Colorado Seeks Public Input on High-Risk AI Rulemaking
The state is refining implementation of the AI Act to prevent algorithmic discrimination in critical life opportunities.
Colorado is seeking public input on the implementation of proposed artificial intelligence regulations ahead of a formal rulemaking hearing. The state is moving to establish specific guidelines for the deployment of high-risk AI systems to prevent algorithmic discrimination.
At the center of the effort is the AI Act (SB24-205), passed by the Colorado General Assembly. The law mandates that both developers and deployers of high-risk AI systems implement comprehensive risk management frameworks. This "duty of reasonable care" ensures that AI tools do not unfairly disadvantage individuals based on protected characteristics. As the state enters the rulemaking phase, legal firms, including Ogletree Deakins, have alerted clients to the importance of participating in the comment period to influence the final regulatory language.
The Focus on High-Risk Systems
Colorado's regulatory approach reflects a growing trend of state-level AI oversight in the United States. Rather than attempting to regulate all forms of machine learning, the state is focusing specifically on "high-risk" systems. These are defined as AI applications that could significantly impact critical life opportunities, including employment, housing, and healthcare. By targeting these specific sectors, the state aims to mitigate the risk of automated bias in areas where a negative decision can have a profound effect on a citizen's quality of life.
Industry Implications
As one of the first comprehensive state-level AI laws in the U.S., Colorado's final rules are expected to serve as a blueprint for other states considering similar legislation. For companies, the implications are significant; the requirement to maintain risk management frameworks creates a new compliance burden for any entity operating within the state that utilizes high-risk AI. The outcome of the current rulemaking process will determine the exact technical and administrative hurdles companies must clear to remain compliant.
Next Steps
Stakeholders are encouraged to submit comments during the current window to shape the final rules. The state will then move toward a formal rulemaking hearing to finalize the guidelines. While the framework of SB24-205 is set, the specific operational requirements for what constitutes a "reasonable" risk management framework remain the primary point of contention and discussion for the industry.