Skip to content

Deployer duties and consumer rights

The deployer's duties run as one sequence for the consumer: a pre-use notice that a covered ADMT is in play (§ 6-1-1704(1)–(2)); after an adverse outcome, disclosures within 30 days (§ 6-1-1704(3)); on request, correction of inaccurate personal data and meaningful human review (§ 6-1-1705); and throughout, records for at least three years per decision (§ 6-1-1703) that double as the evidence the liability-allocation rules of § 6-1-1707 make decisive. MFF-28 carries these as MRF-485 through MRF-488 (ADMT Role: Deployer); the organization framework's ORF-486 carries the liability posture. Section citations follow the enrolled act.

Pending Attorney General rules

Two rulemakings that will add detail to this page are mandatory and due on or before January 1, 2027, the act's effective date: rules clarifying and implementing the post-adverse-outcome disclosures (§ 6-1-1704(4)) and rules clarifying and implementing the consumer-rights section (§ 6-1-1705(3)). Both authorities took effect on signing. Until the rules are adopted, MRF-486 and MRF-487 state the statutory minimum and flag the pending rules; the framework and this page will be updated when the rules are adopted.

Pre-use notice at points of consumer interaction — MRF-485

Prior to a deployer using a covered ADMT to materially influence a consequential decision, the deployer shall provide a clear and conspicuous notice to a consumer that the deployer used or will use a covered ADMT in a consequential decision affecting the consumer and instructions regarding how the consumer may obtain the additional information described in this section.

The standing-notice route (§ 6-1-1704(2)): a deployer complies by maintaining a prominent public notice that is reasonably accessible at points of consumer interaction, including through a link or posting reasonably proximate to the interaction or transaction in which a consequential decision may occur. One prominent, reasonably proximate public notice covers ongoing use; per-consumer notice is not required where the standing notice qualifies. "Reasonably proximate" ties the notice to the interaction in which the decision may occur; a buried site-wide footer is a weak claim.

Accessibility (§ 6-1-1704(8)): every notice and disclosure required by part 17, for deployers and developers alike, must be provided in a manner reasonably accessible to consumers with disabilities and consumers with limited English proficiency, consistent with applicable state and federal law.

Education (§ 6-1-1704(9)): a FERPA-subject deployer satisfies the section's notice and disclosure duties through FERPA-consistent processes and channels, including notice to a parent, guardian, or eligible student, without a separate duplicative process.

HIPAA covered entities carry a distinct duty (§ 6-1-1708(3)(c)): "A covered entity shall provide patients with a general notice of use of advanced technologies, including a covered ADMT. The notice may be incorporated with other notices describing patient rights and how the covered entity provides care." This binds the covered entity directly, is not an instance of the pre-use notice, and has no pre-use or point-of-interaction condition; for the covered entity's exempt practice it is the standalone notice, while the pre-use notice still applies to its employment uses.

The requirement is carried by the new control MCF-691 (Pre-use ADMT notice at interaction points): placement, prominence, proximity, accessibility, and the covered-entity general notice where applicable. The shared control MCF-171 (Transparent Automated Decision-Making) supports it with the framework-agnostic practice of telling people an automated tool participates in decisions about them; the Colorado mechanics stay in the requirement and in MCF-691.

Post-adverse-outcome and sectoral disclosures — MRF-486

If a deployer uses a covered ADMT to materially influence a consequential decision that results in an adverse outcome for a consumer, the deployer shall provide within thirty days after making the decision:

PartContent (§ 6-1-1704(3))
(a)A plain-language description of the consequential decision and the role the covered ADMT played in it
(b)Instructions and a simple-to-follow process to request additional information about the covered ADMT and the inputs, including the name of the covered ADMT, its version number if applicable, its developer, and the types, categories, and sources of personal data used, to the extent the deployer receives the necessary information from the developer in compliance with § 6-1-1702
(c)An explanation of the consumer rights described in § 6-1-1705 and how to exercise them

Adverse outcome (§ 6-1-1701(1)): a decision that denies, terminates, revokes, or materially reduces or restricts a consumer's access to, eligibility for, selection for, compensation for, or the provision of an opportunity or service; or one resulting in materially less favorable differentiated price, cost, compensation, or other material terms that are reasonably likely to materially limit, delay, or effectively deny, or otherwise fundamentally alter, the consumer's access to, eligibility for, selection for, compensation for, or the provision of an opportunity or service compared to terms offered to similarly situated consumers.

Limits and branches around the disclosure:

  • Trade secrets (§ 6-1-1704(5)): nothing requires disclosing a trade secret or legally protected information; a deployer that withholds information on that basis shall notify the consumer. Withholding is a permission with a notice attached, not a duty.
  • Federal-law and program limits (§ 6-1-1704(7)): part 17 does not require a disclosure that federal law prohibits or that would compromise the confidentiality or integrity of cybersecurity, fraud-prevention, anti-money-laundering, counter-terrorist-financing, or sanctions-compliance programs required by law.
  • GLBA (§ 6-1-1708(6)): part 17 does not require disclosure of nonpublic personal information in a manner that would violate the Gramm-Leach-Bliley Act or its implementing regulations.
  • Accessibility (§ 6-1-1704(8)) applies to these disclosures as to all part 17 notices.

The sectoral routes:

ActorRouteRule
CreditorsThe ECOA / Regulation B (and, where applicable, FCRA) adverse-action notice for the same decision discharges the Colorado duty only if it also satisfies the Colorado requirements; the federal notice may include a brief statement that a covered ADMT was used and instructions for obtaining additional information or exercising rights§ 6-1-1704(6): conditional satisfaction, not deemed compliance; federal compliance alone is insufficient
InsurersAn insurer deemed compliant through C.R.S. § 10-3-1104.9 owes no part 17 disclosure in the practice of insurance; an insurer not deemed compliant "shall" provide the § 6-1-1704(3) disclosures, to the extent applicable§ 6-1-1708(1)(a)–(b)
HIPAA covered entities using a covered ADMT for financial-assistance eligibility, including discounted careA four-part disclosure of their own: a plain-language description of the decision and the ADMT's role; the types of information relied upon (except trade secrets and other confidential or legally protected information); how to request correction of materially inaccurate personal data consistent with HIPAA and C.R.S. § 25.5-3-502; and how to request meaningful human review or reconsideration, where applicable. Delivered by an advance general disclosure or a notice within thirty calendar days after an adverse outcome; no separate duplicative process where existing review opportunities and information cover it§ 6-1-1708(3)(d)–(e); binds the covered entity directly
FERPA-subject education deployersFERPA-consistent channels§ 6-1-1704(9)
Federal health-privacy conflictsWhere compliance with § 6-1-1704 or § 6-1-1705 would conflict with federal health-privacy requirements, the deployer complies with federal law and provides disclosures and access consistent with that law§ 6-1-1708(5)

The requirement is carried by the new control MCF-692 (Post-adverse-outcome disclosures): the 30-day clock, the three content elements, the withholding-with-notice mechanic, and the routing of each adverse outcome to the statutorily applicable path. No existing control carries a timed post-decision disclosure of this shape.

Consumer correction and meaningful human review — MRF-487

When a consumer experiences an adverse outcome resulting from a consequential decision in which a covered ADMT materially influences the consequential decision, the consumer may request and the deployer shall provide in response to the request:

  • (I) instructions for requesting personal data and correcting factually incorrect or materially inaccurate personal data used in a consequential decision that used a covered ADMT, consistent with C.R.S. § 6-1-1306; and
  • (II) an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable.

Three boundaries (§ 6-1-1705(1)(b)–(c)):

  • The correction right is broadened: the exceptions to the Colorado Privacy Act's consumer definition (§ 6-1-1303(6)(b)) and the exemptions in § 6-1-1304(2)(k), (2)(n), and (2)(o) do not apply to it, so employees and applicants are inside it.
  • No correction of opinions, predictions, scores, or protected evaluations.
  • "To the extent commercially reasonable" qualifies the review-and-reconsideration opportunity, not the correction instructions; a refusal should rest on a documented commercial-reasonableness judgment.

The reviewer test (§ 6-1-1701(15)), verbatim:

“Meaningful human review” means review by a individual designated by the deployer who has authority to approve, modify, or override a consequential decision and who: (a) considers relevant, available primary evidence; (b) is trained to conduct the review; (c) does not default to the system output; and (d) has access to sufficient information to understand: (I) the output's: (A) intended use; (B) material limitations; and (C) categories of inputs; and (II) the principal factors used to generate the output, without requiring disclosure of proprietary source code, model weights, or other trade secrets.

Authority is the hard limb: a reviewer who can only recommend does not satisfy the definition. "Does not default to the system output" is an operating practice to be made observable (reversal and modification statistics, documented reasoning per review, case-level primary-evidence records). The information-access limb is fed per tool by the developer's transparency package.

FERPA (§ 6-1-1705(2)): a FERPA-subject deployer complies through its existing student-record inspection, review, and amendment procedures and applicable complaint or appeal processes, if it offers a reasonable mechanism for correction of materially inaccurate personal data and reconsideration where applicable. Federal health-privacy conflicts (§ 6-1-1708(5)) resolve in favor of federal law with disclosures and access consistent with it.

What this is not: there is no general appeal right, no explanation-of-principal-reasons duty, and no opt-out; those concepts belonged to the repealed 2024 act. The rights here are the correction route and the commercially reasonable human-review opportunity, triggered by an adverse outcome and a request.

The requirement is carried by the new control MCF-693 (Consumer correction and human-review handling): request intake, correction routing to whoever holds the inaccurate personal data, reviewer assignment against the ¶ 15 test, and the reconsideration record. The organization-level capability behind it (trained reviewer pool, authority, information access) is OCF-381 under ORF-484.

Deployer compliance records and liability evidence — MRF-488

A deployer shall retain, for not less than three years after the date of a consequential decision or for a longer period if required by applicable state or federal law, records reasonably necessary to demonstrate compliance with this part 17. Records may include, as applicable, covered ADMT version identifiers, changelogs, and documentation of material mitigation changes.

The clock is a rolling, per-decision minimum: each consequential decision starts its own three-year period, extended by any longer applicable retention law. It differs from the developer's from-creation clock in MRF-484. The statute's record list is illustrative ("may include, as applicable"); what demonstrates compliance also includes the notice, disclosure, correction, and human-review records that an Attorney General action would test.

The liability dimension (§ 6-1-1707) is why the record set is larger than a retention schedule. In a state anti-discrimination action arising from a consequential decision materially influenced by a covered ADMT, fault is allocated among deployers and developers by relative fault; a developer is liable only to the extent its covered ADMT was used in a manner that was intended, documented, marketed, advertised, configured, or contracted for by the developer and materially influenced the decision; the deployer's independent acts remain its own, including off-envelope use of a tool whose developer complied with § 6-1-1702. What decides those questions is evidence this requirement retains: which version materially influenced which decision, the developer's representations across all six envelope verbs (from the MRF-483 package and MRF-484 notices), the deployment configuration and actual manner of use, and the basis for material influence.

The requirement is carried by the new control MCF-694 (ADMT compliance records and traceability): the per-decision record set, the retention clock, and version-to-decision traceability, use-envelope capture, and deployment-manner documentation. The organization-level records program behind it is OCF-382 under ORF-485.

Liability allocation and contract hygiene — § 6-1-1707 and ORF-486

The organization framework's ORF-486 (ADMT liability posture and contract hygiene, both ADMT Roles) carries the enterprise side of § 6-1-1707:

  • Exposure (§ 6-1-1707(1)–(2)): a developer or deployer may be held liable in an action alleging unlawful discrimination under state anti-discrimination laws, including the Colorado Anti-Discrimination Act, arising from a consequential decision materially influenced by a covered ADMT; fault is allocated by relative fault; no joint-and-several liability is created beyond existing law (§ 6-1-1707(4)).
  • Developer limits (§ 6-1-1707(5)–(6)): liability only for use within the six-verb envelope that materially influenced the decision; the deployer's liability for its independent acts is preserved.
  • Void indemnification (§ 6-1-1707(7)(a)), verbatim:

Notwithstanding any other provision of law, if a provision of a contract for the use of automated decision-making technology in making a consequential decision or any other contract between a developer and deployer purports to indemnify, defend, or hold harmless or has the effect of indemnifying, defending, or holding harmless the indemnitee from or against any liability for damages pursuant to this section resulting from the developer's or deployer's own acts or omissions related to the use of automated decision-making technology in making consequential decisions in violation of the “Colorado Anti-Discrimination Act”, parts 3 to 8 of article 34 of title 24, or other Colorado anti-discrimination law, the provision is contrary to public policy and void.

The prohibition does not apply to a developer for off-envelope use where the developer complied with § 6-1-1702 (§ 6-1-1707(7)(b)); it does not limit commercial contract terms otherwise (§ 6-1-1707(7)(c)); and it does not prohibit insurance claims (§ 6-1-1707(7)(d)).

  • No defense (§ 6-1-1707(8)–(9), § 6-1-1709(2)): compliance with part 17 is not a defense to and does not excuse noncompliance with any applicable law; use of an ADMT excuses no obligation under state or federal law.

What an organization can actually do: it cannot change the allocation rules, but it controls the inputs. Contract clauses are reviewed against § 6-1-1707(7) before signature; procurement records capture the developer's representations across all six envelope verbs; deployments stay in-envelope or the departure and its risk acceptance are documented; insurance arrangements and claims are unaffected (§ 6-1-1707(7)(d)), and other commercial terms remain enforceable subject to applicable law (§ 6-1-1707(7)(c)). Developers face the mirror image: their liability turns on their own representations, so the marketing, documentation, configuration, and contracting of a covered ADMT are liability-shaping acts. The act attaches no evidentiary presumption or defense to any governance framework or program; nothing in the requirement or its control may be read as reducing exposure by itself.

ORF-486 is carried by the new control OCF-383 (ADMT liability posture and contract hygiene); the decision-level evidence lives app-side in MCF-694.

The four deployer duties side by side

Pre-use notice (MRF-485)Post-adverse-outcome disclosures (MRF-486)Correction and human review (MRF-487)Records (MRF-488)
TriggerBefore use to materially influence a consequential decisionAdverse outcomeAdverse outcome plus consumer requestEach consequential decision
TimingPrior to use; standing notice covers ongoing useWithin 30 days after the decisionOn requestAt least 3 years after each decision
ContentCovered ADMT used or will be used; how to get more informationDecision and tool's role; tool-information request process; rights explanationCorrection instructions; meaningful human review to the extent commercially reasonableRecords reasonably necessary to demonstrate compliance; may include, as applicable, version identifiers, changelogs, and material-mitigation documentation; MCF-694 additionally captures the use envelope, deployment manner, and notice, disclosure, and request records where needed to demonstrate compliance
Sectoral routesFERPA channel; the separate covered-entity general notice for the exempt covered practice (not a route for satisfying the pre-use duty)Creditor conditional satisfaction; insurer deemed compliance or fallback; covered-entity four-part route; FERPA; HIPAA/GLBA limitsFERPA; federal health-privacy conflicts
ControlMCF-691 (+ MCF-171)MCF-692MCF-693MCF-694

Where to go next

Disclaimer

This page is for general informational purposes and does not constitute legal advice. The mandatory Attorney General rules under §§ 6-1-1704(4) and 6-1-1705(3) had not been adopted when this page was written; section citations follow the SB 26-189 enrolled act, and part 17's final codified disposition is pending. Compliance with part 17 is not a defense to any other law. Always verify against the current published text and consult qualified advisers.