Colorado AI Act documentation requirements
Colorado's algorithmic discrimination statute places duties on both developers and deployers of high-risk AI, centred on reasonable care to protect consumers. Duties of care are established, in practice, by records.
Colorado enacted the first comprehensive United States state law addressing algorithmic discrimination in high-risk AI systems, imposing obligations on both developers and deployers. The statute's effective date has moved through amendment, and implementation details continue to develop, so current text should always be checked.
The architecture, however, is stable and worth understanding on its own terms, because several other states have drawn from it.
The core obligations
- Duty of reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination.
- Impact assessments for high-risk systems, reviewed periodically and after significant modification.
- Consumer notification when a high-risk system is used in a consequential decision, with disclosure duties on adverse outcomes.
- Developer disclosures to deployers about intended use, known limitations, and evaluation.
- Risk management programme aligned to a recognised framework.
How a duty of care is tested
Reasonable care is a standard applied after something goes wrong. The question at that point is not whether the organisation intended care, but whether it can show what it actually did, and when.
That converts nearly every obligation on the list into a records question: what assessments were performed, when, on which version of the system, and what was done about the findings?
Where documentation usually fails
- Impact assessments exist as documents with no binding to the system version they assessed.
- Notification is implemented in code with no record that it fired for a given consumer.
- Significant modifications are tracked in engineering tools that are not retained as compliance records.
Each gap is invisible until challenged, and each is closed the same way: attach a contemporaneous, independently verifiable record to the event when it happens.
Check it yourself
Every Rubric attestation resolves publicly, with no account and no API key, and every anchor resolves to a public ledger message you can read without our cooperation.
HCS topic 0.0.10416909 · ML-DSA-65 signatures
Multi-state reality
Institutions operating across states face overlapping regimes with different triggers and deadlines. Evidence that is independently verifiable travels across regimes without rework, because the underlying question every regulator asks is the same: show me what happened and why I should believe the record.
Related: Illinois SB 315 · Adverse action documentation · Regulatory overview