Two years ago, Colorado made national headlines as the first state to pass a comprehensive artificial intelligence law. The Colorado AI Act was meant to prevent algorithmic discrimination — requiring companies to disclose, test, and mitigate risks from "high-risk" AI systems. It was modeled on Europe's approach, and compliance would have been expensive.

It never actually took effect.

On May 14, Governor Polis signed a bill that replaces it entirely. The new law, SB26-189, starts fresh with a fundamentally different approach. If you run a business in Colorado and you use AI for anything customer-facing — resume screening, loan decisions, pricing algorithms, tenant screening — this matters to you.

What the old law would have required

The original act treated AI like a hazard. Companies using "high-risk" AI systems in hiring, lending, housing, healthcare, and similar decisions would have needed to conduct regular impact assessments, maintain formal risk management programs, notify the attorney general of any algorithmic discrimination discovered, and give consumers the right to opt out and appeal automated decisions.

Even Governor Polis, when he signed the original bill in 2024, said it created a "complex compliance regime" that needed fixing. Industry pushback was intense. Elon Musk's x.AI sued to block it, and the Trump administration's Department of Justice joined the case.

What the replacement does instead

The new law keeps the core concern — automated decisions that affect people's lives — but drops most of the heavy regulatory machinery. Here's what changed:

Scope got narrower. Only AI that "materially influences" decisions about employment, credit, housing, healthcare, insurance, or legal services is covered. Routine automation — scheduling tools, spam filters, spell check — is explicitly excluded.

Risk assessments are gone. Companies no longer need to run impact assessments or maintain formal risk management programs. Instead, they must tell consumers when automated tools are being used and explain why a decision was made if it goes against them.

Consumers get new rights. Individuals can request correction of inaccurate data used in automated decisions and ask for meaningful human review of adverse outcomes.

Enforcement is lighter. Only the attorney general can enforce the law, and companies get a 60-day window to fix problems before penalties apply. There's no private right of action — meaning competitors and class-action lawyers can't sue.

It takes effect January 1, 2027 — provided the x.AI lawsuit doesn't derail it first. Musk's company has until June 11 to file a new injunction motion.

What this means for your business

If you're using AI tools to screen job applicants, set prices, evaluate loan applications, or make any decision that materially affects a customer, this law will eventually apply to you. But the compliance burden is far lighter than it was six months ago.

You don't need a risk management framework. You don't need to file impact assessments with the state. What you do need: know what your AI tools are doing, tell people when they're being used, and be ready to explain decisions that go against someone. That's not nothing. But it's also not the regulatory cliff the original law created.

The bigger lesson

Colorado's experience reveals something about AI regulation that will play out in every state legislature for the next decade: these laws are attempts to pin down a moving target. The original act took two years to write. By the time it was ready to enforce, the technology it was designed to regulate had changed enough that the governor, the legislature, and the industry all agreed it needed a rewrite.

The replacement law will likely face the same problem. By January 2027, "automated decision making technology" may mean something different than it does today.

That doesn't mean do nothing. It means the sensible position for most businesses is to use AI thoughtfully, document what you're doing, and know what your tools are making decisions about — not because a law says so, but because that's how you keep control of your own operations. Regulation will catch up eventually. But it's always going to be running behind the technology.

The businesses that handle this well won't be the ones that hire the most compliance lawyers. They'll be the ones that ask good questions before the law forces them to.

If you're using AI tools to make decisions that affect your customers or employees — or you're thinking about it — talk to someone who understands both the technology and the regulatory landscape. A good advisor can help you sort out what's worth worrying about now versus what can wait.