Appearance
Colorado SB 26-189
Colorado Senate Bill 26-189 (2026, Session Law chapter 131) is Colorado's current law on automated decision-making technology (ADMT) used to materially influence consequential decisions. Signed on May 14, 2026, it repealed and reenacted part 17 of article 1 of title 6 of the Colorado Revised Statutes, replacing the 2024 Colorado AI Act (SB 24-205) before that act ever applied. The reenacted part is a transparency, process-rights, and liability-allocation statute: developers owe deployers a transparency package and update notices; deployers owe consumers a pre-use notice, post-adverse-outcome disclosures within 30 days, and rights to data correction and meaningful human review; both keep records; and liability under existing anti-discrimination law is allocated by relative fault, and specified developer-deployer contract provisions indemnifying a party for its own Colorado anti-discrimination violations are void (with a developer carve-out, and without limiting insurance claims). The act takes effect January 1, 2027 and applies to consequential decisions made on or after that date; its rulemaking authorities and certain related provisions took effect on signing.
Modulos models the act as two paired templates with the Regulation label: MFF-28 for one covered ADMT and OFF-28 for the organization's repeatable capabilities. This page orients you on the legislative history (which matters more here than for most frameworks), what the current law requires, who it reaches, and where to go next.
Read this first: most "Colorado AI Act" literature describes a repealed law
Nearly all guidance published in 2024 and 2025 under the names Colorado AI Act, CAIA, or Colorado ADMT law describes SB 24-205, which SB 26-189 repealed in full. None of the following is current Colorado law: a duty of reasonable care to avoid algorithmic discrimination, a risk-management program, impact assessments, public AI-use statements, principal-reasons explanations of adverse decisions, opt-outs, the under-50-employee exemption, or any NIST- or ISO-based presumption, safe harbor, or affirmative defense. SB 26-189 says twice that compliance with part 17 is not a defense to any other law. This framework and these pages are built from the enrolled text of SB 26-189 only.
Quick decision — is this framework for you?
- You deploy, in Colorado, a tool that scores, ranks, classifies, recommends, or otherwise materially influences decisions about people's access to jobs, housing, credit, insurance, education, health care, or public benefits → SB 26-189 may apply. Run the full covered-ADMT, exclusion, role, and sectoral-overlay analysis in Coverage and roles before treating the tool as covered, and record the determination.
- You develop, offer, sell, lease, license, or otherwise make commercially available such a tool while doing business in Colorado → you may be a developer. Confirm the § 6-1-1701(8) definition and its exclusions, then the § 6-1-1702(5) trigger; the transparency-package and update-notice duties are further limited by § 6-1-1702(3), the record duty is not. See Developer duties. You may also be a deployer of your own tool; the roles are not exclusive.
- You are an insurer, a HIPAA covered entity or business associate, a creditor, or an education deployer subject to FERPA → the sectoral provisions may exempt, deem compliant, conditionally satisfy, or reroute particular duties, and they do not operate uniformly: HIPAA covered entities retain direct notice and disclosure duties, and a non-deemed-compliant insurer has a fallback disclosure duty. Coverage and roles states each provision with its exact limits.
- You already run the EU AI Act or NIST AI RMF in Modulos → one control is shared (
MCF-171, transparent automated decision-making). The rest of this law's duties are new machinery, which is why 12 of the 13 mapped controls are new. See Operationalizing SB 26-189 in Modulos.
TL;DR
- The law: SB 26-189, Session Law ch. 131, signed May 14, 2026; reenacts C.R.S. §§ 6-1-1701 through 6-1-1709 (part 17 of article 1 of title 6) and adds C.R.S. § 10-3-1104.9(3)(e) for insurers. Effective January 1, 2027; applies to consequential decisions made on or after that date. Section citations on these pages follow the enrolled act; part 17's final codified disposition is pending (see below).
- Covered ADMT = ADMT used to materially influence a consequential decision in one of seven covered domains, subject to the ADMT exclusions and nine consequential-decision exclusions.
- Developer duties: the five-element transparency package to each deployer; update notices within a reasonable time; records for at least three years after each record's creation.
- Deployer duties: pre-use notice (a standing notice at points of consumer interaction suffices); post-adverse-outcome disclosures within 30 days; correction instructions and meaningful human review on request; records for at least three years after each consequential decision; accessibility of every notice and disclosure.
- Liability: developers and deployers may be liable under state anti-discrimination law by relative fault; specified developer-deployer contract provisions indemnifying a party for its own Colorado anti-discrimination violations are void, subject to the developer carve-out in § 6-1-1707(7)(b), with other commercial terms and insurance claims unaffected under (7)(c)–(d); compliance with part 17 is not a defense.
- Enforcement: Attorney General only, through the Colorado Consumer Protection Act; 60-day cure period where cure is deemed possible (not required for knowing or repeated violations); cure subsection repealed January 1, 2030; no private right of action.
- Pending rules: two mandatory Attorney General rulemakings, on the post-adverse-outcome disclosures and on the consumer rights, are due on or before January 1, 2027, the act's own effective date. The framework and these pages will be updated when the rules are adopted.
- Modulos:
MFF-28(AI application, 7 requirements,MRF-482–MRF-488) +OFF-28(organization, 5 requirements,ORF-483–ORF-487), templates 1.0.30, mapped to 13 distinct controls (12 new, 1 shared). An ADMT Role tag (Developer, Deployer) marks the developer and deployer branches; the roles are not exclusive.
Primary source
Senate Bill 26-189, Concerning the use of automated decision-making technology in consequential decisions, signed May 14, 2026 (Session Law ch. 131): bill page and signed act on leg.colorado.gov. Read the enrolled act itself; the bill-page summary contains errors on the effective date and safety clause. Always verify claims against the current published text.
Key facts
Legislator
Colorado General Assembly (SB 26-189, Session Law ch. 131)
Instrument
C.R.S. §§ 6-1-1701–1709 as reenacted, plus § 10-3-1104.9(3)(e) (Regulation label in Modulos)
Signed / effective
May 14, 2026 / January 1, 2027 (§§ 6-1-1704(4), 6-1-1705(3), 6-1-1706(6), 10-3-1104.9(3)(e), and Sections 4–6 of the act on passage)
Enforced by
Colorado Attorney General, exclusively, via the Colorado Consumer Protection Act
Covers
Developers and deployers doing business in Colorado of ADMT that materially influences consequential decisions in seven covered domains
Modulos templates
MFF-28 (application) + OFF-28 (organization): 12 requirements, 13 controls
Four legislative layers
The current law is the third of four instruments that touched the same statutory part in two years. Knowing which one a source describes is the first compliance task.
| Layer | Instrument | Signed | What it did | Status |
|---|---|---|---|---|
| 1 | SB 24-205, "Consumer Protections for Artificial Intelligence" (the 2024 Colorado AI Act) | May 17, 2024 | Created C.R.S. §§ 6-1-1701–1707: a high-risk-AI regime built around developer and deployer duties, risk-management programs, impact assessments, and public statements; original effective date February 1, 2026 | Repealed by SB 26-189 before it applied |
| 2 | SB 25B-004, "Increase Transparency for Algorithmic Systems" (2025 special session) | August 28, 2025 | Delayed SB 24-205's effective date to June 30, 2026 | Overtaken by layer 3 |
| 3 | SB 26-189, "Concerning the use of automated decision-making technology in consequential decisions" (Session Law ch. 131) | May 14, 2026 | Repealed and reenacted part 17 as an ADMT transparency, process-rights, and liability-allocation regime; added § 10-3-1104.9(3)(e); effective January 1, 2027 | Current law; this framework |
| 4 | HB 26-1263, conversational-AI service operator requirements (Session Law ch. 208) | May 29, 2026 | Added conversational-AI definitions and its own § 6-1-1708 to the same part 17, duplicating SB 26-189's § 6-1-1708; its petition clause provides an August 12, 2026 effective date only if the stated adjournment assumption holds and no referendum petition is filed, with staggered operative dates through 2027 | Separate regime; not covered by this framework |
Two consequences for reading these pages:
- Citations follow the SB 26-189 enrolled act. HB 26-1263 enacted a second § 6-1-1708 in the same part, so part 17's final codified disposition is pending. The framework carries a watch marker for it and will be updated when the final codified disposition is published.
- HB 26-1263 is out of scope. Its conversational-AI operator duties sit in the same statutory part but form a separate regime with a conditional petition-clause effective date and staggered operative dates. This framework documents SB 26-189's ADMT regime only.
What the law requires
| Provision (enrolled act) | What it holds |
|---|---|
| § 6-1-1701 — Definitions | ADMT and its exclusions, consequential decision and its nine exclusions, the seven covered domains, consumer, covered ADMT, developer and deployer, materially influence, material update, intentional and substantial modification, adverse outcome, meaningful human review. |
| § 6-1-1702 — Developer responsibilities | The five-element transparency package to each deployer; update notices within a reasonable time; the subsection (3) scope limit; three-year records from creation; the section-wide trigger. |
| § 6-1-1703 — Deployer record keeping | Records reasonably necessary to demonstrate compliance, kept for at least three years after the date of each consequential decision. |
| § 6-1-1704 — Deployer disclosures | The pre-use notice and its standing-notice route; the post-adverse-outcome disclosures within 30 days; the mandatory Attorney General rulemaking on those disclosures; trade-secret withholding with notice; the creditor, federal-law, accessibility, and FERPA provisions. |
| § 6-1-1705 — Consumer rights | Correction instructions and meaningful human review on request after an adverse outcome; the broadened correction right; the boundary for opinions, predictions, scores, and protected evaluations; the mandatory Attorney General rulemaking on this section. |
| § 6-1-1706 — Enforcement | Attorney General enforcement through the Colorado Consumer Protection Act; violation as deceptive trade practice; the 60-day cure regime and its January 1, 2030 repeal; no new private right of action; discretionary rules including on "materially influence". |
| § 6-1-1707 — Liability | Liability under state anti-discrimination law by relative fault; developer limits tied to the represented use envelope; specified developer-deployer indemnification provisions for a party's own anti-discrimination violations void, with the developer carve-out and insurance unaffected; compliance is not a defense. |
| § 6-1-1708 — Sectoral overlays | Insurers, HIPAA covered entities and business associates, FDA-regulated devices, HIPAA and GLBA disclosure limits. |
| § 6-1-1709 — Application of other law | No new private right of action; compliance is not a defense to and does not excuse noncompliance with any other applicable law. |
| § 10-3-1104.9(3)(e); §§ 5–6 of the act | Insurance commissioner notice-and-disclosure rulemaking; effective date, applicability, and safety clause. |
Who is covered
Most duties fall on developers and deployers doing business in Colorado of a covered ADMT. Under § 6-1-1701(5), "“Covered ADMT” means automated decision-making technology that is used to materially influence a consequential decision." Separately, § 6-1-1708(1)(b) and (3)(c)–(e) impose direct duties by sectoral capacity on non-deemed-compliant insurers and HIPAA covered entities, described on the coverage page. For the role-based branches, coverage turns on a conjunctive test:
- the technology is ADMT (processes personal data, uses computation to generate output used to make, guide, or assist a decision about an individual) and no ADMT exclusion applies;
- it is used to materially influence the decision (a non-de minimis factor that affects the outcome; incidental, trivial, or clerical uses are excluded);
- the decision is a consequential decision in one of the seven covered domains (education; employment or an employment opportunity that creates or may create an employer-employee relationship; the lease or purchase of residential real estate in Colorado; a financial or lending service; insurance; health-care services; essential government services and public benefits), and none of the nine exclusions applies;
- the organization acts as developer, deployer, or both, and the applicable sectoral provisions (exemption, deemed compliance, conditional satisfaction, rerouting) determine the resulting duty set; independently, determine whether a direct sectoral capacity under § 6-1-1708 applies.
The roles are not exclusive and can change: a deployer that intentionally and substantially modifies an ADMT into a covered ADMT becomes its developer, and developer duties are also triggered on becoming aware of consistent consequential-decision use.
→ Full treatment, including the exclusion conditions and the sectoral overlays with their exact limits: Coverage and roles.
How Modulos models it
| Template | Project type | Holds | Requirements |
|---|---|---|---|
MFF-28 — Colorado SB 26-189 | AI application | For one covered ADMT: coverage and role determination; the developer's transparency package and update notices; the deployer's pre-use notice, post-adverse-outcome and sectoral disclosures, consumer correction and meaningful human review, and compliance records with their liability-evidence dimension | 7 (MRF-482–MRF-488) |
OFF-28 — Colorado SB 26-189 | Organization | The repeatable capabilities: notice and disclosure infrastructure with the accessibility duty; the meaningful-human-review capability; the deployer records program; liability posture and contract hygiene; the Colorado rulemaking and codification watch | 5 (ORF-483–ORF-487) |
One MFF-28 project assesses one covered ADMT. Every requirement carries an ADMT Role tag, Developer or Deployer or both, so a project can be filtered to the developer or deployer branch; the tags do not encode every sectoral capacity, so MRF-485 and MRF-486 (which also carry direct HIPAA covered-entity duties and the insurer fallback) are reviewed regardless of the role filter. There is no scoping questionnaire: MRF-482 records the coverage and role determination inside the project.
The 12 requirements group into three coverage areas plus the organization capabilities, each with its own topic page.
1. Coverage and roles
The conjunctive covered-ADMT test, the ADMT and consequential-decision exclusions with their conditions, the seven covered domains, developer versus deployer with the re-evaluation triggers, and the sectoral overlays (MRF-482).
→ Deep dive: Coverage and roles.
2. Developer duties
The five-element transparency package with the withholding notice (MRF-483); update notices with the subsection (3) scope and the release-notes route, and developer records for three years from creation (MRF-484).
→ Deep dive: Developer duties.
3. Deployer duties and consumer rights
The pre-use notice at points of consumer interaction (MRF-485); the post-adverse-outcome disclosures within 30 days with the sectoral routes (MRF-486); correction and meaningful human review with the reviewer test (MRF-487); records as liability evidence (MRF-488); and the § 6-1-1707 fault-allocation and void-indemnification rules (ORF-486).
→ Deep dive: Deployer duties and consumer rights.
What the law does not require
The reenacted part 17 contains no duty of care, no risk-management-program mandate, no impact assessment, no anchoring to any external framework, no public AI-use statement, no principal-reasons explanation, no opt-out, and no appeal right beyond the commercially reasonable human-review opportunity. It also gives compliance no defensive effect: § 6-1-1707(8)–(9) and § 6-1-1709(2) state that compliance with part 17 is not a defense to and does not excuse noncompliance with any other applicable law, and the act does not limit or displace existing rights and remedies. Nothing on these pages, and nothing in the framework, should be read as suggesting that operating the framework earns statutory or evidentiary credit; what it does is make the duties performable and the records producible.
Pending Attorney General rules
Two rulemakings are mandatory and are due on or before January 1, 2027, the day the act takes effect: rules clarifying and implementing the post-adverse-outcome disclosures (§ 6-1-1704(4); those rules may, as appropriate, address disclosure content, sector-specific guidance or examples, role-description standards, and interactions with federal and state notice laws) and rules clarifying and implementing the consumer rights section (§ 6-1-1705(3)). Both authorities took effect on signing. The Attorney General may also adopt rules clarifying the definition of "materially influence" through presumptions, illustrative examples, and objective indicators (§ 6-1-1706(5)), and the insurance commissioner may adopt notice-and-disclosure rules for insurers (§ 10-3-1104.9(3)(e)).
Until the rules are adopted, the framework states the statutory minimum and flags where the rules will add detail (MRF-486, MRF-487). Modulos will update the framework and these pages when the mandatory rules are adopted; framework versioning notifies affected projects. The organization framework's ORF-487 carries the watch as a readiness practice.
Enforcement
The Attorney General enforces part 17 exclusively, through the Colorado Consumer Protection Act; a violation is a deceptive trade practice (§ 6-1-1706(1)–(2); § 6-1-105(1)(uuuu)). Where the Attorney General deems a cure possible, a notice of violation precedes any enforcement action, and the developer or deployer has 60 days to cure; a cure period is not required where the Attorney General finds and can demonstrate a knowing or repeated violation, and a cure within 60 days of written notice may be considered a mitigating factor. Annual public enforcement reporting starts in January 2028. The cure-and-reporting subsection is repealed effective January 1, 2030. The act creates no new private right of action and does not limit existing rights and remedies under state or federal law, including the Colorado Anti-Discrimination Act, the Colorado Consumer Protection Act, and product liability law (§ 6-1-1706(4)).
How Modulos operationalizes SB 26-189
Each requirement is evidenced through its linked controls; the Requirement Owner reviews the completed controls and marks the Requirement as Fulfilled. The Colorado-specific tests, clocks, and content elements live in the requirement text and in the 12 new controls; the one shared control carries no Colorado-specific wording.
- 12 new controls:
MCF-688(coverage and role determination),MCF-689(developer transparency package),MCF-690(developer update notices and records),MCF-691(pre-use notice at interaction points),MCF-692(post-adverse-outcome disclosures),MCF-693(consumer correction and human-review handling),MCF-694(compliance records and traceability);OCF-380(notice and disclosure infrastructure),OCF-381(meaningful-human-review capability),OCF-382(records program),OCF-383(liability posture and contract hygiene),OCF-384(rulemaking and codification watch). - 1 shared control:
MCF-171(Transparent Automated Decision-Making), supporting the pre-use notice; also mapped by the EU AI Act and NIST AI RMF templates.
The reuse story is deliberately thin. The other 12 of the 13 mapped controls are new in the reviewed platform mapping: existing candidates did not align closely enough with the statute's specific content, triggers, clocks, and liability dimensions (a statutory transparency package between developer and deployer, a 30-day post-adverse-outcome disclosure, a reviewer test for human review, per-decision records that double as fault-allocation evidence) to support reuse. Nothing from the repealed 2024 act's vocabulary was reused in the coverage model either: the coverage determination is a conjunctive test, not risk tiering.
Framework mapping
Four layers, one reusable column.
Frameworks
EU AI Act
ISO 42001
Requirements
Art. 9.1Risk management
Art. 10.2Data governance
6.1.1Risk assessment
Components
Risk identification
Impact analysis
Evidence
Risk register
Test results
Controls
The reusable column
One control satisfies many requirements across many frameworks, and groups the components and evidence beneath them.
Risk assessment process
Data validation checks
Edge from any layer card crosses into the Controls column — the same control may serve a regulatory article, a standards clause, a downstream component, and the evidence that closes it.
→ Full rollout: Operationalizing SB 26-189 in Modulos: project structure, the requirement mapping tables, the 12 new controls, the ADMT Role tag, the rollout sequence, and the watch.
Where to go next
Coverage and roles
The covered-ADMT test, exclusions, seven domains, developer vs deployer, sectoral overlays — MRF-482
Developer duties
The transparency package, update notices, and the developer record clock — MRF-483, MRF-484
Deployer duties and consumer rights
Pre-use notice, 30-day disclosures, correction and human review, records, liability allocation — MRF-485–488, ORF-486
Operationalizing in Modulos
The MFF-28 / OFF-28 rollout: mapping tables, new controls, ADMT Role tag, sequence, and watch
Frequently asked questions about Colorado SB 26-189
What is Colorado SB 26-189?
Colorado Senate Bill 26-189 (2026, Session Law chapter 131), signed May 14, 2026, is Colorado's current law on automated decision-making technology (ADMT) used to materially influence consequential decisions. It repealed and reenacted part 17 of article 1 of title 6 of the Colorado Revised Statutes, replacing the 2024 Colorado AI Act (SB 24-205) before that act ever applied. The reenacted part requires developers to give deployers a transparency package and update notices, requires deployers to give consumers a pre-use notice, post-adverse-outcome disclosures within 30 days, and rights to data correction and meaningful human review, requires both to keep records, and allocates liability under existing anti-discrimination law by relative fault. It takes effect January 1, 2027 and applies to consequential decisions made on or after that date; its rulemaking authorities and certain related provisions took effect on signing. The act has no statutory short title. Colorado AI Act and CAIA commonly refer to the repealed SB 24-205 regime, and Colorado ADMT law is an informal and potentially ambiguous label; literature under those names published before May 2026 describes the repealed statute.
Is the Colorado AI Act (SB 24-205) still in force?
No. SB 24-205, the 2024 Colorado AI Act, was signed May 17, 2024 with an original effective date of February 1, 2026, delayed to June 30, 2026 by SB 25B-004 in the August 2025 special session, and then repealed and reenacted in full by SB 26-189, signed May 14, 2026, before it ever applied. The duties associated with the 2024 act, among them the duty of reasonable care to avoid algorithmic discrimination, the risk-management program, impact assessments, public AI-use statements, principal-reasons explanations, opt-outs, and any NIST- or ISO-based presumption or affirmative defense, are not part of current Colorado law. Guidance written about the Colorado AI Act in 2024 and 2025 describes the repealed statute.
Who is covered by SB 26-189?
Most duties apply to developers and deployers doing business in Colorado of a covered ADMT, meaning automated decision-making technology that is used to materially influence a consequential decision. Separately, § 6-1-1708 imposes duties by sectoral capacity: a non-deemed-compliant insurer must provide the applicable disclosures, a HIPAA covered entity must give patients a general notice of advanced-technology use without a covered-ADMT condition, and a covered entity using a covered ADMT to determine financial-assistance eligibility owes a four-part disclosure. A consequential decision is a decision, determination, or action about a consumer that relates to the provision of, or the consumer's access to, eligibility for, selection for, or compensation for, one of seven covered domains (education, employment, the lease or purchase of residential real estate in Colorado, a financial or lending service, insurance, health-care services, and essential government services and public benefits), or one that relates to differentiated price, cost sharing, compensation, or other material terms in a manner reasonably likely to materially limit, delay, effectively deny, or otherwise fundamentally alter the consumer's access, eligibility, or opportunity for a covered domain, subject to nine enumerated exclusions. The ADMT definition itself excludes a fixed technology list, tools used by an individual solely to summarize, organize, translate, draft, route, or present information for human review of administrative processing, and consumer-facing natural-language technology that is not intended, configured, contracted, advertised, or marketed for consequential decisions and is subject to an acceptable-use policy prohibiting such use. Sectoral overlays apply to insurers, HIPAA covered entities and business associates, FDA-regulated devices, creditors, and FERPA-subject deployers. The developer and deployer roles are not exclusive and can change. Coverage and roles walks through each element.
What must a deployer do under SB 26-189?
Before using a covered ADMT to materially influence a consequential decision, give the consumer a clear and conspicuous notice that the tool was or will be used, with instructions for obtaining further information; a prominent standing public notice at points of consumer interaction satisfies this. Where the decision results in an adverse outcome, provide within 30 days a plain-language description of the decision and the tool's role, instructions and a simple process to request information about the tool and its inputs, and an explanation of the consumer's rights. On request after an adverse outcome, provide instructions for requesting the personal data used in the decision and for correcting factually incorrect or materially inaccurate personal data, and an opportunity for meaningful human review and reconsideration to the extent commercially reasonable. Retain records reasonably necessary to demonstrate compliance for at least three years after the date of each consequential decision. All notices and disclosures must be reasonably accessible to consumers with disabilities and limited English proficiency. Deployer duties and consumer rights has the detail.
What must a developer do under SB 26-189?
On and after January 1, 2027, make available to each deployer of a covered ADMT, in an understandable and trade-secret-protective form, a five-element transparency package: a general statement of intended uses and known harmful or inappropriate uses; the categories of data, including personal data, used to train it, to the extent known; known limitations, risks, and circumstances in which it should not be used; instructions for appropriate use, monitoring, and meaningful human review, where applicable; and the information reasonably necessary for the deployer's own disclosures, with notice to the deployer where information is withheld. Notify each deployer within a reasonable time of material updates, intentional and substantial modifications, and changes to intended use, limitations, or risk mitigation. Retain, for at least three years after each record's creation or longer where applicable state or federal law requires, the records reasonably necessary to demonstrate compliance, including system version identifiers, changelogs, and documentation and notices of material updates provided to deployers. The disclosure duties apply for uses where the ADMT was marketed, advertised, configured, contracted, sold, or licensed to materially influence consequential decisions, and the section applies when the developer creates a covered ADMT for such use or becomes aware of consistent consequential-decision use (§ 6-1-1702(5)). Developer duties has the detail.
How is SB 26-189 enforced?
Exclusively by the Colorado Attorney General through the Colorado Consumer Protection Act; a violation of part 17 is a deceptive trade practice. Where the Attorney General deems a cure possible, a notice of violation precedes any enforcement action and the developer or deployer has 60 days to cure; a cure period is not required where the Attorney General can demonstrate a knowing or repeated violation. The cure-and-reporting subsection is repealed effective January 1, 2030. The act creates no new private right of action and does not limit existing rights and remedies under other law, and compliance with part 17 is not a defense to and does not excuse noncompliance with any other applicable law. Two mandatory Attorney General rulemakings, on the post-adverse-outcome disclosures and on the consumer rights, are due on or before January 1, 2027.
How does Modulos model Colorado SB 26-189?
As two paired templates carrying the Regulation label (templates 1.0.30). MFF-28 assesses one covered ADMT across 7 requirements (MRF-482 through MRF-488): coverage and role determination, the developer transparency package, developer update notices and records, the pre-use notice at points of consumer interaction, the post-adverse-outcome and sectoral disclosures, consumer correction and meaningful human review, and deployer compliance records with their liability-evidence dimension. OFF-28 covers the organization across 5 requirements (ORF-483 through ORF-487): notice and disclosure infrastructure with the accessibility duty, the meaningful-human-review capability, the deployer records program, liability posture and contract hygiene, and the Colorado rulemaking and codification watch. Together they map to 13 distinct controls: 12 new controls (MCF-688 through MCF-694 and OCF-380 through OCF-384) and one shared control, MCF-171, also mapped by the EU AI Act and NIST AI RMF templates. An ADMT Role tag (Developer, Deployer) marks the developer and deployer branches; the roles are not exclusive, and MRF-485 and MRF-486 also carry direct HIPAA covered-entity duties (and MRF-486 the insurer fallback) that the role tags do not encode. The framework will be updated when the mandatory Attorney General rules are adopted.
Source attribution
This page summarizes Colorado Senate Bill 26-189 (2026, Session Law ch. 131), enrolled act, reenacting C.R.S. §§ 6-1-1701–1709 and adding §§ 6-1-105(1)(uuuu) and 10-3-1104.9(3)(e); the legislative history draws on the signed acts SB 24-205 (2024), SB 25B-004 (2025), and HB 26-1263 (2026, Session Law ch. 208). Colorado session laws are public domain; quoted passages are verbatim from the enrolled acts. Section citations follow the SB 26-189 enrolled act; part 17's final codified disposition is pending. Requirement and control codes (MFF-28, OFF-28, MRF-, ORF-, MCF-, OCF-) are Modulos template identifiers, not references used by the act.
Disclaimer
This page is for general informational purposes and does not constitute legal advice. SB 26-189 takes effect January 1, 2027, and the mandatory Attorney General rules under §§ 6-1-1704(4) and 6-1-1705(3) had not been adopted when this page was written; statements about them describe open regulatory events. Compliance with part 17 is not a defense to any other law. Always verify against the current published text and consult qualified advisers.