The act permits an administrative agency that is conducting an adjudicatory hearing (agency) to serve a person entitled to notice of that hearing using electronic means. The agency's use of electronic service requires a documented request by or the documented consent of the person to be notified. The act similarly authorizes electronic service with respect to an agency's final decision or the initial decision by an administrative law judge or hearing officer.(Note: This summary applies to this bill as enacted.)
The act prohibits individuals lawfully permitted to provide psychotherapy services in the state (regulated professionals) from allowing an artificial intelligence system (AI system) to interact with clients in any form of therapeutic communication without synchronous, real-time interaction between the regulated professional, the AI system, and the client, or generate therapeutic recommendations or treatment plans without review and approval by the regulated professional. Except for educational, administrative, simulation, or training purposes or as part of a research program, a regulated professional shall not use an AI system to provide, direct, or guide psychotherapy, clinical intervention, counseling, diagnosis, treatment planning, or other activity that constitutes the practice of psychotherapy with an individual or group unless the use satisfies the conditions specified in the act. At initial client contact, a regulated professional shall inform clients of the prohibitions regarding use of AI systems in the practice of psychotherapy. Regulated professionals may be disciplined by the appropriate licensing board in the department of regulatory agencies for violations of this act. The act allows regulated professionals to use an AI system to assist in providing administrative support or supplementary support, as these terms are defined in the act, for psychotherapy services if the regulated professional maintains responsibility for reviewing any outputs of the AI system used to provide administrative support or supplementary support. If a client's therapeutic session will be recorded or transcribed through the use of an AI system, the regulated professional must disclose in advance the use of an AI system and the purposes for its use, and obtain written, informed consent from the client. The act does not prohibit a regulated professional from using an AI system within accredited or approved educational, instructional, or professional training programs, so long as the AI system is used solely for educational, administrative, simulation, or training purposes and is not deployed, marketed, or represented as a tool for use with clients, patients, or the public. Further, a regulated professional may be involved in the development, testing, or evaluation of an AI system solely for research purposes under the oversight of a federally registered institutional review board, so long as the AI system is not offered to consumers or used outside of the research setting. The act does not apply to regulated professionals who use or recommend the use of technology in the state that does not diagnose or treat mental health disorders, clearly discloses that the technology is not a substitute for clinical care, and:Provides self-help, therapeutic homework, coaching, patient navigation, guided meditation, journaling, or other tools specified in the act; orIs regulated by the federal food and drug administration. Except as provided in the act, the act also makes it an unfair or deceptive trade practice under the 'Colorado Consumer Protection Act' for an individual, corporation, or entity (person) to use any term, letter, or phrase in the use of an AI system in a manner that:Indicates or implies that the AI system's outputs are provided by, endorsed by, or equivalent to services provided by a regulated professional;Represents that the AI system provides psychotherapy services; orRepresents that a user's data is confidential in a manner that would lead a reasonable user to believe that the privacy of their data is protected in a manner similar to therapist-client confidentiality. The act does not impose liability on a regulated professional for defects in or failures of an AI system that are attributable to the developer or deployer of the AI system. Further, under conditions specified in the act, nothing in the act prohibits a person from developing, testing, or evaluating an AI system solely for research purposes or using an AI system in educational, instructional, or training programs. In addition, it is not an unfair or deceptive trade practice for a person to use a technology that does not diagnose or treat mental health disorders, clearly discloses that the technology is not a substitute for clinical care, and:Provides self-help, therapeutic homework, coaching, patient navigation, guided meditation, journaling, or other tools specified in the act; orIs regulated by the federal food and drug administration.(Note: This summary applies to this bill as enacted.)
The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding. If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit. The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies. The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data. The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually. The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer. The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor. The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information. The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.)
The act makes various updates to language in the 'Workers' Compensation Act of Colorado' to align with technology changes in the division of workers' compensation in the department of labor and employment. These updates include changing current statutory language requiring mailing of documents to allow for electronic mailing or filing of the documents. The act also changes the fund into which an employer or employer's insurance carrier makes payments to the state for a compensable injury resulting in death of a minor without surviving parents from the subsequent injury fund to the Colorado uninsured employer fund.(Note: This summary applies to this bill as enacted.)
Surveillance data is defined in the act as data that is obtained through observation, inference, or surveillance of consumers or workers and that is related to personal characteristics, online behaviors, or biometrics of an individual or group, band, class, or tier to which the individual belongs. The definition of 'worker' in the act excludes federal and state employees and employees of public entities. The act prohibits discrimination against a consumer or worker resulting from the use of a price or wage setting algorithm (PWSA) that uses statistical modeling, data analytics, artificial intelligence, or other data processing techniques to analyze surveillance data, the output of which is a substantial factor in:Individualized price setting used to determine the amount charged to a consumer; orIndividualized wage setting used to determine the wage offered to a worker. The act specifies activities that are not individualized price or wage setting, as well as exemptions from the prohibition on price or wage setting. A person has not engaged in individualized price setting if the person can demonstrate, as described in the act, that differential prices are:Based on differences in the cost in providing a good or service to different consumers, such as delivery distance or temporal differences, such as ride or delivery time;Based on publicly disclosed eligibility criteria to all persons that meet the criteria, such as consumers purchasing in volume, or to all members of a broadly defined group of consumers, such as teachers;Afforded on equal terms to all participants in a loyalty, membership, or rewards program or are offered in response to a consumer complaint, service disruption, request for account cancellation, or similar reason;Offered pursuant to a specified needs-based discount program for reduced pricing related to income or financial need, such as hospital discounted care;Based on a subscription or other continuous agreement that includes a monthly or other recurring price that was not informed by a PWSA; orBased on a refusal to extend credit on specific terms or to enter into a financial transaction based on a consumer's data in a consumer report or data required as part of the application for the financial transaction. A person has not engaged in individualized wage setting if the person can demonstrate, as described in the act, that the person offers individualized wages based solely on data specific to an individual worker that is directly related to worker seniority or the tasks the worker was required to perform, and the person discloses to the worker before hiring, and to all workers whose wages are set in whole or in part by a PWSA, what data is considered and how the PWSA considers the data. A person that uses a PWSA shall develop and publish reasonable procedures to ensure the accuracy of all data considered by the PWSA, for workers to request and receive information about what data is collected, and to correct or challenge data considered by a PWSA. A violation of the prohibition against individualized price or wage setting is a deceptive trade practice under the 'Colorado Consumer Protection Act' and is subject to the enforcement provisions and remedies provided in that act.(Note: This summary applies to this bill as enacted.)
The act requires a landlord to:Comply with applicable court rules governing the protection and redaction of personal identifying information in eviction filings; andRedact personal identifying information from supporting documents submitted to a court. The act also requires a landlord to include in all rental applications:A notice to prospective tenants regarding the information and data the landlord will attempt to access when conducting a tenant screening;A general description of the factors the landlord will consider when evaluating a rental application, including a prospective tenant's credit history, rental history, income, and criminal background, if applicable; andAn indication of whether the landlord uses a third-party tenant screening service and, if so, the name of the service.(Note: This summary applies to this bill as enacted.)
The act repeals limited purpose fee-for-service contracts for: the career pathways program, the multidisciplinary health-care provider access training program, and the career and technical education and apprenticeship programs alignment, on June 30, 2028; and cybersecurity and distributed ledger technologies and the food systems advisory council, on June 30, 2026. The act repeals, on June 30, 2028, the multidisciplinary health-care provider access training program, the career pathways program, and the state apprenticeship agency's career and technical education and apprenticeship programs alignment requirement.(Note: This summary applies to this bill as enacted.)
The act requires the state treasurer to transfer any unexpended and unencumbered money remaining in the public safety communications revolving fund at the end of a fiscal year to the public safety communications trust fund (trust fund). The act clarifies that the primary purpose of the money in the trust fund is to support the digital trunked radio system (DTRS) by acquiring and maintaining public safety communications systems and equipment for use by the office of public safety communications (office), state departments, and other users of the system. The money in the fund may also be used for the payment of maintenance expenses of the office, state departments, and other users related to the DTRS, including the cost of leased or rented equipment, infrastructure maintenance, tower lease costs, payments to local governmental entities for radio communications systems, or payments related to public safety radio systems.(Note: This summary applies to this bill as enacted.)
Current law requires an amount equivalent to the recorded depreciation or amortization of an information technology asset acquired, repaired, improved, replaced, renovated, or constructed with an appropriation from the information technology capital account in the capital construction fund based on the depreciation period (information technology annual depreciation-lease equivalent payment) to be credited and transferred to the information technology capital account within the capital construction fund. Current law also requires the state treasurer to transfer any unappropriated balances in the information technology capital account or any otherwise unexpended and unencumbered money remaining in the information technology capital account at the end of a fiscal year to the general fund. The act prohibits the state treasurer from transferring any money that was transferred, credited, or paid into the information technology capital account as an information technology annual depreciation-lease equivalent payment back to the general fund at the end of a fiscal year, for state fiscal years commencing on or after July 1, 2026.(Note: This summary applies to this bill as enacted.)
The act requires that the state treasurer make the following transfers of money on July 1, 2026:$131,514,555 from the general fund to the capital construction fund;$3,420,943 from the general fund to the information technology capital account in the capital construction fund;$500,000 from the general fund exempt account to the capital construction fund;$1,748,863 from the community impact cash fund to the information technology capital account in the capital construction fund;$587,318 from the motor carrier safety fund to the information technology capital account in the capital construction fund to be used for a records utilization upgrade for the Colorado state patrol; and$1,976,782 from the motorcycle operator safety training fund to the information technology capital account in the capital construction fund to be used for a records utilization upgrade for the Colorado state patrol.(Note: This summary applies to this bill as enacted.)