Truyo recognized in Gartner® Magic Quadrant™ for AI Governance Platforms | Download Report
Colorado AI rules ADMT and Chatbot Safety
Artificial Intelligence, Privacy Enforcement, U.S. Laws & Regulations

How AI Governance and Privacy Compliance Teams Should Prepare as Colorado’s AI Rules Find Grounds

On August 11, 2026, the Colorado Attorney General’s Office moved into the formal rulemaking phase for two important laws regarding AI governance and privacy compliance. The Automated Decision-Making Technology (ADMT) Act (SB 26-189) and the Chatbot Safety Act (HB 26-1263) were both signed into law earlier this year and will be going into effect on January 1, 2027. But before that, rules had to be adopted for both the acts and after collecting public feedback and pre-rulemaking comments, the draft for the rulemaking was filed last week.

While the Colorado Attorney General’s Office is open to rulemaking comments up till later in the year, we can use the proposed draft to understand the scope and requirements of these rules for a proactive AI governance and privacy compliance strategy. Truyo AI governance and Truyo Privacy can help companies in scope with compliance to these laws, but it is important that we understand what’s ahead.

Who is in Scope?

The ADMT rules primarily apply to two categories of businesses:

  • Developers of covered automated decision-making technology
  • Deployers that use covered ADMT to materially influence consequential decisions affecting consumers.

In practical terms, this captures organizations involved in developing or using covered automated systems in decisions with significant effects on consumers, with different obligations depending on whether the organization is the Developer, Deployer, or both.

The Chatbot Safety rules, by contrast, apply to operators of conversational artificial intelligence services, subject to the Act’s specified exemptions. Their obligations focus particularly on services interacting with minors, including age assurance, AI-versus-human disclosures, safeguards against prohibited content and emotional dependence, privacy and account controls, and related reporting requirements.

The Two Colorado Acts

Both the ADMT rules and the Chatbot Safety rules regulate different parts of the AI ecosystem. However, they both regulate consumer-facing risks created by AI systems.  Here’s what the draft proposes for the two act:

ADMT Rules

  • Know and document where ADMT is used in consequential decisions, including its purpose, data inputs, limitations, developer, version, and role in the final decision.
  • Establish AI vendor/developer documentation controls so required model information flows from upstream developers through integrators to deployers.
  • Build compliant customer communications that are understandable, accessible, appropriately translated, device-readable, and not misleading.
  • Operationalize adverse-decision notices: when ADMT materially influences a negative consequential decision, issue the required explanation within 30 days, including the decision, AI’s role, principal reasons, relevant data, and consumer rights.
  • Make AI decisions explainable at the individual level, including relevant inferences, scores, profiles, automatic-denial factors, and underlying personal data.
  • Create an ADMT rights workflow for consumers to access data, correct inaccurate information, obtain additional AI information, and appeal decisions without unnecessary friction.
  • Implement meaningful human review with qualified, sufficiently independent reviewers who can modify or override AI-influenced decisions; the ADMT itself cannot perform that review.
  • Maintain evidence and audit trails covering reviewers, timestamps, evidence considered, AI information accessed, outcomes, and justification.

Chatbot Safety Rules

  • Determine which chatbot experiences are covered and build compliance around the January 1, 2027 effective date.
  • Implement robust age assurance, using multiple reliable signals rather than relying solely on self-declared age, payment methods, or contractual age restrictions.
  • Make AI identity unmistakable: clearly tell users they are interacting with AI, with stronger persistent disclosure requirements for minors and recurring disclosures for other users.
  • Remove engagement mechanics that improperly incentivize minors to spend more time with the chatbot, including problematic use of streaks, points, badges, rewards, and feature unlocks.
  • Build and continuously test minor-safety guardrails, including safeguards against prohibited content and testing after meaningful product/model changes.
  • Prevent emotional dependency patterns, including the AI presenting itself as human, encouraging secrecy or isolation, positioning itself as a primary relationship, or exploiting loneliness or distress to drive engagement.
  • Default minors to maximum privacy: no conversational-history retention for personalization and no use of minors’ personal data for training by default, with controls for minors and parents/guardians.
  • Prevent misleading professional representations, particularly suggestions that the chatbot is equivalent to or endorsed by licensed healthcare, mental-health, legal, or other specified professionals.
  • Establish annual compliance reporting and evidence collection covering age assurance, minor protections, crisis/self-harm safeguards, testing, monitoring, efficacy, and relevant incidents.

Countdown to Compliance

Both the acts are coming into effect on January 1, 2027. Therefore, it would be wise to prepare for a proactive strategy keeping both in mind. Here’s how the AI governance and privacy compliance roadmap will look like for the two acts:

AI Governance

For ADMT

  • AI Inventory: Create an enterprise ADMT inventory and classification framework. Identify AI systems that materially influence consequential decisions and document their business purpose, owner, developer/vendor, version, decision context, level of human involvement, and affected populations. The rules require deployers to understand the ADMT’s purpose, role, version, developer, and use in consequential decisions.
  • AI Documentation: Establish system for AI documentation across the lifecycle that requires developers and vendors to provide intended and inappropriate uses, required data categories, monitoring methods, explainability capabilities, system controls, and relevant training-data categories before deployment. Incorporate the documentation obligations into the supply-chain (vendor onboarding, procurement, integration and more).
  • Meaningful monitoring: Define when human review in terms of availability, responsibility, qualifications, independence, and authority. The AI system itself cannot perform the meaningful human review.
  • Audit trail: Preserve reviewer identity, timestamps, evidence considered, relevant ADMT information, final decisions, and written justification so the organization can demonstrate that governance controls operated as designed.

For Chatbot Safety

  • Minor facing chatbot: If the conversational AI is probable to interact with users under 18, treat it as a distinct high-risk use case. Establish enhanced governance requirements for systems that may interact with minors, including age assurance, disclosures, content controls, engagement design, privacy defaults, testing, and monitoring.
  • AI identity and representation: Establish controls preventing conversational systems from misleading users into believing they are human or equivalent to, provided by, or endorsed by specified licensed professionals.

Data Privacy Compliance

For ADMT

  • Data Inventory: ALWAYS map the personal-data lifecycle behind automated decisions. Document the types, categories, and sources of personal data used by ADMT. This should include information used to create scores, classifications, predictions, recommendations, and inferences. The organization should be able to satisfy disclosure and access obligations.
  • Disclosure to Consumers: Make data-use information available to consumers in understandable form. The process for requesting additional ADMT information must allow the Consumer to obtain the ADMT name, version, Developer, and the types, categories, and sources of Personal Data used. On request, the Deployer must provide all specific pieces of Personal Data used in the Consequential Decision, including relevant ADMT inputs.
  • Meet the rights-request deadline: The Deployer must inform the Consumer of action taken on a Personal Data or correction request without undue delay and in any event within 45 days. Denials must include the basis and instructions for appeal.
  • Sensitive categories in training data: Developer disclosures must identify sensitive categories in training data with detailed documentation for Deployers to understand whether the data includes sensitive data, biometric identifiers, or biometric data.

For Chatbot Safety

  • Preserving Privacy: Age-assurance methods may collect only the data necessary to determine the age of the specific user for whom the data was collected. Make sure you have policies in place to protect the data from being shared or used for another purpose and to delete it in required time.
  • Data retention and training data: Operators must give a minor account holder or user tools to control whether information from prior interactions or sessions is retained for personalizing future interactions. The minor must also have settings controlling whether their personal data is used to train the chatbot.
  • Documentation and audit trail: Document your age-estimation methodology, data trail, timestamps, evidence and more to ensure an audit trail for regulators.

Proposed Proactive Preparation

The August 11 draft gives organizations an early view of how Colorado expects these two AI laws to work in practice. And while the rules may still change through the formal comment and rulemaking process, the direction feels pretty clear. organizations do not need to wait for the final rules to start identifying potential gaps. AI governance and privacy compliance teams can use the proposed rules as a readiness benchmark. The rules may still be taking shape. The systems, documentation, and compliance infrastructure needed to respond to them shouldn’t be starting from zero when they become final.

Truyo AI governance will help businesses maintain the required compliance for ADMT and Chatbot safety rules with features for AI inventory, use case assessment, risk analysis, third-party risk-assessment and more. Truyo Privacy will further help protect sensitive data, maintain audit trail for data usage, cater to use requests, and more.


Author

Dan Clarke
Dan Clarke
President, Truyo
August 19, 2026

Let Truyo Be Your Guide Towards Safer AI Adoption

Connect with us today