Deployer or Developer? Which One Are You Under Colorado’s AI Law

Photograph by Michael Hoog
← Colorado AI Compliance

SB 26-189 assigns duties by role. A developer builds the technology. A deployer uses it. Most Colorado businesses are deployers and nothing else, which is the simpler position to be in. A meaningful number are quietly both, and they are usually the ones who have not thought about it.

The definitions

A deployer is a person doing business in Colorado that deploys a covered automated decision-making technology. Deploying means putting it to use in your operation to make, guide, or assist a consequential decision.

A developer is a person doing business in Colorado that does any of three things: develops, offers, sells, leases, licenses, or otherwise makes a covered ADMT commercially available; develops a component designed, marketed, intended, documented, advertised, configured, or contracted to be used as part of a covered ADMT; or intentionally and substantially modifies an ADMT such that it becomes a covered ADMT.

The internal-use exclusion, which changes the answer for a lot of businesses

The Act says a developer does not include a person that develops and uses an ADMT for internal purposes, including use and development activities by affiliates and commercial support functions, so long as that person does not make the system available to another person for use in a consequential decision.

So a staffing firm that built its own candidate ranking tool and runs it only on its own hiring is not a developer. It is a deployer, with deployer obligations, and that is the whole answer. Building something for yourself does not put you on the developer side of the line. Handing it to someone else does.

There is a parallel exclusion for research: developing and using an ADMT solely for research, where it is not used in a consequential decision within that research.

What “intentionally and substantially modifies” actually means

This one is defined too, and more narrowly than the plain words suggest. An intentional and substantial modification is a deliberate change to an ADMT that results in a material change to the system’s intended, documented, advertised, configured, or contracted use.

The test is whether you changed what the system is for, not how hard you tuned it. Fine-tuning a hiring tool to work better on your own hiring is not obviously a change in intended use. Repurposing a marketing tool into a tenant screening tool plainly is. If you customized heavily but the documented purpose never moved, you have a real argument that you did not modify it within the meaning of the Act.

The Attorney General has asked for comment on what facts should determine whether a component is designed, marketed, intended, documented, advertised, configured, or contracted for use as part of a covered ADMT. Expect the rules to say more here.

Two more exclusions worth knowing

A preceding developer that makes an ADMT commercially available is not a developer as to changes an unaffiliated person makes that alter the system’s intended, documented, marketed, advertised, configured, or contracted use. If a customer repurposes your product into something you never built it for, that is on them.

Likewise, someone who supplied a component is not a developer where the component was integrated into a covered ADMT without that person’s actual knowledge.

When you really are both

The overlap case that survives all of the above is selling. A Colorado software company that added a scoring feature its customers use in consequential decisions is a developer, even if it thinks of itself as selling workflow software, and it is separately a deployer as to anything it runs internally.

That catches Front Range companies who do not consider themselves AI companies at all. If your product scores, ranks, or classifies people, and customers use those outputs in one of the seven covered domains, the statute is looking at you regardless of how the product is described.

What each role owes

Deployer obligations are the ones most Colorado businesses will live with: clear and conspicuous notice before covered ADMT materially influences a consequential decision, notice within 30 days of an adverse outcome describing the role the technology played, and records retained at least three years. Plus a working process for consumers who ask to correct inaccurate personal data or request meaningful human review.

Developer obligations run to disclosure and documentation that lets deployers meet their own duties. A developer who tells customers nothing about how the system works is selling a product its customers cannot lawfully deploy in Colorado, which is a commercial problem before it is a legal one.

Do not read the split as a way to pass the duty along. A deployer who licenses a tool still owes the notices. Buying the software does not transfer anything.

How to place yourself

Work through it in order:

  • Do you use software that scores, ranks, classifies, or recommends people in education enrollment or an education opportunity; employment or an employment opportunity that creates or may create an employer-employee relationship; the lease or purchase of residential real estate in Colorado; a financial or lending service; insurance, including underwriting, pricing, coverage, and claims adjudication; health-care services; and essential government services and public benefits, including eligibility and renewal determinations decisions? If yes, you are a deployer.
  • Did you build any of it, tune it on your own data, or assemble tools into something that produces a new output? If yes, look hard at developer status.
  • Do you sell, license, or offer any of it to others who use it that way? If yes, you are a developer as to that product.

Most businesses answer yes to the first and no to the others. If you answered yes to more than one, you are carrying two sets of obligations and they do not collapse into each other.

Why this is worth settling now

In short, the effective date is January 1, 2027 and the Attorney General’s rules are due the same day, which means operational detail arrives close to the deadline. A business that knows its role can absorb the rules when they issue. A business still arguing about whether it is a developer will be starting from zero in December.

If you are somewhere in the middle, that is a reason to work it through rather than a reason to wait. Start with the compliance checklist, and see the coverage article for why company size does not resolve it. If placing yourself is not obvious, I would welcome the chance to work through it with you.

Common questions

What is the difference between a deployer and a developer under Colorado SB 26-189?

A deployer is a person doing business in Colorado that deploys covered automated decision-making technology, meaning they use it in a consequential decision. A developer is a person doing business in Colorado that develops, offers, sells, leases, licenses, or otherwise makes a covered ADMT commercially available; develops a component designed or contracted to be used as part of a covered ADMT; or intentionally and substantially modifies an ADMT such that it becomes a covered ADMT. Critically, a person who develops and uses an ADMT solely for internal purposes, and does not make it available to another person for use in a consequential decision, is excluded from the developer definition. Deployer obligations center on notice, human review, and recordkeeping. Developer obligations center on disclosure and documentation that lets deployers comply.

Can a business be both a deployer and a developer?

Yes, but less often than people assume. A company that builds a tool and uses it only internally is not a developer, because SB 26-189 excludes a person that develops and uses an ADMT for internal purposes and does not make it available to another person for use in a consequential decision. That company is simply a deployer. The genuine both case is a company that licenses or otherwise makes a scoring product commercially available to others while also using it in its own operations. There the two sets of obligations apply independently and do not merge.

Does customizing an AI tool make me a developer under Colorado law?

Less often than people assume. SB 26-189 defines intentional and substantial modification as a deliberate change to an ADMT that results in a material change to the system’s intended, documented, advertised, configured, or contracted use. The test is whether you changed what the system is for, not how extensively you tuned it. Fine-tuning a hiring tool to perform better on your own hiring does not obviously change its intended use. Repurposing a marketing tool into a tenant screening tool does. Separately, a person who develops and uses an ADMT solely for internal purposes, without making it available to others for use in a consequential decision, is excluded from the developer definition entirely.

If I license an AI tool, does the developer’s compliance cover me?

No. Deployer obligations attach to the business deploying the technology. Licensing does not transfer them. The developer’s disclosures are what let you meet your own duties, but the duties remain yours.

Is a Colorado software company a developer if it does not consider itself an AI company?

If the product processes personal data and produces predictions, recommendations, classifications, rankings, or scores, and customers use those outputs in education enrollment or an education opportunity; employment or an employment opportunity that creates or may create an employer-employee relationship; the lease or purchase of residential real estate in Colorado; a financial or lending service; insurance, including underwriting, pricing, coverage, and claims adjudication; health-care services; and essential government services and public benefits, including eligibility and renewal determinations decisions, the statute can reach it regardless of how the company describes itself. What the software does is the test, not how it is marketed.

Regulatory status as of August 18, 2026

The Colorado Attorney General has filed proposed rules under SB 26-189. They are not final.

The Colorado Department of Law filed proposed Automated Decision-Making Technology and Chatbot Safety rules, 4 CCR 904-6, with the Secretary of State on August 11, 2026. Written comment is open through October 26, 2026, and comment received by September 4, 2026 will be considered for a revised draft the Department expects to publish on September 23. A rulemaking hearing is set for October 26, 2026. The rules are scheduled to take effect January 1, 2027, alongside the statutes.

The proposed rules add obligations the statute alone does not state, particularly around what an adverse outcome notice must contain and what meaningful human review requires. They also leave “materially influence,” the term that decides who is covered, undefined. Treat this page as the current baseline rather than a final answer, and see Colorado’s proposed ADMT rules.

General information, not legal advice. No attorney-client relationship is created by reading this page.