Colorado's AI Rulemaking Is Titled Anti-Discrimination. The Law No Longer Is.
Colorado's Aug 11 AI rulemaking page is titled anti-discrimination. Neither the law nor the draft rules use that word.
On August 11, 2026, Colorado's Department of Law filed draft rules to implement the state's rewritten AI statute, opening a public comment period that runs through October 26, 2026. Search for that rulemaking, and the page that comes up first is titled, in the text that shows in a browser tab and in most search results, "Colorado Anti-Discrimination in AI Law (ADAI) Rulemaking." Open it, and the page itself is headed something else: "Colorado Automated Decision-Making Technology & Chatbot Safety Rulemaking." That is not a typo. The name is left over from a law the state repealed in May.
What the 2024 law did, and what replaced it
In 2024, Colorado passed Senate Bill 24-205, which the Attorney General's own site describes as having created consumer protections from algorithmic discrimination in consequential decisions made by high-risk artificial intelligence systems. On May 14, 2026, Governor Polis signed Senate Bill 26-189, repealing and reenacting that entire framework. The new law takes effect January 1, 2027.
Its text does not use the phrase "high-risk" once. It does not use "impact assessment," "risk management," or "reasonable care" once either - all three tied to duties the 2024 law imposed that this one does not reenact.
The word "discrimination" survives exactly once in substance, in Section 6-1-1707, and it points outward, not in: a developer or deployer "may be held liable in an action alleging unlawful discrimination under state anti-discrimination laws, including the 'Colorado Anti-Discrimination Act'" - a separate statute, at a different Title of the Colorado Revised Statutes, that predates this one. The same section adds that nothing in the new AI law "excuses, justifies, or provides a defense to any obligation or liability under state or federal law, including obligations and liability related to discrimination." That is a savings clause, preserving somebody else's liability. It is not, itself, a discrimination rule.
What the new law actually requires
What Senate Bill 26-189 creates is narrower and more procedural. A developer must give each deployer of a "covered ADMT" documentation - intended and known harmful uses, categories of training data, known limitations, instructions for human review - before the system is used to materially influence a "consequential decision" in one of seven listed "covered domains": education, employment, housing, lending, insurance, health care, and government benefits. A deployer must post notice at the point of interaction, and within 30 days of an adverse outcome, explain in plain language what role the system played. A consumer gets the right to request correction of inaccurate personal data used in the decision, and "an opportunity for meaningful human review and reconsideration ... to the extent commercially reasonable." That is the operative core: documentation, notice, disclosure, correction, review.
The rulemaking, and what it doesn't say
The August 11 filing - fourteen numbered rules, covering everything from multiparty developer-deployer arrangements to the separate Chatbot Safety Act's age-estimation and annual-reporting requirements - carries the same absence as the statute it implements. Across the full text of the draft rules, neither "discriminat-" nor "high-risk" appears once. The Chatbot Safety Act, House Bill 26-1263, enacted the same season and folded into this same rulemaking, is a genuinely different track: it requires operators of conversational AI services to estimate a user's age, and where that user is a minor, to disclose AI use, block engagement-reward incentives, guard against sexual content and simulated emotional dependence, provide a stop-protocol for prompts about sexual conduct involving a minor, and report annually to the Attorney General on a self-harm response protocol. None of that is framed as anti-discrimination either.
This is where the record stops and this Article's own reading starts. A reader who finds this rulemaking by searching for Colorado's "anti-discrimination AI law" - following the page's own indexed title - could reasonably expect the open comment period to be about discrimination protections. It is not: what is actually up for comment is documentation format, notice timing, and how "meaningful human review" and "commercially reasonable" get defined in the final rules. Nothing in the record says the mismatch was deliberate - the Attorney General's office visibly updated the page's own heading and its social-share preview title to the accurate name. The one piece of copy that did not move is the indexed title, the part a search engine shows before anyone clicks through. Whether that is oversight or simply not yet queued for update, a reader who stops at the search result meets the old name before the new law.
What changes, and for whom
That same reading, extended, cuts differently depending on where an organization already stands - this is inference, not something the statute states about its own effect. An organization that built compliance infrastructure toward the 2024 law's algorithmic-discrimination duty now has that infrastructure aimed at something this statute no longer imposes in its own right, even though liability under Colorado's separate Anti-Discrimination Act, which Section 6-1-1707 preserves, has not gone anywhere. An organization starting from nothing faces the opposite risk: underrating the actual work, because a documentation packet and a correction-and-human-review intake process sound smaller than "anti-discrimination compliance," even though they are what Colorado is actually asking for by January 1, 2027.
The comment period is genuinely open - through October 26, 2026, with written comments requested by October 5 for consideration at the rulemaking hearing. A well-run AI operation spends that time on the rules the Department of Law actually filed on August 11, not the title on the page that hosts them: building toward developer documentation, point-of-interaction notice, 30-day adverse-outcome disclosure, and a correction-and-human-review process - the obligations Colorado is actually going to start checking for in eleven months.
Source note: This Article is based on Colorado Senate Bill 26-189 (signed May 14, 2026) and House Bill 26-1263, both read directly from the Colorado General Assembly's enrolled bill text; the Colorado Attorney General's Automated Decision-Making Technology & Chatbot Safety Rulemaking page and its August 11, 2026 draft rule filing (4 CCR 904-6); and the Attorney General's own historical description of Senate Bill 24-205 (2024).
Map your disclosures against AI & Technology.
Noa reads your disclosures, traces every number to its source, and flags what's missing.