If you searched “Colorado AI Act sales compliance” this week, much of what you found is wrong. Plenty of vendor blogs still tell sales teams that from February 2026 they must run risk-management programmes, file impact assessments and announce “you are talking to an AI” on every Colorado call, citing the 2024 Act (SB 24-205). None of that is current law. Colorado repealed that Act before a single obligation took effect and replaced it with a narrower statute regulating automated decision-making technology (ADMT) in consequential decisions. Here is the corrected record, from primary sources.
The short answer: Colorado’s 2024 AI Act (SB 24-205) never took effect — it was repealed and re-enacted on 14 May 2026 as SB 26-189, a narrower automated decision-making technology (ADMT) law that applies to consequential decisions made on or after 1 January 2027. The old general duty to tell consumers they are interacting with AI did not survive the rewrite; the new law instead requires deployer notice and 30-day adverse-outcome disclosures only where ADMT materially influences decisions about education, employment, housing, lending, insurance, health care or essential government services. Most routine sales outreach sits outside that framework — though a separate Colorado chatbot law (HB 26-1263) and other jurisdictions’ AI-disclosure rules still apply.
What actually happened: three dates that killed the old advice
The confusion is understandable, because Colorado moved fast. Here is the verified timeline, from the Colorado General Assembly’s own records:
- 17 May 2024 — Governor Polis signs SB 24-205, the original Colorado AI Act: duties of reasonable care to prevent algorithmic discrimination, risk-management programmes, impact assessments, consumer notices — and, in the old C.R.S. § 6-1-1704, a general duty to disclose AI interactions. Original start date: 1 February 2026.
- 28 August 2025 — After a special session fails to produce a compromise, SB 25B-004 “extends the effective date of the requirements of Senate Bill 24-205 to June 30, 2026.”
- 14 May 2026 — Before that delayed date ever arrives, the Governor signs SB 26-189, which repeals and re-enacts, with amendments, part 17 of article 1 of title 6 of the Colorado Revised Statutes. The old framework is gone; the new one, C.R.S. §§ 6-1-1701 to 6-1-1709, takes effect on 1 January 2027 and “applies to consequential decisions made on or after January 1, 2027.”
The upshot: no obligation from the 2024 Act was ever enforceable against anyone. Any checklist telling you to comply with SB 24-205 “from February 2026” describes a law that was postponed, then repealed before it began.
The disclosure duty that vanished
For sales teams, the most important casualty of the rewrite is the chatbot-disclosure duty. The old Act’s § 6-1-1704 said that, on and after 1 February 2026, anyone who “deploys, offers, sells, leases, licenses, gives, or otherwise makes available an artificial intelligence system that is intended to interact with consumers” had to ensure disclosure to each consumer “that the consumer is interacting with an artificial intelligence system” — unless that would be “obvious to a reasonable person”.
That duty does not appear anywhere in SB 26-189. We read the signed act end to end: the re-enacted part 17 contains no requirement to announce that a person is talking to an AI — the phrase “artificial intelligence” does not appear in the new statute at all. The new § 6-1-1704 is titled “Deployer disclosures — point-of-interaction notice” but it is about something different: telling consumers that a covered ADMT was or will be used in a consequential decision affecting them, not that the voice or chat on the other end is synthetic. That said, “no duty under SB 26-189” is not the same as “no duty at all” — we come back to Colorado’s separate chatbot statute, the FCC baseline and other states below.
What SB 26-189 actually regulates
The new law is built on three defined terms, and all three have to be satisfied before any duty attaches.
1. Covered ADMT
“Automated decision-making technology” is technology that processes personal data and uses computation to generate output — predictions, recommendations, classifications, rankings, scores — used to make, guide or assist a decision about an individual. It becomes “covered ADMT” only when it is used to materially influence a consequential decision. “Materially influence” means the output is a non-de-minimis factor that affects the outcome; incidental, trivial or clerical uses do not count.
Crucially for sales teams, § 6-1-1701(2)(b)(III) expressly excludes technology that communicates with consumers in natural language to provide information, make referrals or recommendations, answer questions or generate content — provided it is (a) not contracted, advertised, marketed, configured or intended to be used in a consequential decision, and (b) subject to an acceptable use policy that prohibits its output being used in one. Colorado wrote a statutory safe path for conversational assistants, and the price of admission is a written acceptable-use policy plus configuration discipline — exactly what a good guardrails document already covers.
2. Consequential decision
A “consequential decision” is a decision about a consumer’s access to, eligibility for, selection for or compensation for a covered domain. The statutory list in § 6-1-1701(6) is exhaustive:
- education enrolment or an education opportunity;
- employment or an employment opportunity that creates (or may create) an employer-employee relationship;
- the lease or purchase of residential real estate in Colorado;
- a financial or lending service;
- insurance — including underwriting, pricing, coverage and claims;
- health-care services; and
- essential government services and public benefits.
A second prong catches decisions that impose materially less favourable differentiated pricing or terms in those same domains. And the exclusion list is just as instructive: “consequential decision” expressly does not include low-stakes or routine decisions such as routine scheduling, administrative routing, customer service triage, communication of decisions or workflow management — nor “advertising, marketing, differentiated product recommendations, search, or content moderation”.
3. Deployers and developers doing business in Colorado
Duties fall on “deployers” (persons doing business in Colorado that deploy a covered ADMT) and “developers” (those who make covered ADMT commercially available or substantially modify an ADMT into one). One broadening move: “consumer” includes employees and Colorado-resident job applicants, so AI-assisted recruiting and screening is squarely in scope as an employment decision.
Old law vs new law: what survived, what didn’t
| Obligation | SB 24-205 (2024 — never took effect) | SB 26-189 (from 1 January 2027) |
|---|---|---|
| Reasonable care to prevent algorithmic discrimination | Required of developers and deployers of high-risk AI systems | Repealed, not re-enacted. Discrimination claims proceed under existing law, with fault-allocation and anti-indemnification rules (§ 6-1-1707) |
| Risk-management policy and programme | Required of deployers | Repealed, not re-enacted |
| Impact assessments with annual review | Required of deployers | Repealed, not re-enacted |
| Disclosure that the consumer is interacting with AI (old § 6-1-1704) | Required for any consumer-facing AI system, unless obvious to a reasonable person | Not re-enacted — no equivalent duty anywhere in the new part 17 (but see HB 26-1263 for public chatbot services) |
| Notice that AI is used in a consequential decision | Required, with statements of purpose and system description | Replaced by a narrower duty: clear and conspicuous notice before covered ADMT materially influences a consequential decision, satisfiable by a prominent public posting at points of consumer interaction (§ 6-1-1704(1)–(2)) |
| Post-decision explanation and appeal | Required: explanation, data correction, appeal with human review | Re-enacted in modified form: adverse-outcome disclosure within 30 days, right to correct factually incorrect or materially inaccurate personal data, and meaningful human review “to the extent commercially reasonable” (§§ 6-1-1704(3), 6-1-1705) |
| Developer duties | Documentation for impact assessments, public statements, reporting algorithmic discrimination to the Attorney General within 90 days | Narrowed to documentation: intended and known harmful uses, training-data categories, known limitations and risks, instructions for use and human review, material-update notices, three-year records (§ 6-1-1702). No AG discrimination reporting |
| Enforcement | Attorney General exclusively; deceptive trade practice | Same structure: AG-exclusive, deceptive trade practice, 60-day cure right (sunsets 1 January 2030), no new private right of action (§§ 6-1-1706, 6-1-1709) |
What sales and outbound teams should do before January 2027
First, map your decisions, not your tools. The question under SB 26-189 is never “do we use AI?” — it is “does any automated output materially influence a decision about a person’s access to a covered domain?” For a typical sales motion — prospecting, qualifying, booking meetings, following up — the honest answer is usually no. Lead scoring that decides who gets called first is workflow management; suggesting a product tier is a product recommendation; sending the outcome of a decision a human made is “communication of decisions”. All are expressly outside the definition.
Second, know when sales outreach is the exception. If your team sells in a covered domain, the line moves. An AI agent that pre-qualifies loan applicants, quotes insurance premiums, screens rental applicants or shortlists job candidates is very plausibly influencing access to a financial service, insurance, housing or employment — and if its output is a non-de-minimis factor in the outcome, notice and adverse-outcome duties attach from 1 January 2027. The same applies internally: AI-assisted recruiting for your own sales team is in scope as an employment decision.
Third, use the statute’s own safe path for conversational AI. If your assistants inform, recommend, answer questions and book meetings — and you do not configure or market them to make consequential decisions — put that in writing: an acceptable-use policy prohibiting such use is one of the two statutory conditions for staying outside the ADMT definition altogether. Pair it with human-in-the-loop checkpoints so anything resembling an eligibility call is made by a person, with AI output as context rather than verdict.
Fourth, if you are covered, build the two disclosure workflows now. Deployers must give clear and conspicuous notice before covered ADMT materially influences a consequential decision — satisfiable by a prominent public notice reasonably proximate to the interaction. Within 30 days of an adverse outcome, you must deliver a plain-language description of the decision and the ADMT’s role, a simple process for requesting details (system name, version, developer, data categories), and an explanation of the consumer’s correction and human-review rights. Keep records for three years. Vendors have duties to you too: from 1 January 2027 your ADMT suppliers must hand over documentation on intended uses, training-data categories, known limitations and oversight instructions — ask for it in procurement.
Fifth, watch the rulemaking — it is not finished. The Attorney General must adopt implementing rules on or before 1 January 2027; as of this writing they are proposed, not adopted (filed 11 August 2026, formal comment open until 26 October 2026). The final content of adverse-outcome disclosures, sector guidance and any “materially influence” presumptions will land there.
Disclosure duties didn’t disappear — they moved
Two honest caveats before anyone deletes the disclosure line from their call scripts. First, Colorado passed a second statute in the same session: HB 26-1263, the Chatbot Safety Act, signed 29 May 2026 with operator requirements also starting 1 January 2027. It applies to operators of publicly available conversational AI services and requires, among minor-protection duties, a protocol to inform users that they are interacting with AI. Whether a given sales deployment counts as a “publicly available conversational AI service” is a scoping question — a public website chatbot looks much closer to the definition than a one-to-one outbound calling agent — and the AG’s proposed chatbot rules should sharpen the line. Second, other jurisdictions genuinely do retain AI-interaction disclosure duties: Utah’s amended disclosure rules, Maine’s outset-of-call notification, California’s bot law, and a pending federal proposal covered in our FCC NPRM 24-84 explainer. Our AI disclosure scripts post keeps the full jurisdiction-by-jurisdiction table, with wording that doesn’t kill the conversation.
SB 26-189 also changes nothing about telemarketing, spam and privacy law. The TCPA, Spam Act and GDPR rules for AI outreach apply exactly as before, and the new act says expressly that compliance with part 17 is no defence to non-compliance with any other law. Teams selling into Europe face a separate, live framework — see our EU AI Act status update.
This article is general information for sales operators, not legal advice — if you deploy ADMT in a covered domain, have counsel review your specific decision flows.
FAQ
Is the original Colorado AI Act (SB 24-205) still in force?
No — it never came into force at all. Its start date was delayed from 1 February 2026 to 30 June 2026, and before that date arrived Colorado repealed and re-enacted the entire framework on 14 May 2026 as SB 26-189, which applies to consequential decisions made on or after 1 January 2027. Guidance that tells you to comply with SB 24-205 obligations is describing a law that no longer exists.
Does Colorado still require telling people they are talking to an AI?
Not under SB 26-189 — the re-enacted statute contains no general AI-interaction disclosure duty, and the phrase “artificial intelligence” does not appear in its text. However, Colorado’s separate Chatbot Safety Act (HB 26-1263, operator duties from 1 January 2027) requires operators of publicly available conversational AI services to implement a protocol informing users they are interacting with AI, and disclosure duties in other jurisdictions and pending FCC rules are unaffected.
When does SB 26-189 take effect, and are the Attorney General’s rules final?
The act takes effect on 1 January 2027 and applies to consequential decisions made on or after that date. The Attorney General must adopt implementing rules by the same date; according to the Colorado Attorney General’s rulemaking page, proposed rules were filed on 11 August 2026 and the formal comment period runs until 26 October 2026 — so the rules are proposed, not yet adopted.
Are ordinary sales calls, SMS follow-ups and lead scoring “consequential decisions”?
Generally no. The statute excludes advertising, marketing, product recommendations, routine scheduling, customer service triage, communication of decisions and workflow management from “consequential decision”, and law-firm analyses such as Crowell & Moring’s client alert read those exclusions the same way. The picture changes if automated output materially influences access to a covered domain — lending, insurance, housing, employment, education, health care or government services — including AI-assisted screening of your own job applicants.
Is there a small-business exemption or a private right of action?
The enacted text contains no size-based exemption — duties turn on what the technology does, not headcount. Carve-outs are sectoral instead: regulated insurers, HIPAA-covered entities, FDA-regulated devices, and credit decisions already covered by ECOA/FCRA notices. Enforcement sits exclusively with the Attorney General as a deceptive trade practice, with a 60-day cure period available until 1 January 2030, and the act creates no new private right of action.
Where Zian fits
Zian’s AI sales agents are built for exactly this kind of regulatory motion: configurable disclosure lines for the jurisdictions that require them, guardrails and human-in-the-loop controls that keep consequential calls with your people, and private model deployment on your own infrastructure when data control matters. If you want outbound that scales across phone, SMS, email and WhatsApp without guessing at the rules — Apply For Partnership.