Status: Enacted — SB25-143 cleared the Colorado General Assembly on April 4, 2025, and was signed by Governor Jared Polis. The law extends and modifies Colorado's prior moratorium on school facial recognition technology (FRT), partially lifting the prohibition for narrowly defined school safety and education purposes while extending the prohibition past its previous July 1, 2025 sunset for all other uses.
Bill Number: Colorado SB25-143 — “Extend Prohibition on School Facial Recognition”
Jurisdiction: Colorado
Category: Biometric Privacy / School Security Technology Regulation
Industries: K-12 Public Education, Higher Education, AI Physical Security Vendors
Enacted Date: Signed in 2025 by Governor Jared Polis
Effective Date: Effective per the bill's enacting clause (provisions tied to the 2025-2026 school year and forward)
Summary: Colorado SB25-143 is the first state law in the United States to affirmatively authorize school district use of facial recognition technology under a structured safety-and-privacy framework. Colorado had previously imposed a moratorium on FRT in K-12 schools in 2022, with a sunset of July 1, 2025. SB25-143 keeps the prohibition in place as the default, but carves out three narrowly defined authorized uses for FRT, requires explicit opt-in consent from individuals or their parents/guardians, caps biometric retention at 18 months, and requires each school district to adopt a written policy governing FRT use before deploying any such system.
The law is consequential well beyond Colorado. It represents the emerging compromise position in state-level FRT debate: rather than outright bans (the New York model) or unrestricted authorization (the prior status quo in most states), SB25-143 adopts a permissive-but-bounded framework that authorizes FRT for specific, articulable safety use cases while imposing real consent, retention, and policy guardrails. Other states considering FRT legislation in 2026 and 2027 are likely to look to SB25-143 as a template.
Authorized Uses (Narrowly Defined):
- Threat-of-violence alerts: Alerting authorized staff to the presence on school grounds of an individual who has made a credible threat of violence against the school.
- Missing children: Helping to immediately locate missing children on school grounds.
- Court-ordered exclusions: Providing alerts to staff when specific individuals are prohibited from entering school grounds under a court order or district determination (e.g., custody orders, restraining orders, expulsions).
- Educational purposes: Use approved by the local school board for narrowly defined educational applications.
Privacy Guardrails:
- Opt-In Consent: Schools must obtain explicit, opt-in consent from individuals (or parents/guardians of minors) before processing biometric identifiers. A standalone consent form is required — consent cannot be bundled into a broader district notice.
- Consent Form Disclosures: The consent form must clearly explain the purpose of the biometric processing and the retention period.
- Retention Cap: Schools may not retain biometric identifiers for more than 18 months.
- Local Policy Mandate: Each school district must adopt a written FRT policy before deploying any such system, with the policy governing authorized personnel, use cases, retention, and incident response.
- Authorized Personnel Only: Only school administrators and law enforcement officials designated under the local policy may process FRT data, and only in response to an articulable and significant threat against the school.
Continuing Prohibition: All other uses of FRT in Colorado K-12 schools remain prohibited under the extended moratorium. The statute does not authorize general surveillance, attendance taking, classroom monitoring, behavior analytics tied to identity, or any retention or sharing of biometric identifiers outside the authorized safety use cases.
Affected Entities: All Colorado public school districts (K-12), charter schools, and BOCES (Boards of Cooperative Educational Services). Higher education institutions are not directly governed by SB25-143 but should monitor as the state legislature has indicated FRT regulation in higher education may follow.
IntelliSee Relevance: Adjacent — And Strategically Important. IntelliSee does not use facial recognition, biometric identification, or unique-individual identity tracking in any of its visual intelligence products. The platform's privacy-preserving architecture places it entirely outside the scope of SB25-143's prohibition and its consent, retention, and local-policy requirements. For Colorado school districts evaluating AI security platforms, this distinction is operationally significant:
- No consent burden: IntelliSee does not collect, process, or store biometric identifiers. Districts deploying IntelliSee are not required to obtain opt-in FRT consent from students or families.
- No retention compliance burden: The 18-month biometric retention cap does not apply to IntelliSee because no biometric identifiers are generated.
- No FRT policy adoption prerequisite: Districts may deploy IntelliSee without first adopting the formal FRT policy SB25-143 requires for facial recognition systems.
- Authorized safety use cases without identity processing: IntelliSee provides the safety-monitoring outcomes SB25-143 contemplates (threat-of-violence detection via AI weapon detection, unauthorized-access alerts, aggressive-behavior monitoring) without crossing into biometric identification.
Colorado security directors, superintendents, and school boards comparing vendors in 2026 should map each vendor's data processing surface against SB25-143's three-category authorization framework and ask explicitly whether the platform generates biometric identifiers, processes facial geometry, or persists identity-linked data. See the 2026 Biometric Privacy Compliance Briefing for cross-jurisdictional vendor evaluation context.
Related Legislation & Resources
- Colorado AI Act Repeal and Replace (SB 26-189, 2026)
- Colorado Healthcare Workplace Violence Incentive Payments (SB 25-166)
- California AI Transparency Act (AB 853, 2026)
- California Data Broker Disclosure Expansion (SB 361, 2026)
- EU AI Act High-Risk Systems Deadline (Annex III, Revised May 2026)
- Biometric Privacy Compliance for AI Physical Security (2026)
- State-by-State AI Security Legislation: Q2 2026 Tracker