What Colorado’s AI Rewrite Tells Us About the Future of AI Compliance

Luke Lister 

Associate Editor 

Loyola University Chicago School of Law, JD 2028 

The Colorado AI Act (CAIA), formally known as the “Consumer Protections for Artificial Intelligence” Act, was set to take effect on June 30, 2026. It would have required companies deploying high-risk AI (AI that makes, or is a substantial factor in making, a consequential decision about a person, unlike a low-risk tool such as a spam filter) in hiring, lending, housing, healthcare, and other areas to run a review of how an AI system affects the people subject to it, operate an AI-focused risk-management program, and satisfy a reasonable care duty to avoid discrimination. But on May 14, 2026, Governor Jared Polis signed SB 26-189 (the AI Replacement Law), scrapping the CAIA before any of the burdensome requirements came due. Because the AI Replacement Law lets companies deploy AI first and only offers protection after someone has been harmed, it is an insufficient safeguard for the people affected by AI-driven decisions.  

From CAIA to the AI Replacement Law 

The AI Replacement Law shifts focus from regulating how AI is built and implemented to regulating what is disclosed. Specifically, it drops the original bill’s key operational mechanisms, such as the impact assessment and the risk-management program. Taking their place are requirements relating to pre-consumer notices, human review for adverse decisions, and developer documentation duties. Developers must also retain compliance records for at least three years from the date of recording and will have 60 days to cure any violations before facing enforcement. 

The rewrite did not happen in a vacuum. Over the past two years, company compliance departments built programs to comply with the incoming law. Then, in April 2026, the AI company xAI sued to block CAIA’s enforcement, and the federal government intervened on xAI’s side, the first time federal authorities had joined a challenge to a state AI law. Colorado’s Attorney General agreed to suspend enforcement while the case played out, and the legislature rewrote the law instead. 

The cost to consumers 

While the CAIA would have required companies to proactively prevent discriminatory AI decisions before they happened, the AI Replacement Law doesn’t require action from companies until after someone has been harmed. This means a person has to be denied a job, a loan, or housing by AI before they are entitled to an explanation and human review. There is no requirement for companies to test their systems for bias before deploying them. 

Furthermore, the limited protections do not apply to every affected individual. The law only protects you if AI materially influenced the adverse decision, a phrase that is not yet defined. Additionally, companies only have to offer human review to the extent commercially reasonable, a standard that is also not yet defined. While the determination of the standard will be left to the discretion of the state’s Attorney General, regulators have proposed that serious, irreversible harm shall presumptively be reviewed. Regardless, even when the standard applies, there is no private right of action. Only the Attorney General can act on an individual’s behalf, and only after the individual files a complaint. 

Protection after the fact 

The legislature’s retreat from the CAIA to a more company-friendly AI Replacement Law should cause concern for not only those in Colorado, but all American citizens. For Coloradans, the concern is immediate. The CAIA would have made companies prove their AI was safe before making consequential decisions, while the AI Replacement Law lets companies use AI first and only requires review and correction after someone has been negatively impacted. With critical terms still undefined, a company could argue that AI was not substantially involved in a decision, leaving the person harmed without an explanation or a human review. And because only the Attorney General can enforce the law, an office that will likely be overwhelmed with complaints from across the state, even a valid claim may go unanswered. 

For those not in Colorado, the concern is what comes next. Colorado’s rewrite came after a lawsuit and federal pressure, and with Congress unable to pass its own AI framework, other states facing the same pressure may follow suit and build an AI compliance program similar to Colorado’s. This will result in companies having an easier compliance path and consumers left waiting for things to go wrong. 

Ultimately, a law that waits for harm to happen before offering protection, and leaves its most important terms undefined, is an insufficient safeguard against harmful AI-driven decisions. By shifting the burden from companies proving their AI is safe to consumers proving, after the fact, that it was not, the AI Replacement Law leaves the people affected to carry the burden of proving harm that the original law could have helped prevent.