Colorado’s SB 189: A Law Rewritten to Disclose Rather Than Decide

METHODS · WORKING PAPER — Governance. Empirical and analytical. All claims are anchored to dated, citable events as of July 2026. The forward-looking reading of the pattern described here is kept in the Futures strand (see Signposts, Dial 6 — The Deadline); this paper does not forecast.

Colorado’s SB 189: A Law Rewritten to Disclose Rather Than Decide

Colorado repealed its risk-based AI law before it ever took effect and replaced it, in May 2026, with a narrower regime built on disclosure and consumer rights. The obligations that would have imposed a substantive standard on the decision itself — a duty of reasonable care against algorithmic discrimination, mandatory risk-management programmes, and impact assessments — were removed. The obligations that make an automated decision visible and contestable — pre-use notice, an adverse-outcome explanation, a right to correct one’s data, and a right to human review — survived. The pattern is precise and worth naming: the duties that make AI visible were kept; the duties that would make a decision accountable were dropped. And, in an unusual second movement, the surviving accountability core is simultaneously under federal constitutional attack.

This paper sets out what changed, reads the change through the Institute’s admissibility lens, and marks what remains unsettled. It takes no position on the constitutional merits of the litigation it describes; its interest is structural.

What the 2024 law was going to require

Colorado’s original AI Act, SB 24-205, was signed on 17 May 2024 as the first broad state AI statute in the United States. It regulated “high-risk artificial intelligence systems” used in “consequential decisions” and turned on a substantive duty: developers and deployers had to use reasonable care to protect consumers from algorithmic discrimination. Around that duty sat a machinery of anticipation — mandatory risk-management programmes, impact assessments, disclosures to the Attorney General, and consumer notice and appeal rights, all enforced by the AG under the Colorado Consumer Protection Act.

It never took effect. Its original February 2026 start date was pushed to 30 June 2026 by a special-session bill, and Governor Polis had signed it in 2024 with open reservations, asking the legislature to revisit it. By early 2026 it was, in the words of its own sponsors and the Governor, a law widely agreed to need fixing before it could be implemented.

What SB 189 kept, and what it dropped

Signed on 14 May 2026 and effective 1 January 2027, SB 189 repealed and re-enacted the 2024 framework. It pivots from regulating “high-risk AI systems” to regulating “covered automated decision-making technology” (ADMT) — technology that processes personal data and computes an output (a prediction, score, ranking, classification, or recommendation) used to materially influence a consequential decision. The reach is, in places, wider than what it replaced: the ADMT definition requires no inference, it expressly pulls in employees and Colorado job applicants, and it drops the conditional exemptions the 2024 law had granted some federally regulated entities. Narrower in machinery does not mean narrower in scope.

SB 24-205 (2024, never in force)SB 189 (effective 1 Jan 2027)
Governing conceptHigh-risk AI systemCovered ADMT materially influencing a consequential decision
Core dutyReasonable care against algorithmic discriminationNone equivalent — no substantive decision standard
Risk-management programmeRequiredRemoved
Impact assessmentsRequired (annual)Removed
Reporting to the AGRequired (discrimination)Removed
Pre-use consumer noticeRequiredKept (clear and conspicuous, before the decision)
Adverse-outcome disclosureRequiredKept (plain-language, within 30 days)
Data correction rightRequiredKept
Human review of adverse outcomesRequiredKept — with a demanding definition (below)
Record retention3 years (developers and deployers)
EnforcementAG only, via CCPAAG only, via CCPA; no private right of action
Cure period60 days, unless knowing/repeated; sunsets 1 Jan 2030
RulemakingPermissiveMandatory, by 1 Jan 2027

Read down the “core duty” and “risk-management / impact assessment” rows, then down the “notice / disclosure / correction / review” rows. Everything in the first set was removed. Everything in the second set was kept. The law did not shrink evenly; it shed one kind of obligation and retained another.

What kind of obligation survived, and what kind did not

The distinction the two sets fall along is the one the Institute tracks. A decision-accountability obligation imposes a standard on the decision itself and requires you to demonstrate, before deployment, that the system meets it: the duty of care, the risk-management programme, the impact assessment. A disclosure obligation governs what you must tell people around the decision: that an automated system was used, what it did, and how to see or contest your data. The first asks whether the decision should have been made this way. The second asks only whether you were told about it.

SB 189 removed the first kind entirely and kept the second. A covered ADMT may now enter a consequential decision — about a job, a loan, a tenancy, a benefit — carrying notice-and-explanation duties but no prior obligation to show that it decides acceptably. Colorado did not deregulate so much as change the kind of thing it regulates: from the quality of the decision to the visibility of it. That is not a smaller version of the 2024 law. It is a different instrument aimed at a different target.

The one place substance survived: meaningful human review

One thread of decision-accountability did carry over, and it is worth isolating because it is the exception that shows the rule. SB 189’s right to “meaningful human review” of an adverse outcome comes with a demanding statutory definition: the reviewer must be trained, must have authority to approve, modify, or override the decision, and must not simply default to the system’s output. A recruiter who ratifies an automated ranking without genuine deliberation does not satisfy it.

On paper, that is a real standard — this is Dial 2 of the Signposts, the human at the point of decision, written into a statute. But its force is suspended between two qualifiers. The right runs only “to the extent commercially reasonable” and where review is “technically feasible,” and the content of the surrounding disclosures, along with the meaning of “materially influence,” is left to Attorney General rulemaking due by January 2027. Whether this clause reads as genuine override authority or as a documented formality will be decided not by the statute but by the rules written under it. The Institute’s reading is that this single clause is where Colorado’s regime will be won or lost on the accountability side — and that it currently sits, undetermined, between the two.

The second movement: the accountability core is also under constitutional attack

The legislative rewrite did not happen in isolation. On 9 April 2026, xAI filed suit in federal court to enjoin SB 24-205 before its effective date, on four constitutional theories: compelled speech under the First Amendment, extraterritorial reach under the Commerce Clause, vagueness under the Due Process Clause, and an Equal Protection challenge to the law’s carve-out for diversity-promoting uses. On 24 April, the U.S. Department of Justice intervened in support, focused on Equal Protection — the first time the federal government sought to invalidate a state AI law — acting on a December 2025 executive order that directed the DOJ to establish a task force to challenge state AI statutes. On 27 April, the court stayed enforcement, and the Attorney General agreed not to enforce, including opening no investigations, until fourteen days after a ruling on xAI’s forthcoming preliminary-injunction motion.

The Institute takes no position on whether these constitutional claims are sound; that is a question for the courts. The structural observation is narrower and, for present purposes, sufficient: both the challenge and the intervention are aimed at the same component — the anti-discrimination duty, the substantive standard on the decision — and not at the disclosure layer. The state’s defenders held that the duty was ordinary civil-rights protection applied to automated systems, and that the law expressly permitted diversity-promoting uses; the challengers held that it compelled protected speech and demographic-conscious engineering. Whatever the merits, the target is the accountability core. So the legislative rewrite and the federal litigation converge: the part of the law that would let someone challenge a discriminatory automated decision is the part that was legislated out, and the part that survived is being litigated against — while the transparency layer draws no comparable fire.

Reading it through admissibility

In the Institute’s terms, admissibility is the pre-runtime, record-based decision about whether a system may enter a consequential decision chain at all — the standing test that comes before deployment. SB 189 builds part of the record substrate for such a test: it requires three years of compliance records and developer documentation of intended uses, training-data categories, and limitations. In that narrow sense, the principle no record, no standing survives — records must be kept.

But the substantive gate is gone. Under the 2024 law, a high-risk system faced a pre-deployment demand: assess your risks, manage them, show reasonable care. Under SB 189 there is no such precondition. A covered ADMT is admitted to the decision chain on the strength of disclosure obligations alone; nothing requires a prior demonstration that it decides adequately. Admission now turns on notice, not on standing. The record is kept, but it no longer has to establish anything before the system acts — only document what it did after.

What SB 189 does not settle

Three things remain open, and honest analysis has to hold them open. First, the Attorney General’s mandatory rulemaking, due by January 2027, will define “materially influence,” the content of the required notices, and the boundaries of the human-review right — the provisions on which the regime’s real force depends. Second, the enforcement posture is contingent: the stay agreed in the xAI litigation extends to SB 189, and the federal preemption question is unresolved, so the January 2027 date is the operative target but not a settled one. Third, none of this displaces existing law: discrimination claims arising from AI-assisted decisions remain actionable under other state and federal statutes regardless of what SB 189 does. The law’s shape is clear; its ultimate force is not yet fixed.

FAQ

Did Colorado repeal its AI law, or amend it?
It repealed and re-enacted it. SB 24-205 was replaced in full by SB 189 before the original ever took effect. The governing concept changed from “high-risk AI system” to “covered ADMT,” and the core duty of care was removed rather than adjusted.

Is SB 189 weaker than the law it replaced?
On decision-accountability, yes — the duty of care, risk-management programmes, and impact assessments are gone. On reach, not uniformly: SB 189’s ADMT definition is broad, it covers employees and applicants, and it drops some exemptions the 2024 law had. It is a shift in the kind of obligation, not simply a reduction.

What is the difference between a disclosure duty and a decision-accountability duty?
A disclosure duty governs what you must tell people about an automated decision. A decision-accountability duty imposes a standard on the decision itself and requires you to show, before deploying, that it is met. SB 189 kept the first and dropped the second.

Does SB 189 take effect on 1 January 2027?
That is the operative date, but it is contingent. Enforcement is stayed pending the xAI litigation, mandatory rulemaking is still to come, and the federal preemption question is unresolved.



Synthocracy Institute — Power & Accountability When AI Co-Decides