The Colorado General Assembly passed SB 26-189 on May 9, 2026 by 57-6 in the House and 34-1 in the Senate, repealing SB 24-205 in its entirety and replacing mandatory bias audits with a disclosure framework built on "covered ADMT." Governor Polis has confirmed he will sign it. The provision that will cost insurers the most work is not in the audit section. It is a single sentence voiding vendor indemnities.
Key Takeaways
- Pre-deployment bias audits, annual impact assessments and the documented risk management program are all eliminated, replaced by point-of-interaction notice and a post-outcome explanation.
- Any clause indemnifying a party against liability for its own discriminatory use of ADMT is void as against public policy, which unwinds standard AI vendor risk transfer for Colorado consequential decisions.
- Thirty days is the window for a plain-language explanation of the technology's role, the data types used and the consumer's rights after an adverse outcome.
- The insurance safe harbor at Section 10-3-1104.9 survives, but it exempts insurers only where they are already complying with Division of Insurance rules.
- SB 21-169 and Regulation 10-1-1 are untouched, and the July 1, 2026 annual compliance report for auto and health benefit plan insurers has not moved.
What Was Swapped Out
SB 24-205, signed in May 2024, was the first US state law imposing risk-based AI governance on private developers and deployers of high-risk AI systems used as a substantial factor in consequential decisions.
For deployers it required a documented risk management policy, annual impact assessments with updates within 90 days of substantial modification, pre-decision consumer notices, a public statement of systems in use, and disclosure to the Attorney General within 90 days of discovering algorithmic discrimination.
SB 26-189 replaces the whole architecture. "Covered ADMT" is narrower than "high-risk AI system": technology that processes personal data and generates predictions, recommendations, classifications, rankings or scores used to materially influence a consequential decision. The covered domains barely change. The obligations invert, from audit before deployment to explain after outcome.
| Requirement | SB 24-205 (Repealed) | SB 26-189 (New Law) |
|---|---|---|
| Pre-deployment bias audits | Mandatory | Eliminated |
| Risk impact assessments | Annual, plus 90-day update after modification | Eliminated |
| Governance framework | Documented risk management program required | No standalone governance requirement |
| Consumer notice | Pre-decision, at or before consequential decision | Point-of-interaction notice that ADMT is in use |
| Post-adverse outcome disclosure | Not specifically required as standalone | Within 30 days: plain-language explanation of ADMT's role, data types used, consumer rights |
| Human review | Appeal right where technically feasible | "Meaningful human review and reconsideration, to the extent commercially reasonable" |
| Data correction rights | Limited | Right to request personal data used and correct inaccuracies |
| Recordkeeping | Impact assessments retained | Three-year retention of compliance records |
| Enforcement | AG enforcement plus private right of action | AG enforcement only; no private right of action |
| Cure period | Limited | 60-day notice and cure (expires January 1, 2030) |
| DEI carve-out | Exempted diversity-promoting algorithms | Removed entirely |
| Federal entity exemption | Conditional exemptions for some regulated entities | Eliminated: broader coverage |
| Effective date | June 30, 2026 (after delay) | January 1, 2027 |
The retreat had three drivers running at once. Governor Polis's working group, formed in August 2025 across tech, insurers, labor and civil rights groups, spent six months and, as the Colorado Sun reported, hundreds of hours negotiating the replacement, which Senate Majority Leader Rodriguez summarized as everybody losing and everybody winning. xAI sued on April 9, 2026, the DOJ intervened on April 24 arguing the algorithmic discrimination duty compelled race- and sex-conscious engineering, and the court suspended enforcement on April 27. The carve-out the DOJ challenged, which had exempted algorithms designed to advance diversity, does not appear in the new bill.
And as the Consumer Finance Monitor analysis noted, no consensus methodology for auditing insurance AI systems had emerged to audit against.
The Sentence That Voids the Vendor Indemnity
The developer tier survives, and what it now produces is documents rather than audits.
From January 1, 2027 developers of covered ADMT must give deployers technical documentation of intended and known harmful uses, categories of training data, known limitations, guidance on appropriate use and human review, and notice of material updates. The artifacts a carrier needs for compliance survive the rewrite; the vendor's obligation to audit itself does not.
Then the provision that changes the economics. Any contract clause purporting to indemnify, defend or hold harmless a party from liability for their own discriminatory use of ADMT in consequential decisions is void as against public policy. That reaches most standard AI vendor indemnification language covering decisions affecting Colorado consumers.
The consequence is a risk transfer that carriers have already paid for and no longer hold. A carrier that accepted a vendor's model on the strength of an indemnity now carries the discrimination exposure on its own balance sheet for every Colorado consequential decision, whatever the contract says. The exception is narrow and it runs the other way: a developer escapes liability only where the deployer used the technology outside its documented intended use and the developer met its documentation obligations.
That makes documented intended use the load-bearing phrase in the whole framework. Liability allocation between carrier and vendor now turns on whether a given deployment sits inside the vendor's written description of what the system is for. A pricing model documented for one line and deployed across three is outside it. The compliance artifact that decides the question is a document the vendor writes and the carrier accepts, which is why contract renegotiation cycles need to run before January 2027 rather than after.
The Safe Harbor Is Earned, Not Granted
The framework insurers actually sit under did not soften, and the exemption from the one that did is conditional.
Section 10-3-1104.9 survives the rewrite, exempting insurers from deployer obligations where they are already complying with Division of Insurance rules governing external consumer data, algorithms and predictive models. Read plainly, the safe harbor is not relief. It is available only to carriers doing the quantitative testing and governance work that SB 26-189 just stopped requiring of everyone else.
Those rules are on a different statutory track and were never in the litigation. SB 21-169 and Regulation 10-1-1 are enforced by the Commissioner of Insurance rather than the Attorney General, and the July 1, 2026 annual compliance report for auto and health benefit plan insurers stands on its original calendar.
The new disclosure duty then adds an obligation the audit regime never imposed. After an adverse consequential decision, a deployer has thirty days to deliver a plain-language explanation of the technology's role, the data types it used and the consumer's rights, alongside the right to request and correct that data.
Producing that in thirty days is not a drafting exercise. It requires per-decision lineage, recorded at decision time, linking a specific consumer outcome to the model version, the inputs and the human review that occurred. A carrier that cannot reconstruct which model scored which application on which date cannot answer inside the window. The governance infrastructure the legislature removed from the front of the process is what the thirty-day clock quietly requires at the back of it, and unlike an annual impact assessment, it comes due on the consumer's schedule.
Further Reading
- Colorado AI Act: 73 Days Until the June 30 Insurance Deadline: Our April 2026 analysis of the original SB 24-205 compliance framework, now superseded by SB 26-189 for the general statute but still relevant for understanding the DOI safe harbor mechanics.
- Colorado Insurance Bias Audits: The July 1 Deadline Stands: Why the insurance-specific Regulation 10-1-1 bias audit requirements remain fully in force regardless of SB 26-189, with the four-part testing methodology and compliance roadmap.
- NAIC Weighs Jump From AI Bulletin to Enforceable Model Law: The 33 RFI comment letters and fault lines around scope, vendor liability, and company-size thresholds shaping the national AI regulatory trajectory for insurers.
- NAIC AI Evaluation Pilot Launches Amid Industry Pushback: The 12-state pilot framework and how Colorado's legislative pivot may influence the NAIC's decision on whether to codify evaluation requirements.
- The AI Governance Gap in Actuarial Practice: Where ASOP No. 56 meets AI systems and where actuarial standards fall short of statutory requirements.
- Four AI Compliance Regimes Now Confront Multi-State Carriers: How Colorado's "deemed compliant" safe harbor fits alongside Connecticut SB 5, the NAIC 12-state pilot, and Texas TRAIGA in the expanding state AI regulatory patchwork.
Sources
- Colorado General Assembly, SB 26-189: Automated Decision-Making Technology (passed May 9, 2026)
- Colorado General Assembly, SB 24-205: Consumer Protections for Artificial Intelligence (enacted May 2024)
- Consumer Finance Monitor, "Colorado Rewrites Its Landmark AI Law: Unpacking SB 26-189" (May 12, 2026)
- Fisher Phillips, "Colorado Moves to Replace AI Bias Audit Law With New Transparency Framework" (May 2026)
- Airia, "Colorado Rewrote Its AI Law. Here's What Governance Practitioners Need to Do Before January 2027" (May 2026)
- Colorado Newsline, "New Bill Would Narrow Scope of Colorado's Landmark 2024 AI Law" (May 4, 2026)
- Colorado Sun, "Colorado's Fierce Two-Year Fight Over AI Regulation Ends With Watered-Down Law" (May 12, 2026)
- Baker Botts, "Colorado Repeals and Replaces AI Act" (May 2026)
- Reed Smith, "SB 26-189: Colorado Legislature Kicks Off CAIA Rewrite Race" (May 2026)
- Faegre Drinker, "Colorado Division of Insurance Expands AI-Related Governance and Risk Management Obligations for Insurers" (September 2025)
- US Department of Justice, "Justice Department Intervenes in xAI Lawsuit Challenging Colorado's 'Algorithmic Discrimination' Law" (April 2026)
- NAIC, Artificial Intelligence Insurance Topics Page
- Colorado Division of Insurance, SB 21-169 External Data and Algorithms Page
- Debevoise, "Colorado Approves Extension of AI Regulation to Health and Auto Insurers" (September 2025)
- CPR News, "Polis Says He Will Sign Pared Down AI Bill That Passed Overnight" (May 12, 2026)