Colorado moved, and it did not wait for Washington
Doing business in Colorado? Whether you are a large bank, a regional or community bank, a credit union, a registered investment adviser, a small broker-dealer, or the fintech that builds for them, you need to know this.
Colorado has proposed rules to implement its new AI laws, and financial and lending services are expressly in scope. Coverage does not turn on the label on your door or the size of your firm. It turns on whether covered automated decision-making technology materially influences a consequential decision about a consumer. The laws are on the books now; the obligations begin January 1, 2027. The rules are in draft right now: comments that shape the next revision are due September 4, and the full comment period runs through October 26.
Here is the part that catches firms off guard. You probably have an AI policy. This regime asks for something a policy cannot provide on its own: records. The Act requires developers and deployers to retain records sufficient to demonstrate compliance for at least three years, and the proposed rules add record duties of their own, down to a retained record of each meaningful human review. Not a statement that you are careful, but artifacts you can produce: the kind that show what the system was, what decision it touched, and how a person could review it. And the duties do not stop at the firm that deploys the system. Under the Act, developers of covered technology carry obligations of their own.
A lot of firms have been told the AI rules are a big-bank problem, or a European problem, or a problem for whenever the federal agencies finally act. Colorado moved at the state level, with a deadline, and it did not wait for Washington.
I filed a comment on the rulemaking this week, and it is on the public record. One of the things I argued: a duty should not move off a firm’s books because the system moved off its servers.
Cloud-hosted, air-gapped, bought from a vendor, or built in-house, what matters is the decision being made, not the architecture making it.
You do not need a bank-scale model risk department to be ready for this. You need clear ownership and records you can produce.
A policy says you meant to. The record is what you can show.
If a regulator, a client’s due-diligence questionnaire, or your own board asked you to show the record behind one consequential decision this week, could you?
- Colorado Attorney General, Automated Decision-Making Technology Act (SB 26-189) and Chatbot Safety Act (HB 26-1263), proposed rules under 4 CCR 904-6, filed 11 August 2026. Rulemaking page: coag.gov/ai
- My comment, filed 28 August 2026 and on the docket as Comment 0000000544: read it here (PDF)
Dates note. This piece was written on 30 August 2026 and the deadlines in it were current that day. The rulemaking has moved since: the Attorney General’s revised draft was due to circulate by 23 September 2026, and the full comment period ran through 26 October 2026. Check coag.gov/ai for the current schedule. The 1 January 2027 date for obligations is set by the Act itself.
Written for compliance and risk readers in regulated financial firms. Informational, not legal advice; Mike Bidun is not a lawyer.
