June 17, 2026 · Article

Colorado Built a Landmark AI Law, Then Dismantled It Before It Took Effect

Colorado built the first comprehensive AI law in the United States, SB 24-205, a risk-management regime modeled on the EU AI Act, then repealed and replaced it before it ever took effect. The successor, SB 26-189, abandons high-risk classification, mandatory risk-management programs, annual impact assessments, and the duty of care in favor of a lighter disclosure-and-consumer-rights model, pulling Colorado toward the approach California has anchored. Organizations that spent 2024–2025 building toward the original framework were left holding impact-assessment and high-risk-classification work calibrated to a law that no longer exists.

Where the prior article framed AI regulation as fragmenting across states, Colorado shows it is also volatile, since a governance program can be invalidated not just by new obligations but by the reversal of the ones it was built for. The piece argues this is an architecture problem before a legal one: the organizations that absorbed the reversal as a readjustment rather than a write-off were the ones whose governance was built as adaptable operating infrastructure, with living system inventories, jurisdictional mapping, decision documentation, and a designated regulatory-change owner, none of it tied to any single statute. A static AI policy will not survive a dynamic regulatory environment. Part of the AI Governance Series, and a direct sequel to AI Governance Is Becoming a Multi-State Operating Model Problem.

← All posts