Colorado’s ADMT Rules Are Drafted. Here Is What SB 26-189 Would Require.

Photograph by Michael Hoog
← Colorado AI Compliance

On August 11, 2026 the Colorado Department of Law filed proposed rules for the Automated Decision-Making Technology Act and the Chatbot Safety Act. Fourteen rules, one combined rulemaking, codified at 4 CCR 904-6. They are scheduled to take effect January 1, 2027, the same day the statutes do.

The June considerations paper asked questions. This is the answer, in draft.

It is worth saying plainly what the draft does, because the framing around SB 26-189 has been that Colorado backed off. The 2026 statute dropped the impact assessments, the risk management program, and the duty of reasonable care that made SB 24-205 so unpopular. Read the proposed rules and a good deal of that operational weight comes back, routed through what your notices have to contain, what you have to be able to explain, and what human review now requires you to staff and document.

Where the process actually stands

Three documents went to the Secretary of State on August 11: the proposed rules, a notice of rulemaking hearing, and a statement of basis and purpose. All three sit on the Attorney General’s rulemaking page at coag.gov/ai. Read all three. The most consequential material in this rulemaking is not in the rules document at all: the two competing definitions of “materially influence,” the term that decides who is covered, appear only in the notice of hearing. Anyone who downloads the proposed rules and stops there will miss the open question that matters most.

The dates that matter:

  • September 4, 2026. The deadline to submit written comment and have it considered for the revised draft.
  • September 23, 2026. The Department publishes any revised draft rules and sends them to the rulemaking mailing list.
  • October 5, 2026. The deadline to comment and have it presented at the hearing.
  • October 26, 2026. The rulemaking hearing, 10:00 AM, in person at 1300 Broadway in Denver and by video. Written comments close at 11:59 PM that night.
  • January 1, 2027. Rules and statutes take effect together.

September 4 is the one to circle. Comments after that date still land in the official record, and the record is public, but only comments received by September 4 get considered for the draft that circulates on September 23. If your goal is to change rule text rather than to build a record, that window is about two weeks wide.

The definition that decides who is covered is still blank

The Act reaches ADMT used to materially influence a consequential decision. That phrase is the whole coverage test. The proposed rules do not define it.

Instead the notice sets out two competing standards and asks the public which one to adopt. The difference is not academic.

Under the first, a factor is outside the Act only if its impact is “trifling, trivial, or incidental,” and the notice adds that a factor is not trivial simply because other factors mattered more. Under the second, a factor can fall outside the Act if other information, independent of the software, played a significantly larger role in the decision.

The first version pulls in almost any tool whose output a human looked at. The second leaves room for a business to say that a person did the real analysis and the software was a data point. For a company running a screening tool alongside genuine human evaluation, that is the difference between being regulated and not.

Both versions carry the same presumption. If the output pertains to the individual being decided about, was reviewed by the decision-maker or used to screen what the decision-maker ever saw, and is consistent with the outcome, it is presumed to materially influence the decision. You can rebut that presumption, but the burden is yours.

A business that is confident today about whether it is covered is confident about a definition the regulator has not written.

The adverse outcome notice got specific

Rule 6 is the longest rule in the draft and the one most likely to change how you operate. The notice requirements under the statute were general. The proposed rule is not.

Within thirty days of an adverse decision, the notice has to go out in writing through at least two channels you normally use with that person, and electronically if you have any online presence at all. Printed notices cannot be set smaller than 12-point type. Beyond form, the content requirements are where the work sits:

  • Name the decision in plain language. The draft’s own example is “Bank ABC closed your checking account.”
  • State the principal reasons with specificity. The rule says outright that pointing to your internal standards or policies is insufficient.
  • Explain any inference. If the outcome rested on a conclusion the person never stated, such as socioeconomic status read off employment history and geography, you have to name the inference and identify the data that produced it.
  • Disclose the score. Not that a score was used. The number. The draft uses a risk score of 82 out of 100 as its illustration.
  • Name automatic denial factors. If a credit score below a threshold ended the analysis, say so.
  • Say what was missing. If the outcome turned on incomplete information, the notice has to identify what you would have needed.
  • Identify your data sources by name. Specific brokers, databases, courts, schools. If you bought data from an aggregator, the original source too.

Two sentences in Rule 6.4 deserve more attention than the rest of the rule combined. A deployer does not comply if it cannot explain how the technology influenced the decision. A deployer does not comply if it cannot accurately explain the principal reasons for the outcome.

That converts explainability from a good practice into a compliance obligation. A tool your vendor will not explain to you is a tool you cannot lawfully use for consequential decisions, and no amount of careful drafting at the notice stage fixes it. That is a vendor contract problem, and it has a long lead time.

There is relief worth knowing about. If you already send an adverse action notice under the Equal Credit Opportunity Act or the Fair Credit Reporting Act, that notice can satisfy the rule, provided it carries the additional content and goes out within thirty days. Schools operating under FERPA can use their existing FERPA channels. For employers running background checks, this matters: the pipeline may already exist even if the content does not.

Human review became a staffed process

The statute gives a consumer the right to meaningful human review of an adverse decision, to the extent commercially reasonable. Rule 7.7 fills in what that means, and the answer is more than most businesses have today.

The reviewer has to be independent of the original decision-maker and not that person’s subordinate, wherever feasible. The reviewer needs subject matter understanding proportional to the harm at issue, plus documented training. The reviewer must have real authority to overturn the decision, cannot be steered by management, and has to be shielded from retaliation. Automated technology may not assist in the review.

You then have ten days to acknowledge the request and forty-five to decide, with reasons tied to the evidence the person gave you rather than a recital of how the model works. Where possible, the adverse outcome is supposed to be stayed while the review runs.

And you have to keep a record of six things for every review: who the reviewer was, their authority and training, timestamps, what evidence was in front of them, whether they approved or overrode the output, and a written justification for the call.

That is a case management system, not a mailbox.

Can you ever decline to provide review?

Yes, and this is worth understanding precisely, because the structure is easy to read backwards.

The right itself is qualified. The statute grants review “to the extent commercially reasonable,” so the argument exists in every case. Rule 7.7 sets out seven factors to weigh together, with no single one decisive: the type of review required, the magnitude of harm, the reversibility of the outcome, the value of reviewing the available evidence, your size and capacity, the marginal cost and technical feasibility, and whether qualified reviewers are available.

Where the harm is a severe and irreversible denial of a basic human need, review is presumed commercially reasonable, and the only ways out are proving it technically or financially impossible or proving it could not have changed the outcome.

Here is the part that gets misread. The presumption is not what creates your ability to argue. The presumption is what takes that ability away in the worst cases. In every case, including ordinary ones, the rule puts the burden on the deployer to demonstrate that review is not commercially reasonable, using specific evidence. Silence is not a defense anywhere on the spectrum.

One more thing about that phrase. Neither the statute nor the proposed rules define “basic human need.” The only worked examples in the draft treat denial of housing as one. Utilities, government benefits, and access to healthcare are the obvious candidates, and none of them are confirmed. That is a clean, concrete thing for a Colorado business to ask the Department to fix.

If a vendor runs the tool, who owes the notice?

This is the question I would most like answered, and the Department is asking it too.

Say you are an employer who uses no AI at all. You hire a staffing agency to run prequalification, and the agency uses automated screening to decide who reaches you. Do the disclosure obligations roll up to you as the principal, or stay with the agency that operates the software and talks to the applicants?

The notice puts that exact hypothetical to the public and concedes the gap: the Act “does not explicitly contemplate scenarios in which Deployers do not directly operate the ADMT that Materially Influences their Consequential Decisions.” The Department asks whether it should define “ADMT vendor,” whether deployers should be responsible for all obligations regardless, whether vendors should carry duties similar to processor obligations under the Colorado Privacy Act, and whether there are cases where the vendor should issue the notices directly.

The draft does contain one signal. In the insurance example under Rule 6.5, a third party claims administrator hired by an insurer operates the technology and is the sole basis for denying a claim, and the rule says the insurance provider must provide the adverse outcome notice. The duty lands on the principal, not the operator. That is one sector illustration rather than a general allocation rule, but it is the only place in the filed text where the Department resolves facts like these, and it resolves them against the company that outsourced the work.

Until the rules say otherwise, the safe assumption is that it is your obligation. You cannot satisfy it without information only your vendor holds: the score, the principal reasons, the data sources, the version of the tool. Ask for those now. If your agency’s own screener made the original call, ask who is going to serve as the independent reviewer, because it probably cannot be them.

The chatbot rules ride along

Rules 8 through 13 implement House Bill 26-1263, the Chatbot Safety Act, and they are more demanding than the statute reads.

Age estimation cannot rest on asking, and cannot require government identification as the only route. Operators have to use device and app store signals without ignoring contradicting evidence, reassess when new signals appear, and detect falsified information. An inconclusive result cannot support a conclusion that the user is an adult.

Disclosure for minors has to be a persistent visible disclaimer, no smaller than the largest text on the screen, with no scrolling or hovering required. For adults it appears at the first interaction each day and at least every three hours in a continuing conversation, and any time the user asks whether they are talking to a person.

Engagement mechanics aimed at minors are out: streaks, badges, leaderboards, spin the wheel, and unlocking features by time spent. Minor accounts default to the most protective settings, with no memory of past sessions and no training on their data unless someone changes it. Operators cannot let a bot present itself as a therapist, doctor, lawyer, or dietitian. And there is an annual report due to the Attorney General by July 1, 2027, with crisis referral numbers, age distribution data, and protocol descriptions the Department can demand backup for on thirty days’ notice.

Most Colorado small businesses are not operators under this Act. If you deploy a customer service bot that handles billing questions or appointment scheduling and cannot discuss self harm or produce sexual content, Rule 8 likely exempts you. Read Rule 8 before assuming it does.

What to do between now and September 4

  • Find out whether you can explain your tools. Not whether you like them. Whether you can state, for a specific decision about a specific person, what the output was and what drove it. If the answer is no, that is now a compliance defect rather than a technical annoyance.
  • Ask your vendors for the Rule 5 package. Intended uses, known limitations, known inappropriate uses, training data categories, monitoring instructions, and how to determine the primary factors behind a specific output. Developers may withhold genuine trade secrets, but they have to state the legal basis and still satisfy the statute another way.
  • Decide who your reviewer is. A named person, independent of the original decision, with authority to reverse it and training you can document. This is the requirement most businesses do not have and cannot improvise in December.
  • Comment. The portal is at comments.coag.gov. The Department asked direct questions about the coverage definition, about vendor and staffing arrangements, and about developer disclosures. Small and mid-sized businesses almost never file comments, which is exactly why the ones that do get read.

None of the underlying work is wasted if the rules change. Your inventory of tools, your designated reviewer, your recordkeeping, and your vendor agreements are required under any version of these rules. If you are not sure where your business sits, start with the coverage question or work through the SB 26-189 compliance checklist. And if you would rather talk it through than read your way to an answer, I would welcome the conversation.

Common questions

Has the Colorado Attorney General issued rules under SB 26-189?

Proposed rules, yes. Final rules, not yet. The Colorado Department of Law filed proposed Automated Decision-Making Technology and Chatbot Safety rules, 4 CCR 904-6, with the Secretary of State on August 11, 2026. A rulemaking hearing is set for October 26, 2026 and written comments close that night. The rules are scheduled to take effect January 1, 2027.

When is the deadline to comment on Colorado’s proposed AI rules?

Written comment is open from August 11 through October 26, 2026. To be considered for the revised draft the Department expects to publish on September 23, a comment must arrive by September 4, 2026. Comments are submitted at comments.coag.gov and become part of the public record.

Do the proposed rules define “materially influence”?

No. The proposed rules leave the term undefined, and the notice of rulemaking sets out two competing standards and asks which to adopt. One treats a factor as outside the Act only if its impact is trifling, trivial, or incidental. The other allows a factor to fall outside the Act if information independent of the software played a significantly larger role. Both share a presumption that an output reviewed by the decision-maker and consistent with the outcome materially influenced the decision.

If a staffing agency runs the AI screening, is the employer responsible?

It is unresolved. The Attorney General’s notice puts that exact scenario to the public and acknowledges the Act does not contemplate a deployer who does not directly operate the technology. The one signal in the draft is the insurance example in Rule 6.5, where a third party claims administrator operates the tool and the insurer must provide the notice. Until the rules settle, the safer assumption is that the obligation runs to the business whose decision it is.

What do the proposed rules require in an adverse outcome notice?

Delivery within thirty days through at least two channels you normally use, and no smaller than 12-point type if printed. The content must name the decision in plain language, state the principal reasons specifically, explain any inference and the data behind it, disclose any score including the number itself, identify automatic denial factors, say what was missing if the outcome turned on incomplete information, and identify data sources by name.

Regulatory status as of August 18, 2026

The Colorado Attorney General has filed proposed rules under SB 26-189. They are not final.

The Colorado Department of Law filed proposed Automated Decision-Making Technology and Chatbot Safety rules, 4 CCR 904-6, with the Secretary of State on August 11, 2026. Written comment is open through October 26, 2026, and comment received by September 4, 2026 will be considered for a revised draft the Department expects to publish on September 23. A rulemaking hearing is set for October 26, 2026. The rules are scheduled to take effect January 1, 2027, alongside the statutes.

The proposed rules add obligations the statute alone does not state, particularly around what an adverse outcome notice must contain and what meaningful human review requires. They also leave “materially influence,” the term that decides who is covered, undefined. Treat this page as the current baseline rather than a final answer.

General information, not legal advice. No attorney-client relationship is created by reading this page.