The act permits an administrative agency that is conducting an adjudicatory hearing (agency) to serve a person entitled to notice of that hearing using electronic means. The agency's use of electronic service requires a documented request by or the documented consent of the person to be notified. The act similarly authorizes electronic service with respect to an agency's final decision or the initial decision by an administrative law judge or hearing officer.(Note: This summary applies to this bill as enacted.)
The act requires an operating system provider that operates a publicly available internet website, software application, online service, or platform that distributes and facilitates, on a commercial basis, the download of applications from third-party developers to users of devices (covered application store) or makes a covered application store available preinstalled on an operating system to:Provide an accessible interface at account setup that requires an account holder to indicate the birth date, age, or age bracket of the user of that device in order to provide a signal regarding the user's age (age signal) to applications available in the covered application store;Provide application developers with a reasonably consistent, real-time application programming interface to request and receive an age signal; andSend only the minimum amount of information necessary to comply with the act. An operating system provider or covered application store shall not share an age signal with a third party for a purpose not required by the act. The act requires a consumer software application that is accessed through a covered application store and that may be run or directed by a user on a device (covered application) to request an age signal with respect to a particular user when the covered application is initially launched or when a user first creates an account. A covered application that receives an age signal is deemed to have knowledge of the age range of the user to whom that age signal pertains across all platforms of the application and points of access of the application. However, if a developer has clear and convincing information that a user's age is different than the age indicated by an age signal, the developer shall use that information as the primary indicator of the user's age range. A developer shall ensure that a covered application that receives an age signal does not:Request more information concerning a user from an operating system provider or a covered application store than is necessary to comply with the act; orCommunicate an age signal to a third party for a purpose not required by the act. With respect to a device for which account setup was completed before July 1, 2028, the act requires an operating system provider to provide, before January 1, 2029, an accessible interface that allows an account holder to indicate the birth date or age of the user of that device for the purpose of providing an age signal regarding the user's age-bracket data to covered applications available in the operating system provider's covered application store. If a covered application last updated on or after July 1, 2027, was downloaded to a device before July 1, 2028, and the covered application has not requested an age signal with respect to the user of the device on which the covered application was downloaded, the covered application must request an age signal from the covered application store from which the covered application was downloaded with respect to that user before January 1, 2029. A person that violates the act must pay a civil penalty of not more than $2,500 for each minor affected by each negligent violation or not more than $7,500 for each minor affected by each intentional violation. The penalty is assessed and recovered in a civil action brought by the attorney general. An operating system provider or covered application store that makes a good faith effort to comply with the act is not liable for an erroneous age signal or for conduct by a covered application that receives an age signal.(Note: This summary applies to this bill as enacted.)
The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding. If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit. The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies. The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data. The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually. The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer. The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor. The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information. The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.)
The act makes various updates to language in the 'Workers' Compensation Act of Colorado' to align with technology changes in the division of workers' compensation in the department of labor and employment. These updates include changing current statutory language requiring mailing of documents to allow for electronic mailing or filing of the documents. The act also changes the fund into which an employer or employer's insurance carrier makes payments to the state for a compensable injury resulting in death of a minor without surviving parents from the subsequent injury fund to the Colorado uninsured employer fund.(Note: This summary applies to this bill as enacted.)
Surveillance data is defined in the act as data that is obtained through observation, inference, or surveillance of consumers or workers and that is related to personal characteristics, online behaviors, or biometrics of an individual or group, band, class, or tier to which the individual belongs. The definition of 'worker' in the act excludes federal and state employees and employees of public entities. The act prohibits discrimination against a consumer or worker resulting from the use of a price or wage setting algorithm (PWSA) that uses statistical modeling, data analytics, artificial intelligence, or other data processing techniques to analyze surveillance data, the output of which is a substantial factor in:Individualized price setting used to determine the amount charged to a consumer; orIndividualized wage setting used to determine the wage offered to a worker. The act specifies activities that are not individualized price or wage setting, as well as exemptions from the prohibition on price or wage setting. A person has not engaged in individualized price setting if the person can demonstrate, as described in the act, that differential prices are:Based on differences in the cost in providing a good or service to different consumers, such as delivery distance or temporal differences, such as ride or delivery time;Based on publicly disclosed eligibility criteria to all persons that meet the criteria, such as consumers purchasing in volume, or to all members of a broadly defined group of consumers, such as teachers;Afforded on equal terms to all participants in a loyalty, membership, or rewards program or are offered in response to a consumer complaint, service disruption, request for account cancellation, or similar reason;Offered pursuant to a specified needs-based discount program for reduced pricing related to income or financial need, such as hospital discounted care;Based on a subscription or other continuous agreement that includes a monthly or other recurring price that was not informed by a PWSA; orBased on a refusal to extend credit on specific terms or to enter into a financial transaction based on a consumer's data in a consumer report or data required as part of the application for the financial transaction. A person has not engaged in individualized wage setting if the person can demonstrate, as described in the act, that the person offers individualized wages based solely on data specific to an individual worker that is directly related to worker seniority or the tasks the worker was required to perform, and the person discloses to the worker before hiring, and to all workers whose wages are set in whole or in part by a PWSA, what data is considered and how the PWSA considers the data. A person that uses a PWSA shall develop and publish reasonable procedures to ensure the accuracy of all data considered by the PWSA, for workers to request and receive information about what data is collected, and to correct or challenge data considered by a PWSA. A violation of the prohibition against individualized price or wage setting is a deceptive trade practice under the 'Colorado Consumer Protection Act' and is subject to the enforcement provisions and remedies provided in that act.(Note: This summary applies to this bill as enacted.)
On and after January 1, 2027, when determining coverage for health-care services, the act requires entities that use an artificial intelligence system (AI system) for the purpose of conducting utilization review of health-care services, including health insurance companies (carriers), pharmacy benefit managers, private utilization review organizations, behavioral health administrative services organizations, and managed care entities (entities), ensure that the AI system complies with certain requirements specified in the act. Specifically, an entity shall ensure that the AI system:Makes determinations based on medical or clinical history, the patient's individual clinical circumstances, and other relevant clinical factors specified in the act, with denial of coverage reviewed by a licensed clinician or physician or other competent regulated professional who is competent to evaluate the specific clinical issues and review the health benefit plan's terms of coverage (competent regulated professional);Does not base its determination solely on group data without reference to the individual's data;Is not used in any way that discriminates against individuals in violation of other state or federal laws and is fairly and equitably applied, including in accordance with regulations and guidance issued by the federal department of health and human services; andIs periodically reviewed to ensure the AI systems outcomes are accurate and reliable and that an individual's health data is not used beyond its intended or stated purpose. Entities that use AI systems shall disclose to the division of insurance, the department of human services, or the department of health care policy and financing, as applicable, the utilization review functions for which the AI system will be used and the points in the utilization review process when it will be used, the process for human oversight of adverse coverage determinations, and the process for maintaining audit information to ensure that the use of the AI system complies with the requirements in the act. The AI system may be used to assist in utilization review, including expedited approvals. A carrier's denial of coverage for a service based in whole or in part on medical necessity shall not be issued solely on the output of an AI system without human review by a licensed clinician or physician or other competent regulated professional. Further, the act prohibits a carrier and a payer of services under the 'Colorado Medical Assistance Act' and the 'Children's Basic Health Plan Act' from paying for psychotherapy services that are provided directly to a client and that are conducted by an AI system.(Note: This summary applies to this bill as enacted.)
The act defines a 'conversational artificial intelligence service' as an artificial intelligence system that is accessible to the general public and that primarily simulates human conversation and interaction through adaptive textual, visual, or aural communications. Effective January 1, 2027, the act creates requirements and prohibitions for a person, partnership, corporation, or entity that develops and makes publicly available a conversational artificial intelligence service or offers a conversational artificial intelligence service to a consumer (operator). An operator is required to use commercially reasonable methods or generally accepted methods to estimate the age of a consumer who has or opens an account or profile to use a conversational artificial intelligence service (account holder) and the age of other users of a conversational artificial intelligence service. If an operator knows that an account holder or user is a minor, an operator is:Required to provide certain disclosures;Prohibited from providing the minor account holder or minor user with points or rewards to encourage engagement with the conversational artificial intelligence service;Required to institute technically feasible measures to prevent the conversational artificial intelligence service from producing explicit sexual conduct, intimate digital depictions, or statements that simulate emotional dependence;Required to implement a protocol for a conversational artificial intelligence service to stop engaging in response to a user prompt regarding sexual conduct with a minor; andRequired to provide tools for the minor account holder or minor user or a parent or guardian of the minor account holder or minor user to manage the minor account holder's or minor user's privacy and account settings. The act also requires an operator to provide a disclosure to a user that a conversational artificial intelligence service is artificial intelligence, implement a protocol for user prompts regarding suicidal ideation or self-harm, and annually report to the attorney general's office information regarding the protocol the operator is implementing. The act prohibits an operator from stating that any output data provided by a conversational artificial intelligence service is provided by, endorsed by, or equivalent to services provided by certain licensed or certified professionals. The act clarifies that nothing in the act limits an individual's ability to access certain information and resources pursuant to the state constitution, requires an operator to disclose confidential information, or authorizes content moderation practices inconsistent with the United States constitution.(Note: This summary applies to this bill as enacted.)
The act requires an operator of a social media platform (operator) to ensure that its social media platform provides a streamlined process to allow law enforcement agencies to contact the social media platform. The process must be available to law enforcement agencies at all times and make available a staffed hotline for the purposes of:Receiving and responding to questions about search warrants;Acknowledging the receipt of a search warrant within 8 hours after receipt; andProviding status updates on search warrant compliance to a requesting law enforcement agency. With certain exceptions, an operator must comply with a search warrant within 24 hours if certain conditions apply. A court may reasonably extend this time if the court makes a written finding that the operator or social media platform has shown good cause for the extension and that an extension would not cause an adverse result. The act sets forth enforcement options for the attorney general and district attorneys regarding operators' compliance with search warrants. The act requires an operator to report to a social media platform user's (user's) local law enforcement agency within 24 hours if the operator's social media platform takes any one of certain described adverse actions against a user. A violation of the reporting requirement is a violation of the 'Colorado Consumer Protection Act'. In current law, 'social media platform' is defined as an internet-based service, website, or application that satisfies certain criteria, including having more than 100,000 active users in Colorado. The act removes this criterion. The act makes conforming amendments as necessary to Senate Bill 26-011, as enacted in the 2026 regular legislative session, to have Senate Bill 26-011 conform with the provisions of the act.(Note: This summary applies to this bill as enacted.)
In 2024, the general assembly enacted Senate Bill 24-205, which created consumer protections in interactions with artificial intelligence systems. The act repeals and reenacts those provisions with new requirements regarding the use of automated decision-making technology in consequential decisions. The act defines an 'automated decision-making technology' (ADMT) as a technology that processes personal data and uses computation to generate output, including predictions, recommendations, classifications, rankings, scores, or other information that is used to make, guide, or assist a decision, judgment, or determination concerning an individual. The act defines a 'consequential decision' as a decision that relates to an individual's access to, eligibility for, or compensation related to education, employment, housing, financial or lending services, insurance, health-care services, or essential government services and public benefits. The act requires the developer of an ADMT (developer) that is used to materially influence a consequential decision (covered ADMT), starting January 1, 2027, to provide a deployer of a covered ADMT (deployer) with technical documentation describing the covered ADMT's intended uses, categories of training data, known limitations, and instructions for appropriate use and human review. Developers must notify deployers of material updates or modifications to the covered ADMT. Both developers and deployers are required to retain records necessary to demonstrate compliance with the act for at least 3 years. The act establishes consumer notice requirements, mandating that deployers provide clear and conspicuous notice to consumers at the point of interaction with a covered ADMT. A deployer is required to provide a consumer with a plain language description of a covered ADMT's role within 30 days after the covered ADMT makes a consequential decision that results in an adverse outcome for the consumer. The attorney general must adopt rules to clarify these post-adverse outcome disclosure requirements by January 1, 2027. Consumers have the right to request personal data and correction of factually incorrect personal data used by a covered ADMT. The act also grants consumers the right to request meaningful human review and reconsideration following a covered ADMT making a consequential decision resulting in an adverse outcome. The attorney general is directed to enforce the act through the 'Colorado Consumer Protection Act', and a violation of the act is deemed a deceptive trade practice. Before initiating an action before January 1, 2030, the attorney general must provide the developer or deployer with a 60-day notice and opportunity to cure the alleged violation, if a cure is deemed possible. The act does not create a new private right of action but establishes how fault is allocated between developers and deployers in civil actions alleging unlawful discrimination under existing law. Specified entities are exempted from the requirements of the act to the extent the entities comply with other legal obligations.(Note: This summary applies to this bill as enacted.)
The bill establishes the "Surveillance Accountability and Freedom Ensured (SAFE) Act" (SAFE Act). On and after July 1, 2027, the SAFE Act requires a law enforcement agency to use surveillance technology only for lawful purposes directly related to public safety or for an active investigation.If a law enforcement agency uses surveillance technology to collect surveillance data, the law enforcement agency must comply with certain requirements related to the collection, storage, sharing, and destruction of the data.The law enforcement agency must ensure that:Facial recognition systems are only used after a warrant is obtained or in exigent circumstances when there is an imminent threat to public safety;Traffic cameras and automated license plate readers must only be used in public spaces and for specific enforcement purposes, such as traffic violations or identifying stolen vehicles; andDrone cameras are operated in compliance with federal aviation administration regulations.A law enforcement agency may store data collected by surveillance technology only for a specified amount of time depending on the type of technology used and how the data is collected or until an active investigation is concluded.A law enforcement agency shall not sell any data that is collected from its surveillance technologies, but the law enforcement agency may share the surveillance data with another law enforcement agency if the data is related to an active investigation and the other law enforcement agency agrees to comply with the requirements of the SAFE Act. A law enforcement agency must also ensure that surveillance data is permanently destroyed at the end of an applicable retention period or once the data is no longer needed for the matter. The bill creates civil penalties for violations of these provisions.The bill also requires a law enforcement agency to make certain information related to the law enforcement agency's compliance with the SAFE Act available to residents who request it at no cost to the resident.The bill requires the attorney general to conduct an audit of a law enforcement agency every 2 years and authorizes the attorney general to bring a civil action to enforce the SAFE Act.(Note: This summary applies to this bill as introduced.)