Colorado AI Act
SB 24-205
The first comprehensive US state AI law. $20,000 per violation per consumer or transaction. Effective June 30, 2026. NIST AI RMF compliance activates the strongest safe harbor in US law.
What the law says
Who it covers
Developers and deployers of high-risk AI systems making consequential decisions in employment, education, housing, healthcare, financial services, insurance, legal, and government sectors.
Key requirements
- • Duty of care to prevent algorithmic discrimination
- • Impact assessments (initial + annual)
- • Risk management aligned with NIST AI RMF / ISO 42001
- • Consumer notification before consequential decisions
- • Public disclosure on website
- • Report discrimination to AG within 90 days
When it takes effect
AG exclusive enforcement begins on day one. No cure period for initial violations. This is not a grace period — it's a cliff.
What happens if you don't
If your AI system processes 100 transactions per day, that's $2,000,000/day in potential penalty exposure. AG has exclusive enforcement authority.
The safe harbor — and how to activate it
Colorado offers the strongest AI safe harbor in US law: a rebuttable presumption of reasonable care if you demonstrate NIST AI RMF or ISO 42001 compliance.
Policies alone don't qualify
Having a PDF that describes your NIST mapping isn't enough. The safe harbor requires evidence that you actually followed the framework — not just that you documented it.
GLACIS activates the defense
GLACIS generates continuous cryptographic evidence that your NIST AI RMF-mapped controls actually executed — third-party witnessed, tamper-proof, ready for auditors and courts. This is the evidence trail that activates your affirmative defense.
How GLACIS gets you there
1. Assess your gaps
Free compliance wizard maps your current state against NIST AI RMF requirements. Get a personalized gap analysis in 5 minutes.
2. Continuous attestation
Deploy the GLACIS SDK. Every AI decision generates a cryptographic receipt — witnessed by our independent network. Zero data egress.
3. Activate safe harbor
Your evidence trail proves NIST AI RMF compliance continuously — not just at audit time. This is the affirmative defense the law was designed for.
5 minutes. Personalized report. Share with your GC.