Colorado's original AI Act (SB 24-205), which offered an ISO 42001 / NIST AI RMF affirmative defense, was repealed before it took effect and replaced by SB 189, signed 14 May 2026 and effective 1 January 2027. SB 189 is a narrower transparency framework, and the affirmative defense is gone. ISO 42001 is no longer a Colorado statutory defense, but it remains the strongest evidence of AI governance for Microsoft SSPA, the EU AI Act, enterprise procurement, and SB 189's own documentation and disclosure expectations.
Colorado was the first US state to pass a comprehensive AI law, the Colorado Artificial Intelligence Act (Senate Bill 24-205, "CAIA"), enacted in 2024 with an effective date that had been pushed to 30 June 2026. Before it ever took effect, the legislature repealed and replaced it. On 14 May 2026, Governor Jared Polis signed SB 189, which takes effect 1 January 2027.
The original CAIA gave developers and deployers an affirmative defense if they were in compliance with a recognised AI risk-management framework such as ISO/IEC 42001 or the NIST AI RMF. SB 189 removed that mechanism, along with the mandatory risk-management programmes, impact assessments, and the duty of reasonable care to prevent algorithmic discrimination. ISO 42001 is therefore no longer a statutory affirmative defense in Colorado. Any source still describing one is out of date.
SB 189 is a narrower transparency and disclosure framework aimed at automated systems used to make, or substantially inform, consequential decisions about Colorado consumers (in areas such as employment, housing, healthcare, finance, insurance, education, and legal or essential government services). Its core obligations centre on:
SB 189 is signed law, but its details may move: the Colorado Attorney General has rulemaking to complete before 1 January 2027, and the replacement legislation has been the subject of ongoing litigation. Treat the dates and obligations here as the best public reading as of 28 July 2026, and confirm specifics with qualified Colorado counsel. This toolkit's 24-month update window covers material changes.
Yes, just not as a statutory defense. ISO 42001 gives you the AI policy, governance structure, risk methodology, impact-assessment process, lifecycle controls, and documented disclosures that map naturally onto SB 189's documentation and transparency expectations. More importantly, the same management system is what carries weight for the drivers that are live and binding today:
| AI governance area | Toolkit artefact(s) | Tier |
|---|---|---|
| AI policy & governance structure | AIMS-01 AI Policy, AIMS-02/03 roles & responsibilities | Starter |
| Risk methodology, register & treatment | AIMS-04 Risk Methodology, AIMS-05 Risk Register, AIMS-06 Risk Treatment, AIMS-06a Treatment Action Catalogue, AIMS-07 Statement of Applicability | Starter |
| Impact assessment (best practice; required under the EU AI Act) | AIMS-08 Impact Assessment Procedure, AIMS-09 Record Template; Professional adds SaaS / FinTech / HealthTech variants | Starter / Pro |
| Consumer notice & transparency disclosures | AIMS-12 Communication Plan (notice & public transparency templates) | Starter |
| Lifecycle controls, monitoring & incident response | AIMS-19 AI System Lifecycle, AIMS-13 Internal Audit, AIMS-16 Nonconformity & CAPA, AIMS-22 Incident Response | Starter |
| Framework crosswalk (ISO 42001 × ISO 27001 × NIST AI RMF × EU AI Act) | Professional: Four-Way Crosswalk | Pro |
Bottom line: ISO 42001 is no longer a Colorado affirmative defense, but the documentation it produces is exactly what SB 189 disclosure, Microsoft SSPA, EU AI Act readiness, and enterprise procurement all draw on. The Starter tier ($199) delivers the 23 core documents; the Professional tier ($697) adds the crosswalk and industry impact-assessment variants. This page is educational and is not legal advice.