
Colorado’s draft ADMT and Chatbot Safety rules are a systems requirement.
Colorado filed its draft rules on August 11. Comments close October 26. The rules take effect January 1, 2027.
The practitioner question isn’t “what do the rules say.” It’s “what can I configure before the decision happens, and therefore have to start now.”
Three things fall in that category.
1. Scope is decided by evidence you have to capture in advance
The most consequential question in this rulemaking is what counts as an AI output “materially influencing” a decision because that determines how large your covered inventory is. The Department hasn’t picked a standard yet; it filed two and asked for comment.
Skip the drafting debate and look at what both versions accept as evidence that an output didn’t materially influence a decision. First on the list: the decision-maker recorded an independent judgment before the AI output was made available to them.
You cannot reconstruct, six months later, that a reviewer formed an independent view before seeing the model’s score. Either the workflow captured it and timestamped it, or the presumption stands and the use case is in scope.
If you want the option to argue you’re out of scope, the workflow has to assess first and reveal second, and it has to record both moments.
2. The disclosure is a query, not a document
Two requirements combine into something most teams underestimate.
The rules state flatly that a deployer fails to comply when it cannot explain how the technology influenced a decision or how it used someone’s personal data. Inability to explain is the violation.
Then, when a consumer clicks the link in an adverse outcome notice, the technology’s name, version number, developer, and the types, categories, and individually named sources of personal data have to be available immediately. Where data came through a broker, both the original source and every intermediary. The ten-business-day window applies only to mail and email. The web path has to be generated, not researched.
Here’s the test worth running on your own organization this week. Ask which model version scored a specific applicant in March, and which named sources fed it. If the honest answer involves Slack archaeology and a data engineer, you don’t have a disclosure capability. You have a research project with a same-day SLA attached to it.
A hand-authored transparency page is stale the moment you ship a version bump.
3. The appeal leaves the notification layer and enters operations
The human review requirements read less like consumer protection drafting and more like an internal audit standard pointed at a customer-facing queue. The reviewer has to be independent of the original decision-maker and not their subordinate. Subject-matter competence has to scale with the severity of the harm. The reviewer can’t be subject to steering from above, and has to be shielded from retaliation. AI may not assist in the review.
Before reviewing, the reviewer has to diagnose which kind of review would be meaningful. Did the system malfunction, or was it the wrong system for this person’s circumstances? That question is unanswerable unless the developer’s stated intended use and known limitations actually reach the person sitting in the appeal seat. In most organizations that documentation dies in a procurement folder.
And where possible, the adverse outcome has to be stayed pending review. That’s the line that moves this out of the notice function entirely. Staying an outcome means the appeal is wired into the system that executes the decision.
The deadline is earlier than it looks
Detection capability creates duty. Willful disregard of a user’s minor status expressly includes failing to act on signals the model itself processed. Build a good classifier and you inherit an obligation to act on it; don’t build one and you’re exposed on the failure-to-verify prong instead. There’s no version where not looking wins.
And the annual report wants a referral count, a denominator, and referral accuracy benchmarked against clinical screening instruments with metric values over time. First report is July 2027, covering calendar 2027. You cannot compute a 2027 time series after the fact. The real deadline is instrumentation on January 1.
What this looks like when it’s built right
Every requirement above resolves to the same thing: governance state that exists at decision time and can be queried afterward. That’s the architecture Airia is built around.
The use case is the unit. Colorado’s scope question can’t be answered from a model inventory, because the same model is out of scope in one deployment and covered in another. Note that the two acts even pull in opposite directions on internal tools: the chatbot rules exempt internal workforce deployments, while the ADMT rules reach squarely into employment decisions. Registering the use case, with its decision type, covered domain, deployer-or-developer posture, and bound model version, is what makes that determination answerable at all.
Assess and approve is where the sequencing decision gets made and recorded. Whether your workflow captures independent human judgment before revealing the output, who the independent reviewer is, whether outcomes stay pending review, what the commercial-reasonableness analysis concluded and on what evidence. These are design decisions with owners and dates, and Colorado shifts the burden of proving them onto you. A gated approval record is the artifact that survives the question “show me how you decided this.”
Living Disclosures is the answer to the immediacy requirement. The reason we built disclosures as generated surfaces rather than authored documents is precisely the problem the rules create: the same underlying state has to serve a consumer clicking a link, an internal reviewer diagnosing an appeal, and a regulator asking for the record. When the model version changes, the consumer-facing disclosure changes with it, because it was never a separately maintained document.
Monitor is where the metric time series lives. Not for the report. For the fact that safety safeguards remaining effective after model updates is itself a compliance input under these rules.
These are draft rules and will change before adoption. This reflects the text filed August 11, 2026, and is practitioner analysis rather than legal advice. Read the filed documents at coag.gov/AI and file comments through the rulemaking portal.
Put these ideas to work.
Schedule a 30-minute walkthrough with our team.