Update: SB 24-205 took effect June 30, 2026 and Colorado’s attorney general now enforces it. Federal preemption efforts may yet change the picture, but as of this update the obligations below are live. The compliance checklist in this article still applies.
On June 30, 2026, Colorado becomes the first state in the country to enforce a comprehensive artificial intelligence law, and thousands of small businesses have no idea it applies to them. The Colorado AI Act (SB 24-205) wasn’t written for tech giants alone. If your business uses AI to help screen job applicants, approve financing, set insurance terms, or make housing decisions about Colorado residents, you may be a “deployer” under the law, with real obligations attached.
The good news: most of the coverage so far has been dense legal memos written for corporate counsel. This guide translates the Colorado AI law into plain English for small business owners, who’s covered, what counts as high-risk AI, what the small business exemption actually exempts, and a practical checklist you can work through before the deadline.
What Is the Colorado AI Law (SB 24-205)?
The Colorado Artificial Intelligence Act, passed as Senate Bill 24-205 and signed by Governor Jared Polis in May 2024, is the first comprehensive state-level AI law in the United States. After amendments and a delayed start date, it takes effect on June 30, 2026.
The law’s core purpose is to prevent algorithmic discrimination, situations where an AI system produces unlawful, biased outcomes in decisions that materially affect people’s lives. Rather than regulating all AI, it zeroes in on “high-risk AI systems” used to make, or substantially help make, what the statute calls consequential decisions.
Two roles carry obligations under the law. Developers are the companies that build or substantially modify high-risk AI systems. Deployers are the businesses that use them. Most small businesses will never be developers, but a surprising number are already deployers without realizing it, because AI features are now baked into everyday hiring platforms, lending software, and tenant-screening tools.
Who Must Comply With the Colorado AI Act?
The law applies to any person or company doing business in Colorado that deploys a high-risk AI system affecting Colorado residents. Three things matter here for small businesses:
- You don’t need to be based in Colorado. If your AI-assisted decisions reach Colorado consumers, employees, or applicants, the law can reach you.
- You don’t need to have built the AI. Using a third-party tool with AI-driven screening or scoring features can make you a deployer.
- Size matters, but less than you’d hope. There is a partial exemption for businesses with fewer than 50 full-time employees, but it’s conditional, not a free pass (more on that below).
If you’ve been weighing whether to hire a person or use AI for the role, this law is now part of that math, especially for anything touching hiring, lending, housing, or insurance.
What Counts as a High-Risk AI System?
An AI system is “high-risk” under the Colorado AI law when it makes, or is a substantial factor in making, a consequential decision. The statute lists the domains explicitly:
- Employment, resume screeners, applicant ranking tools, AI video-interview scoring, promotion algorithms
- Financial or lending services, credit scoring, loan approval models, payment-plan eligibility
- Housing, tenant screening, rental application scoring
- Insurance, underwriting and pricing models
- Healthcare services, care eligibility or triage tools
- Education, enrollment and opportunity decisions
- Legal services and essential government services
What’s not high-risk is just as important. Using ChatGPT to draft marketing copy, an AI chatbot that answers store hours, AI bookkeeping categorization, or AI writing tools for your blog, none of that triggers the law, because no consequential decision about a person is being made. The question to ask: does this AI help decide something significant about a specific human being? If yes, treat it as high-risk until proven otherwise.
Colorado AI Law Requirements for Deployers
Deployers must use “reasonable care” to protect consumers from algorithmic discrimination. In practice, the law translates that into specific duties:

1. A Risk Management Policy and Program
You need a written policy governing how you use high-risk AI, who oversees it, how risks are identified, and how they’re mitigated. The law points to the NIST AI Risk Management Framework as a benchmark, which sounds intimidating but scales down reasonably for a small operation: document the tool, the decision it influences, the data it touches, and who reviews its outputs.
2. Impact Assessments
Deployers must complete an impact assessment for each high-risk system, annually, and within 90 days of any substantial modification. The assessment covers the system’s purpose, the data it uses, known risks of discrimination, and the safeguards in place.
3. Consumer Notices
Before a high-risk AI system makes or helps make a consequential decision about someone, you must tell them. That means updating job postings, application flows, and customer communications to disclose AI involvement, plus a public statement on your website describing the high-risk systems you deploy.
4. Adverse Decision Rights
If the AI contributes to a decision against someone, a rejected application, a denied lease, you must explain why, disclose the principal reasons including the AI’s role, give them a chance to correct inaccurate data, and offer an appeal with human review where feasible.

5. Reporting Discovered Discrimination
If you discover your system has caused algorithmic discrimination, you must notify the Colorado Attorney General within 90 days. Developers carry a parallel duty to notify deployers and the AG about known risks.
The Small Business Exemption: Smaller Than It Sounds
Businesses with fewer than 50 full-time employees are exempt from some deployer duties, chiefly the risk management program, impact assessments, and the public website statement, but only if they meet conditions, including not using their own data to train the high-risk system and using it as the developer intended.
Critically, the exemption does not remove the consumer-facing duties. You still have to notify people that AI is involved in consequential decisions, explain adverse outcomes, and honor correction and appeal rights. For most small businesses, the consumer-notice obligations are the ones most likely to be visibly violated, and most likely to generate complaints.
What Happens If You’re Not Ready by June 30?
There’s no private right of action, individuals can’t sue you directly under this law. Enforcement belongs exclusively to the Colorado Attorney General, and violations are treated as unfair trade practices under the Colorado Consumer Protection Act, which carries penalties of up to $20,000 per violation. Each affected consumer can count as a separate violation, so a misconfigured screening tool processing hundreds of applicants is not a rounding-error risk.
The law does include a rebuttable presumption of reasonable care for deployers who comply with the framework, meaning the paperwork isn’t just bureaucracy; it’s your legal shield.
Colorado AI Law Compliance Checklist for Small Businesses
- Inventory your AI. List every tool that touches hiring, lending, housing, insurance, or healthcare decisions. Check your ATS, CRM, and screening vendors, AI features often arrived in updates you never opted into. (Our guide to auditing your SaaS stack pairs well with this step.)
- Classify each tool. Does it make or substantially influence a consequential decision about a person? If yes, it’s high-risk.
- Ask your vendors for documentation. Developers owe deployers disclosures about training data, known risks, and intended use. Request them in writing now, vendor response times will balloon as the deadline nears.
- Confirm your exemption status. Under 50 full-time employees? Verify you meet the conditions (no training on your own data, used as intended).
- Draft your consumer notices. Update job postings, application confirmations, and adverse-action letters to disclose AI involvement and explain appeal rights.
- Set up a human review path. Decide who in your business reviews appealed decisions and how quickly.
- Document everything. Even exempt businesses should keep a one-page record per tool, it’s the cheapest insurance available.
- Calendar an annual review. Obligations recur; treat this like your annual insurance renewal.
The Bigger Picture: A Patchwork Is Coming
Colorado is first, not last. A bipartisan federal discussion draft, the Great American Artificial Intelligence Act of 2026, released June 4, proposes a national framework for frontier AI models and includes a temporary federal override of certain state AI rules. Whether or not it passes, the direction is clear: AI-assisted decisions about people are becoming regulated activity, the way data privacy did after GDPR and the California Consumer Privacy Act.
Small businesses that build lightweight AI governance now, an inventory, vendor files, consumer notices, will be able to absorb each new state law as a footnote rather than a fire drill. If you’re still getting oriented on the tools themselves, our AI agent rundown explains what these systems actually do behind the buzzwords.
Bottom Line
The Colorado AI law is not an anti-AI law. It doesn’t ban tools, and it won’t touch the vast majority of everyday AI use in a small business. What it does is attach accountability to AI that makes decisions about people, and it gives prepared businesses a clear, achievable safe harbor. Spend a few focused hours before June 30 on the checklist above, and you’ll be ahead of most of your competitors, including the big ones.
This article is for general information and isn’t legal advice. For questions about your specific obligations, consult a Colorado-licensed attorney.
