days until compliance begins
Colorado’s new ADMT law
SB 26-189
Colorado repealed and replaced its 2024 AI Act with SB 26-189, an automated decision-making technology (ADMT) transparency regime. Substantive compliance begins January 1, 2027. For configured, covered events, GLACIS can preserve signed reports that may support a broader evidence set for selected notices, disclosures, and human-review workflows.
What the law says
Colorado rewrote its position in a single bill. The 2024 AI Act never bound anyone. SB 26-189 took its place, and it asks far less about whether you exercised reasonable care than about what you told the person on the other side of the decision. Two questions follow from that. Are your systems covered, and what do you owe once they are?
Who it covers
Developers and deployers of covered automated decision-making technology (ADMT) used to materially influence a consequential decision: access to or eligibility for education, employment, housing, financial or lending services, insurance, health-care services, and essential government services or public benefits.
Key requirements
- • Clear-and-conspicuous pre-use notice before a covered ADMT materially influences a consequential decision
- • Plain-language disclosure within 30 days of an adverse outcome
- • On request, access to and correction of inaccurate personal data
- • On request, meaningful human review where commercially reasonable
- • Developer documentation for deployers; records retained at least 3 years
Where this bites first: hiring. Candidate screening and ranking are consequential decisions under SB 26-189; see how signed runtime evidence works for hiring AI. Health-care services are covered too; teams that buy or review clinical AI should start with healthcare AI vendor review.
When it takes effect
SB 26-189 was signed May 14, 2026; substantive duties commence January 1, 2027, and the AG must adopt clarifying rules by the same date. The Attorney General must give 60 days’ notice and an opportunity to cure where a cure is possible, a right that sunsets January 1, 2030. Continuous evidence can show what configured controls and systems reported for covered ADMT events; source truth, execution, timing, and coverage require corroborating evidence.
How it’s enforced
Violations are deceptive trade practices, enforced exclusively by the Colorado Attorney General with no private right of action. Civil penalties run up to $20,000 per violation (up to $50,000 where the affected consumer is an elderly person), each consumer or transaction a separate violation.
From a duty of care to a duty to disclose
SB 26-189 drops the old reasonable-care duty, mandatory impact assessments, and the NIST AI RMF / ISO 42001 safe harbor. What remains is a transparency regime: notices, disclosures, data correction, and meaningful human review. Supporting records should show what configured systems and controls reported for covered decisions, with source truth, execution, timing, and coverage established separately.
A disclosure you can’t substantiate is a risk
When you tell a consumer how an ADMT shaped a decision, or offer human review of it, preserve decision-linked operational records alongside the applicable policy, notice, review, and system evidence. A policy PDF evidences intent, but not by itself what occurred in a particular event. (Frameworks like NIST AI RMF and ISO 42001 remain useful practice, though Colorado no longer treats them as a legal defense.)
Add a bounded operational record
For configured ADMT events, GLACIS can preserve signed reports of selected control decisions. Verification checks supported signatures and covered-field integrity; separate delivery, workflow, and coverage evidence is needed for notices, outcome disclosures, and human-review records.
How GLACIS gets you there
1. Assess your gaps
We map where your ADMT decisions are observable today against the notice, disclosure, and human-review duties ahead, starting with one named workflow.
2. Continuous evidence
Route in-scope ADMT decisions through the configured path. SDK or self-hosted receipts may be operator-signed; receipts minted through the Glacis portal may add a Glacis service-operated witness countersignature and inclusion proof. Covered payload fields can be excluded.
3. Preserve covered operational reports
For configured paths, signed records can support integrity and signer-attribution checks for selected ADMT notices, outcome disclosures, and human-review events. Separate evidence is needed for source truth, coverage, effectiveness, and legal sufficiency.
A signed record can make selected covered reports inspectable. It does not establish every SB 26-189 duty, complete capture, source truth, or compliance.