shipping production AI · since 2026 NAICS 541330 / 541511 / 541512 / 541519  ·  CMMC-aware
Refinery Report / Colorado AI Act / post · ntechs
Colorado AI ActAI GovernanceFinancial ServicesFintech

Colorado AI Act for Banks and Fintechs: What SB 26-189 Requires Before January 2027

Colorado SB 26-189 replaced the original AI Act and takes effect January 1, 2027. Here is what banks, credit unions, mortgage lenders, and fintechs need to know: which AI systems are in scope, practical exemptions for AML and fraud tools, and the four compliance obligations the new law imposes.

D
By the DSE practice team
Operator-led practice · how we research & review
September 1, 2026
16 min · 3,435 words

By the DSE practice team · published September 1, 2026 · reviewed September 1, 2026

Colorado Senate Bill 26-189, which replaced the original Colorado AI Act and takes effect January 1, 2027, is the first US state AI law to impose consumer-notice and human-review obligations specifically on financial services AI at a general statutory level. Banks, credit unions, mortgage lenders, and fintechs using AI to make or materially influence consequential decisions about Colorado consumers are in scope. The statute requires four core compliance actions: a public website disclosure listing covered AI systems, advance consumer notice before AI drives a consequential decision, a post-adverse-outcome notice within 30 days, and a meaningful human-review process on consumer request. Practical exemptions carve out AML, fraud-prevention, sanctions screening, and identity-verification tools regardless of charter type. The Attorney General has stated he will not enforce the statute until implementing rules are finalized, so the enforcement calendar is open, but the statute itself goes live January 1, 2027, and the preparation window is now.

This guide explains what SB 26-189 requires of financial institutions, which AI systems are in scope and which are exempt, how the four obligations work in practice, and how the Colorado law intersects with SR 26-2 model risk guidance and NIST AI RMF 1.0.

What SB 26-189 changed from the original Colorado AI Act

The original Colorado AI Act, SB 24-205 signed in May 2024 and scheduled to take effect in 2026, imposed mandatory impact assessments, annual reporting obligations to the Attorney General, and a broad algorithmic-discrimination-prevention duty. Those requirements generated significant compliance-cost concern from financial institutions, employers, and technology companies.

In May 2026, Colorado replaced SB 24-205 entirely with SB 26-189. The legislature stripped out the mandatory impact assessments and the annual AG reporting requirement. The new law is narrower in its obligations and more focused on consumer transparency and consumer rights: knowing when AI is used, receiving a notice when AI produces an adverse outcome, being able to request human review, and having records retained for three years.

The other material change is the exemption structure. The original SB 24-205 offered a broad exemption for financial institutions subject to examination by a federal or state prudential regulator whose guidance was substantially equivalent to the Colorado Act. SB 26-189 eliminates that blanket exemption. Banks and credit unions are in scope for the statute’s consumer-facing obligations, though the lighter compliance burden under the new law substantially reduces the practical impact of that structural change. What the new statute does preserve are practical use-case-specific exemptions: AML and BSA-compliance tools, sanctions screening, fraud prevention, and identity verification are excluded from the definition of covered consequential-decision AI, and those exclusions apply to any institution regardless of charter.

Which financial institutions and AI systems are in scope

SB 26-189 applies to developers and deployers of automated decision-making technology used in consequential decisions. A consequential decision is one that has a material effect on a consumer’s access to, or the cost of, financial services, credit, insurance, housing, employment, or education, among other named domains. For financial-services firms, credit underwriting, loan pricing, account-opening approvals, insurance underwriting, and mortgage qualification decisions are the clearest cases in scope.

The developer-deployer distinction matters operationally. For financial institutions using a vendor-provided credit-scoring model, the vendor is the developer under the statute and the financial institution is the deployer. The deployer carries the consumer-facing obligations, meaning the bank or fintech is responsible for the website disclosure, consumer notice, adverse-outcome notice, and human-review process, even if the underlying model is built and maintained by a third party. That vendor relationship must be addressed in vendor contracts: the institution needs the right to obtain the information required to support a compliant human-review process and to respond to a consumer request with more than a vendor deflection.

Non-bank lenders and fintechs that are not subject to substantive prudential AI oversight have no institutional-level exemption pathway under SB 26-189, unlike under the original law. They are in scope in the same way as a depository bank. The exemptions that help them are the use-case exemptions for fraud, AML, sanctions, and identity tools, not an institutional status.

The Colorado AI Act scope matrix for financial services AI

AI Use Case SB 26-189 Status Basis
Credit underwriting, scoring, creditworthiness assessment In scope Consequential decision over access to financial services
Loan pricing and rate-setting for individual consumers In scope Consequential decision over cost of financial services
Mortgage qualification and denial In scope Consequential decision over access to housing credit
Account-opening approval or denial In scope Consequential decision over access to financial services
Insurance underwriting and premium pricing for individuals In scope Consequential decision over access to or cost of insurance
Fraud detection and fraud-prevention tools Exempt Statute expressly exempts fraud-prevention AI
AML and BSA transaction monitoring Exempt Statute expressly exempts AML-compliance AI
Sanctions and OFAC screening Exempt Statute expressly exempts sanctions-screening AI
Identity verification and KYC Exempt Statute expressly exempts identity-verification AI
Internal operational AI with no consumer-facing decision effect Out of scope Does not produce a consequential decision about a consumer
Marketing personalization that does not affect terms or access Out of scope Does not constitute a consequential decision

The table reflects the statute’s structure as enacted in May 2026. Precise classification of any specific AI system is the output of a real assessment conducted with qualified legal counsel. The exemption categories are real statutory carve-outs, not practitioner-derived assumptions, but their application to any given system depends on how the system is used and what the implementing rules ultimately say.

The four compliance obligations under SB 26-189

Website disclosure. Deployers must maintain a publicly accessible statement on their website identifying each high-risk AI system used in consequential decisions and describing how the deployer manages the risk of algorithmic discrimination. This is a standing disclosure that must be updated when covered AI systems are added or changed. Practically, this means maintaining a current AI inventory with the fields necessary to support the disclosure: system name or category, use case, and how the institution oversees discrimination risk.

Advance consumer notice. Before an AI system materially influences a consequential decision about an individual consumer, the deployer must notify the consumer that AI will be used. The form and content of this notice will be further defined in the AG’s implementing rules. At a minimum, it appears to require a clear, affirmative statement rather than a buried disclosure in account terms. For online loan applications and account-opening flows, this means a conspicuous pre-decision notice, not a general terms-and-conditions reference.

Post-adverse-outcome notice. When an AI system produces an adverse outcome, the deployer must notify the affected consumer within 30 days. The notice must include enough information for the consumer to understand that AI influenced the decision and what the significant factors were. This obligation is structurally analogous to the adverse-action notice requirements under ECOA and Regulation B, which already require specific reason codes for AI-assisted credit decisions. For institutions that have already built ECOA-compliant adverse-action logic, the Colorado obligation is additive content, not a new architecture. For institutions that have not, it is a reason to address both simultaneously.

Meaningful human review on request. A consumer who receives an adverse outcome from an AI-influenced decision has the right to request human review of that decision. The deployer must provide a process for that review and must have qualified personnel capable of conducting it. This is the obligation that exposes the governance gap in institutions that have deployed AI credit decisions without a parallel human-review capacity: if the only person who can interpret the AI’s output is an engineer, the human-review process will not satisfy the statute’s intent, and the implementing rules are expected to define what “meaningful” requires in more detail.

Record retention. Deployers must retain records sufficient to demonstrate compliance for at least three years. That includes the AI systems in use, the disclosures made, the notices sent, and the human reviews conducted.

How Colorado AI Act obligations intersect with SR 26-2 and NIST AI RMF

SR 26-2, the interagency model risk management guidance issued jointly by the Federal Reserve, OCC, and FDIC in April 2026, is the current supervisory standard for US bank model risk. SR 26-2 applies a risk-based, principles-driven approach to statistical and machine-learning models, and it explicitly excludes generative AI and agentic AI from its model-risk scope. It does not address consumer-notice obligations, post-adverse-outcome disclosure to consumers, or the human-review-on-request right that the Colorado Act requires. SR 26-2 compliance and Colorado AI Act compliance are not the same thing, and a bank that treats its SR 26-2 documentation as satisfying the Colorado Act has a gap.

NIST AI RMF 1.0, the voluntary federal framework organized into GOVERN, MAP, MEASURE, and MANAGE functions, is useful structuring language for the Colorado readiness work. The MAP function, which establishes context and classifies risk, is where the scope analysis and AI inventory that Colorado requires would sit. The GOVERN function, which covers accountability, policy, and oversight structure, is where the human-review process and disclosure obligations would be anchored in the institution’s governance framework. NIST AI RMF does not itself create a Colorado AI Act compliance posture, but an institution using NIST as its organizing language already has the inventory and governance infrastructure the Colorado work builds on.

For institutions that have already built a fair lending model validation framework for AI credit decisions, the intersection is direct: fair lending testing and ECOA adverse-action documentation are both prerequisites for, and components of, a defensible Colorado AI Act posture for credit AI. The institution that already has disparate-impact analysis, explainability artifacts, and adverse-action reason-code logic is not starting the Colorado work from zero.

A four-step readiness sequence before January 2027

The statute takes effect January 1, 2027. The AG is developing implementing rules before enforcement begins, but the statutory obligations are live on that date regardless of whether the rules are final. The prudent approach is to treat January 1 as the compliance target and the rulemaking as supplemental guidance that will refine implementation details.

Step 1: Complete a scope inventory. Identify every AI system used in decisions about Colorado consumers that plausibly constitutes a consequential decision. Apply the exemption categories: remove AML, fraud, sanctions, and identity-verification tools from the list. The result is the list of systems that must be covered by the website disclosure and the consumer-notice program. The AI regulatory crosswalk is a structured starting point for mapping each AI system to the regulatory regimes, including the Colorado AI Act, that govern it.

Step 2: Build the website disclosure. Draft and publish the statutory disclosure for each in-scope system. Legal counsel should review the disclosure before publication. The disclosure should be updated each time a covered system is added, changed significantly, or retired.

Step 3: Design the consumer notice and adverse-outcome notice workflows. Map the in-scope AI decision points to the customer-facing interface. Identify where an advance notice must appear and design the post-adverse-outcome notice content and delivery mechanism. For institutions with existing ECOA adverse-action workflows, the Colorado adverse-outcome notice is an additive layer on a process that already exists.

Step 4: Stand up a qualified human-review process. Identify who is responsible for human reviews of adverse AI-influenced decisions, what that review looks like operationally, and how a consumer request for review is routed and resolved. The process must be documented, tested, and staffed before January 1.

What this guide is / What it is not

What it is: a practitioner orientation for US banks, credit unions, mortgage lenders, and fintechs on Colorado SB 26-189 scope, the four compliance obligations, and how the statute intersects with SR 26-2 and NIST AI RMF.

What it is not: legal advice, a compliance certification, a legal determination that any specific AI system is or is not in scope, or a guarantee of any regulatory or enforcement outcome. DSE prepares organizations for audit and assessment; it does not certify, and it does not guarantee any regulatory or exam outcome. The AG’s implementing rules will clarify several open questions, and the application of the statute to any specific use case requires qualified legal counsel.

FAQ

Does the Colorado AI Act apply to banks and credit unions?

Yes. Colorado SB 26-189 removed the blanket prudential-regulator exemption that appeared in the original SB 24-205. Banks and credit unions are in scope for the statute’s consumer-facing obligations, including the website disclosure, advance consumer notice, post-adverse-outcome notice, and human review on request, for AI systems used in consequential decisions about Colorado consumers. The compliance burden is substantially lighter than the original law: mandatory impact assessments and annual AG reporting are gone. Practical exemptions remain for AML, fraud prevention, sanctions screening, and identity verification tools.

Which financial services AI systems are exempt from the Colorado AI Act?

Colorado SB 26-189 expressly exempts AI used for fraud prevention, AML and BSA compliance, sanctions and OFAC screening, and identity verification from the definition of covered consequential-decision AI. These exemptions apply regardless of institutional charter. AI used for credit underwriting, loan pricing, account-opening decisions, mortgage qualification, and insurance underwriting is in scope and carries the four compliance obligations: website disclosure, advance consumer notice, adverse-outcome notice within 30 days, and human review on request.

When does Colorado SB 26-189 take effect and will it be enforced?

Colorado SB 26-189 takes effect January 1, 2027. The Colorado Attorney General has stated he does not intend to enforce the statute until after implementing rules are finalized. As of September 2026, those rules are not final, so the enforcement timeline remains open. The statutory obligations go live on January 1, 2027 regardless of rulemaking status, and treating that date as the compliance target is the prudent approach.

How does the Colorado AI Act differ from SR 26-2 model risk management?

SR 26-2, the April 2026 interagency model risk management guidance from the Federal Reserve, OCC, and FDIC, is a supervisory standard for bank model risk covering model development, validation, and governance. It does not require consumer notice, post-adverse-outcome disclosure to consumers, or a human-review process accessible to individual consumers. SR 26-2 and Colorado SB 26-189 address different risk dimensions, and a bank’s SR 26-2 documentation does not satisfy the Colorado Act’s consumer-facing obligations. For the full treatment of SR 26-2’s scope and the generative AI carve-out, see SR 26-2 vs SR 11-7: what changed for AI model risk management.

What is the human review requirement under the Colorado AI Act?

Colorado SB 26-189 gives consumers the right to request human review of an adverse AI-influenced decision. The deploying institution must provide a process for that review conducted by qualified personnel. The implementing rules will define what meaningful human review requires. Institutions using AI credit or underwriting decisions without a parallel human-review capacity need to build that process before the statute takes effect. For institutions with existing ECOA adverse-action workflows, the Colorado human-review right is an additive layer on processes that partially overlap with the statutory requirement.

The Bottom Line

Colorado SB 26-189 is the first general US state AI statute to impose consumer-notice and human-review obligations specifically on financial services AI at a statutory level. The original law’s most burdensome features are gone: no mandatory impact assessments, no annual reporting to the AG. What remains is a transparency and consumer-rights framework: tell consumers AI is being used before a consequential decision, tell them what happened within 30 days of an adverse outcome, let them request a qualified human review, and keep records for three years. AML, fraud-prevention, sanctions-screening, and identity-verification tools are exempt. The rest of financial services AI, including credit underwriting, pricing, and account decisions, is in scope.

The effective date is January 1, 2027. The four-step readiness sequence, inventory in-scope systems, build the website disclosure, design the notice workflows, and stand up a human-review process, is achievable in the window available, but it requires starting now. The AG’s implementing rules will add specificity; they are not an excuse to wait.


For a starting point on inventorying which of your AI systems are in scope and which regulatory regimes govern each one, the AI governance checklist provides the fields and the framework-mapping structure a compliance team can use before a readiness engagement. When your institution is ready to build an audit-ready posture across the Colorado Act, NIST AI RMF, and your federal supervisory obligations, the banking AI governance engagement starts with a readiness assessment that maps where each in-scope system stands today.

Key facts

Read next · AI Security & Governance

P
Founder · Principal Engineer
Data & AI engineer · 10+ yrs hands-on

Writes most of the long-form here. Lives in the codebase. Active on GitHub and LinkedIn.

§ Next step

Not sure which of these is you?

Tell us what's broken in a paragraph and a principal reads it directly, or walk the ladder from a low-commitment first engagement up to retained work.

One long-form a week. No marketing.

Subscribe to the Refinery Report. Practitioner deep-dives on AI engineering, security, and the realities of running production systems. Unsubscribe in one click.

~12 issues / quarter