Colorado’s AI Sunshine Act 2026: Legal AI Compliance Reset
- Authority
- Colorado General Assembly
- Rule type
- statute
- Jurisdiction scope
- US state - Colorado
- Effective date
- Jan 1, 2027
- Source text
- Read primary rule text ↗
Narrower ADMT transparency regime; removes legal services from covered domain; requires pre-use notice, adverse outcome disclosure, and meaningful human review; voids certain ADMT indemnity provisions.
If you arrived here looking for “sunshine protection act 2026 status and updates,” the first correction matters: this is not an update on the federal daylight-saving-time bill commonly associated with that phrase. This article is about Colorado’s AI Sunshine Act delay and the later replacement of Colorado’s original AI Act with SB 26-189.
As of Q3 2026, the verified status is straightforward. Colorado delayed the original AI Act, then repealed and replaced it with SB 26-189, a narrower law scheduled to take effect on January 1, 2027.[1][2] This is a statutory-status and compliance-risk discussion, not legal advice. The practical point for law firms is also straightforward: Colorado no longer looks like the broad legal-AI compliance project it appeared to be when “legal services” sat inside the original covered-domain structure.
That does not mean Colorado has become irrelevant. It means the work moves. For ordinary AI use in legal-practice workflows, the direct Colorado-specific burden has been cut back sharply. For internal firm operations, multistate vendor review, and contractual allocation of ADMT-related discrimination risk, there is still enough left to track.

The statutory reset in one comparison
The before-and-after comparison is the controlling document for a law-firm briefing. SB 24-205 treated legal services as a covered domain for consequential decisions; SB 26-189 deletes that category and removes the original high-risk AI compliance machinery.[1][2] That single deletion changes which firm workflows deserve Colorado-specific escalation.
| Issue | SB 24-205, original Colorado AI Act | SB 26-189, replacement framework | Operational consequence for law firms |
|---|---|---|---|
| Effective status | Originally set to take effect before being delayed by the Colorado AI Sunshine Act. | Takes effect January 1, 2027.[1][2] | No enforcement practice exists yet under the replacement law; planning is anticipatory. |
| Core regulatory model | Built around “high-risk AI systems” and algorithmic-discrimination obligations. | Replaces that structure with a narrower ADMT transparency regime.[3] | The firm’s AI register should not treat every legal-practice tool as if it still triggers the old programmatic obligations. |
| Legal services | Included “legal services” as a covered domain for consequential decisions. | Deletes “legal services” from the covered-domain structure.[1][2] | Most AI use in legal-service delivery, including research, drafting support, document review, and legal decision support, falls out of the direct Colorado covered-domain frame. |
| Risk-management program | Required risk-management programs for covered high-risk AI systems. | Eliminates mandatory risk-management programs tied to the prior high-risk AI category.[3][4] | A Colorado-specific risk-management program is no longer the default answer for legal-practice AI tools. |
| Impact assessments | Required annual impact assessments for covered high-risk AI systems. | Eliminates annual impact-assessment requirements from the prior framework.[3][4] | Annual AI impact assessments may still be useful for governance, clients, or other jurisdictions, but they are no longer imposed by Colorado in the same broad legal-services way. |
| Attorney General reporting | Included Attorney General reporting requirements in the original compliance framework. | Eliminates those reporting requirements.[3] | The reporting workstream that firms may have expected under the original act should be removed from Colorado-specific legal-practice planning. |
| Consumer-facing duties | Part of the broader high-risk AI compliance structure. | Requires pre-use notice to consumers, a 30-day post-adverse-outcome disclosure, and meaningful human review to the extent commercially reasonable.[1][2] | The remaining obligations are more likely to matter where a firm’s tool materially influences a covered decision about a consumer, not merely because a lawyer used AI in legal work. |
| Enforcement | Original enforcement structure was tied to the broader framework. | Sole enforcement by the Colorado Attorney General, with no private right of action and a 60-day cure period that sunsets in 2030.[2][3] | Risk is regulatory rather than private-litigation driven under the statute, but cure-period planning still belongs in the issue log. |
| Vendor contracts | No equivalent provision serving as a focal point in the same way. | Voids contractual indemnification provisions that shield a party from its own ADMT-related discrimination liability.[1][4] | Procurement review should add a Colorado ADMT indemnity screen, even where the underlying legal-practice workflow is no longer a covered-domain project. |

What this means for law-firm AI workflows
The useful separation is not “AI tool” versus “non-AI tool.” It is legal-practice use versus firm operations that may independently fall inside an ADMT framework. Colorado’s reset makes that distinction much more important.
Client intake
A client-intake assistant that collects facts, routes a potential matter, summarizes conflicts information, or helps a lawyer decide whether to schedule a consultation no longer sits in Colorado’s framework merely because the work concerns legal services. Under SB 24-205, the inclusion of legal services made that analysis more uncomfortable. Under SB 26-189, the legal-services hook is gone.[1][2]
That is not permission to ignore intake design. It is a narrower statutory conclusion. A firm still has to ask what the tool actually does. If an intake system is being used in a non-legal operational context, or if the workflow materially influences a covered decision outside the deleted legal-services category, the Colorado analysis may not end with “we are a law firm.” The statute has narrowed; the factual workflow still matters.
Document review and drafting support
For e-discovery review, privilege triage, contract summarization, deposition-outline generation, research memos, and first-draft assistance, the Colorado-specific change is substantial. These are legal-service delivery functions. With “legal services” removed from the covered-domain list and the high-risk AI category eliminated, the original risk-management program, annual impact assessment, and Attorney General reporting structure no longer follows those tools simply because they support legal work.[1][3]
A firm may still keep these tools in an AI inventory for knowledge management, confidentiality review, client requirements, insurance questionnaires, or professional-responsibility analysis. But that is not the same as saying Colorado SB 26-189 imposes the old high-risk AI compliance package on the tool. A management committee should not be asked to fund a Colorado legal-services compliance build that the replacement statute no longer supports.
Decision support in legal matters
Litigation-risk scoring, settlement modeling, venue analysis, damages estimation, and similar decision-support tools deserve careful internal governance because they can affect legal strategy. But SB 26-189 changes the Colorado statutory classification problem. The original act’s legal-services category made it plausible to treat AI-assisted legal decision support as a covered consequential-decision issue. The replacement law removes that category.[1][2]
The practical result is not that the tool is low risk. It is that the risk no longer maps cleanly to the original Colorado AI Act obligations. For law-firm risk staff, that matters because it changes the review queue. Legal decision-support tools may belong in the ethics, confidentiality, supervision, privilege, and client-disclosure lane. They should not automatically be assigned to a Colorado high-risk AI assessment lane that SB 26-189 has removed.
Internal hiring and other non-legal firm operations
Hiring is the edge case that should stay on the list. Law firms are legal-service providers, but they are also employers. If a firm uses an automated decision-making technology in a hiring workflow, the deletion of “legal services” does not by itself answer whether Colorado’s remaining ADMT transparency duties apply. The relevant question is whether the tool materially influences a covered decision under the replacement framework.[2][4]
That same separation applies to other internal operations. A tool used to summarize briefs for a litigation team is different from a tool used to rank job candidates, screen applicants, or support another covered non-legal decision. The first may remain important for firm governance without triggering Colorado’s narrowed ADMT duties. The second may require notice, post-adverse-outcome disclosure, and commercially reasonable human review if the statutory trigger is met.[1][2]
The vendor-contract issue that should survive the reset
The indemnification provision is the part of SB 26-189 most likely to show up in procurement redlines. The replacement law voids contractual indemnification provisions that shield a party from its own ADMT-related discrimination liability.[1][4] That is narrower than a general AI indemnity rule, and it is not a settled litigation doctrine. No court has interpreted its scope or enforceability under the replacement framework.
Still, it belongs in vendor review because many AI contracts already contain broad indemnity, limitation-of-liability, responsibility-allocation, and compliance-with-law clauses. A clause that looks routine in a generic software agreement may need a second look if the product is used as an ADMT in a Colorado-covered workflow.
- Ask whether the vendor product can materially influence a covered decision, rather than asking only whether the product is marketed as “AI.”
- Separate legal-practice deployments from internal firm operations such as hiring, where the remaining Colorado ADMT framework may still matter.
- Review indemnity language that purports to shift responsibility for the customer’s own discriminatory use of an ADMT.
- Check whether the vendor will provide information needed for pre-use notice, adverse-outcome disclosure, and commercially reasonable human review if the tool is deployed in a covered workflow.
- Avoid treating the Colorado clause as a general vendor guarantee against all AI risk; the provision is specific to ADMT-related discrimination liability.
For legal-tech buyers, the drafting problem is not only whether the vendor will indemnify the firm. It is whether the allocation of responsibility assumes that one party can be insulated from its own ADMT-related discrimination liability. SB 26-189 makes that assumption unsafe enough to flag, even before enforcement guidance exists.
Colorado and California now share a date, not a model
The multistate tracking issue is easy to miss because both Colorado’s SB 26-189 and California’s ADMT regulations point to January 1, 2027. The shared date does not mean the same workflow analysis applies. California’s ADMT regulations under the CCPA provide broader opt-out rights and apply to systems that “replace or substantially replace” human decision-making, while Colorado’s trigger is framed around systems that materially influence covered decisions.[2][4]
| Issue | Colorado SB 26-189 | California ADMT regulations | Why it matters for firms |
|---|---|---|---|
| Effective date | January 1, 2027.[1][2] | January 1, 2027.[2][4] | The same implementation date can create one procurement calendar, but not one legal analysis. |
| Trigger formulation | ADMT that materially influences covered decisions.[2][4] | Systems that replace or substantially replace human decision-making.[2][4] | Colorado may capture influence; California focuses on replacement or substantial replacement. |
| Consumer rights emphasis | Notice, 30-day post-adverse-outcome disclosure, and meaningful human review to the extent commercially reasonable.[1][2] | Broader opt-out rights under the CCPA ADMT regulations.[2][4] | Vendor questionnaires should ask jurisdiction-specific questions rather than using a single “AI compliance” field. |
| Law-firm consequence | Legal services removed as a covered domain.[1][2] | Separate California analysis required for covered uses. | A tool may be outside Colorado’s legal-services concern and still require review under another state’s privacy or ADMT framework. |

Why the repeal-and-replace happened
The political history explains the speed of the reset, but it should not obscure the operative change. Colorado’s AI Sunshine Act, SB 25B-004, was signed on August 28, 2025, and pushed the original AI Act’s effective date from January 1, 2026, to June 1, 2026.[5] The bill had been pitched as a consumer-protection expansion but was reduced through the legislative process and industry lobbying to a five-month delay.[6]
The pressure did not stop there. In December 2025, Executive Order 14365 specifically called out the Colorado AI Act and directed the Department of Justice to establish an AI Litigation Task Force to challenge state AI laws.[1][4] In April 2026, the xAI lawsuit and DOJ intervention created the first case in which the federal government intervened in a challenge to a state-level AI law.[1]
That sequence matters, but it does not answer the law-firm implementation question by itself. The repeal mooted the immediate fight over the original act, leaving the legal significance of the DOJ intervention unresolved. What remains for current planning is the replacement statute: narrower duties, no legal-services covered domain, Attorney General enforcement only, and no enforcement record yet under the January 1, 2027 framework.[1][2][3]
What to tell the procurement or management committee now
The clean answer is that Colorado’s replacement law should narrow, not expand, the firm’s immediate Colorado-specific legal-AI workstream. A firm using AI for legal research, drafting assistance, document review, matter analysis, or lawyer-facing decision support should not be told that those tools still carry the original Colorado high-risk AI package merely because they support legal services. That category was removed.
The less clean answer is that procurement cannot close the file. Internal hiring and other non-legal operational uses may still need Colorado ADMT analysis if the tool materially influences a covered decision. Vendor contracts now need attention to a novel, untested indemnification rule. California’s January 1, 2027 ADMT timeline creates a separate state-law track with different triggers and broader opt-out rights.
As of Q3 2026, the Colorado Attorney General has not supplied the kind of enforcement practice that would justify a detailed operational checklist. The sounder position is to update the AI inventory taxonomy, separate legal-service tools from firm operations, add the indemnity issue to vendor review, and keep Colorado in the regulation-and-ethics lane rather than the emergency-compliance lane.
Colorado no longer looks like the broad legal-AI compliance shock it once did. It does, however, show where state AI regulation is consolidating: transparency, recourse, enforcement discretion, and contract-risk terms that firms will need to track jurisdiction by jurisdiction.
References
- Colorado Repeals and Replaces Its AI Act — Skadden
- Colorado Replaces Its AI Act with a Narrower Transparency-Focused Law — Cozen O'Connor
- Colorado enacts revised AI law — Norton Rose Fulbright
- Colorado Replaces Landmark AI Act: An Overview of the New SB 26-189 Framework — Finnegan
- Colorado Special Session Update: AI Law Delayed to June 2026 — Hudson Cook
- In Delaying Its AI Law, Colorado Shows Tech Lobby's Power In State Politics — TechPolicy.Press
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →