Skip to content

Operationalizing Colorado SB 26-189 in Modulos

Modulos ships SB 26-189 as a paired framework (templates 1.0.30): MFF-28 produces the per-tool evidence for one covered ADMT, and OFF-28 establishes the organization's repeatable capabilities once. Both carry the Regulation label and the colorado-sb189.svg icon. Section citations follow the enrolled act; part 17's final codified disposition is pending, and the framework will be updated when it is published.

Project structure

TemplateProject typeScopeRequirementsDistinct Controls
MFF-28 — Colorado SB 26-189AI applicationOne covered ADMT, in the developer role, the deployer role, or both7 (MRF-482MRF-488)8 (7 new + MCF-171)
OFF-28 — Colorado SB 26-189OrganizationThe organization's notice, review, records, liability, and watch capabilities5 (ORF-483ORF-487)5 (all new)

One MFF-28 project per covered ADMT. The coverage determination, the developer package received or provided, the notices, the disclosures, and the per-decision records are all tool-specific. The two templates' control sets do not overlap, so together the 12 requirements map to 13 distinct controls: 12 new and 1 shared. There is no scoping questionnaire; MRF-482 records the coverage and role determination inside the project.

The ADMT Role tag

Template version 1.0.30 adds one tag category, ADMT Role, with two values, attached directly to the requirements:

  • Developer — a person doing business in Colorado that develops, offers, sells, leases, licenses, or otherwise makes commercially available a covered ADMT; develops a component designed, marketed, intended, documented, advertised, configured, or contracted to be used as part of one; or intentionally and substantially modifies an ADMT such that it becomes covered (§ 6-1-1701(8)).
  • Deployer — a person doing business in Colorado that deploys a covered ADMT (§ 6-1-1701(7)).

The roles are deliberately non-exclusive: an organization can hold both for the same tool, and a deployer that intentionally and substantially modifies an ADMT into a covered ADMT becomes its developer. Filter a project by role to see the developer or deployer branch; MRF-482, ORF-486, and ORF-487 carry both tags. The tags do not encode every sectoral capacity: MRF-485 and MRF-486 also carry direct HIPAA covered-entity duties under § 6-1-1708(3)(c)–(e), and MRF-486 the insurer fallback under § 6-1-1708(1)(b); review those branches regardless of the role filter.

The application framework — MFF-28

RequirementLegal anchor (enrolled act)ADMT RoleMapped controls
MRF-482 — ADMT coverage and role determination§ 6-1-1701 (¶¶ 2–8, 12–14); § 6-1-1708; Section 5Developer, DeployerMCF-688
MRF-483 — Developer transparency package to deployers§ 6-1-1702(1), (3), (5)DeveloperMCF-689
MRF-484 — Developer update notices and records§ 6-1-1702(2)–(5); § 6-1-1701(12), (14)DeveloperMCF-690
MRF-485 — Pre-use notice at points of consumer interaction§ 6-1-1704(1)–(2), (8)–(9); § 6-1-1708(3)(c)Deployer (also carries the direct covered-entity notice)MCF-691, MCF-171
MRF-486 — Post-adverse-outcome and sectoral disclosures§ 6-1-1704(3), (5)–(9); § 6-1-1708(1)(b), (3)(d)–(e), (5)–(6)Deployer (also carries the insurer fallback and the direct covered-entity disclosure)MCF-692
MRF-487 — Consumer correction and meaningful human review§ 6-1-1705; § 6-1-1701(15); § 6-1-1708(5)DeployerMCF-693
MRF-488 — Deployer compliance records and liability evidence§ 6-1-1703; § 6-1-1707DeployerMCF-694

Each requirement's detail content carries the source list, the obligations addressed with the operative statutory text quoted verbatim, the key concepts, and a modeling note stating why the mapped control is new. MRF-486 and MRF-487 flag the pending Attorney General rules with watch markers (CO-WATCH-AG-1704-RULES, CO-WATCH-AG-1705-RULES).

The organization framework — OFF-28

RequirementLegal anchor (enrolled act)ADMT RoleMapped controls
ORF-483 — Consumer notice and disclosure infrastructure§ 6-1-1704(1)–(2), (8)DeployerOCF-380
ORF-484 — Meaningful-human-review capability§ 6-1-1701(15); § 6-1-1705(1)(a)(II)DeployerOCF-381
ORF-485 — Deployer records program§ 6-1-1703DeployerOCF-382
ORF-486 — ADMT liability posture and contract hygiene§ 6-1-1707; § 6-1-1709Developer, DeployerOCF-383
ORF-487 — Colorado rulemaking and codification watch§ 6-1-1704(4); § 6-1-1705(3); § 6-1-1706(3), (5); § 10-3-1104.9(3)(e); codification of part 17Developer, DeployerOCF-384

ORF-487 is framed in its own text as a supporting readiness practice, not a statutory duty: its anchors bind the Attorney General and the insurance commissioner, not the customer. It exists so the organization is ready to apply the rules when adopted, which may be as late as the day the act takes effect.

The 12 new controls

All twelve carry the tag Framework: Specific; the application controls are Scope: Project, the organization controls Scope: Organization. Each has a guidance component (what the law requires, key considerations, what would fail the control, relationships to other controls, and the evidence an auditor expects), an evidence upload, and a report template.

ControlCarries
MCF-688 — ADMT coverage and role determinationThe documented, current conjunctive determination: ADMT, exclusions, material influence, consequential decision, covered domain, sectoral overlays, roles; re-run on modification, new deployment, or awareness of consequential-decision use
MCF-689 — Developer ADMT transparency packageWhen § 6-1-1702(5) applies, the five-element package made available to each deployer for the uses § 6-1-1702(3) covers, in an understandable, trade-secret-protective form, with notice of any withheld information
MCF-690 — Developer update notices and recordsNotice within a reasonable time of material updates, intentional and substantial modifications, and changes to intended use, limitations, or risk mitigation, for the uses subsection (3) specifies, directly or via release notes plus direct notice; developer records for three years from each record's creation
MCF-691 — Pre-use ADMT notice at interaction pointsThe clear and conspicuous notice as a prominent standing notice reasonably proximate to each point of consumer interaction, accessible; the covered-entity general advanced-technology notice where applicable
MCF-692 — Post-adverse-outcome disclosuresThe three-part disclosure within 30 days of the decision, withholding with notice, and routing of each adverse outcome to the statutorily applicable path (creditor conditional satisfaction, insurer deemed compliance or fallback, covered-entity four-part route, FERPA channel)
MCF-693 — Consumer correction and human-review handlingCorrection instructions on request (reaching employees), the meaningful-human-review opportunity to the extent commercially reasonable by a reviewer meeting the ¶ 15 test, and the boundary for opinions, predictions, scores, and protected evaluations
MCF-694 — ADMT compliance records and traceabilityThe per-decision record set (version, changelogs, mitigation changes, represented use envelope, deployment configuration, notice, disclosure, and request records) for three years from each consequential decision
OCF-380 — ADMT notice and disclosure infrastructureThe interaction-point inventory with notice placements, governed disclosure templates, delivery channels with tracking, all accessible to consumers with disabilities and limited English proficiency
OCF-381 — Meaningful-human-review capabilityDesignated reviewers with authority to approve, modify, or override; training; primary-evidence practice without defaulting to system output; per-tool information access
OCF-382 — ADMT records programThe rolling per-decision three-year minimum, extended by longer law and holds, with a defined compliance-record scope
OCF-383 — ADMT liability posture and contract hygieneContracts screened against the void-indemnification rule; use-envelope representations captured and deployments reviewed against them with departures documented; other commercial terms preserved subject to applicable law and insurance arrangements and claims unaffected; no defensive credit claimed
OCF-384 — Colorado rulemaking and codification watchOwnership of the five watch tracks and routing of each development into the affected templates, procedures, and determinations; enforcement planning reflecting the cure regime and its January 1, 2030 sunset

Control reuse — deliberately thin

One control is shared: MCF-171 (Transparent Automated Decision-Making), which supports the pre-use notice with the framework-agnostic practice of informing people that an AI system makes or assists decisions about them. On the platform it is also mapped by the EU AI Act (MFF-1) and NIST AI RMF (MFF-3) templates; an AI-application project that already carries one of them and adds MFF-28 keeps that control as one instance, so the Evidence attached to its components serves both frameworks in that project. Separate per-tool projects keep separate control instances and Evidence libraries.

The other 12 of the 13 mapped controls are new in the reviewed platform mapping, because the existing candidates did not align closely enough with the statute's specific content, triggers, clocks, and liability dimensions: a statutory transparency package between developer and deployer, a 30-day post-adverse-outcome disclosure with sectoral routes, a reviewer test for human review, per-decision records that double as fault-allocation evidence, and a void-indemnification rule. Two reuse candidates were considered and rejected: the shared risk-tiering control for the coverage determination (its tiering and impact-assessment vocabulary belongs to the repealed 2024 act) and the general organization-level retention controls for the records program (they govern having a retention policy, not the part 17 rolling per-decision clock). Neither was edited; both remain available in other frameworks.

The watch — five tracks

ORF-487 / OCF-384 own five greppable watch markers, each naming the requirement it feeds:

MarkerWhat it watchesFeeds
CO-WATCH-AG-1704-RULESMandatory Attorney General rules on the post-adverse-outcome disclosures, due on or before January 1, 2027; they may, as appropriate, address content, sector-specific guidance or examples, role-description standards, and interactions with federal and state notice lawsMRF-486, OCF-380 templates
CO-WATCH-AG-1705-RULESMandatory Attorney General rules on the consumer-rights section, due on or before January 1, 2027MRF-487, OCF-381 procedures
CO-WATCH-AG-MATERIAL-INFLUENCEDiscretionary Attorney General rules clarifying "materially influence" through presumptions, illustrative examples, and objective indicators (§ 6-1-1706(5))MRF-482 coverage test
CO-WATCH-DOI-NOTICEInsurance commissioner notice-and-disclosure rules for insurers (§ 10-3-1104.9(3)(e))Insurer branches of MRF-485, MRF-486
CO-WATCH-CRS-CODIFICATIONFinal codified disposition of part 17 after HB 26-1263's second § 6-1-1708Every citation

Modulos will update the framework when the mandatory rules are adopted; framework versioning notifies affected projects. The enforcement horizon belongs in readiness planning too: Attorney General enforcement is exclusive, through the Colorado Consumer Protection Act, with a 60-day cure period where cure is deemed possible (not required where a knowing or repeated violation can be demonstrated) and annual public enforcement reporting from January 2028; the cure-and-reporting subsection is repealed on January 1, 2030, after which the cure cushion is gone.

Rollout sequence

  1. Determine coverage and roles for each tool (MRF-482): run the conjunctive test, apply the sectoral overlays, record developer, deployer, or both, and set the re-evaluation triggers.
  2. Stand up the organization capabilities (ORF-483ORF-485): the interaction-point inventory and accessible notice and disclosure infrastructure; the designated, trained reviewer pool with authority; the records program with its rolling per-decision clock.
  3. Fix the liability posture (ORF-486): screen ADMT contracts against § 6-1-1707(7), capture developer use-envelope representations, decide the in-envelope discipline, confirm insurance arrangements.
  4. Developer role, per tool (MRF-483, MRF-484): when § 6-1-1702(5) applies, make the five-element package available and provide update notices for each deployer use § 6-1-1702(3) covers; implement the separate subsection (4) record duty with its from-creation clock.
  5. Deployer role, per tool (MRF-485MRF-488): place the standing pre-use notice at every relevant interaction point; wire the 30-day post-adverse-outcome disclosure with its sectoral routing; connect request intake to correction routing and the reviewer pool; capture the per-decision record set with version-to-decision traceability.
  6. Own the watch (ORF-487): assign the five tracks before January 1, 2027. As each rule is adopted, and when the final codified disposition is published, reconcile the affected notices, templates, procedures, and determinations against the published text; the mandatory rules may arrive as late as January 1, 2027 itself.

Each requirement is evidenced through its linked controls; the Requirement Owner reviews the completed controls and marks the Requirement as Fulfilled.

What the framework deliberately does not include

  • Nothing from the repealed 2024 act: no duty-of-care, risk-management-program, impact-assessment, public-statement, principal-reasons, opt-out, or presumption-and-defense machinery. Where a customer's existing program contains those artifacts, they are not Colorado requirements and the framework does not ask for them.
  • No governance credit. The act attaches no evidentiary presumption or defense to any framework or program (§ 6-1-1707(8)–(9), § 6-1-1709(2)); the framework makes duties performable and records producible and claims nothing beyond that.
  • HB 26-1263's conversational-AI service operator duties, which sit in the same statutory part, with a conditional petition-clause effective date and staggered operative dates, and are a separate regime.
  • The C.R.S. § 10-3-1104.9 insurance regime itself; only its interface with part 17 is modeled.

Where to go next

Disclaimer

This page is for general informational purposes and does not constitute legal advice. Section citations follow the SB 26-189 enrolled act; part 17's final codified disposition is pending, and the mandatory Attorney General rules had not been adopted when this page was written. Always verify against the current published text and consult qualified advisers.