Colorado's second AI law, SB 26-189, sets the operational standard for Colorado AI Act compliance: every deployer touching Colorado consumers must run a documented AI system inventory, conduct pre-deployment impact assessments, publish consumer deployer disclosures, manage vendor conformance, and operate an ongoing monitoring + 90-day incident reporting program. Penalties reach $20,000 per violation under the Colorado Consumer Protection Act. This guide walks through the five obligations step-by-step.
12 questions · 5 minutes · Instant score · No account required
SB 26-189 is the operational complement to SB 24-205. Where SB 24-205 focuses on high-risk consequential decisions in seven named domains, SB 26-189 focuses on whether your AI system interacts with Colorado consumers in any "covered context." The decision is binary per system: if the system touches a Colorado consumer in a covered context, all five obligations apply to that system.
The covered contexts under SB 26-189 §6-1-1701(4) (Colorado General Assembly):
Use these three questions to determine if SB 26-189 applies to a given AI system in your stack:
Is the system exposed — directly or through a downstream decision — to consumers residing in Colorado, whether as customers, applicants, employees, patients, claimants, or bidders? Pure internal analytics with no consumer touchpoint is out of scope.
Yes → Proceed to Question 2 No → SB 26-189 obligations do not apply to this systemDoes the AI system operate in any of the six covered contexts shown above — procurement, employment screening, financial eligibility, healthcare access, insurance, or other significant consumer interaction?
Yes → Proceed to Question 3 No → Document the scope reasoning and keep the AI in your general AI registryDo you operate the AI in your business operations under your name, with your customer relationship, and with risk-bearing responsibility for the system's output? If yes, you are a deployer under SB 26-189 and all five obligations apply.
Yes → SB 26-189 applies. Run the five-step framework immediately.SB 26-189 places direct compliance obligations on the business that operates the AI under its own customer or employment relationship. Buying a vendor's AI product does not transfer the deployer's obligations to the vendor. The deployer is responsible for: producing the inventory entry, completing the impact assessment, publishing the consumer disclosures, holding the vendor contractually accountable, and operating the monitoring program. Vendors and developers have separate obligations under §6-1-1705, but those obligations do not absolve the deployer. Source: SB 26-189, Colorado General Assembly; Colorado AG rulemaking guidance at coag.gov/resources/artificial-intelligence.
For every AI system in scope under SB 26-189, deployers must complete and continuously maintain these five operational records. Each one feeds the next — the inventory defines what gets assessed, the assessment informs the disclosure, the disclosure links to vendor clauses, and the monitoring loop closes the system.
A live, maintained record of every AI system touching Colorado consumers in a covered context. The inventory is the foundation for every other obligation — without it, the rest of the framework cannot function. SB 26-189 §6-1-1702 requires quarterly inventory reviews with updates within 30 days of any new deployment or substantial modification.
Required before deploying any AI system into a covered context, and annually thereafter. If the system undergoes an "intentional and substantial modification," a new impact assessment must be completed within 90 days of the change. SB 26-189 §6-1-1703 specifies the required elements, sign-off, and retention rules.
Notice to the Colorado consumer that an AI system is being used, before the AI materially affects a decision, and again after an adverse outcome. Both moments are required under SB 26-189 §6-1-1704. The disclosures must be in plain language, accessible to the consumer at the point of decision, and not buried in privacy policies.
SB 26-189 §6-1-1705 does not absolve deployers of obligations because they purchased an AI tool from a vendor. Deployers must hold vendors contractually accountable for current conformance documentation, notice of model updates, audit cooperation, and records retention. The deployer is responsible for detecting vendor changes that trigger a new impact assessment.
The compliance record is not a one-time artifact. SB 26-189 §6-1-1707 requires quarterly inventory reviews, annual impact assessment re-runs, change-triggered re-assessment within 90 days, and incident reporting to the Colorado Attorney General within 90 days of discovering algorithmic discrimination. The monitoring program is what converts an annual compliance posture into a continuously defensible one.
SB 26-189 does not prescribe a single framework, but your existing NIST AI RMF program (whether built for SB 24-205 or the EU AI Act) already supplies the four mechanics you need: Govern sets ownership for the inventory, Map drives each impact assessment, Measure produces the bias testing evidence, and Manage runs the quarterly review and incident-reporting loop. The NIST record is also what you'd present to the Colorado AG if an investigation is opened.
1. Adopt NIST AI RMF 1.0 formally. Adopt it via an executive resolution as your organization's AI risk management standard; document the adoption date so the rebuttable presumption under SB 24-205 is preserved. NIST AI RMF 1.0 is free at nist.gov/artificial-intelligence.
2. Map every SB 26-189 in-scope system. For each AI system in your SB 26-189 inventory, complete a NIST "Map" exercise: purpose, stakeholders, context, risk categories. The Map output is the foundation for the SB 26-189 impact assessment — build it once, use it for both laws.
3. Implement Govern, Measure, and Manage. Assign ownership (Govern), execute bias and accuracy testing (Measure), and operate the quarterly inventory, annual review, change-trigger re-assessment, and 90-day reporting (Manage). All five SB 26-189 obligations get satisfied within the same NIST loop.
4. Run the annual review on schedule. The NIST record sustains the SB 24-205 presumption and provides ongoing evidence of Colorado AI Act compliance under SB 26-189. If the AG investigates or you report an incident, the annual program log is what demonstrates continuing compliance — not just point-in-time paperwork.
Note: NIST reduces risk dramatically; it does not eliminate it. The AG can still pursue enforcement with strong evidence of disparate impact even when NIST documentation is complete. The framework is your best legal posture — but it is a defensive posture, not a license to ignore consumer harm. Source: Colorado Attorney General guidance.
SB 26-189's enforcement rolls in phases, with ongoing obligations layered on top of the initial deadline. The dates below are the milestones every SMB deployer should have on its compliance calendar as of August 2026.
SB 26-189 enacted as the operational complement to SB 24-205. The law directs the Colorado Attorney General to develop rulemaking guidance on the five-step operational framework — inventory, impact assessment, disclosures, vendor management, and ongoing monitoring. The bill provides a preparation window before enforcement begins.
The Colorado Attorney General's office issues implementation guidance covering scope (covered contexts), the five obligations, the 90-day incident reporting rule, and the cure provision. Businesses were advised to begin compliance preparations during this window. AG guidance available at coag.gov/resources/artificial-intelligence.
This is the last window to complete: full AI system inventory with documented owners and deployment surfaces; pre-deployment impact assessments for each in-scope system; published pre-interaction and post-decision disclosures; vendor contract clauses with conformance, audit, and 30-day update provisions; and a quarterly monitor with 90-day AG reporting procedure. Most organizations need 4–8 weeks per system assessed. If you have 2+ in-scope systems and haven't started, start today.
All deployers of AI systems in covered contexts must have: a complete and current inventory; impact assessments completed and retained; pre- and post-decision disclosures operational; vendor contracts with the required SB 26-189 clauses; and an ongoing monitoring program with documented quarterly, annual, and change-trigger reviews. The AG's office can investigate, issue civil investigative demands, and impose penalties up to $20,000 per violation from this date forward.
If you discover or reasonably suspect that an AI system in a covered context has caused disparate-impact harm to Colorado consumers, you must report it to the Colorado AG within 90 days of that discovery. Failure to report within 90 days is a separate violation. Proactive reporting, full cooperation, and demonstrated remediation may reduce or waive penalties under the cure provision — particularly if the violation is not a pattern or practice.
Inventory entries must be reviewed quarterly, with documented updates within 30 days of any new deployment or substantial modification. Impact assessments must be re-completed annually from the date of initial deployment, within 90 days of each system's anniversary. Triggered re-assessments (vendor update, metric drift, incident) must be completed within 90 days of the triggering event. Plan these into your compliance calendar now — they are what sustain Colorado AI Act compliance after the initial deadline.
The five obligations are reproduced below in their checklist form for easy reference and operational use. A separate print-friendly HTML version is also available for download — it strips out styling chrome and renders cleanly on letter-size paper or as a saved reference document for your compliance team.
A standalone, print-friendly version of this checklist is available at /checklists/sb-26-189-checklist.html. It is sized for letter paper, contains no JavaScript or analytics, and is suitable for printing and including in your compliance binder or sharing with your legal team.
If your company serves Colorado consumers in any relevant context, you face both Colorado AI laws. They are additive, not duplicative — but the specific obligations are distinct. Understanding the difference prevents under-investment (missing an SB 26-189-specific duty) and over-investment (treating one statute as a substitute for the other).
| Dimension | SB 26-189 (new) | SB 24-205 |
|---|---|---|
| Trigger | AI system interacting with Colorado consumer in any covered context | AI system making or substantially influencing a consequential decision in 7 domains |
| Scope of in-scope systems | Broader — includes procurement, screening, financial eligibility, healthcare access, insurance, and significant consumer interaction | Narrower — 7 named domains (employment, credit, housing, healthcare, insurance, education, legal) |
| AI system inventory | Required with quarterly review and 30-day update on new deployment / substantial modification | Implicit through impact assessment record-keeping; no separate inventory mandate |
| Impact assessment | Pre-deployment + annual + within 90 days of trigger; signed executive sign-off; 3-year retention | Pre-deployment + annual + within 90 days of substantial modification; 3-year retention |
| Consumer disclosures | Pre-interaction + post-decision notice with data categories and contact channel | Pre-decision + post-adverse-decision notice; appeal rights included |
| Vendor management | Specific procurement clauses: model card, 30-day update notice, audit cooperation, records retention | Deployer cannot rely solely on vendor compliance; specific contract terms not enumerated |
| Ongoing monitoring | Quarterly inventory review + annual re-assessment + change-trigger rules | Annual review + change-trigger rule; no quarterly inventory mandate |
| Affirmative defense | Framework adoption supports compliance posture and reduces enforcement risk | NIST AI RMF / ISO 42001 = rebuttable presumption of reasonable care |
| Incident reporting | Report to Colorado AG within 90 days of discovery; cure provision available | Report to Colorado AG within 90 days; cure provision available |
| Maximum penalty | $20,000 per violation (Colorado Consumer Protection Act) | $20,000 per violation (Colorado Consumer Protection Act) |
| Private right of action | No — AG enforcement only | No — AG enforcement only |
| Best compliance posture | Run both programs; the NIST record + impact assessment + disclosure language + monitoring loop satisfy both laws from a single evidence base | NIST AI RMF adoption + annual review + AG reporting on incidents |
Sources: Colorado SB 26-189, Colorado General Assembly; Colorado SB 24-205, Colorado General Assembly. If you're building a compliance program that covers both, start with our Colorado SB 205 deep dive →
Knowing the law is the first step. Knowing exactly which of your AI systems are in scope under SB 26-189, whether your existing NIST AI RMF program covers the five operational obligations, and getting a prioritized written action plan is the second. GovernIQ automates the gap analysis — built specifically for SMBs, not enterprise GRC teams.
Covers AI tool inventory, data handling practices, employee training status, policy governance, vendor management, and monitoring posture. Takes 5 minutes. Generates a 0–100 compliance score and identifies up to 8 specific policy gaps — mapped to SB 26-189, SB 24-205, and EU AI Act requirements.
Take the Assessment →See a real example of the personalized Compliance Action Plan output for a fictional financial advisory firm facing similar Colorado AI Act compliance obligations. Understand what you'll get before you purchase.
View Sample Plan →After a $299 one-time purchase, receive a full Compliance Action Plan specific to your company's AI stack, SB 26-189 / SB 24-205 / EU AI Act gaps, risk level, and industry — with actionable items, five-obligation SOP templates, vendor contract clause library, disclosure language, monitoring cadence, and a 90-day remediation roadmap.
See Pricing →The GovernIQ assessment identifies which of your AI systems interact with Colorado consumers in a covered context, maps your current posture against the five SB 26-189 obligations, and tells you exactly what to fix before enforcement begins. Free. No account required.
Free assessment · Personalized Compliance Action Plan $299 · No subscription