Skip to content
HRaizon Subscribe

How Colorado’s New AI Hiring Rules Apply in 2027

Colorado’s revised AI law covers some hiring tools from January 1, 2027. Check which systems qualify and when applicants receive review rights.

Share X in f
Priya Ellison

Yes. Colorado still regulates AI-assisted hiring when technology processes personal data and produces a score, ranking, recommendation, classification, prediction, or other inference that materially influences an employment decision. Governor Jared Polis signed SB26-189 on May 14, 2026, and its principal developer and deployer requirements begin January 1, 2027.

The replacement is narrower than the 2024 Colorado AI Act. It centers on notice, decision-level disclosure, access to relevant personal data, correction of qualifying inaccurate data, meaningful human review, reconsideration, developer documentation, and recordkeeping. It does not retain the original deployer impact assessments, risk-management programs, algorithmic-discrimination duty of care, or mandatory annual reviews.

Choose the tool’s function, employment decision, influence, and outcome to see the likely coverage and attached duties.

Colorado AI Hiring Coverage Checker

This screens the core statutory conditions. It is not a legal determination, and geographic or final-rule questions may change the result.

Likely covered ADMT useDefault result
  • Provide clear and conspicuous notice at the covered interaction.
  • Within 30 days after the adverse outcome, provide a plain-language description of the decision and the technology’s role.
  • Support access to relevant personal data, correction of qualifying inaccurate data, and commercially reasonable human review and reconsideration.
  • Keep records reasonably necessary to demonstrate compliance for at least three years.

How Common Hiring Functions Map to the Test

FunctionDecision ConnectionLikely DirectionReason
Résumé score sets an interview cutoffEligibility and advancementPotentially coveredThe score acts as a gate and materially influences selection.
Applicant ranking controls review orderHiring and advancementPotentially coveredLow-ranked applicants may never receive meaningful review.
Interview-response score recommends rejectionSelectionPotentially coveredAn evaluative output guides the adverse decision.
Compensation recommendationPayPotentially coveredCompensation is a consequential employment context.
Promotion or performance scorePromotion or another employment actionPotentially coveredCoverage depends on material influence and the actual workflow.
Interview calendar schedulerAdministrative scheduling onlyLikely outsideIt does not generate an evaluative inference or determine selection.
Neutral résumé summary reviewed independentlyInformation presentationLikely outsideNeutral presentation without a materially influential evaluation is assistive.
Routing or file storageWorkflow administrationLikely outsideStorage and transmission alone do not produce a decision-related inference.

Rights and Duties by Trigger

TriggerEmployer or Developer DutyApplicant or Employee Position
Covered interactionClear and conspicuous notice about covered ADMT useReceives notice concerning the technology’s role
Covered adverse outcomePlain-language decision and technology description within 30 daysMay receive the decision-level disclosure
Relevant inaccurate personal dataSupport access and correction of qualifying dataMay correct facts, but cannot dictate a preferred score or opinion
Request after a qualifying adverse outcomeMeaningful human review and reconsideration to the extent commercially reasonableReview must be capable of changing the result, but reversal is not guaranteed
Compliance periodRetain reasonably necessary records for at least three yearsNo unrestricted right to every internal or proprietary record
Developer supplies covered technologyProvide intended-use, training-data-category, limitation, oversight, and update documentationEmployer remains responsible for explaining its own use of the output

Which Calendar Applies

2024SB24-205 creates the original broad, risk-based Colorado AI framework.
May 14, 2026Governor Polis signs SB26-189, replacing the original framework before it becomes operative.
June 30, 2026The prior planned effective date is superseded; it is not the implementation date for SB26-189.
January 1, 2027The replacement law’s principal developer and deployer requirements begin.

Source: Colorado SB26-189 and the article’s synthesis of the enacted requirements. “Potentially covered” reflects a functional screen, not a final legal conclusion; final rules and geographic facts may alter coverage.

The Colorado General Assembly’s SB26-189 page provides the enacted measure, official status, and legislative summary. The statute was enacted but was not yet operative while implementing rules remained unfinished in August 2026.

This is general information, not legal or employment advice. Coverage depends on the employer, worker, location, technology, workflow, and final attorney-general rules.

Colorado Replaced the 2024 Act Without Excluding Hiring

Colorado enacted SB24-205 in 2024 as a broad, risk-based law for certain high-risk AI systems. Its implementation was postponed, and June 30, 2026 eventually became the planned effective date.

SB26-189 was signed before that framework took effect. It repealed and reenacted the relevant provisions, replacing the original model with the narrower Automated Decision-Making Technology Act. Its principal requirements begin January 1, 2027.

References to February 1 or June 30, 2026 describe earlier or superseded versions of Colorado’s framework. Neither is the implementation date for SB26-189.

The rewrite changed the object of compliance. The original law emphasized system-level governance: identify a high-risk system, maintain a risk-management program, conduct impact assessments, and exercise a statutory duty of care concerning algorithmic discrimination.

The replacement focuses on particular decisions and the recourse available to affected people. According to analysis of the enacted amendment, it removed the original duty of care, deployer risk-management programs, impact assessments, and certain reporting obligations.

Employers should therefore retire Colorado checklists that present the following as SB26-189 requirements:

  • a February 1 or June 30, 2026 effective date;
  • the original algorithmic-discrimination duty of care;
  • deployer risk-management programs or impact assessments;
  • mandatory annual AI-tool reviews;
  • mandatory formal bias audits or validation studies; or
  • reporting duties carried over from the original framework.

Tool inventories, vendor reviews, and workflow maps created for the 2024 law can remain useful. Policies, contracts, notices, and training materials should be checked against the replacement statute rather than merely relabeled.

A Hiring Tool Must Satisfy Three Coverage Conditions

The Tool Must Affect a Consequential Employment Decision

Recruiting software is not covered merely because it appears in a hiring process. Its output must relate to a consequential decision involving access to, eligibility for, selection for, or compensation related to employment.

Examples include deciding who receives recruiter review, advances to an interview, is rejected, receives an offer, or receives particular compensation. Promotion, performance evaluation, discipline, termination, and compensation may also qualify when the other statutory conditions are met, as explained in Venable’s employer-focused analysis.

Interview scheduling, file transfer, and routine administrative routing ordinarily do not make eligibility or selection decisions by themselves.

The Tool Must Generate a Decision-Related Output

Covered technology processes personal data and generates a score, ranking, recommendation, classification, prediction, or other information or inference used to make, guide, or assist the decision.

An applicant tracking system is not covered simply because it is an ATS. One installation may store applications and coordinate workflows. Another may score candidates, control review order, recommend advancement, or apply a rejection threshold.

Product labels such as “AI platform,” “copilot,” “automation,” and “decision support” do not resolve coverage. Each feature must be evaluated according to what it does in the employer’s actual workflow. For a closer look at those functional differences, see AI May Read Your Resume, but It Rarely Auto-Rejects You.

The Output Must Materially Influence the Result

Material influence is the central limiting condition. The output must play more than a trivial role in the consequential decision, although the precise regulatory test remained unsettled during 2026 rulemaking.

A recruiter’s final click does not necessarily remove a system from the law. A résumé score may materially influence selection if applicants below a cutoff are never reviewed. Ranking may have the same effect if recruiters read only the highest-ranked applications before filling the position.

Useful workflow questions include:

  • Would the same applicants have been reviewed without the output?
  • Does a score determine interview eligibility?
  • Does ranking control review order?
  • Are low-ranked applicants actually reviewed?
  • Do reviewers ordinarily follow the recommendation?
  • Can a reviewer independently depart from it?
  • Does the tool hide or alter information shown to the reviewer?
  • Is the output an independent input or effectively a gate?

A system that only schedules interviews, transfers files, or reformats information without generating a materially influential evaluative inference is less likely to qualify.

Function, Not the Product Label, Separates Covered Tools

Potentially Covered When Materially Influential Likely Outside the Act When Purely Assistive
Résumé scoring used to determine interview eligibility Interview scheduling
Applicant ranking that controls review or advancement Administrative routing
Screening recommendations followed in rejection decisions Workflow management
Predictive candidate scores used in selection Drafting communications
Structured-interview scores affecting who is hired Translation without evaluation
Classifications that determine a candidate’s hiring path Neutral summarization for independent review
Automated advancement or rejection thresholds Organization or presentation of information
Recommendations reviewers ordinarily follow Storage and retrieval without an evaluative inference

These are functional examples, not categorical exemptions. A product can contain both administrative and evaluative features.

“Summarization” is not automatically excluded. A tool that neutrally condenses work history for independent review may be assistive. A purported summary that labels someone “weak,” predicts performance, hides applicants, or generates a fit score is producing an evaluative inference.

The same distinction applies to interviews. Finding a mutually available time and sending an invitation is administrative. Scoring interview responses and recommending rejection may materially influence selection.

Reported exclusions include certain routine administrative processes, identity verification, cybersecurity, and sanctions-compliance activities. An excluded identity-verification function does not necessarily protect a separate suitability score generated by the same product.

Employers should record what data enters each feature, what output it creates, who sees it, when it appears, whether it changes eligibility or review order, and whether the reviewer can override it. Those are recommended mapping fields, not individually mandated statutory fields.

Colorado Connections Can Extend Beyond an In-State Office

The clearest coverage scenario is an employer doing business in Colorado evaluating a Colorado-resident applicant or employee.

Remote roles and out-of-state participants require a more specific analysis. One employment-law interpretation reports that the statute may also reach a person whose access to, eligibility for, or opportunity in Colorado is evaluated by a person doing business in Colorado. That should not be converted into a rule that every remote opening or out-of-state employer is covered. The Law and the Workplace analysis treats broader geographic scenarios as fact-specific.

Secondary analysis also reports an exclusion for independent-contractor decisions. Organizations should confirm that exclusion against the enacted text and final rules before applying it to a particular classification.

Covered Employers Have Duties Across the Decision Lifecycle

Notice Applies at the Covered Interaction

A covered deployer must provide clear and conspicuous notice concerning its use of covered automated decision-making technology at the point of interaction.

The final wording remained subject to rulemaking, but an operational notice should identify the relevant technology or category, the consequential decision, the technology’s role, and a route for questions and rights requests. A generic privacy policy or vague statement that an employer “may use technology” may not describe the relevant hiring interaction adequately.

An Adverse Outcome Triggers a 30-Day Disclosure

When covered technology materially influences a consequential decision that produces an adverse outcome, the deployer must provide a plain-language description of the decision and the technology’s role within 30 days.

The process must also support applicable rights involving access to relevant personal data, correction of qualifying inaccurate data, human review, and reconsideration. The employer needs candidate-level inputs and outputs, vendor documentation, and decision records that can be reconciled with the explanation it provides.

Compliance Records Generally Must Be Kept for Three Years

Developers and deployers generally must retain records reasonably necessary to demonstrate compliance for at least three years. Employer records may include the notice version, tool and model version, relevant input data, generated output, decision log, adverse-outcome explanation, correction requests, and review result.

Those examples are not a claim that every field is mandatory in every case. Retention also needs to account for privacy duties, litigation holds, employment-record rules, and any law requiring a longer period.

Developers and Employers Have Different Roles

A developer creates or supplies the technology. A deployer uses it in a consequential decision. An employer will commonly be the deployer, although staffing agencies and other intermediaries can complicate the allocation.

Developers must provide documentation about intended uses, training-data categories, known limitations, appropriate use, human-review instructions, and material updates or modifications. Deployers use that information to operate their own notices, decisions, disclosures, review procedures, and records.

An employer should obtain definitions for every score and recommendation, candidate-level inputs and outputs, correction support, change logs, export functions, and enough information to produce a plain-language explanation. Copying a vendor’s technical documentation into an applicant notice does not explain how the employer actually used the output.

Applicants Can Correct Facts and Request Human Reconsideration

The revised law gives affected people limited rights connected to covered adverse consequential decisions. It does not provide a general right to prohibit all AI use in hiring.

Access Covers Relevant Personal Data

An affected applicant or employee may request access to relevant personal data used by the covered technology. This does not necessarily provide unrestricted access to every internal record, trade secret, or proprietary component.

Correction Applies to Inaccurate Data, Not Preferred Scores

A person may request correction of factually incorrect or materially inaccurate personal data used in the decision. The right does not generally allow the person to rewrite an opinion, prediction, score, model-generated judgment, or protected evaluation.

If a system used an incorrect employment end date and concluded that an applicant lacked the required experience, the applicant could seek correction of that date and pursue the applicable follow-up process.

An applicant cannot necessarily demand that a suitability score of 62 be changed to 90 simply because the applicant disputes the evaluation. The applicant may challenge incorrect facts feeding the score and request qualifying human review, but factual correction is not a right to dictate the evaluative result.

Human Review Must Permit a Real Change

After a qualifying adverse outcome, an individual may request meaningful human review and reconsideration to the extent commercially reasonable.

A meaningful reviewer should understand the decision and tool, have access to the relevant information, consider corrected data, and possess authority to approve, modify, or override the result. Merely confirming that the system generated a low score does not necessarily reconsider the decision.

Review does not guarantee reversal. The scope of “commercially reasonable” review remained unresolved in important respects during 2026 rulemaking.

The Rewrite Does Not Require Bias Audits

SB26-189 does not require the original deployer impact assessments, risk-management programs, formal bias audits, annual AI-tool reviews, or validation studies.

Employers may still test a tool voluntarily for discrimination, validity, accuracy, or hiring quality. Existing federal and Colorado discrimination laws, including Title VII and the Colorado Anti-Discrimination Act, continue to apply independently.

A tool can fall outside SB26-189 and still create discrimination risk. Conversely, giving notice, retaining records, or conducting human review does not establish that a tool is nondiscriminatory, accurate, or job-related.

The Colorado attorney general enforces the revised Act through the Colorado Consumer Protection Act. SB26-189 creates no new private right of action. Before January 1, 2030, the attorney general generally must provide a 60-day opportunity to cure when an alleged violation is considered curable. Employers should not treat that process as a guaranteed safe harbor.

Final Rules Will Define Important Coverage Boundaries

The Colorado Attorney General released proposed implementing rules on August 11, 2026. They were not final as of August 26, 2026.

The enacted statute establishes the baseline: covered technology must materially influence a consequential decision, and covered uses carry documentation, notice, adverse-outcome, individual-rights, and recordkeeping duties.

The proposals would add detail about material influence, notices, post-outcome disclosures, human review, and compliance records. Competing approaches to material influence could produce different results for applicant-tracking screeners, résumé-ranking systems, and structured-interview scoring tools.

Other unresolved issues included the required content and timing of notices, what qualifies as commercially reasonable review, how much independent recruiter analysis is sufficient, treatment of remote roles, mixed administrative and evaluative features, and allocation among employers, staffing agencies, and vendors.

Before January 1, 2027, employers can map each score or recommendation to the decision it affects, separate administrative from evaluative functions, obtain developer documentation, prepare adaptable notices, establish correction intake, designate reviewers with authority to change outcomes, and test whether the 30-day response records can be retrieved.

The Colorado Attorney General’s ADMT rulemaking page confirms the January 1, 2027 effective date and provides the rulemaking record. Final rules should be compared with draft notices, contracts, procedures, retention settings, and reviewer training before those materials are put into use.