Colorado AI Governance — Trustible
Colorado Regulation 10-1-1 · Colorado AI Act (SB 26-189)

Colorado AI Governance

Colorado is the most active state legislature in the US on AI governance. Regulation 10-1-1 establishes insurance-specific AI requirements with annual certification obligations. The broader Colorado AI Act (SB 26-189) extends consumer protection requirements for high-risk AI across multiple sectors.

Requirement
What It Means
Written AI Governance Program
A documented program covering all AI systems in regulated insurance practices — not just a policy, but an operational process with defined roles and documentation standards.
Board-Level Accountability
Boards and C-suite executives engaged with AI risk, informed about significant AI systems, and accountable for program adequacy.
Bias Testing and Validation
Active testing for unfairly discriminatory outcomes across protected classes, with documented methodology and results available for regulatory examination.
Third-Party Vendor Oversight
Contractual and operational oversight of AI from vendors — insurers cannot delegate accountability for AI they use to the vendor.
Annual Compliance Certification
Regulated entities must certify compliance with the Commissioner of Insurance each year.
Requirement
What It Means
Impact Assessments
Deployers must complete impact assessments for high-risk AI systems before deployment and annually thereafter.
Consumer Notice
Consumers must be notified when a high-risk AI system is used in a decision that affects them.
Algorithmic Discrimination Prevention
Reasonable care must be taken to avoid algorithmic discrimination in high-risk AI outcomes.
Public Disclosure
Developers and deployers must publish statements describing the types of high-risk AI systems they make available or use.

How Trustible Supports Colorado Compliance

Compliance
Trustible Capability
AI Inventory
Centralizes all AI systems, models, and external data sources with ownership and assessment history.
Risk Management
Structured risk assessments evaluate each AI system for bias and discriminatory impact, with inherent and residual risk scoring and mitigation tracking.
Insights Taxonomies
Expert-curated risk categories address fairness, bias, and discriminatory outcomes with relevant incident data and mitigation options.
Model and Vendor Evaluations
AI-assisted analysis of vendor documentation surfaces transparency gaps for third-party AI and external data providers.
Reporting & Dashboards
Compliance reporting generates audit-ready evidence for regulatory review and supports annual certification requirements.

Your First 90 Days

Day 30: Inventory AI and External Data Sources

Identify and document all AI systems, external consumer data sources, algorithms, and predictive models in use within regulated business functions.

Day 60: Assess Bias and Discriminatory Risk

Launch structured bias and fairness assessments for each identified AI system. Document testing methodology and results.

Day 90: Operationalize and Certify

Connect AI governance workflows to internal policies and vendor oversight processes. Generate documentation for annual certification and regulatory audit readiness.

Colorado AI FAQs

The law specifies outcomes — no unfair discrimination — rather than prescribing specific testing methodologies. Regulated entities have flexibility in how they test, provided they can document methodology and results.

Regulation 10-1-1 established insurance-specific AI governance requirements. SB 26-189 establishes broader requirements for high-risk AI across multiple sectors. Organizations subject to both will find significant overlap in governance activities — all of which Trustible manages in a unified platform.

A developer is an organization that builds or substantially modifies a high-risk AI system before it goes to market. A deployer is an organization that uses a high-risk AI system to make, or as a substantial factor in making, a consequential decision about a consumer. The obligations differ by role. Developers must document the system's intended uses, known limitations, and risk mitigation measures, and share that documentation with deployers. Deployers must maintain a risk management program, conduct impact assessments, and notify consumers when AI plays a role in a decision about them. Many organizations hold both roles across their AI portfolio, building some systems in-house while deploying tools built by vendors elsewhere. Trustible's AI Inventory captures this distinction at the use case level, so governance activities route to the right obligations depending on whether your organization built the system or is using one built by a vendor.

A high-risk AI system is one that makes, or is a substantial factor in making, a consequential decision, meaning a decision with a material effect on a consumer's access to or terms for things like employment, education, lending, housing, healthcare, insurance, or legal services. The threshold isn't how advanced the technology is. It's whether the system's output meaningfully shapes an outcome that affects someone's life. A tool that screens job applicants before a human reviews them meets that bar. A general-purpose chatbot answering customer questions typically doesn't. Trustible's Insights Taxonomies and Risk Management module apply this test during intake, so systems that trigger consequential decisions get routed to the deeper risk and impact assessments SB 26-189 requires, while lower-impact systems move through faster.

Yes. Scope follows the impact, not the organization's address. Any developer or deployer doing business in Colorado, or whose AI system is used to make consequential decisions about Colorado consumers, falls under the law regardless of where the company is headquartered. A lender or employer based in another state that uses AI to make decisions about Colorado residents carries the same obligations as a Colorado-based organization. Because Regulation 10-1-1 and SB 26-189 share significant overlap in governance activities, organizations already managing AI documentation, bias testing, and vendor oversight for one are well positioned to extend that same program to the other, all inside a single Trustible governance program.

See How Trustible Operationalizes Colorado AI Compliance in a Unified Governance Program.

© 2026 Trustible