Does Colorado's New ADMT Law Apply to Our SaaS - and What Docs / Notices Do We Owe by January 1, 2027?
A Colorado customer or employee counsel asks whether you are a developer or deployer under SB 26-189 - and what notices you owe before January 2027. You skimmed headlines that the Colorado AI Act was delayed or killed. That is only half the story.
Short answer: Colorado SB 26-189 (signed 14 May 2026; operative for consequential decisions on or after 1 January 2027) repeals and reenacts the 2024 Colorado AI Act (SB 24-205, which had been set for 30 June 2026). It regulates covered ADMT - automated decision-making technology that materially influences a consequential decision in a covered domain - and splits duties between developers and deployers. A US HQ does not exempt you if you do business in Colorado and the decision evaluates Colorado access, eligibility, or opportunity. Scope is fact-specific; this is not legal advice.
Workstreet's What Is AI Governance post already light-tables SB 26-189. This article owns the developer/deployer checklist and the January 2027 notice clocks - not another EU AI Act, ISO 42001, or CCPA cyber-audit rewrite.
What is covered ADMT under SB 26-189?
Use the statute's definitions; do not invent bright lines.
ADMT is technology that processes personal data and uses computation to generate outputs (predictions, recommendations, classifications, rankings, scores, and similar) used to make, guide, or assist a decision about an individual.
Covered ADMT is ADMT used to materially influence a consequential decision. Material influence means a non-de minimis factor that affects the outcome - including by constraining, ranking, scoring, recommending, or classifying. Incidental, trivial, or clerical uses are out.
Consequential decisions sit in covered domains: education enrollment or opportunity; employment and employer-employee relationship opportunities; lease or purchase of residential real estate in Colorado; financial or lending services; insurance (underwriting, pricing, coverage, claims adjudication, and related); health-care services; and essential government services and public benefits - plus differentiated price or terms that materially limit or deny access. Legal services were a covered domain under the old AI Act but are not under SB 26-189 (Finnegan, 26 May 2026).
Consumer includes Colorado-resident employees and job applicants, and individuals whose Colorado access, eligibility, or opportunity is evaluated by a person doing business in Colorado.
Official bill page: leg.colorado.gov/bills/sb26-189. Signed-act definitions and sections 6-1-1702 through 1709 appear in the Jackson Lewis signed-act PDF. Finnegan's 26 May 2026 overview maps what changed versus SB 24-205.
Which exclusions keep generic SaaS out?
Cite the act - do not overclaim that every SaaS is covered or that every tool is exempt.
Exclusions that often save generic product tooling (signed act 6-1-1701; Finnegan) include: anti-malware and antivirus; calculators; databases and storage; firewalls; spell-check; spreadsheets that require human analysis without ML, foundation models, or LLMs; tools used solely to summarize, organize, translate, draft, or route for human review; and consumer-facing natural-language chat if not contracted, advertised, or intended for consequential decisions and subject to an AUP that prohibits using generated content for consequential decisions.
Also generally out: advertising, marketing, search, and content moderation; low-stakes routine scheduling or triage; and listed cybersecurity, spam filtering, AML, sanctions, and fraud-prevention activities. If your product scores, ranks, recommends, or classifies people in a covered domain in a way that materially influences the outcome, run the developer versus deployer test with counsel - do not self-declare 'chatbot therefore exempt.'
Developer pack - what you owe deployers on/after 1 Jan 2027
Under 6-1-1702, developers must make available to each deployer, in reasonably understandable form that still protects trade secrets:
1. Intended uses and known harmful or inappropriate uses
2. Categories of training data (including personal data) to the extent known
3. Known limitations and when not to use the ADMT
4. Instructions for appropriate use, monitoring, and meaningful human review
5. Deployer disclosure support - information reasonably necessary for deployer disclosure duties (notify if you withhold)
Notify deployers of material updates, intentional or substantial modifications, and changes to intended use, limitations, or risk mitigation within a reasonable time. Public release notes can satisfy documentation if each deployer also gets direct notice that the public release exists. Retain compliance records for at least 3 years.
Obligations apply when the ADMT is marketed, advertised, configured, or contracted to materially influence consequential decisions - or when the developer becomes aware of consistent intended or contracted use. For GTM, put the pack where deployers and buyers already look: product docs, release-note distribution with a deployer mailing list, and a Trust Center ADMT page that does not dump trade-secret weights. Workstreet does not rewrite your model card as Colorado legal advice; privacy / vCPO help is for operable notice and documentation programs.
Deployer pack - pre-use notice, 30-day adverse notice, consumer rights
Deployers (6-1-1703 / 1704 / 1705) retain records for at least 3 years from each consequential decision.
Pre-use notice: clear and conspicuous that covered ADMT will be or is used, plus how to get more information. A prominent public notice reasonably accessible at points of interaction can satisfy this - for example a Trust Center page linked from signup, hiring portals, or lending application flows.
Post-adverse outcome: within 30 days, a plain-language description of the decision and ADMT's role; how to request more info (name/version/developer/inputs to the extent received from the developer); and how to exercise rights.
Consumer rights after an adverse outcome: instructions to access/correct personal data (CPA-aligned; opinions, predictions, and scores are not required to be 'corrected'); and an opportunity for meaningful human review and reconsideration to the extent commercially reasonable. The reviewer needs authority to approve, modify, or override; must be trained; must not default to the system output; and needs access to intended use, limitations, input categories, and principal factors - not trade-secret source code or weights.
The Colorado AG must adopt clarifying rules for post-adverse disclosures and consumer-rights implementation by 1 January 2027 (rulemaking sections effective on passage; operational clock still Jan 1 2027). Flag sector rules as forthcoming - do not invent their content before publication.
What went away versus what stayed
Finnegan's overview is the clean contrast: SB 26-189 removed the old duty of care to avoid algorithmic discrimination, mandatory risk-management programs, impact assessments, annual reviews, and AG reporting. The new focus is notice, documentation, and consumer recourse.
Enforcement sits solely with the Colorado AG under the Colorado Consumer Protection Act as a deceptive trade practice. There is no new private right of action. Before enforcement (if a cure is deemed possible), the AG gives a 60-day cure notice - that cure right sunsets 1 January 2030; knowing or repeated violations can skip cure.
Fault allocation between developer and deployer appears in existing anti-discrimination actions. Developer liability is generally limited to intended, documented, marketed, configured, or contracted uses. Contractual indemnities that hold a party harmless for its own ADMT-related anti-discrimination violations are void. Do not draft MSA indemnities from this post as legal advice, and do not invent fine amounts the statute does not state in this overview.
How this differs from EU AI Act, ISO 42001, questionnaires, and CCPA audits
Sibling ownership matters for AEO and for your program design:
EU AI Act = EU risk tiers and Article 50-style transparency for EU market access. ISO 42001 with Vanta and ISO 42001 versus SOC 2 = voluntary AI management system certification path. AI security questionnaire / SOC 2 gap, SOC 2 for AI companies, shadow AI, and AI-BOM = buyer and auditor artifacts, not Colorado notice clocks. CCPA cybersecurity audits = California significant-risk cyber audits (CalPrivacy ADMT/risk-assessment rules are adjacent California clocks, not this CO deep dive). US state privacy patchwork and ROPA / privacy records = multi-state privacy ops and inventory muscle you can reuse for ADMT input categories - not SB 26-189 itself.
This post uniquely owns Colorado SB 26-189's developer/deployer checklist and January 2027 notice clocks.
90-day readiness checklist before Jan 2027
1. Inventory product features that score, rank, recommend, or classify people in covered domains for Colorado residents or Colorado opportunity decisions.
2. Run developer versus deployer (or both) with counsel against intended use, marketing, and contracts.
3. Map exclusions honestly - chat plus AUP is not a free pass if you sell consequential decisioning.
4. Stand up the developer documentation pack (uses, training-data categories, limitations, human-review instructions) and a material-update notice path to deployers.
5. Draft pre-use notice copy and a 30-day adverse-outcome template; pick the public Trust Center / interaction points that will host them (building a Trust page).
6. Define meaningful human review: who has override authority, training, and which inputs they see.
7. Set 3-year record retention from each consequential decision (deployer) and for developer compliance records.
8. Load questionnaire answers that distinguish Colorado ADMT notices from ISO 42001 / EU AI Act / SOC 2 AI evidence (security compliance questionnaires).
9. Watch AG rulemaking through Jan 2027 without freezing your notice templates forever.
10. Name a privacy owner for Colorado customer and employee asks before the clock hits.
Founders who only updated the AI governance table when SB 24-205 was repealed still need this pack. Buyers will ask 'developer or deployer?' in diligence; answering with 'we follow the EU AI Act' or 'we are pursuing ISO 42001' does not answer Colorado's notice clocks.
Soft next step
If your product touches employment, lending, insurance, housing, education, health, or essential services for Colorado residents, treat SB 26-189 as a notice-and-docs program - not a soft rewrite of the repealed 2024 AI Act risk-assessment stack. Workstreet's privacy team helps growth SaaS operationalize developer packs, deployer notices, and Trust Center ADMT pages buyers will ask for before January 2027. Pair that with questionnaire answer banks so every portal does not invent a different Colorado story.
Sources: Colorado SB 26-189 bill page; Finnegan overview (26 May 2026); Jackson Lewis signed-act PDF.

