The Colorado AI Act: Developers, Deployers and Algorithmic Discrimination


The Colorado AI Act, which took effect on 1 July 2024, introduces specific obligations for developers and deployers of AI systems. These roles are central to the Act’s framework, particularly regarding algorithmic discrimination. The Act defines a developer as someone who creates or designs an AI system, while a deployer is responsible for implementing or using such a system. Both roles carry distinct responsibilities under the law, especially when it comes to ensuring fair and non-discriminatory outcomes.
The Act places a strong emphasis on preventing algorithmic discrimination, which is defined as any adverse impact on protected classes such as race, gender, or age. Companies must take steps to identify and mitigate such impacts. For example, a developer of a credit scoring algorithm must ensure that the system does not disproportionately disadvantage applicants from certain demographic groups. Similarly, a deployer of an AI-based hiring tool must monitor its outcomes to avoid unintentional bias against candidates from protected categories.
The Act requires developers to conduct bias impact assessments before deploying AI systems. These assessments must evaluate whether the system could lead to discriminatory outcomes. For instance, a developer working on an AI tool for college admissions must test the tool against historical data to identify any disparities in outcomes across different demographic groups. The results of these assessments must be documented and reviewed regularly. Deployers must also maintain records of these assessments and take corrective actions if bias is identified.
The Act also introduces transparency obligations for developers and deployers. These include providing information about how AI systems make decisions, particularly when such decisions affect individuals. For example, a deployer using an AI system to evaluate job applications must be able to explain how the system arrived at its recommendations. This requirement is similar to the EU AI Act’s Article 50 transparency duties, which apply from 2 August 2026. Companies must ensure that their AI systems are interpretable and that explanations are provided where required.
The Act further compels developers and deployers to implement appropriate governance frameworks. These frameworks must include processes for monitoring AI systems post-deployment. For example, a developer of an AI-based clinical decision support tool must monitor its usage and outcomes to ensure it does not introduce or amplify bias. The framework must also include procedures for addressing complaints or concerns raised by users or affected individuals.
The Colorado AI Act aligns with broader efforts to regulate AI systems at the state level. It reflects a growing awareness of the potential for AI to perpetuate or amplify existing inequalities. The Act’s approach is practical and outcome-focused, requiring developers and deployers to take concrete steps to prevent discrimination. Companies must ensure that their AI systems are not only effective but also fair and accountable.
The Act also highlights the importance of AI literacy, a duty that applies under the EU AI Act since 2 February 2025. In Colorado, this translates into training for staff who work with AI systems. For example, a company deploying an AI-based customer service chatbot must ensure that its support staff understand how the system functions and how to identify potential issues. This knowledge helps maintain oversight and accountability.
The Act’s provisions apply to any AI system that is developed or deployed in Colorado, regardless of where the company is headquartered. This makes it particularly relevant for multi-state firms that operate across the US. Companies must ensure that their AI governance practices meet the Act’s requirements, even if they are not directly regulated by Colorado law. The Act’s focus on algorithmic discrimination makes it a key component of any AI compliance strategy.
The Act’s enforcement mechanisms are still evolving, but it sets a clear expectation for developers and deployers. Companies must be prepared to demonstrate that their AI systems are designed and used in a way that avoids discrimination. This involves not only technical measures but also organisational processes and cultural commitments to fairness. The Act underscores the importance of embedding these principles into AI development and deployment workflows.
The Act’s framework is aligned with international developments such as the EU AI Act, which introduces similar obligations for developers and deployers. Companies operating in both US and EU jurisdictions must ensure that their AI governance strategies meet the requirements of both frameworks. The Act’s focus on bias impact assessments and transparency mirrors these global efforts. Companies must stay informed of these developments to maintain compliance.
The Act also highlights the role of certification in AI governance. The ISO/IEC 42001:2023 standard provides a framework for AI management systems, and certification through bodies such as BSI is becoming increasingly important. Companies that seek to demonstrate compliance with the Colorado AI Act may benefit from aligning their practices with this standard. The Act’s emphasis on governance makes such certification a practical step towards meeting regulatory expectations.
The Act’s provisions apply to AI systems that are used in employment, housing, credit, and other areas where discrimination is a concern. Companies must ensure that these systems are reviewed and tested to prevent adverse outcomes. The Act’s approach is practical and focused on outcomes, requiring developers and deployers to take responsibility for the impact of their AI systems. This makes it a significant development in US AI regulation.
