On August 11, the Colorado Department of Law (DOL) filed proposed rules implementing two significant Colorado artificial intelligence laws, the Automated Decision-Making Technology in Consequential Decisions Act (ADMT Act) and the Conversational Artificial Intelligence Services Act (Chatbot Safety Act), both of which take effect January 1, 2027. As we reported in May (here), the Colorado legislature significantly rewrote its earlier 2024 AI law, replacing the prior framework with a more targeted set of obligations focused on automated decision-making technology (ADMT) in consequential decisions. The proposed rules represent the Attorney General’s effort to flesh out that framework before the upcoming effective date. They also begin to answer several of the questions we flagged as unresolved when the new law was signed. A formal rulemaking hearing has been scheduled on October 26, 2026. Public comments about any proposed revisions to the rules to be presented during the hearing must be submitted by October 5, but all public comments submitted through October 26 will be considered for the final set of rules.
Background: Two New Colorado AI Laws
The ADMT Act (Senate Bill 26-189, signed May 2026) creates obligations for both developers and deployers of ADMT used to materially influence “consequential decisions” — defined to include decisions affecting employment, education, financial services, housing, insurance, and other significant areas of consumer life. As discussed in our prior post, the law imposes disclosure, consumer rights, and human review obligations on deployers, and documentation and notification obligations on developers, while removing many of the governance, bias assessment, and public reporting requirements from the 2024 version.
The Chatbot Safety Act (House Bill 26-1263, signed July 1, 2026) imposes obligations on operators of conversational AI services accessible to the general public, including requirements to disclose that users are interacting with AI, estimate user age, protect minors from sexually explicit content and simulated emotional dependence, implement suicide and self-harm response protocols, and submit annual reports to the Colorado Attorney General. The law also prohibits chatbot outputs from being presented as equivalent to services provided by licensed health care, legal, or mental health professionals.
Key Provisions of the Proposed Rules
Consumer Communications. All disclosures and communications to consumers must use plain language, be accessible to consumers with disabilities, be available in languages in which the deployer ordinarily interacts with consumers, and be readable across all devices.
Multiparty Arrangements. “Midstream developers,” companies that integrate third-party ADMT models into their own products and sell them to others, must obtain and pass along all developer documentation from upstream providers to downstream deployers who use the product to make consequential decisions. The roles of other parties in multiparty arrangements, including ADMT vendors, will be a topic of discussion during the upcoming hearing.
Developer Obligations. Developers must provide deployers with meaningful, accurate information about their ADMT’s intended uses, known limitations and risks, monitoring instructions, and the categories of data used to train the system. Trade secrets may be withheld by developers, but the legal basis must be identified and sufficient alternative information provided to deployers.
Adverse Outcome Disclosures. When a deployer uses covered ADMT to produce an adverse outcome, the deployer must provide a written disclosure to the consumer within 30 days through at least two communication methods. The disclosure must include a plain language description of the decision, the ADMT’s role, principal reasons for the adverse outcome (including automatic denial factors, inferences drawn from personal data, and risk scores) and instructions for exercising consumer rights. The proposed rules provide sector-specific examples for financial services, housing, insurance, employment, and education. Importantly, the Colorado Attorney General will consider deployers that are already required to provide adverse action notices under the Equal Credit Opportunity Act or the Fair Credit Reporting Act as satisfying Colorado’s requirements through those existing notices, provided they also include the required ADMT-specific content. This addresses one of the open questions we flagged in our prior blog regarding whether Colorado would require additional notices beyond existing federal requirements.
Consumer Rights. Consumers may request the personal data used in a covered ADMT consequential decision, correct factually inaccurate personal data used by the ADMT in making a consequential decision, and request meaningful human review and reconsideration of any ADMT consequential decisions. Deployers must confirm receipt of requests within 10 days and complete meaningful human review within 45 days. Reviewers must be independent, possess relevant expertise, and have genuine authority to override the consequential decision by the ADMT. ADMT may not assist in the review. The proposed rules’ multi-factor commercial reasonableness framework begins to address the open question we raised in our prior blog about the “commercially reasonable” standard for human review, though concerns about its application in consumer lending remain. Where an adverse outcome constitutes a severe and irreversible denial of a basic human need, a company’s ability to provide meaningful human review is presumed to be commercially reasonable.
Age Assurance. Operators must use commercially reasonable or generally accepted methods to estimate user age. Self-declarations by consumers alone are insufficient. Accepted methods include zero-knowledge proofs, facial recognition matched to government ID, and digital footprint assessment. Operators may not willfully disregard signals, including behavioral signals processed by the AI itself, that a user is a minor.
AI Disclosures. Operators must disclose to all users that they are interacting with AI and not a human. For minor users, a persistent visible disclaimer is required throughout the conversation. For all users, the disclosure must appear at the start of each day’s first interaction, at least once every three hours in a continuous interaction, and whenever a user asks whether the chatbot is human.
Minor User Protections. Prohibited engagement-maximizing features for minors include leaderboards, badges, login streaks, and features tied to session length. Privacy settings for minor accounts must default to the most protective setting, including defaulting to not retaining prior session information or using minor user data for model training.
Annual Report. Operators must submit a detailed annual report to the Colorado Attorney General by July 1, 2027, covering calendar year 2027, including user tier by monthly active users, crisis referral counts and accuracy metrics, suicide and self-harm protocol descriptions, age-estimation methodologies, and metrics on minor users encountering prohibited content.
Our Take
As we noted in our prior blog (here), financial institutions and other consumer-facing businesses in financial services, insurance, employment, education, and housing should carefully assess whether their use of algorithmic or AI-assisted tools constitutes covered ADMT or conversational AI services. The proposed rules begin to answer several open questions from the new law, particularly around adverse outcome disclosure alignment with existing federal notice regimes and the factors governing commercial reasonableness for meaningful human review. Many uncertainties remain, however — notably around enforcement timing given the pending litigation challenging the 2024 law and the Attorney General’s agreement to stay enforcement until regulations are finalized and the court addresses the plaintiffs’ preliminary injunction motion.
We believe that the financial services industry should strongly consider commenting on these proposed rules, because they contain a number of provisions that we expect will be difficult to operationalize or which may lead to highly negative outcomes for financial services companies and their customers. In particular:
- The proposed rules use examples of decisions covered by the CO ADMT Act that we would not have expected to be covered under the language of the statute, leading to the possibility that the AG’s office views the scope of the law more broadly than the industry would have understood based on the statutory language. The implication is that financial services companies may be providing many more notices under the law than is the practice under current laws that require adverse action notices.
- The proposed rules minimize the exception for required human review based on commercial reasonableness in a way that suggests that financial services companies may not be able to rely on this exception in a broad manner.
- The proposed rules require very detailed disclosure of the consumer information used in making decisions in a way that would expose the attributes used in automated models, which would both infringe on the trade secret nature of such models and equip perpetrators of fraud to more effectively manipulate outcomes under those models.
We will continue to monitor the Attorney General’s rulemaking efforts under these laws.
