RIG.
← Rodgers Intelligence Group

ADMT Compliance · Colorado SB 26-189 · California CCPA

Is your automated decision-making compliant under Colorado's new ADMT law?

SB 24-205 was repealed and replaced. Here's what SB 26-189 — and California's CCPA/ADMT rules — actually require, and the January 1, 2027 date you're working toward. Score your readiness in about five minutes.

5-min readiness check Current as of July 2026 Not legal advice
Get my ADMT readiness score →

the correction most checklists miss

SB 24-205 was repealed. The live law is SB 26-189.

Load-bearing

If your compliance plan still cites the original "Colorado AI Act" — high-risk AI systems, a duty of reasonable care, mandatory risk-management programs, and annual impact assessments — it's built on a law that never took effect. The original SB 24-205 was delayed, then repealed and replaced by SB 26-189 (signed May 14, 2026): a narrower ADMT transparency-and-rights regime scheduled to take effect January 1, 2027, subject to pending litigation and AG rulemaking. This report reflects the law as it actually stands today.

The shift matters. SB 26-189 drops the three obligations that drew the most concern — the risk-management program, the impact-assessment requirement, and the duty of reasonable care to prevent algorithmic discrimination — and refocuses on automated decision-making technology (ADMT) that materially influences a consequential decision: targeted disclosures, post-adverse-outcome explanations, correction rights, and meaningful human review. Most competing checklists are still selling you the repealed framework.

the readiness check

Are you covered — and where are your gaps?

Two questions decide whether the law even touches you. If it does, a short self-check scores your gaps against the four duties. Answer honestly — if you're out of scope, we'll tell you plainly.

Coverage · 01
Do you use software, AI, or automated scoring to make or materially influence a consequential decision about people — in hiring, lending or credit, insurance, housing, healthcare, or education?
Coverage · 02
Do you do business in Colorado, or process the personal data of California residents, in those decisions?
Your ADMT readiness
Get the full ADMT Readiness Report

I'll send your personalized report by email: a covered/not-covered verdict, a red/amber/green rating across the four duties, your named gaps, a fix-first priority order for Jan 1 2027, and every legal point cited to leg.colorado.gov and cppa.ca.gov. It's a readiness check, not legal advice.

what Colorado (SB 26-189) requires — and by when

Four duties. One deadline.

Effective January 1, 2027, a covered deployer must:

  • Pre-use notice — tell people, before an automated system materially influences a consequential decision about them, that it's used and what it does.
  • Adverse-outcome explanation — within 30 days of an adverse automated outcome, provide a plain-language explanation of the system's role.
  • Meaningful human review — a trained person with real authority to approve, modify, or override, who weighs the evidence rather than rubber-stamps.
  • Access & correction — let people access the personal data used and correct it.

Enforcement is the Colorado Attorney General only — no private right of action — and rulemaking is mandatory, to be completed by January 1, 2027. The repealed high-risk / duty-of-care / impact-assessment framework does not apply.

what California's CCPA / ADMT rules add

A second regime, the same year.

California's finalized CCPA regulations layer on more, with ADMT obligations taking effect in 2027: a pre-use notice describing how the ADMT works and what data feeds it; a frictionless opt-out with at least two methods and a genuine non-automated alternative (a link or cookie banner alone isn't enough); and a right to access the decision logic. Hiring, lending, and work-allocation carry specific exceptions — but pre-use notice and access still apply even when an exception does.

The overlap

Both laws bite on the same trigger, in the same year: automated tools that materially influence a consequential decision, compliance dates in 2027. And both rest on the same operational core — pre-use notice, a human who can actually override the machine, access and correction, and an auditable record of where automated decisioning is used. Build those four in from day one and you satisfy the load-bearing parts of both. That's not a bolt-on; it's how governed AI gets built.

what the report covers

Eight checks, scored against your answers.

  • You use AI or automated scoring to make or materially influence decisions about people — hiring, lending, insurance, housing, healthcare, or education.
  • You do business in Colorado, or process California residents' personal data, in those decisions.
  • Before an automated decision, you give a clear pre-use notice: that an automated system is used, what data feeds it, and what it does.
  • When an automated system produces an adverse outcome, you can deliver a plain-language explanation within 30 days.
  • A trained human with real authority reviews and can override the decision — and you can prove they reviewed it, not rubber-stamped it.
  • A person can access the logic behind a decision and correct the data used about them.
  • (California) You offer a frictionless opt-out with two methods and a genuine non-automated alternative — or a documented exception applies.
  • You keep an inventory and audit trail of every place automated decisioning touches a consequential decision — models, inputs, and who can override.

governance from day one

How RIG closes the gaps.

The free ADMT Readiness Report is the top of a short ladder: report → a $2,500 refundable opportunity brief → a fractional CAIO engagement → a governed build. RIG is an operating and governance layer — not a law firm and not a compliance certifier. We build the notice-logging, human-override, and decision-logging controls these laws center on, and we tell you plainly what a report can and can't answer.

RIG runs its own operation on 100+ governed agents across 24 internal systems — our own build, not client deployments. Every governed decision we build carries pre-use-notice logging, a human-override step with the evidence surfaced, and a hash-bound audit trail — the exact controls these laws center on.

Get my ADMT readiness score → See how governed agents work →

questions

ADMT compliance, answered.

Is my company covered by the Colorado AI Act / ADMT rules?

You're covered if you use AI or automated systems that materially influence a consequential decision — hiring, lending, insurance, housing, healthcare, or education — about Colorado residents, or (under California's CCPA) California residents' data. If you don't use automated tools in those decisions, you're likely out of scope.

When does the Colorado AI Act take effect?

The original SB 24-205 was repealed before it went live. The current law, SB 26-189, is scheduled to take effect January 1, 2027 — subject to pending litigation and AG rulemaking, so enforcement may follow the rulemaking rather than start immediately.

What do I actually have to do to comply?

Give people a pre-use notice that an automated system is used, explain an adverse automated decision in plain language within 30 days, provide meaningful human review with real override authority, and let people access and correct the data used about them.

How is this different from California's ADMT rules?

California's CCPA/ADMT regime adds a pre-use notice, a frictionless opt-out with two methods, and access rights, with ADMT obligations taking effect in 2027. One governance approach — notice, human-in-the-loop, access, and an audit trail — covers the common core of both.

This is an operational readiness checklist, not legal advice — confirm your obligations with qualified counsel before relying on it.

Last updated July 2026 — reflects Colorado SB 26-189, which repealed and replaced SB 24-205. SB 26-189 is scheduled to take effect January 1, 2027 and is subject to pending litigation and AG rulemaking; the exact California ADMT compliance date in 2027 should be confirmed with counsel.

Penalty figures (up to $20,000 per violation) reflect the general Colorado Consumer Protection Act civil penalty, not an SB 26-189-specific fine. Legal points reference leg.colorado.gov and cppa.ca.gov. RIG is an operating / governance layer — not a law firm and not a compliance certifier.