A federal magistrate blocked enforcement of Colorado's AI Act on April 27, and the headlines read as a reprieve. For insurers it is not one. The temporary restraining order reaches SB 24-205, enforced by the Attorney General. The bias testing and documentation obligations that bind carriers come from SB 21-169 and Regulation 10-1-1, enforced by the Commissioner of Insurance, never challenged in court, and still due July 1, 2026.

Key Takeaways

  • Two statutes, two enforcers. SB 24-205 sits with the Attorney General and is stayed. SB 21-169 and Regulation 10-1-1 sit with the Division of Insurance and are not.
  • Nine protected classes are covered by SB 21-169, narrower than SB 24-205's thirteen-plus, and the July 1 report must show bias testing results across all of them.
  • The four-fifths rule sets an 80% threshold on selection rates, but the proxy variable audit is the component that reaches traditional rating variables, and it carries no fixed threshold at all.
  • Testing runs in hours; documentation runs eight to twelve weeks from an unstructured baseline, which is the constraint auto and health carriers filing their first full report are actually against.
  • SB 26-189 passed May 7 and May 9, 2026 and would eliminate mandatory bias audits from January 1, 2027. It replaces SB 24-205 and leaves SB 21-169 untouched.

Which Track Actually Binds

Colorado regulates AI in insurance on two statutory tracks, and conflating them is the common error.

SB 24-205, the Consumer Protections for Artificial Intelligence Act signed in May 2024, is economy-wide and applies to deployers of high-risk AI systems making consequential decisions. It carries a safe harbor at Section 10-3-1104.9 for insurers already complying with DOI rules on algorithms and predictive models, a point we mapped in our analysis of the June 30 deadline.

SB 21-169, signed in July 2021, is insurance-specific and governs External Consumer Data and Information Sources in underwriting, rating and claims. Regulation 10-1-1 implements it, effective for life insurers from November 14, 2023 and extended to private passenger auto and health benefit plan insurers when the amended version took effect October 15, 2025.

xAI filed suit on April 9, 2026 in the District of Colorado, Case No. 1:26-cv-01515, on six constitutional grounds. The Department of Justice intervened on April 24, the first federal move to invalidate a state AI law under Executive Order 14365, and Magistrate Judge Cyrus Y. Chung issued a TRO on April 27 running until 14 days after a ruling on the forthcoming preliminary injunction motion.

None of that litigation names SB 21-169. Auto and health carriers filed an interim compliance progress report on December 1, 2025 and face their first full annual report on July 1, 2026, on the original calendar.

The Proxy Audit Is Where It Reaches a Rating Plan

Regulation 10-1-1 requires four distinct testing methodologies, and three of them measure outcomes. One of them measures the variable itself.

MethodologyWhat It TestsKey ThresholdPrimary Challenge
Four-Fifths RuleSelection rate ratios across protected classes80% of most-favored group rateDefining "selection" for insurance pricing tiers
Proxy Variable AuditFeature correlation with protected attributesNo fixed threshold; actuarial justification requiredDisentangling predictive value from proxy load
Intersectional TestingCompound group outcomes (e.g., Black women, elderly Hispanic applicants)Same as four-fifths rule applied to intersectionsCombinatorial explosion across nine protected classes
Counterfactual AnalysisOutcome sensitivity to protected attribute changesStatistical significance of outcome changeConstructing valid counterfactual data points

The four-fifths rule is a screen with a stated threshold: a selection rate below 80% of the most favored class flags the model, and the carrier documents actuarial justification for the gap. Intersectional testing extends the same test to combinations, which across nine protected classes is a methodology-selection problem the regulation does not resolve. Counterfactual analysis flips the protected attribute and measures whether the outcome moves.

The proxy variable audit is the one with no threshold, and it is the one that reaches territory, credit score and occupation. Regulation 10-1-1 does not prohibit those variables. It requires the carrier to measure how much of each variable's predictive value flows through its correlation with a protected attribute, and to justify retaining what remains. The documented question moves from whether a variable is predictive to whether its predictive value is separable from protected class membership, which is a different exhibit and one most rate filings have never had to produce.

The demographic estimate underneath it carries its own error. Colorado proposed Bayesian Improved First Name Surname Geocoding as the default method for imputing race and ethnicity. The CFPB has used the surname-and-geocode variant in fair lending exams since 2014, so the technique is not novel, but its accuracy degrades in areas of low ethnic diversity because the geocoding component reads Census block group composition, and it performs poorly for multiracial applicants and names common across groups. A disparity measured on an imputed class is a disparity measured with noise, and the carrier owns both halves.

Auto carriers inherit a specific version of this. The DOI has flagged telematics location data, because driving patterns track residential geography, which tracks race and income. That places a variable most auto insurers regard as behavioral squarely inside the proxy audit.

The NAIC Model Bulletin, adopted in 24 states, requires the governance program, the model inventory and the vendor oversight. It does not specify quantitative bias testing, consumer data correction rights, or impact assessments with remediation evidence. Meeting the NAIC standard alone does not produce a Colorado filing.

The Replacement Bill Leaves the Binding Layer in Place

The Colorado legislature passed SB 26-189 on May 7 and May 9, 2026, and it is expected to be signed.

It swaps "high-risk artificial intelligence systems" for "automated decision-making technology" and eliminates mandatory bias audits and risk impact assessments, substituting notice at the point of interaction, a plain-language explanation within 30 days of an adverse outcome, data correction rights and three-year record retention, enforced solely by the Attorney General with a 60-day cure period on first violations. It takes effect January 1, 2027.

It replaces SB 24-205. It does not amend SB 21-169 or Regulation 10-1-1. So the practical effect for carriers is the opposite of relief: from January 2027 they face two Colorado layers rather than one, and the surviving layer is the more demanding one, with the four-part testing methodology and the annual DOI filing intact.

The nearer constraint is calendar rather than legal. Bias testing itself runs in hours or days on modern fairness toolkits. Assembling the filing does not. On the Faegre Drinker reading of the amended regulation and the Swept AI compliance roadmap, the filing runs to seven documentation categories: responsible personnel, impact assessments, testing results, consumer notification records, a version-controlled system inventory, remediation evidence and governance structure.

Connecting those routinely takes eight to twelve weeks from an unstructured baseline, on the pattern from the life insurer cycles. Carriers that treated the December 2025 interim report as an attestation rather than a documentation rehearsal are doing that work inside the remaining 50 days.

Further Reading

Sources