Colorado AI Act: The Most Ambitious State AI Law in the US Rewrote Itself in 2026

By Carlos Montiel | Enterprise AI Specialist
Leer en español →
Published: 2026-07-28 | By: Carlos Montiel | Reading time: ~4 minutes

Colorado had the first comprehensive AI law from a US state ready to go. Between an xAI lawsuit, a federal court block, and an express legislative rewrite, it ended up with a completely different law than the one it started with.

The original plan: developers vs. deployers

SB 24-205, signed in 2024, was set to make Colorado the first US state with a comprehensive AI law, structured similarly to the EU AI Act: a clear distinction between “developers” (those who build or substantially modify a high-risk AI system) and “deployers” (those who use it to make decisions about people). Both had a duty of care to prevent “algorithmic discrimination,” and deployers had to maintain risk management programs and conduct impact assessments before deploying the system.

The 2025 and 2026 delays

The original effective date was February 1, 2026. On August 28, 2025, Governor Jared Polis signed SB 25B-004, which pushed that date to June 30, 2026 — the first sign that industry was pushing hard against implementation.

The court block and xAI's lawsuit

On April 27, 2026, a federal magistrate judge in the District of Colorado issued an order blocking the state from enforcing SB 205, following a lawsuit filed by xAI (Elon Musk's AI company) challenging the law's constitutionality. That was the event that forced the state legislature's hand.

The express rewrite: SB 189

On May 1, 2026 — just four days after the court block — Colorado lawmakers introduced SB 189, a comprehensive replacement law that repeals and re-enacts SB 205's consumer protection framework, but with a much narrower approach based on disclosure and transparency instead of active risk management. Governor Polis signed it on May 14, 2026, barely two weeks after it was introduced.

What disappeared and what stayed

The rewrite eliminated the duty of care to prevent algorithmic discrimination and deployers' obligation to maintain risk management programs and conduct impact assessments — the regulatory heart of the original law. What remains is a disclosure-based approach: developers must give deployers specific information about the system — intended uses, potentially harmful uses, categories of training data, and oversight instructions — but there's no longer an obligation to actively manage discrimination risk. The new effective date is January 1, 2027.

What it means for companies operating across multiple US states

Colorado's case is the clearest illustration yet of a pattern that was already coming into view: state-level AI regulation in the US is volatile, subject to rapid court challenges from the very AI companies it regulates, and can change substantively within weeks. For a company that had designed its compliance around the original SB 205, that work suddenly became obsolete — the practical lesson is not to build a permanent compliance program around the exact text of a still-young state AI law, but around more stable principles (training data documentation, use transparency) that are likely to survive the next rewrite, whether it comes from Colorado or any other state.

Carlos Montiel
Enterprise AI Solutions Architect
Specialist in LLMs, Agents, and Orchestration
guatemalia.com/en/#contact · info@guatemalia.com

Need to implement AI at your company?

Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.

Contact Carlos Montiel

info@guatemalia.com