Skip to main content
Beyond High-Risk AI: Navigating Colorado's SB 189 Repeal and the New Automated Decision-Making (ADM) Liability for Legal Deployments
HyperCounsel Team
9 min read

Beyond High-Risk AI: Navigating Colorado's SB 189 Repeal and the New Automated Decision-Making (ADM) Liability for Legal Deployments

Learn how Colorado's SB 189 repeal impacts automated decision-making liability for law firms.

The regulatory landscape for artificial intelligence in the United States has taken a dramatic turn. In a surprise legislative shift, Colorado lawmakers repealed Senate Bill 24-205 (originally known as the colorado artificial intelligence act) before its initial implementation, replacing it entirely with Senate Bill 26-189. This new legislative framework shifts the regulatory focus from broad "high-risk AI" to automated decision-making technology (ADMT) that directly impacts consumer life opportunities.

For law firms and corporate legal departments, this regulatory pivot fundamentally alters how legal AI and automated tools must be vetted, contracted, and deployed. 65% of law firms plan to replace or significantly upgrade their AI vendor contracts by 2027 due to new regulatory liabilities, making immediate compliance preparation a operational survival skill rather than a future checkbox.

Navigating these shifts requires a deep understanding of how risk, liability, and contractual responsibilities are allocated under the new Colorado framework. Partnering with a specialized legal services platform like HyperCounsel helps firms rapidly review their software agreements and deploy compliant, automated workflows without interrupting daily practice operations.

Table of Contents

The Evolution: Repealing the Colorado Artificial Intelligence Act for SB 189

The initial colorado artificial intelligence act (SB 24-205) was heavily criticized for imposing broad, burdensome risk management programs and impact assessment obligations on developers and deployers alike. In response to these concerns, the Colorado legislature passed SB 26-189.

This new law repeals the previous act's framework. Instead of a sweeping, precautionary regulatory model, SB 26-189 establishes a narrower, transparency-based compliance structure. It focuses strictly on the active deployment of automated processes that yield discriminatory outcomes, eliminating the general "duty to use reasonable care" to prevent algorithmic discrimination and replacing it with specific documentation, notice, and relative-fault rules.

Legislative Metric Repealed CAIA (SB 24-205) Retooled SB 26-189 Framework
Primary Focus Broad "High-Risk AI" systems Automated Decision-Making Technology (ADMT)
Risk Management Comprehensive assessment programs Target transparency & operational disclosures
Liability Allocation Shared joint liability concepts Fault-based liability allocation
Effective Date Originally planned for 2026 January 1, 2027

Infographic: Beyond High-Risk AI: Navigating Colorado's SB 189 Repeal and the New Automated Decision-Making (ADM) Liability for Legal Deployments

To fall under the scope of Colorado's new framework, a system must meet the definition of Automated Decision-Making Technology (ADMT) and be used to make or facilitate "consequential decisions."

According to SB 26-189, ADMT is any technology that uses machine learning, statistics, or artificial intelligence to make or facilitate decisions. A "consequential decision" is a decision that has a material legal, financial, or similarly significant effect on a consumer's access to, or the cost of, critical life opportunities. In a professional legal environment, several common software applications trigger these definitions.

A lawyer reviewing data-driven software tools on a dual-screen monitor setup

Automated Employment and Hiring Tools

If your law firm uses AI-driven screening software to filter job applicants, evaluate resumes, or analyze video interviews, you are deploying ADMT. Because employment is explicitly categorized as a consequential decision, these tools fall directly under the statutory compliance guidelines.

Client Intake and Credit Qualification

Many modern firms utilize automated assessment intake forms to screen potential clients. If these algorithms automatically decline prospective clients based on financial history, credit scoring, or geographic risk models without human oversight, the system is facilitating a consequential decision regarding access to professional services.

Case Valuation and Settlement Algorithms

In insurance defense or personal injury practices, utilizing predictive AI to automatically determine settlement value ranges or qualify case viability may cross into ADMT territory if the tool outputs direct, binding recommendations that dictate consumer access to restitution or legal solutions.

The New Fault-Based Liability Framework

One of the most consequential changes under SB 26-189 is the shift to a relative fault-based liability framework for state antidiscrimination violations. If an automated decision-making tool produces a discriminatory outcome, liability is allocated between the "developer" (the vendor who built the tool) and the "deployer" (the law firm or business utilizing it).

Under this relative-fault model, a deployer can defend itself from state enforcement actions by proving it fully complied with all operational duties, relied in good faith on the developer's documentation, and did not misuse or modify the software. If a firm operates outside the developer's designed parameters or ignores warning signs of bias, the weight of liability shifts back to the firm.

Voiding Indemnification Clauses and Mandating Contract Audits

Before the repeal of the original colorado artificial intelligence act, tech vendors frequently used broad indemnification clauses to shift all legal responsibility for algorithmic discrimination onto the end-user. SB 26-189 fundamentally disrupts this practice.

The new law voids any contract provision that attempts to indemnify a developer or deployer for their own discriminatory acts when using or providing ADMT. Consequently, firms cannot rely on boilerplate SaaS agreements to shield themselves from regulatory liability.

Law firms must immediately review and audit current vendor agreements. Contracts must be updated to clearly delineate the technical capabilities of the developer's system, ensure the developer provides adequate training documentation, and define joint responsibilities in accordance with the relative-fault standards of SB 26-189.

The Four Operational Duties for Deployers

For law firms deploying ADMT, maintaining immunity from relative-fault liability requires complete adherence to four key operational obligations.

  • Developer Documentation Review: Deployers must request, review, and retain technical documentation provided by the ADMT developer. This documentation must prove the system was designed, tested, and validated to minimize the risk of algorithmic discrimination.
  • Deployer Transparency: Firms must publish a clear, easily accessible privacy policy or disclosure on their website indicating that they utilize automated decision-making technologies, detailing the scope of their use, and explaining how decisions are reached.
  • Consumer Notice: Before or at the time an automated system is introduced to perform a consequential decision (such as during client intake or employment application submission), the consumer must receive a specific, written notice of its deployment.
  • Post-Adverse Outcome Disclosure: If an adverse decision is made against a consumer utilizing an ADMT system, the firm has 30 days to provide a detailed explanation to the consumer. This explanation must outline the factors that led to the determination and provide instructions on how the consumer can request a human review of the decision.

Enforcement, the Cure Period, and Penalties

Enforcement of the new framework rests strictly in public hands. There is no private right of action under SB 26-189, meaning individual consumers or job applicants cannot sue your firm directly in court for statutory violations of this act.

Instead, the Colorado Attorney General holds exclusive authority to enforce compliance under the Colorado Consumer Protection Act. Violations are treated as deceptive trade practices, exposing non-compliant firms to steep civil penalties.

Crucially, the law includes a temporary "right to cure" provisions for early infractions, allowing businesses to correct compliance failures within a set period after receiving an official notice of violation. However, this cure period is scheduled to sunset, meaning firms must have fully audited, reliable operational protocols operational by the January 1, 2027 deadline.

Implementation Checklist: Preparing for the 2027 Effective Date

To prevent disruption and insulate your practice from structural liability, legal operators should initiate an internal compliance program immediately.

Phase Action Item High-Level Steps Done
Phase 1 Inventory Systems Map all internal intake, screening, evaluation, and hiring software to identify potential ADMT. [ ]
Phase 2 Contract Audits Review and renegotiate terms with software vendors to remove invalid indemnification clauses. [ ]
Phase 3 Obtain Docs Collect and analyze the required technical testing and bias validation reports from your ADMT developers. [ ]
Phase 4 Consumer Notices Draft and integrate consumer notices and automated 30-day adverse outcome letters into workflows. [ ]
Phase 5 Staff Training Educate intake specialists, hiring managers, and IT personnel on the correct parameters for ADMT usage. [ ]

Take the Next Step

Adapting your practice to the sweeping changes of Colorado's SB 189 requires clear insight, specialized technical validation, and precise legal drafting. Attempting to draft boilerplate policies or relying on standard tech-vendor terms introduces severe regulatory risk to your firm.

HyperCounsel helps law firms streamline their compliance efforts with reliable legal services and predictable pricing. By assessing your existing software stack and auditing vendor contracts, our partner network ensures your practice meets Colorado's strict 2027 structural guidelines without sacrificing efficiency.

Protect your business, improve your operational security, and ensure seamless transition to compliant automated technology. Book a Demo with HyperCounsel today to review your contract frameworks and set up a robust compliance roadmap.


This article provides general information and is not legal advice.

Frequently Asked Questions

What is the effective date of Colorado's SB 189?

The provisions of SB 26-189, which repeals the former colorado artificial intelligence act and establishes the new ADMT framework, will take effect on January 1, 2027.

Does SB 189 create a private right of action for individuals?

No. SB 26-189 does not grant a private right of action to individuals. The Colorado Attorney General holds the exclusive authority to enforce the rules and file actions against non-compliant entities.

How does the new liability framework differ from the repealed CAIA?

The repealed CAIA imposed a general duty of reasonable care and joint liability frameworks. The new SB 26-189 establishes a relative fault-based liability framework, allowing users (deployers) to defend themselves by proving they satisfied operational duties and relied in good faith on developer documentation.

Firms must carefully assess and update indemnification, developer compliance warranties, and data usage clauses. Any contract provision attempting to indemnify a party for their own discriminatory acts or use of skewed automated data is considered void under the law.

Related Articles