The Colorado AI Act Never Took Effect: What US State AI Law Actually Looks Like in September 2026
If your AI governance programme still has a "Colorado readiness" workstream built around a duty of reasonable care to prevent algorithmic discrimination, a mandatory risk management programme and annual impact assessments, it targets a statute that no longer exists. The Colorado AI Act - SB 24-205, the law most 2025 commentary treated as the template for US state AI regulation - never took effect. Not once. Its operative date was postponed twice, then the legislature repealed and reenacted it into something materially different before that date arrived. That matters beyond Colorado, because so much "US state AI laws" content used Colorado as the model for American AI compliance.
The Colorado AI Act never took effect
SB 24-205 was enacted in 2024, operative 1 February 2026. In a special session the General Assembly passed SB 25B-004, signed 28 August 2025, moving that date to 30 June 2026, as Akin's tracker recorded. Then, before 30 June arrived, the legislature went further. SB 26-189, "Automated Decision-Making Technology", was signed by Governor Polis on 14 May 2026, becoming Chapter 131 of the Session Laws of Colorado 2026. (Some secondary sources say 20 May; the General Assembly's record says 14 May.)
The legislature's own language is "repeals and reenacts". The original Act was never in force for a single day, and the successor does not commence for another year. The Colorado AG's AI page says it plainly: "This new law and its provisions go into effect January 1, 2027."
What was deleted, and what replaced it
Three of the most burdensome features were removed outright: the mandatory risk management programme, the annual impact assessment, and the duty of reasonable care to prevent algorithmic discrimination (Crowell).
Four duties replace them - documentation and process, not a care standard:
- Developer technical documentation to deployers, covering intended uses, categories of training data, known limitations, and instructions for human review.
- Clear and conspicuous consumer notice at the point of interaction.
- A plain-language explanation within 30 days of an adverse outcome.
- Rights to data correction and to meaningful human review and reconsideration.
Both must retain records for three years.
The scope narrowed - but there is a definitional trap
The statute now regulates "covered ADMT": technology processing personal data that materially influences a consequential decision in education, employment, housing, financial or lending services, insurance, health care, or essential government services and public benefits. Carve-outs cover firewalls, spam filters, spell-checkers, calculators, databases, spreadsheets, and tools solely summarising information for human review. Scheduling, customer-service triage, advertising, product recommendations, search and content moderation fall outside "consequential decision".
The trap: unlike SB 24-205, the covered ADMT definition does not require the system to infer from inputs, which widens scope even as the sectoral narrowing tightens it. A deterministic rules engine - a range-check tool screening applicants against a numeric threshold - can qualify, though nobody would call it AI. Inventories built by asking "where do we use AI?" miss these; ask instead what processes personal data and materially influences one of the eight listed decision types.
Enforcement, contracts and safe harbours
The Colorado AG enforces exclusively, under the Colorado Consumer Protection Act; violations are deceptive trade practices. A 60-day notice and cure requirement applies to actions brought before 1 January 2030 where cure is possible, with no cure right for knowing or repeated violations. No private right of action.
SB 26-189 also voids any clause indemnifying a party for its own ADMT-related discriminatory acts in a consequential decision, and sets a developer/deployer fault-allocation framework. Contracts drafted in 2025 to push that exposure downstream no longer work.
New sector safe harbours:
| Sector | Treatment under SB 26-189 |
|---|---|
| Colorado-regulated insurers | Compliant insurers safe-harboured |
| HIPAA covered entities and business associates | Largely exempt outside employment decisions and financial-assistance determinations |
| FDA-regulated medical devices, pharma R&D | Fully excluded |
| Credit and lending | ECOA/FCRA adverse-action notices satisfy the disclosure duty |
| Education | FERPA-compliant institutions deemed compliant on notice and human review |
The rulemaking is live right now
The Colorado Department of Law filed proposed ADMT and Conversational AI Service rules on 11 August 2026. The comment period runs to 26 October 2026; comments received by 4 September 2026 feed a revised draft due by 23 September 2026. AG rules are statutorily required before 1 January 2027 (source).
Colorado also enacted a Chatbot Safety Act, HB 26-1263, operative 1 January 2027: age estimation, AI disclosure, minor protections, self-harm protocols, annual AG report. Signed in mid-2026 (sources differ on the exact date).
Texas has been in force all year, and almost nobody has to do anything
The Texas Responsible Artificial Intelligence Governance Act (HB 149, "Texas TRAIGA") was signed 22 June 2025 and took effect 1 January 2026 (K&L Gates on the pared-back version actually signed). Its reach is broad: it binds anyone who develops or deploys AI in Texas, produces a product or service used by Texas residents, or promotes, advertises or conducts business in Texas. Then it asks almost nothing.
The structural point: TRAIGA prohibits only AI developed or deployed with the intent to unlawfully discriminate against a protected class. Disparate impact alone cannot establish that intent.
There is no private-sector disclosure duty, no impact assessment requirement. Only state agencies must disclose AI interaction to consumers, and health care providers must disclose AI use in treatment. Private employers have neither obligation. Prohibited uses target bad actors, not compliance programmes: AI intentionally aimed at inciting self-harm or criminal activity; CSAM and deepfake pornography generation; sexualised text conversations impersonating a child; government social scoring; biometric misuse.
Penalties are modest - curable violations USD 10,000 to 12,000, uncurable USD 80,000 to 200,000, continuing violations USD 2,000 to 40,000 per day. The Texas AG enforces exclusively; no private right of action. A cure regime applies; the widely cited 60-day figure is secondary-source only, not confirmed in the primary text.
TRAIGA carries a safe harbour tied to recognised risk-management frameworks: compliance with something like the NIST AI RMF Generative AI Profile supports a defence against AG enforcement - useful if you already run one. The Texas Department of Information Resources also runs a sandbox where participants may test AI systems without licence or registration, with certain rules waived; claims about a fixed 36-month term and preemption of city and county ordinances are unverified.
TRAIGA required a consumer complaint mechanism by 1 September 2026. The Texas AG's Consumer AI Rights page now carries a "File an AI Complaint" link, but shows no launch date, so timely publication is not independently verified.
Illinois versus Texas: opposite liability standards, same start date
Illinois HB 3773 amends the Illinois Human Rights Act. Signed 9 August 2024, effective 1 January 2026, it bars AI use with a discriminatory effect across recruitment, hiring, promotion, discharge, discipline and terms of employment. It also bars zip code as a proxy for a protected class, and requires notice to applicants and employees. Texas TRAIGA took effect the same day and requires intent, expressly rejecting disparate impact.
This is the cleanest illustration of why "US AI compliance" is not one thing. Same country, same start date, opposite standards, same hiring tool. A screening model producing a statistically adverse selection rate creates exposure in Illinois on the outcome alone, and none in Texas absent evidence of discriminatory purpose.
Illinois implementing rules are unsettled: IDHR temporarily withdrew its proposed AI-notice rules and cancelled the 10 June 2026 public hearing (Seyfarth). The notice obligation remains in force with no finalised guidance on what compliant notice looks like.
NYC Local Law 144 still requires annual independent bias audits of automated employment decision tools plus candidate notice, at USD 500 to 1,500 per day. But on 2 December 2025 the New York State Comptroller found DCWP's enforcement ineffective - 75% of 311 test calls were misrouted, and DCWP found one non-compliant firm among 32 surveyed where auditors identified at least 17 potential violations. DCWP agreed to move toward proactive review - read that as the enforcement floor rising.
Illinois has also moved into frontier models: SB 315, the Artificial Intelligence Safety Measures Act, was signed by Governor Pritzker on 6 July 2026 - the third state after California and New York, and, per Crowell, the first to mandate annual independent third-party audits of covered developers' safety practices. Same 10^26 FLOP and USD 500m thresholds as California SB 53; provisions begin taking effect 1 January 2027.
California is the real compliance burden
California SB 53, the Transparency in Frontier Artificial Intelligence Act, was signed 29 September 2025, effective 1 January 2026. It applies to "frontier developers" - training models above 10^26 FLOPs - with heavier duties on "large frontier developers" (over USD 500m annual gross revenue with affiliates). Per White & Case, they must publish and annually update a Frontier AI Framework; publish a transparency report before or with each new frontier model deployment; report critical safety incidents to Cal OES within 15 days, or 24 hours where there is imminent risk of death or serious injury; and, for large developers, produce quarterly internal-use catastrophic-risk summaries. Whistleblower protections apply. The AG enforces, up to USD 1 million per violation.
AB 2013 (Generative AI Training Data Transparency), also effective 1 January 2026, requires GenAI developers to publish high-level training data documentation.
SB 942, the California AI Transparency Act, did not take effect on 1 January 2026 - another widely repeated error. AB 853, approved 13 October 2025, moved the operative date to 2 August 2026, explicitly to align with the EU AI Act timeline. It covers GenAI providers with more than 1,000,000 monthly visitors or users publicly accessible in California, with later phases reaching large online platforms and GenAI hosting platforms in 2027 and capture-device manufacturers in 2028.
And it is about to change again, this month. SB 1000, an urgency rewrite, was presented to the Governor on 2 September 2026; he has until 30 September 2026 to act. As enrolled it would remove the one-million-user threshold, replace the AI detection tool with a "disclosure verification tool", drop the optional manifest disclosure, and revise latent-disclosure provisions - effective on signing, not 1 January 2027. Removing the threshold is the headline: it pulls in providers who scoped out on volume.
CPPA regulations on ADMT, risk assessments and cybersecurity audits were approved by OAL on 23 September 2025, effective 1 January 2026 and phased: risk-assessment compliance from 1 January 2026; ADMT significant-decision requirements (pre-use notice, opt-out, access rights) from 1 January 2027; first attestation and summary to the CPPA by 1 April 2028; cybersecurity audit certifications from 1 April 2028 for over USD 100m revenue, 2029 for USD 50-100m, 2030 for under USD 50m.
On employment, the Civil Rights Council's FEHA automated-decision-system regulations took effect 1 October 2025. Newsom vetoed SB 7, the "No Robo Bosses Act", on 13 October 2025 - but SB 947 (No Robo Bosses Act of 2026) passed 31 August 2026 and awaits the Governor by 30 September 2026; it would bar relying solely on an automated decision system to discipline or terminate workers, operative 1 July 2027. SB 903 (AI substitutes for mental-health professionals) and SB 813 (independent AI safety verification bodies) sit on the same desk, same deadline.
The preemption fight has produced one lawsuit and no statute
Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence", was signed 11 December 2025. A DOJ AI Litigation Task Force followed on 9 January 2026, with sole DOJ authority to challenge state AI laws on dormant Commerce Clause, preemption and other grounds (Paul Hastings). The EO carves out categories not to be preempted: child safety, AI compute and data-centre infrastructure (excluding generally applicable permitting reform), and state government procurement and use of AI.
There has been exactly one court action. xAI sued Colorado on 9 April 2026 (xAI v. Weiser, D. Colo. No. 1:26-cv-01515) on First Amendment, Equal Protection, dormant Commerce Clause and compelled-speech theories, and DOJ moved to intervene on 24 April 2026 - the first DOJ intervention against a state AI law. Caveat: whether the enforcement stay remains in place, and whether SB 26-189 mooted the case, could not be verified. The posture is unclear; check the docket.
As of early September 2026 that intervention remains the visible court posture under EO 14365, and there is still no federal AI statute and no enacted federal preemption. The Commerce Department's evaluation of "onerous" state AI laws, due 11 March 2026, was not publicly released as of the sources reviewed (Ropes & Gray). The White House's National Policy Framework for AI of 20 March 2026 is a set of recommendations to Congress, not law.
Congress has rejected preemption repeatedly: the 10-year state AI moratorium in budget reconciliation was stripped by the Senate 99-1 in 2025, and preemption was kept out of the FY2026 NDAA. The current vehicle remains a discussion draft - Reps. Obernolte (R-CA) and Trahan (D-MA) released the "Great American AI Act" draft on 4 June 2026, proposing a three-year preemption limited to state laws regulating AI model development, not use or deployment, plus transparency duties for large frontier developers. Not formally introduced as of September 2026. The real pressure is financial: the EO directs Commerce to explore withholding BEAD non-deployment broadband funds, roughly USD 21bn, from states with "onerous" AI laws (Tech Policy Press). Plan on the basis that state law governs.
How many US state AI laws are there? Depends who you ask
The NYU Center on Technology Policy, via Tech Policy Press on 6 July 2026, counted 109 enacted AI laws and 28 data-centre laws across 29 states as of 1 July 2026. The same date in 2025 showed 121 AI plus 27 data-centre laws. Full-year 2025: 159 AI laws and 37 data-centre laws across 46 states. NCSL, on a different methodology, is lower: "In the 2025 legislative session, all 50 states, Puerto Rico, the Virgin Islands and Washington, D.C. introduced legislation on this topic. Thirty-eight states adopted or enacted around 100 measures this year."
Roughly 100 versus 159 for the same year is not rounding - the trackers disagree about what counts. Attribute every number to its tracker.
Tech Policy Press puts the substantive trend bluntly: "This year has seen the near total collapse of broad algorithmic discrimination protection". States pivoted in 2026 to companion chatbots (14 laws from over 100 bills), data centres, health-insurer AI limits and AI dynamic pricing, with strong cross-partisan overlap. Colorado's retreat is the clearest instance.
How this compares to the EU AI Act
The EU has also moved. The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force 27 July 2026, deferring Annex III standalone high-risk obligations from 2 August 2026 to 2 December 2027 and Annex I embedded-product obligations to 2 August 2028. What did not move matters more: Article 5 prohibitions, in force since 2 February 2025; Article 4 AI literacy, GPAI model obligations and the AI Office, since 2 August 2025; and Article 50 transparency and AI-content labelling, applying from 2 August 2026 with a four-month grace period to 2 December 2026 for existing systems on the Article 50(2) marking duty only.
| Dimension | EU AI Act | US state law, September 2026 |
|---|---|---|
| Structure | Horizontal risk-tiering (prohibited / high-risk / limited / minimal) across all sectors | Sector- and use-case-specific. No state has a general risk tier; Colorado abandoned its "high-risk AI system" classification in May 2026 |
| Who bears duties | Provider-heavy, with a defined deployer layer (Articles 26-27) | Developer/deployer split is the norm (Colorado SB 26-189, California SB 53, Illinois SB 315), but the developer duty is documentation, not conformity assessment |
| Assessments | FRIA under Article 27, notified to the market surveillance authority, pre-deployment | Colorado's impact assessment is gone; Texas never had one; California's analogue is the CPPA privacy risk assessment - a privacy instrument, not a fundamental-rights one |
| Enforcement | AI Office plus national market surveillance authorities; Article 99 ceiling of EUR 35m or 7% of turnover; conformity assessment and CE marking | State AGs almost exclusively, under consumer-protection statutes, with notice-and-cure built in. Far lower ceilings (CA SB 53 USD 1m per violation; TX USD 200k uncurable). No ex-ante conformity assessment |
| Liability standard | Risk-based and outcome-oriented | Split within itself - Illinois HB 3773 uses discriminatory effect; Texas TRAIGA requires intent and rejects disparate impact |
Article 99's three tiers: EUR 35m or 7% of global turnover for prohibited practices; EUR 15m or 3% for high-risk and transparency breaches; EUR 7.5m or 1% for misleading information - higher-of for large firms, lower-of for SMEs and start-ups. Article 27 FRIAs bind public bodies, private entities providing public services and deployers of specified Annex III systems.
The EU gives a dual-market organisation one architecture; the US gives none. What ports across is not the risk classification but the evidence behind it.
What to actually do after the Colorado AI Act repeal
Map by use case and jurisdiction, not by a single risk tier. Use case down the side, jurisdiction across the top. A hiring screen in Illinois, Texas, New York City and Colorado sits in four regimes with four triggers; only Illinois creates exposure on outcomes alone.
Reuse the EU work. An Article 27 FRIA and a maintained inventory will over-satisfy most current US state duties. Colorado's four surviving obligations - documentation, notice, adverse-outcome explanation, human review - are downstream artefacts of a properly conducted FRIA.
Re-scope the Colorado inventory. Covered ADMT no longer requires inference, so deterministic tools that never appeared in an AI inventory can be in scope.
Keep the risk-management programme anyway. It is now a defence under TRAIGA's NIST AI RMF safe harbour rather than a Colorado mandate.
Review vendor indemnities in the eight Colorado sectors. Clauses shifting ADMT-related discrimination liability are void there from 1 January 2027.
Two dates for the calendar:
- 30 September 2026 - the Governor's deadline on California SB 1000 (urgency, effective on signing, removes the AI Transparency Act's one-million-user threshold), plus SB 947, SB 903 and SB 813.
- 26 October 2026 - close of the Colorado AG's ADMT and Chatbot rulemaking comment period, revised draft due 23 September 2026, ahead of 1 January 2027.
If you do nothing else this month: delete the Colorado AI Act workstream as scoped, diary 30 September for California, and read the revised Colorado draft rules when they land.
Related reading

The AI Governance Operating Model: Who Owns What, Who Signs, and How to Build the Machine
Most AI governance frameworks fail not because the policy is wrong but because nobody owns anything. Here's how to build the operating model that actually works - roles, RACI, forums, inventory, and a first-90-days plan.
The Cyber Resilience Act and the EU AI Act: Reporting Went Live on 11 September 2026 - What AI Product Makers Must Do Now
Since 11 September 2026, makers of software and connected products, including most AI products, must report actively exploited vulnerabilities within 24 hours under the Cyber Resilience Act. Here is how CRA reporting works, how CRA Article 12 links to AI Act Article 15, and how to build one incident playbook for both.
EU AI Act News: What the First 60 Days of Enforcement Actually Produced (August-September 2026)
2 August 2026 was supposed to be the day the EU AI Act got teeth. Sixty days later, here is what actually happened: the AI Office's first information requests to GPAI providers, a transparency Code of Practice with 200+ signatories, a new complaints tool, and a string of GDPR decisions that show where AI enforcement is really coming from.