Issue · Technology

Technology

Every technology bill, vote, and legislator stance in Colorado, automatically classified by Maddy, our AI policy reader.

Total bills
6
2026 Regular Session
Top supporter
Mike Weissman
80% support rate
Top opponent
Larry Liston
12% support rate
Ranked legislators
10
5 support · 5 oppose
Key legislators

Who's moving technology in Colorado

Legislators moving technology in Colorado
Legislator Party Stance Support rate Votes
Mike Weissman
Mike Weissman Senate · District 28
D
Strong +
80% 20
Sheila Lieder
Sheila Lieder House · District 28
D
Support
73% 136
Lesley Smith
Lesley Smith House · District 49
D
Support
72% 126
Regina English
Regina English House · District 17
D
Support
71% 117
Gretchen Rydin
Gretchen Rydin House · District 38
D
Support
70% 139
Larry Liston
Larry Liston Senate · District 10
R
Strong −
12% 45
Ken DeGraaf
Ken DeGraaf House · District 22
R
Oppose
27% 122
Ron Weinberg
Ron Weinberg House · District 51
R
Oppose
30% 130
Stephanie Luck
Stephanie Luck House · District 60
R
Oppose
35% 128
LG
Lorena García House · District 35
D
Oppose
36% 42
Showing 6 of 6 bills

All technology bills

signed · Colorado · Senate Jun 3, 2026

SB 51: Age Attestation on Computing Devices

The act requires an operating system provider that operates a publicly available internet website, software application, online service, or platform that distributes and facilitates, on a commercial basis, the download of applications from third-party developers to users of devices (covered application store) or makes a covered application store available preinstalled on an operating system to:Provide an accessible interface at account setup that requires an account holder to indicate the birth date, age, or age bracket of the user of that device in order to provide a signal regarding the user's age (age signal) to applications available in the covered application store;Provide application developers with a reasonably consistent, real-time application programming interface to request and receive an age signal; andSend only the minimum amount of information necessary to comply with the act. An operating system provider or covered application store shall not share an age signal with a third party for a purpose not required by the act.     The act requires a consumer software application that is accessed through a covered application store and that may be run or directed by a user on a device (covered application) to request an age signal with respect to a particular user when the covered application is initially launched or when a user first creates an account. A covered application that receives an age signal is deemed to have knowledge of the age range of the user to whom that age signal pertains across all platforms of the application and points of access of the application. However, if a developer has clear and convincing information that a user's age is different than the age indicated by an age signal, the developer shall use that information as the primary indicator of the user's age range.     A developer shall ensure that a covered application that receives an age signal does not:Request more information concerning a user from an operating system provider or a covered application store than is necessary to comply with the act; orCommunicate an age signal to a third party for a purpose not required by the act.     With respect to a device for which account setup was completed before July 1, 2028, the act requires an operating system provider to provide, before January 1, 2029, an accessible interface that allows an account holder to indicate the birth date or age of the user of that device for the purpose of providing an age signal regarding the user's age-bracket data to covered applications available in the operating system provider's covered application store. If a covered application last updated on or after July 1, 2027, was downloaded to a device before July 1, 2028, and the covered application has not requested an age signal with respect to the user of the device on which the covered application was downloaded, the covered application must request an age signal from the covered application store from which the covered application was downloaded with respect to that user before January 1, 2029.     A person that violates the act must pay a civil penalty of not more than $2,500 for each minor affected by each negligent violation or not more than $7,500 for each minor affected by each intentional violation. The penalty is assessed and recovered in a civil action brought by the attorney general. An operating system provider or covered application store that makes a good faith effort to comply with the act is not liable for an erroneous age signal or for conduct by a covered application that receives an age signal.(Note: This summary applies to this bill as enacted.)
signed · Colorado · Senate Jun 2, 2026

SB 185: Enhance Security of Office of Information Technology

The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding.     If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit.     The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies.     The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data.     The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually.     The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer.     The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor.     The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information.     The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.)
signed · Colorado · Senate Jun 2, 2026

SB 186: Update Workers' Compensation Statutes Allow Electronic Filing

The act makes various updates to language in the 'Workers' Compensation Act of Colorado' to align with technology changes in the division of workers' compensation in the department of labor and employment. These updates include changing current statutory language requiring mailing of documents to allow for electronic mailing or filing of the documents. The act also changes the fund into which an employer or employer's insurance carrier makes payments to the state for a compensable injury resulting in death of a minor without surviving parents from the subsequent injury fund to the Colorado uninsured employer fund.(Note: This summary applies to this bill as enacted.)
vetoed · Colorado · House Jun 2, 2026

HB 1210: Prohibit Surveillance Price & Wage Setting

Surveillance data is defined in the act as data that is obtained through observation, inference, or surveillance of consumers or workers and that is related to personal characteristics, online behaviors, or biometrics of an individual or group, band, class, or tier to which the individual belongs. The definition of 'worker' in the act excludes federal and state employees and employees of public entities.     The act prohibits discrimination against a consumer or worker resulting from the use of a price or wage setting algorithm (PWSA) that uses statistical modeling, data analytics, artificial intelligence, or other data processing techniques to analyze surveillance data, the output of which is a substantial factor in:Individualized price setting used to determine the amount charged to a consumer; orIndividualized wage setting used to determine the wage offered to a worker.     The act specifies activities that are not individualized price or wage setting, as well as exemptions from the prohibition on price or wage setting. A person has not engaged in individualized price setting if the person can demonstrate, as described in the act, that differential prices are:Based on differences in the cost in providing a good or service to different consumers, such as delivery distance or temporal differences, such as ride or delivery time;Based on publicly disclosed eligibility criteria to all persons that meet the criteria, such as consumers purchasing in volume, or to all members of a broadly defined group of consumers, such as teachers;Afforded on equal terms to all participants in a loyalty, membership, or rewards program or are offered in response to a consumer complaint, service disruption, request for account cancellation, or similar reason;Offered pursuant to a specified needs-based discount program for reduced pricing related to income or financial need, such as hospital discounted care;Based on a subscription or other continuous agreement that includes a monthly or other recurring price that was not informed by a PWSA; orBased on a refusal to extend credit on specific terms or to enter into a financial transaction based on a consumer's data in a consumer report or data required as part of the application for the financial transaction.     A person has not engaged in individualized wage setting if the person can demonstrate, as described in the act, that the person offers individualized wages based solely on data specific to an individual worker that is directly related to worker seniority or the tasks the worker was required to perform, and the person discloses to the worker before hiring, and to all workers whose wages are set in whole or in part by a PWSA, what data is considered and how the PWSA considers the data.     A person that uses a PWSA shall develop and publish reasonable procedures to ensure the accuracy of all data considered by the PWSA, for workers to request and receive information about what data is collected, and to correct or challenge data considered by a PWSA.     A violation of the prohibition against individualized price or wage setting is a deceptive trade practice under the 'Colorado Consumer Protection Act' and is subject to the enforcement provisions and remedies provided in that act.(Note: This summary applies to this bill as enacted.)
signed · Colorado · House Jun 2, 2026

HB 1139: Use of Artificial Intelligence in Health Care

On and after January 1, 2027, when determining coverage for health-care services, the act requires entities that use an artificial intelligence system (AI system) for the purpose of conducting utilization review of health-care services, including health insurance companies (carriers), pharmacy benefit managers, private utilization review organizations, behavioral health administrative services organizations, and managed care entities (entities), ensure that the AI system complies with certain requirements specified in the act. Specifically, an entity shall ensure that the AI system:Makes determinations based on medical or clinical history, the patient's individual clinical circumstances, and other relevant clinical factors specified in the act, with denial of coverage reviewed by a licensed clinician or physician or other competent regulated professional who is competent to evaluate the specific clinical issues and review the health benefit plan's terms of coverage (competent regulated professional);Does not base its determination solely on group data without reference to the individual's data;Is not used in any way that discriminates against individuals in violation of other state or federal laws and is fairly and equitably applied, including in accordance with regulations and guidance issued by the federal department of health and human services; andIs periodically reviewed to ensure the AI systems outcomes are accurate and reliable and that an individual's health data is not used beyond its intended or stated purpose.     Entities that use AI systems shall disclose to the division of insurance, the department of human services, or the department of health care policy and financing, as applicable, the utilization review functions for which the AI system will be used and the points in the utilization review process when it will be used, the process for human oversight of adverse coverage determinations, and the process for maintaining audit information to ensure that the use of the AI system complies with the requirements in the act.     The AI system may be used to assist in utilization review, including expedited approvals. A carrier's denial of coverage for a service based in whole or in part on medical necessity shall not be issued solely on the output of an AI system without human review by a licensed clinician or physician or other competent regulated professional.     Further, the act prohibits a carrier and a payer of services under the 'Colorado Medical Assistance Act' and the 'Children's Basic Health Plan Act' from paying for psychotherapy services that are provided directly to a client and that are conducted by an AI system.(Note: This summary applies to this bill as enacted.)
signed · Colorado · Senate May 14, 2026

SB 189: Automated Decision-Making Technology

In 2024, the general assembly enacted Senate Bill 24-205, which created consumer protections in interactions with artificial intelligence systems. The act repeals and reenacts those provisions with new requirements regarding the use of automated decision-making technology in consequential decisions.     The act defines an 'automated decision-making technology' (ADMT) as a technology that processes personal data and uses computation to generate output, including predictions, recommendations, classifications, rankings, scores, or other information that is used to make, guide, or assist a decision, judgment, or determination concerning an individual. The act defines a 'consequential decision' as a decision that relates to an individual's access to, eligibility for, or compensation related to education, employment, housing, financial or lending services, insurance, health-care services, or essential government services and public benefits.     The act requires the developer of an ADMT (developer) that is used to materially influence a consequential decision (covered ADMT), starting January 1, 2027, to provide a deployer of a covered ADMT (deployer) with technical documentation describing the covered ADMT's intended uses, categories of training data, known limitations, and instructions for appropriate use and human review. Developers must notify deployers of material updates or modifications to the covered ADMT. Both developers and deployers are required to retain records necessary to demonstrate compliance with the act for at least 3 years.     The act establishes consumer notice requirements, mandating that deployers provide clear and conspicuous notice to consumers at the point of interaction with a covered ADMT. A deployer is required to provide a consumer with a plain language description of a covered ADMT's role within 30 days after the covered ADMT makes a consequential decision that results in an adverse outcome for the consumer. The attorney general must adopt rules to clarify these post-adverse outcome disclosure requirements by January 1, 2027.     Consumers have the right to request personal data and correction of factually incorrect personal data used by a covered ADMT. The act also grants consumers the right to request meaningful human review and reconsideration following a covered ADMT making a consequential decision resulting in an adverse outcome.     The attorney general is directed to enforce the act through the 'Colorado Consumer Protection Act', and a violation of the act is deemed a deceptive trade practice. Before initiating an action before January 1, 2030, the attorney general must provide the developer or deployer with a 60-day notice and opportunity to cure the alleged violation, if a cure is deemed possible. The act does not create a new private right of action but establishes how fault is allocated between developers and deployers in civil actions alleging unlawful discrimination under existing law.     Specified entities are exempted from the requirements of the act to the extent the entities comply with other legal obligations.(Note: This summary applies to this bill as enacted.)