America's first comprehensive state AI law. If your AI system makes consequential decisions — hiring, credit, housing, healthcare — you're in scope. Fines up to $20,000 per violation. 6 weeks to deadline.
12 questions · 5 minutes · Instant compliance score
Colorado SB 205 is narrower than the EU AI Act. It only applies to AI systems that make or substantially factor into decisions with a "material legal or similarly significant effect" in these domains. If your AI doesn't touch these areas, you're out of scope.
Hiring, promotion, scheduling, performance evaluation, termination
Educational opportunity or enrollment decisions
Loan approval, interest rates, credit terms and limits
Rental approval, housing terms, pricing
Treatment decisions, access to services, healthcare coverage
Coverage decisions, pricing, claims assessment
Access to legal services and representation
Benefits, permits, licensing, public services
The AI doesn't have to make the final decision alone to be in scope. If it assists in or significantly influences a consequential decision, SB 205 applies. Example: using an AI to rank candidates before a human reviews them is "substantial factor" territory.
Quick-reference table for common SMB AI tools. "Maybe" means consult legal — it depends on how the system is used.
| AI System | In Scope? | Why |
|---|---|---|
| Hiring / recruitment AI (CV screening, candidate ranking) | In Scope | Substantially factors into employment decisions — full compliance required |
| Employee performance evaluation AI | In Scope | Affects employment outcomes (promotion, termination) |
| Employee scheduling AI (shift allocation, hours) | In Scope | Employment decisions — affects scheduling as significant employment factor |
| Loan / credit decision AI | In Scope | Direct consequential decision (credit access, terms) |
| Insurance claims processing AI | In Scope | Substantially factors into claims decisions |
| Healthcare diagnostic / triage AI | In Scope | Healthcare access and treatment decisions |
| Pricing AI (insurance premiums, loan rates, housing) | Likely In Scope | If it affects cost/terms of a covered service — consult legal |
| Sales pipeline AI (lead scoring) | Out of Scope | Internal sales tool — no consequential decision about individuals |
| Customer service chatbot | Out of Scope | No consequential decision — out of scope unless it affects covered domains |
| Recommendation engine (products, content) | Out of Scope | No material legal effect on individuals |
| Internal analytics (no people decisions) | Out of Scope | No consequential decision about individuals |
If you use a high-risk AI system (any system making a consequential decision), these are the three things you must have in place by June 30, 2026.
Use "reasonable care" to avoid algorithmic discrimination. Documented evidence is required — a policy on paper that you don't follow doesn't count. The fastest path to compliance: adopt the NIST AI Risk Management Framework (free, 160 pages) or ISO/IEC 42001, which gives you a rebuttable presumption of compliance.
Before deployment and annually thereafter, conduct a formal impact assessment documenting the system's purpose, data inputs, outputs, discrimination risks, bias testing, mitigation measures, and human oversight mechanism. Retain assessments for 3+ years after final deployment.
Notify individuals when a high-risk AI system makes or substantially influences a consequential decision about them. For adverse decisions, provide the reasons, explain the AI's role, offer data correction, and provide a pathway to human review.
Nine required elements. Must be completed before deployment and annually after. If a system undergoes "intentional and substantial modification," complete a new assessment within 90 days.
What is the system designed to do? What consequential decision does it support or influence?
Required Element 1What types and sources of data does the system use — training data and real-time inputs? Who provides the data?
Required Element 2What does the system output? How exactly is it used to make or influence consequential decisions?
Required Element 3Does the system disproportionately affect protected groups? Race, gender, age, disability — what's the evidence for or against?
Required Element 4What testing has been conducted to check for discrimination? What were the results? Who ran the tests?
Required Element 5What controls reduce discrimination risk? Threshold tuning, human review checkpoints, fairness constraints?
Required Element 6Is there meaningful human review before adverse decisions are finalized? How does it work in practice?
Required Element 7How are affected individuals informed about AI use? What plain-language explanations are provided?
Required Element 8When does the system not work reliably? What are its edge cases and known weaknesses?
Required Element 9Colorado Attorney General has exclusive enforcement authority — no private right of action (yet). Each violation is a separate fine. A deployer with 3 high-risk systems and none of the 3 requirements in place = up to $60,000 exposed from day one.
| Violation | Fine |
|---|---|
| Using high-risk AI without a risk management program | Up to $20,000 per violation |
| Failing to complete an impact assessment before deployment | Up to $20,000 per violation |
| Failing to notify consumers of AI use in a consequential decision | Up to $20,000 per violation |
| Failing to provide a human appeal process | Up to $20,000 per violation |
| Failing to report algorithmic discrimination to Colorado AG within 90 days | Up to $20,000 per violation |
Adopt the NIST AI Risk Management Framework 1.0 (free, public) or ISO/IEC 42001 and document that you follow it. This creates a rebuttable presumption that you used "reasonable care" — the core standard under SB 205. There's also a cure provision: discover discrimination, fix it proactively, report to the AG, and you may avoid the full penalty if it's not a pattern violation.
The free 5-minute assessment identifies which of your AI systems fall under SB 205, what compliance gaps you have, and exactly what to do before June 30.
Free assessment · Compliance Action Plan $299 · No subscription