What to Ask Your AI Vendor Before January 2027

The vendor information gap: the deployer owes the disclosure, the vendor holds the explanation, and the contract is the bridge
← Colorado AI Compliance

SB 26-189 requires you to describe, in plain language, the role the technology played in an adverse decision. You do not have that information. Your vendor does.

That gap is the most underestimated part of Colorado AI compliance, because it cannot be closed by writing a better policy. It requires another company to agree to something, and that takes months.

Why the duty lands on you

Deployer obligations attach to the business deploying the technology, not to the developer that built it. Licensing software does not transfer the duty. If a hiring platform ranks your applicants, the notice obligation is yours.

What licensing does create is a dependency. You owe a disclosure whose content sits inside somebody else’s system, and your only route to it is your contract.

What standard terms give you, which is not much

Most SaaS agreements were drafted before any of this existed. Typically they give the vendor broad discretion to change features, disclaim warranties about outputs, treat the methodology as a trade secret, and say nothing about supporting your regulatory obligations. Some go further and prohibit you from disclosing details about how the system works, which sits badly against a statute requiring you to describe exactly that.

None of that is bad faith. It is what contracts drafted for a world without SB 26-189 look like. It still leaves you unable to comply.

What to ask for

Explainability you can actually use. Commit the vendor to provide, per decision, enough about what the system did that you can describe it in plain language. Not model architecture. The functional account: what was evaluated, what was produced, how it factored in. Tie it to your 30-day clock, so a response arriving in six weeks does not count.

Access to the personal data used. Consumers can request correction of data that is factually incorrect or materially inaccurate. You need to see what data the system used and to get corrections pushed back through.

Support for human review. Your reviewer needs visibility into the output and the ability to override it. Some platforms have no override path at all. Better to learn that in negotiation than from a consumer request.

Notice of material changes. If the vendor changes the scoring model, your notices may become inaccurate. Ask for advance notice of changes affecting how outputs are generated.

A carve-out from confidentiality. Make explicit that you may disclose what SB 26-189 requires without breaching the agreement. Small clause, and it removes a real conflict.

Cooperation with an inquiry. The Attorney General’s 60-day cure period is not much time if you are waiting on a vendor. Commit them to respond on a defined timeline.

Allocation of responsibility. If you cannot comply because the vendor did not deliver, that should have a consequence. Indemnity is the aggressive version. A termination right for failure to provide compliance support is often more achievable and more useful.

Bargaining position, and how to find some

Against this background, a small Colorado business is not rewriting a major platform’s standard terms. That is worth being honest about.

What you do have is renewal timing and the fact that you are not alone. Colorado is not the only state moving here, and vendors are being asked the same questions by many customers at once. A vendor that has already built a compliance addendum will hand it over if asked. Many have. Ask before assuming they have not.

Renewal is the moment you have the most to work with. Map which agreements renew before January 2027, and raise it then rather than mid-term when the vendor has no reason to move.

If a vendor will not commit to anything, that is information. A tool you cannot lawfully deploy is a tool to replace, and finding that out in September beats finding out in December.

What to do this quarter

  • List every tool that scores, ranks, or classifies people in a consequential decision
  • Pull each agreement and find the clauses on outputs, confidentiality, changes, and support
  • Note renewal dates and flag anything renewing before January 1, 2027
  • Send each vendor the same written question: what will you give me so I can describe your system’s role in an adverse decision within 30 days?
  • Track who answers well, who answers slowly, and who does not answer

That last list tends to make the replace-or-keep decision for you.

Simply put, this is commercial contract work aimed at a new requirement. For what the notices have to contain, see the notice requirements article, and for whether you are in scope, start here. If you would like someone to read your agreements with this in mind, I am glad to take a look.

Common questions

Why do AI vendor contracts matter for Colorado SB 26-189 compliance?

Because the adverse outcome notice must describe in plain language the role the technology played in the decision, and that information lives with the vendor rather than the deployer. The obligation is the deployer’s, but the information is the vendor’s, so the contract is the only route to it.

What should Colorado businesses ask AI vendors for?

Per-decision explainability delivered inside the 30-day notice window, access to the personal data the system used and a path to push corrections through, support for meaningful human review including an override capability, advance notice of material changes to the model, an explicit carve-out from confidentiality for disclosures the statute requires, cooperation on a defined timeline during an Attorney General inquiry, and allocation of responsibility if the vendor fails to provide compliance support.

Does my vendor’s compliance cover my business?

No. Deployer obligations attach to the business deploying the technology. Licensing software does not transfer them. Vendor disclosures are what enable you to meet your own duties, but the duties remain yours.

What if an AI vendor refuses to provide compliance support?

That is a signal worth acting on. A tool you cannot lawfully deploy in Colorado is a tool to replace, and discovering that early leaves time to find an alternative. Renewal is when a vendor has the most reason to accommodate you, so businesses should map which agreements renew before January 1, 2027 and raise the question then.

Do standard SaaS terms address Colorado AI law requirements?

Usually not. Most were drafted before SB 26-189 existed. They commonly give the vendor discretion to change features, disclaim warranties about outputs, treat methodology as a trade secret, and say nothing about supporting a customer’s regulatory obligations. Some restrict disclosure of how the system works, which conflicts with a statute requiring the deployer to describe it.

Regulatory status as of August 18, 2026

The Colorado Attorney General has filed proposed rules under SB 26-189. They are not final.

The Colorado Department of Law filed proposed Automated Decision-Making Technology and Chatbot Safety rules, 4 CCR 904-6, with the Secretary of State on August 11, 2026. Written comment is open through October 26, 2026, and comment received by September 4, 2026 will be considered for a revised draft the Department expects to publish on September 23. A rulemaking hearing is set for October 26, 2026. The rules are scheduled to take effect January 1, 2027, alongside the statutes.

The proposed rules add obligations the statute alone does not state, particularly around what an adverse outcome notice must contain and what meaningful human review requires. They also leave “materially influence,” the term that decides who is covered, undefined. Treat this page as the current baseline rather than a final answer, and see Colorado’s proposed ADMT rules.

General information, not legal advice. No attorney-client relationship is created by reading this page.