Colorado ADMT compliance guide
Colorado’s ADMT law focuses on developers and deployers of automated decision-making technology used for consequential decisions. Stacksona may be relevant when organizations need to route consequential AI-agent actions to reviewers and preserve evidence, but it does not supply every notice, rights, governance, testing, or legal-analysis obligation.
Direct answer
Colorado’s ADMT law focuses on developers and deployers of automated decision-making technology used for consequential decisions. Stacksona may be relevant when organizations need to route consequential AI-agent actions to reviewers and preserve evidence, but it does not supply every notice, rights, governance, testing, or legal-analysis obligation.
Source: Colorado Attorney General AI rulemaking page; Colorado General Assembly SB26-189 Automated Decision-Making Technology
Regulatory summary
Colorado Automated Decision-Making Technology in Consequential Decisions Act applies in Colorado with status: Replacement ADMT law enacted in 2026; effective January 1, 2027. The practical compliance question is whether the organization, system, decision, and use case fit the covered scope.
Relevant sectors and businesses
These broad categories may need to review the guide when AI agents support covered or sensitive decisions.
Who may be affected
- Deployers using ADMT to make or materially influence consequential decisions involving Colorado consumers.
- Developers of ADMT made available for consequential-decision use.
- Employers, insurers, lenders, healthcare, housing, education, and government-adjacent workflows should assess applicability.
Covered technology
- Automated decision-making technology that materially influences consequential decisions.
- AI, algorithmic, or software systems that rank, recommend, classify, score, or trigger an outcome.
- Agent workflows that can create or route recommendations before a human or system makes a final decision.
Covered decisions
- Education enrollment or opportunity.
- Employment or employment opportunity.
- Financial or lending services, housing, insurance, healthcare, legal services, and government services.
Main requirements
- Provide notices and post-decision disclosures where required.
- Support consumer rights processes for correction, appeal, or human review where applicable.
- Maintain governance practices appropriate to the role of developer or deployer.
- Document how ADMT is used and how consequential decisions are handled.
Human-review implications
Human review is most valuable when the reviewer can independently assess the proposed consequential action, see the ADMT output and rationale, consider new information, and record a decision rather than rubber-stamping an automated recommendation.
Record requirement: Maintain records of notices, disclosures, appeal outcomes, reviewer decisions, ADMT versions, and workflow evidence.
Self-assessment questions
- Does the workflow involve a covered organization, consumer, patient, employee, applicant, or similarly protected person?
- Does software make, recommend, or materially influence a decision?
- Can the action be paused before execution for qualified human review?
- What evidence would prove what the reviewer saw and decided?
Practical workflow example
- An agent recommends rejecting an applicant, escalating an account, or changing eligibility.
- A policy checks whether the action is consequential and routes it for review.
- The reviewer receives source facts, agent rationale, system confidence, and proposed downstream change.
- The decision thread links the decision, reviewer notes, and final execution status.
When Stacksona may be relevant
Stacksona is relevant when a regulated or sensitive AI-agent action needs an approval step, reviewer context, and a decision record before the action runs.
Requirement-to-capability table
| Compliance need | Stacksona capability |
|---|---|
| Identify a proposed action | Show what the agent wants to do before execution. |
| Pause and route for review | Send covered actions to the right reviewer or team. |
| Preserve reviewer evidence | Store approval, rejection, comments, timestamps, and outcome. |
| Export a decision record | Help teams share records with legal, risk, operations, or compliance. |
When Stacksona is not the complete solution
Stacksona does not replace legal advice, policy design, required notices, impact assessments, model validation, clinical judgment, anti-discrimination testing, vendor management, or full regulatory reporting.
Pending questions or rulemaking
- The Colorado Attorney General rulemaking and guidance may clarify definitions, notice content, appeal mechanics, developer/deployer duties, and enforcement expectations before January 1, 2027.
Official sources
Update history
- 2026-07-14: Initial Stacksona guide published after Colorado replacement-law status became public.
Informational disclaimer
This guide is for general informational purposes only. It is not legal advice and does not create an attorney-client relationship. Consult qualified counsel for advice about your obligations.
Use this guide to plan AI approval controls
When a compliance review points to human oversight, Stacksona can help teams test the approval path before an AI agent sends a message, changes a record, exports data, or triggers another sensitive action.