โ†
AI Governance, Risk & Red Teaming
Aware ยท M7 ยท lesson 7 of 18 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Colorado AI Act SB 24-205 - Federal Stay, xAI Lawsuit, SB 189 Replacement
๐Ÿ“–
now learning

Colorado AI Act SB 24-205 - Federal Stay, xAI Lawsuit, SB 189 Replacement

15 min

A Denver-based HR Director opens Monday morning, May 11, 2026, and her general counsel forwards three emails: the federal court in Denver issued a preliminary injunction staying SB 24-205 on April 27, the xAI v. Weiser case is in active briefing on First Amendment and Dormant Commerce Clause grounds, and SB 189, the legislature's compromise replacement, passed both chambers Friday May 8 and is on Governor Polis's desk. She had been operating against a June 30, 2026 effective date for SB 24-205, with a Notice of Adverse Consequential Decision template ready and an algorithmic-discrimination risk-management framework half-built. Now nothing is effective. SB 24-205 is stayed. SB 189 is unsigned. The AG has no rulemaking on the books. Her CFO wants to know if she can stand down the eighteen-month Colorado readiness program. The defensible answer is no, and this lesson is the framework that explains why. The L1 posture for Colorado in May 2026 is monitor, do not depend: maintain SB 24-205 capability against reinstatement, prepare SB 189 notice-and-transparency capability against signature, and run federal-preemption scenarios against the pending Congressional bills. The cost of standing down and being wrong is materially higher than the cost of maintaining a paused-but-ready Colorado program through Q4 2026.

SB 24-205 - The Original Law and Why It Mattered

Colorado SB 24-205, signed by Governor Polis on May 17, 2024, was the first comprehensive U.S. state law to regulate high-risk artificial intelligence systems across the consumer lifecycle. It borrowed structurally from the EU AI Act, risk-tiered obligations on developers and deployers, mandatory impact assessments, a duty to avoid algorithmic discrimination, but applied it to a U.S. consumer-protection framing under the Colorado Consumer Protection Act enforcement model administered by the Colorado Attorney General.

The original statutory definition of "high-risk artificial intelligence system" anchored on consequential decisions affecting consumers in eight enumerated categories: education enrollment / opportunity, employment / employment opportunity, financial / lending services, essential government services, health-care services, housing, insurance, and legal services. The structural overlap with EU AI Act Annex III is intentional: most jurisdictions converged on a similar high-risk taxonomy because the underlying harm patterns (discriminatory denial of essential goods, services, or opportunities) are the same.

SB 24-205 Developer Obligations - The Upstream Bar

Under the original SB 24-205, a developer of a high-risk AI system (the analog to the EU AI Act provider) owed the following obligations:

  • Documentation to deployers: Reasonably available information necessary for deployers to complete their impact assessments, including the system's purpose, intended uses, benefits, limitations, training-data summary, evaluation results, and known or foreseeable risks of algorithmic discrimination. The structural cousin of EU AI Act Article 13 (transparency to deployers) and Annex IV (technical documentation).
  • Risk-management documentation, A statement summarizing how the developer manages known or reasonably foreseeable risks of algorithmic discrimination throughout the system's lifecycle. The cousin of EU AI Act Article 9 (risk management system).
  • Disclosure of known or reasonably foreseeable risks, To deployers and (in some categories) directly to consumers.
  • Public statement on the developer's website, Summary of the high-risk AI systems developed and how the developer manages algorithmic-discrimination risk.
  • Notification of known algorithmic discrimination to the AG, Within 90 days of discovery, with cooperation obligations on subsequent investigation.

SB 24-205 Deployer Obligations - The Operational Bar

A deployer of a high-risk AI system (the analog to the EU AI Act deployer) owed:

  • Risk-management policy and program, Reasonably designed to manage known or reasonably foreseeable risks of algorithmic discrimination. Updated annually.
  • Impact assessment, Before deployment, and updated annually and within 90 days of any intentional and substantial modification to the system. The impact assessment had to address: the system's purpose and intended use; categories of data processed; outputs produced; known limitations; risks of algorithmic discrimination; mitigation measures; transparency provided to consumers; and post-deployment monitoring approach. The structural cousin of EU AI Act Article 27 (FRIA).
  • Notice to consumers: Before a consequential decision is made using the high-risk AI system: identification that an AI system is being used, the system's purpose, the nature of the consequential decision, contact information of the deployer, and information about the consumer's rights.
  • Notice of an Adverse Consequential Decision: When the high-risk AI system contributes to an adverse decision, the deployer had to inform the consumer of the principal reasons, including the degree to which the AI system contributed, the type of data processed, the source of that data, and the consumer's right to correct inaccurate personal data and to appeal the decision (where appropriate, with human review).
  • Website disclosure, Public statement summarizing the deployer's use of high-risk AI systems and risk-management approach.
  • Notification of algorithmic discrimination, To the AG within 90 days of discovery.

SB 24-205 Timeline - Effective February 1, 2026, Then Postponed

The original effective date for SB 24-205 was February 1, 2026. As that date approached, two pressures converged: (1) deployers, particularly mid-market employers using third-party HR tools, testified that the documentation and notice requirements were operationally unworkable on the original timeline because developers were not delivering the upstream documentation deployers needed for their impact assessments; (2) developers, particularly out-of-state SaaS providers, argued that the algorithmic-discrimination duty-of-care framing exposed them to disparate-impact litigation in a way that no other U.S. state's law required. The Colorado General Assembly passed a postponement in late 2025 moving the effective date to June 30, 2026, and the AG opened a rulemaking docket on the impact-assessment template and the Notice of Adverse Consequential Decision content.

By March 2026, three additional pressures had materialized: a federal-preemption bill was advancing in the U.S. Senate Commerce Committee; the Texas TRAIGA HB 149 (effective January 1, 2026) had narrowed its scope through industry pressure and was operating in a posture markedly less aggressive than SB 24-205 had been drafted to be; and constitutional litigation was being prepared in Denver federal court by xAI Corp.

The xAI Lawsuit - April 9, 2026 Federal Constitutional Challenge

On April 9, 2026, xAI Corp. filed xAI Corp. v. Weiser in the U.S. District Court for the District of Colorado, naming Colorado Attorney General Phil Weiser as the lead defendant. The complaint raised four constitutional grounds. Each one is a serious challenge in its own right; together, they constitute a comprehensive attack on the structural model of SB 24-205 and, by extension, on every U.S. state law that follows the same model.

First Amendment - Compelled Speech

The first claim asserted that the SB 24-205 disclosure regime, particularly the Notice of Adverse Consequential Decision, the website public statement, and the risk-management public summary, constitutes compelled commercial speech that does not survive the Zauderer or Central Hudson tests. The compelled disclosures, xAI argued, are not purely factual and uncontroversial; they require the speaker to characterize its own AI system in terms (algorithmic discrimination risk, principal reasons for adverse decision, data source attribution) that embed contested policy judgments. The complaint cited recent First Amendment jurisprudence from the Fifth and Eleventh Circuits striking down compelled-speech requirements in social-media content-moderation transparency regimes, arguing the same logic extends to AI-system compelled disclosures.

Dormant Commerce Clause - Extraterritorial Regulation of AI Services

The second claim asserted that SB 24-205 effectively regulates AI-system development and deployment occurring entirely outside Colorado, in violation of the Dormant Commerce Clause's extraterritoriality doctrine. An AI system trained in California and deployed via SaaS to a Colorado employer triggers SB 24-205 obligations on the California developer, including documentation production, risk-management framework maintenance, and AG notification, based solely on the system's reach into Colorado consumers. xAI argued this is the kind of extraterritorial regulation the Supreme Court struck down in Healy v. Beer Institute (1989), Brown-Forman v. NYSLA (1986), and more recently signaled concern about in National Pork Producers v. Ross (2023). The complaint emphasized that SaaS AI services are inherently national and global; a state cannot demand that the entire production process be reshaped to satisfy that state's regulatory preferences without violating the Commerce Clause.

Fifth Amendment Due Process - Vagueness

The third claim challenged the statutory term algorithmic discrimination and the deployer's affirmative duty to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination, on vagueness grounds. The complaint argued that algorithmic-discrimination risk has no objectively determinable threshold, every AI system can be shown to have disparate-impact outcomes at some statistical decomposition, so the duty of care is unbounded and provides no fair notice of what conduct is required to avoid liability. The vagueness claim is structurally similar to the constitutional challenges against earlier state-level data-protection statutes that imposed reasonable-security duties without operational specificity.

Equal Protection - Disparate-Impact Framework as Unconstitutional

The fourth claim, the most ambitious, argued that the SB 24-205 algorithmic-discrimination framework operates as a disparate-impact regime that effectively requires developers and deployers to discriminate by protected class in their training, evaluation, and deployment practices in order to demonstrate the absence of discriminatory outcomes: and that this required race-, sex-, age-, and disability-conscious decision-making violates the Equal Protection Clause as construed in Students for Fair Admissions v. Harvard (2023) and its progeny. This is the most novel of the four claims and would, if successful, restructure not only state AI law but federal employment, lending, housing, and insurance disparate-impact frameworks. Most observers expect the court will not reach this claim on the merits, since the others provide sufficient grounds for the preliminary injunction.

DOJ Intervention - April 24, 2026 Statement of Interest

On April 24, 2026, the U.S. Department of Justice filed a statement of interest in xAI v. Weiser. The DOJ statement, signed by the Assistant Attorney General for the Civil Division, explicitly endorsed two of xAI's claims:

  • Dormant Commerce Clause: DOJ argued that SB 24-205, as drafted, regulates AI services that are inherently interstate commerce, and that the law's reach to out-of-state developers based solely on Colorado-consumer touchpoints raises significant Commerce Clause concerns that warrant preliminary injunctive relief pending full briefing on the merits.
  • First Amendment compelled speech, DOJ argued that the Notice of Adverse Consequential Decision and the website public statement requirements impose compelled speech that does not satisfy First Amendment scrutiny under recent precedent.

The DOJ statement of interest did not endorse the due-process vagueness or Equal Protection claims, signaling internal DOJ caution about the more aggressive theories. It also did not formally seek federal preemption of SB 24-205, though it referenced ongoing federal AI policy development and noted that "uniform federal frameworks for AI services may be preferable to a fifty-state patchwork."

The DOJ intervention is consequential beyond the Colorado case. A federal-government endorsement of constitutional concerns against a state AI law signals the same concerns will arise against parallel laws in Texas, California, Illinois, and New York. State legislatures considering similar statutes in 2026, and there are at least twelve, are now reading the DOJ statement of interest as a roadmap of what to avoid.

Federal Court Stay - April 27, 2026 Preliminary Injunction

On April 27, 2026, Judge Charlotte Sweeney of the U.S. District Court for the District of Colorado issued a preliminary injunction staying enforcement of SB 24-205 in its entirety pending resolution of the constitutional challenges. The injunction order, running 47 pages, found:

  • Likelihood of success on the merits, The court found xAI is likely to succeed on the First Amendment compelled-speech claim and the Dormant Commerce Clause extraterritoriality claim. The court reserved judgment on the vagueness and Equal Protection claims, finding the first two grounds sufficient.
  • Irreparable harm, The court accepted that compliance with SB 24-205 obligations during pendency of the constitutional challenge would impose irreversible operational and reputational costs on developers and deployers, and that compelled-speech harm in particular is presumed irreparable under First Amendment jurisprudence.
  • Balance of equities and public interest, The court found the balance favors the injunction, citing the DOJ statement of interest and the absence of evidence of immediate consumer harm during the injunction period.

The preliminary injunction stays enforcement of SB 24-205 against all developers, deployers, and other parties pending the court's resolution of the merits. The AG's rulemaking docket is also effectively paused. There is no statutory authority to issue rules implementing a statute whose enforcement is enjoined. Trial briefing is scheduled through Q4 2026; a merits ruling is expected in Q1 2027. An expedited appeal to the Tenth Circuit is likely from either side regardless of outcome.

SB 189 - The May 7-9, 2026 Legislative Replacement

Anticipating the federal injunction (and acknowledging the operational unworkability of SB 24-205 as drafted), the Colorado General Assembly took up Senate Bill 189 in the final week of the 2026 session. SB 189 was introduced on May 5, 2026, fast-tracked through committee on May 6, passed the Senate on May 7, passed the House on May 8, and was transmitted to Governor Polis on May 9. As of May 16, 2026 (the date of this lesson), the bill is on the Governor's desk awaiting signature; the Governor has 30 days to sign, veto, or allow to become law without signature.

SB 189 Structure. Notice-and-Transparency Only

SB 189 is materially narrower than SB 24-205. It abandons the algorithmic-discrimination duty of care and the risk-management mandate, replacing them with a notice-and-transparency framework. The core SB 189 obligations:

  • Developer notice obligation, Developers of AI systems making or substantially contributing to consequential decisions in the eight enumerated categories must provide deployers with a plain-language description of: the system's purpose and intended uses; categories of data inputs and outputs; known limitations; and a contact address for the developer. No risk-management documentation, no algorithmic-discrimination duty, no AG notification.
  • Deployer notice obligation: Deployers must provide consumers, at or before the consequential decision, with notice that an AI system is being used, identification of the deployer, and contact information for inquiries. Deployers must also publish a website statement summarizing the categories of consequential decisions for which they use AI systems.
  • Consumer right to information: Consumers may request from the deployer, after a consequential decision, plain-language information about: the principal categories of data used; the general nature of the decision-making process; and (where appropriate) the option to request human review. No detailed Notice of Adverse Consequential Decision template, no per-decision data-source attribution.
  • Effective date-January 1, 2027, IF signed by Governor Polis. The 2027 effective date provides eight months of implementation runway for deployers and developers.
  • Enforcement, Sole enforcement authority lies with the AG under the Colorado Consumer Protection Act. Enforcement is contingent on AG rulemaking on the format and content of consumer notices, the website statement template, and the consumer-information-request process. The bill directs the AG to open rulemaking within 120 days of the bill's effective date; the rulemaking is expected to consume most of 2027.

SB 189 - What It Deliberately Omits

SB 189 was drafted with constitutional defensibility against the xAI claims in mind. It omits:

  • Algorithmic-discrimination duty of care: No statutory duty to identify, mitigate, or report algorithmic discrimination. This removes the vagueness target and the Equal Protection disparate-impact angle.
  • Risk-management mandate, No statutory requirement for developers or deployers to implement risk-management programs. This removes the compelled-speech angle for risk-management public statements.
  • Detailed Notice of Adverse Consequential Decision, No requirement for the deployer to characterize the AI system's contribution to the adverse decision or to attribute data sources. This removes the compelled-speech angle for adverse-decision notices.
  • Impact assessment mandate, No requirement for deployers to conduct annual or per-modification impact assessments. The structural cousin of EU AI Act Article 27 (FRIA) is absent.
  • AG notification of algorithmic discrimination, Removed entirely.

The trade-off is explicit: SB 189 is constitutionally defensible against the xAI claims but provides materially less consumer protection than SB 24-205 did. Civil-society groups (ACLU Colorado, Center for Democracy and Technology) have publicly opposed signature; industry groups (Colorado Chamber of Commerce, BSA | The Software Alliance) have publicly supported signature. Governor Polis has not yet indicated a position. A veto is possible, in which case SB 24-205 remains the law on the books (still stayed) and Colorado has no operative AI law into 2027.

The Colorado Employer Decision This Quarter - Monitor, Do Not Depend

For a Colorado-resident employer (or any out-of-state employer with Colorado consumer touchpoints) in May 2026, the practical L1 obligation matrix has three scenarios:

Scenario 1 - SB 189 Signed into Law (Probability Moderate)

If Governor Polis signs SB 189 within the 30-day window, the law becomes effective January 1, 2027, contingent on AG rulemaking. The employer obligation set is materially lighter than SB 24-205 contemplated: deployer notice to consumers, website statement, consumer information-request process, no risk-management mandate, no impact assessment, no algorithmic-discrimination duty. The capability-build is roughly six months of work for a mid-market employer, focused on: notice template integration into customer-facing decision flows; website statement drafting and legal review; consumer information-request intake process design; coordination with HR-tech vendors on their developer-notice obligations.

Scenario 2 - SB 24-205 Reinstated (Probability Low but Real)

If the federal court rules against xAI on the merits, or the Tenth Circuit reverses, or DOJ withdraws its statement of interest under a future administration, SB 24-205 enforcement could resume. The original June 30, 2026 effective date is past; a court would have to set a new effective date or the legislature would have to act. The capability-build for this scenario is the eighteen-month program many Colorado employers had under way before April 2026: full algorithmic-discrimination risk-management program; annual impact assessment cadence; Notice of Adverse Consequential Decision integration into adverse-decision workflows; developer documentation pull-through from vendor contracts; AG notification process and 90-day reporting calendar; website public statement; coordination with the EU AI Act Article 27 FRIA program for dual compliance.

Scenario 3 - Federal Preemption (Probability Rising)

Two federal bills currently advancing, the bipartisan Senate AI Services Standards Act (S. 2401) and the House Manager's amendment to the AI Innovation and Accountability Act (H.R. 3892): contain express preemption clauses that would void state AI laws on specified topics (developer documentation, deployer notice to consumers, algorithmic-discrimination duty) in favor of a federal framework administered by NIST and FTC. If either bill is enacted in 2026, both SB 24-205 (stayed) and SB 189 (whether or not signed) are effectively moot to the extent of the preemption. The employer obligation set then shifts to the federal framework, which is currently more limited than either Colorado bill. The capability-build for this scenario is monitoring the federal legislation, participating in NIST and FTC rulemaking comment periods, and aligning the Colorado capability-build with anticipated federal requirements.

The Defensible L1 Posture

The L1 posture for Colorado in Q2 2026 is monitor, do not depend, maintain capability:

  • Monitor, Track Governor Polis's signature decision on SB 189 (decision expected by June 8, 2026); track the federal court merits ruling (expected Q1 2027); track the Tenth Circuit appeal; track the federal preemption bills (decisions expected late 2026 / early 2027); track the AG rulemaking docket (currently paused but may reactivate).
  • Do not depend, Do not assume SB 24-205 will reactivate on its original terms; do not assume SB 189 will be signed; do not assume federal preemption will arrive in time. Each scenario has material probability mass and the obligation sets are different enough that you cannot pick one and bet the program on it.
  • Maintain capability: Preserve the in-flight SB 24-205 capability work product (developer documentation pull-through from vendors, draft impact-assessment templates, draft Notice of Adverse Consequential Decision templates, draft AG notification process). The work product is reusable for SB 189 with modifications; it is reusable for the federal framework with modifications; it is fully usable if SB 24-205 reactivates. Standing down loses the option value.

Cross-Jurisdiction Overlay - Colorado in the Multi-State Context

Most enterprises operating in Colorado are also operating in other jurisdictions with active or pending AI laws. The dual-and-triple compliance picture in May 2026:

Colorado + EU AI Act

An employer with Colorado consumer touchpoints AND EU operations (or EU outputs from a US-based AI system) faces overlapping obligations. The EU AI Act Article 27 FRIA on December 2, 2027 (for Annex III ยง4 employment systems and ยง5(b) creditworthiness systems) imposes obligations structurally similar to the SB 24-205 impact assessment, with materially more detail required (Article 27(1)(a)-(g)). The EU Article 13 transparency-to-deployers and Article 11 Annex IV technical documentation are structural cousins of the SB 24-205 / SB 189 developer documentation. The pragmatic approach is to build the EU AI Act FRIA template as the master template and derive the Colorado impact assessment (under SB 24-205, if reinstated) or the Colorado consumer notice (under SB 189, if signed) from the same source document. The Article 26 deployer obligations under the EU AI Act overlap structurally with the SB 24-205 deployer obligations; SB 189 deployer obligations are a strict subset.

Colorado + Texas TRAIGA HB 149

Texas TRAIGA HB 149, effective January 1, 2026, is operative law right now. TRAIGA targets state-government use of AI systems and government contractors using AI to provide services to the state; the consumer-protection reach is narrower than SB 24-205 contemplated. For an employer deploying AI in both Colorado and Texas, say, an Austin-based employer with a Denver branch, the TRAIGA obligations are limited and the Colorado obligations are currently stayed. The combined obligation picture is lighter than it would have been if SB 24-205 had taken effect. The next lesson in this curriculum covers TRAIGA in operating detail.

Colorado + NYC Local Law 144 AEDT

NYC Local Law 144 applies to automated employment-decision tools used to screen NYC-resident candidates. The law has been operative since July 2023, with the NYC Comptroller's enforcement scrutiny stepping up materially in 2025-2026. An employer hiring NYC residents using HR-tech AI faces LL 144 bias audit, candidate notice, and public disclosure obligations regardless of any Colorado-law status. The structural overlap with SB 24-205 deployer obligations is partial but real; LL 144 capability-build is reusable for SB 24-205 if reinstated and for SB 189 in modified form.

Colorado + California Pending Bills

California has at least four AI-system bills pending in 2026, including AB 2930 (employment decision systems), SB 1047-successor (general AI safety, after the 2024 veto), and the California Privacy Protection Agency's ADMT rulemaking under CCPA. None is operative as of May 2026; the regulatory landscape in California is in flux. An employer with California consumer touchpoints should preserve optionality on the California capability-build alongside the Colorado optionality.

Colorado + Illinois HB 3773 + New York AAA

Illinois HB 3773 amended the Illinois Human Rights Act effective January 1, 2026 to prohibit employer use of AI that subjects employees to discrimination, requires notice to applicants and employees when AI is used in employment decisions, and authorizes the Illinois Department of Human Rights to issue rules. The AI Accountability Act in New York (pre-enforcement, pending) targets similar ground. An employer with Illinois operations is already in scope of HB 3773 and is building capability that is partially reusable for Colorado.

Common Colorado Mistakes This Quarter

Mistake 1 - "SB 24-205 was repealed"

SB 24-205 has not been repealed. It is stayed by federal court order pending merits resolution. The statute remains on the books. If the federal court rules against xAI on the merits, or the Tenth Circuit reverses, the stay can be dissolved and enforcement can resume. The capability-build for SB 24-205 retains option value through Q1 2027 at minimum.

Mistake 2 - "SB 189 is law"

SB 189 is not yet law. It passed both chambers May 7-8, 2026 and is on the Governor's desk awaiting signature. The Governor has 30 days. A veto is possible. Even if signed, enforcement is contingent on AG rulemaking that may not complete until late 2027. The capability-build for SB 189 should proceed conditionally, with the trigger event being the signature, not the legislative passage.

Mistake 3 - Ignoring AG rulemaking risk

Both SB 24-205 (if reinstated) and SB 189 (if signed) depend on AG rulemaking for operational definition: the format of the impact assessment, the template of the consumer notice, the content of the website statement, the process for consumer information requests, the categories of "consequential decision" interpretation. The AG rulemaking will materially shape the operational obligation set. Employers that ignore the AG comment periods and rulemaking timeline cede the operational definitions to other industry participants and to civil-society groups. The L1 posture includes engagement with the AG rulemaking docket on whatever scenario materializes.

Mistake 4 - Under-investing in Colorado contingency planning

The instinct after the federal court stay is to redirect capability-build budget to other jurisdictions where the obligations are more certain. This is a mistake. Colorado is the highest-probability state for U.S. AI consumer-protection law in some form by 2027. The optionality cost of preserving the Colorado capability through 2026 is modest compared to the reactive cost of standing it back up after either SB 189 signature or SB 24-205 reinstatement.

Mistake 5 - Assuming federal preemption will arrive in time

The federal AI bills are advancing but not yet enacted. The probability of enactment in the 2026 Congress is moderate, not high. Even if enacted, the preemption scope is narrower than the full Colorado obligation surface, algorithmic-discrimination duty may be preempted, but consumer-notice and deployer-website-statement obligations likely survive. Federal preemption is a scenario to monitor, not a basis to stand down the state-level capability-build.

Mistake 6 - Confusing developer and deployer obligation sets across jurisdictions

SB 24-205 used developer / deployer terminology mapping roughly to EU AI Act provider / deployer. SB 189 retains the developer/deployer split. Texas TRAIGA uses different terminology. NYC LL 144 uses employer. Illinois HB 3773 uses employer. An employer that buys a third-party HR-tech tool is the deployer under SB 24-205 / SB 189 / EU AI Act; the HR-tech vendor is the developer / provider. The actor classification is jurisdiction-specific in terminology but structurally consistent in obligation allocation. The L1 actor mapping artifact (covered in the EU AI Act lessons) should be refreshed with Colorado and other state-law columns.

L1 Deliverable - The Colorado Contingency Plan

The L1 artifact for this lesson is a Colorado contingency plan covering the three scenarios above, with explicit triggers, capability-build allocations, and decision dates. A representative plan:

  • Scenario 1 - SB 189 signed (trigger: Governor Polis signature, expected by June 8, 2026): Activate consumer-notice template integration; activate website statement drafting and legal review; activate consumer information-request intake process; activate vendor coordination on developer-notice flow-through. Capability-build estimated at 6 months for mid-market employer; budget 0.5 FTE in legal, 0.5 FTE in compliance, 0.25 FTE in HR-tech engineering. Trigger AG rulemaking engagement plan.
  • Scenario 2 - SB 24-205 reinstated (trigger: federal court merits ruling for Colorado, or Tenth Circuit reversal): Reactivate algorithmic-discrimination risk-management program build; reactivate impact-assessment template and cadence; reactivate Notice of Adverse Consequential Decision integration; reactivate AG notification process; reactivate website public statement; align with EU AI Act Article 27 FRIA program. Capability-build estimated at 18 months from reactivation; budget 1.5 FTE legal, 1.5 FTE compliance, 1.0 FTE HR-tech engineering, plus external counsel on AG rulemaking and enforcement defense.
  • Scenario 3 - Federal preemption (trigger: enactment of S. 2401 or H.R. 3892): Pause state-level capability-build to the extent of preemption; pivot to federal framework capability-build (NIST and FTC rulemaking engagement, federal compliance program design). Capability-build redirected, not reduced.
  • Decision date matrix: June 8, 2026 (Polis signature); Q4 2026 (federal preemption bill status); Q1 2027 (federal court merits ruling on SB 24-205); Q2 2027 (Tenth Circuit appeal status); H2 2027 (AG rulemaking completion on whichever framework prevails).
  • Capability-preservation budget: Through Q4 2026, maintain 0.25 FTE compliance and 0.10 FTE legal on Colorado monitoring and capability preservation. Cost order-of-magnitude: $80-120K annualized. Cost of standing down and then reactivating: $400-800K plus 4-6 months of timeline slip.

The Colorado contingency plan is the artifact that turns regulatory uncertainty into operational discipline. It allows the CFO to budget the right amount, allows legal to monitor the right triggers, allows HR-tech engineering to preserve the right work product, and allows the audit committee to understand the risk posture in regulator-defensible terms.

Key Takeaways

  • SB 24-205 is stayed, not repealed. Federal court preliminary injunction April 27, 2026 enjoins enforcement pending merits resolution. The statute remains on the books. Reinstatement is possible.
  • The xAI lawsuit raised four constitutional claims. First Amendment (compelled speech), Dormant Commerce Clause (extraterritorial regulation), Fifth Amendment due process (vagueness), Equal Protection (disparate-impact framework). The court found likelihood of success on the first two; the rest were not reached.
  • DOJ intervened April 24, 2026 on Commerce Clause and First Amendment grounds. Federal endorsement of state-law constitutional challenges; signal to other state legislatures considering similar laws.
  • SB 189 passed May 7-8, 2026 and awaits Governor Polis's signature. Notice-and-transparency framework only; no algorithmic-discrimination duty; no risk-management mandate; effective January 1, 2027 if signed; enforcement contingent on AG rulemaking.
  • SB 189 is materially narrower than SB 24-205. Deliberately constructed to be constitutionally defensible against the xAI claims. Trade-off: less consumer protection in exchange for survivability.
  • The L1 posture for Colorado in Q2 2026 is monitor, do not depend, maintain capability. Three scenarios, SB 189 signed, SB 24-205 reinstated, federal preemption, each with material probability mass and different obligation sets.
  • Multi-jurisdiction overlay matters. EU AI Act Article 27 FRIA, Texas TRAIGA, NYC LL 144, Illinois HB 3773, California pending bills, the Colorado capability-build should be designed to be reusable across the multi-jurisdiction picture, not single-state-specific.
  • Six common mistakes this quarter: (1) believing SB 24-205 was repealed; (2) believing SB 189 is law; (3) ignoring AG rulemaking risk; (4) under-investing in contingency planning; (5) assuming federal preemption will arrive in time; (6) confusing developer/deployer terminology across jurisdictions.
  • The L1 deliverable is the Colorado contingency plan. Three scenarios, explicit triggers, capability-build allocations, decision-date matrix, capability-preservation budget. Turns regulatory uncertainty into operational discipline.
  • The cost of preserving optionality is materially less than the cost of reactive standup. $80-120K annualized to maintain monitoring and capability preservation; $400-800K plus 4-6 months of timeline slip to stand back up after standing down. Optionality is the rational L1 posture.