Colorado
Colorado: New Proposed Rule Implementing Revised AI Law
|
APPLIES TO All Employers with Employees in CO |
EFFECTIVE JAN 1, 2027 |
QUESTIONS? Contact HR On-Call |
Quick Look
|
Discussion
On August 11, 2026, the Colorado Attorney General’s Office filed proposed rules to implement two new state AI laws: the Automated Decision-Making Technology in Consequential Decisions Act (ADMT Act) and the Chatbot Safety Act. Both laws were signed by Colorado’s Governor in May 2026 and are set to take effect January 1, 2027. The proposed rules are now subject to public comment and may change before the laws’ effective date. Key aspects of the proposal are summarized below.
Adverse Decision Outcome. The ADMT Act requires “deployers,” including employers, to tell employees and job applicants when they use ADMT to make a “consequential decision,” such as hiring, promotion, or termination. If the tool contributes to an “adverse outcome,” affected employees and applicants gain new rights, including the ability to request more information, correct inaccurate data, and ask for human review of the decision. Under the proposed rules, when an AI tool contributes to an adverse outcome, employers would need to explain the specific purpose of the tool, the role it played in the decision, and the role of any human reviewer. Employers would also need to explain the main reasons for the outcome clearly and specifically, avoiding vague or generic language. Notably, the proposed rules make clear that an employer cannot comply if it is unable to explain how the tool actually influenced the decision or how it used the person’s data. This means employers should understand, in practical terms, how any AI tool they use actually works and weighs information, not just what the vendor’s marketing materials describe.
Responding to Requests for ADMT Information. If an employee or applicant asks for more detail, the proposed rules require employers to describe the categories of information the tool considered (for example, credit score, health information, or criminal history) and identify each original source of that data by name, including any data broker, background check provider, or other third party. If the data passed through a data aggregator, the employer would need to trace it back to the original source.
Submitting Post-Adverse Outcome Rights Requests. The ADMT law requires that deployers provide an explanation of ADMT consumer rights and how to exercise them. The proposed rules specify that an outcome disclosure must include a clearly labeled link that leads directly to the request mechanism, as well as a mailing address or toll-free number. Employers would be required to offer two or more designated methods for submitting requests, taking into account how they typically interact with employees and job applicants. Those requests would need to be monitored by someone able to act on them, available at any time (not just business hours), and processed with as few steps as possible for the requester.
Requesting Personal Data and Making Corrections. The proposed rules provide employees and applicants the right to see the specific information used in a decision, including not just raw data but also any score, ranking, or recommendation generated by the tool. If they believe the information is incorrect, employers would need to correct it in their systems and, where possible, pause the adverse outcome until the correction is resolved. While employers would be entitled to request supporting documentation for a correction request, employers would need to give the employee or job applicant requesting the correction “a meaningful understanding of why the documentation is necessary.”
Independent Human Review. The proposed rules seek to clarify what counts as the “meaningful human review” that employees and applicants can request after an adverse outcome. Employers would need to confirm receipt of a review request within 10 days and complete the review within 45 days. The review would need to be conducted by someone independent of the original decision-maker, with subject-matter knowledge appropriate to the situation, and with real authority to approve, change, or reverse the decision. The rules also set out a multi-factor test for when human review is “commercially reasonable,” and would presume review is required when an adverse outcome results in a severe, hard-to-reverse loss, such as job loss, placing the burden on the employer to show why review was not feasible.
What Does This Mean for Employers? Because these rules are still in draft form, employers do not yet have a final compliance checklist to follow. However, the proposal signals a detailed and technical set of obligations for any Colorado employer using AI tools to help with hiring, promotion, termination, or similar decisions. Employers should not wait until the rules are finalized to start preparing, since building the necessary processes, training reviewers, and understanding exactly how existing AI tools function will likely take time.
Action Items
- Inventory AI or automated tools currently used in hiring, promotion, termination, or similar employment decisions.
- Review vendor and data provider contracts to confirm access to the underlying data sources.
- Have appropriate personnel trained on the requirements.
- Montior the rulemaking process for updates to forthcoming final rules.
Disclaimer: This document is designed to provide general information and guidance concerning employment-related issues. It is presented with the understanding that ManagEase is not engaged in rendering any legal opinions. If a legal opinion is needed, please contact the services of your own legal adviser. © 2026 ManagEase
