigned
  • Bias testing methodology documented and executed before deployment
  • Accuracy and fairness validation across protected classes
  • Data quality controls and lineage documentation
  • Human oversight checkpoints built into decision workflows
  • Annual program review or review triggered by material system changes
🔍

Impact Assessment (Pre-Deployment + Annual)

Before deploying any high-risk AI system, and annually thereafter, conduct a formal impact assessment covering all required elements. If the system undergoes "intentional and substantial modification," a new assessment is required within 90 days.

  • System purpose and intended consequential decision use case
  • Data inputs: training data sources, real-time data, data providers
  • System outputs and how they are used to make or influence decisions
  • Known and foreseeable discrimination risks by protected class
  • Bias testing results and methodology
  • Mitigation measures and residual risk documentation
  • Human oversight mechanism and its operational effectiveness
  • Transparency measures: how individuals are informed and what explanations are provided
  • System limitations, failure modes, and edge cases
📣

Consumer Disclosures

Notify individuals when a high-risk AI system makes or substantially influences a consequential decision about them. Pre-decision and post-decision notice requirements apply separately.

  • Pre-decision notice: inform individuals that AI is used, its purpose, and data sources
  • Post-decision notice for adverse outcomes: explain AI's contribution and reasons
  • Plain-language explanation of what data was used in the AI's decision
  • Contact information for questions about the AI system and decision
  • Update privacy notices, job applications, and service agreements before June 30
🔁

Appeal Rights & Incident Reporting

Individuals subject to adverse consequential decisions have a right to appeal and request human review. Known or suspected algorithmic discrimination must be reported to the Colorado AG within 90 days of discovery.

  • Right to correct data errors used in the AI decision
  • Right to request re-evaluation after data correction
  • Right to appeal the decision and request human review
  • Technical infrastructure to receive and process appeals
  • Incident reporting: within 90 days of discovering discrimination, notify AG and remediate
  • Incident log maintained internally for compliance documentation
Affirmative Defense

The NIST AI RMF safe harbor — your best path to compliance

Colorado SB 205 includes a powerful compliance shortcut. Adopting and documenting adherence to a recognized AI risk management framework creates a rebuttable presumption that you used "reasonable care" — the core legal standard under the statute. The Colorado AG can still pursue enforcement with strong evidence of discrimination, but documented NIST compliance dramatically reduces enforcement risk and is your strongest legal defense.

Two frameworks qualify for the affirmative defense under SB 205:

Recommended for SMBs

NIST AI Risk Management Framework 1.0

Published by the National Institute of Standards and Technology. Free, public, and well-documented. Covers Govern, Map, Measure, and Manage functions. Widely recognized, vendor-neutral, and well-matched to SB 205's reasonable care standard.

Download Free at NIST.gov →
Enterprise Option

ISO/IEC 42001:2023

International standard for AI management systems. Certifiable (third-party audit available). Stronger for enterprise compliance programs. More prescriptive than NIST AI RMF. Costs ~$200 to purchase the standard; certification adds cost and time.

iso.org/standard/81230.html
How to activate the affirmative defense

Four steps to establish the NIST AI RMF presumption

1. Adopt the framework formally. Obtain NIST AI RMF 1.0 (free at nist.gov/artificial-intelligence) and formally adopt it as your organization's AI risk management standard via a board or executive resolution. Document the adoption date.

2. Map each high-risk AI system. For every AI system in scope under SB 205, complete a NIST AI RMF "Map" exercise: document the system's purpose, stakeholders, context, and risk categories. This becomes the foundation of your SB 205 impact assessment.

3. Implement Govern, Measure, and Manage functions. Establish governance (assign ownership, document policies), measure risks (bias testing, accuracy validation, human oversight effectiveness), and manage residual risks (mitigation plans, incident procedures). Retain all documentation.

4. Conduct annual reviews and log them. NIST AI RMF is an ongoing program, not a one-time certification. Annual reviews demonstrating continued implementation are what sustain the rebuttable presumption over time. If the AG investigates, you need to show current compliance, not past compliance.

Note: The presumption is rebuttable. If there is evidence of actual algorithmic discrimination causing harm, the AG can still pursue enforcement even if you have NIST documentation. The framework reduces risk dramatically — it does not eliminate it. Source: Colorado Attorney General rulemaking guidance, coag.gov/resources/artificial-intelligence.

Enforcement Timeline

Key dates for Colorado SB 205 compliance

SB 205 has a tight timeline with ongoing obligations after the initial June 30, 2026 deadline. Here are every date that matters for deployers as of May 2026.

May 17, 2024 — Passed

Colorado SB 24-205 Signed Into Law

Governor Jared Polis signed Senate Bill 24-205 into law, making Colorado the first U.S. state to pass comprehensive AI regulation. The law directed the Colorado Attorney General to develop rulemaking guidance on implementation standards. It also granted developers and deployers two years to prepare for enforcement.

2024–2025 — Rulemaking Phase

AG Guidance and Rulemaking Developed

The Colorado Attorney General's office developed implementation guidance, clarifying definitions, rulemaking on the affirmative defense frameworks, and the specific requirements for impact assessments and consumer disclosures. Businesses were advised to begin compliance preparations during this window. AG guidance available at coag.gov.

NOW
Now → June 29, 2026 — Final Preparation Window

Risk Management Programs, Impact Assessments, Disclosure Systems

This is the last window to complete: NIST AI RMF adoption documents, impact assessments for each high-risk system, consumer disclosure notices and appeal infrastructure, governance policy finalization, bias testing documentation, and staff training. Most organizations need 4–8 weeks for each system assessed. If you have 2+ high-risk AI systems and haven't started, start today.

JUNE
June 30, 2026 — Hard Enforcement Deadline

Colorado AG Begins Enforcement of SB 205

All deployers of high-risk AI systems must have: risk management programs documented and implemented, pre-deployment impact assessments completed and retained, consumer disclosure notices live and operational, appeal rights infrastructure working, and incident reporting procedures defined. The AG's office can investigate, issue civil investigative demands, and impose penalties of up to $20,000 per violation from this date forward.

90D
Ongoing — 90-Day Incident Reporting Rule

Algorithmic Discrimination Must Be Reported Within 90 Days

If you discover or reasonably suspect that a high-risk AI system has caused algorithmic discrimination, you must report it to the Colorado AG within 90 days of that discovery. Failure to report is a separate violation. Proactive disclosure, remediation, and cooperation with the AG's office may reduce or waive penalties under the cure provision — particularly if the violation is not a pattern or practice.

ANN
Ongoing — Annual Reviews Required

Annual Impact Assessment Reviews + NIST RMF Program Updates

Impact assessments must be reviewed annually from the date of initial deployment. If a high-risk AI system undergoes an "intentional and substantial modification," a new impact assessment must be completed within 90 days of the change. Your NIST AI RMF program documentation must also be updated annually to sustain the affirmative defense. Plan these into your compliance calendar now.

Regulatory Comparison

Colorado SB 205 vs. EU AI Act — side by side

If your company has operations or customers in both Colorado and the EU, you face both deadlines — Colorado on June 30, 2026 and EU AI Act high-risk enforcement on August 2, 2026. Understanding the differences prevents both under-investment (missing a requirement unique to one regime) and over-investment (assuming they require entirely different programs).

Dimension Colorado SB 205 EU AI Act
Enforcement deadline June 30, 2026 August 2, 2026
Geographic scope Consequential decisions affecting Colorado consumers — company location irrelevant AI systems affecting EU residents — company location irrelevant
Scope trigger Consequential decisions in 7 domains (employment, credit, housing, healthcare, insurance, education, legal) Any AI system in Annex III categories (broader — includes biometric, critical infrastructure, border control, etc.)
Maximum penalty $20,000 per violation (Colorado Consumer Protection Act) €35M or 7% of global annual turnover, whichever is higher
Private right of action No — AG enforcement only No — national market surveillance authorities only
Risk management Reasonable care standard; NIST AI RMF / ISO 42001 = rebuttable presumption Mandatory documented risk management system per Article 9; no equivalent safe harbor
Impact / conformity assessment Pre-deployment + annual impact assessment required Conformity assessment required; vendor must provide technical documentation; registries required
Consumer disclosures Pre- and post-decision notice to individuals affected by AI Transparency to affected persons required; chatbot transparency under Article 50
Appeal rights Mandatory right to human review, data correction, and re-evaluation Human oversight required but no equivalent right-to-appeal mandate
Incident reporting Report to AG within 90 days of discovering discrimination No equivalent proactive AG-reporting requirement; incident logs required
AI literacy training Not explicitly required Mandatory under Article 4 for all AI users
Vendor obligations Developer obligations exist separately; deployers cannot rely solely on vendor compliance Providers bear primary conformity burden; deployers must obtain documentation and verify

Sources: Colorado SB 24-205, Colorado General Assembly; Regulation (EU) 2024/1689, EU AI Act Portal. If you're building a compliance program that covers both, check our EU AI Act SMB Guide →

How GovernIQ Helps

From this guide to a Colorado SB 205 compliance plan in under an hour

Knowing the law is the first step. Knowing exactly which of your AI systems are in scope, what gaps you have against the four deployer obligations, and getting a prioritized written action plan is the second. GovernIQ automates the gap analysis — built specifically for SMBs, not enterprise GRC teams.

01

12-Question Assessment

Covers AI tool inventory, data handling practices, employee training status, and policy governance. Takes 5 minutes. Generates a 0–100 compliance score and identifies up to 8 specific policy gaps — matched to SB 205 and EU AI Act requirements.

Take the Assessment →
02

Sample Compliance Plan

See a real example of the personalized Compliance Action Plan output for a fictional financial advisory firm facing similar AI compliance obligations. Understand what you'll get before you purchase.

View Sample Plan →
03

Personalized Action Plan

After a $299 one-time purchase, receive a full Compliance Action Plan specific to your company's AI stack, SB 205 gaps, risk level, and industry — with actionable items, policy templates, and a 90-day remediation roadmap.

See Pricing →
Frequently Asked Questions

Colorado SB 205 compliance — the questions we hear most

What is Colorado SB 205?
Colorado Senate Bill 24-205, signed into law May 17, 2024, is the first comprehensive state AI law in the United States. It requires deployers of "high-risk" AI systems to implement risk management programs, conduct impact assessments, provide consumer disclosures, and offer appeal rights for consequential decisions. Enforcement begins June 30, 2026 under the Colorado Consumer Protection Act. Source: Colorado General Assembly, SB24-205.
Who must comply with Colorado SB 205?
Any "deployer" — a company or individual that uses a high-risk AI system to make or substantially influence consequential decisions about Colorado consumers. You do not need to be based in Colorado. If your AI touches hiring decisions, credit decisions, housing decisions, healthcare, insurance, education, or legal services for Colorado residents — and that AI is a substantial factor — SB 205 applies. Developers (companies that create high-risk AI systems for others to deploy) also have separate obligations under the statute.
What is a 'consequential decision' under Colorado SB 205?
A decision with a "material legal or similarly significant effect" on an individual's access to, or cost of, any of seven covered domains: employment, education, financial products and services, healthcare, housing, insurance, or legal services. The key word is "material" — trivial or indirect effects likely do not trigger SB 205. But if your AI output influences whether someone gets a job, loan, apartment, policy, or treatment, that is a consequential decision.
What is the 'substantial factor' test and why does it matter?
An AI system is "high-risk" under SB 205 if it "substantially factors into" a consequential decision — even if a human makes the final call. The substantial factor test is the key expansive element of the law: it captures AI tools that rank, score, recommend, or filter inputs to human decision-makers. If your AI generates a candidate shortlist before a recruiter reviews it, that AI is a substantial factor in the hiring decision. If your AI produces a risk score before an underwriter approves a loan, that AI is a substantial factor. The burden falls on the deployer to demonstrate the AI was not a substantial factor if it believes SB 205 does not apply.
What are the penalties for violating Colorado SB 205?
Civil penalties up to $20,000 per violation under the Colorado Consumer Protection Act. The Colorado Attorney General has exclusive enforcement authority — no private right of action currently exists, meaning individuals cannot sue you directly. However, violations stack: three non-compliant high-risk systems equals up to $60,000 in day-one exposure. The AG can also seek injunctive relief and require compliance audits. A cure provision may reduce penalties if you discover discrimination proactively, report it within 90 days, and remediate — but only if the violation is not a pattern or practice.
What is the NIST AI RMF affirmative defense under SB 205?
Colorado SB 205 includes a safe harbor: if a deployer follows the NIST AI Risk Management Framework 1.0 or ISO/IEC 42001 and can demonstrate compliance, this creates a rebuttable presumption that the deployer exercised "reasonable care" — the core standard under SB 205. The presumption is rebuttable, meaning strong evidence of actual discrimination can still support enforcement. But documented NIST AI RMF compliance is your strongest defense and dramatically reduces enforcement risk. NIST AI RMF 1.0 is free at nist.gov/artificial-intelligence.
When does Colorado SB 205 enforcement begin?
June 30, 2026. The Colorado AG begins civil enforcement of SB 205 on that date. After initial deployment, annual impact assessment reviews are required. Incidents of known or reasonably suspected algorithmic discrimination must be reported to the AG within 90 days of discovery. If a high-risk AI system undergoes substantial modification, a new impact assessment is required within 90 days of the change.
Does Colorado SB 205 apply to companies outside Colorado?
Yes. The law applies to any deployer whose high-risk AI system makes consequential decisions about Colorado consumers — regardless of where the company is headquartered. A New York financial firm using AI to screen Colorado loan applicants, or a California employer using AI to rank Colorado job candidates, is subject to SB 205. The test is whether Colorado consumers are affected, not where the deployer is located.
What is required in a SB 205 impact assessment?
Nine elements: (1) system purpose and intended use case, (2) data inputs including training data sources, (3) system outputs and how they are used in consequential decisions, (4) known and foreseeable discrimination risks by protected class, (5) bias testing results and methodology, (6) mitigation measures, (7) human oversight mechanism, (8) transparency measures showing how affected individuals are informed, and (9) system limitations and known failure modes. Assessments must be retained for at least 3 years after the system is discontinued. Annual reviews are required; substantial system changes require a new assessment within 90 days.
How does Colorado SB 205 compare to the EU AI Act?
Both target algorithmic discrimination in high-stakes decisions, but differ in scope, penalties, and structure. SB 205 is narrower (7 domains), applies only to consequential decisions, carries $20K/violation penalties enforced by the AG, and has no private right of action. The EU AI Act is broader (all Annex III AI systems in the EU), more prescriptive (conformity assessments, technical documentation, vendor registries), carries higher penalties (€35M or 7% of turnover), and has more extensive consumer transparency requirements including AI literacy training. If you comply with EU AI Act high-risk requirements, you likely satisfy most SB 205 requirements — but you should verify the specific consumer disclosure, appeal rights, and AG reporting obligations that are unique to SB 205. See our full EU AI Act SMB guide for a deeper comparison.
Is there a cure provision under Colorado SB 205?
Yes. If a deployer discovers or reasonably suspects that a high-risk AI system has caused algorithmic discrimination, they must report the incident to the Colorado AG within 90 days. If the deployer reports proactively, cooperates fully, remedies the harm, and demonstrates the violation was not part of a pattern or practice, the AG may exercise enforcement discretion and reduce or waive penalties. This cure provision creates a strong incentive for proactive compliance monitoring, internal auditing, and self-reporting — rather than hoping issues are never discovered.
📋
Free Tool — No signup required
Need a starting policy before June 30? Get a customized AI Acceptable Use Policy in 60 seconds.
Includes SB 205 deployer obligations checklist, NIST AI RMF mapping, and escalation path — generated for your org.
Build Your Policy Free →

Find out if your AI is in scope — before June 30.

The GovernIQ assessment identifies which of your AI tools are high-risk under SB 205, what compliance gaps you have, and exactly what to do before the June 30 enforcement deadline. Free. No account required.

Create a workspace → Guided intake → See a Sample Report

Free assessment · Personalized Compliance Action Plan $299 · No subscription