Issue · Technology

Technology

Every technology bill, vote, and legislator stance in Colorado, automatically classified by Maddy, our AI policy reader.

Total bills
9
2026 Regular Session
Top supporter
Mike Weissman
80% support rate
Top opponent
Larry Liston
12% support rate
Ranked legislators
10
5 support · 5 oppose
Key legislators

Who's moving technology in Colorado

Legislators moving technology in Colorado
Legislator Party Stance Support rate Votes
Mike Weissman
Mike Weissman Senate · District 28
D
Strong +
80% 20
Sheila Lieder
Sheila Lieder House · District 28
D
Support
73% 136
Lesley Smith
Lesley Smith House · District 49
D
Support
72% 126
Regina English
Regina English House · District 17
D
Support
71% 117
Gretchen Rydin
Gretchen Rydin House · District 38
D
Support
70% 139
Larry Liston
Larry Liston Senate · District 10
R
Strong −
12% 45
Ken DeGraaf
Ken DeGraaf House · District 22
R
Oppose
27% 122
Ron Weinberg
Ron Weinberg House · District 51
R
Oppose
30% 130
Stephanie Luck
Stephanie Luck House · District 60
R
Oppose
35% 128
LG
Lorena García House · District 35
D
Oppose
36% 42
Showing 9 of 9 bills

All technology bills

signed · Colorado · Senate Jun 3, 2026

SB 51: Age Attestation on Computing Devices

The act requires an operating system provider that operates a publicly available internet website, software application, online service, or platform that distributes and facilitates, on a commercial basis, the download of applications from third-party developers to users of devices (covered application store) or makes a covered application store available preinstalled on an operating system to:Provide an accessible interface at account setup that requires an account holder to indicate the birth date, age, or age bracket of the user of that device in order to provide a signal regarding the user's age (age signal) to applications available in the covered application store;Provide application developers with a reasonably consistent, real-time application programming interface to request and receive an age signal; andSend only the minimum amount of information necessary to comply with the act. An operating system provider or covered application store shall not share an age signal with a third party for a purpose not required by the act.     The act requires a consumer software application that is accessed through a covered application store and that may be run or directed by a user on a device (covered application) to request an age signal with respect to a particular user when the covered application is initially launched or when a user first creates an account. A covered application that receives an age signal is deemed to have knowledge of the age range of the user to whom that age signal pertains across all platforms of the application and points of access of the application. However, if a developer has clear and convincing information that a user's age is different than the age indicated by an age signal, the developer shall use that information as the primary indicator of the user's age range.     A developer shall ensure that a covered application that receives an age signal does not:Request more information concerning a user from an operating system provider or a covered application store than is necessary to comply with the act; orCommunicate an age signal to a third party for a purpose not required by the act.     With respect to a device for which account setup was completed before July 1, 2028, the act requires an operating system provider to provide, before January 1, 2029, an accessible interface that allows an account holder to indicate the birth date or age of the user of that device for the purpose of providing an age signal regarding the user's age-bracket data to covered applications available in the operating system provider's covered application store. If a covered application last updated on or after July 1, 2027, was downloaded to a device before July 1, 2028, and the covered application has not requested an age signal with respect to the user of the device on which the covered application was downloaded, the covered application must request an age signal from the covered application store from which the covered application was downloaded with respect to that user before January 1, 2029.     A person that violates the act must pay a civil penalty of not more than $2,500 for each minor affected by each negligent violation or not more than $7,500 for each minor affected by each intentional violation. The penalty is assessed and recovered in a civil action brought by the attorney general. An operating system provider or covered application store that makes a good faith effort to comply with the act is not liable for an erroneous age signal or for conduct by a covered application that receives an age signal.(Note: This summary applies to this bill as enacted.)
signed · Colorado · Senate Jun 2, 2026

SB 185: Enhance Security of Office of Information Technology

The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding.     If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit.     The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies.     The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data.     The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually.     The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer.     The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor.     The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information.     The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.)
signed · Colorado · Senate Jun 2, 2026

SB 186: Update Workers' Compensation Statutes Allow Electronic Filing

The act makes various updates to language in the 'Workers' Compensation Act of Colorado' to align with technology changes in the division of workers' compensation in the department of labor and employment. These updates include changing current statutory language requiring mailing of documents to allow for electronic mailing or filing of the documents. The act also changes the fund into which an employer or employer's insurance carrier makes payments to the state for a compensable injury resulting in death of a minor without surviving parents from the subsequent injury fund to the Colorado uninsured employer fund.(Note: This summary applies to this bill as enacted.)
signed · Colorado · House Jun 2, 2026

HB 1424: Transportation Network Company Consumer Protection

Current law requires that, before an individual is permitted to act as a transportation network company (TNC) driver through the use of a TNC's digital network, the individual shall obtain a criminal history record check. The act requires that the TNC:If the TNC has at least 20,000 rides occurring monthly (large-scale TNC) on its digital network, pay for the required criminal history record check for an individual before the individual is permitted to act as a driver;Procure a privately administered criminal history record check for a driver at least once every 6 months after the initial criminal history record check;Share the results of each criminal history record check with the driver who is the subject of the record check; andProcure a privately administered criminal history record check if a person files a complaint against a driver with the TNC or the public utilities commission (commission) regarding specified allegations. The TNC shall pay the costs of the privately administered criminal history record checks.     A TNC shall create a deactivation and suspension policy to initiate a review of a driver for deactivation within 7 business days if the TNC is notified through a complaint filed with the TNC or the commission or is contacted by the attorney general's office, a district attorney's office, or a law enforcement agency regarding certain allegations against the driver. A driver who has been deactivated may challenge the deactivation through the TNC's deactivation and suspension policy. The act requires the commission to create a process by rule for sharing information between TNCs regarding the deactivation of drivers. A TNC's deactivation and suspension policy must include meaningful human review of the permanent deactivation of a driver.     The act requires a TNC to provide regular safety training to each driver and rider in accordance with rules adopted by the commission.     If a person files a complaint against a TNC or a driver, the TNC shall respond to a subpoena or search warrant for information related to the complaint from a court, the attorney general's office, a district attorney's office, the commission, or a law enforcement agency no later than 72 hours after the request is made, unless the subpoenaing party agrees to a different deadline.     The act requires the commission to adopt rules on or before June 1, 2028, establishing requirements for a TNC to ensure that a driver or rider may opt in to audio and video recording of each prearranged ride and integrate audio and video recording into the TNC's digital platform. A large-scale TNC shall not charge a fee or increase the cost of a prearranged ride solely on the basis of a rider opting in to audio and video recording of the prearranged ride. The commission shall also adopt rules regarding access to, ownership of, storage of, notification about, and deadlines for the implementation of the audio and video recordings, including different requirements for large-scale and small-scale TNCs.     A provision in a contract between a TNC and a driver or rider is declared void as against public policy if the provision attempts or purports to waive specified rights.     The act requires that, on or before February 1, 2027, and on or before February 1 each year thereafter, a TNC shall submit specified data related to incidents involving safety and discrimination to the commission, the attorney general, and each member of the general assembly.     The act requires a TNC to develop policies to:Prevent imposter drivers, account sharing, and account renting;Prevent sexual assault, physical assault, and homicide against or committed by the TNC's drivers;Prohibit the transportation of an unaccompanied youth who is under 15 years old unless the youth is part of a duly authorized family account;Allow a driver to refuse a prearranged ride to an individual who is not authorized to use the account requesting the prearranged ride;Notify and train drivers and riders of any updates to TNC safety policies;Prohibit drivers from offering, selling, or providing food or beverages that are not factory-sealed to riders;Require drivers to report information regarding a conviction of or a plea of guilty or nolo contendere to specified offenses; andPrevent crimes committed against drivers by riders.     A TNC is prohibited from:Altering the rating a rider assigned to a driver or the rating a driver assigned to a rider on a TNC's digital platform;Assigning an automatic or default driver rating that the rider did not assign; orAssigning an automatic or default rider rating that the driver did not assign.     A TNC may delete ratings or reviews that are plausibly motivated by fraud or bias. A TNC shall not consider negative ratings or reviews that are motivated by fraud or bias in a review of a driver for deactivation or an internal deactivation reconsideration.     A TNC is prohibited from collecting biometric data or biometric identifiers from a driver or rider without first obtaining the consent of the driver or rider. If a TNC collects biometric data or biometric identifiers from a driver or rider, the TNC shall comply with specified provisions of the 'Colorado Privacy Act' regarding biometric data and biometric identifiers.     A TNC that violates the act may be assessed a civil penalty of not more than $1,500 per violation.(Note: This summary applies to this bill as enacted.)
signed · Colorado · House Jun 2, 2026

HB 1139: Use of Artificial Intelligence in Health Care

On and after January 1, 2027, when determining coverage for health-care services, the act requires entities that use an artificial intelligence system (AI system) for the purpose of conducting utilization review of health-care services, including health insurance companies (carriers), pharmacy benefit managers, private utilization review organizations, behavioral health administrative services organizations, and managed care entities (entities), ensure that the AI system complies with certain requirements specified in the act. Specifically, an entity shall ensure that the AI system:Makes determinations based on medical or clinical history, the patient's individual clinical circumstances, and other relevant clinical factors specified in the act, with denial of coverage reviewed by a licensed clinician or physician or other competent regulated professional who is competent to evaluate the specific clinical issues and review the health benefit plan's terms of coverage (competent regulated professional);Does not base its determination solely on group data without reference to the individual's data;Is not used in any way that discriminates against individuals in violation of other state or federal laws and is fairly and equitably applied, including in accordance with regulations and guidance issued by the federal department of health and human services; andIs periodically reviewed to ensure the AI systems outcomes are accurate and reliable and that an individual's health data is not used beyond its intended or stated purpose.     Entities that use AI systems shall disclose to the division of insurance, the department of human services, or the department of health care policy and financing, as applicable, the utilization review functions for which the AI system will be used and the points in the utilization review process when it will be used, the process for human oversight of adverse coverage determinations, and the process for maintaining audit information to ensure that the use of the AI system complies with the requirements in the act.     The AI system may be used to assist in utilization review, including expedited approvals. A carrier's denial of coverage for a service based in whole or in part on medical necessity shall not be issued solely on the output of an AI system without human review by a licensed clinician or physician or other competent regulated professional.     Further, the act prohibits a carrier and a payer of services under the 'Colorado Medical Assistance Act' and the 'Children's Basic Health Plan Act' from paying for psychotherapy services that are provided directly to a client and that are conducted by an AI system.(Note: This summary applies to this bill as enacted.)
signed · Colorado · House May 29, 2026

HB 1263: Conversational Artificial Intelligence Service Operator Requirements

The act defines a 'conversational artificial intelligence service' as an artificial intelligence system that is accessible to the general public and that primarily simulates human conversation and interaction through adaptive textual, visual, or aural communications.     Effective January 1, 2027, the act creates requirements and prohibitions for a person, partnership, corporation, or entity that develops and makes publicly available a conversational artificial intelligence service or offers a conversational artificial intelligence service to a consumer (operator).     An operator is required to use commercially reasonable methods or generally accepted methods to estimate the age of a consumer who has or opens an account or profile to use a conversational artificial intelligence service (account holder) and the age of other users of a conversational artificial intelligence service. If an operator knows that an account holder or user is a minor, an operator is:Required to provide certain disclosures;Prohibited from providing the minor account holder or minor user with points or rewards to encourage engagement with the conversational artificial intelligence service;Required to institute technically feasible measures to prevent the conversational artificial intelligence service from producing explicit sexual conduct, intimate digital depictions, or statements that simulate emotional dependence;Required to implement a protocol for a conversational artificial intelligence service to stop engaging in response to a user prompt regarding sexual conduct with a minor; andRequired to provide tools for the minor account holder or minor user or a parent or guardian of the minor account holder or minor user to manage the minor account holder's or minor user's privacy and account settings.     The act also requires an operator to provide a disclosure to a user that a conversational artificial intelligence service is artificial intelligence, implement a protocol for user prompts regarding suicidal ideation or self-harm, and annually report to the attorney general's office information regarding the protocol the operator is implementing. The act prohibits an operator from stating that any output data provided by a conversational artificial intelligence service is provided by, endorsed by, or equivalent to services provided by certain licensed or certified professionals.     The act clarifies that nothing in the act limits an individual's ability to access certain information and resources pursuant to the state constitution, requires an operator to disclose confidential information, or authorizes content moderation practices inconsistent with the United States constitution.(Note: This summary applies to this bill as enacted.)
vetoed · Colorado · House May 28, 2026

HB 1286: Automated Driving System Commercial Vehicles

The act prohibits using an automated driving system to drive a commercial motor vehicle unless an individual who holds a commercial driver's license is in the vehicle, monitors the vehicle's driving, and intervenes, if necessary, to avoid illegal or unsafe driving. The individual must be in the driver's seat if hazardous materials are being transported. The penalty is $1,000 for a first offense, is $2,000 for a second offense, and doubles for each subsequent offense.     The act does not apply to a light-duty vehicle or a truck-mounted attenuator.     The prohibition is repealed September 1, 2031. The chief of the Colorado state patrol will analyze the act's effects on commercial vehicle safety on highways. By November 1, 2030, the chief of the Colorado state patrol will issue a report to the relevant committees of the house of representatives and senate. The report must make recommendations as whether to continue the prohibition and, if continued, any recommended legislation to improve the prohibition.     For the 2026-27 state fiscal year, $14,357 is appropriated to the department of revenue from the Colorado DRIVES vehicle services account in the highway users tax fund to implement the act.(Note: This summary applies to this bill as enacted.)
signed · Colorado · Senate May 14, 2026

SB 189: Automated Decision-Making Technology

In 2024, the general assembly enacted Senate Bill 24-205, which created consumer protections in interactions with artificial intelligence systems. The act repeals and reenacts those provisions with new requirements regarding the use of automated decision-making technology in consequential decisions.     The act defines an 'automated decision-making technology' (ADMT) as a technology that processes personal data and uses computation to generate output, including predictions, recommendations, classifications, rankings, scores, or other information that is used to make, guide, or assist a decision, judgment, or determination concerning an individual. The act defines a 'consequential decision' as a decision that relates to an individual's access to, eligibility for, or compensation related to education, employment, housing, financial or lending services, insurance, health-care services, or essential government services and public benefits.     The act requires the developer of an ADMT (developer) that is used to materially influence a consequential decision (covered ADMT), starting January 1, 2027, to provide a deployer of a covered ADMT (deployer) with technical documentation describing the covered ADMT's intended uses, categories of training data, known limitations, and instructions for appropriate use and human review. Developers must notify deployers of material updates or modifications to the covered ADMT. Both developers and deployers are required to retain records necessary to demonstrate compliance with the act for at least 3 years.     The act establishes consumer notice requirements, mandating that deployers provide clear and conspicuous notice to consumers at the point of interaction with a covered ADMT. A deployer is required to provide a consumer with a plain language description of a covered ADMT's role within 30 days after the covered ADMT makes a consequential decision that results in an adverse outcome for the consumer. The attorney general must adopt rules to clarify these post-adverse outcome disclosure requirements by January 1, 2027.     Consumers have the right to request personal data and correction of factually incorrect personal data used by a covered ADMT. The act also grants consumers the right to request meaningful human review and reconsideration following a covered ADMT making a consequential decision resulting in an adverse outcome.     The attorney general is directed to enforce the act through the 'Colorado Consumer Protection Act', and a violation of the act is deemed a deceptive trade practice. Before initiating an action before January 1, 2030, the attorney general must provide the developer or deployer with a 60-day notice and opportunity to cure the alleged violation, if a cure is deemed possible. The act does not create a new private right of action but establishes how fault is allocated between developers and deployers in civil actions alleging unlawful discrimination under existing law.     Specified entities are exempted from the requirements of the act to the extent the entities comply with other legal obligations.(Note: This summary applies to this bill as enacted.)
passed · Colorado · Senate Apr 27, 2026

SB 90: Exempt Critical Infrastructure from Right to Repair

Under current law, consumers in Colorado have a right to repair all digital electronic equipment, which could include equipment that is considered critical infrastructure.     The bill exempts information technology equipment that is intended for use to be used in critical infrastructure from Colorado's consumer right to repair laws. Critical infrastructure is defined as a system or asset, whether physical or virtual, so vital to the United States that the incapacity or destruction of the system or asset would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.      The bill authorizes the attorney general to review an exemption from Colorado's consumer right to repair laws for certain information technology equipment (equipment) that is intended to be used in critical infrastructure. In reviewing whether the equipment is exempt, the attorney general shall consider whether the equipment is actually intended to be used in a manner that qualifies as critical infrastructure and whether the equipment is sold under a business-to-business or business-to-government contract and not customarily sold in a retail setting. Any determination made by the attorney general regarding an exemption may be appealed by the manufacturer of the equipment.(Note: Italicized words indicate new material added to the original summary; dashes through words indicate deletions from the original summary.)(Note: This summary applies to the reengrossed version of this bill as introduced in the second house.)