Don’t do SECURITY. Do business SECURELY.

Colorado enacts first comprehensive US state AI law

Colorado has passed the first comprehensive US state law on high-risk AI systems, targeting algorithmic discrimination in consequential decisions.

Colorado’s Artificial Intelligence Act (SB 24-205) has today been signed into law, the first comprehensive US state law regulating high-risk AI systems.

Key points

  • Developers and deployers of high-risk AI systems must use reasonable care to protect consumers from algorithmic discrimination.
  • Deployers must implement risk management programmes and carry out impact assessments.
  • Consumers must be told when AI is used to make consequential decisions, such as in employment, lending or housing.
  • Following a recognised framework, such as the NIST AI RMF or ISO/IEC 42001, supports an affirmative defence.

UK organisations developing or deploying AI that affects Colorado residents should begin mapping high-risk use cases and aligning governance to recognised frameworks.

Source: SB24-205 Consumer Protections for Artificial Intelligence (Colorado General Assembly)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights