AI regulation direction

Colorado was meant to be the American test case for a European-style, risk-based AI law. In May 2026, before that law ever took effect, the state repealed and replaced it with something much lighter. It is the clearest sign yet of a wider retreat from prescriptive AI regulation.

What happened

Senate Bill 189, signed on 14 May 2026, removed the original Act’s duty of reasonable care against algorithmic discrimination, its mandatory risk-management programmes and its impact assessments. In their place is a narrower framework built around notice, disclosure and human review, due to apply from January 2027. The obligations that most resembled a bias audit are gone.

Part of a pattern

Colorado is not alone. Across 2026 the direction of travel has been from risk-based rules toward disclosure-based ones, driven by competitiveness worries and political pushback. Even the EU deferred the toughest parts of its AI Act. The mood has shifted from “prove it is safe” to “tell people you are using it”.

The ethical question

Lighter regulation is not automatically worse, but disclosure alone does not make a system fair. Telling a candidate that AI was used does nothing for them if the tool quietly discriminates. As legal floors drop, the responsibility shifts back to the organisations deploying AI to hold their own line, because the law will increasingly assume they are adults about it.

Where a duty like Colorado’s is coming, we help organisations get ready without over-engineering it. See our read on the Colorado position.

Sources: Colorado Senate Bill 189 (Holland & Knight)

This article is general information, not legal advice.

Recommended Posts