FPF Submits Comments to Inform Colorado Automated Decision-Making Technology and Chatbot Rulemaking Processes
On July 13, FPF submitted comments in response to the Colorado Department of Justice’s (the Department’s) pre-rulemaking process for the Colorado Automated Decision-making Act (SB 189) and the Chatbot Safety Act (HB 1263). As lawmakers continue to calibrate a proportionate approach to consumer protection from risks of AI-related harms, Colorado’s two new laws each take a distinctive approach. FPF’s comments seek to ensure that Colorado’s regulations adequately clarify compliance ambiguities while supporting interoperability with existing state and federal privacy frameworks.
Colorado Automated Decision-Making Act
Enacted in 2026 to repeal and replace the Colorado AI Act (CAIA), SB 189 incorporates several revisions recommended by the Colorado AI Policy Working Group convened by Governor Polis to address concerns raised against the prior law. As amended, the law has three main obligations: (1) imposing documentation obligations on developers of covered automated decision-making technology (ADMT) when it is marketed or advertised to materially influence a consequential decision; (2) requiring deployers to provide notice of use and specific post-adverse-outcome disclosures when such technology is used to make consequential decision; and (3) creating consumer rights to access and correct personal data used in an adverse consequential decision made by a covered ADMT, and an opportunity for meaningful human review of that decision. The law takes effect January 1, 2027, and the Department has opened a pre-rulemaking process to gather stakeholder input on rules clarifying and implementing these core requirements.
With these goals in mind, FPF recommended that the Department focus on clarifying requirements to ease points of tension between the Colorado Automated Decision-making Act (“ADM Act”) and the Colorado Privacy Act (“CPA”), including by:
- Aligning the scope and definition of automated decision-making technology;
- Clarifying transparency obligations to enable compliance under both laws; and
- Streamlining consumer rights.
Chatbot Safety Act
Also enacted in 2026, HB 1263 regulates “conversational AI services” by requiring operators to implement age estimation and tools for minors or parents to adjust privacy and account settings; prohibit engagement-based rewards targeting minors; disclose to users that the service is AI, not human; and prevent the service from producing sexual content, simulating emotional dependence, or engaging in sexually explicit interactions with minors. The law is subject to tiered effective dates, with the law as a whole taking effect on August 12, 2026, the substantive operator obligations taking effect January 1, 2027, and annual reporting requirements taking effect July 1, 2027. The Department’s pre-rulemaking questions addressed HB 1263’s scope and key terms, age estimation requirements, and protocols related to suicidal ideation and self-harm, among other topics.
In response to these questions, FPF outlined three recommendations for the Department’s consideration to improve the law’s clarity and implementation:
- Clarifying key exemptions and terms, including the exemption for services limited to a “narrow and discrete topic”;
- Ensuring age estimation rules are both flexible and interoperable with the recently enacted Digital Age Assurance Act; and
- Specifying rules regarding the creation and implementation of suicide and self-harm crisis intervention protocols.