Which states have AI laws in effect today? This tracker summarizes key AI laws that may impact your business. Subscribe for updates.
| State/Terr | AI Scope | Relevant Law | Law Link | Effective Date | Key Requirements | Enforcements & Penalties |
|---|---|---|---|---|---|---|
| Colorado | Automated Decision-Making | Colorado AI Act As amended by SB26-189 | Co. Rev. Stat. § 6-1-1701 et seq. | 1/1/2027 | • Governs "covered automated decision-making technology" or "covered ADMT", which is defined to mean a technology that processes personal data and uses computation to generate output that is used to make, guide, or assist a decision, judgment or determination concerning an individual ("automated decision-making technology") that is used to materially influence a "consequential decision" (or a decision, determination, or action about a consumer that relates to the provision of or access to (or different terms relating to) an education enrollment or an education opportunity, employment or an employment opportunity that creates an employer-employee relationship, the lease or purchase of residential real estate, a financial or lending service, insurance (and its benefits), health-care services, or essential government services and public benefits). • Requires developers of covered ADMT to make available to each deployer information relating to the intended uses and known harmful / inappropriate uses of the covered ADMT, the data used to train the covered ADMT, any known limitations of the covered ADMT, and the appropriate use, monitoring, and meaningful human review of the covered ADMT--as well as notice of material updates. • Requires deployers to disclose to the consumer prior to the use of a covered ADMT to materially influence a consequential decision that such a tool is being used. • Requires deployers that use a covered ADMT to materially influence a consequential decision that results in an adverse outcome for a consumer to provide an adverse outcome notice that describes the consequential decision and the role the covered ADMT played in the consequential decision, provides instructions and a process for obtaining additional information about the covered ADMT and its inputs, and an explanation of the consumers' rights to access and correct personal data use by the covered ADMT and to request the deployer to reconsider the consequential decision using meaningful human review (to the extent commercially reasonable). • Clarifies that a developer or deployer may be held liable in an action alleging unlawful discrimination under state anti-discrimination laws arising from a consequential decision materially influenced by a covered ADMT. | Up to $20,000 per violation. |
| Colorado | AI in Political Advertising | Colorado Candidate Election Deepfake Disclosures Law | Co. Rev. Stat. 1-45-111.5 to 111.7 and 1-46-101 to 106 Reprinted from Westlaw with the permission of Thomson Reuters. | 7/1/2024 | • Prohibits the distribution of AI-generated deepfakes of election candidates. • Provides a safe harbor from liability where the person provides a clear and conspicuous disclaimer that the media has been edited and depicts speech or conduct that falsely appears to be authentic or truthful. | At least $100 per violation and 10% of the amount spent on the communication. |
| Colorado | Automated Decision-Making | Colorado Privacy Act | Col. Rev. Stat. § 6-1-1301 et seq. Reprinted from Westlaw with the permission of Thomson Reuters. | 7/1/2023 | • Provides consumers the right to opt-out of any form of automated processing of personal data to evaluate, analyze, or predict personal aspects concerning an identified or identifiable individual’s economic situation, health, personal preferences, interests, reliability, behavior, location, or movements in furtherance of solely-automated decisions that produce legal or similarly significant effects concerning the consumer (i.e., the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, healthcare services, or access to essential goods and services). • Requires a data protection assessment of each processing activity involving such automated processing of personal data in certain circumstances. Other obligations and restrictions may apply depending on the type of data processed. | Up to $20,000 per violation. |
| Colorado | AI in Insurance | Colorado Protecting Consumers from Unfair Discrimination in Insurance Practices | Co. Rev. Stat. 10-3-1104.9 Reprinted from Westlaw with the permission of Thomson Reuters. | 7/6/2021 | • Prohibits insurance providers from using algorithms or predictive models that unfairly discriminate based on race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression. • Requires the Colorado Commissioner of Insurance to adopt rules requiring insurers to demonstrate that their use of algorithms and predictive models do not result in unfair discrimination. | Up to $3,000 per violation, or $30,000 per knowing violation. |
| Colorado | User-Facing AI | Concerning Requirements for an Operator of a Conversational Artificial Intelligence Service | HB 1263 | 1/1/2027 | • Requires any person who develops and makes available an artificial intelligence system that primarily simulates human conversation and interaction through adaptive textual, visual, or aural communications (a "conversational AI service") to the public (an "operator") to: - Use commercially reasonable methods or generally accepted methods to estimate the age of account holders or users; - Clearly and conspicuously disclose that the conversational AI service is artificial intelligence (i) at the beginning of a user's first interaction with the service for each day of interaction, (ii) at least once every 3 hours in a continuous conversational interaction (or as a persistent disclosure), and (iii) be provided in response to user prompts regarding whether the conversational AI service is AI or human; - Implement a protocol for the conversational AI service to respond to user prompts regarding suicidal ideation or self-harm that includes but is not limited to making a referral to a suicide hotline, crisis text line, or other appropriate crisis services; and - Refrain from using any term, letter, or phrase in the advertising, interface, or output of a conversational AI service that represents it is, or is equivalent to, a licensed health-care professional, legal professional, mental health professional or qualified dietitian. • Requires operators to implement additional procedures for minor users, including (i) providing a clear and conspicuous disclosure that they are interacting with AI via a persistent disclaimer or at the beginning of each session and at least every three hours in a continuous conversation, (ii) not providing the user with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with the service, (iii) instituting technically feasible measures to prevent the conversational AI service from producing textual, visual or aural material of explicit sexual conduct, producing an intimate digital depiction, generating a statement that the minor should engage in explicit sexual conduct, or engaging in erotic or sexually explicit interactions with the minor, (iv) instituting reasonable measures to prevent the service from generating statements that simulate emotional dependence or isolation from real-world supports, (v) implementing a protocol prohibiting the service from engaging in explicit sexual conduct with a minor, and to stop the service from engaging in response to a user prompt regarding explicit sexual conduct with a minor, and (v) offering tools for managing privacy and account settings. • Requires annual reporting to the Attorney General's Office. • Expressly excludes, among other things, software applications, web interfaces, or computer programs that are primarily designed and marketed for use by a developer or researcher, to provide commerce-related or transactional assistance, or for commercial use by business entities for the purpose of business operations, productivity, information analysis, internal research, training, or technical assistance. | • Constitutes an unfair trade practice enforceable under the Colorado Consumer Protection Act. |
| Colorado | AI Healthcare | Concerning Restrictions on the Use of Artificial Intelligence Relating to Psychotherapy Services | HB 1195 | 8/12/2026 | • Prohibits any person from using any term, letter, or phrase in the advertising, interface, or outputs of an artificial system in a manner that indicates or implies that the AI system's output data is being provided by or endorsed by, or is the equivalent of a licensed pyschotherapy professional, or otherwise representing the AI system provides psychotherapy services or a user's data is confidential in a manner similar to therapist-client confidentiality. | • Constitutes an unfair trade practice enforceable under the Colorado Consumer Protection Act. |
| Colorado | AI Healthcare | Concerning Restrictions on the Use of Artificial Intelligence Relating to Psychotherapy Services | HB 1195 | 8/12/2026 | • Outlines permitted and prohibited uses of artificial intelligence in the provision of psychotherapy services. • Permits AI use by individuals lawfully permitted to provide psychotherapy services for the purposes of administrative support or supplementary support for pyschotherapy services, provided the licensed individual maintains responsibility for any artificially generated output and satisfies the requirements set forth below. • Prohibits lawful providers of psychotherapy services from using artificial intelligence systems to (i) record or transcribe a client's therapeutic session without consent, or (ii) interact with clients in any form of therapeutic communication without the direct oversight from the provider, or (iii) provide therapeutic recommendations or treatments without a provider's review and approval. • Requires the provider to provide to the client written information concerning these prohibitions. • Prohibits any person from using any term, letter, or phrase in the advertising, interface, or outputs of an artificial system in a manner that indicates or implies that the AI system's output data is being provided by or endorsed by, or is the equivalent of a licensed pyschotherapy professional, or otherwise representing the AI system provides psychotherapy services or a user's data is confidential in a manner similar to therapist-client confidentiality. | • Constitutes an unlawful practice by a licensed psychotherapy provider, which is subject to existing penalties including revocation of license. • Constitutes an unfair trade practice enforceable under the Colorado Consumer Protection Act. |
| Colorado | AI Healthcare | Concerning the Use of Artificial Intelligence in Health Care | HB 1139 | 1/1/2027 | • Requires carriers that use artificial intelligence systems for utilization reviews to ensure that their artificial intelligence systems (i) base their determination solely on permissible information, (ii) do not base their determinations solely on group data, (iii) are not used in any way that discriminates against individuals in violation of the law, (iv) are fairly and equitably applied, (v) produce and retain documentation, audit logs, and model-governance records, (vi) are periodically reviewed to maximize accuracy and reliability, (vii) do not use individual's health data beyond its intended or stated purpose, and (viii) their criteria and guidelines comply with applicable state or federal law concerning utilization review and coverage for health-care services. • Establishes that carriers that use artificial intelligence systems for utilization reviews provide written disclosures to the Department of Human Services or the Department of Health Care Policy and Financing that include how, why and when AI is used in their processes. • Prohibits a carrier's denial of coverage based in whole or in part on medical necessity from being issued solely on the output of an AI system without human review and approval of the denial by authorized personnel. • Prohibits the carrier's payment for AI-led psychotherapy services that violate the state's psychotherapy service AI rules. | Enforcement by the Colorado Division of Insurance and the state Commissioner of Insurance. |
| Colorado | AI CSAM | Preventing Unauthorized Disclosure of Intimate Digital Depictions Act | SB 288 | 8/6/2025 | • Expands child sexually exploitative material to include a realistic visual depiction, which has been created, altered, or produced by digitization or computer-generated means, that depicts an identifiable child, in whole or in part, engaged in, participating in, observing, or being used for explicit sexual conduct. | Plaintiffs may bring civil actions to obtain relief, and a court may order a temporary restraining order, injunctive relief, and order the defendants to cease disclosure. |
| Colorado | AI Intimate Images | Preventing Unauthorized Disclosure of Intimate Digital Depictions Act | SB 288 | 8/6/2025 | • Allows an individual depicted in an intimate digital depiction to sue the individual who disclosed or threatened to disclose the picture if they acted with knowledge or disregard for whether the depicted individual: did not consent to the disclosure; would experience serve emotional distress; and was identifiable. • Expands the scope of Colorado's intimate image harassment statute to include intimate digital depictions. | • For intimate digital depictions - the greater of actual damages or liquidated damages of $150,000, plus an amount equal to the monetary gain, exemplary damages, and the cost of the action; as well as equitable relief. • For intimate image harassment - existing criminal penalties apply. |
Which states have AI laws in effect today? This tracker summarizes key AI laws that may impact your business.
A guide to the online safety, privacy and harmful content state laws and global regulatory developments that may impact your business.