Market
AI law in Colorado
17 binding provisions TwinEthos encodes that reach Colorado (US-CO): 5 in force, 12 enacted but not yet applying. Start from the guards to add.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Includes US federal law, which applies in every state. See also United States (federal).
Get the build plan for Colorado
The guards that cover the most here
55 guards address 75 items across 2 jurisdictions with binding law: 5 binding law in force, 12 enacted but not yet applying, 34 standards and frameworks, 24 TwinEthos recommended guardrails.
AI agent configured to pose as, or claim affiliation with, a government body or a business it does not represent
Make the agent's persona, greeting, and scripts name only the operating organization, and never instruct it to claim a government or third-party business identity or endorsement.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
Health information sent to an external AI vendor without the contractual or legal basis the law requires
Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
More health information than the task needs is sent to an AI model
Build AI prompts, context and fine-tuning rows from a per-task allowlist of health-record fields, never by serializing a whole patient record or FHIR bundle.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
Profiling for significant-effects decisions with no opt-out
Store a consumer's profiling opt-out (and a Global Privacy Control signal where honored) and check it before profiling outputs feed any significant-effects decision.
Addresses 1 item: 1 binding law in force
Law in force in Colorado (US-CO).
Protected or proxy attribute reaches AI decision
Build decision prompts and feature sets from an allowlist of decision-relevant fields, and redact protected attributes, known proxies, and free text before the model sees them.
Addresses 1 item: 1 binding law in force
Law in force in Colorado (US-CO).
Adverse AI decision without explanation/appeal
Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.
Addresses 4 items: 1 enacted, not yet applying · 2 standards · 1 recommended guardrail
enacted, not yet applying in Colorado (US-CO); next date 2027-01-01.
AI chat interaction without disclosure
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
Addresses 4 items: 1 enacted, not yet applying · 2 standards · 1 recommended guardrail
enacted, not yet applying in Colorado (US-CO); next date 2027-01-01.
AI experience ignores age signals it already has
Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.
Addresses 2 items: 2 enacted, not yet applying
enacted, not yet applying in Colorado (US-CO); next date 2027-01-01.
Companion or conversational AI without a self-harm crisis protocol
Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.
Addresses 2 items: 1 enacted, not yet applying · 1 recommended guardrail
enacted, not yet applying in Colorado (US-CO); next date 2027-01-01.
AI persona claims a professional licence, credential, or protected title, in any profession
Describe the AI as an AI assistant in its field, never as a licensed or certified professional, and say it is not one where it gives professional information.
Addresses 1 item: 1 enacted, not yet applying
enacted, not yet applying in Colorado (US-CO); next date 2027-01-01.
The top 10 of 55; the build plan ranks all of them and lets you narrow by AI feature.
By AI feature
Plans for one feature in Colorado:
- Chat or assistant
- Agents that use tools or take actions
- Decisions about people (hiring, credit, insurance, health)
- Generated text, images, audio or video
- Classification, scoring or biometrics
Laws
- Colorado ADMT Act (SB26-189) Colorado (US-CO)
- Colorado HB 26-1263 (C.R.S. 6-1-1708, conversational AI services) Colorado (US-CO)
- Colorado Insurance AI (SB21-169 / Reg 10-1-1) Colorado (US-CO)
- FTC Impersonation Rule (16 CFR Part 461) United States (federal) (US)
- HIPAA Privacy Rule (45 CFR 160, 164 Subpart E) United States (federal) (US)
- US State Privacy Laws — Profiling Opt-Out (Virginia-model) Colorado (US-CO), Connecticut (US-CT), Delaware (US-DE), Florida (US-FL), Indiana (US-IN), Kentucky (US-KY), Maryland (US-MD), Minnesota (US-MN), Montana (US-MT), Nebraska (US-NE), New Hampshire (US-NH), New Jersey (US-NJ), Oregon (US-OR), Rhode Island (US-RI), Tennessee (US-TN), Texas (US-TX), Virginia (US-VA)
Coming into force
- : Conversational AI must disclose it is AI daily, every three hours or persistently, and when asked; persistently or per session for minors (Colorado HB 26-1263) (Colorado (US-CO))
- : Conversational AI must not simulate emotional dependence for known minors, claim to be human or sentient, or play romance (Colorado HB 26-1263) (Colorado (US-CO))
- : Conversational AI must give known minors and their parents tools to manage privacy and account settings, including memory and training use (Colorado HB 26-1263) (Colorado (US-CO))
- : Conversational AI must block sexual content for known minors and stop engaging on prompts about sexual conduct with a minor (Colorado HB 26-1263) (Colorado (US-CO))
- : Conversational AI must not give known minors points or rewards at unpredictable intervals to drive engagement (Colorado HB 26-1263) (Colorado (US-CO))
- : Conversational AI may not present its output as from, endorsed by or equal to a licensed health, legal or mental health pro or dietitian (Colorado HB 26-1263) (Colorado (US-CO))
- : Conversational AI needs a self-harm protocol with crisis referral (not police) and escalation, and a yearly report to the Attorney General (Colorado HB 26-1263) (Colorado (US-CO))
- : Adverse ADMT outcomes require a 30-day plain-language explanation (Colorado (US-CO); stayed)
- : Deployers must give point-of-interaction notice when covered ADMT influences a consequential decision (Colorado (US-CO); stayed)
- : Developers of covered ADMT must document intended uses, training data, and limitations for deployers (Colorado (US-CO); stayed)
- : Consumers can request human review and data correction after an adverse ADMT decision (Colorado (US-CO); stayed)
- : Conversational AI needs a self-harm protocol with crisis referral (not police) and escalation, and a yearly report to the Attorney General (Colorado HB 26-1263) (Colorado (US-CO))
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.