A federal magistrate blocked enforcement of Colorado's AI Act on April 27, and the headlines read as a reprieve. For insurers it is not one. The temporary restraining order reaches SB 24-205, enforced by the Attorney General. The bias testing and documentation obligations that bind carriers come from SB 21-169 and Regulation 10-1-1, enforced by the Commissioner of Insurance, never challenged in court, and still due July 1, 2026.
Key Takeaways
- Two statutes, two enforcers. SB 24-205 sits with the Attorney General and is stayed. SB 21-169 and Regulation 10-1-1 sit with the Division of Insurance and are not.
- Nine protected classes are covered by SB 21-169, narrower than SB 24-205's thirteen-plus, and the July 1 report must show bias testing results across all of them.
- The four-fifths rule sets an 80% threshold on selection rates, but the proxy variable audit is the component that reaches traditional rating variables, and it carries no fixed threshold at all.
- Testing runs in hours; documentation runs eight to twelve weeks from an unstructured baseline, which is the constraint auto and health carriers filing their first full report are actually against.
- SB 26-189 passed May 7 and May 9, 2026 and would eliminate mandatory bias audits from January 1, 2027. It replaces SB 24-205 and leaves SB 21-169 untouched.
Which Track Actually Binds
Colorado regulates AI in insurance on two statutory tracks, and conflating them is the common error.
SB 24-205, the Consumer Protections for Artificial Intelligence Act signed in May 2024, is economy-wide and applies to deployers of high-risk AI systems making consequential decisions. It carries a safe harbor at Section 10-3-1104.9 for insurers already complying with DOI rules on algorithms and predictive models, a point we mapped in our analysis of the June 30 deadline.
SB 21-169, signed in July 2021, is insurance-specific and governs External Consumer Data and Information Sources in underwriting, rating and claims. Regulation 10-1-1 implements it, effective for life insurers from November 14, 2023 and extended to private passenger auto and health benefit plan insurers when the amended version took effect October 15, 2025.
xAI filed suit on April 9, 2026 in the District of Colorado, Case No. 1:26-cv-01515, on six constitutional grounds. The Department of Justice intervened on April 24, the first federal move to invalidate a state AI law under Executive Order 14365, and Magistrate Judge Cyrus Y. Chung issued a TRO on April 27 running until 14 days after a ruling on the forthcoming preliminary injunction motion.
None of that litigation names SB 21-169. Auto and health carriers filed an interim compliance progress report on December 1, 2025 and face their first full annual report on July 1, 2026, on the original calendar.
The Proxy Audit Is Where It Reaches a Rating Plan
Regulation 10-1-1 requires four distinct testing methodologies, and three of them measure outcomes. One of them measures the variable itself.
| Methodology | What It Tests | Key Threshold | Primary Challenge |
|---|---|---|---|
| Four-Fifths Rule | Selection rate ratios across protected classes | 80% of most-favored group rate | Defining "selection" for insurance pricing tiers |
| Proxy Variable Audit | Feature correlation with protected attributes | No fixed threshold; actuarial justification required | Disentangling predictive value from proxy load |
| Intersectional Testing | Compound group outcomes (e.g., Black women, elderly Hispanic applicants) | Same as four-fifths rule applied to intersections | Combinatorial explosion across nine protected classes |
| Counterfactual Analysis | Outcome sensitivity to protected attribute changes | Statistical significance of outcome change | Constructing valid counterfactual data points |
The four-fifths rule is a screen with a stated threshold: a selection rate below 80% of the most favored class flags the model, and the carrier documents actuarial justification for the gap. Intersectional testing extends the same test to combinations, which across nine protected classes is a methodology-selection problem the regulation does not resolve. Counterfactual analysis flips the protected attribute and measures whether the outcome moves.
The proxy variable audit is the one with no threshold, and it is the one that reaches territory, credit score and occupation. Regulation 10-1-1 does not prohibit those variables. It requires the carrier to measure how much of each variable's predictive value flows through its correlation with a protected attribute, and to justify retaining what remains. The documented question moves from whether a variable is predictive to whether its predictive value is separable from protected class membership, which is a different exhibit and one most rate filings have never had to produce.
The demographic estimate underneath it carries its own error. Colorado proposed Bayesian Improved First Name Surname Geocoding as the default method for imputing race and ethnicity. The CFPB has used the surname-and-geocode variant in fair lending exams since 2014, so the technique is not novel, but its accuracy degrades in areas of low ethnic diversity because the geocoding component reads Census block group composition, and it performs poorly for multiracial applicants and names common across groups. A disparity measured on an imputed class is a disparity measured with noise, and the carrier owns both halves.
Auto carriers inherit a specific version of this. The DOI has flagged telematics location data, because driving patterns track residential geography, which tracks race and income. That places a variable most auto insurers regard as behavioral squarely inside the proxy audit.
The NAIC Model Bulletin, adopted in 24 states, requires the governance program, the model inventory and the vendor oversight. It does not specify quantitative bias testing, consumer data correction rights, or impact assessments with remediation evidence. Meeting the NAIC standard alone does not produce a Colorado filing.
The Replacement Bill Leaves the Binding Layer in Place
The Colorado legislature passed SB 26-189 on May 7 and May 9, 2026, and it is expected to be signed.
It swaps "high-risk artificial intelligence systems" for "automated decision-making technology" and eliminates mandatory bias audits and risk impact assessments, substituting notice at the point of interaction, a plain-language explanation within 30 days of an adverse outcome, data correction rights and three-year record retention, enforced solely by the Attorney General with a 60-day cure period on first violations. It takes effect January 1, 2027.
It replaces SB 24-205. It does not amend SB 21-169 or Regulation 10-1-1. So the practical effect for carriers is the opposite of relief: from January 2027 they face two Colorado layers rather than one, and the surviving layer is the more demanding one, with the four-part testing methodology and the annual DOI filing intact.
The nearer constraint is calendar rather than legal. Bias testing itself runs in hours or days on modern fairness toolkits. Assembling the filing does not. On the Faegre Drinker reading of the amended regulation and the Swept AI compliance roadmap, the filing runs to seven documentation categories: responsible personnel, impact assessments, testing results, consumer notification records, a version-controlled system inventory, remediation evidence and governance structure.
Connecting those routinely takes eight to twelve weeks from an unstructured baseline, on the pattern from the life insurer cycles. Carriers that treated the December 2025 interim report as an attestation rather than a documentation rehearsal are doing that work inside the remaining 50 days.
Further Reading
- Colorado AI Act: 73 Days Until the June 30, 2026 Insurance Deadline: Analysis of the Section 10-3-1104.9 insurance safe harbor scope, the SB 25B-004 delay, and where the safe harbor breaks for third-party AI vendors.
- NAIC AI Evaluation Pilot Launches Amid Industry Pushback: The 12-state pilot framework and how its documentation expectations compare to Colorado's compliance report requirements.
- NAIC AI Risk Taxonomy and Compliance Framework: The four-tier risk classification system that underlies the NAIC's approach to insurer AI governance.
- Hartford's Algorithmic Impact Assessment Sets the Carrier Transparency Bar: How Hartford voluntarily published bias audit documentation that meets or exceeds Colorado's requirements, and what other carriers can learn from the approach.
- Three Months to the EU AI Act: Insurers Need Compliance Actuaries: The international parallel to Colorado's framework, with Annex III high-risk classification and the emerging compliance actuary role.
- Colorado Rewrites Its AI Bias Law With SB 26-189: The May 2026 rewrite replaces SB 24-205's mandatory bias audits with a transparency framework, but DOI Regulation 10-1-1 testing obligations remain in force for the July 1 deadline.
- AI Exclusions Win 80% State Approval Across CGL Books: How carrier AI exclusion filings interact with state AI governance mandates like Colorado's, and the regulatory tension when carriers exclude AI risk while deploying AI internally.
Sources
- Colorado General Assembly, SB 24-205 Bill Text
- Colorado General Assembly, SB 21-169 Bill Text
- Swept AI, "Colorado AI Act Insurance Compliance Roadmap"
- Faegre Drinker, "Colorado DOI Expands AI Governance Obligations for Insurers" (September 2025)
- Fisher Phillips, "Colorado Moves to Replace AI Bias Audit Law with New Transparency Framework"
- Colorado Sun, "Elon Musk's xAI Sues Over Colorado AI Law" (April 2026)
- Government Contractor Compliance Update, "Federal Government Intervenes in Colorado AI Law Case" (April 2026)
- Colorado Politics, "Colorado's AI Law Can't Be Enforced Yet, Judge Rules" (April 2026)
- Debevoise Data Blog, "Colorado Extension of AI Regulation to Health and Auto Insurers" (September 2025)
- Credo AI, "Colorado SB 21-169: 8 Things to Know About Colorado's AI Insurance Regulation"
- NAIC, Artificial Intelligence Insurance Topics