Colorado
Colorado AI Laws and Regulation (2026)
Independently fact-checked against primary sources (last audited August 20, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 20, 2026. · 9 primary sources cited on this page. How we verify our legal content

Colorado has no comprehensive AI statute in force today. SB 24-205, the Colorado Artificial Intelligence Act, was signed on May 17, 2024 and would have been the first comprehensive state AI consumer protection law in the United States, but it was repealed before its enforcement date ever arrived. Governor Polis signed SB 26-189 on May 14, 2026, repealing and reenacting part 17 of article 1 of title 6 as the narrower Automated Decision-Making Technology (ADMT) Act, codified at C.R.S. 6-1-1701 to 6-1-1709 and effective January 1, 2027. Two narrower Colorado AI laws are already in force: election deepfake disclosures (C.R.S. 1-46-101 to 1-46-106) and the intimate digital depictions laws (C.R.S. 18-7-107 to 18-7-109 and 13-21-1501 to 13-21-1507).
Colorado made history on May 17, 2024, when Governor Jared Polis signed Senate Bill 24-205 into law, creating what was then the first comprehensive AI consumer protection statute in the United States. It never became operative. After two delays, the legislature repealed and reenacted it in 2026 as the Colorado Automated Decision-Making Technology (ADMT) Act, a substantially narrower disclosure regime that takes effect January 1, 2027.
This guide covers the law that actually binds Colorado businesses first, then the repealed framework and how it collapsed, then Colorado's two AI laws that are already in force. This article is for informational purposes only. Consult an attorney for advice specific to your situation.
The Colorado ADMT Act (SB 26-189): The Operative Law
The ADMT Act is codified at C.R.S. 6-1-1701 to 6-1-1709. It takes effect January 1, 2027 and applies to consequential decisions made on or after that date. Three provisions took effect on passage so the Attorney General could begin rulemaking: C.R.S. 6-1-1704(4), 6-1-1705(3), and 6-1-1706(6).
What Is a Covered ADMT?
"Automated decision-making technology" is technology that processes personal data and uses computation to make or materially influence a decision. A "covered ADMT" is narrower: automated decision-making technology that is used to materially influence a consequential decision (C.R.S. 6-1-1701(5)). The repealed act's term "high-risk artificial intelligence system" does not appear anywhere in the operative law.
The Seven Covered Domains
A consequential decision is one relating to a consumer's access to, eligibility for, selection for, or compensation for a covered domain, or to differentiated pricing or material terms that materially limit that access. C.R.S. 6-1-1701(6) lists seven covered domains.
| Covered Domain | Scope in the Statute |
|---|---|
| Education | An education enrollment or an education opportunity |
| Employment | Employment or an employment opportunity that creates or may create an employer-employee relationship |
| Housing | The lease or purchase of residential real estate in Colorado |
| Financial/Lending | A financial or lending service |
| Insurance | Underwriting, pricing, coverage, claims adjudication, or other determinations that materially affect access to benefits |
| Healthcare | Health-care services |
| Government Services | Essential government services and public benefits, including eligibility and renewal determinations |
The statute also carves out a long list of things that are not consequential decisions, including low-stakes or routine business processes, advertising and content moderation, spreadsheets requiring manual human analysis, systems that only summarize or organize information for human review, cybersecurity and fraud-prevention tooling, and sanctions and anti-money-laundering compliance.
Developer Duties (C.R.S. 6-1-1702)
On and after January 1, 2027, a developer must make available to each deployer of its covered ADMT a general statement of intended and known harmful uses, a description of the categories of data used to train the system, known limitations and risks, instructions for appropriate use and meaningful human review, and the information the deployer needs to meet its own disclosure duties. Developers must also notify deployers of material updates and substantial modifications, and must retain compliance records for at least three years.
Deployer Recordkeeping (C.R.S. 6-1-1703)
A deployer must retain records reasonably necessary to demonstrate compliance for at least three years after the date of a consequential decision. Those records may include covered ADMT version identifiers, changelogs, and documentation of material mitigation changes.
Deployer Disclosures (C.R.S. 6-1-1704)
This is the core of the act. Before using a covered ADMT to materially influence a consequential decision, a deployer must give the consumer clear and conspicuous notice that a covered ADMT was or will be used, plus instructions for obtaining more information. A deployer satisfies that duty by maintaining a prominent public notice that is reasonably accessible at points of consumer interaction, such as a link or posting reasonably proximate to the transaction.
If the decision results in an adverse outcome, the deployer must provide three things within thirty days after making the decision:
- A plain language description of the decision and the role the covered ADMT played in it
- Instructions and a simple process to request more information about the system and its inputs, including the system name, version number, developer, and the types, categories, and sources of personal data used
- An explanation of the consumer rights in C.R.S. 6-1-1705 and how to exercise them
Nothing in the section requires disclosure of a trade secret, but a deployer that withholds information must tell the consumer. Creditors that already provide Equal Credit Opportunity Act or Fair Credit Reporting Act notices may satisfy this section through those notices rather than issuing a duplicate one, and deployers subject to FERPA may use their existing FERPA notice channels for education decisions.
Consumer Rights (C.R.S. 6-1-1705)
When a consumer experiences an adverse outcome from a consequential decision that a covered ADMT materially influenced, the consumer may request, and the deployer must provide, instructions for requesting personal data and correcting factually incorrect or materially inaccurate personal data, and an opportunity for meaningful human review and reconsideration of the decision, to the extent commercially reasonable. The correction right does not extend to opinions, predictions, scores, or protected evaluations.
Enforcement (C.R.S. 6-1-1706 and 6-1-1709)
A violation of part 17 is a deceptive trade practice under the Colorado Consumer Protection Act, and the disclosure and consumer-rights provisions are enforceable exclusively by the Attorney General. Before bringing an enforcement action, the Attorney General must issue a notice of violation where a cure is deemed possible, and the developer or deployer gets sixty days to cure. That cure period is not required where the Attorney General can show a knowing or repeated violation. The act creates no new private right of action.
The Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements and the consumer-rights requirements on or before January 1, 2027, and must report annually on enforcement actions and cure periods beginning in January 2028.

The Repealed Colorado AI Act (SB 24-205)
Everything in this section describes a framework that was repealed before it ever became enforceable. It is preserved here because the CAIA is still widely cited in compliance guidance written between 2024 and 2026, and businesses need to know that none of it binds them.
The Colorado Artificial Intelligence Act was built around preventing algorithmic discrimination, defined as any condition where an AI system results in unlawful differential treatment based on protected characteristics such as age, race, color, ethnicity, sex, sexual orientation, gender identity, disability, religion, veteran status, or national origin.
The law would have focused on "high-risk artificial intelligence systems," which it defined as AI systems that make, or are a substantial factor in making, "consequential decisions."
What the CAIA Would Have Called a Consequential Decision
Under the repealed SB 24-205, a consequential decision was one with a material legal or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of, services in eight categories. The operative ADMT Act narrowed this list to seven and dropped legal services entirely.
| Category (Repealed SB 24-205) | In the Operative ADMT Act? |
|---|---|
| Education enrollment or opportunity | Yes |
| Employment or employment opportunity | Yes |
| Financial or lending service | Yes |
| Essential government service | Yes |
| Health-care services | Yes |
| Housing | Yes, narrowed to lease or purchase of residential real estate in Colorado |
| Insurance | Yes |
| Legal service | No, removed |
Developer Duties That Never Took Effect
The CAIA would have placed a duty of reasonable care on developers of high-risk AI systems. Developers would have had to provide deployers with a general statement describing reasonably foreseeable harmful uses and known risks of algorithmic discrimination, detailed documentation covering training data, system limitations, intended purposes, and discrimination testing methods, and any documentation deployers needed for their own impact assessments.
Those duties would not have been one-time requirements. A developer that discovered its high-risk AI system had caused or materially contributed to algorithmic discrimination would have had to notify the Colorado Attorney General and all known deployers within 90 days.
Deployer Duties That Never Took Effect
Deployer obligations under the CAIA would have been extensive, and they are the single biggest difference between the repealed act and the law that actually takes effect.
Deployers would have had to implement a risk management policy incorporating principles, processes, and personnel for identifying and mitigating discrimination risks. They would have had to complete an impact assessment for each high-risk AI system, at least annually and within 90 days of any intentional and substantial modification, covering the system's purpose and deployment context, an analysis of known or foreseeable discrimination risks, mitigation steps, data categories processed as inputs and outputs, transparency metrics, and post-deployment monitoring. Those assessments would have had to be retained for at least three years after final deployment and provided to the Attorney General on request within 90 days.
Deployers would also have owed consumers notice that an AI system was being used, a description of how it factored into the decision, an opportunity to correct incorrect personal information, and an opportunity to appeal an adverse decision. They would have had to review each deployed system annually and publish a public statement describing the high-risk systems they deploy. A deployer with fewer than 50 full-time employees could have qualified for reduced requirements under three conditions.
None of these obligations is in the operative ADMT Act. The ADMT Act has no risk management policy requirement, no impact assessment requirement, no annual review requirement, and no public-statement requirement. Its deployer duties are the recordkeeping, disclosure, and consumer-rights provisions described earlier.
The Repealed NIST Safe Harbor
The repealed SB 24-205 contained a safe harbor: compliance with the NIST AI Risk Management Framework, ISO/IEC 42001, or another nationally or internationally recognized AI risk management framework would have created a rebuttable presumption that a developer or deployer used reasonable care.
That safe harbor does not exist in Colorado law. SB 26-189 repealed and reenacted the entire part, and the operative text contains no reference to NIST, to ISO/IEC 42001, to reasonable care, to risk management frameworks, or to any rebuttable presumption. Because the ADMT Act imposes disclosure and consumer-rights duties rather than a duty of care, there is no standard of care for a framework to create a presumption about. A business building a Colorado compliance program around framework certification is preparing for a law that was repealed before it took effect.
Adopting the NIST AI RMF or ISO/IEC 42001 may still be sound governance practice and may matter under other states' laws or customer contracts, but in Colorado it carries no statutory legal effect.
Enforcement Under the Repealed AI Act
Under the CAIA, the Colorado Attorney General would have had exclusive enforcement authority and rulemaking power in six areas. Violations would have been treated as unfair trade practices under the Colorado Consumer Protection Act. The act would not have created a private right of action, and developers and deployers would have had an affirmative defense for violations discovered through feedback, testing, or internal review and promptly cured.
The operative ADMT Act keeps exclusive Attorney General enforcement and the deceptive-trade-practice framing, and keeps the absence of a private right of action, but replaces the affirmative defense with the sixty-day right to cure described above.
Enforcement Timeline
| Date | Event |
|---|---|
| May 17, 2024 | Governor Polis signs SB 24-205 into law |
| August 28, 2025 | Governor signs SB 25B-004, delaying enforcement to June 30, 2026 |
| May 14, 2026 | Governor Polis signs SB 26-189, repealing and reenacting the law as the narrower ADMT Act |
| January 1, 2027 | ADMT Act obligations take effect |
The Delays and Repeal
The original effective date was February 1, 2026. However, Governor Polis called a special legislative session in August 2025 to address concerns about the law. Lawmakers were unable to reach a compromise on substantive amendments, so they instead passed SB 25B-004, which delayed the effective date by five months to June 30, 2026.
That June 30, 2026 date never arrived either. During the 2026 regular session, the legislature passed Senate Bill 26-189, which Governor Polis signed on May 14, 2026. SB 26-189 repeals and reenacts part 17 of article 1 of title 6 in its entirety, replacing the CAIA with the Colorado Automated Decision-Making Technology Act. The new law eliminates the duty-of-care standard, mandatory risk management programs, and annual impact assessments, replacing them with consumer-notice and disclosure obligations covering seven covered domains. Because SB 24-205 was repealed before its enforcement date ever arrived, none of its duty-of-care, risk-management, or impact-assessment provisions ever became legally operative.
Proposed Amendments (SB 25-318)
During the 2025 regular session, SB 25-318 was introduced to modify the CAIA's requirements. The bill would have adjusted the risk management program requirements, modified impact assessment obligations, and refined consumer notification provisions. However, SB 25-318 did not pass during the regular session. The following year, similar goals were achieved a different way: SB 26-189 repealed and replaced the CAIA outright rather than amending it (see The Delays and Repeal, above).
Election Deepfake Law (HB 24-1147)
Colorado enacted the Candidate Election Deepfake Disclosures Act (HB 24-1147) on May 24, 2024. The law took effect on July 1, 2024 and is codified at C.R.S. 1-46-101 to 1-46-106. It applies to communications distributed on or after July 1, 2024.
Disclosure Requirements
The law requires clear disclaimers on communications that have been generated or substantially altered by AI and that falsely depict what a candidate or elected official has said or done. The required disclosure statement reads: "This [image/audio/video/multimedia] has been edited and depicts speech or conduct that falsely appears to be authentic or truthful."
C.R.S. 1-46-103(2) sets formatting and placement standards. In a visual communication, the disclosure must appear in a font no smaller than the largest font used elsewhere in the communication. In an audio communication, it must be read in the same pitch, speed, language, and volume as the majority of the audio, at the beginning and end, and at intervals of no more than one minute if the audio runs longer than two minutes. The communication's metadata must include the disclosure statement, the identity of the tool used to create the deepfake, and the date and time it was created, and the disclosure must be permanent or not easily removable to the extent technically feasible.
Penalties
Communications that fail to include proper disclaimers are subject to civil penalties. A hearing officer must impose a penalty of at least $100 for each violation that does not involve paid advertising or other promotional spending. Where there was paid advertising, the penalty is at least 10% of the amount paid or spent to advertise, promote, or attract attention to the communication. In either case the hearing officer may impose a higher amount based on the degree of distribution and public exposure.
Private Right of Action
Unlike the AI Act, the deepfake disclosure law does create a private right of action (C.R.S. 1-46-105). A candidate who is the subject of a communication with an undisclosed or improperly disclosed deepfake may bring a civil action for injunctive or equitable relief, compensatory damages, punitive damages, or both.

Intimate Digital Depictions (SB 25-288)
Governor Polis signed SB 25-288 into law on June 2, 2025. The act creates the Preventing Unauthorized Disclosure of Intimate Digital Depictions Act, codified at C.R.S. 13-21-1501 to 13-21-1507, and amends Colorado's criminal statutes at C.R.S. 18-7-107 to 18-7-109 to cover AI-generated and digitally altered imagery.
What the Law Covers
An "intimate digital depiction" is a digitally created or altered image that appears to show an identifiable individual. The criminal provisions reach disclosing, or threatening to disclose, a private intimate image or intimate digital depiction without the depicted individual's consent, rather than the act of creating one. Separate provisions at C.R.S. 18-7-108 and 18-7-109 address disclosure for pecuniary gain and disclosure, possession, or exchange by a juvenile.
Penalties
| Violation | Penalty |
|---|---|
| Disclosing or threatening to disclose a private intimate image or intimate digital depiction for harassment (C.R.S. 18-7-107) | Class 1 misdemeanor, or a class 6 felony where the disclosure posed an imminent and serious threat to the depicted individual's safety or that of their immediate family |
| Additional fine on conviction (C.R.S. 18-7-107(1)(c)) | Up to $10,000, credited to the crime victim compensation fund |
| Civil remedies for victims (C.R.S. 13-21-1506) | The defendant's monetary gain, plus the greater of actual damages or liquidated damages of $150,000, plus exemplary damages and reasonable attorney fees |
The civil cause of action gives victims a direct legal remedy without relying on law enforcement or the Attorney General's office, and a court may also order a temporary restraining order, preliminary injunction, or permanent injunction requiring the defendant to stop disclosing the depiction.
Context
The law closed a gap in Colorado's existing nonconsensual pornography statutes, which had not previously covered AI-generated or digitally altered material.

Federal AI Policy and Colorado
Colorado's AI legislation makes it a recurring reference point in the federal government's efforts to establish AI policy uniformity.
Executive Order 14365
On December 11, 2025, President Trump issued Executive Order 14365, directing the Department of Justice to establish an AI Litigation Task Force to challenge state AI laws. The order specifically targets state laws that the administration believes may obstruct national AI policy.
Impact on Colorado's AI Laws
Colorado's AI laws could face federal scrutiny under several theories. The AI Litigation Task Force could challenge them as an unconstitutional regulation of interstate commerce, arguing that they burden AI companies operating nationally. The executive order also ties certain federal funding to state compliance with federal AI policy goals.
However, the executive order has significant limitations. Federal preemption typically requires congressional action, not executive orders. The order also carves out child safety protections and state government AI procurement from potential preemption. These carve-outs could protect Colorado's deepfake laws.
On March 20, 2026, the Trump Administration released its "National Policy Framework for Artificial Intelligence," calling on Congress to pass federal AI legislation. If Congress acts, Colorado's ADMT Act could face preemption challenges before or after its January 1, 2027 effective date.
Governor Polis's Position
Governor Polis expressed concerns about the burden the original CAIA would place on businesses, which aligned with some of the federal administration's concerns about state-level AI regulation. Rather than let those obligations take effect, Colorado repealed and reenacted the law through SB 26-189 in May 2026, narrowing it to a disclosure-based ADMT framework while preserving core consumer-notice protections.
Summary of Colorado AI Laws
| Law | Codified At | Subject | Status |
|---|---|---|---|
| SB 24-205 | Former C.R.S. 6-1-1701 et seq. | Comprehensive AI consumer protection | Repealed and reenacted by SB 26-189 (never took effect) |
| HB 24-1147 | C.R.S. 1-46-101 to 1-46-106 | Election deepfake disclosures | In effect (July 1, 2024) |
| SB 25B-004 | n/a (delay bill) | AI Act enforcement delay | Signed Aug. 28, 2025 |
| SB 25-288 | C.R.S. 13-21-1501 to 1507; 18-7-107 to 18-7-109 | Intimate digital depictions | In effect (2025) |
| SB 25-318 | n/a (failed) | AI Act amendments | Did not pass |
| SB 26-189 | C.R.S. 6-1-1701 to 6-1-1709 | Automated Decision-Making Technology (ADMT) Act, repeal and replace of SB 24-205 | Effective January 1, 2027 |
More Colorado Laws
Frequently Asked Questions
Does Colorado have an AI law in effect right now?
Not a comprehensive one. The Colorado AI Act (SB 24-205) was signed on May 17, 2024 but was repealed before its enforcement date ever arrived. Its replacement, the Automated Decision-Making Technology (ADMT) Act at C.R.S. 6-1-1701 to 6-1-1709, was signed on May 14, 2026 and takes effect January 1, 2027, applying to consequential decisions made on or after that date. Two narrower Colorado AI laws are already in force: the election deepfake disclosure law (C.R.S. 1-46-101 to 1-46-106) and the intimate digital depictions laws (C.R.S. 18-7-107 to 18-7-109 and 13-21-1501 to 13-21-1507).
What is a covered ADMT under Colorado law?
A covered ADMT is automated decision-making technology that is used to materially influence a consequential decision (C.R.S. 6-1-1701(5)). A consequential decision is one relating to a consumer's access to, eligibility for, selection for, or compensation for one of seven covered domains listed in C.R.S. 6-1-1701(6): education, employment, the lease or purchase of residential real estate in Colorado, financial or lending services, insurance, health-care services, and essential government services and public benefits. Legal services is not a covered domain. The term 'high-risk AI system' came from the repealed SB 24-205 and does not appear in the operative law.
Is there a NIST or ISO 42001 safe harbor under Colorado AI law?
No. The rebuttable presumption of reasonable care for businesses following the NIST AI Risk Management Framework or ISO/IEC 42001 was a provision of SB 24-205, which was repealed before it took effect. The operative ADMT Act contains no reference to NIST, ISO/IEC 42001, reasonable care, risk management frameworks, or any rebuttable presumption. It imposes disclosure and consumer-rights duties instead of a duty of care, so there is no standard of care for framework compliance to create a presumption about.
What will Colorado businesses actually have to do on January 1, 2027?
Deployers must give consumers a clear and conspicuous notice before using a covered ADMT to materially influence a consequential decision, which can be satisfied with a prominent public notice at points of consumer interaction. If the decision produces an adverse outcome, the deployer must provide a plain language explanation of the decision and the system's role, instructions for requesting more information, and an explanation of consumer rights, all within thirty days (C.R.S. 6-1-1704). Consumers may request correction of inaccurate personal data and an opportunity for meaningful human review and reconsideration (C.R.S. 6-1-1705). Deployers must keep compliance records for at least three years, and developers owe documentation to their deployers (C.R.S. 6-1-1702, 6-1-1703). The Attorney General enforces the act exclusively, with a sixty-day right to cure, and the act creates no new private right of action.
What are the penalties for election deepfakes in Colorado?
Under HB 24-1147 (C.R.S. 1-46-101 to 1-46-106, effective July 1, 2024), communications featuring undisclosed AI-generated deepfakes of candidates face civil penalties of at least $100 per violation where no paid advertising was involved, or at least 10% of the amount paid or spent to advertise the communication where there was. A hearing officer may impose a higher amount based on the degree of distribution and public exposure. Candidates depicted in deepfakes also have a private right of action for injunctive relief, compensatory damages, and punitive damages.
Is AI-generated intimate imagery illegal in Colorado?
Yes. SB 25-288, signed June 2, 2025, makes it a crime to disclose, or threaten to disclose, a private intimate image or intimate digital depiction of someone without their consent (C.R.S. 18-7-107). The base offense is a class 1 misdemeanor, rising to a class 6 felony where the disclosure posed an imminent and serious threat to the depicted individual's safety or that of their immediate family, plus a fine of up to $10,000. The act also creates a civil cause of action at C.R.S. 13-21-1501 to 13-21-1507 under which a prevailing plaintiff may recover the defendant's monetary gain, the greater of actual damages or liquidated damages of $150,000, exemplary damages, and attorney fees.
Updates
Corrected this page to reflect the operative Colorado Automated Decision-Making Technology Act (C.R.S. 6-1-1701 to 6-1-1709): removed a NIST and ISO/IEC 42001 safe harbor and a repealed eight-category list that were presented as current law, added what the ADMT Act actually requires, and added codified statute citations throughout.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Updated Colorado AI Act coverage: SB 24-205 was repealed and replaced by SB 26-189 (2026) before taking effect.
Corrected: the original Colorado AI Act (SB 24-205) was repealed and reenacted by SB 26-189 (signed May 14, 2026) as a narrower Automated Decision-Making Technology Act, now effective January 1, 2027, not June 30, 2026.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Colorado Revised Statutes, Title 6 (Consumer and Commercial Affairs), Article 1, Part 17: Automated Decision-Making Technology in Consequential Decisions
§ 6-1-1704Deployer disclosures - point-of-interaction notice - public posting option - post-adverse outcome disclosures - legislative declaration - trade secrets - compliance with other law - accessibility - rulesIn force
6-1-1704. Deployer disclosures - point-of-interaction notice - public posting option - post-adverse outcome disclosures - legislative declaration - trade secrets - compliance with other law - accessibility - rules. (1) PRIOR TO A DEPLOYER USING A COVERED ADMT TO MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION, THE DEPLOYER SHALL PROVIDE A CLEAR AND CONSPICUOUS NOTICE TO A CONSUMER THAT THE DEPLOYER USED OR WILL USE A COVERED ADMT IN A CONSEQUENTIAL DECISION AFFECTING THE CONSUMER AND INSTRUCTIONS REGARDING HOW THE CONSUMER MAY OBTAIN THE ADDITIONAL INFORMATION DESCRIBED IN THIS SECTION. (2) A DEPLOYER COMPLIES WITH SUBSECTION (1) OF THIS SECTION BY MAINTAINING A PROMINENT PUBLIC NOTICE THAT IS REASONABLY ACCESSIBLE AT POINTS OF CONSUMER INTERACTION, INCLUDING THROUGH A LINK OR POSTING THAT
Official text (excerpt) · last checked 2026-09-03 · Read the full text in our law library · Verify at leg.colorado.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- SB 24-205 Consumer Protections for Artificial Intelligence(leg.colorado.gov).gov
- SB 24-205 Signed Text(content.leg.colorado.gov).gov
- HB 24-1147 Candidate Election Deepfake Disclosures(leg.colorado.gov).gov
- Colorado Secretary of State Deepfakes Press Release(coloradosos.gov).gov
- NAAG Deep Dive into Colorado AI Act(naag.org)
- FPF Policy Brief: The Colorado AI Act(content.leg.colorado.gov).gov
- CDT FAQ on Colorado AI Act (SB 24-205)(cdt.org)
- Executive Order on AI National Policy Framework(whitehouse.gov).gov
- Colorado SB 25-288 Intimate Deepfake Protections(content.leg.colorado.gov).gov
- NIST AI Risk Management Framework(nist.gov).gov
- SB 26-189 Colorado ADMT Act (repeals and reenacts SB 24-205)(leg.colorado.gov).gov
- Colorado SB 26-189 enrolled act, Automated Decision-Making Technology in Consequential Decisions (C.R.S. 6-1-1701 to 6-1-1709)(leg.colorado.gov)
- Colorado HB 24-1147 signed act, Candidate Election Deepfake Disclosures (C.R.S. 1-46-101 to 1-46-106)(leg.colorado.gov)
- Colorado SB 25-288 signed act, Intimate Digital Depictions Criminal and Civil Actions (C.R.S. 13-21-1501 to 13-21-1507; 18-7-107 to 18-7-109)(leg.colorado.gov)