Back to Home

Colorado's AI Rulebook: Draft Rules for Hiring and Chatbots

On August 11, 2026, the Colorado Department of Law published a single package of proposed rules that turn two freshly signed AI statutes into an operational rulebook. The Automated Decision-Making Technology (ADMT) rules and the Conversational AI Service Operator Requirements together dictate how companies disclose AI involvement, explain adverse outcomes, run human review, and police consumer-facing chatbots.

Both laws take effect on January 1, 2027, and the proposed rules would become effective the same day. Covered organizations have roughly four months to comment and build compliance infrastructure, because the drafts demand more than the statutes they implement.

The Two Laws Behind the Rulebook

The ADMT Act (SB 26-189), signed on May 14, 2026, repeals and replaces Colorado's 2024 AI Act. The old impact assessment and risk management regime is gone, replaced by a transparency-and-notice structure built on data access, disclosure, and human review.

The Chatbot Safety Act (HB 26-1263), signed on July 1, 2026, targets general-purpose, consumer-facing conversational AI with age-estimation, disclosure, minor-protection, crisis-response, and annual-reporting duties. Rulemaking is mandatory for the ADMT Act and discretionary for the Chatbot Safety Act, but the Attorney General addressed both in one package.

The ADMT Act applies when automated decision technology "materially influences" a consequential decision. The draft rules enumerate the covered domains:

  • Education access and terms
  • Employment decisions, covering Colorado-resident employees and job applicants
  • Lease or purchase of residential real estate in Colorado
  • Financial or lending services
  • Insurance
  • Health-care services
  • Essential government services or public benefits

The Material-Influence Question

The most consequential open issue is the meaning of "materially influence." The Department proposes two competing standards and asks the public to choose.

Standard 1 is broad, pulling resume rankers, applicant scoring tools, and structured interview assessments into the law. Standard 2 would leave a tool outside where a qualified human does real, documented work on top of it. Employers are advised to plan for the broader standard while arguing for the narrower one.

Both versions share a rebuttable presumption: an AI output materially influenced a decision when it constrains an option set, sets a threshold, or produces a rank, score, classification, recommendation, prediction, or inference about the individual; the decision-maker reviews that output or uses it to screen what they see; and the final outcome is consistent with it. That fits most applicant tracking screening, resume ranking, and interview scoring products.

One carve-out survives: tools used solely to summarize, organize, translate, draft, route, or present information for human review fall outside the definition entirely.

Disclosure, Data, and Human Review

Deployers must issue a detailed disclosure within 30 days after a covered ADMT materially influences an adverse outcome. The notice must identify the decision, explain the ADMT's purpose, describe the roles of system and human reviewers, and state the principal reasons with specificity. Generic references to internal policy will not satisfy the standard, and extra explanation is required when a decision rests on an inference, risk score, automatic-denial factor, or incomplete information.

The consequence is blunt: if a vendor cannot produce the principal reasons behind an output, the tool is effectively unusable for Colorado decisions. Decision-level explainability and data lineage become procurement requirements.

Consumers can request the personal data the ADMT used, including ranks, scores, classifications, and inferences, presented legibly rather than as internal codes. Where data arrives through aggregators or brokers, the deployer may need to name both the intermediary and the original source, a traceability demand standard vendor representations do not answer.

Human review becomes a staffed, documented process. Requests must be acknowledged within 10 days and completed within 45 days. Where feasible, the reviewer must be independent of the original decision-maker, trained, authorized to change the outcome, and protected from retaliation. AI may not assist in the review.

The statute's "commercially reasonable" qualifier becomes a factor test: type of review, magnitude and reversibility of harm, value of primary evidence, deployer size, cost and feasibility, and availability of qualified reviewers. A presumption favors review when an adverse outcome involves the severe and irreversible denial of a basic human need, and deployers must stay the outcome while review or correction is pending.

Two responsibility questions remain open. An employer that fine-tunes a model, sets scoring thresholds, or trains on its own workforce data crosses from deployer to developer, carrying heavier documentation duties. The Department also asks who owes deployer obligations when a staffing agency operates the AI and the employer relies on its output.

The Chatbot Safety Act adds a second compliance surface. Internal workforce deployments behind authentication appear outside the general-public scope, and narrow, task-specific bots may remain outside. Public-facing hiring chatbots that screen applicants and book interviews are squarely exposed, especially where they regularly talk with 16- and 17-year-olds.

Covered operators face five concrete duties:

  • Age estimation beyond self-declaration, with reassessment when new signals indicate a different likely age, and government ID barred as the sole method
  • Clear disclosure that the user is interacting with AI, not a human
  • Safeguards protecting teens from sexually explicit content and simulated emotional dependence
  • Suicide and self-harm response protocols, and no presentation of outputs as licensed professional services
  • An annual report to the Attorney General with metrics on age distributions, crisis-referral outcomes, resolution times, and age-determination changes

The timeline is compressed. Comments submitted by September 4 are expected to be considered for a revised draft, interim updates are expected by September 23, and a public hearing is scheduled for October 26. Final rules, like the statutes, take effect on January 1, 2027.

The through-line: compliance extends beyond legal and privacy teams. Product, HR, risk, data governance, and vendor management all get pulled in, the "more operational work than the statutes suggest" outcome analysts flagged immediately.

Comments

No comments yet. Be the first to share your thoughts!