Key point: On August 11, 2026, the Colorado Attorney General’s Office released draft regulations and a notice of proposed rulemaking to implement the state’s new Automated Decision-Making Technology (ADMT) Act, extending obligations to midstream developers, proposing detailed standards for when AI “materially influences” a decision, what post-adverse-outcome disclosures must contain, and what “meaningful human review” requires. Businesses operating in Colorado should review the draft rules now and consider submitting comments before the October 26, 2026 hearing.
Background
Colorado’s original AI statute, the 2024 Colorado AI Act, was the nation’s first comprehensive state AI law imposing a duty of reasonable care on developers and deployers of “high-risk” AI systems. On May 14, 2026, Governor Polis signed the ADMT Act (SB 26-189), which repeals and reenacts the 2024 law with a narrower framework centered on transparency and disclosure.
The ADMT Act takes effect January 1, 2027, and applies to consequential decisions made on or after that date. The August 11 release, together with a companion set of rules for the newly enacted Chatbot Safety Act (HB 26-1263), represents the Attorney General’s first formal step toward meeting that deadline.
Who and what is covered?
The ADMT Act and proposed rules apply to “developers” and “deployers” of “covered ADMT,” which is automated decision-making technology used to “materially influence” a “consequential decision.” Consequential decisions include an individual’s access to, eligibility for, or terms of:
- education;
- employment;
- residential real estate;
- financial or lending services;
- insurance;
- health-care services; and
- essential government services and public benefits.
Developers are persons doing business in Colorado that (i) develop, offer, sell, lease, license, or otherwise make commercially available covered ADMT, (ii) develop a component of covered ADMT, or (iii) intentionally and substantially modify an ADMT such that it becomes covered ADMT. Under the statute, developers must supply deployers with documentation about the covered ADMT’s intended uses, training data, known limitations, and material updates. The draft regulations specify what the developer’s required documentation must include on each topic.
Deployers, on the other hand, are persons doing business in Colorado that “deploy” covered ADMT, which the draft regulations define as “make use of Covered ADMT in a way that Materially Influences a Consequential Decision.” Under the statute, deployers must give consumers clear and conspicuous notice before using covered ADMT to materially influence a consequential decision. If that decision results in an adverse outcome, deployers have 30 days to explain the decision, describe the ADMT’s role, and inform the consumer of their rights to request personal data, correct inaccuracies, and seek meaningful human review.
The draft regulations address another type of entity not covered in the statute: A “midstream developer,” under the proposed rules, is a party that integrates a covered ADMT as a component into its own covered ADMT product and then supplies that product to another developer or deployer for further configuration before deployment. Under the proposed regulations, a midstream developer must reasonably obtain the upstream developer’s required documentation for any covered ADMT it incorporates and then make that documentation available to any downstream developer or deployer. The notice of proposed rulemaking flags these types of multiparty arrangements as an area of active interest, asking for comment on how the rules should define “ADMT vendor” and allocate responsibility between a deployer and a third-party vendor operating the ADMT on the deployer’s behalf.
Defining “materially influence”
The draft regulations do not rewrite the ADMT Act’s requirements, but they do begin to fill in details the legislature had left to rulemaking. The most significant gap concerns the very definition of when ADMT “materially influences” a decision.
The statute defines ADMT as a technology that processes personal data and uses computation to generate output, including predictions, recommendations, classifications, rankings, scores, or other information that is used to make, guide, or assist a decision, judgment, or determination concerning an individual.
Notably, the definition does not clearly describe whether a human being’s role in the decision-making process affects whether a given tool is an ADMT or not. Instead, the statute lists sixteen examples of technologies that are not ADMT, three of which presume human involvement in the analysis. Colorado’s definition contrasts with California’s ADMT regulations, which define ADMT as a technology that substantially or completely replaces human decision-making,
Likewise, Colorado’s definition of “materially influence” does not address the role of a human being involved in the output. Rather, the statute defines “materially influence” to require that an ADMT output be a “non-de minimis factor” that affects the outcome of a consequential decision, and it gives the Attorney General authority to clarify that standard. In the Notice of Proposed Rulemaking, the Attorney General is requesting public comment on two alternative standards for the factors that “materially influence” an ADMT output.
For Standard #1, a de minimis factor would only have a trifling, trivial, or incidental impact on the outcome, and would consider whether:
- The decision maker reviewed the ADMT output before coming to a decision;
- The decision reached is the same as, or consistent with, the ADMT output;
- The decision maker saw the primary evidence or only the ADMT output before reaching the decision; and
- The decision maker’s judgment was independent of the ADMT output.
For Standard #2, a de minimis factor is one that is not a substantial factor in the outcome, and would consider whether:
- The decision maker reviewed and analyzed other information independent of the ADMT output;
- The ADMT output played a significantly smaller role in the decision reached than the other information (reviewed and analyzed);
- The other information reviewed was consistent with the outcome;
- The decision maker has a subject matter understanding to reach the decision based on the other relevant information (reviewed and analyzed); and
- The decision maker had the authority to reach or change the decision based on their independent review and analysis.
Both standards include factors that trigger a presumption of material influence, and both standards allow for the rebuttal of that presumption. The proposed standards differ mainly in how high the bar will be to rebut the presumption that an ADMT output materially influences a consequential decision in the factors used to assess independence of human judgment.
Looking at today’s workflows and today’s uses of automated technologies, it appears that it would be easier to satisfy the factors under Standard No. 2 and assert that a given technology falls outside the ADMT Act’s reach. The Attorney General’s Office is actively soliciting comments on which approach (if either) should be adopted.
Post-adverse-outcome disclosures
The draft rules also propose substantial detail on the post-adverse-outcome disclosures that have generated significant compliance interest since the statute was enacted. Under the draft rules, a disclosure following an adverse outcome must:
- Describe the specific consequential decision that was made;
- Describe the deployer’s purpose in using the ADMT and the respective roles of the ADMT and any human reviewers;
- State the effective date of the adverse outcome, where applicable;
- Describe the principal reasons for the outcome with real specificity — a generic reference to “internal standards or policies” would not suffice;
- Describe whether the principal reasons consisted of inferences based on personal data and/or profiles, risks or other scores about the individual (where applicable); and
- Describe any automatic-denial factors based on the individual’s personal data.
The draft rules include illustrative, sector-specific examples spanning education, housing, lending, insurance, and employment to show what compliant disclosure language might look like in practice, while making clear that deployers remain responsible for tailoring disclosures to their own facts and for independently confirming that their underlying decision-making practices comply with other applicable law.
Meaningful human review
The draft rules also flesh out what “meaningful human review” requires. The proposed rules call for a reviewer who:
- Is independent of the original decision-maker whenever feasible;
- Has a level of subject matter understanding commensurate with the nature and consequences of the adverse outcome under review;
- Has training in decision-making accuracy and objectivity, and the information considered by the covered ADMT;
- Has genuine authority to approve, modify, or override the decision; and
- Is shielded from managerial pressure that might compromise the reviewer’s independence.
Notably, the draft rules would prohibit the reviewer from using ADMT to assist in conducting the review itself. The rules also provide some clarity on the “commercially reasonable” standard, which the statute uses to gauge how far a deployer must go to provide human review. The rules list factors such as the magnitude and reversibility of the harm, the deployer’s size and capacity, and the availability of qualified reviewers, while creating a presumption that review is commercially reasonable where the harm amounts to a severe and irreversible denial of a basic human need, such as housing.
The companion Chatbot Safety Act rules
Beyond the ADMT Act, the same proposed rulemaking addresses the Chatbot Safety Act, which imposes a distinct set of obligations on operators of consumer-facing conversational AI services. The statute encompasses age-assurance requirements, disclosures that a user is interacting with AI rather than a human, protections for minors against sexually explicit content and simulated emotional dependence, and annual reporting to the Attorney General on suicide and self-harm safeguards.
The draft rules propose detailed criteria for several of the Chatbot Safety Act’s exemptions and undefined terms, including:
- What classifies as a conversational AI service “designed to simulate emotional companionship”;
- What qualifies as a business-focused service exempt from the law; and
- What “commercially reasonable” age-assurance methods look like, explicitly disfavoring reliance on self-declared age or government ID as the sole method.
Timeline for comment
The rulemaking process is now underway and moving on a compressed timeline. According to the Notice of Hearing, the Department of Law has scheduled a public hearing for October 26, 2026, in Denver and by videoconference, and it is accepting written comments through the same date, with an earlier deadline of September 4, 2026, for comments to be considered in any revisions presented at the hearing. Any interim updates to the proposed rules will be posted on the Department of Law’s website by September 23, 2026.
Given that the ADMT Act must take effect January 1, 2027, regardless of whether rulemaking is complete, businesses should not wait for final rules to begin compliance planning. The core statutory obligations (point-of-interaction notice, post-adverse-outcome disclosure, and consumer rights to data access, correction, and human review) are already set by statute and will apply on the effective date whether or not the Attorney General finalizes implementing rules beforehand.
Looking ahead
For companies operating in Colorado the draft rules are a strong signal of where the Attorney General intends to draw lines on some of the statute’s most significant and previously undefined terms, particularly “materially influence” and “meaningful human review.” Businesses should review their AI-driven decision processes now, evaluate whether they are likely to be treated as covered ADMT under either proposed materiality standard, and consider whether their current consumer notices and adverse-outcome procedures would satisfy the disclosure content the draft rules describe. Companies with a stake in how these definitions are ultimately drawn also have a real opportunity to participate directly in the process by submitting written comments or testifying at the October hearing before the rules are finalized.
Contact us
If you have questions regarding your use of AI in the workplace as a developer or deployer, or you want to discuss submitting comments about the draft rules, contact Erik Dullea, Owen Davis, or your Husch Blackwell attorney.
Recent Comments