Complete Guide Colorado SB 26-189 ⚠ Colorado AI Act Compliance

SB 26-189 Compliance Checklist for Small & Mid-Market Businesses

Colorado's second AI law, SB 26-189, sets the operational standard for Colorado AI Act compliance: every deployer touching Colorado consumers must run a documented AI system inventory, conduct pre-deployment impact assessments, publish consumer deployer disclosures, manage vendor conformance, and operate an ongoing monitoring + 90-day incident reporting program. Penalties reach $20,000 per violation under the Colorado Consumer Protection Act. This guide walks through the five obligations step-by-step.

Create a workspace → Guided intake → See Sample Plan

12 questions · 5 minutes · Instant score · No account required

TL;DR — Three Things You Must Know
Scope & Applicability

Does SB 26-189 apply to you? The covered-contexts test

SB 26-189 is the operational complement to SB 24-205. Where SB 24-205 focuses on high-risk consequential decisions in seven named domains, SB 26-189 focuses on whether your AI system interacts with Colorado consumers in any "covered context." The decision is binary per system: if the system touches a Colorado consumer in a covered context, all five obligations apply to that system.

The covered contexts under SB 26-189 §6-1-1701(4) (Colorado General Assembly):

🛒
Consumer Procurement
AI used to evaluate, rank, or award bids, contracts, or procurement
👔
Employment Screening
AI used to screen, rank, or filter candidates in hiring or HR decisions
💳
Financial Eligibility
AI used to determine eligibility for credit, loans, or financial products
🏥
Healthcare Access
AI used to triage, route, or determine healthcare access or coverage
🛡️
Insurance Decisions
AI used for underwriting, claims assessment, or pricing of coverage
📨
Significant Consumer Interaction
AI materially interacting with Colorado consumers in any other high-stakes context

Use these three questions to determine if SB 26-189 applies to a given AI system in your stack:

01

Does the AI system interact with Colorado consumers?

Is the system exposed — directly or through a downstream decision — to consumers residing in Colorado, whether as customers, applicants, employees, patients, claimants, or bidders? Pure internal analytics with no consumer touchpoint is out of scope.

Yes → Proceed to Question 2   No → SB 26-189 obligations do not apply to this system
02

Is the interaction in a covered context?

Does the AI system operate in any of the six covered contexts shown above — procurement, employment screening, financial eligibility, healthcare access, insurance, or other significant consumer interaction?

Yes → Proceed to Question 3 No → Document the scope reasoning and keep the AI in your general AI registry
03

Are you the deployer (not just the developer or integrator)?

Do you operate the AI in your business operations under your name, with your customer relationship, and with risk-bearing responsibility for the system's output? If yes, you are a deployer under SB 26-189 and all five obligations apply.

Yes → SB 26-189 applies. Run the five-step framework immediately.

The deployer test under SB 26-189 — what counts

SB 26-189 places direct compliance obligations on the business that operates the AI under its own customer or employment relationship. Buying a vendor's AI product does not transfer the deployer's obligations to the vendor. The deployer is responsible for: producing the inventory entry, completing the impact assessment, publishing the consumer disclosures, holding the vendor contractually accountable, and operating the monitoring program. Vendors and developers have separate obligations under §6-1-1705, but those obligations do not absolve the deployer. Source: SB 26-189, Colorado General Assembly; Colorado AG rulemaking guidance at coag.gov/resources/artificial-intelligence.

The Five Obligations

The five-step Colorado AI Act compliance checklist

For every AI system in scope under SB 26-189, deployers must complete and continuously maintain these five operational records. Each one feeds the next — the inventory defines what gets assessed, the assessment informs the disclosure, the disclosure links to vendor clauses, and the monitoring loop closes the system.

🗂️

1. AI System Inventory

A live, maintained record of every AI system touching Colorado consumers in a covered context. The inventory is the foundation for every other obligation — without it, the rest of the framework cannot function. SB 26-189 §6-1-1702 requires quarterly inventory reviews with updates within 30 days of any new deployment or substantial modification.

  • Vendor name and contract reference; developer if different from vendor
  • Model name, version, and date acquired or deployed
  • Training data sources, provenance, and last refresh date
  • Deployment surface: where the AI meets the Colorado consumer
  • Covered context(s) under SB 26-189 that the system is operating in
  • Business owner inside the organization, with accountability for outcomes
  • Date of last impact assessment and next scheduled annual review
  • Quarterly inventory review with documented sign-off
🔍

2. Impact Assessment

Required before deploying any AI system into a covered context, and annually thereafter. If the system undergoes an "intentional and substantial modification," a new impact assessment must be completed within 90 days of the change. SB 26-189 §6-1-1703 specifies the required elements, sign-off, and retention rules.

  • System purpose and intended Colorado consumer use case
  • Data inputs: training data sources, real-time consumer data, third-party data
  • Known and foreseeable disparate-impact risks by protected class
  • Bias testing methodology and quantitative results across protected classes
  • Mitigation measures, residual risk acceptance, and escalation triggers
  • Human oversight mechanism and its operational effectiveness
  • Consumer disclosure language and the channels used to deliver it
  • Vendor conformance documentation relevant to this deployment
  • Designated accountable executive sign-off and 3-year retention
📣

3. Consumer Deployer Disclosures

Notice to the Colorado consumer that an AI system is being used, before the AI materially affects a decision, and again after an adverse outcome. Both moments are required under SB 26-189 §6-1-1704. The disclosures must be in plain language, accessible to the consumer at the point of decision, and not buried in privacy policies.

  • Pre-interaction disclosure: state plainly that AI is being used and the high-level purpose
  • Post-decision disclosure for adverse outcomes: explain the AI's role and the consumer's review rights
  • Plain-language description of the categories of data the AI processes
  • A working contact channel (email or web form) for AI-related questions
  • Statement that the consumer may request human review of any adverse decision
  • Disclosure language reviewed by counsel and updated whenever the system changes
📑

4. Vendor Management

SB 26-189 §6-1-1705 does not absolve deployers of obligations because they purchased an AI tool from a vendor. Deployers must hold vendors contractually accountable for current conformance documentation, notice of model updates, audit cooperation, and records retention. The deployer is responsible for detecting vendor changes that trigger a new impact assessment.

  • Procurement clause requiring vendor to deliver current model card and training data summary
  • Vendor obligation to provide known limitations and evaluation results on request
  • Vendor obligation to notify deployer within 30 days of any material model update
  • Vendor obligation to cooperate with deployer-conducted bias audits
  • Records-retention clause supporting the deployer's 3-year assessment retention obligation
  • Change-trigger log: which vendor update requires deployer re-assessment
📊

5. Ongoing Monitoring & 90-Day Reporting

The compliance record is not a one-time artifact. SB 26-189 §6-1-1707 requires quarterly inventory reviews, annual impact assessment re-runs, change-triggered re-assessment within 90 days, and incident reporting to the Colorado Attorney General within 90 days of discovering algorithmic discrimination. The monitoring program is what converts an annual compliance posture into a continuously defensible one.

  • Quarterly inventory review — log changes and updates
  • Annual impact assessment review — within 90 days of each system's anniversary
  • Change-trigger rules: vendor update, metric drift, incident
  • Re-assessment within 90 days of any triggering change
  • Incident log maintained internally with protected-class breakdowns
  • 90-day reporting to the Colorado AG for any known or suspected harm
  • Cooperation procedure and remediation tracking for AG inquiries
Affirmative Defense Integration

How NIST AI RMF plugs into the SB 26-189 five-step framework

SB 26-189 does not prescribe a single framework, but your existing NIST AI RMF program (whether built for SB 24-205 or the EU AI Act) already supplies the four mechanics you need: Govern sets ownership for the inventory, Map drives each impact assessment, Measure produces the bias testing evidence, and Manage runs the quarterly review and incident-reporting loop. The NIST record is also what you'd present to the Colorado AG if an investigation is opened.

Activating the NIST record under SB 26-189

Four steps that satisfy both SB 24-205 and SB 26-189

1. Adopt NIST AI RMF 1.0 formally. Adopt it via an executive resolution as your organization's AI risk management standard; document the adoption date so the rebuttable presumption under SB 24-205 is preserved. NIST AI RMF 1.0 is free at nist.gov/artificial-intelligence.

2. Map every SB 26-189 in-scope system. For each AI system in your SB 26-189 inventory, complete a NIST "Map" exercise: purpose, stakeholders, context, risk categories. The Map output is the foundation for the SB 26-189 impact assessment — build it once, use it for both laws.

3. Implement Govern, Measure, and Manage. Assign ownership (Govern), execute bias and accuracy testing (Measure), and operate the quarterly inventory, annual review, change-trigger re-assessment, and 90-day reporting (Manage). All five SB 26-189 obligations get satisfied within the same NIST loop.

4. Run the annual review on schedule. The NIST record sustains the SB 24-205 presumption and provides ongoing evidence of Colorado AI Act compliance under SB 26-189. If the AG investigates or you report an incident, the annual program log is what demonstrates continuing compliance — not just point-in-time paperwork.

Note: NIST reduces risk dramatically; it does not eliminate it. The AG can still pursue enforcement with strong evidence of disparate impact even when NIST documentation is complete. The framework is your best legal posture — but it is a defensive posture, not a license to ignore consumer harm. Source: Colorado Attorney General guidance.

Enforcement Timeline

Key dates for Colorado AI Act SB 26-189 compliance

SB 26-189's enforcement rolls in phases, with ongoing obligations layered on top of the initial deadline. The dates below are the milestones every SMB deployer should have on its compliance calendar as of August 2026.

2026 Spring — Passed

Colorado SB 26-189 Signed Into Law

SB 26-189 enacted as the operational complement to SB 24-205. The law directs the Colorado Attorney General to develop rulemaking guidance on the five-step operational framework — inventory, impact assessment, disclosures, vendor management, and ongoing monitoring. The bill provides a preparation window before enforcement begins.

Summer 2026 — Rulemaking Phase

AG Guidance and Rulemaking Developed

The Colorado Attorney General's office issues implementation guidance covering scope (covered contexts), the five obligations, the 90-day incident reporting rule, and the cure provision. Businesses were advised to begin compliance preparations during this window. AG guidance available at coag.gov/resources/artificial-intelligence.

NOW
Now → Hard Enforcement Date — Final Preparation Window

Inventory, Impact Assessments, Disclosure Systems, Vendor Contracts, Monitoring

This is the last window to complete: full AI system inventory with documented owners and deployment surfaces; pre-deployment impact assessments for each in-scope system; published pre-interaction and post-decision disclosures; vendor contract clauses with conformance, audit, and 30-day update provisions; and a quarterly monitor with 90-day AG reporting procedure. Most organizations need 4–8 weeks per system assessed. If you have 2+ in-scope systems and haven't started, start today.

LIVE
Hard Enforcement Date — SB 26-189 Live

Colorado AG Begins Enforcement of SB 26-189

All deployers of AI systems in covered contexts must have: a complete and current inventory; impact assessments completed and retained; pre- and post-decision disclosures operational; vendor contracts with the required SB 26-189 clauses; and an ongoing monitoring program with documented quarterly, annual, and change-trigger reviews. The AG's office can investigate, issue civil investigative demands, and impose penalties up to $20,000 per violation from this date forward.

90D
Ongoing — 90-Day Incident Reporting Rule

Algorithmic Discrimination Must Be Reported Within 90 Days

If you discover or reasonably suspect that an AI system in a covered context has caused disparate-impact harm to Colorado consumers, you must report it to the Colorado AG within 90 days of that discovery. Failure to report within 90 days is a separate violation. Proactive reporting, full cooperation, and demonstrated remediation may reduce or waive penalties under the cure provision — particularly if the violation is not a pattern or practice.

Q+ANN
Ongoing — Quarterly + Annual Review Cycle

Quarterly Inventory Reviews + Annual Impact Assessment Updates

Inventory entries must be reviewed quarterly, with documented updates within 30 days of any new deployment or substantial modification. Impact assessments must be re-completed annually from the date of initial deployment, within 90 days of each system's anniversary. Triggered re-assessments (vendor update, metric drift, incident) must be completed within 90 days of the triggering event. Plan these into your compliance calendar now — they are what sustain Colorado AI Act compliance after the initial deadline.

Downloadable Checklist

The SB 26-189 compliance checklist — print or save as HTML

The five obligations are reproduced below in their checklist form for easy reference and operational use. A separate print-friendly HTML version is also available for download — it strips out styling chrome and renders cleanly on letter-size paper or as a saved reference document for your compliance team.

🗂️

1. AI System Inventory

  • Vendor + developer identified
  • Model name + version recorded
  • Training data sources listed
  • Deployment surface documented
  • Covered context(s) flagged under SB 26-189
  • Business owner assigned inside the org
  • Last assessment date + next review date stored
  • Quarterly review log kept
🔍

2. Impact Assessment

  • System purpose + Colorado consumer use case documented
  • Data inputs: training + real-time + third-party listed
  • Disparate-impact risks by protected class enumerated
  • Bias testing methodology + cross-class results recorded
  • Mitigation + residual risk + escalation triggers noted
  • Human oversight mechanism verified for operational use
  • Disclosure language + delivery channels documented
  • Vendor conformance documentation linked to assessment
  • Executive sign-off recorded; retained for 3 years
📣

3. Consumer Deployer Disclosures

  • Pre-interaction disclosure: AI use stated plainly
  • Pre-interaction disclosure: high-level purpose stated
  • Post-decision disclosure for adverse outcomes created
  • Plain-language data categories disclosed
  • Working contact email or form available
  • Right to human review language included
  • Disclosure reviewed by counsel and version-controlled
📑

4. Vendor Management

  • Procurement clause: model card + training data summary
  • Procurement clause: known limitations + evaluation results
  • Procurement clause: 30-day notice on material model updates
  • Procurement clause: audit cooperation
  • Procurement clause: records retention (3+ years)
  • Change-trigger log: which vendor update triggers re-assessment
📊

5. Ongoing Monitoring & 90-Day Reporting

  • Quarterly inventory review — log kept
  • Annual impact assessment — within 90 days of anniversary
  • Change-trigger rules defined (vendor update / drift / incident)
  • Triggered re-assessment within 90 days
  • Internal incident log maintained with protected-class breakdowns
  • 90-day AG reporting procedure documented and rehearsed
  • Cooperation procedure for AG inquiries
  • Remediation tracking for completed incidents

Save the checklist — printable HTML version

A standalone, print-friendly version of this checklist is available at /checklists/sb-26-189-checklist.html. It is sized for letter paper, contains no JavaScript or analytics, and is suitable for printing and including in your compliance binder or sharing with your legal team.

Regulatory Comparison

Colorado SB 26-189 vs. SB 24-205 — side by side

If your company serves Colorado consumers in any relevant context, you face both Colorado AI laws. They are additive, not duplicative — but the specific obligations are distinct. Understanding the difference prevents under-investment (missing an SB 26-189-specific duty) and over-investment (treating one statute as a substitute for the other).

Dimension SB 26-189 (new) SB 24-205
Trigger AI system interacting with Colorado consumer in any covered context AI system making or substantially influencing a consequential decision in 7 domains
Scope of in-scope systems Broader — includes procurement, screening, financial eligibility, healthcare access, insurance, and significant consumer interaction Narrower — 7 named domains (employment, credit, housing, healthcare, insurance, education, legal)
AI system inventory Required with quarterly review and 30-day update on new deployment / substantial modification Implicit through impact assessment record-keeping; no separate inventory mandate
Impact assessment Pre-deployment + annual + within 90 days of trigger; signed executive sign-off; 3-year retention Pre-deployment + annual + within 90 days of substantial modification; 3-year retention
Consumer disclosures Pre-interaction + post-decision notice with data categories and contact channel Pre-decision + post-adverse-decision notice; appeal rights included
Vendor management Specific procurement clauses: model card, 30-day update notice, audit cooperation, records retention Deployer cannot rely solely on vendor compliance; specific contract terms not enumerated
Ongoing monitoring Quarterly inventory review + annual re-assessment + change-trigger rules Annual review + change-trigger rule; no quarterly inventory mandate
Affirmative defense Framework adoption supports compliance posture and reduces enforcement risk NIST AI RMF / ISO 42001 = rebuttable presumption of reasonable care
Incident reporting Report to Colorado AG within 90 days of discovery; cure provision available Report to Colorado AG within 90 days; cure provision available
Maximum penalty $20,000 per violation (Colorado Consumer Protection Act) $20,000 per violation (Colorado Consumer Protection Act)
Private right of action No — AG enforcement only No — AG enforcement only
Best compliance posture Run both programs; the NIST record + impact assessment + disclosure language + monitoring loop satisfy both laws from a single evidence base NIST AI RMF adoption + annual review + AG reporting on incidents

Sources: Colorado SB 26-189, Colorado General Assembly; Colorado SB 24-205, Colorado General Assembly. If you're building a compliance program that covers both, start with our Colorado SB 205 deep dive →

How GovernIQ Helps

From this guide to a Colorado AI Act compliance plan in under an hour

Knowing the law is the first step. Knowing exactly which of your AI systems are in scope under SB 26-189, whether your existing NIST AI RMF program covers the five operational obligations, and getting a prioritized written action plan is the second. GovernIQ automates the gap analysis — built specifically for SMBs, not enterprise GRC teams.

01

12-Question Assessment

Covers AI tool inventory, data handling practices, employee training status, policy governance, vendor management, and monitoring posture. Takes 5 minutes. Generates a 0–100 compliance score and identifies up to 8 specific policy gaps — mapped to SB 26-189, SB 24-205, and EU AI Act requirements.

Take the Assessment →
02

Sample Compliance Plan

See a real example of the personalized Compliance Action Plan output for a fictional financial advisory firm facing similar Colorado AI Act compliance obligations. Understand what you'll get before you purchase.

View Sample Plan →
03

Personalized Action Plan

After a $299 one-time purchase, receive a full Compliance Action Plan specific to your company's AI stack, SB 26-189 / SB 24-205 / EU AI Act gaps, risk level, and industry — with actionable items, five-obligation SOP templates, vendor contract clause library, disclosure language, monitoring cadence, and a 90-day remediation roadmap.

See Pricing →
Frequently Asked Questions

Colorado AI Act SB 26-189 compliance — the questions we hear most

What is Colorado SB 26-189?
SB 26-189 is Colorado's second comprehensive AI law, enacted in 2026 as the operational complement to SB 24-205. Where SB 24-205 focuses on consequential decisions in seven domains, SB 26-189 establishes a five-part operational standard for any deployer whose AI system interacts with Colorado consumers in a covered context: (1) AI system inventory, (2) pre-deployment impact assessment, (3) consumer deployer disclosures, (4) vendor management with documented conformance, and (5) ongoing monitoring with 90-day incident reporting. It is enforced under the Colorado Consumer Protection Act with civil penalties up to $20,000 per violation. Source: Colorado General Assembly, SB26-189.
Who must comply with Colorado AI Act SB 26-189?
Any deployer — regardless of where the company is headquartered — that operates an AI system interacting with Colorado consumers in a covered context. Covered contexts include procurement, employment screening, financial eligibility, healthcare access, insurance, and other significant consumer-facing interactions. The test is whether Colorado consumers are affected by the AI system. You do not need to be based in Colorado; you do not need to operate only in Colorado. The five obligations apply to the system, not the deployer's geography.
What is required in an SB 26-189 AI system inventory?
For each in-scope system, the inventory must record the vendor and developer, model name and version, training data sources and provenance, the deployment surface (where the AI interacts with consumers), the covered context(s) it operates in, the business owner inside the organization with accountability for outcomes, the date of the last impact assessment, and the date of the next scheduled annual review. The inventory must be reviewed quarterly with documented sign-off, and updated within 30 days of any new deployment or substantial modification. The inventory is the foundation for every other obligation under SB 26-189.
What elements must a Colorado AI Act impact assessment include?
Nine elements: (1) system purpose and intended Colorado consumer use case, (2) data inputs (training data sources, real-time consumer data, third-party data), (3) known and foreseeable disparate-impact risks by protected class, (4) bias testing methodology and quantitative cross-class results, (5) mitigation measures, residual risk acceptance, and escalation triggers, (6) human oversight mechanism and its operational effectiveness, (7) consumer disclosure language and delivery channels, (8) vendor conformance documentation relevant to the deployment, and (9) designated accountable executive sign-off. Assessments must be retained for at least three years and re-completed annually and within 90 days of any triggering change.
When is a consumer deployer disclosure required under SB 26-189?
Both before and after a covered decision. The pre-interaction disclosure must be presented to the Colorado consumer at or before the point where the AI materially affects the decision; it must state plainly that AI is being used, identify the high-level purpose, and provide a working contact channel for AI-related questions. The post-decision disclosure for adverse outcomes must explain the AI's contribution, identify the data categories used, and state the consumer's right to request human review. Both must be in plain language, accessible at the point of decision, and not buried in privacy policies.
What are the vendor management obligations under SB 26-189?
Deployers must hold AI vendors contractually accountable for: current conformance documentation (model card, training data summary, known limitations, evaluation results), notice within 30 days of any material model update, cooperation with deployer-conducted bias audits, and records retention sufficient to support the deployer's three-year assessment retention obligation. The deployer remains responsible for monitoring vendor model updates and re-running the impact assessment when material changes occur. SB 26-189 does not absolve the deployer because the tool was purchased — buying a vendor's AI product does not transfer the deployer's compliance obligations.
What is the 90-day incident reporting rule under SB 26-189?
If a deployer discovers or reasonably suspects that an AI system in a covered context has caused disparate-impact harm to Colorado consumers, the deployer must report the incident to the Colorado Attorney General within 90 days of discovery. The report must include the affected system, the affected consumer population, the nature of the harm, immediate remediation steps, and the corrective action plan. Failure to report within 90 days is a separate violation. The cure provision may reduce or waive penalties for proactive, cooperative reporters — but only when the violation is not a pattern or practice.
How does SB 26-189 interact with Colorado SB 24-205?
They are complementary, additive Colorado AI Act compliance obligations. SB 24-205 governs high-risk AI in seven specified consequential-decision domains (employment, education, credit, housing, healthcare, insurance, legal services) and provides a NIST AI RMF affirmative defense. SB 26-189 is broader on operations: its inventory, vendor management, and 90-day reporting requirements apply to any AI system interacting with Colorado consumers in a covered context — not only to high-risk consequential-decision systems. A complete Colorado compliance program satisfies both laws; the SB 26-189 checklist is operationally additive to SB 24-205's deployer obligations. See our Colorado SB 205 guide for the SB 24-205 deep dive.
Does Colorado AI Act compliance under SB 26-189 require a NIST AI RMF program?
SB 26-189 does not prescribe a single framework. However, adopting and documenting adherence to the NIST AI RMF 1.0 (or ISO/IEC 42001) remains the strongest legal posture under Colorado AI Act compliance generally, and the four-line NIST adoption (adopt, map each system, implement Govern/Measure/Manage, conduct annual reviews) integrates directly into the SB 26-189 inventory, impact assessment, and vendor management cycles. The SB 24-205 affirmative defense flows into the SB 26-189 evidence record — when both laws apply, you build the documentation once and use it for both. The NIST AI RMF 1.0 framework is free at nist.gov/artificial-intelligence.
What are the penalties for violating Colorado AI Act SB 26-189?
Civil penalties up to $20,000 per violation under the Colorado Consumer Protection Act, enforced by the Colorado Attorney General. There is no private right of action. Violations stack across systems, incidents, and missed report deadlines: a deployer with three non-compliant systems and two unreported incidents faces five distinct violations on day one of enforcement, with theoretical exposure up to $100,000. The AG can also seek injunctive relief and require compliance audits. The cure provision may reduce or waive penalties for proactive, cooperative reporters — but only if the violation is not a pattern or practice.
What is the ongoing monitoring requirement under SB 26-189?
Three concrete ongoing monitoring activities. First, quarterly inventory reviews with logged sign-off. Second, annual impact assessment reviews for every system in the inventory, completed within 90 days of the system's anniversary date. Third, change-triggered re-assessment: if a vendor releases a material model update, if protected-class performance metrics drift, or if an internal incident surfaces a foreseeable risk, a new impact assessment must be completed within 90 days of the triggering event. These three layers convert an annual compliance posture into a continuously defensible record — which is what the AG will request if an investigation is opened.
Is there a cure provision under Colorado AI Act SB 26-189?
Yes. If a deployer discovers or reasonably suspects an SB 26-189 violation — typically a disparate-impact incident affecting Colorado consumers — and reports it to the Colorado Attorney General within 90 days, cooperates fully with the inquiry, remedies the harm, and demonstrates the violation was not a pattern or practice, the AG may reduce or waive penalties. The cure provision creates a meaningful incentive for the monitoring and self-reporting behavior SB 26-189 already requires, and makes a documented monitoring program materially valuable beyond mere compliance posture.
📋
Free Tool — No signup required
Need a starting policy before the SB 26-189 deadline? Get a customized AI Acceptable Use Policy in 60 seconds.
Includes AI system inventory template, SB 26-189 five-obligation checklist, NIST AI RMF mapping, and escalation path — generated for your org.
Build Your Policy Free →

Find out which of your AI systems are in scope — before the deadline.

The GovernIQ assessment identifies which of your AI systems interact with Colorado consumers in a covered context, maps your current posture against the five SB 26-189 obligations, and tells you exactly what to fix before enforcement begins. Free. No account required.

Create a workspace → Guided intake → See a Sample Report

Free assessment · Personalized Compliance Action Plan $299 · No subscription