Appearance
Operationalizing Colorado SB 26-189 in Modulos
Modulos ships SB 26-189 as a paired framework (templates 1.0.30): MFF-28 produces the per-tool evidence for one covered ADMT, and OFF-28 establishes the organization's repeatable capabilities once. Both carry the Regulation label and the colorado-sb189.svg icon. Section citations follow the enrolled act; part 17's final codified disposition is pending, and the framework will be updated when it is published.
Project structure
| Template | Project type | Scope | Requirements | Distinct Controls |
|---|---|---|---|---|
MFF-28 — Colorado SB 26-189 | AI application | One covered ADMT, in the developer role, the deployer role, or both | 7 (MRF-482–MRF-488) | 8 (7 new + MCF-171) |
OFF-28 — Colorado SB 26-189 | Organization | The organization's notice, review, records, liability, and watch capabilities | 5 (ORF-483–ORF-487) | 5 (all new) |
One MFF-28 project per covered ADMT. The coverage determination, the developer package received or provided, the notices, the disclosures, and the per-decision records are all tool-specific. The two templates' control sets do not overlap, so together the 12 requirements map to 13 distinct controls: 12 new and 1 shared. There is no scoping questionnaire; MRF-482 records the coverage and role determination inside the project.
The ADMT Role tag
Template version 1.0.30 adds one tag category, ADMT Role, with two values, attached directly to the requirements:
- Developer — a person doing business in Colorado that develops, offers, sells, leases, licenses, or otherwise makes commercially available a covered ADMT; develops a component designed, marketed, intended, documented, advertised, configured, or contracted to be used as part of one; or intentionally and substantially modifies an ADMT such that it becomes covered (§ 6-1-1701(8)).
- Deployer — a person doing business in Colorado that deploys a covered ADMT (§ 6-1-1701(7)).
The roles are deliberately non-exclusive: an organization can hold both for the same tool, and a deployer that intentionally and substantially modifies an ADMT into a covered ADMT becomes its developer. Filter a project by role to see the developer or deployer branch; MRF-482, ORF-486, and ORF-487 carry both tags. The tags do not encode every sectoral capacity: MRF-485 and MRF-486 also carry direct HIPAA covered-entity duties under § 6-1-1708(3)(c)–(e), and MRF-486 the insurer fallback under § 6-1-1708(1)(b); review those branches regardless of the role filter.
The application framework — MFF-28
| Requirement | Legal anchor (enrolled act) | ADMT Role | Mapped controls |
|---|---|---|---|
MRF-482 — ADMT coverage and role determination | § 6-1-1701 (¶¶ 2–8, 12–14); § 6-1-1708; Section 5 | Developer, Deployer | MCF-688 |
MRF-483 — Developer transparency package to deployers | § 6-1-1702(1), (3), (5) | Developer | MCF-689 |
MRF-484 — Developer update notices and records | § 6-1-1702(2)–(5); § 6-1-1701(12), (14) | Developer | MCF-690 |
MRF-485 — Pre-use notice at points of consumer interaction | § 6-1-1704(1)–(2), (8)–(9); § 6-1-1708(3)(c) | Deployer (also carries the direct covered-entity notice) | MCF-691, MCF-171 |
MRF-486 — Post-adverse-outcome and sectoral disclosures | § 6-1-1704(3), (5)–(9); § 6-1-1708(1)(b), (3)(d)–(e), (5)–(6) | Deployer (also carries the insurer fallback and the direct covered-entity disclosure) | MCF-692 |
MRF-487 — Consumer correction and meaningful human review | § 6-1-1705; § 6-1-1701(15); § 6-1-1708(5) | Deployer | MCF-693 |
MRF-488 — Deployer compliance records and liability evidence | § 6-1-1703; § 6-1-1707 | Deployer | MCF-694 |
Each requirement's detail content carries the source list, the obligations addressed with the operative statutory text quoted verbatim, the key concepts, and a modeling note stating why the mapped control is new. MRF-486 and MRF-487 flag the pending Attorney General rules with watch markers (CO-WATCH-AG-1704-RULES, CO-WATCH-AG-1705-RULES).
The organization framework — OFF-28
| Requirement | Legal anchor (enrolled act) | ADMT Role | Mapped controls |
|---|---|---|---|
ORF-483 — Consumer notice and disclosure infrastructure | § 6-1-1704(1)–(2), (8) | Deployer | OCF-380 |
ORF-484 — Meaningful-human-review capability | § 6-1-1701(15); § 6-1-1705(1)(a)(II) | Deployer | OCF-381 |
ORF-485 — Deployer records program | § 6-1-1703 | Deployer | OCF-382 |
ORF-486 — ADMT liability posture and contract hygiene | § 6-1-1707; § 6-1-1709 | Developer, Deployer | OCF-383 |
ORF-487 — Colorado rulemaking and codification watch | § 6-1-1704(4); § 6-1-1705(3); § 6-1-1706(3), (5); § 10-3-1104.9(3)(e); codification of part 17 | Developer, Deployer | OCF-384 |
ORF-487 is framed in its own text as a supporting readiness practice, not a statutory duty: its anchors bind the Attorney General and the insurance commissioner, not the customer. It exists so the organization is ready to apply the rules when adopted, which may be as late as the day the act takes effect.
The 12 new controls
All twelve carry the tag Framework: Specific; the application controls are Scope: Project, the organization controls Scope: Organization. Each has a guidance component (what the law requires, key considerations, what would fail the control, relationships to other controls, and the evidence an auditor expects), an evidence upload, and a report template.
| Control | Carries |
|---|---|
MCF-688 — ADMT coverage and role determination | The documented, current conjunctive determination: ADMT, exclusions, material influence, consequential decision, covered domain, sectoral overlays, roles; re-run on modification, new deployment, or awareness of consequential-decision use |
MCF-689 — Developer ADMT transparency package | When § 6-1-1702(5) applies, the five-element package made available to each deployer for the uses § 6-1-1702(3) covers, in an understandable, trade-secret-protective form, with notice of any withheld information |
MCF-690 — Developer update notices and records | Notice within a reasonable time of material updates, intentional and substantial modifications, and changes to intended use, limitations, or risk mitigation, for the uses subsection (3) specifies, directly or via release notes plus direct notice; developer records for three years from each record's creation |
MCF-691 — Pre-use ADMT notice at interaction points | The clear and conspicuous notice as a prominent standing notice reasonably proximate to each point of consumer interaction, accessible; the covered-entity general advanced-technology notice where applicable |
MCF-692 — Post-adverse-outcome disclosures | The three-part disclosure within 30 days of the decision, withholding with notice, and routing of each adverse outcome to the statutorily applicable path (creditor conditional satisfaction, insurer deemed compliance or fallback, covered-entity four-part route, FERPA channel) |
MCF-693 — Consumer correction and human-review handling | Correction instructions on request (reaching employees), the meaningful-human-review opportunity to the extent commercially reasonable by a reviewer meeting the ¶ 15 test, and the boundary for opinions, predictions, scores, and protected evaluations |
MCF-694 — ADMT compliance records and traceability | The per-decision record set (version, changelogs, mitigation changes, represented use envelope, deployment configuration, notice, disclosure, and request records) for three years from each consequential decision |
OCF-380 — ADMT notice and disclosure infrastructure | The interaction-point inventory with notice placements, governed disclosure templates, delivery channels with tracking, all accessible to consumers with disabilities and limited English proficiency |
OCF-381 — Meaningful-human-review capability | Designated reviewers with authority to approve, modify, or override; training; primary-evidence practice without defaulting to system output; per-tool information access |
OCF-382 — ADMT records program | The rolling per-decision three-year minimum, extended by longer law and holds, with a defined compliance-record scope |
OCF-383 — ADMT liability posture and contract hygiene | Contracts screened against the void-indemnification rule; use-envelope representations captured and deployments reviewed against them with departures documented; other commercial terms preserved subject to applicable law and insurance arrangements and claims unaffected; no defensive credit claimed |
OCF-384 — Colorado rulemaking and codification watch | Ownership of the five watch tracks and routing of each development into the affected templates, procedures, and determinations; enforcement planning reflecting the cure regime and its January 1, 2030 sunset |
Control reuse — deliberately thin
One control is shared: MCF-171 (Transparent Automated Decision-Making), which supports the pre-use notice with the framework-agnostic practice of informing people that an AI system makes or assists decisions about them. On the platform it is also mapped by the EU AI Act (MFF-1) and NIST AI RMF (MFF-3) templates; an AI-application project that already carries one of them and adds MFF-28 keeps that control as one instance, so the Evidence attached to its components serves both frameworks in that project. Separate per-tool projects keep separate control instances and Evidence libraries.
The other 12 of the 13 mapped controls are new in the reviewed platform mapping, because the existing candidates did not align closely enough with the statute's specific content, triggers, clocks, and liability dimensions: a statutory transparency package between developer and deployer, a 30-day post-adverse-outcome disclosure with sectoral routes, a reviewer test for human review, per-decision records that double as fault-allocation evidence, and a void-indemnification rule. Two reuse candidates were considered and rejected: the shared risk-tiering control for the coverage determination (its tiering and impact-assessment vocabulary belongs to the repealed 2024 act) and the general organization-level retention controls for the records program (they govern having a retention policy, not the part 17 rolling per-decision clock). Neither was edited; both remain available in other frameworks.
The watch — five tracks
ORF-487 / OCF-384 own five greppable watch markers, each naming the requirement it feeds:
| Marker | What it watches | Feeds |
|---|---|---|
CO-WATCH-AG-1704-RULES | Mandatory Attorney General rules on the post-adverse-outcome disclosures, due on or before January 1, 2027; they may, as appropriate, address content, sector-specific guidance or examples, role-description standards, and interactions with federal and state notice laws | MRF-486, OCF-380 templates |
CO-WATCH-AG-1705-RULES | Mandatory Attorney General rules on the consumer-rights section, due on or before January 1, 2027 | MRF-487, OCF-381 procedures |
CO-WATCH-AG-MATERIAL-INFLUENCE | Discretionary Attorney General rules clarifying "materially influence" through presumptions, illustrative examples, and objective indicators (§ 6-1-1706(5)) | MRF-482 coverage test |
CO-WATCH-DOI-NOTICE | Insurance commissioner notice-and-disclosure rules for insurers (§ 10-3-1104.9(3)(e)) | Insurer branches of MRF-485, MRF-486 |
CO-WATCH-CRS-CODIFICATION | Final codified disposition of part 17 after HB 26-1263's second § 6-1-1708 | Every citation |
Modulos will update the framework when the mandatory rules are adopted; framework versioning notifies affected projects. The enforcement horizon belongs in readiness planning too: Attorney General enforcement is exclusive, through the Colorado Consumer Protection Act, with a 60-day cure period where cure is deemed possible (not required where a knowing or repeated violation can be demonstrated) and annual public enforcement reporting from January 2028; the cure-and-reporting subsection is repealed on January 1, 2030, after which the cure cushion is gone.
Rollout sequence
- Determine coverage and roles for each tool (
MRF-482): run the conjunctive test, apply the sectoral overlays, record developer, deployer, or both, and set the re-evaluation triggers. - Stand up the organization capabilities (
ORF-483–ORF-485): the interaction-point inventory and accessible notice and disclosure infrastructure; the designated, trained reviewer pool with authority; the records program with its rolling per-decision clock. - Fix the liability posture (
ORF-486): screen ADMT contracts against § 6-1-1707(7), capture developer use-envelope representations, decide the in-envelope discipline, confirm insurance arrangements. - Developer role, per tool (
MRF-483,MRF-484): when § 6-1-1702(5) applies, make the five-element package available and provide update notices for each deployer use § 6-1-1702(3) covers; implement the separate subsection (4) record duty with its from-creation clock. - Deployer role, per tool (
MRF-485–MRF-488): place the standing pre-use notice at every relevant interaction point; wire the 30-day post-adverse-outcome disclosure with its sectoral routing; connect request intake to correction routing and the reviewer pool; capture the per-decision record set with version-to-decision traceability. - Own the watch (
ORF-487): assign the five tracks before January 1, 2027. As each rule is adopted, and when the final codified disposition is published, reconcile the affected notices, templates, procedures, and determinations against the published text; the mandatory rules may arrive as late as January 1, 2027 itself.
Each requirement is evidenced through its linked controls; the Requirement Owner reviews the completed controls and marks the Requirement as Fulfilled.
What the framework deliberately does not include
- Nothing from the repealed 2024 act: no duty-of-care, risk-management-program, impact-assessment, public-statement, principal-reasons, opt-out, or presumption-and-defense machinery. Where a customer's existing program contains those artifacts, they are not Colorado requirements and the framework does not ask for them.
- No governance credit. The act attaches no evidentiary presumption or defense to any framework or program (§ 6-1-1707(8)–(9), § 6-1-1709(2)); the framework makes duties performable and records producible and claims nothing beyond that.
- HB 26-1263's conversational-AI service operator duties, which sit in the same statutory part, with a conditional petition-clause effective date and staggered operative dates, and are a separate regime.
- The C.R.S. § 10-3-1104.9 insurance regime itself; only its interface with part 17 is modeled.
Where to go next
Colorado SB 26-189 overview
The four legislative layers, what the law requires, who is covered, enforcement, and the pending rules
Coverage and roles
The covered-ADMT test, exclusions, seven domains, roles, and sectoral overlays — MRF-482
Developer duties
The transparency package, update notices, and developer records — MRF-483, MRF-484
Deployer duties and consumer rights
Pre-use notice, 30-day disclosures, correction and human review, records, liability — MRF-485–488, ORF-486
Disclaimer
This page is for general informational purposes and does not constitute legal advice. Section citations follow the SB 26-189 enrolled act; part 17's final codified disposition is pending, and the mandatory Attorney General rules had not been adopted when this page was written. Always verify against the current published text and consult qualified advisers.