Skip to content
SATURDAY, AUGUST 1, 2026
Policy & Governance

Colorado starts rulemaking on two new AI laws as compliance deadlines come into view

By Jordan Vale5 min read
colorado,state,usa,map,glowing,silhouette,outline,made,of,stars

Image / fpf.org

The state’s Department of Justice has opened pre-rulemaking for laws on automated decision-making technology and chatbots, setting up a 2027 compliance runway for companies that build or deploy AI tools in Colorado.

Colorado moves from AI lawmaking to implementation

Colorado is now working through the next stage of its AI policy agenda: turning two recently enacted laws into workable rules.

On July 13, the Future of Privacy Forum said it submitted comments to the Colorado Department of Justice’s pre-rulemaking process for the Colorado Automated Decision-Making Act, SB 189, and the Chatbot Safety Act, HB 1263. The group said the rules should clarify compliance ambiguities and align with existing state and federal privacy frameworks.

For technology leaders and compliance teams, that shift matters because the hard part is no longer just what the statutes say on paper. The state is now asking how those obligations will apply in practice, what the key terms mean, and where the law overlaps with Colorado’s privacy regime.

Automated decision-making rules will shape notice, documentation, and human review

The Colorado Automated Decision-Making Act, enacted in 2026, repealed and replaced the Colorado AI Act after revisions recommended by the Colorado AI Policy Working Group convened by Governor Polis.

As amended, the law creates three core obligations for covered automated decision-making technology, or ADMT. Developers must keep documentation when the technology is marketed or advertised to materially influence a consequential decision. Deployers must provide notice and specific post-adverse-outcome disclosures when the technology is used to make a consequential decision. And consumers get rights to access and correct personal data used in an adverse consequential decision, along with an opportunity for meaningful human review.

Those obligations do not take effect immediately. The law takes effect Jan. 1, 2027, and the Department has opened pre-rulemaking to gather stakeholder input on rules that will clarify and implement the requirements.

FPF urged the Department to focus on three areas: aligning the scope and definition of automated decision-making technology; clarifying transparency obligations so companies can comply under both the Automated Decision-Making Act and the Colorado Privacy Act; and streamlining consumer rights.

That is the practical pressure point for companies: the same AI system may trigger both privacy and automated decision-making duties. FPF’s comments reflect a concern that the state should reduce friction between the two regimes rather than create duplicative or conflicting workflows.

Chatbot Safety Act sets tiered deadlines and new restrictions for conversational AI

Colorado’s second AI law, HB 1263, regulates “conversational AI services.” It requires operators to implement age estimation and offer tools for minors or parents to adjust privacy and account settings. It also bans engagement-based rewards targeted at minors, requires disclosure that the service is AI rather than human, and prohibits the system from producing sexual content, simulating emotional dependence, or engaging in sexually explicit interactions with minors.

The timing here is more complicated. The law as a whole takes effect Aug. 12, 2026. The substantive operator obligations take effect Jan. 1, 2027. Annual reporting requirements begin July 1, 2027.

That staggered schedule gives companies a short window to identify whether their products fall within the law’s scope and then map the operational changes needed before the 2027 obligations arrive.

The Department’s pre-rulemaking questions indicate where it wants clarity: the law’s scope and key terms, age estimation requirements, and protocols for suicidal ideation and self-harm, among other topics.

FPF said it recommended that the Department clarify key exemptions and terms, including the exemption for services limited to a “narrow and discrete topic”; ensure age estimation rules are flexible and interoperable with the recently enacted Digital Age Assurance Act; and specify rules on how suicide and self-harm crisis intervention protocols should be created and implemented.

For product teams, those issues are not academic. They determine whether a service is covered, what safeguards it must build, and whether safety measures need to be designed into the product before launch or retrofitted later.

What companies should watch now

The current phase is rulemaking, not enforcement, but the deadlines are already on the calendar.

For ADMT, Jan. 1, 2027 is the key date for the law’s obligations to kick in. For chatbot operators, the law itself takes effect Aug. 12, 2026, with most substantive duties starting Jan. 1, 2027 and annual reporting beginning July 1, 2027.

That means compliance teams should already be pressure-testing whether their systems are “covered” under either law, what notices and disclosures they provide, how they handle consumer access and correction requests, and whether human review processes are actually meaningful in adverse decision scenarios.

For chatbot operators, the higher-risk areas are age assurance, minor protections, and crisis-response protocols. For automated decision-making systems, the biggest questions are documentation, transparency, and how to reconcile the new requirements with existing privacy obligations.

Colorado’s approach reflects a broader policy trend: states are trying to put concrete guardrails around AI without forcing every system into the same mold. But that approach only works if the implementing rules are clear enough for companies to build toward them.

Why the rulemaking matters beyond Colorado

Colorado’s two laws take different paths, but together they signal how regulators are thinking about AI harms: one law targets consequential decisions made with automated systems, while the other focuses on the risks of conversational AI, especially for minors.

That distinction matters because it suggests companies may need separate compliance tracks for decision-support tools and consumer-facing chatbots, even when the underlying model stack overlaps.

FPF’s comments point to a familiar regulatory challenge: laws written to address distinct harms can still collide inside a single product organization. A company may have to manage privacy rights, human review processes, age estimation, safety controls, and crisis protocols across the same platform.

The immediate next step is the Department’s rulemaking. The real business impact will depend on how the state defines scope, sets thresholds, and interprets exemptions. But the deadlines are already fixed, and the practical message is clear: Colorado companies building or deploying covered AI tools need to treat 2027 as a live implementation date, not a distant one.

Sources & methodology

Newsletter

The Robotics Briefing

A daily front-page digest delivered around noon Central Time, with the strongest headlines linked straight into the full stories.

No spam. Unsubscribe anytime. Read our privacy policy for details.