> This is the markdown version of https://www.classet.ai/blog/colorado-ai-act-hiring
> Learn more at https://www.classet.ai



![Timeline of Colorado AI Act amendments and the January 2027 effective date](/_next/image?url=%2Fimages%2Fblog%2Fcolorado-ai-act-hiring.png&w=3840&q=75)

# Colorado's AI Act Got Gutted. Hiring Risk Went Up.

Colorado rewrote its AI Act in May 2026 and pushed it to January 2027. The compliance burden shrank. The evidence burden on individual hiring decisions grew.

[![Paul Jones](/_next/image?url=https%3A%2F%2Fassets.basehub.com%2Fe0b5701f%2F6599306507912123f90f150a8bfaaf6c%2Fscreenshot-2026-01-28-at-10.53.16-am.png%3Fwidth%3D100%26height%3D100%26quality%3D100&w=96&q=75)

Paul JonesHead of Growth at Classet

](/blog/authors/paul-jones)

July 21, 2026

AI Recruiting, Guides & Insights

For two years, every AI hiring vendor sold against the Colorado AI Act. Impact assessments, risk management programs, a duty of reasonable care to avoid algorithmic discrimination. It was the strictest AI employment law in the country and it was coming for anyone screening candidates with software.

Then in May 2026 the legislature took most of it out.

Governor Polis signed SB 26-189 on May 14, 2026. It stripped the impact assessment requirement, the risk management program, the annual review obligation, and the affirmative duty of care. It also pushed the effective date from June 30, 2026 to **January 1, 2027**. If you built a compliance plan around the original text, most of it is now shelf-inventory.

The reflex read is that the risk went away. It didn't. It moved somewhere harder to prepare for.

> **Quick Answer**: Colorado's AI Act (SB 24-205) was substantially rewritten by SB 26-189 in May 2026 and now takes effect January 1, 2027. Impact assessments, risk management programs, and the duty of care were removed. Three obligations remain for employers using automated tools in hiring: clear pre-use notice to candidates, a plain-language explanation plus human review within 30 days of an adverse decision, and three years of record retention. Enforcement is by the Colorado Attorney General only, up to $20,000 per violation.

## What Survived the Rewrite

Three things, and they're all about the individual candidate rather than the system.

**Pre-use notice.** Before you run someone through an automated decision-making tool, you have to give clear and conspicuous notice that you're doing it. This one is easy and most teams already do it.

**Adverse action explanation.** Within 30 days of a decision that goes against a candidate, you owe them a plain-language description of the decision, the right to request the information that fed it, the right to correct inaccurate data, and the right to meaningful human review "to the extent commercially reasonable."

**Record retention.** Three years, minimum.

Enforcement runs exclusively through the Colorado Attorney General. There's no private right of action, which matters a lot. It means no class actions from rejected applicants. Violations count as unfair or deceptive trade practices, with penalties up to $20,000 each and a 60-day cure period before the AG can act.

## Why the Lighter Law Is Harder to Comply With

Here's the part that got lost in the "Colorado backed down" coverage.

Under the original text, compliance was a project. You ran an impact assessment, documented your risk management program, filed it, and you were largely done until the annual review. It was expensive and it was finite. You could hire a consultant, produce a binder, and point at the binder.

The rewrite deleted the binder and kept the questions. You no longer certify that your system is fair in the abstract. Instead, for any candidate who asks, at any point in the next three years, you have to explain why _that specific person_ didn't advance, in plain language, with the underlying data, with a path to correction, and with a human who can actually review it.

That's not a project you finish. It's a property your hiring process either has or doesn't.

And it's much less forgiving of the way most AI screening actually works. A resume-ranking model that outputs a score between 0 and 100 can pass an impact assessment. It cannot produce a plain-language explanation of why candidate #4,417 scored a 62, because there isn't one. The score is the output of weights, not of reasons.

## What This Means for Vendor Selection

The question you ask AI hiring vendors should change, and most buying teams haven't updated it yet.

The old question was "do you have a bias audit?" That question was built for NYC's Local Law 144, which requires an annual independent bias audit for automated employment decision tools and published results. It's still a fair question if you hire in New York City. It just doesn't answer anything Colorado now asks.

The new question is narrower and more awkward for a lot of vendors: **can you show me, three years from now, exactly why this one candidate was rejected, in language I could read to them?**

Some architectures answer that easily. A structured screen where a candidate is asked "do you hold a current CDL Class A?" and answers "no," against a criterion the employer set in advance, produces an explanation that writes itself. There's a transcript, a recording, a question, an answer, and a rule. Every piece of it is inspectable and correctable, if the candidate says the transcription was wrong, you can play the audio.

Other architectures don't. An opaque ranking model gives you a number and a shrug.

## Where Classet Sits in This

We build one of these tools, so it's worth stating plainly how it works rather than letting you infer it.

Classet does not make hiring decisions

Joy conducts the interview and reports what the candidate said. That's the whole job.

-   The employer writes the questions and defines the criteria. Joy doesn't generate either.
-   Joy asks, listens, and records. Every answer is stored as audio, transcript, and structured summary on the candidate record.
-   Joy does not score candidates on suitability, rank them against each other, or reject anyone.
-   When a candidate misses a must-have criterion, Joy completes the full interview anyway and flags the miss for the recruiter. It doesn't end the conversation or close the file.
-   A person reviews the record and decides who advances. Always.

There is a human in the loop making every hiring decision, and never an AI making one.

This matters for the adverse action requirement specifically. If a candidate asks why they didn't move forward, the answer isn't buried in model weights. It's the question you asked, the answer they gave, and the criterion you set, all sitting on the record with the audio attached. If the transcription got something wrong, you play the tape and correct it. That's what "meaningful human review" is supposed to look like in practice.

One thing I won't claim: that a human-in-the-loop design puts you outside the law. It doesn't, and any vendor telling you otherwise is selling something. Colorado's obligations attach to the employer deploying the technology, and a tool that materially informs who advances is in scope regardless of who clicks the final button. You still owe candidates pre-use notice, a plain-language explanation within 30 days of an adverse decision, and three years of records.

What the design does change is how hard those obligations are to meet. Producing an explanation is straightforward when the underlying record is a conversation a person can read. It's close to impossible when the record is a score.

## Scope: Who This Actually Covers

The law reaches employers "doing business in Colorado" and covers automated decision-making technology used in consequential decisions about access to, eligibility for, selection for, or compensation for employment. That includes hiring, promotion, and compensation decisions.

It excludes independent contractors and non-Colorado residents. It also carves out identity verification, cybersecurity tooling, routine scheduling, and clerical tools like spreadsheets that require human analysis, so your calendar integration isn't in scope.

Liability between vendors and employers is allocated by relative fault. A deployer can avoid liability where it used the technology as the developer intended, documented, marketed, configured, or contracted. That clause makes your vendor documentation genuinely load-bearing. If you configure a tool outside how the developer documented it, you've absorbed the risk.

_This is a summary for planning purposes, not legal advice. Talk to employment counsel before finalizing your approach._

## The Wider Pattern

Colorado is not moving alone, and the direction of travel across states is consistent even where the details differ.

Illinois' AI video interview disclosure law is in effect. California finalized employment discrimination regulations covering automated decision systems. NYC Local Law 144 still requires annual bias audits with published results for tools used on NYC candidates. The EU AI Act classifies employment AI as high-risk with its own obligations for anyone hiring in Europe.

Read together, these are converging on the same requirement from different angles: tell candidates you're using AI, be able to explain what it did, and keep the receipts. A hiring process built to satisfy that holds up across all of them. One built to pass a single jurisdiction's audit doesn't.

## Key Points

-   SB 26-189 (signed May 14, 2026) moved the Colorado AI Act's effective date to January 1, 2027
-   Impact assessments, risk management programs, annual reviews, and the duty of care were removed
-   Pre-use notice, 30-day adverse action explanation with human review, and 3-year record retention remain
-   Colorado AG enforces exclusively: no private right of action, up to $20,000 per violation, 60-day cure period
-   The burden shifted from proving system-level fairness to explaining individual decisions on demand
-   Screening tools that produce transcripts and explicit criteria satisfy this more easily than opaque scoring models

## Next Steps

You have until January 1, 2027, which is more runway than you had in April. The useful thing to do with it is inventory: list every tool that touches a hiring, promotion, or compensation decision, and for each one, try to write the adverse action notice for a real rejected candidate. The tools where that's hard are the ones to revisit.

If you want to see what a structured, fully-transcribed screen looks like in practice, [book a walkthrough](/demo). Related reading: [how to evaluate AI recruiting vendors](/blog/ai-recruiting-vendor-questions) and [what bias audits actually cover](/blog/ai-recruiting-bias-audits-compliant-platform).

## FAQ

When does the Colorado AI Act take effect?

January 1, 2027. The original effective date was February 2026, pushed to June 30, 2026, then delayed again by SB 26-189 which Governor Polis signed on May 14, 2026. That amendment also substantially rewrote the substance of the law, so the delay came with a much lighter set of obligations.

Do I still need an impact assessment under the Colorado AI Act?

No. SB 26-189 removed the impact assessment requirement, along with the risk management program, the annual review obligation, the duty to report discriminatory outcomes to the Attorney General, and the affirmative duty of reasonable care to avoid algorithmic discrimination. What remains is candidate notice, adverse action explanation, and record retention.

Does the Colorado AI Act apply to my company if we're not based in Colorado?

It applies to employers doing business in Colorado, so location of headquarters isn't the test. If you hire Colorado residents using automated decision tools, you're likely in scope. It does not cover independent contractors or non-Colorado residents. Check with counsel on your specific footprint.

Can candidates sue under the Colorado AI Act?

No. Enforcement runs exclusively through the Colorado Attorney General, and there's no private right of action. Violations are treated as unfair or deceptive trade practices with penalties up to $20,000 per violation, and the AG must give a 60-day cure notice before taking enforcement action.

Is AI phone screening covered by the Colorado AI Act?

If it factors into a consequential employment decision (who advances, who gets hired, what they're paid) then yes, it's automated decision-making technology under the law. That means candidates get pre-use notice, adverse decisions need a plain-language explanation with a route to human review within 30 days, and records are kept three years.

Does Classet make hiring decisions about candidates?

No. Joy conducts a structured interview using questions the employer wrote and criteria the employer defined, then reports what the candidate said, as audio, transcript, and a summary on the candidate record. Joy doesn't score candidates on suitability, rank them, or reject anyone. When someone misses a must-have criterion, Joy finishes the interview and flags it for the recruiter rather than ending the call. A person reviews the record and decides who advances, every time.

Does a human-in-the-loop process exempt me from the Colorado AI Act?

No, and be skeptical of any vendor who says it does. The obligations attach to the employer deploying the technology, and a tool that materially informs who advances is in scope even when a person makes the final call. You still owe pre-use notice, a plain-language explanation within 30 days of an adverse decision, and three years of records. What a human-in-the-loop design changes is difficulty, not applicability. Explaining a decision is far easier when the record is a conversation rather than a score.

What's the difference between the Colorado AI Act and NYC Local Law 144?

Local Law 144 requires an annual independent bias audit of automated employment decision tools, with results published, plus candidate notice. Colorado's rewritten law requires no audit at all. It focuses on explaining individual decisions after the fact and retaining records. They're different obligations, so satisfying one doesn't satisfy the other if you hire in both places.

What should I ask an AI hiring vendor about Colorado compliance?

Ask them to walk you through a specific rejected candidate: what question was asked, what the candidate said, which criterion they missed, and what you'd hand the candidate if they requested an explanation three years later. Vendors with structured questions and stored transcripts answer that in a minute. Vendors relying on model scores usually can't answer it at all.

Does 'meaningful human review' mean a person has to review every rejection?

No. The obligation is to provide the opportunity for human review when a candidate requests it after an adverse decision, and the statutory language qualifies it as being required to the extent commercially reasonable. Practically, that means having a defined process someone can trigger, not a human re-reviewing every automated screen.

Should I wait until 2027 to change anything?

The notice and retention pieces are cheap to do now and there's no reason to wait. The harder item is explainability, since fixing it may mean changing tools, and tool changes take longer than five months once you factor in evaluation and rollout. Inventory now, decide by fall, implement before year-end.

[![Paul Jones](/_next/image?url=https%3A%2F%2Fassets.basehub.com%2Fe0b5701f%2F6599306507912123f90f150a8bfaaf6c%2Fscreenshot-2026-01-28-at-10.53.16-am.png%3Fwidth%3D100%26height%3D100%26quality%3D100&w=128&q=75)

Paul Jones

Head of Growth at Classet

Paul comes from an operator background running an Alpine-owned company, and brings firsthand experience with the hiring challenges Classet was built to solve. He's driven by a belief that the right technology can make meaningful work more accessible.

](/blog/authors/paul-jones)

Follow Classet in Google

Add classet.ai as a preferred source and our hiring research is more likely to show up in your Top Stories and AI Overviews.

[Add as preferred source →](https://www.google.com/preferences/source?q=classet.ai)

## Explore More

### Use Cases

-   [RPO / BPO Recruiting](/use-cases/call-centers-bpo)
-   [Healthcare Recruiting](/use-cases/healthcare)
-   [Hospitality Recruiting](/use-cases/hospitality)

### Integrations

-   [Greenhouse](/integrations/greenhouse)
-   [Bullhorn](/integrations/bullhorn)
-   [Lever](/integrations/lever)