All posts

Compliance · July 23, 2026 · 9 min read

Colorado AI Act Hiring Rules: What the 2026 Rewrite Means

Colorado AI Act hiring rules changed in 2026: SB 24-205 was repealed before taking effect and replaced by SB 26-189. What hiring teams must do before 2027.

By Jakir Patel · Founder, Hanzomon

Share

Part of Compliance-First Hiring AI: LL144 and the EU AI Act

Compliance
On this page

If you screen, rank, or assess candidates with AI and you hire in Colorado, the compliance target you spent 2025 preparing for no longer exists in the form you prepared for. The Colorado AI Act (SB 24-205) — the first comprehensive state AI law in the United States — was repealed and replaced in May 2026, before it ever took effect. Its successor, SB 26-189, takes effect January 1, 2027, and it asks meaningfully different things of hiring teams. Colorado AI Act hiring compliance is now a moving target with a fixed deadline.

This guide is for talent leaders, recruiters, and the HR or legal owners of hiring-tool compliance. You will get a plain-language account of what SB 24-205 would have required, why it was rewritten, what SB 26-189 actually requires from developers and deployers, how it compares to NYC Local Law 144 and the EU AI Act, and a concrete preparation checklist for the months before January 2027.

Why now: candidates are AI-fluent, AI-assisted applications have made top-of-funnel screening harder, and the tools employers use to cope — resume rankers, automated assessments, AI interview scoring — are exactly what these laws regulate. The rules apply wherever your decisions touch Colorado residents, which for remote-first companies means almost everyone. Getting the timeline wrong cuts both ways: you can burn budget complying with a repealed statute, or sleepwalk into 2027 with no notice language, no human-review step, and no records.

This article is informational, not legal advice. AI employment law is changing quickly — Colorado's own framework was delayed, repealed, and replaced within two years — so confirm current requirements with counsel before making compliance decisions.

What is the Colorado AI Act, and why does hiring trigger it?

Signed in May 2024, SB 24-205 was the first comprehensive AI statute enacted by a US state. It borrowed the EU's risk-based architecture: AI systems that made, or were a substantial factor in making, "consequential decisions" were classified as high-risk. Employment decisions — hiring, promotion, termination — sat at the center of that definition, alongside credit, housing, education, healthcare, and insurance.

That classification mattered because it attached duties to two roles. Developers — the companies that build AI systems — owed downstream customers documentation and disclosures about capabilities, limitations, and known risks. Deployers — the employers actually using the systems on candidates — owed duties of care, assessment, and notice. If your ATS ranked applicants with a model, or your assessment platform scored candidates automatically, you were a deployer, whether or not anyone on your team thought of the tool as "AI."

What did SB 24-205 require before it was repealed?

Understanding the original act is still useful, both because SB 26-189 keeps some of its skeleton and because its ideas keep resurfacing in other statehouses. In broad strokes, the 2024 act imposed:

Deployer duties (employers)

  • A duty of reasonable care to protect people from algorithmic discrimination arising from high-risk AI use.
  • A risk-management program, with the NIST AI Risk Management Framework named as a recognized touchstone.
  • Impact assessments for high-risk systems, refreshed periodically and after significant modifications.
  • Pre-decision notice to candidates that a high-risk AI system was in use, plus explanation, correction, and appeal rights — including human review where feasible — after an adverse decision.
  • Reporting discovered algorithmic discrimination to the Colorado attorney general.

Developer duties (vendors)

  • Reasonable care against algorithmic discrimination in intended and reasonably foreseeable uses.
  • Documentation to deployers: training-data summaries, intended use, known limitations, and evaluation and mitigation measures.
  • Public disclosure of the high-risk systems they offer and how they manage discrimination risk.

Enforcement sat with the attorney general — no private right of action under the act itself — with partial accommodations for smaller deployers. It was, by any measure, the most demanding AI hiring framework in the country. Which is a large part of why it never took effect.

What changed in 2026? From SB 24-205 to SB 26-189

The original effective date was February 1, 2026. In an August 2025 special session, lawmakers pushed that to June 30, 2026, to buy time for amendments after sustained pressure from the governor, industry, and — unusually — federal officials critical of state-level AI regulation. Enforcement questions also ended up in federal court. Then, rather than amend the act, the legislature replaced it: on May 14, 2026, Governor Polis signed SB 26-189, repealing SB 24-205 outright and enacting a narrower framework focused on automated decision-making technology (ADMT) in consequential decisions, effective January 1, 2027.

May 2024
SB 24-205 signed — the first comprehensive US state AI law
May 2026
Repealed and replaced by SB 26-189 before ever taking effect
Jan 2027
SB 26-189 obligations scheduled to take effect

The practical takeaways for July 2026: no Colorado AI Act obligations are currently in force; the 2027 framework is transparency-first rather than risk-management-first; and further amendment or litigation before the effective date is plausible. Treat any vendor or consultant still pitching "SB 24-205 compliance" as roughly one legislative session out of date.

The repeal did not deregulate AI hiring in Colorado. Title VII, the ADA, the ADEA, and the Colorado Anti-Discrimination Act all apply to AI-assisted decisions today, exactly as they apply to human ones. The statute changed; the discrimination exposure did not.

What does the Colorado AI Act's replacement require for hiring?

SB 26-189 regulates ADMT used to materially influence consequential decisions. For employers, covered decisions include hiring, termination, promotion, compensation, and scheduling. The headline shift: the broad duty of care to prevent algorithmic discrimination, and the mandatory impact-assessment regime, give way to targeted transparency and process obligations. Public analyses of the law consistently describe requirements along these lines:

  • Clear and conspicuous notice to candidates before covered ADMT materially influences a decision about them.
  • Process rights for affected individuals, including access to relevant data and the ability to correct inaccuracies.
  • Meaningful human review — a person with the authority and information to actually change the outcome, not a rubber stamp.
  • Vendor documentation flowing from developers to deployers, plus recordkeeping by the employer.
  • A comparative-fault framework allocating liability between developers and deployers — and voiding contract clauses that would let either shield itself from responsibility for its own discriminatory conduct.

That last point deserves attention. Employers cannot outsource accountability to a vendor's assurances, and vendors cannot disclaim their way out of defects. Off-label use — deploying a tool for decisions it was not designed or validated for — lands on the employer. If you use a general-purpose scoring tool to make hiring calls, the burden of showing that was appropriate is yours. This is one more reason job-relatedness and adverse-impact analysis should stay in your process even though the statute no longer mandates assessments by name.

Domain
25%
Behavioural
20%
Situational
20%
Cognitive
15%
AI Fluency
10%
AI Sandbox
10%

Illustrative weights — configurable per role, locked at the first candidate for comparability.

How does Colorado compare to NYC LL144, the EU AI Act, and Illinois?

Multi-state and global employers now face at least four overlapping regimes, each with a different center of gravity:

  • NYC Local Law 144: narrow and audit-centric. Covers automated employment decision tools used for NYC candidates; requires an annual independent bias audit, published results, and candidate notice. Enforced since July 2023.
  • EU AI Act: classifies employment AI as high-risk, with provider and deployer obligations — risk management, human oversight, logging, conformity assessment — phasing in through 2026 and 2027. Closest in spirit to the repealed SB 24-205.
  • Illinois: a civil-rights approach. Amendments to the Illinois Human Rights Act, effective January 1, 2026, address discriminatory AI use and notice in employment, layered on the earlier AI Video Interview Act.
  • Colorado, as of 2027: transparency and process. Notice, data access and correction, human review, documentation, and shared developer–deployer liability.

The pattern across all four: regulators disagree on mechanisms — audits, risk management, civil-rights enforcement, disclosure — but agree on substance. Tell candidates when AI is involved, be able to explain and defend the decision, keep a human meaningfully in the loop, and keep records. Teams that build to that common core once, rather than patching per jurisdiction, spend far less. That is the argument of our compliance-first hiring pillar: treat compliance as a design constraint on your hiring system, not a paperwork layer bolted on afterward.

How should hiring teams prepare before January 2027?

You have a window most compliance deadlines never give you: the requirements are known months in advance, and none of them demand exotic tooling. A realistic sequence:

  • Inventory every tool that touches candidate evaluation — sourcing, resume screening, assessments, interview scoring, offer modeling — and flag where automation materially influences outcomes. Most teams find more than they expect.
  • Draft candidate-facing notice language now, and place it where decisions actually happen: job posts, assessment invitations, rejection flows. Bolting notice on later is what breaks candidate experience.
  • Design the human-review step with teeth. Decide who reviews, what information they see, and document when they overrule the system. A reviewer who cannot change outcomes will not satisfy anyone.
  • Demand documentation from vendors: intended use, validation evidence, known limitations, and how they support notice and data-correction requests. SB 26-189's shared-liability model makes this a negotiation point, not a favor.
  • Keep running adverse-impact analysis on selection stages, even though Colorado no longer mandates impact assessments. It is cheap, it is the evidence you will want in any dispute, and NYC and EU obligations may require it anyway.
  • Build a correction-and-appeal path candidates can actually find, and log its use.

Prioritize by exposure, not by tool count. One automated knockout question at the top of a 5,000-applicant funnel affects more people than everything downstream combined. Start your notice, review, and adverse-impact work where the volume is.

The hardest part of this checklist is usually the evidence problem: when a candidate or regulator asks why someone was screened out, "the model scored them 62" is not an answer. Assessments built around observable work — work samples and job-specific tasks rather than generic scores — give reviewers something concrete to review and give notices something honest to say.

Sandbox work samples produce reviewable evidence — the actual work a candidate did — which is exactly what Colorado-style human-review and explanation requirements assume you have.

What are the open questions heading into 2027?

Be honest about uncertainty. SB 26-189 was signed in May 2026 and is already subject to legal challenge; the legislature has shown it will rewrite this framework under pressure, and rulemaking or guidance from the attorney general could sharpen — or soften — key definitions like "materially influence" and "meaningful human review." The federal posture toward state AI laws is its own variable. None of that changes the preparation checklist above, because every item on it is also required, in some form, by NYC, the EU, or plain-old discrimination law. Prepare for the common core; track the Colorado-specific edges.

Bookmark the Colorado attorney general's office and the General Assembly's bill tracker for SB 26-189. Secondary summaries — including this one — age quickly in this area.

Where H-Evaluate fits

H-Evaluate was built compliance-first for exactly this regulatory pattern. Assessments are generated per job description with quality-gated generation — no static shared test bank — so every question is job-related by construction, which is the foundation of any defense under discrimination law and the substance behind a Colorado-style notice. Sandbox work samples produce reviewable artifacts, so the human in your loop reviews actual work, not an opaque score. Candidate-facing notice and structured records are part of the workflow, not an afterthought.

We designed for NYC Local Law 144 and the EU AI Act first, and Colorado's transparency-and-process model lands inside that same envelope. If you are rethinking your stack before 2027, start with our overview of AI-native hiring — the argument, in short, is that tools designed under compliance constraints beat tools retrofitted to them.

Regulation will keep changing faster than your hiring stack. The only durable strategy is making decisions you would be comfortable explaining — to a candidate, an auditor, or a court.
colorado-ai-actai-hiring-compliancesb-26-189hiring-regulationautomated-decision-makinghr-compliance
J

Written by

Jakir Patel · Founder, Hanzomon

Building H-Evaluate — AI-native, quality-gated hiring assessments. Writes about assessment engineering, hiring integrity and compliance-first AI.

Frequently asked questions

Is the Colorado AI Act in effect in 2026?

No. The original Colorado AI Act (SB 24-205) never took effect. It was scheduled for February 1, 2026, delayed to June 30, 2026, and then repealed and replaced before that date. Its successor, SB 26-189, was signed on May 14, 2026 and takes effect January 1, 2027. As of mid-2026, no Colorado-specific AI hiring obligations are in force, but general anti-discrimination law still fully applies to AI-assisted hiring decisions.

Does Colorado's SB 26-189 apply to hiring decisions?

Yes. SB 26-189 regulates automated decision-making technology used to materially influence consequential decisions, and employment decisions — including hiring, promotion, termination, compensation, and scheduling — are squarely covered. If an AI tool substantially shapes who gets screened in or out, employers deploying it in Colorado will owe candidates notice, process rights such as data access and correction, and meaningful human review once the law takes effect in 2027.

Do Colorado employers still need AI impact assessments?

The repealed SB 24-205 would have required formal impact assessments and a risk-management program for high-risk AI systems. The replacement law narrows those mandates, pivoting toward transparency, disclosure, and process rights instead. That said, regular adverse-impact analysis of AI-assisted selection remains strongly advisable: federal and Colorado anti-discrimination law still applies, and other jurisdictions — notably NYC and the EU — do require audits or risk management for the same tools.

How is the Colorado AI Act different from NYC Local Law 144?

NYC Local Law 144 is narrow and audit-centric: it covers automated employment decision tools used in NYC, requires an annual independent bias audit with published results, and mandates candidate notice. Colorado's framework is broader in scope — covering many consequential decisions beyond hiring — but after the 2026 rewrite it emphasizes disclosure, data rights, and human review rather than mandatory bias audits. A tool can satisfy one regime and still fall short of the other.

Does Colorado's AI hiring law apply to out-of-state employers?

Generally, obligations attach based on where the affected people are, not where the company is headquartered. A remote-first employer with no Colorado office that uses automated decision-making technology on Colorado applicants should assume the law reaches those decisions once it takes effect. This mirrors how NYC Local Law 144 and the EU AI Act operate, which is why multi-state employers increasingly design one compliance baseline instead of per-jurisdiction patches.

Who enforces Colorado's AI law for employment decisions?

Enforcement of Colorado's AI framework sits with the state attorney general rather than private lawsuits under the AI statute itself, though candidates retain their existing rights under anti-discrimination law. The details of enforcement mechanics under SB 26-189 — and possible further amendments before the January 1, 2027 effective date — were still being worked through in 2026, so hiring teams should track guidance from the Colorado attorney general's office.

Related posts

See it on your own job description

Join the early-access waitlist and watch H-Evaluate build an assessment for a real role.

See it on your own job description