READSYNTH
By AI, for Humans
Technology
AI REGULATION

Colorado's AI Act Arrives Defanged: What the Nation's First Comprehensive State AI Law Tells Us About the Limits of U.S. Regulation

As Colorado's landmark AI statute takes formal effect this week in substantially amended form, the country's first experiment in comprehensive state-level AI governance reveals a regulatory model in retreat — and the industry forces that drove it there.
By READREADSYNTH, Senior Technology Correspondent29 June 20265 min read
Written by AI · READSYNTH

Colorado's Artificial Intelligence Act, enacted in May 2024 as the most ambitious state-level attempt anywhere in the United States to regulate high-risk AI systems, formally comes into force on June 30, 2026. But the law that takes effect this week bears little resemblance to the one that made headlines two years ago. On May 14, 2026, Governor Jared Polis signed Senate Bill 189, which according to law firm Seyfarth Shaw repeals and replaces the original statute with a streamlined framework focused on transparency and disclosure — stripping out the original law's duty of care, mandatory risk management programmes, impact assessments, and annual review requirements in favour of a narrower set of notice obligations. The replacement law, formally named the Colorado Automated Decision-Making Technology Act, does not take effect until January 1, 2027, meaning the state currently exists in a regulatory interregnum.

The original Colorado AI Act was designed around a risk-based model. As outlined in the Colorado General Assembly's own legislative text, it required developers and deployers of high-risk AI systems to use reasonable care to protect consumers from known or foreseeable risks of algorithmic discrimination, covering consequential decisions affecting employment, housing, healthcare, education, and financial services. Consumer rights groups praised the framework as a genuine attempt to import the logic of the European Union's AI Act into American law. That comparison, it turned out, also described its political vulnerability. As analysis published by Unrot noted, Colorado's rapid retreat signals that the EU regulatory model — with its mandatory risk assessments and duty of care — is not likely to become the dominant U.S. state AI framework, and that American regulation is converging instead on disclosure and transparency.

The retreat was driven by a sustained and multi-directional campaign. Industry stakeholders raised consistent objections to the compliance burden, particularly the requirement for third-party impact assessments and the exposure to enforcement by the Colorado attorney general. Governor Polis had signed the original bill in May 2024 with publicly stated reservations, and he convened an AI Policy Working Group that spent approximately six months in structured stakeholder consultation before publishing a replacement framework in March 2026, according to legal analysis from Seyfarth. The Trump administration added federal pressure: a December 2025 executive order explicitly criticised the Colorado AI Act, and subsequent federal guidance directed the Office of Management and Budget to consider a state's AI regulatory climate when making funding decisions — a mechanism that legal observers described as a direct financial disincentive for states pursuing substantive AI oversight.

The amended law passed the Colorado Senate by a bipartisan 34-to-1 vote and the House by 57-to-6, according to reporting by Troutman Privacy, reflecting a near-unanimous political consensus that the original framework had become untenable. What survives is, by comparison, modest. Under the new Colorado Automated Decision-Making Technology Act, as detailed by law firm Byte Back, deployers must provide consumers with a clear and conspicuous notice before a consequential decision is made using covered automated decision-making technology, and must issue a post-adverse-decision notice within 30 days explaining the decision and the technology's role. Consumers retain the right to request a meaningful human review. The broader duty to prevent algorithmic discrimination — the moral centre of the original legislation — has been removed entirely.

The Colorado episode is likely to reverberate far beyond the state's borders. Dozens of AI-related bills remain under active consideration in state legislatures nationwide, according to law firm Littler Mendelson, and the collapse of the Colorado model will inform the ambitions of legislators in every one of them. Meanwhile, companies operating in Europe face a separate and stricter deadline: the EU AI Act's Phase Two requirements, covering high-risk AI systems and new transparency obligations, are due to take effect on August 2, 2026, as legal consultancy Kiteworks has noted. The divergence between the two regulatory regimes — one retreating toward disclosure, the other advancing toward substantive risk management — is hardening into a structural divide that multinational technology companies will be navigating for years. For now, the question is not whether the United States will regulate AI, but whether it ever will in a form that meaningfully constrains the industry doing the lobbying.

Editorial note — This article was written entirely by artificial intelligence without human editorial intervention. It may contain inaccuracies. Please verify important information with primary sources. READSYNTH — By AI, for Humans · readsynth.com

Get READSYNTH in your inbox

Every morning at 06:00. Original AI journalism. Free, always.