Salta al contenuto principale

Colorado Rewrote Its AI Hiring Law: What Employers Must Do Before January 1, 2027

8 minuti di letturaMike ThriftMike Thrift
Colorado Rewrote Its AI Hiring Law: What Employers Must Do Before January 1, 2027

Colorado passed the country's first comprehensive AI employment law in 2024. It was set to take effect June 30, 2026. Then, three weeks before it was supposed to kick in, the legislature killed it and replaced it with something almost entirely different.

If you run a small business that uses any kind of software to screen resumes, rank candidates, schedule interviews, or flag applicants for follow-up, that whiplash matters to you — even if you've never heard of the original law and even if your company isn't based in Colorado. Here's what actually changed, who's covered, and what you need to have in place before the new rules land on January 1, 2027.

Why Colorado tore up its own AI law

The original Colorado AI Act (SB 24-205) asked employers to prove their AI hiring tools were fair before they used them: risk management programs, pre-deployment impact assessments, ongoing bias audits, and documentation showing the system as a whole didn't produce discriminatory outcomes. It was modeled on the EU's approach to "high-risk" AI systems — regulate the technology first, the outcome second.

Business groups, tech companies, and even some consumer advocates pushed back hard. The complaint wasn't that AI hiring tools shouldn't be regulated — it was that proving a whole system is unbiased before you're allowed to use it is an expensive, ambiguous compliance exercise that mostly law firms and audit vendors know how to execute. A five-person staffing agency using an off-the-shelf applicant tracking tool had no realistic path to "prove" the system's fairness the way the statute described.

So in May 2026, Governor Jared Polis signed SB 26-189, which repeals the original law entirely and replaces it with a narrower framework. The new approach doesn't ask you to audit the algorithm before you use it. It asks you to be transparent and give people recourse after a decision affects them. That's a real shift in what compliance actually looks like day to day — and it's worth understanding both what got easier and what didn't.

What "automated decision-making technology" actually covers

The new law drops the old "high-risk AI system" language in favor of regulating automated decision-making technology (ADMT) used to make consequential decisions. For employers, a consequential decision means anything that materially affects someone's access to employment — hiring, promotion, compensation, discipline, or termination.

This sweeps in more than a dedicated "AI hiring platform." If you use any of the following to meaningfully influence who gets hired, promoted, or let go, you're in scope:

  • Resume screening or keyword-ranking tools
  • Interview scheduling software that also scores or filters candidates
  • Chatbot-based initial screening interviews
  • Background-check or reference-check tools with automated scoring
  • Performance-management software that flags employees for review or termination

The key word is materially. A spell-checker or a scheduling calendar that has no scoring or filtering function isn't ADMT. A tool that ranks 200 resumes down to a shortlist of 10 is.

The small-business exemption — and its narrow edges

Employers with 40 or fewer employees are generally not treated as a "deployer" under the statute, which exempts most solo operators, small shops, and early-stage startups from the core obligations.

But the carve-out has edges that catch people off guard:

  • It's about employee count, not revenue or Colorado presence. A 15-person company based in Miami with one remote employee or even a single job applicant in Colorado can still fall under the law's reach for that interaction — headcount is what determines deployer status, not where you're headquartered.
  • Using a vendor's tool doesn't shift the obligation. If a third-party platform built the screening algorithm, your business — as the one deploying it against real candidates — is still the "deployer" responsible for compliance, not the vendor. The vendor's job is to give you enough information to use the tool appropriately; your job is to actually meet the notice and review requirements.
  • The exemption is about size, not intent. There's no "we didn't know it counted as ADMT" defense. If the tool materially shapes a hiring or compensation outcome, the exemption depends on your headcount, not on how sophisticated your compliance program is.

If you're near the 40-employee line, or you're a small company that's about to scale hiring using an AI-assisted platform, it's worth building the compliance habits below now rather than scrambling once you cross the threshold mid-recruiting-season.

What covered employers have to do, in practice

For businesses that don't qualify for the exemption, the law sets out three concrete obligations, and unlike the old statute, none of them requires you to hire a data scientist:

1. Notice before you use it. You need to give applicants and employees clear, conspicuous notice that ADMT is part of the process — before it's used, not after. In practice this can be as simple as a line in the online application ("This application uses automated tools to help screen candidates") or a link posted near the point of interaction. It doesn't require a standalone legal disclosure buried in a privacy policy.

2. A real adverse-action process. If ADMT contributes to a decision that's adverse to someone — they're screened out, passed over, or terminated — you have 30 days to give them a plain-language explanation of the decision and the role the tool played in it. They can then request correction of factually inaccurate data the tool relied on, and request "meaningful human review" of the decision, to the extent that's commercially reasonable for a business your size. This is the heart of the law's new "decision-by-decision" approach: instead of proving the system is fair in the abstract, you have to be able to explain and revisit specific outcomes when someone pushes back.

3. Record retention. Keep records of the ADMT you used — version identifiers, any material changes made to how it screens or scores, and documentation tied to each consequential decision — for at least three years.

Compare that to the old law's requirement of a pre-deployment risk management program and regular bias audits, and it's obviously lighter. But "lighter" doesn't mean "nothing" — the notice and adverse-action pieces are new operational habits, not a policy document you write once and file away.

Enforcement: no lawsuits, but real penalties

There's no private right of action under the new law — an individual candidate can't sue you directly over an ADMT violation. Enforcement sits exclusively with the Colorado Attorney General. Violations can carry penalties of up to $20,000 each, though the AG's office generally has to offer a 60-day cure period to fix the issue before penalties apply, when a cure is deemed possible.

That combination — AG-only enforcement, a cure period, no lawsuits — is a big part of why business groups backed the rewrite. It converts the compliance risk from "any rejected applicant's lawyer could sue us" into "we have a defined process, and if we mess it up, we get a chance to fix it before we're fined." For a small employer without in-house counsel, that's a meaningfully different risk profile.

What to do before January 1, 2027

The effective date gives covered employers about five months of runway from when this article is published. A reasonable sequence:

  1. Inventory your hiring and HR software. List every tool that touches applications, screening, scheduling, performance reviews, or compensation decisions. Ask each vendor directly whether their product performs automated scoring, ranking, or filtering.
  2. Confirm your headcount status. If you're under 40 employees today but growing, model out when you'll cross the line and plan compliance work accordingly — not in the week you hire employee #41.
  3. Draft your notice language. A short, plain-language statement that ADMT is part of your process, placed where applicants and employees will actually see it.
  4. Build the adverse-action workflow. Decide who reviews correction requests, who conducts "meaningful human review," and how you'll produce a plain-language explanation within the 30-day window. This is a process question, not a technology purchase.
  5. Set up a retention system. Even a simple shared folder that logs which tool version was used for which hiring cycle, updated whenever a vendor pushes a material change, satisfies the three-year retention requirement.

Keeping the paper trail this law requires

Whatever your business ultimately builds for ADMT compliance, it comes down to being able to show — clearly, and on request — what tool was used, what changed and when, and what happened as a result. That's the same discipline good financial recordkeeping runs on: a clear, dated, auditable trail rather than something reconstructed after the fact from memory or scattered spreadsheets. Beancount.io applies that same plain-text, version-controlled approach to your books — every entry is transparent, timestamped, and traceable, with no vendor lock-in and no black box. Get started for free and see how much easier compliance conversations get when your records are already in order.

Condividi questo articolo