Colorado's AI disclosure law takes effect June 30. Here's what your site needs.

TL;DR. Colorado SB 24-205 begins enforcement on June 30, 2026. If your website is visible to Colorado residents and uses any consequential automated decision-making (recommendation engines that affect purchase decisions, AI chat that gates support tiers, hiring screeners, eligibility checkers, or generative content presented as human), you have under seven weeks to add four specific disclosures and a human-review request mechanism. The statutory damage exposure is up to $20,000 per violation. OSDCM scores the typical unprepared SMB site at Exposure 14 to 16 today; the same site is scorable at Exposure under 5 after four concrete changes covered below.

Who is affected

If your site does no automated decision-making and presents no AI-generated content, this rule does not touch you. That category is shrinking; verify rather than assume.

What the law does

Colorado SB 24-205 imposes three new requirements on operators of consumer-facing sites that use AI in consequential ways:

  1. Disclosure at point-of-use. Each AI feature that materially affects a consumer must be disclosed at the moment of interaction, not just in a buried privacy policy. The disclosure language must identify the feature, summarize what it does, and identify the categories of data used.
  2. Right to human review. Consequential automated decisions must be accompanied by a discoverable mechanism for the user to request human review. “Consequential” tracks the statute’s ยง 3 definition: decisions that materially affect access to goods, services, employment, housing, credit, education, healthcare, or essential services.
  3. Documentation duty. Operators must maintain internal documentation of the AI features, their training data sources, and the rationale for the automated decision logic. This is not a public posting requirement, but the Colorado AG can request the documentation in any enforcement inquiry.

Federal enforcement under FTC Section 5 (unfair or deceptive practices) overlays the Colorado rule. The FTC has, since 2023, treated undisclosed AI use as a Section 5 deceptive-practice violation in several consent orders. Colorado SB 24-205 effectively imports federal expectations into a strict-liability state regime.

What it costs (OSDCM walkthrough)

This dispatch itself is a meta-application of OSDCM (it does not score a specific site; it explains the methodology). For a representative 25-employee Colorado-visible e-commerce retailer scored against this rule today:

Typical aggregate Exposure Score: 13 to 16 (mid bucket; address within 90 days).

Statutory damages under Colorado SB 24-205 cap at $20,000 per violation. Multiple violations across a single site visit are possible because each disclosed-feature gap is its own count. OSDCM’s conservative per-site annual risk band for a mid-bucket SMB is roughly $5,000 to $40,000.

The FTC Section 5 layer adds separate exposure: a federal enforcement action’s civil-penalty cap (up to $51,744 per violation in 2026) plus injunctive relief that can require remediation under court oversight. Federal enforcement is far less likely than state enforcement for a typical SMB but the cost shape is materially worse if it lands.

What to do

The remediation is ordered by impact on Exposure Score and Colorado-AG enforcement priority. A typical site can move from Exposure 14 to Exposure 4 in four steps, completable by counsel-supervised dev work within 30 to 60 days:

  1. Add per-feature AI disclosure on every page where AI affects the user. A short, one-sentence notice at the point of interaction. Drops C.1 from 4 to 1.
  2. Add a discoverable “request human review” mechanism for consequential automated decisions. A link in the user’s account area or a clearly-labeled button at decision points. Drops C.2 from 4 to 1.
  3. Label AI-generated marketing copy, testimonials, and images. A consistent label that identifies AI-generated content. Drops C.3 from 3 to 1.
  4. Document your AI features internally before June 30. A short memo identifying each AI feature, its data sources, and its decision logic. This satisfies the documentation duty and gives counsel a starting point if an AG inquiry arrives.

After remediation: re-score under OSDCM and confirm Exposure under 9 (low bucket). Re-scan quarterly thereafter to catch drift.

If you operate in a high-risk sector (hiring, healthcare-adjacent, financial-services), counsel review of the four items above is recommended before deployment. The state AG’s enforcement priorities historically target high-impact sectors first.

This is the first state AI-disclosure law to reach enforcement. California’s CPPA ADMT regulations and Illinois HB 3773 are on similar trajectories, with effective dates in late 2026 and 2027 respectively. ComplianceBeacon’s learn/ section covers each state separately; the Colorado-specific guide is the deepest treatment.

OSDCM scores will be ported to California ADMT and Illinois HB 3773 as their final rule language is published. The methodology Section H worked example will expand with one per major-state regime.

Find out how this rule affects your specific business in 60 seconds. Run a free scan.

More from ComplianceBeacon