Colorado shifts AI law from risk rules to disclosure
Colorado lawmakers amended the state AI law (SB 26-189), replacing parts of its risk-management regime with disclosure-focused rules and delaying some high-risk mandates for employers.

Colorado lawmakers moved to rework the state's landmark AI statute by approving SB 26-189 and related measures that pull parts of the earlier risk-based Colorado AI Act toward a disclosure- and transparency-focused regime.
In June 2026 the legislature enacted the package, which trims or delays several obligations that had forced employers and HR-technology vendors to start building comprehensive risk-management programs and impact assessments. The amendments instead emphasize notice and disclosure about the use of automated decision systems and push back or narrow the timing and scope of “high‑risk” mandates that had been on a rapid compliance calendar.
Privacy and legal analysts who have followed the changes say the shift is material for employers. IAPP reported that the revisions exchange some pre-emptive, risk‑management measures for new notice and transparency duties, effectively changing what compliance teams and vendors will have to document and disclose to workers and job applicants. For organisations that had scoped tools and third-party contracts around the original risk‑based obligations, the practical effect is a re‑write of compliance roadmaps.
The GLACIS guide to the Colorado AI Act highlights how the amendments recalibrate deadlines and redefine which systems trigger tougher controls. Where the earlier regime leaned on mandatory risk assessments and formalised control measures for systems deemed high risk, the new language leans on public-facing and user-facing transparency obligations — for example, clearer disclosure when automated systems materially affect hiring, promotion or termination decisions — while postponing some of the more prescriptive governance duties.
Legal advisers and HR technology vendors have been parsing the change for weeks. Several vendors that had been marketing risk-management modules and bias‑testing services told clients to pause rollouts or adapt roadmaps to prioritise disclosure features and recordkeeping that will be required under the amended law. The move also complicates procurement: contracts that baked in audit, certification or remediation timelines tied to the previous risk‑management standard now may need re‑negotiation.
This legislative turn comes amid a broader, fragmented U.S. regulatory landscape. BCLP’s legislative tracker shows Colorado’s pivot is one of several state-level variations appearing across the country as legislators weigh how prescriptive to be about AI tools in employment. The result is a patchwork where employers with multi-state workforces must map differing mixes of disclosure duties, impact assessments and timing requirements into a single compliance program.
What the amendments did not make clear is how enforcement will be prioritised, how regulators will evaluate the sufficiency of disclosures, or what technical standards — if any — will be imposed for bias audits and documentation. The bills stop short of setting detailed testing regimes or requiring third‑party certification, and they do not spell out administrative fines or civil penalties in precise terms tied to disclosure failures. There is also limited guidance in the statutes about how employers should reconcile state disclosure duties with federal worker‑privacy and employment‑law obligations.
For HR leaders and talent‑technology suppliers the immediate task is operational: update inventories of automated decision systems, review candidate and employee notices, and revise vendor contracts and service-level obligations to reflect disclosure and recordkeeping first. Longer term, the Colorado shift illustrates a political and regulatory balancing act — lawmakers tempering prescriptive governance in favour of transparency, while leaving open the possibility of re‑introducing tighter risk mandates once implementing guidance or enforcement priorities crystallise. That means HR teams must be ready to switch from disclosure compliance to heavier risk management again if state or federal policy moves in that direction.