# Colorado Replaces Its AI Act with SB 26-189

> Most of Colorado's SB 26-189 waits for January 1, 2027, but one section gave the insurance Commissioner AI disclosure rulemaking power on signing. Where the duties land.

- Source: https://insureaiwire.com/colorado-sb-26-189/
- Publication: InsureAI Wire
- Author: Simon Li
- Updated: 2026-08-02

---
A carrier's pricing model had already been through two rounds of legal review when the email arrived: Colorado had rewritten its artificial intelligence law. The deadline everyone had been planning for, June 30, 2026, was gone [^13]. In its place stood a new statute, a new effective date of January 1, 2027, and a new question [^1]. Was the work already done still useful, or had the target moved so far that compliance officers needed to start over?

For insurers, the answer is closer to a redirection than a reset. Colorado did not drop out of [state AI regulation](/ai-governance-in-insurance/). It replaced SB 24-205, the original Colorado Artificial Intelligence Act, with SB 26-189, a narrower law that swaps the old algorithmic-discrimination framework for a disclosure-and-recourse model. But the redirection points somewhere specific, and it is not at the new statute. SB 26-189 defers to Colorado's own insurance regime for the practice of insurance, which leaves a carrier with two questions: what SB 21-169 has been asking all along, and which of your automated systems fall outside the deference.

## What just happened

On May 14, 2026, Governor Jared Polis signed SB 26-189 into law, repealing and replacing the Colorado AI Act that had been scheduled to take effect on June 30, 2026.[^1] Most of the new law takes effect on January 1, 2027, and applies to consequential decisions made on or after that date. Not all of it. SECTION 5(2) exempts a short list of provisions from that date, and one of them was written into the insurance code rather than the consumer protection code.[^2]

The rewrite followed federal pressure and litigation over the old act. President Trump's December 2025 executive order described a Colorado law without giving its bill number, and the Justice Department intervened in xAI's challenge to SB 24-205 in April 2026.[^3][^4] The Attorney General's stated intention not to enforce the old law generally is not a statutory safe harbor; the case-specific stipulation lasts until fourteen days after a preliminary-injunction ruling.[^5][^11] Our [EO 14365 analysis](/ai-executive-order-insurance-preemption/) maintains that federal timeline. This article follows the Colorado obligations that remain.

## The biggest shift: from "high-risk AI" to "automated decision-making technology"

The old law regulated "high-risk artificial intelligence systems." The new law regulates "[automated decision-making technology](/glossary/automated-decision-system/)," or ADMT.[^1]

ADMT is defined as a technology that processes personal data and uses computation to generate outputs, including predictions, recommendations, classifications, rankings, scores, or other information, used to make, guide, or assist a decision, judgment, or determination about an individual.[^1] The law applies when that ADMT is used to "materially influence" a "consequential decision."[^1]

A consequential decision is one that materially affects a consumer's access to a "covered domain," and the covered-domain list names insurance explicitly, including underwriting, pricing, coverage, and claims adjudication.[^1] That sweeps in pricing algorithms, underwriting triage tools, claims fraud scoring, and eligibility systems, even where the underlying technology does not look like "AI" in the popular sense. Being inside the covered domain is not the end of the question for a licensed carrier, though, and the section on the insurance carve-out below is where it gets answered.

The definition of ADMT is arguably broader than the old "high-risk AI" definition because it does not require inference. A rules-based system that checks whether an answer falls within a fixed range could qualify.[^4] That breadth is fenced from below rather than from above. Section 6-1-1701 (2)(b) names fourteen technologies that are not ADMT at all, including calculators, databases, and spreadsheets that need human analysis and use no machine learning, and section 6-1-1701 (3)(b) lifts nine categories of activity out of "consequential decision" entirely, among them fraud prevention, anti-money-laundering controls, and cybersecurity.[^2] The message for insurers is that the legal trigger is no longer the sophistication of the model. It is the decision the system helps make.

## How the three Colorado layers fit together

SB 26-189 removes four central duties from the old general-purpose AI Act:

- Its duty of reasonable care to protect consumers from [algorithmic discrimination](/glossary/algorithmic-discrimination/), which fell on developers and deployers alike.[^6]
- Its mandatory risk management policy and program.[^6]
- Its impact assessments, due at least annually and again within 90 days of an intentional and substantial modification.[^6]
- Its requirement to disclose algorithmic discrimination to the Colorado Attorney General within 90 days of discovering it.[^6]

That change does not fully arrive until January 1, 2027. SB 24-205 took effect on June 30, 2026 after the 2025 special session moved its date,[^13] and the replacement act repeals it from January 1.[^2] The Attorney General's non-enforcement position reduces practical exposure during the interval but does not erase the text.[^5]

Insurance has a separate layer. SB 21-169 bars specified [unfair discrimination](/glossary/unfair-discrimination/) in insurance practices and makes the external-data and predictive-model prohibition operate through rules adopted by the Commissioner.[^7][^10] The first limb is a direct prohibition across covered insurance practices. The second depends on rules that the Division writes by insurance type and practice. This distinction matters when a statute applies to a line but the Division has not yet supplied a testing method for it.

The insurance statute also excludes title, surety, and most commercial policies. Business owners' and commercial general liability policies remain inside only when annual premiums are ten thousand dollars or less.[^10] These are scope boundaries, not lighter versions of the same requirements. A commercial carrier may therefore fall outside section 10-3-1104.9 and lose the deemed-compliance route that SB 26-189 gives an insurer subject to that section.

The adopted rule is Regulation 10-1-1. Since October 15, 2025 it has covered individual life carriers, private-passenger auto carriers, and health benefit plan issuers, requiring a governance framework and annual officer-signed report.[^8] Life reports are due December 1; auto and health reports are due July 1. The report is capped at ten pages and must identify the title and qualifications of each person responsible for the listed requirements. A carrier that does not use the covered data or models files an officer-signed non-use attestation instead.[^8]

The rule's framework focuses on race, while the statute lists a broader set of protected characteristics. Colorado still has no adopted quantitative testing method. Two life-underwriting drafts remain proposals, and the limited waiver applied only to the 2024 and 2025 life reports.[^9][^12] The rule nevertheless expects later reports to describe testing conducted under Division requirements, leaving carriers with an explicit reporting field and no adopted quantitative method to populate it. The statistical approaches and remediation choices belong to [our disparate-impact guide](/how-disparate-impact-shapes-ai-pricing/); this article tracks which Colorado layer creates the obligation.

<figure class="figure">
<svg viewBox="0 0 460 452" width="460" role="img">
<title>Two-column ledger comparing the repealed SB 24-205 obligations (duty of care, risk-management program, annual impact assessments, 90-day attorney-general disclosure of discovered algorithmic discrimination) with the obligations SB 26-189 enacted: pre-use notice, 30-day adverse-outcome notice, human review and data correction, three-year records, developer documentation, and an anti-indemnity rule. A third band below records the layer the rewrite did not repeal but did widen: Colorado SB 21-169 still bars unfairly discriminatory models, and Division of Insurance Regulation 10-1-1 requires life, private passenger auto, and health benefit plan insurers to run a governance framework aimed at unfair discrimination with respect to race, while SB 26-189 added subsection 10-3-1104.9(3)(e), which gave the insurance Commissioner rulemaking power over insurer notice and disclosure on the May 14, 2026 signature.</title>
<rect x="8" y="8" width="214" height="284" fill="none" class="s-ink" stroke-width="2"/>
<text x="20" y="34" class="t-label f-ink" font-size="15">REPEALED: SB 24-205</text>
<line x1="20" y1="46" x2="210" y2="46" class="s-rule" stroke-width="1"/>
<rect x="20" y="67" width="5" height="5" class="f-muted"/>
<text x="32" y="76" class="t-label f-muted" font-size="14" style="text-decoration:line-through">DUTY OF CARE</text>
<rect x="20" y="111" width="5" height="5" class="f-muted"/>
<text x="32" y="120" class="t-label f-muted" font-size="14" style="text-decoration:line-through">RISK-MANAGEMENT</text>
<text x="32" y="138" class="t-label f-muted" font-size="14" style="text-decoration:line-through">PROGRAM</text>
<rect x="20" y="173" width="5" height="5" class="f-muted"/>
<text x="32" y="182" class="t-label f-muted" font-size="14" style="text-decoration:line-through">ANNUAL IMPACT</text>
<text x="32" y="200" class="t-label f-muted" font-size="14" style="text-decoration:line-through">ASSESSMENTS</text>
<rect x="20" y="235" width="5" height="5" class="f-muted"/>
<text x="32" y="244" class="t-label f-muted" font-size="14" style="text-decoration:line-through">90-DAY AG DISCLOSURE</text>
<rect x="238" y="8" width="214" height="284" fill="none" class="s-ink" stroke-width="2"/>
<text x="250" y="34" class="t-label f-ink" font-size="15">ENACTED: SB 26-189</text>
<line x1="250" y1="46" x2="440" y2="46" class="s-rule" stroke-width="1"/>
<rect x="250" y="67" width="5" height="5" class="f-ink"/>
<text x="262" y="76" class="t-label f-ink" font-size="14">PRE-USE NOTICE</text>
<rect x="250" y="99" width="5" height="5" class="f-ink"/>
<text x="262" y="108" class="t-label f-ink" font-size="14">30-DAY ADVERSE-</text>
<text x="262" y="126" class="t-label f-ink" font-size="14">OUTCOME NOTICE</text>
<rect x="250" y="149" width="5" height="5" class="f-ink"/>
<text x="262" y="158" class="t-label f-ink" font-size="14">HUMAN REVIEW &amp;</text>
<text x="262" y="176" class="t-label f-ink" font-size="14">DATA CORRECTION</text>
<rect x="250" y="199" width="5" height="5" class="f-ink"/>
<text x="262" y="208" class="t-label f-ink" font-size="14">3-YEAR RECORDS</text>
<rect x="250" y="231" width="5" height="5" class="f-ink"/>
<text x="262" y="240" class="t-label f-ink" font-size="14">DEVELOPER DOCS</text>
<rect x="250" y="263" width="5" height="5" class="f-ink"/>
<text x="262" y="272" class="t-label f-ink" font-size="14">ANTI-INDEMNITY RULE</text>
<rect x="8" y="304" width="444" height="90" fill="none" class="s-ink" stroke-width="2"/>
<text x="20" y="330" class="t-label f-ink" font-size="15">NOT REPEALED, WIDENED: SB 21-169</text>
<rect x="20" y="346" width="5" height="5" class="f-ink"/>
<text x="32" y="355" class="t-label f-ink" font-size="14">REG 10-1-1: LIFE, AUTO, HEALTH (RACE SCOPE)</text>
<rect x="20" y="368" width="5" height="5" class="f-ink"/>
<text x="32" y="377" class="t-label f-ink" font-size="14">NEW 10-3-1104.9(3)(e), IN FORCE MAY 14 2026</text>
<text x="230" y="418" text-anchor="middle" class="t-label f-red" font-size="14">FROM RISK MANAGEMENT TO DISCLOSURE-AND-RECOURSE:</text>
<text x="230" y="440" text-anchor="middle" class="t-label f-red" font-size="14">A DIFFERENT SHAPE, NOT DEREGULATION.</text>
</svg>
<figcaption>FIG. 1: WHAT THE REWRITE REMOVED, ADDED, AND WIDENED<span class="figure-source">SOURCE: COLORADO GENERAL ASSEMBLY, SB 24-205 / SB 26-189 / SB 21-169; COLORADO DIVISION OF INSURANCE, 3 CCR 702-10 REG 10-1-1</span></figcaption>
</figure>

## What SB 26-189 added

The new law gives developers and deployers of covered ADMT a disclosure-and-recourse framework.[^1] The insurance deference in the next section determines whether a licensed carrier performs these duties for a particular use.

**Pre-use notice.** Deployers must give consumers clear and conspicuous notice before a covered ADMT is used to materially influence a consequential decision.[^1] This can be satisfied by a prominent public notice accessible via a link, but the notice must be reasonably accessible at points of consumer interaction.[^2]

**Post-adverse-outcome notice.** Within 30 days after making a consequential decision that a covered ADMT materially influenced and that results in an adverse outcome, the deployer must provide a plain-language description of the decision and the ADMT's role in it.[^1] The Attorney General must adopt rules clarifying this requirement by January 1, 2027.[^1]

**Consumer rights.** Consumers can request access to the personal data used by the covered ADMT and correction of factually incorrect personal data. The correction right stops where the model's own output begins: section 6-1-1705 (1)(c) says nothing in it requires correction of opinions, predictions, scores, or protected evaluations.[^2] Consumers can also request meaningful human review and reconsideration following an adverse outcome, though the statute qualifies that right with "to the extent commercially reasonable."[^1]

**Record retention.** Both developers and deployers must retain records necessary to demonstrate compliance for at least three years.[^1]

**Developer documentation.** Developers marketing a covered ADMT must provide deployers with technical documentation covering intended uses, categories of training data, known limitations, instructions for use, and information needed for the deployer's own disclosures.[^1] They must also notify deployers of material updates.[^1]

**Vendor contract terms.** SB 26-189 voids a developer-deployer contract provision that indemnifies a party against liability for its own Colorado anti-discrimination violations in an ADMT-driven consequential decision.[^2]

The timing turns on the consumer decision, not on when the carrier bought or configured the technology. SECTION 5(3) applies the new part to consequential decisions made on or after January 1, 2027.[^2] An older system can therefore enter the new regime when it helps make a later decision, while a 2026 procurement does not by itself trigger the 2027 duties. For an adverse outcome, the thirty-day notice period runs from the decision and requires a plain-language account of the ADMT's role. The access and correction right reaches personal data, while opinions, predictions, scores, and protected evaluations remain outside the correction command.[^2] Human review carries its own qualifier: the opportunity is required only to the extent commercially reasonable. Those limits belong in the workflow design because they determine the request the consumer can make and the record the deployer has to preserve.

## The insurance carve-out that decides how much of this you owe

Section 6-1-1708(1)(a) deems an insurer, and affiliated entities, subject to section 10-3-1104.9 to be in compliance with the ADMT part in the practice of insurance.[^2] That directs covered underwriting, pricing, and claims work to the insurance regime described above.

Three limits keep that from being a general exemption. An insurer that is not deemed compliant still owes the post-adverse-outcome disclosure.[^2] The deference runs, in the statute's own words, only "in the practice of insurance," which leaves an insurer's employment and hiring systems outside it.[^2] It also runs only to entities subject to 10-3-1104.9, which leaves a live question for lines the Division has not written rules for.

The wording also changed who can use the insurance route. SB 24-205 expressly named insurers, fraternal benefit societies, and developers of AI systems used by insurers. SB 26-189 names an insurer and affiliated entities subject to section 10-3-1104.9; it does not carry the developer clause forward.[^6][^2] A technology supplier cannot assume that its customer's insurance status satisfies the supplier's own developer duties. A TPA or MGA deploying the same tool must separately determine whether it is acting within a covered insurer's practice of insurance or as a deployer on its own account.

A separate exclusion runs the other direction, and a health carrier should find it before building anything. Section 6-1-1708(3)(a) takes HIPAA covered entities, and their business associates for services rendered to a covered entity, out of 6-1-1701 through 6-1-1706 altogether, with one exception: consequential decisions about employment or an employment opportunity.[^2] A health benefit plan issuer is itself a covered entity under HIPAA, so it leaves the ADMT duties by two doors, the insurance deference for the practice of insurance and the HIPAA exclusion for the rest, and both stop at the same place, which is again the HR system. What subsection (3) leaves standing is smaller, and it belongs to health privacy rather than to the ADMT part. A covered entity owes patients, in the statute's word, a general notice that it uses advanced technologies including covered ADMT, and that notice can be folded into the patient-rights notices it already sends.[^2]

One insurance provision did not wait for 2027. SECTION 3 added subsection 10-3-1104.9(3)(e), and SECTION 5(2) made it effective on passage.[^2] Since May 14, 2026, the Commissioner has been able to adopt or update rules on insurer notices and disclosures. That authority sits inside the insurance statute and follows the Division's calendar, even where the ADMT deference applies.

## Enforcement: one enforcer, and a tight cure window

The Attorney General enforces the law through the Colorado Consumer Protection Act, and violations of the disclosure and consumer-rights sections are enforceable by the AG exclusively.[^1] Part 17 creates no new private right of action, and it says in the same breath that it does not limit existing rights or remedies, naming the Colorado Anti-Discrimination Act, the Consumer Protection Act, and product liability law.[^2] A consumer who could sue before can still sue; what the new part withholds is a fresh cause of action of its own.

Before initiating an enforcement action before January 1, 2030, the AG must give the developer or deployer a 60-day notice and opportunity to cure, if a cure is deemed possible.[^1] The right to cure does not apply to knowing or repeated violations.[^2] After 2030, the cure period sunsets. This creates a narrow window in which a carrier can fix a problem without public enforcement, but only if the compliance program can detect the problem quickly enough.

## What this means for insurance operations

The carve-out sorts the work into three piles, and most of what has been written about this statute belongs to the smallest one.

**Underwriting, pricing, and claims.** A carrier subject to section 10-3-1104.9 is deemed compliant with the ADMT part for the practice of insurance. Regulation 10-1-1 already supplies the operative framework for life, private passenger auto, and health benefit plans. Other lines require a direct read of the statute and its exclusions because the Division has not supplied the same rulebook.[^10] This is also why an insurer should resist copying the general ADMT notice program into every insurance workflow. The applicable notice may instead arrive through the Commissioner's insurance-specific authority that took effect on May 14, 2026.[^2]

**Hiring and HR.** From January 1, 2027, section 6-1-1708(2) puts insurer employment and employment opportunities inside the new ADMT part. Resume screeners, interview scoring, promotion models, and workforce analytics will therefore need the applicable notice, review, and retention controls. From that date, such a system will require the carrier to bring HR and procurement owners into scope so they can identify embedded scoring features that sit outside the insurance model register.

**Vendors, MGAs, and third-party administrators.** A vendor may owe developer duties, and a TPA may be a deployer in its own right, even when the carrier receives deemed compliance for the insurance decision.[^6][^2] The result can change by customer and use. A business associate serving a HIPAA covered entity is excluded for those services, while the same provider can remain exposed when it supplies a property-casualty carrier. Fraud-prevention and cybersecurity activity may leave the consequential-decision definition, but claims adjudication does not disappear merely because a fraud score informs it.[^2] The immediate questions are the party's statutory role, the business process, and the reason the system is used. Contract implementation belongs in the [AI vendor risk assessment](/ai-vendor-risk-assessment/).

Contract labels do not settle those statutory roles. A company called a vendor can be a developer when it places the ADMT on the market and a deployer when it uses the tool to make or materially influence its own covered decision. An MGA or TPA can occupy either position depending on the authority it exercises in the transaction. The HIPAA exclusion is similarly service-specific: business-associate status can remove the health-plan service from sections 6-1-1701 through 6-1-1706 without carrying the same provider out of the law for unrelated property-casualty work.[^2] This is why the analysis belongs at the combination of legal entity, customer, use, and decision, rather than at the product name alone.

**Three edges worth flagging to counsel.** The carve-out reaches insurers "subject to the requirements of section 10-3-1104.9," and the phrase is doing more work than it looks. For a line the Division has not yet written a rule for, it is arguable either way, since the statutory prohibition binds even where the testing rules do not. For title, surety, and most commercial business, subsection (6) of 10-3-1104.9 takes the carrier outside the section by its terms, which points the other way: not deemed compliant, and therefore inside the ADMT part in full.[^10] Second, SB 24-205 named fraternal benefit societies alongside insurers and SB 26-189 does not, so from January 1, 2027 a society will be arguing its way into the definition of insurer at 10-1-102 (13) rather than finding itself listed.[^6] Third, the anti-indemnity provision voids offending contract terms as contrary to public policy rather than imposing a duty, so whether a deemed-compliant insurer's vendor agreements escape it is a live question. None of the three is settled. All three are cheap to plan around now and expensive to discover after the replacement law takes effect.[^2]

## What to do before January 1, 2027

1. **Classify each system by Colorado regime.** Separate the practice of insurance, insurer employment, and a vendor's own deployment before assigning duties.

2. **Confirm the existing insurance filing.** Life insurers [file under Regulation 10-1-1](https://doi.colorado.gov/for-consumers/sb21-169-protecting-consumers-from-unfair-discrimination-in-insurance-practices) every December 1; private passenger auto and health benefit plan insurers file every July 1.[^8] Confirm the responsible officer, ten-page report, named control owners, and any non-use attestation. Our page on [Colorado's AI insurance law](/states/colorado/) sets those filing duties beside the NAIC model bulletin. The limited life testing waiver ended with the December 1, 2025 report, while the Division still has not adopted a quantitative method.[^12] Monitor the separate notice-and-disclosure rulemaking authority now in force.

3. **Find the HR systems.** Identify tools that score, rank, or filter applicants and employees, including features embedded in an HR platform, and apply the ADMT duties that the employment exception restores.

4. **Resolve vendor and consumer-facing duties.** Identify whether each supplier is a developer, deployer, affiliate, TPA, MGA, or HIPAA business associate for the use at issue. Obtain the developer documentation and update notices the statute describes, remove prohibited indemnity language, and build notice and review only for uses that remain inside the ADMT part.

## The larger signal

Colorado changed the general-purpose AI layer without unwinding its insurance-specific rules. A carrier that treats the rewrite as a single replacement risks cutting the wrong workstream.

The next insurance change now sits with the Division. Section 10-3-1104.9(3)(e) has been in force since May 14, 2026, and the ADMT part does not control when the Commissioner uses it.[^2] A notice or disclosure rule issued there would reach insurance systems on the Division's calendar, not the January 1, 2027 ADMT timetable.

---

[^1]: Colorado General Assembly, "SB26-189 Automated Decision-Making Technology," signed May 14, 2026 (bill summary and all text versions, including the signed act): https://leg.colorado.gov/bills/sb26-189
[^2]: Colorado General Assembly, Senate Bill 26-189, signed act text (SECTION 5 effective date and applicability, including the upon-passage list in SECTION 5 (2); SECTION 3 adding 10-3-1104.9 (3)(e); section 6-1-1704 deployer disclosures and the attorney general rulemaking at (4); 6-1-1705 (3) attorney general rulemaking; 6-1-1706 (3) notice and cure; 6-1-1707 (7)(a) void indemnification; 6-1-1708 insurer deemed compliance and the HIPAA covered entity exclusion at (3)(a); 6-1-1709 no new private right of action): https://leg.colorado.gov/bill_files/116489/download
[^3]: The White House, "Ensuring a National Policy Framework for Artificial Intelligence," Executive Order 14365, December 11, 2025: https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/
[^4]: Holland & Knight, "Colorado Governor Signs SB 189, Significantly Amending the State's AI Law" (May 18, 2026): https://www.hklaw.com/en/insights/publications/2026/05/colorado-governor-signs-sb-189
[^5]: Norton Rose Fulbright, "Colorado enacts revised AI law" (May 2026): https://www.nortonrosefulbright.com/en-us/knowledge/publications/18733d31/colorado-enacts-revised-ai-law
[^6]: Colorado General Assembly, Senate Bill 24-205, signed act text (6-1-1702 (1) developer duty of reasonable care and 6-1-1703 (1) deployer duty of reasonable care against algorithmic discrimination; 6-1-1703 (2)(a) risk management policy and program; 6-1-1703 (3)(a) impact assessments at least annually and within ninety days of an intentional and substantial modification; 6-1-1703 (7) deployer notice to the attorney general within ninety days of discovery; 6-1-1705 (7) deemed compliance for an insurer, a fraternal benefit society, or a developer of an artificial intelligence system used by an insurer): https://leg.colorado.gov/bill_files/47770/download
[^7]: Colorado Division of Insurance, "SB21-169: Protecting Consumers from Unfair Discrimination in Insurance Practices" (statutory scope, line-by-line stakeholder process for life, auto, and health): https://doi.colorado.gov/for-consumers/sb21-169-protecting-consumers-from-unfair-discrimination-in-insurance-practices. Statute: Colorado General Assembly, "SB21-169 Restrict Insurers' Use Of External Consumer Data": https://leg.colorado.gov/bills/sb21-169
[^8]: Colorado Division of Insurance, Amended Regulation 10-1-1, 3 CCR 702-10, effective October 15, 2025, adopted by notice of August 20, 2025 (section 3 applicability to individually issued life, private passenger automobile, and health benefit plan insurers; section 5.A framework "designed to determine whether the use of such ECDIS, algorithms, and predictive models potentially result in unfair discrimination with respect to race"; section 5.A.11 documented description of quantitative testing "conducted pursuant to requirements established by the Division"; section 5.C availability of framework components on December 1 for life and July 1 for auto and health; sections 6.B and 6.C annual compliance reports on the same dates; section 6.D officer signature, ten-page limit, and the title and qualifications of each individual responsible for each requirement; section 6.E officer-signed non-use attestation due December 1): https://doi.colorado.gov/announcements/notice-of-adoption-amended-regulation-10-1-1-governance-and-risk-management-framework. Readers checking the regulation text elsewhere should note that the copies of 3 CCR 702-10 hosted at Cornell LII and Justia still carry the superseded 2023 life-only title.
[^9]: Colorado Division of Insurance, "DRAFT Proposed Algorithm and Predictive Model Quantitative Testing Regulation," released for informal comment September 28, 2023 (prescriptive: BIFSG race estimation, logistic regression on approvals and linear regression on premium per $1,000 of face amount, with escalation at p < .05 plus a five-percentage-point or five-percent gap, and any ECDIS variable whose coefficient shifts deemed unfairly discriminatory): https://doi.colorado.gov/sites/doi/files/documents/DRAFT%20Proposed%20Algorithm%20and%20Predictive%20Model%20Quantitative%20Testing%20Regulation.pdf. The competing text is the American Council of Life Insurers' "ACLI DRAFT PROPOSED Quantitative Testing Regulation," presented at the Division's June 17, 2024 life underwriting stakeholder meeting (a single screening test on whether the model-output coefficient survives the addition of inferred race, with justification and Division review rather than automatic remediation): https://doi.colorado.gov/sites/doi/files/documents/ACLI-DRAFT-PROPOSED-Life-UW-Quantitative-Testing-Regulation.pdf. Both are indexed on the Division's SB21-169 page.
[^10]: Colorado General Assembly, Senate Bill 21-169, signed act text enacting C.R.S. 10-3-1104.9 (subsection (1)(a) freestanding bar on unfair discrimination and (1)(b) external-data bar operating pursuant to commissioner rules; (3)(b)(V) attestation by one or more officers; (6) exclusions for title insurance, surety bonds, and commercial policies other than business owners' and commercial general liability policies with annual premiums of ten thousand dollars or less; (8)(c) definition of insurance practice; (8)(e) definition of unfair discrimination): https://leg.colorado.gov/bill_files/54604/download
[^11]: Docket, X. AI LLC v. Weiser, No. 1:26-cv-01515-DDD-CYC (D. Colo., filed April 9, 2026), entry 24 (stipulation staying enforcement of SB 24-205, and of any legislation passed in the same session replacing or amending it, as to the plaintiff until fourteen days after a ruling on a preliminary injunction): https://www.courtlistener.com/docket/73171074/x-ai-llc-v-weiser/
[^12]: Colorado Division of Insurance, Revised Bulletin No. B-10.004, "Concerning the Quantitative Testing Reporting Requirement for Life Insurers that Use External Consumer Data and Information Sources," issued October 18, 2024 and reissued October 22, 2025 (section III: the annual reports due December 1, 2024 and December 1, 2025 are not required to include a description of the quantitative testing referenced in Regulation 10-1-1 section 5.A.11; "the waiver of this requirement is for the annual reports due December 1, 2024 and December 1, 2025 only; subsequent annual reports will be expected to include a description of the quantitative testing conducted"; section II limits the bulletin to life insurers): https://doi.colorado.gov/announcements/notice-of-adoption-bulletin-b-605-and-revised-bulletins-b-4148-and-b-10004
[^13]: Colorado General Assembly, Senate Bill 25B-004, "Concerning Measures Effective No Later Than June 30, 2026, to Increase Transparency for Algorithmic Systems," signed August 28, 2025 (striking "February 1, 2026" and substituting "June 30, 2026" throughout 6-1-1702, 6-1-1703, and 6-1-1704 of the Colorado AI Act): https://leg.colorado.gov/bills/sb25b-004