Colorado AI Act: What SMEs Must Do Before June 30, 2026
Colorado SB 24-205 is the first comprehensive state AI law in the US. If your business uses AI in hiring, lending, housing, or other consequential decisions, the clock is ticking.
Colorado's SB 24-205 — the Colorado AI Act — is the first comprehensive state-level AI law in the United States. It targets high-risk AI systems: those that make, or are a substantial factor in making, consequential decisions about people in areas like employment, lending, housing, education, healthcare, and insurance.
If you assumed state AI laws only apply to big tech, think again. The Act applies to deployers — businesses that simply use these systems — not just the companies that build them.
Who is covered?
- Developers who create or substantially modify high-risk AI systems doing business in Colorado.
- Deployers — any business using a high-risk AI system to make consequential decisions about Colorado residents.
- SMEs get partial relief: deployers with fewer than 50 full-time employees that don't train the system with their own data are exempt from some (not all) duties.
What deployers must do
- Exercise reasonable care to protect consumers from algorithmic discrimination.
- Implement a risk management policy and program governing the high-risk system.
- Complete an impact assessment before deployment and review it annually.
- Notify consumers when a high-risk system makes a consequential decision about them — and explain adverse decisions.
- Offer consumers a chance to correct data and appeal adverse decisions with human review where feasible.
- Report discovered algorithmic discrimination to the Colorado Attorney General.
Why SMEs should act now
Even with the small-deployer exemption, you still owe consumers notice and adverse-decision explanations. And the exemption disappears the moment you fine-tune a vendor's model on your own data — something many SMEs do without realizing the legal consequence.
The most common trap: using an AI-powered hiring or screening tool from a vendor and assuming the vendor carries the compliance burden. Under the Colorado AI Act, the deployer has independent duties.
A practical 30-day plan
- Week 1 — Inventory. List every AI tool that touches decisions about people: hiring, promotion, credit, insurance, housing, healthcare.
- Week 2 — Classify. Flag anything that is a "substantial factor" in a consequential decision as high-risk.
- Week 3 — Ask vendors. Request the developer disclosures the Act requires them to provide — data, limitations, discrimination risks.
- Week 4 — Document. Draft your risk management policy and a simple impact assessment. The NIST AI Risk Management Framework is explicitly recognized as a safe-harbor baseline.
Start with the inventory. You cannot govern what you have not listed — and under this law, "we didn't know we were using it" is not a defense.