The Colorado AI Act Collapse: The 2026 Standards-Compliance Briefing on the SB 24-205 Repeal, the SB 26-189 ADMT Reset, and Why Physical Security AI Sits Outside the Consequential-Decision Perimeter
How the first comprehensive US state AI law collapsed before it took effect, what the SB 26-189 ADMT framework replaced it with, and why threat detection sits outside the consequential-decision perimeter.
The first comprehensive state AI law in the United States was repealed before it ever took effect. Here is what its collapse means for security buyers writing multi-year AI contracts.
For two years, the Colorado Artificial Intelligence Act was the law every other state legislature studied and every AI vendor's compliance team feared. Signed in May 2024 as the first comprehensive state framework for high-risk AI in the country, SB 24-205 imposed an EU-style obligation set on developers and deployers of systems making consequential decisions about people. Then, in the span of roughly six weeks in the spring of 2026, it fell apart: a federal court stayed enforcement, the U.S. Department of Justice joined a constitutional challenge, the state attorney general announced it would not enforce until rulemaking finished, and the legislature repealed the statute outright and replaced it with a narrower disclosure regime. The most-watched AI law in America never took effect.
This briefing is for security directors, risk officers, and procurement teams who are evaluating AI physical security platforms under multi-year contracts and need to understand what the Colorado reset actually changes. The short answer is that the regulatory ground shifted from a prescriptive risk-tier model toward transparency and consumer rights, and that threat-detection systems that identify objects and events sit largely outside the "consequential decision" perimeter both versions of the law were built around. The longer answer, which determines how a buyer should write a contract and structure a vendor's documentation obligations, is below.
What actually happened to the Colorado AI Act
The collapse of Colorado's AI Act was not a single event but a sequence, and the sequence matters because each step signaled a different failure mode that buyers should learn to read. Governor Jared Polis signed SB 24-205 on May 17, 2024, and did so "with reservations" stated plainly in his signing statement. He urged the sponsors to "significantly improve" the law before it took effect, and called on the federal government to enact preemptive legislation that would replace the bill he had just signed with a "cohesive federal approach." Signing a bill while publicly asking Washington to override it is not a vote of confidence. It was, in retrospect, the first crack.
The substantive design choice that drew the most criticism was that SB 24-205 regulated the results of an AI system's use, regardless of intent, importing a disparate-impact theory of algorithmic discrimination into a technology statute. Polis himself flagged this in the signing statement and asked the legislature to reexamine it. The original effective date was February 1, 2026. As that date approached and the promised "significant improvement" had not materialized, Polis called a special legislative session in August 2025. Lawmakers could not reach a compromise on amendments, so the session produced SB 25B-004, signed August 28, 2025, which did the only thing the legislature could agree on: it pushed the effective date to June 30, 2026.
Then the federal layer arrived. On December 11, 2025, the White House signed an executive order titled "Ensuring a National Policy Framework for Artificial Intelligence," establishing an AI Litigation Task Force inside the Department of Justice charged with challenging state AI laws in federal court on interstate-commerce and preemption grounds. On March 20, 2026, the White House released a National Policy Framework recommending that Congress broadly preempt state AI laws that impose "undue burdens." Colorado's first-in-the-nation statute was the most conspicuous target in the country.
The endgame was fast. On April 27, 2026, a federal magistrate judge stayed enforcement of the Colorado AI Act, with the DOJ aligned alongside a private constitutional challenge. The Colorado Attorney General, who held exclusive enforcement authority, announced it would not seek to enforce the law until it completed interpretive rulemaking. And on May 14, 2026, Governor Polis signed SB 26-189, which repealed and reenacted the statute entirely, swapping the high-risk and algorithmic-discrimination architecture for a narrower automated-decision-making-technology disclosure framework taking effect January 1, 2027. The law that defined the state-AI-regulation debate for two years was gone before its own delayed effective date.
Regulatory volatility is now a procurement variable, not a footnote
A security platform purchased on a three-to-five-year term will outlive the specific statute in force at signing. The Colorado sequence is the clearest possible demonstration: a buyer who built a compliance program around SB 24-205's impact-assessment obligations in early 2025 would have spent a year preparing for a regime that no longer exists. The durable lesson is not which Colorado framework won. It is that contracts should require the vendor to maintain documentation that travels across frameworks, because the framework will change. A vendor whose compliance posture is tied to one statute's checklist is a vendor whose posture expires.
The rise and fall, on one timeline
The two-year arc from first-in-the-nation statute to repeal compresses into six milestones. Read left to right, it is a map of how quickly the state AI regulatory landscape can move underneath a buyer who signed a long-term contract at any single point along it.
Two years from first-in-the-nation to repealed-before-effect
Every milestone that moved the regulatory ground under a long-term AI security contract.
Polis signs SB 24-205, the first comprehensive US state AI law, while urging federal preemption and a sponsor rewrite.
No compromise on amendments. SB 25B-004 pushes the effective date from Feb 1 to June 30, 2026.
White House executive order creates a DOJ AI Litigation Task Force to challenge state AI laws.
White House National Policy Framework urges Congress to preempt "undue burden" state AI laws.
Federal magistrate stays the Act; DOJ aligns with a constitutional challenge; the AG pauses enforcement.
SB 26-189 repeals the Act and installs an ADMT disclosure regime effective Jan 1, 2027.
What changed: SB 24-205 versus SB 26-189
The two laws answer the same question very differently. SB 24-205 was modeled on the European Union's risk-tier approach: classify a system as high-risk, then impose a prescriptive obligation set built around preventing algorithmic discrimination. SB 26-189 is a deliberate pivot away from that model toward transparency, disclosure, and consumer rights, with the attorney general as sole enforcer and no private right of action. The practical difference for any buyer is that the new law asks "did you tell the consumer and let them seek human review?" rather than "did you prove your system does not produce a discriminatory result?"
The Repealed Law vs. the Replacement, Side by Side
| Dimension | SB 24-205 (Repealed) | SB 26-189 (Effective Jan 1, 2027) |
|---|---|---|
| Core concept | "High-risk AI system" making a consequential decision | "Automated decision-making technology" (ADMT) that materially influences a consequential decision |
| Regulatory model | EU-style risk tiers plus algorithmic-discrimination duty (results-based, regardless of intent) | Transparency, disclosure, and consumer rights |
| Core obligation | Risk-management program, impact assessments, discrimination prevention | Technical documentation to deployers; clear consumer notice; post-adverse-outcome plain-language explanation within 30 days |
| Consumer rights | Disclosure and limited appeal | Access to data, correction of inaccurate data, meaningful human review and reconsideration after an adverse outcome |
| Enforcement | Attorney general; results-liability theory | Attorney general only, via Consumer Protection Act; 60-day cure period; no new private right of action |
| Recordkeeping | Program documentation | Developers and deployers retain compliance records for at least 3 years |
Note what survived the rewrite intact: the definition of a "consequential decision." Under both laws, that term is anchored to decisions about a person's access to, eligibility for, or compensation related to education, employment, housing, financial or lending services, insurance, health-care services, and essential government services. This is the perimeter that matters most for security buyers, because the entire weight of either statute only lands on systems that operate inside it.
Why threat detection sits outside the consequential-decision perimeter
The most important sentence in this briefing for a physical security buyer is this: a system that detects a drawn firearm, an unauthorized person in a restricted zone, a fall, or a vehicle in a no-park lane is not making a consequential decision about a consumer in the statutory sense. It is classifying an object or an event and routing an alert to a human. It is not determining whether a person gets a job, an apartment, a loan, an insurance policy, or a public benefit.
This is a definitional point, not a marketing one. Both versions of the Colorado law tether their obligations to "consequential decisions" affecting eligibility, access, or compensation across a fixed list of life domains. Threat-detection computer vision of the kind deployed for active-shooter, perimeter, loitering, and fall scenarios produces a signal that something is happening, not a judgment about who someone is or what they deserve. The original SB 24-205 reinforced the point from the other direction with an explicit carve-out: the act did not restrict anyone's ability to take immediate steps to protect an interest essential to the life or physical safety of a consumer. Life-safety response is the paradigm case the law was written to leave alone.
The replacement law, SB 26-189, narrows scope further by excluding entire categories of processing from its ADMT definition, including cybersecurity, fraud prevention, and tools used solely to organize or summarize information for human review. A threat-detection alert that a human security officer verifies before acting is closer to the "information for human review" pattern than to an autonomous eligibility determination. The architecture that keeps a security platform out of scope is the same architecture that makes it defensible: object-and-event detection, a human in the loop, and no personal-data profiling that scores individuals. IntelliSee's platform performs object, posture, and motion-pattern detection without facial recognition, without storing video, and without building consumer profiles, which is the configuration that sits cleanly outside the ADMT core.
Where physical security AI can cross into scope
The perimeter is not absolute. A system crosses toward "consequential decision" territory when it stops detecting events and starts scoring people in ways that gate access to a covered life domain. Examples worth flagging in a vendor evaluation: an AI that ranks individuals by a "risk score" to decide who is admitted to housing, a model that filters job applicants, or a video system repurposed to make automated employment or tenancy judgments. Pure threat detection that alerts a human is outside the core; algorithmic eligibility scoring of identified individuals is inside it. The line is whether the output decides a person's standing in education, employment, housing, finance, insurance, health care, or government benefits, not whether the system happens to use a camera.
Mapping common AI security use cases against the perimeter
Buyers do not evaluate "AI" in the abstract; they evaluate specific use cases on specific cameras. The cleanest way to apply the Colorado lesson is to sort each deployed capability into one of two buckets and document the reasoning. The grid below shows how the most common physical security functions fall out against the consequential-decision test that both Colorado laws share.
Outside the perimeter · Drawn-weapon detection
Firearm detection classifies a visible weapon in a frame and alerts a human responder. It makes no determination about a person's eligibility for any covered life domain. The original Act's life-safety carve-out is squarely on point.
Outside the perimeter · Perimeter and loitering
Unauthorized-access and loitering detection flag movement into a zone or persistence beyond a threshold. They are event signals routed to staff, not eligibility judgments about identified consumers.
Outside the perimeter · Fall detection
Fall detection is a posture-pattern safety function. It triggers a care response, which is the life-safety pattern the statute was drafted to protect rather than restrict.
Inside the perimeter · Eligibility scoring
A model that assigns individuals a risk score to gate housing admission, screen job applicants, or restrict access to a covered benefit is making or materially influencing a consequential decision. This is the ADMT core, and it carries the full disclosure and human-review obligation set.
Gray zone · Identity-linked access control
Access control becomes a closer call when it links to identity and conditions a person's entry to a covered domain such as employment or housing. Document the human-decision step and avoid automated identity profiling to keep the function on the right side of the line.
Architecture that keeps you out of scope
Object-and-event detection, a verified human-in-the-loop response, no facial recognition, no stored video, and no individual scoring. This is the configuration most defensible against any state's consequential-decision definition, and it is the IntelliSee design baseline.
The Colorado reset is a national signal, not a local one
It would be a mistake to read the repeal as Colorado simply getting cold feet. The same forces are acting on every state at once. The National Conference of State Legislatures reports lawmakers in 45 states introduced 1,561 AI-related bills in the first quarter of the 2026 session alone, already exceeding the total volume of AI bills introduced in all of 2024. The volume guarantees churn: many of those bills will conflict, many will be amended after passage, and some will be repealed before they take effect, exactly as Colorado's was.
The federal layer adds a second source of instability. The December 2025 executive order directed the Federal Trade Commission to issue a policy statement classifying state-mandated algorithmic-bias mitigation as a potential deceptive trade practice, and the March 2026 National Policy Framework asked Congress to preempt burdensome state AI laws outright. Whether Congress acts is genuinely uncertain, and early reporting suggests broad preemption is a difficult sell. But the direction of travel is unmistakable: a tug-of-war between state experimentation and federal preemption that will keep the compliance baseline moving for years. For a buyer, the takeaway is not to pick the winning framework. It is to assume the framework will change and to contract accordingly. The companion State-by-State AI Security Legislation Q2 2026 Tracker maintains the moving picture, and the EU AI Act compliance briefing covers the risk-tier model Colorado just walked away from.
What a security buyer should do now
The practical response to regulatory volatility is to make your vendor's documentation, not the current statute, the load-bearing part of your compliance posture. Documentation that describes intended uses, training-data categories, known limitations, and human-review instructions satisfies the surviving Colorado framework, maps onto the NIST AI Risk Management Framework, and would have satisfied the repealed law as well. That cross-framework documentation set is the asset that survives a repeal.
Concretely, a procurement team should require four things in writing. First, a use-case classification: for each deployed capability, whether it makes or materially influences a consequential decision, and the reasoning. Second, an architecture attestation: whether the system performs facial recognition, stores video, or builds individual profiles, since those are the features that pull a system toward scope. Third, a documentation commitment that the vendor will maintain technical documentation and at least three years of compliance records, mirroring SB 26-189's retention rule. Fourth, a change-notification clause requiring the vendor to flag material model updates and any new capability that could change the use-case classification. A vendor that can produce these is a vendor whose compliance posture does not expire when a legislature changes its mind.
The durable principle. The Colorado AI Act is gone, but the question it forced every buyer to ask is permanent: does this AI decide something consequential about a person, and can the vendor prove how it works? Threat detection that alerts a human and scores no one answers that question cleanly. Eligibility scoring of identified individuals does not. Build the contract around the answer, not around the statute. The IntelliSee team can walk a procurement team through this classification during a structured risk assessment.
Frequently asked questions about the Colorado AI Act repeal and physical security
Is the Colorado AI Act (SB 24-205) still in effect?
No. Governor Polis signed SB 26-189 on May 14, 2026, which repealed and reenacted the Colorado AI Act. Enforcement of the original law had already been stayed by a federal magistrate in April 2026, and the attorney general had announced it would not enforce the law pending rulemaking. SB 24-205's high-risk and algorithmic-discrimination framework never took effect. The replacement ADMT framework takes effect January 1, 2027.
Does Colorado's AI law apply to AI gun detection or perimeter security systems?
Generally no. Both the repealed law and SB 26-189 attach their obligations to systems that make or materially influence a "consequential decision" about a person's access to, eligibility for, or compensation in education, employment, housing, finance, insurance, health care, or essential government services. A system that detects a drawn firearm, an intrusion, or a fall and alerts a human is classifying an object or event, not deciding a person's standing in a covered domain. The original Act also included an explicit carve-out for steps taken to protect an interest essential to a person's life or physical safety.
What is the difference between SB 24-205 and SB 26-189?
SB 24-205 used an EU-style risk-tier model with a duty to prevent algorithmic discrimination based on outcomes regardless of intent. SB 26-189 replaces that with a narrower automated-decision-making-technology framework focused on transparency: technical documentation to deployers, clear consumer notice, a plain-language explanation within 30 days of an adverse outcome, and consumer rights to data access, correction, and meaningful human review. The attorney general is the sole enforcer under both; SB 26-189 adds a 60-day cure period and creates no new private right of action.
When could a physical security AI system fall inside the law's scope?
When it stops detecting events and starts scoring identified individuals in a way that gates a covered life domain. Examples include an AI that ranks people to decide housing admission, screens job applicants, or restricts access to a public benefit. Pure threat detection that routes an alert to a human is outside the core; automated eligibility scoring of identified individuals is inside it. The deciding factor is whether the output determines a person's standing in a covered domain, not whether the system uses a camera.
How should a multi-year AI security contract address regulatory change?
Require cross-framework documentation rather than statute-specific compliance. Ask the vendor for a use-case classification, an architecture attestation covering facial recognition, video storage, and individual profiling, a commitment to retain technical and compliance records for at least three years, and a clause requiring notice of material model updates or new capabilities that could change the classification. Documentation that satisfies the NIST AI RMF and the surviving Colorado framework will travel across whatever replaces it.
Will the federal government preempt state AI laws like Colorado's?
It is uncertain. A December 2025 executive order created a DOJ task force to challenge state AI laws, and a March 2026 White House framework asked Congress to preempt laws that impose "undue burdens," but broad federal preemption requires congressional action and early reporting suggests it is a difficult sell. The practical posture is to assume continued volatility, with state experimentation and federal preemption efforts pulling in opposite directions, rather than to bet on a single outcome.
Does IntelliSee perform facial recognition or store video?
No. IntelliSee performs object, posture, and motion-pattern detection. It does not perform facial recognition, does not store video, and does not build individual consumer profiles. Detection is based on what something is, such as a drawn firearm or a person in a restricted zone, rather than who someone is. This architecture is what keeps the platform outside the consequential-decision core that both Colorado frameworks were written to govern.
Continue the research
This briefing covers the Colorado reset and its lesson for physical security buyers. For deeper reading on the surrounding regulatory landscape and the architecture that keeps detection outside scope:
- State-by-State AI Security Legislation: Q2 2026 Tracker — the actively maintained map of state AI bills and effective dates, including the 1,561-bill Q1 2026 surge driving regulatory churn.
- The EU AI Act and Physical Security AI — the risk-tier model Colorado adopted and then abandoned, and how it treats security use cases.
- The NIST AI Risk Management Framework for Physical Security — the cross-framework documentation architecture procurement teams should anchor to instead of any single statute.
- Biometric Privacy Compliance for AI Physical Security — how facial-recognition and biometric processing pull a system toward regulatory scope, and why object-level detection avoids it.
- How IntelliSee works — the object-and-event detection architecture, human-in-the-loop response, and privacy-by-design posture referenced throughout this briefing.
More intelligence like this
New IntelliSee research drops monthly at most. Subscribe and get the next sector playbook, technology briefing, or threat intelligence report in your inbox the day it ships.
Request a Risk Assessment
Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.
Request a Risk Assessment