Colorado SB 205 Senate Bill 24-205 ⚠ June 30, 2026 Deadline

Colorado SB 205 AI Compliance —
SMB Checklist for June 30, 2026

America's first comprehensive state AI law. If your AI system makes consequential decisions — hiring, credit, housing, healthcare — you're in scope. Fines up to $20,000 per violation. 6 weeks to deadline.

Create a workspace → Guided intake → EU AI Act →

12 questions · 5 minutes · Instant compliance score

June 30 Enforcement deadline Colorado Attorney General begins enforcement
$20K Per violation fine Under Colorado Consumer Protection Act
Narrow Scope Only "consequential decisions" — most AI tools are out of scope
NIST RMF Affirmative defense Following NIST AI RMF or ISO 42001 = rebuttable presumption of compliance
The Key Question

Does your AI make "consequential decisions"?

Colorado SB 205 is narrower than the EU AI Act. It only applies to AI systems that make or substantially factor into decisions with a "material legal or similarly significant effect" in these domains. If your AI doesn't touch these areas, you're out of scope.

👔

Employment

Hiring, promotion, scheduling, performance evaluation, termination

🎓

Education

Educational opportunity or enrollment decisions

💳

Credit & Lending

Loan approval, interest rates, credit terms and limits

🏠

Housing

Rental approval, housing terms, pricing

🏥

Healthcare

Treatment decisions, access to services, healthcare coverage

🛡️

Insurance

Coverage decisions, pricing, claims assessment

⚖️

Legal Services

Access to legal services and representation

🏛️

Government Services

Benefits, permits, licensing, public services

The "substantial factor" test — broader than you think

The AI doesn't have to make the final decision alone to be in scope. If it assists in or significantly influences a consequential decision, SB 205 applies. Example: using an AI to rank candidates before a human reviews them is "substantial factor" territory.

In-Scope Reference

Is your AI system covered by SB 205?

Quick-reference table for common SMB AI tools. "Maybe" means consult legal — it depends on how the system is used.

AI System In Scope? Why
Hiring / recruitment AI (CV screening, candidate ranking) In Scope Substantially factors into employment decisions — full compliance required
Employee performance evaluation AI In Scope Affects employment outcomes (promotion, termination)
Employee scheduling AI (shift allocation, hours) In Scope Employment decisions — affects scheduling as significant employment factor
Loan / credit decision AI In Scope Direct consequential decision (credit access, terms)
Insurance claims processing AI In Scope Substantially factors into claims decisions
Healthcare diagnostic / triage AI In Scope Healthcare access and treatment decisions
Pricing AI (insurance premiums, loan rates, housing) Likely In Scope If it affects cost/terms of a covered service — consult legal
Sales pipeline AI (lead scoring) Out of Scope Internal sales tool — no consequential decision about individuals
Customer service chatbot Out of Scope No consequential decision — out of scope unless it affects covered domains
Recommendation engine (products, content) Out of Scope No material legal effect on individuals
Internal analytics (no people decisions) Out of Scope No consequential decision about individuals
Core Requirements

Three things SB 205 requires from deployers

If you use a high-risk AI system (any system making a consequential decision), these are the three things you must have in place by June 30, 2026.

01

Risk Management Program

Use "reasonable care" to avoid algorithmic discrimination. Documented evidence is required — a policy on paper that you don't follow doesn't count. The fastest path to compliance: adopt the NIST AI Risk Management Framework (free, 160 pages) or ISO/IEC 42001, which gives you a rebuttable presumption of compliance.

  • Written risk management policy specifying who owns AI decisions, how risks are assessed, what testing is done
  • Defined governance structure (assign roles: data owner, system owner, compliance reviewer)
  • Documented evidence of implementation — not just the policy document
  • Baseline controls: bias testing, accuracy validation, data quality checks, human oversight
Deadline: May 31, 2026
02

Impact Assessment for Each High-Risk System

Before deployment and annually thereafter, conduct a formal impact assessment documenting the system's purpose, data inputs, outputs, discrimination risks, bias testing, mitigation measures, and human oversight mechanism. Retain assessments for 3+ years after final deployment.

  • System purpose and intended use (what consequential decision does it support?)
  • Data inputs — training data, real-time inputs, data sources
  • Known or foreseeable risks of algorithmic discrimination by protected class
  • Bias testing results and mitigation measures
  • Human oversight mechanism (how does meaningful human review happen?)
  • How affected individuals are informed and what explanations are available
Deadline: June 15, 2026
03

Consumer Disclosures + Appeal Rights

Notify individuals when a high-risk AI system makes or substantially influences a consequential decision about them. For adverse decisions, provide the reasons, explain the AI's role, offer data correction, and provide a pathway to human review.

  • Pre-decision notice: inform individuals that AI is used, its purpose, data sources, and their rights
  • Post-decision notice for adverse outcomes: explain AI's contribution, reasons, data used
  • Right to correct data errors and request re-evaluation
  • Right to appeal and request human review
  • Technical infrastructure to deliver notices and handle appeals
Deadline: June 25, 2026
Impact Assessment

What goes in a SB 205 impact assessment

Nine required elements. Must be completed before deployment and annually after. If a system undergoes "intentional and substantial modification," complete a new assessment within 90 days.

System Purpose & Intended Use

What is the system designed to do? What consequential decision does it support or influence?

Required Element 1

Data Inputs

What types and sources of data does the system use — training data and real-time inputs? Who provides the data?

Required Element 2

Outputs & Decision Impact

What does the system output? How exactly is it used to make or influence consequential decisions?

Required Element 3

Discrimination Risk Assessment

Does the system disproportionately affect protected groups? Race, gender, age, disability — what's the evidence for or against?

Required Element 4

Bias Testing & Validation

What testing has been conducted to check for discrimination? What were the results? Who ran the tests?

Required Element 5

Mitigation Measures

What controls reduce discrimination risk? Threshold tuning, human review checkpoints, fairness constraints?

Required Element 6

Human Oversight Mechanism

Is there meaningful human review before adverse decisions are finalized? How does it work in practice?

Required Element 7

Transparency Measures

How are affected individuals informed about AI use? What plain-language explanations are provided?

Required Element 8

Limitations & Failure Modes

When does the system not work reliably? What are its edge cases and known weaknesses?

Required Element 9
Penalties

What violations cost

Colorado Attorney General has exclusive enforcement authority — no private right of action (yet). Each violation is a separate fine. A deployer with 3 high-risk systems and none of the 3 requirements in place = up to $60,000 exposed from day one.

Violation Fine
Using high-risk AI without a risk management program Up to $20,000 per violation
Failing to complete an impact assessment before deployment Up to $20,000 per violation
Failing to notify consumers of AI use in a consequential decision Up to $20,000 per violation
Failing to provide a human appeal process Up to $20,000 per violation
Failing to report algorithmic discrimination to Colorado AG within 90 days Up to $20,000 per violation

Good news: there's an affirmative defense

Adopt the NIST AI Risk Management Framework 1.0 (free, public) or ISO/IEC 42001 and document that you follow it. This creates a rebuttable presumption that you used "reasonable care" — the core standard under SB 205. There's also a cure provision: discover discrimination, fix it proactively, report to the AG, and you may avoid the full penalty if it's not a pattern violation.

Find out if your AI is covered by SB 205.

The free 5-minute assessment identifies which of your AI systems fall under SB 205, what compliance gaps you have, and exactly what to do before June 30.

Take the Free Assessment → See a Sample Plan

Free assessment · Compliance Action Plan $299 · No subscription