Colorado Repealed Its AI Act — What Replaces It

Colorado replaced its risk-based AI Act with a disclosure law effective Jan 2027, and the EU delayed its deadline too. Why your chatbot should comply now.

Cover Image for Colorado Repealed Its AI Act — What Replaces It

This summer was supposed to be the AI compliance reckoning. Colorado's Artificial Intelligence Act, the first comprehensive state AI law in the country, was set to take effect June 30. The EU AI Act's high-risk obligations were due August 2. Businesses spent months preparing impact assessments and governance programs for both.

Then, in a two-week stretch in May, both deadlines moved.

On May 14, 2026, Colorado Governor Jared Polis signed SB 189, which repealed the original AI Act outright and replaced it with a narrower law that does not take effect until January 1, 2027. A week earlier, on May 7, EU lawmakers reached political agreement to defer the AI Act's high-risk obligations by more than a year.

If you run a chatbot on your website, the temptation is to file this under "good news, ignore for now." That would be a mistake. The deadlines slipped, but the direction did not, and the practical work is largely the same. Here is what actually changed, what survived, and what you should do about it.

What Colorado Actually Did

The original Colorado AI Act (SB 24-205, signed in 2024) was modeled on the EU's risk-based approach. It would have required developers and deployers of "high-risk AI systems" to maintain risk management programs, run annual impact assessments, and exercise a duty of reasonable care to prevent algorithmic discrimination. It was first slated for February 1, 2026, then pushed to June 30 during a 2025 special session.

SB 189 throws that framework out and starts over. The new law drops the impact-assessment regime, the standalone duty to prevent algorithmic discrimination, and the mandatory risk-management programs. In their place is a transparency-and-consumer-rights model built around "automated decision-making technology" (ADMT).

Old: SB 24-205 (repealed)New: SB 189 (effective Jan 1, 2027)
ApproachRisk-based, EU-styleTransparency + consumer rights
Core dutyReasonable care to prevent algorithmic discriminationNotice, documentation, human review
Impact assessmentsRequired annuallyNot required
Small-business exemptionYes (under 50 employees)Removed
EnforcementAttorney GeneralAttorney General (no private right of action)
Effective dateJune 30, 2026January 1, 2027

The reframe matters. Colorado moved from policing outcomes (did your system discriminate?) to policing transparency (did you tell people a machine was involved, and can they contest it?). That is a meaningfully lighter lift for most businesses, and it lines up with where US regulation has been drifting all year: away from the EU model and toward disclosure.

What the EU Did

The EU AI Act's high-risk obligations for Annex III systems — the categories covering employment, credit, insurance, education, and essential services — were scheduled to apply August 2, 2026. On May 7, EU lawmakers agreed on a package, informally the "Digital Omnibus," that defers those obligations to December 2, 2027 for standalone high-risk systems, and to August 2, 2028 for AI embedded in already-regulated products.

One caveat worth stating plainly: that deferral is a political agreement, not yet law. It only takes legal effect once formally adopted and published in the Official Journal. Until then, August 2, 2026 technically remains on the books. If your business touches EU users with a genuinely high-risk system, treat the old date as live until the new one is final.

Delay Is Not Dismissal

Two of the year's biggest AI deadlines slipping inside two weeks is not a coincidence. Both moved for the same reasons: the compliance burden was heavier than lawmakers expected, the cost fell hardest on smaller operators, and the rules were drafted before anyone had run them in production.

What did not change is the destination. Every version of every one of these laws — the repealed Colorado act, the new one, the EU framework, the dozens of state bills we covered in our breakdown of 2026 chatbot laws — agrees on the same baseline: people have a right to know when they are dealing with a machine, and a right to reach a human when the machine gets it wrong. The deadlines are negotiable. That principle is not.

So the right read on the delay is not "stop." It is "you have more time to do the thing you were always going to have to do."

Does Your Chatbot Even Fall Under This?

Here is the part most coverage skips. SB 189 does not regulate every chatbot. It regulates "automated decision-making technology" that materially influences a consequential decision in one of seven domains:

  • Education and educational opportunity
  • Employment or employment opportunity
  • Housing (property leases and purchases)
  • Financial or lending services
  • Insurance
  • Healthcare services
  • Essential government services

The operative phrase is "materially influence a consequential decision." A typical website chatbot — one that answers product questions, deflects support tickets, or captures leads — does not make or influence decisions in those categories. It informs a human; it does not decide for one. That kind of bot largely sits outside SB 189's ADMT obligations.

The bots that are squarely in scope are the ones quietly making gatekeeping calls:

Chatbot use caseMaterially influences a consequential decision?
Product FAQ / support deflectionNo
Lead capture and routingNo (unless it qualifies/scores applicants)
Order tracking, returns, schedulingNo
Screening or ranking job applicantsYes — employment
Pre-qualifying loan or credit applicantsYes — financial services
Triaging patients or recommending careYes — healthcare
Assessing rental or insurance eligibilityYes — housing / insurance

If your chatbot lives in the bottom half of that table, SB 189 expects real things from you starting in 2027: clear notice before the decision, a plain-language explanation of the technology's role after an adverse outcome, and a route to meaningful human review — defined as review by someone with the authority to override the system, who looks at the underlying evidence rather than rubber-stamping the output. Developers in scope must also hand deployers documentation of intended uses, known risks, and limitations, and retain records for three years.

If your chatbot lives in the top half, your obligations are lighter — but not zero, because a different set of rules never went away.

What Survived the Reset

The delays apply to two specific laws. They do not touch the baseline that has governed chatbots all along.

FTC deception rules are active now. A chatbot that pretends to be human, or that confidently states things that are not true, is a deceptive practice under the FTC Act regardless of what any state does. This is the exposure that bites first in practice — it is the Air Canada problem, where a company was held to what its bot told a customer. No deadline was ever attached to it.

State disclosure laws are already in effect. Maine's Chatbot Disclosure Act has required businesses to tell users they are talking to AI since September 2025. California's AB 489 restricts AI from implying healthcare licensure. These are live today, not in 2027.

Colorado's enforcement clock is set. SB 189 gives the Attorney General exclusive enforcement, with a 60-day cure period for most violations — but that cure period expires January 1, 2030. After that, the grace window closes. The runway is long, but it is finite, and it favors businesses that build compliant habits now rather than scrambling later.

The Checklist You Can Run Today

None of this requires waiting for 2027. The steps that satisfy the new Colorado law, the EU framework, and the disclosure laws already in force are the same handful of things, and they happen to be good chatbot design.

Disclose that it is AI, clearly. This is the one universal requirement across every law, delayed or not. Name the bot so it reads as a bot, and open every conversation by saying so. On Agentkit you set the chatbot's name, avatar, and greeting, so a line like "I'm an AI assistant for [Company] — how can I help?" satisfies the disclosure baseline at the point of interaction.

Know whether your bot touches a consequential decision. Run your use case against the seven domains above. If it screens, scores, ranks, or qualifies people for jobs, credit, housing, insurance, healthcare, or government services, treat it as in-scope ADMT and build for it. If it answers questions and routes leads, it is almost certainly not, and you can right-size your effort accordingly.

Offer meaningful human review. Both the new Colorado law and basic customer trust point the same way: people need a path to a person. A "talk to a human" trigger and a clean escalation flow cover it. The handoff between AI and human is the hardest part to get right, and the part regulators care about most.

Log and retain conversations. SB 189 expects records kept for three years, and logs are your evidence either way. Conversation logs and analytics ship on every Agentkit plan; the discipline is reviewing them, not just collecting them.

Let users reach their data. The new law gives consumers the right to access and correct inaccurate personal data used in a decision. If your bot captures names, emails, or other details, make sure that data is findable and correctable, and that your privacy policy covers it.

Keep the bot on topic. A chatbot that stays inside its business purpose is easier to defend than one that wanders into advice it was never meant to give. Tight prompt engineering and curated training sources keep it from drifting into territory — medical, legal, financial — where the regulatory stakes climb.

The Bottom Line

The headline is that Colorado repealed its AI Act and the EU pushed its deadline, and it is tempting to read that as a reprieve. It is not, really. The specific dates moved; the standard the dates were enforcing did not. Be transparent that customers are talking to a machine. Keep that machine out of decisions it has no business making alone. Give people a way to reach a human and to fix what the system got wrong.

Every one of those is something a good chatbot should already do — which is the quiet point behind a year of churning regulation. The laws are slowly codifying what users have wanted all along. Build a chatbot that discloses what it is, stays in its lane, and hands off gracefully, and the next deadline — whenever it actually lands — is a formality rather than a fire drill.

Build your chatbot for free →

No credit card required.

Get started freeNo credit card required