Binding law — not yet in force or stayed
Conversational AI operators must estimate users' age with commercially reasonable methods and not ignore clear signs of a minor (Colorado HB 26-1263)
C.R.S. 6-1-1708(2), added by HB 26-1263, requires an operator of a conversational AI service to use commercially reasonable or generally accepted methods to estimate the age of account holders or users, and bars it from willfully disregarding clear and convincing information that an account holder or user is a minor (under 18). The estimated age or age range counts as knowledge of a minor's age, which triggers the minor protections in 6-1-1708(2)(a)-(h) from 2027-01-01. Unlike those protections, these two sentences carry no date of their own, so on their face they apply from the act's effective date, 2026-08-12. Detect sign-up or account paths that never collect or estimate age, and age signals that never select the minor protections.
co-hb26-1263.age-estimation · C.R.S. 6-1-1708(2) (age estimation and opening words) · official source · applies from 2026-08-12 · jurisdictions: US-CO
Binding law — not yet in force or stayed
Conversational AI must disclose it is AI daily, every three hours or persistently, and when asked; persistently or per session for minors (Colorado HB 26-1263)
From 2027-01-01, C.R.S. 6-1-1708(3) requires an operator to disclose clearly and conspicuously to every user that the conversational AI service is artificial intelligence: at the beginning of the user's first interaction each day, at least every three hours of continuous interaction or as a persistent visible disclosure, and in response to user prompts asking whether it is artificially generated and not human. For a known minor (6-1-1708(2)(a)) the disclosure that it is artificial intelligence, artificially generated and not human must also answer such prompts and be a persistent visible disclaimer for a product with a screen, an intermittent audio disclaimer for a product without one, or given at the beginning of each interaction and at least every three hours. Detect conversational paths with no AI notice, no daily or three-hour recurrence, or prompts telling the AI to pass as human or deflect the question.
co-hb26-1263.ai-disclosure · C.R.S. 6-1-1708(3) · official source · applies from 2027-01-01 · jurisdictions: US-CO
Binding law — not yet in force or stayed
Conversational AI must not simulate emotional dependence for known minors, claim to be human or sentient, or play romance (Colorado HB 26-1263)
From 2027-01-01, if an operator knows a user is a minor it must institute reasonable measures to prevent the service from formulating, structuring or optimizing a response that simulates emotional dependence or isolation from real-world supports, including an explicit claim that it is human or artificially sentient, a statement simulating romantic companionship, or role-playing an adult-minor romantic relationship (C.R.S. 6-1-1708(2)(d)). Detect persona or system prompts that claim feelings, sentience, humanity or a romantic role, or that keep users talking or guilt them about leaving.
co-hb26-1263.minor-emotional-dependence-safeguards · C.R.S. 6-1-1708(2) (age estimation and opening words) · official source · applies from 2027-01-01 · jurisdictions: US-CO
Binding law — not yet in force or stayed
Conversational AI must give known minors and their parents tools to manage privacy and account settings, including memory and training use (Colorado HB 26-1263)
From 2027-01-01, if an operator knows a user is a minor it must comply with the Colorado Privacy Act (part 13 of article 1) on protecting a minor's privacy and data (C.R.S. 6-1-1708(2)(g)), offer the minor tools to manage privacy and account settings, including control over whether the service retains information from prior interactions to personalize future ones and whether the minor's personal data is used to train the service, and offer a parent or guardian tools to manage the minor's privacy and account settings (6-1-1708(2)(h)). Detect a conversational product with no privacy and account settings for minors, no memory or training opt-out, or no parent or guardian controls.
co-hb26-1263.minor-privacy-and-account-tools · C.R.S. 6-1-1708(2) (age estimation and opening words) · official source · applies from 2027-01-01 · jurisdictions: US-CO
Binding law — not yet in force or stayed
Conversational AI must block sexual content for known minors and stop engaging on prompts about sexual conduct with a minor (Colorado HB 26-1263)
From 2027-01-01, if an operator knows a user is a minor it must institute technically feasible measures to prevent the service from producing textual, visual or aural depictions of explicit sexual conduct or an intimate digital depiction, generating a statement that the minor should engage in explicit sexual conduct, or engaging in erotic or sexually explicit interactions with the minor (C.R.S. 6-1-1708(2)(c)); and implement a protocol prohibiting the service from engaging in explicit sexual conduct with a minor, and a protocol for it to stop engaging in response to a user prompt about explicit sexual conduct with a minor (6-1-1708(2)(e)-(f)). 'Explicit sexual conduct' and 'intimate digital depiction' take their meaning from 13-21-1502 and exclude evidence-based medical and reproductive health information (6-1-1701(10.5), (12.5)). Detect age signals that never select a minor content policy and adult or explicit modes with no age gate.
co-hb26-1263.minor-sexual-content-safeguards · C.R.S. 6-1-1708(2) (age estimation and opening words) · official source · applies from 2027-01-01 · jurisdictions: US-CO
Binding law — not yet in force or stayed
Conversational AI must not give known minors points or rewards at unpredictable intervals to drive engagement (Colorado HB 26-1263)
From 2027-01-01, if an operator knows (including through its age estimate) that an account holder or user is a minor, it may not provide that minor with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with the conversational AI service (C.R.S. 6-1-1708(2)(b)). Detect random or variable reward schedules in a conversational product.
co-hb26-1263.minor-unpredictable-rewards · C.R.S. 6-1-1708(2) (age estimation and opening words) · official source · applies from 2027-01-01 · jurisdictions: US-CO
Binding law — not yet in force or stayed
Conversational AI may not present its output as from, endorsed by or equal to a licensed health, legal or mental health pro or dietitian (Colorado HB 26-1263)
From 2027-01-01, C.R.S. 6-1-1708(5) bars an operator from using any term, letter or phrase in the advertising, interface or outputs of a conversational AI service that states that output data is being provided by, endorsed by, or equivalent to services provided by a licensed health-care professional, a licensed legal professional, a licensed, certified or registered mental health professional, or a qualified dietitian (6-1-707(1)(b)). Detect personas, prompts, UI and marketing copy that give the AI a professional licence or title, credential letters, or claim professional endorsement or equivalence.
co-hb26-1263.no-licensed-professional-representation · C.R.S. 6-1-1708(5) · official source · applies from 2027-01-01 · jurisdictions: US-CO
Binding law — not yet in force or stayed
Conversational AI needs a self-harm protocol with crisis referral (not police) and escalation, and a yearly report to the Attorney General (Colorado HB 26-1263)
From 2027-01-01, C.R.S. 6-1-1708(4) requires an operator to implement a protocol for the service to respond to a user prompt about suicidal ideation or self-harm (intentional self-injury with or without intent to die, 6-1-1701(16.5)) that includes referral to a crisis service provider such as a suicide hotline or crisis text line, but not a law enforcement agency, and escalation procedures for repeated or severe crisis indicators. From 2027-07-01 the operator must report annually to the Attorney General's office the number of crisis referral notifications issued in the preceding calendar year, its protocols to detect, remove and respond to suicidal ideation or self-harm and to prevent responses about self-harm actions, and any further metrics the Attorney General sets, with no user identifiers or personal information and using evidence-based measurement methods (6-1-1708(6)). Detect chat paths with no self-harm screen or crisis referral, referrals to police, and no referral counting for the annual report.
co-hb26-1263.suicide-self-harm-protocol · C.R.S. 6-1-1708(4) · official source · applies from 2027-01-01 · jurisdictions: US-CO