Regulation3 min read

Colorado Softens AI Law, Federal Fight Continues

July 9, 2026Synthesized from 1 source: Theconversation

Colorado replaced its ambitious AI accountability law with a lighter disclosure-only version in May 2026, but a federal lawsuit backed by the DOJ and a White House campaign against state AI laws mean the new version could face legal challenges too.

Colorado passed the most ambitious AI accountability law in the United States in May 2024. It told companies that if they used AI to make decisions affecting people's jobs, loans, insurance, or healthcare, they had to build internal systems to catch bias before it reached consumers. Companies had to audit their AI tools, run risk management programs, and prove they were doing it.

That law never actually took effect. From the day it was signed, the tech industry pushed back hard. The legislature delayed the enforcement date twice. Then, in April 2026, xAI, the company behind Elon Musk's Grok chatbot, sued to block it entirely. The DOJ joined the lawsuit just two weeks later, making it the first time the federal government had ever intervened to fight a state AI law. A court froze the law pending further proceedings, and the Colorado legislature moved quickly to replace it before the original June 30 deadline arrived.

What replaced it is a much thinner framework. The new law, signed on May 14, 2026, and set to take effect January 1, 2027, requires companies to notify consumers when automated systems played a role in a consequential decision. If that decision went against the consumer, the company has 30 days to explain what role AI played. Consumers can also ask for a human review of the decision and request corrections to inaccurate personal data used in the process.

Noticeably absent from the new law: any obligation on companies to audit their own AI systems for bias. Under the old law, a bank using AI to deny a loan would have needed internal processes designed to catch discriminatory patterns before they reached the customer. Under the new law, the bank simply has to explain the denial after it happens. The accountability shifted from the institution to the individual consumer.

The federal legal challenge, however, did not disappear with the rewrite. The DOJ had made two constitutional arguments against the original law. The first, that requiring companies to monitor and correct for racial or gender bias effectively forced companies to classify people by protected characteristics, was eliminated when Colorado dropped the bias-prevention requirements entirely. The second argument, that forcing companies to send specific messages to consumers violates freedom of speech protections, actually became easier to make against the new law. Because the new version is almost entirely disclosure requirements, it is now a cleaner target for that argument.

The broader federal campaign behind this is worth understanding. In December 2025, President Trump signed an executive order directing the DOJ to set up a task force whose stated sole job is to challenge state AI laws. The Commerce Department was ordered to publish a list of state AI laws it considers too burdensome by March 11, 2026. That list has not appeared yet. If and when it does, and if Colorado's new law ends up on it, the federal government's campaign against state-level AI rules will have found its next target.

States are watching this closely. More than 100 new AI-related laws have been passed across the US so far in 2026. The federal government has signalled it will fight laws that require companies to check for bias or that mandate specific disclosures, but it has indicated it will leave alone laws covering child safety, AI infrastructure, and government procurement of AI. States appear to be responding: the laws passing in 2026 are clustered in those tolerated categories.

For operators in any industry that makes consequential decisions about people, the practical picture for now is this. If you use automated tools in hiring, lending, insurance pricing, or healthcare eligibility decisions in Colorado, the new law applies to you from January 1, 2027. You need to be able to explain, in plain language, what role an automated system played when a decision went against a customer. You need a designated person capable of reviewing those decisions by hand. You do not need to audit your system for bias proactively, but that does not mean bias claims disappear: Colorado's existing anti-discrimination laws still apply, and the new law explicitly says companies cannot use contracts to shield themselves from liability when their AI tools violate those laws.

The bigger picture for business operators globally: the US has no single federal AI law, and the fight over whether states can fill that gap is now a live court battle. The compliance rules you follow today may change through litigation, not legislation. Planning around the strictest current requirements, rather than waiting to see which ones survive, is the more durable approach.

Stay informed

Get AI intelligence like this delivered to your inbox.