Colorado Enacts Comprehensive AI Legislation to Combat Algorithmic Discrimination

On May 17, 2024, Colorado set a precedent by becoming the first U.S. state to enact comprehensive artificial intelligence (AI) legislation. The new law, effective February 1, 2026, aims to safeguard Colorado residents against potential harms arising from AI use, with a particular emphasis on preventing discrimination in decision-making processes.

The legislation mandates that developers and deployers of high-risk AI systems exercise reasonable care to mitigate known or reasonably foreseeable risks of algorithmic discrimination. Specific obligations are placed on both developers and deployers to ensure protection against such discrimination. Developers are required to provide clear instructions on the proper use and monitoring of AI systems. Deployers, on the other hand, must conduct detailed impact assessments on their AI usage. An affirmative defense is available for developers and deployers who can demonstrate that they have addressed any discovered violations and comply with a recognized AI risk management framework, such as the National Institute of Standards and Technology (NIST) AI Risk Management Framework.

Become a Subscriber

Please purchase a subscription to continue reading this article.

Subscribe Now

The law includes several exemptions to ensure practicality and flexibility. Certain technologies, including calculators and some chatbots, are specifically excluded from the legislation. Additionally, companies with fewer than 50 full-time employees are exempt from certain deployer responsibilities, although this exemption is subject to various conditions. Other common exemptions align with those in existing consumer protection laws, such as those enabling compliance with law enforcement or applying to companies already subject to similar sector-specific regulations.

The legislation does not provide a private right of action; instead, enforcement authority is vested exclusively in the Colorado Attorney General. The Attorney General can seek penalties of up to $20,000 per violation. Moreover, the Attorney General is authorized to promulgate rules on specific topics under the law. Colorado’s proactive approach to AI regulation is a significant step in addressing the ethical and societal impacts of rapidly evolving technologies. By imposing stringent requirements on high-risk AI systems, the state aims to prevent discriminatory practices and promote fair treatment for all residents. The law’s comprehensive nature and its focus on recognized risk management frameworks highlight the importance of responsible AI development and deployment.

This landmark legislation positions Colorado as a leader in AI governance, reflecting growing concerns about the implications of AI in various sectors. As AI continues to integrate into daily life and business operations, Colorado’s legislation may serve as a model for other states and countries seeking to balance innovation with ethical considerations and consumer protection.