Colorado's 2024 AI Act — once the most ambitious US state AI law on the books — survived just two years before Governor Jared Polis signed its replacement on 14 May 2026. Senate Bill 26-189 (SB 26-189) repeals and reenacts the original statute, stripping out its three most contested obligations and substituting a disclosure-centred framework that takes effect on 1 January 2027.
What the Original Law Required — and Why It Failed to Survive
Senate Bill 24-205, signed in May 2024, imposed a duty of care on developers and deployers of "high-risk AI systems" to prevent algorithmic discrimination, required formal risk management programmes, and mandated annual impact assessments. Business groups fought the rules from the outset. When Polis signed the original bill, he did so with publicly stated reservations: his signing statement explicitly encouraged sponsors to significantly improve their approach before the law took effect, and called on Colorado legislators to fine-tune provisions so they would not hamper AI development. The statute's lifespan was uncertain from the day it was signed.
The political pressure came to a head in April 2026 when Elon Musk's xAI filed suit to block enforcement on constitutional grounds, and the US Department of Justice intervened to support the challenge — the first time the DOJ had sought to intervene in a lawsuit challenging a state AI law. Colorado's Attorney General agreed to suspend enforcement pending the outcome. Faced with a stalled law, an active legal challenge, and a legislature receptive to change, the governor moved to replace the statute entirely.
The New Framework: ADMT, Not High-Risk AI
SB 26-189 discards the "high-risk AI system" construct in favour of "Automated Decision-Making Technology" (ADMT): any system that processes personal data to generate predictions, recommendations, classifications, or scores used to guide decisions about individuals. The shift to ADMT drops the inference requirement that had caused compliance headaches under the original law.
Coverage is pegged to seven consequential-decision domains: employment, education, housing, financial services, insurance, healthcare, and essential government services. Outside those domains, the law does not apply.
What Deployers and Developers Must Actually Do
The obligations are more surgical than the original law's broad duties. Deployers must give consumers advance notice before using covered ADMT to make employment decisions. When an adverse outcome follows, they have 30 days to provide a plain-language explanation of the ADMT's role and must offer a mechanism for meaningful human review and reconsideration. Consumers can also request correction of inaccurate personal data used as inputs.
Developers carry upstream obligations: they must supply deployers with documentation covering intended uses, training data categories, known risks, and usage instructions. Absent that documentation, deployers cannot claim they were uninformed about a system's limitations.
Enforcement sits exclusively with the Colorado Attorney General. There is no private right of action, a deliberate choice to remove the litigation risk that had most alarmed the business community. A 60-day cure period applies before the AG can pursue enforcement action, though that provision sunsets on 1 January 2030.
Who Gets a Pass
The law carves out several categories: HIPAA-covered entities, FDA-regulated medical devices, creditors complying with federal requirements, and insurers already subject to state-specific regulation. Research tools, fraud-prevention systems, and internal scheduling or administrative routing tools are also exempt. Holland & Knight's analysis notes the exemptions are drafted broadly enough to give most pure-infrastructure and product-development teams a clear path out of scope.
The Wider Signal for AI Governance
Colorado's reversal shows US states diverging from the EU's risk-management model. The original 2024 law was loosely based on the EU AI Act's tiered-risk approach; its replacement is a consumer-protection disclosure regime. The Governor's office characterised the new law as protecting consumers while not being onerous on developers or the businesses that use AI technology — language that reflects where the political centre of gravity now sits in American AI policy debates.
Other states watching Colorado's experiment — including those that had cited SB 24-205 as a template — will now weigh whether a disclosure-plus-explanation model is both politically viable and practically enforceable. For enterprises with Colorado-facing operations, the January 2027 effective date is meaningful: compliance programmes built for the original law's risk assessments and impact reports need to be redesigned around the narrower ADMT definition and the notice-and-explanation obligations. Those programmes are lighter, but they still require audit trails, consumer-facing processes, and developer documentation chains to be in place before the new year.
The replacement is stayed as well
Repealing the contested statute and substituting a disclosure framework looked like a way to defuse the litigation. It has not, and the sequence of events shows why.
xAI sued in April. The Department of Justice moved to intervene on 24 April, the first time it had sought to join a challenge to a state AI law. On 27 April a federal court granted a stay of enforcement. Governor Polis signed the replacement on 14 May.
The stay reaches the new statute too. It runs until fourteen days after the court rules on xAI's preliminary injunction motion, and as of late August no ruling had issued.
So Colorado has legislated twice on artificial intelligence in two years and currently has neither statute in force. The original duty-of-care regime is enjoined and the lighter disclosure framework that was meant to replace it is enjoined with it, on a timetable set by a federal judge rather than by the legislature.
What that means for the retreat argument
The obvious reading of the repeal was that a state had tried the ambitious version of AI regulation, met sustained industry resistance, and settled for something enforceable. The stay complicates that.
Softening a law does not moot a constitutional challenge. An argument based on preemption or compelled speech applies just as well to a disclosure framework as to a duty of care. Colorado gave up the substance and kept the litigation.
That is the practical lesson for other legislatures watching, and it points away from the conclusion most of the commentary drew. The way to avoid this outcome was not necessarily to write a lighter law.
Illinois went the other way in the same quarter
While Colorado was retreating, Illinois passed the Artificial Intelligence Safety Measures Act 110-0 in the House. Governor Pritzker signed it on 6 July, and it takes effect on 1 January 2027.
It requires developers above US$500 million in revenue that also cross a frontier-scale compute threshold to publish a safety framework, issue transparency reports before deploying new frontier models, and retain an independent third-party auditor each year. No suit has been filed against it.
The difference in what the two states regulate may explain the difference in what happened to them. Colorado's original act imposed a duty of care on deployers against algorithmic discrimination, which reaches into how firms use models. Illinois obliges a small number of very large developers to document what they do and have somebody check the documentation. One is a conduct rule and the other is closer to a reporting regime, and reporting regimes have historically been the more durable form of American technology regulation.
The disclosure framework has a January date it may not reach
SB 26-189 takes effect on 1 January 2027, which is the date to hold in mind against a stay of unknown duration.
If the injunction motion is decided before then and Colorado prevails, the disclosure regime starts roughly on schedule. If the court rules against the state, or does not rule at all for some months, Colorado enters 2027 in the position it has been in since April, with a statute on the books and nothing operating.
For a business with Colorado exposure, the question is not what SB 26-189 requires, but whether to build for a regime that may never take effect. The practical answer is to build for the strictest applicable state law and wait for Colorado to resolve its own legal problems.