Colorado’s attorney general Office Department of Law has filed proposed rules covering automated decision-making technology, with employers facing significant new compliance obligations starting January 1, 2027.
The proposed “Automated Decision-Making Technology and Conversational Artificial Intelligence Service rules” were filed with the Colorado secretary of state on August 11, 2026.
The draft rules seek to implement two new Colorado laws signed by Governor Jared Polis in May 2026, both scheduled to take effect on January 1, 2027.
Those laws are the Automated Decision-Making Technology in Consequential Decisions Act, Senate Bill 26-189, and the Chatbot Safety Act, House Bill 26-1263.
SB 26-189 mandates that deployers, including employers, disclose the use of automated decision-making technology before making any consequential decision such as hiring or termination affecting employees or job applicants.
When an automated decision results in an adverse outcome, affected employees can request that their personal data be corrected and that the decision undergo meaningful human review and reconsideration.
Under Rule 6.4, employers must describe the specific purpose for which they used covered automated technology, the role it played in reaching a consequential decision, and the role of any human reviewers involved.
Employers must also describe the principal reasons for any adverse outcome with specificity, avoiding language that is overly broad or vague, according to the proposed rules.
Rule 6.6 would require employers to identify each source of personal data by name, including specific data brokers, databases, social media companies, schools, and employers used during the decision-making process.
If an employer obtained personal data through a third-party aggregator, the disclosure would need to trace the chain back to the original source and identify every intermediary along the way.
Rule 7.2 specifies that adverse outcome disclosures must include a clearly labeled link leading directly to a request mechanism, as well as a mailing address or toll-free number for affected individuals.
Employers would need to offer two or more designated methods for submitting requests, ensuring those channels are regularly monitored by someone with the knowledge and ability to process them.
Rule 7.7 would require employers to confirm receipt of a human review request within ten days and complete that review within forty-five days of receiving the request.
The proposed rules clarify that meaningful human review must be conducted by an independent reviewer who has authority to approve, modify, or override the original automated decision.
That reviewer should, whenever feasible, not be the individual who made the original decision or a subordinate of that decisionmaker, according to the draft rules.
The proposed rules would create a rebuttable presumption of commercial reasonableness when an adverse outcome results in a severe and irreversible denial of a basic human need, which could include employment terminations.
Employers would bear the burden of rebutting that presumption by demonstrating technical or financial impossibility, or that a review could not realistically change the outcome of the decision.
The proposed rules contemplate two types of meaningful human review, covering both technical failures in the automated system and broader concerns about whether the tool itself was appropriate for the decision at hand.
A decision to override the original decision and reverse the adverse outcome would be sufficient to indicate that human review was meaningful, according to the proposed framework.
Employers currently using automated decision-making tools may wish to begin operationalising compliance requirements ahead of the January 1, 2027 effective date, including identifying and training qualified independent reviewers.

