The Colorado General Assembly passed SB 26-189 on May 9, 2026 by 57-6 in the House and 34-1 in the Senate, repealing SB 24-205 in its entirety and replacing mandatory bias audits with a disclosure framework built on "covered ADMT." Governor Polis has confirmed he will sign it. The provision that will cost insurers the most work is not in the audit section. It is a single sentence voiding vendor indemnities.

Key Takeaways

  • Pre-deployment bias audits, annual impact assessments and the documented risk management program are all eliminated, replaced by point-of-interaction notice and a post-outcome explanation.
  • Any clause indemnifying a party against liability for its own discriminatory use of ADMT is void as against public policy, which unwinds standard AI vendor risk transfer for Colorado consequential decisions.
  • Thirty days is the window for a plain-language explanation of the technology's role, the data types used and the consumer's rights after an adverse outcome.
  • The insurance safe harbor at Section 10-3-1104.9 survives, but it exempts insurers only where they are already complying with Division of Insurance rules.
  • SB 21-169 and Regulation 10-1-1 are untouched, and the July 1, 2026 annual compliance report for auto and health benefit plan insurers has not moved.

What Was Swapped Out

SB 24-205, signed in May 2024, was the first US state law imposing risk-based AI governance on private developers and deployers of high-risk AI systems used as a substantial factor in consequential decisions.

For deployers it required a documented risk management policy, annual impact assessments with updates within 90 days of substantial modification, pre-decision consumer notices, a public statement of systems in use, and disclosure to the Attorney General within 90 days of discovering algorithmic discrimination.

SB 26-189 replaces the whole architecture. "Covered ADMT" is narrower than "high-risk AI system": technology that processes personal data and generates predictions, recommendations, classifications, rankings or scores used to materially influence a consequential decision. The covered domains barely change. The obligations invert, from audit before deployment to explain after outcome.

Requirement SB 24-205 (Repealed) SB 26-189 (New Law)
Pre-deployment bias audits Mandatory Eliminated
Risk impact assessments Annual, plus 90-day update after modification Eliminated
Governance framework Documented risk management program required No standalone governance requirement
Consumer notice Pre-decision, at or before consequential decision Point-of-interaction notice that ADMT is in use
Post-adverse outcome disclosure Not specifically required as standalone Within 30 days: plain-language explanation of ADMT's role, data types used, consumer rights
Human review Appeal right where technically feasible "Meaningful human review and reconsideration, to the extent commercially reasonable"
Data correction rights Limited Right to request personal data used and correct inaccuracies
Recordkeeping Impact assessments retained Three-year retention of compliance records
Enforcement AG enforcement plus private right of action AG enforcement only; no private right of action
Cure period Limited 60-day notice and cure (expires January 1, 2030)
DEI carve-out Exempted diversity-promoting algorithms Removed entirely
Federal entity exemption Conditional exemptions for some regulated entities Eliminated: broader coverage
Effective date June 30, 2026 (after delay) January 1, 2027

The retreat had three drivers running at once. Governor Polis's working group, formed in August 2025 across tech, insurers, labor and civil rights groups, spent six months and, as the Colorado Sun reported, hundreds of hours negotiating the replacement, which Senate Majority Leader Rodriguez summarized as everybody losing and everybody winning. xAI sued on April 9, 2026, the DOJ intervened on April 24 arguing the algorithmic discrimination duty compelled race- and sex-conscious engineering, and the court suspended enforcement on April 27. The carve-out the DOJ challenged, which had exempted algorithms designed to advance diversity, does not appear in the new bill.

And as the Consumer Finance Monitor analysis noted, no consensus methodology for auditing insurance AI systems had emerged to audit against.

The Sentence That Voids the Vendor Indemnity

The developer tier survives, and what it now produces is documents rather than audits.

From January 1, 2027 developers of covered ADMT must give deployers technical documentation of intended and known harmful uses, categories of training data, known limitations, guidance on appropriate use and human review, and notice of material updates. The artifacts a carrier needs for compliance survive the rewrite; the vendor's obligation to audit itself does not.

Then the provision that changes the economics. Any contract clause purporting to indemnify, defend or hold harmless a party from liability for their own discriminatory use of ADMT in consequential decisions is void as against public policy. That reaches most standard AI vendor indemnification language covering decisions affecting Colorado consumers.

The consequence is a risk transfer that carriers have already paid for and no longer hold. A carrier that accepted a vendor's model on the strength of an indemnity now carries the discrimination exposure on its own balance sheet for every Colorado consequential decision, whatever the contract says. The exception is narrow and it runs the other way: a developer escapes liability only where the deployer used the technology outside its documented intended use and the developer met its documentation obligations.

That makes documented intended use the load-bearing phrase in the whole framework. Liability allocation between carrier and vendor now turns on whether a given deployment sits inside the vendor's written description of what the system is for. A pricing model documented for one line and deployed across three is outside it. The compliance artifact that decides the question is a document the vendor writes and the carrier accepts, which is why contract renegotiation cycles need to run before January 2027 rather than after.

The Safe Harbor Is Earned, Not Granted

The framework insurers actually sit under did not soften, and the exemption from the one that did is conditional.

Section 10-3-1104.9 survives the rewrite, exempting insurers from deployer obligations where they are already complying with Division of Insurance rules governing external consumer data, algorithms and predictive models. Read plainly, the safe harbor is not relief. It is available only to carriers doing the quantitative testing and governance work that SB 26-189 just stopped requiring of everyone else.

Those rules are on a different statutory track and were never in the litigation. SB 21-169 and Regulation 10-1-1 are enforced by the Commissioner of Insurance rather than the Attorney General, and the July 1, 2026 annual compliance report for auto and health benefit plan insurers stands on its original calendar.

The new disclosure duty then adds an obligation the audit regime never imposed. After an adverse consequential decision, a deployer has thirty days to deliver a plain-language explanation of the technology's role, the data types it used and the consumer's rights, alongside the right to request and correct that data.

Producing that in thirty days is not a drafting exercise. It requires per-decision lineage, recorded at decision time, linking a specific consumer outcome to the model version, the inputs and the human review that occurred. A carrier that cannot reconstruct which model scored which application on which date cannot answer inside the window. The governance infrastructure the legislature removed from the front of the process is what the thirty-day clock quietly requires at the back of it, and unlike an annual impact assessment, it comes due on the consumer's schedule.

Further Reading

Sources

  1. Colorado General Assembly, SB 26-189: Automated Decision-Making Technology (passed May 9, 2026)
  2. Colorado General Assembly, SB 24-205: Consumer Protections for Artificial Intelligence (enacted May 2024)
  3. Consumer Finance Monitor, "Colorado Rewrites Its Landmark AI Law: Unpacking SB 26-189" (May 12, 2026)
  4. Fisher Phillips, "Colorado Moves to Replace AI Bias Audit Law With New Transparency Framework" (May 2026)
  5. Airia, "Colorado Rewrote Its AI Law. Here's What Governance Practitioners Need to Do Before January 2027" (May 2026)
  6. Colorado Newsline, "New Bill Would Narrow Scope of Colorado's Landmark 2024 AI Law" (May 4, 2026)
  7. Colorado Sun, "Colorado's Fierce Two-Year Fight Over AI Regulation Ends With Watered-Down Law" (May 12, 2026)
  8. Baker Botts, "Colorado Repeals and Replaces AI Act" (May 2026)
  9. Reed Smith, "SB 26-189: Colorado Legislature Kicks Off CAIA Rewrite Race" (May 2026)
  10. Faegre Drinker, "Colorado Division of Insurance Expands AI-Related Governance and Risk Management Obligations for Insurers" (September 2025)
  11. US Department of Justice, "Justice Department Intervenes in xAI Lawsuit Challenging Colorado's 'Algorithmic Discrimination' Law" (April 2026)
  12. NAIC, Artificial Intelligence Insurance Topics Page
  13. Colorado Division of Insurance, SB 21-169 External Data and Algorithms Page
  14. Debevoise, "Colorado Approves Extension of AI Regulation to Health and Auto Insurers" (September 2025)
  15. CPR News, "Polis Says He Will Sign Pared Down AI Bill That Passed Overnight" (May 12, 2026)