Colorado Senate Bill 24-205 is America's first comprehensive state AI law. It takes effect June 30, 2026 — the closest AI compliance deadline in the country. If your AI system makes or influences decisions about hiring, credit, housing, healthcare, insurance, or education for Colorado residents, you're in scope. Penalties reach $20,000 per violation. The good news: following NIST AI RMF creates a rebuttable presumption of compliance.
12 questions · 5 minutes · Instant score · No account required
Colorado SB 205 is narrower than the EU AI Act. It only covers AI systems that make or substantially factor into "consequential decisions" in specific domains. Most AI tools — chatbots, writing assistants, analytics dashboards — are out of scope. The question is whether your AI touches decisions with material effects on individuals.
The seven covered domains under Senate Bill 24-205, §6-1-1702 (Colorado General Assembly):
Use these three questions to determine if SB 205 applies to you:
Do you use AI tools for hiring, credit evaluation, housing applications, healthcare triage, insurance underwriting, educational assessments, or legal service eligibility — for any customers, employees, or applicants in Colorado?
Yes → Proceed to Question 2 No → SB 205 does not apply to your current AI stackThe test is whether the AI influences whether someone gets a job, a loan, housing, coverage, care, or a degree. If the AI is purely internal analytics with no effect on individual decisions, you are likely out of scope.
Yes → Proceed to Question 3 No → Likely out of scope (document your reasoning)Does the AI rank, score, recommend, or filter before a human decides? Even if a human makes the final call, if the AI's output meaningfully shapes the pool of options presented to the decision-maker, it is likely a substantial factor and SB 205 applies.
Yes → SB 205 applies. Full compliance required by June 30, 2026.The AI does not need to make the final decision alone to be in scope. Under SB 205 §6-1-1703, an AI system "substantially factors into" a consequential decision if it generates recommendations, scores, or outputs that meaningfully inform what the human decision-maker sees and acts on. Classic examples: CV screening AI that ranks candidates before a recruiter reviews them; credit scoring AI that generates recommendations before an underwriter approves; insurance triage AI that flags claims for manual review. All three involve human final decisions — but all three are covered under the substantial factor test. Source: SB 24-205, Colorado General Assembly.
If you have a high-risk AI system (one that substantially factors into consequential decisions), these are your four categories of obligations as a deployer under Colorado SB 205. All four must be in place before June 30, 2026.
Use "reasonable care" to protect Colorado consumers from known or reasonably foreseeable risks of algorithmic discrimination. A documented, implemented risk management program is required — not just a policy document.
Before deploying any high-risk AI system, and annually thereafter, conduct a formal impact assessment covering all required elements. If the system undergoes "intentional and substantial modification," a new assessment is required within 90 days.
Notify individuals when a high-risk AI system makes or substantially influences a consequential decision about them. Pre-decision and post-decision notice requirements apply separately.
Individuals subject to adverse consequential decisions have a right to appeal and request human review. Known or suspected algorithmic discrimination must be reported to the Colorado AG within 90 days of discovery.
Colorado SB 205 includes a powerful compliance shortcut. Adopting and documenting adherence to a recognized AI risk management framework creates a rebuttable presumption that you used "reasonable care" — the core legal standard under the statute. The Colorado AG can still pursue enforcement with strong evidence of discrimination, but documented NIST compliance dramatically reduces enforcement risk and is your strongest legal defense.
Two frameworks qualify for the affirmative defense under SB 205:
Published by the National Institute of Standards and Technology. Free, public, and well-documented. Covers Govern, Map, Measure, and Manage functions. Widely recognized, vendor-neutral, and well-matched to SB 205's reasonable care standard.
Download Free at NIST.gov →International standard for AI management systems. Certifiable (third-party audit available). Stronger for enterprise compliance programs. More prescriptive than NIST AI RMF. Costs ~$200 to purchase the standard; certification adds cost and time.
iso.org/standard/81230.html1. Adopt the framework formally. Obtain NIST AI RMF 1.0 (free at nist.gov/artificial-intelligence) and formally adopt it as your organization's AI risk management standard via a board or executive resolution. Document the adoption date.
2. Map each high-risk AI system. For every AI system in scope under SB 205, complete a NIST AI RMF "Map" exercise: document the system's purpose, stakeholders, context, and risk categories. This becomes the foundation of your SB 205 impact assessment.
3. Implement Govern, Measure, and Manage functions. Establish governance (assign ownership, document policies), measure risks (bias testing, accuracy validation, human oversight effectiveness), and manage residual risks (mitigation plans, incident procedures). Retain all documentation.
4. Conduct annual reviews and log them. NIST AI RMF is an ongoing program, not a one-time certification. Annual reviews demonstrating continued implementation are what sustain the rebuttable presumption over time. If the AG investigates, you need to show current compliance, not past compliance.
Note: The presumption is rebuttable. If there is evidence of actual algorithmic discrimination causing harm, the AG can still pursue enforcement even if you have NIST documentation. The framework reduces risk dramatically — it does not eliminate it. Source: Colorado Attorney General rulemaking guidance, coag.gov/resources/artificial-intelligence.
SB 205 has a tight timeline with ongoing obligations after the initial June 30, 2026 deadline. Here are every date that matters for deployers as of May 2026.
Governor Jared Polis signed Senate Bill 24-205 into law, making Colorado the first U.S. state to pass comprehensive AI regulation. The law directed the Colorado Attorney General to develop rulemaking guidance on implementation standards. It also granted developers and deployers two years to prepare for enforcement.
The Colorado Attorney General's office developed implementation guidance, clarifying definitions, rulemaking on the affirmative defense frameworks, and the specific requirements for impact assessments and consumer disclosures. Businesses were advised to begin compliance preparations during this window. AG guidance available at coag.gov.
This is the last window to complete: NIST AI RMF adoption documents, impact assessments for each high-risk system, consumer disclosure notices and appeal infrastructure, governance policy finalization, bias testing documentation, and staff training. Most organizations need 4–8 weeks for each system assessed. If you have 2+ high-risk AI systems and haven't started, start today.
All deployers of high-risk AI systems must have: risk management programs documented and implemented, pre-deployment impact assessments completed and retained, consumer disclosure notices live and operational, appeal rights infrastructure working, and incident reporting procedures defined. The AG's office can investigate, issue civil investigative demands, and impose penalties of up to $20,000 per violation from this date forward.
If you discover or reasonably suspect that a high-risk AI system has caused algorithmic discrimination, you must report it to the Colorado AG within 90 days of that discovery. Failure to report is a separate violation. Proactive disclosure, remediation, and cooperation with the AG's office may reduce or waive penalties under the cure provision — particularly if the violation is not a pattern or practice.
Impact assessments must be reviewed annually from the date of initial deployment. If a high-risk AI system undergoes an "intentional and substantial modification," a new impact assessment must be completed within 90 days of the change. Your NIST AI RMF program documentation must also be updated annually to sustain the affirmative defense. Plan these into your compliance calendar now.
If your company has operations or customers in both Colorado and the EU, you face both deadlines — Colorado on June 30, 2026 and EU AI Act high-risk enforcement on August 2, 2026. Understanding the differences prevents both under-investment (missing a requirement unique to one regime) and over-investment (assuming they require entirely different programs).
| Dimension | Colorado SB 205 | EU AI Act |
|---|---|---|
| Enforcement deadline | June 30, 2026 | August 2, 2026 |
| Geographic scope | Consequential decisions affecting Colorado consumers — company location irrelevant | AI systems affecting EU residents — company location irrelevant |
| Scope trigger | Consequential decisions in 7 domains (employment, credit, housing, healthcare, insurance, education, legal) | Any AI system in Annex III categories (broader — includes biometric, critical infrastructure, border control, etc.) |
| Maximum penalty | $20,000 per violation (Colorado Consumer Protection Act) | €35M or 7% of global annual turnover, whichever is higher |
| Private right of action | No — AG enforcement only | No — national market surveillance authorities only |
| Risk management | Reasonable care standard; NIST AI RMF / ISO 42001 = rebuttable presumption | Mandatory documented risk management system per Article 9; no equivalent safe harbor |
| Impact / conformity assessment | Pre-deployment + annual impact assessment required | Conformity assessment required; vendor must provide technical documentation; registries required |
| Consumer disclosures | Pre- and post-decision notice to individuals affected by AI | Transparency to affected persons required; chatbot transparency under Article 50 |
| Appeal rights | Mandatory right to human review, data correction, and re-evaluation | Human oversight required but no equivalent right-to-appeal mandate |
| Incident reporting | Report to AG within 90 days of discovering discrimination | No equivalent proactive AG-reporting requirement; incident logs required |
| AI literacy training | Not explicitly required | Mandatory under Article 4 for all AI users |
| Vendor obligations | Developer obligations exist separately; deployers cannot rely solely on vendor compliance | Providers bear primary conformity burden; deployers must obtain documentation and verify |
Sources: Colorado SB 24-205, Colorado General Assembly; Regulation (EU) 2024/1689, EU AI Act Portal. If you're building a compliance program that covers both, check our EU AI Act SMB Guide →
Knowing the law is the first step. Knowing exactly which of your AI systems are in scope, what gaps you have against the four deployer obligations, and getting a prioritized written action plan is the second. GovernIQ automates the gap analysis — built specifically for SMBs, not enterprise GRC teams.
Covers AI tool inventory, data handling practices, employee training status, and policy governance. Takes 5 minutes. Generates a 0–100 compliance score and identifies up to 8 specific policy gaps — matched to SB 205 and EU AI Act requirements.
Take the Assessment →See a real example of the personalized Compliance Action Plan output for a fictional financial advisory firm facing similar AI compliance obligations. Understand what you'll get before you purchase.
View Sample Plan →After a $299 one-time purchase, receive a full Compliance Action Plan specific to your company's AI stack, SB 205 gaps, risk level, and industry — with actionable items, policy templates, and a 90-day remediation roadmap.
See Pricing →The GovernIQ assessment identifies which of your AI tools are high-risk under SB 205, what compliance gaps you have, and exactly what to do before the June 30 enforcement deadline. Free. No account required.
Free assessment · Personalized Compliance Action Plan $299 · No subscription