Colorado AI Governance
Colorado is the most active state legislature in the US on AI governance. Regulation 10-1-1 establishes insurance-specific AI requirements with annual certification obligations. The broader Colorado AI Act (SB 26-189) extends consumer protection requirements for high-risk AI across multiple sectors.
How Trustible Supports Colorado Compliance
Your First 90 Days
Day 30: Inventory AI and External Data Sources
Identify and document all AI systems, external consumer data sources, algorithms, and predictive models in use within regulated business functions.
Day 60: Assess Bias and Discriminatory Risk
Launch structured bias and fairness assessments for each identified AI system. Document testing methodology and results.
Day 90: Operationalize and Certify
Connect AI governance workflows to internal policies and vendor oversight processes. Generate documentation for annual certification and regulatory audit readiness.
Colorado AI FAQs
The law specifies outcomes — no unfair discrimination — rather than prescribing specific testing methodologies. Regulated entities have flexibility in how they test, provided they can document methodology and results.
Regulation 10-1-1 established insurance-specific AI governance requirements. SB 26-189 establishes broader requirements for high-risk AI across multiple sectors. Organizations subject to both will find significant overlap in governance activities — all of which Trustible manages in a unified platform.
A developer is an organization that builds or substantially modifies a high-risk AI system before it goes to market. A deployer is an organization that uses a high-risk AI system to make, or as a substantial factor in making, a consequential decision about a consumer. The obligations differ by role. Developers must document the system's intended uses, known limitations, and risk mitigation measures, and share that documentation with deployers. Deployers must maintain a risk management program, conduct impact assessments, and notify consumers when AI plays a role in a decision about them. Many organizations hold both roles across their AI portfolio, building some systems in-house while deploying tools built by vendors elsewhere. Trustible's AI Inventory captures this distinction at the use case level, so governance activities route to the right obligations depending on whether your organization built the system or is using one built by a vendor.
A high-risk AI system is one that makes, or is a substantial factor in making, a consequential decision, meaning a decision with a material effect on a consumer's access to or terms for things like employment, education, lending, housing, healthcare, insurance, or legal services. The threshold isn't how advanced the technology is. It's whether the system's output meaningfully shapes an outcome that affects someone's life. A tool that screens job applicants before a human reviews them meets that bar. A general-purpose chatbot answering customer questions typically doesn't. Trustible's Insights Taxonomies and Risk Management module apply this test during intake, so systems that trigger consequential decisions get routed to the deeper risk and impact assessments SB 26-189 requires, while lower-impact systems move through faster.
Yes. Scope follows the impact, not the organization's address. Any developer or deployer doing business in Colorado, or whose AI system is used to make consequential decisions about Colorado consumers, falls under the law regardless of where the company is headquartered. A lender or employer based in another state that uses AI to make decisions about Colorado residents carries the same obligations as a Colorado-based organization. Because Regulation 10-1-1 and SB 26-189 share significant overlap in governance activities, organizations already managing AI documentation, bias testing, and vendor oversight for one are well positioned to extend that same program to the other, all inside a single Trustible governance program.