Colorado Recalibrates AI Compliance Rules
New ADMT requirements reshape oversight for servicers
By Carly Imbrogno, Esq. and
Marcello Rojas, Esq.
BDF Law Group *
USFN Member ( AL, AZ, CA, CO, GA, MS, NV, OK, TX, WY)
In 2024, Colorado passed the Consumer Protection for Artificial Intelligence Act to protect consumers in their interactions with artificial intelligence systems. The 2024 law established broad and ambiguous obligations for developers of artificial intelligence systems. Initially scheduled to become effective February 1, 2026, the law's effective date was deferred to June 2026. The legislation mandated that AI developers and deployers of high-risk systems actively mitigate algorithmic discrimination. Specifically, affected businesses were required to conduct risk assessments, notify consumers when AI influences major outcomes, establish clear governance frameworks, and openly disclose their strategies for preventing bias.
The AI industry and Colorado Governor Jared Polis quickly pushed back, warning that the law went too far. Critics immediately described it as the nation's most aggressive state-level AI framework, drawing direct comparisons to the European Union’s strict AI Act. Ultimately, the Colorado AI Act marked a major turning point in U.S. technological governance. It proved that state legislatures will not wait for Congress to act; instead, they are ready to step in and impose heavy compliance demands directly on AI developers and users.
To address the concerns that have been raised, Colorado recently passed Senate Bill 26-189, titled Automated Decision-Making Technology, which is a step back from the 2024 law. The 2026 Act repeals and reenacts provisions with new requirements regarding the use of automated decision-making technology (ADMT). This consequential Act will take effect on January 1, 2027.
Scope
Under the law, ADMT broadly covers any technology that processes personal data and uses computation to generate predictions, recommendations, classifications, rankings, or scores to guide decisions about individuals. A system qualifies as a “covered ADMT” when its outputs "materially influence a consequential decision.” A consequential decision is defined as a decision that materially impacts an individual's access to, eligibility for, or compensation related to education, employment, housing, financial/lending services, insurance, healthcare, or essential government benefits.
The law divides regulatory responsibility between technology creators and the businesses implementing the technology.
Rules for Technology Creators (Developers)
Developers, defined as “a person doing business in Colorado that, develops, offers, sells, leases, licenses, or otherwise makes commercially available a covered ADMT; develops a component that is designed, marketed, intended, documented, advertised, configured, or contracted to be used as part of ADMT; or intentionally and substantially modifies an ADMT such that it becomes a covered ADMT, must explain what the AI is meant for, what data it was trained on, and how deployers should monitor it.” Additionally, developers must furnish deployers with comprehensive technical documentation detailing the system's intended uses, training data categories, known limitations, and operational protocols for human review. They must also notify deployers of any material software updates and retain compliance records for a minimum of three years.
Rules for Companies Using the Technology (Deployers)
Deployers are defined as a person doing business in Colorado that deploys a covered ADMT. Deployers using AI to make significant decisions must provide clear and conspicuous notice to consumers at the point of interaction with a covered ADMT. When AI is used to make a significant decision, deployers must maintain record of such decision, and how it is compliant with the Act for three years. Deployers must inform consumers that they are using AI when they interact with it. Additionally, if the AI gives a consumer a negative result, such as denying a loan, the deployer has 30 days to explain what role the AI played in that decision-making process. Lastly, consumers have the right to review the data that was used, fix mistakes, and demand human review and reconsideration of the AI’s decision. In summary, whenever AI is used in a significant manner and the result is adverse to a consumer, deployers should be aware that consumers can dispute the outcome, which will require human intervention. This intervention can ultimately slow down whatever process is at play.
How it Affects the Default Mortgage Servicing Industry
ADMT sounds technical, but the idea is simple. If a system is doing more than administrative work, such as shaping, guiding, or narrowing the outcome of a decision about a borrower, it may fall within the law’s scope. Think about the tools that support loss mitigation decisions, default or risk segmentation, workout recommendations, or pricing and eligibility adjustments. None of these tools are new in the industry. Under the new law, what matters isn’t whether a system is labeled AI, but whether it meaningfully influences what ultimately happens to the borrower. When such influence occurs, borrowers need to be notified. Servicers will need to be much clearer with borrowers when automated systems are part of the decision-making process.
Servicers will need to be more candid when the interaction is actually happening. If a borrower receives an unfavorable outcome, the expectation isn’t just a standard notice. Servicers will need to explain what happened, and what role the ADMT played in that decision.
Lastly, if a borrower requests reconsideration of the ADMT’s decision, meaningful human review will need to be conducted. Servicers must review the decision and information used, understand the context, and reconsider the outcome if needed.
Violations
Violations of the Act will be enforced by the Attorney General through the Colorado Consumer Protection Act, specifically as a deceptive trade practice. Once the Attorney General is made aware of such violations, a notice of violation must be issued, and then developers or deployers will have 60 days to cure. However, if the Attorney General can show that developers or deployers “knowingly” or “repeatedly” violated the Act, a cure period is not required before penalties are sought.
Violations now extend to civil liability. Developers and deployers may be found liable if ADMT is found to have made a consequential decision that is discriminatory.
Final Thoughts
Colorado's legislative pivot offers immediate regulatory relief, but it requires businesses to recalibrate, rather than abandon, their AI strategies.
- Audit and Streamline Current Compliance: Servicers should audit their AI programs and compliance processes. The new framework eliminates previous burdens, and existing compliance roadmaps may be unnecessarily complex. Make note of the programs currently in use that make consequential decisions. Restructure your governance model to meet actual statutory demands.
- Formulate Disclosures and Recordkeeping: Servicers should assemble the materials that will be provided to borrowers when AI is used in a consequential decision. Furthermore, servicers should develop their recordkeeping systems to prove compliance with the Act for three years.
- Monitor the Shifting Dynamics Between Federal and State AI Legislation: Stay up to date on the shifting dynamic between state laws and federal policy. Although Congress faces constant pressure to pass a unifying federal AI law that could override state rules, the political cycle introduces unpredictability that businesses will need to continue to navigate as technology and laws change.
- Reinforce Strategic Ethics: While state mandates are shifting from bans to transparency, baseline AI governance is still nonnegotiable. Establishing clear human oversight and open disclosures protects servicers from traditional discrimination claims.
Copyright © 2026 USFN
USFNews - July 8, 2026
* Denotes firm is a 2024 Award of Excellence Recipient.