In May 2024, Colorado enacted the Colorado Artificial Intelligence Act (“CAIA”), becoming the first state in the U.S. to implement comprehensive legislation regulating the development and deployment of “high-risk” AI systems making “consequential decisions” about consumers that could result in “algorithmic discrimination” in the areas of education enrollment, education opportunity, employment or employment opportunity, financial or lending services, essential government services, health care services, housing, insurance, and legal services. The CAIA is scheduled to take effect on February 1, 2026.
Key Provisions of the CAIA
The CAIA imposes distinct obligations on both developers and deployers of high-risk AI systems:
- “Developers” (those who have created or coded the high-risk AI system) must:
- Exercise reasonable care to prevent algorithmic discrimination by the high-risk AI system.
- Provide documentation detailing the purpose and uses of the high-risk AI system, training data/data governance, limitations, and discrimination risk mitigation.
- Disclose known or reasonably foreseeable risks of algorithmic discrimination to the Colorado Attorney General and affected parties within 90 days of discovery.
- “Deployers” (those who make the high-risk AI system available to consumers) must:
- Implement a risk management policy and program to govern the deployment of the high-risk AI system.
- Conduct annual impact assessments evaluating the high-risk AI system’s performance and potential discriminatory outcomes.
- Notify consumers when high-risk AI systems are used in consequential decisions and provide avenues for appeal and correction.
Industry Concerns and Proposed Amendments
Despite the CAIA’s pioneering status, industry stakeholders have expressed concerns regarding its breadth and potential impact on innovation:
- Broad Definitions: Critics argue that the CAIA’s definition of “high-risk” AI systems is overly expansive, potentially encompassing routine business tools.
- Liability for Developers: The law holds developers accountable for discriminatory outcomes, even when AI systems are modified or misused by third parties, raising concerns about fair liability distribution.
- Compliance Challenges for Small Businesses: Smaller enterprises fear that the compliance requirements, such as annual impact assessments and public disclosures, may impose disproportionate burdens.
In response, Colorado lawmakers introduced Senate Bill 318 in April 2025, aiming to refine the CAIA by:
- Narrowing the definition of “algorithmic discrimination” to align with violations of existing anti-discrimination laws;
- Adjusting the scope of what constitutes a “consequential decision;” and
- Proposing exemptions for businesses with fewer than 500 employees during the initial implementation phase of the CAIA.
However, Senate Bill 318 faced opposition from both consumer advocates and the tech industry, leading to its withdrawal in May 2025. Consequently, the CAIA is set to take effect as originally enacted, though discussions about potential amendments continue.
Preparing for Compliance
With the CAIA’s implementation date approaching, organizations should proactively:
- Identify whether their AI systems fall under the “high-risk” category as defined by the CAIA;
- Establish or update their AI governance policies in line with recognized standards to demonstrate reasonable care in avoiding algorithmic discrimination; and
- Stay informed about potential legislative changes that may affect compliance obligations.
At Fortis Law Partners, we are committed to assisting clients in navigating the complexities of the CAIA and ensuring readiness for its forthcoming requirements.
For further guidance on aligning your operations with the Colorado Artificial Intelligence Act, please contact Spencer Rubin.
Spencer Rubin is a Senior Associate in the corporate group at Fortis Law Partners, specializing in technology transactions, AI governance, commercial transactions, corporate governance, and M&A.
