Colorado's AI Governance Retreat: What SB 26-189 Means for Enterprise Compliance Programs
The most ambitious state-level attempt to impose substantive AI governance obligations on private-sector organizations has been substantially scaled back before implementation. Compliance teams building programs around state AI laws should treat regulatory requirements as moving targets rather than fixed anchors.
⚖️ What Was Lost in the Rewrite
The strongest AI governance law in the United States never governed anything.
Colorado’s 2024 AI Act (SB 24-205) never took effect. Instead, Governor Polis signed SB 26-189 on May 14, 2026, repealing and reenacting the framework as a substantially narrower regime centered on transparency, documentation, and consumer rights, with most substantive obligations taking effect on January 1, 2027.
For practitioners who spent the past two years modeling compliance programs around the original law, the lesson is structural rather than procedural.
When Colorado enacted SB 24-205 in 2024, it adopted many of the concepts found in the EU AI Act: risk-based obligations, duties of care, risk management programs, impact assessments, and affirmative governance requirements for high-risk AI systems. For financial-services professionals, the architecture looked familiar because it mirrored many of the same principles underlying model risk management frameworks such as SR 26-2.
SB 26-189 removes most of those governance obligations and replaces them with requirements focused on notice, transparency, documentation, and consumer rights relating to covered Automated Decision-Making Technologies (ADMTs).
| SB 24-205 (2024) | SB 26-189 (2026) |
|---|---|
| Duty of reasonable care | Removed |
| Mandatory risk management program | Removed |
| Pre-deployment impact assessments | Removed |
| Discrimination self-reporting to AG | Removed |
| Pre-use notice | Retained |
| Developer documentation requirements | Added/Expanded |
| Record retention requirements | Added |
| Data correction rights | Added |
| Human review / reconsideration rights | Added |
| Adverse decision explanation rights | Added |
The difference is significant. The original law focused on governing how organizations develop and manage AI systems. The replacement law focuses primarily on what organizations must disclose, document, and provide to affected individuals.
Enforcement remains exclusively with the Colorado Attorney General under the Colorado Consumer Protection Act. Violations are treated as deceptive trade practices, and the statute does not provide a private right of action.
🏛️ How It Happened: State Ambition Meets Federal Resistance
When Governor Polis signed SB 24-205 in 2024, he simultaneously expressed concerns about the law’s complexity and invited further legislative refinement. Over the following year, lawmakers, industry groups, civil-society organizations, and regulators engaged in extensive negotiations over implementation.
Those discussions later collided with a rapidly changing federal environment.
In December 2025, the Trump Administration issued an executive order directing federal agencies to examine state AI regulations and challenge laws viewed as unnecessarily burdensome to innovation. Several state AI laws subsequently became targets of heightened legal and political scrutiny.
The most direct challenge came in Colorado. In April 2026, xAI filed suit in federal court seeking to block implementation of the Colorado AI Act, arguing that portions of the law were constitutionally defective and imposed unlawful burdens on interstate commerce.
The litigation remains active. A court-approved stay currently pauses implementation efforts, including rulemaking activities associated with the replacement legislation. As a result, the practical enforcement timeline remains uncertain even though the statutory effective date is January 1, 2027.
📋 What Remains — and Why It Still Matters
Although SB 26-189 is significantly narrower than its predecessor, it should not be mistaken for a purely disclosure-based law.
Organizations deploying covered ADMTs must still provide notices, maintain documentation, preserve records, respond to consumer requests, support data correction processes, and offer meaningful opportunities for human review in certain circumstances. These obligations create operational and governance requirements even in the absence of formal risk-management mandates.
The law is also broader in one important respect: it extends protections to employees and job applicants, groups that are generally outside the scope of the Colorado Privacy Act.
Another provision deserves particular attention from procurement and legal teams. SB 26-189 invalidates contractual provisions that attempt to indemnify a party for its own discriminatory conduct involving covered ADMTs. Organizations relying heavily on vendor contracts to allocate AI-related liability should review those arrangements carefully.
That issue connects directly to a broader vendor-risk challenge. When contractual risk transfer becomes less reliable, organizations retain greater responsibility for understanding how third-party AI systems affect consequential decisions. Removing formal risk-management requirements does not remove the underlying risk.
🔭 The Broader Governance Lesson
The most important lesson from Colorado is not that AI regulation is disappearing. It is that state-level AI governance frameworks remain highly vulnerable to political, legal, and economic pressure.
Two years ago, Colorado appeared poised to become the closest U.S. analogue to the EU’s risk-based AI governance model. Today, that framework has been substantially narrowed before taking effect.
For compliance leaders, this is a reminder that regulatory strategies built around any single state AI law may require rapid adjustment. The challenge is no longer simply tracking new requirements. It is anticipating how quickly those requirements can change.
The January 1, 2027 effective date remains the key planning horizon. However, the ongoing litigation means implementation timelines may continue to evolve. Organizations should prepare for compliance with the statute as written while recognizing that further legal developments could alter the landscape yet again.
Meanwhile, the transatlantic divergence continues to widen. As Europe accelerates toward enforcement of increasingly detailed AI governance obligations, Colorado’s experience suggests the United States may be moving toward a more limited transparency-and-rights-based approach, at least for now.
That divergence is becoming a material design constraint for organizations operating across jurisdictions.