Skip to content

Rights and contracts

Colorado AI Act: does it apply to companies that only supply data?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

The Colorado AI Act usually does not apply directly to a company that only licenses records to an AI developer. Its 2024 text placed duties on developers, who build or substantially modify AI systems, and deployers, who use high-risk systems in consequential decisions. Colorado has since delayed and rewritten the law, so confirm the current text with counsel.

Key takeaways

  • Under the 2024 text, duties fell on developers and deployers of high-risk AI systems; a company that only licenses records usually fits neither role.
  • Colorado delayed the law in 2025 and, in May 2026, repealed and reenacted it in a narrower form with a January 1, 2027 start date.
  • A supplier that co-develops or substantially modifies a model, or uses a high-risk system in its own decisions, may take on a regulated role.
  • Buyers may still ask suppliers for provenance and limitation details to support their own compliance documentation.
  • The license should exclude uses you do not want, allocate AI-law duties to the buyer and include a change-in-law clause.

What is the status of the Colorado AI Act?#

The Colorado AI Act has changed twice since it was signed, so the status question comes before the role question. The original law, Senate Bill 24-205, was signed in May 2024 and never took effect on its first or second start date.

The timeline below reflects the dates reported in the source cited for this article. Because the law has already been delayed once and rewritten once, check the text in force on the day you sign a license, and do not rely on any summary, including this one, as a statement of current law.

What is the status of the Colorado AI Act?
DateEventWhat it means for suppliers
May 17, 2024SB 24-205 signed, with an original effective date of February 1, 2026Developer and deployer roles enter most contract templates and buyer questionnaires
August 28, 2025SB 25B-004 signed, delaying the effective date to June 30, 2026Compliance programs built for 2026 had to be re-planned
May 14, 2026SB 26-189 signed, repealing and reenacting the law in a narrower form effective January 1, 2027Older summaries and contract language may describe duties that no longer exist in the same form

Who did the 2024 text regulate?#

The 2024 text regulated developers and deployers of high-risk AI systems doing business in Colorado. A high-risk system was one that makes, or is a substantial factor in making, a consequential decision about a consumer, such as a decision about employment, lending, housing, insurance, education, healthcare, legal services or essential government services.

Developers were those who build or intentionally and substantially modify an AI system. Deployers were those who use a high-risk system. The duties aimed at algorithmic discrimination: developers owed documentation and disclosures to deployers, and deployers owed risk management, impact assessments and notices to the consumers affected.

These definitions still matter in practice even after the 2026 rewrite, because buyers' contract templates, vendor questionnaires and internal policies were drafted around them. Whether the reenacted law keeps the same roles and duties is a question to check against its text with counsel.

Is a data supplier a developer or a deployer?#

A data supplier is usually neither a developer nor a deployer when it only licenses historical records to a company that builds models. Supplying training material is not building or modifying an AI system, and the supplier does not use the resulting system to make decisions about anyone.

The answer can change with what the company actually does. The table sorts common activities by likely role under the 2024 framework; activities near a line are questions for counsel.

Is a data supplier a developer or a deployer?
ActivityLikely roleWhy
Licensing historical support tickets or work orders to a model developerNeitherNo system is built, modified or used by the supplier
Delivering records labeled for a specific hiring, lending or tenant screening toolUsually neither, but closer review is warrantedPurpose-built labels for a consequential use invite questions
Co-developing or substantially modifying a model the supplier then offersPossibly developerModifying a system is part of the developer definition
Using an AI tool to screen its own job applicantsDeployer for that useEmployment decisions are consequential decisions
Using AI for internal scheduling or routingUsually neitherScheduling is not a consequential decision about a consumer
Selling software that embeds a high-risk AI systemPossibly developer, and customers may be deployersThe product itself is the regulated system

Where can a supplier still be pulled in?#

A supplier can still be pulled in through contracts even when the act does not reach it directly. Under the 2024 text, a developer of a high-risk system owed documentation to deployers that could extend to the data used for training, so it may ask suppliers for facts about where records came from, which periods they cover and what limitations they have.

The second route is the supplier's own operations. A company that uses an AI screening tool in hiring may be a deployer for that use regardless of any data license. That is a separate compliance question from licensing.

Other laws also stay in play. The Colorado Privacy Act and other state privacy laws may apply to personal data in the records, and they are assessed on their own terms, deal by deal. The Colorado Attorney General describes the Privacy Act as covering residents acting in an individual or household context, not in a commercial or employment context, which affects how it applies to business records.

  • Provenance: which systems produced the records and over what period.
  • Collection context: how records were created and under what notices.
  • Known gaps and limitations: missing periods, regions or record types.
  • Privacy treatment: what was removed and how.
  • Intended and excluded uses agreed in the license.

Illustrative: a property management software company draws a line#

Illustrative: a fictional maker of property management software holds years of Zendesk tickets, maintenance work orders and Jira issues from its customers' support requests. A model developer asks to license the support and maintenance history, then later asks for rental application records with approve or deny outcomes to train a tenant screening model.

The general counsel treats the two requests differently. Support tickets and work orders, prepared to remove names, addresses and unit details, stay a plain supplier transaction. The application records are declined: they center on applicant personal data, the company's customer contracts limit their reuse, and their stated purpose is a housing decision of the kind the 2024 text treated as high-risk.

The signed license covers support and maintenance records only. It excludes use in decisions about individual consumers, assigns any developer or deployer duties to the buyer and includes a change-in-law clause. The company provides a short provenance summary and a description of what was removed, nothing more.

What should a supplier put in the license?#

A supplier's license should allocate AI-law responsibility to the party that builds and uses the system. The clauses below are common supplier-friendly positions; the right mix depends on the records and the buyer's intended use.

What should a supplier put in the license?
ClauseSupplier-friendly position
Permitted useDefines the uses allowed and states whether high-risk uses are in or out
Compliance allocationThe buyer is responsible for duties it has as a developer or deployer under any AI law
DocumentationThe supplier provides a defined provenance and preparation summary, not open-ended cooperation
RepresentationsNo promise that records are free of bias or fit for any decision-making purpose
Change in lawA process to revisit terms if a new or amended rule changes either party's obligations
IndemnityThe buyer covers claims arising from its own systems and decisions

How to answer a buyer's AI-law questionnaire#

A buyer's AI-law questionnaire is best answered with facts about the records, not with legal conclusions about the buyer's system. Suppliers are often sent long compliance forms written for software vendors, and some questions assume a role the supplier does not have.

Answer what you know from your own systems and preparation work, mark questions about model behavior as outside your role, and route any request for a warranty or certification to counsel before replying.

  • Describe the source systems, record families and date coverage.
  • State what personal and confidential details were removed, and how.
  • Name known gaps, such as lost periods after a system migration.
  • Decline to certify the fairness or accuracy of a model you did not build.
  • Keep every answer consistent with the license and its documentation.

How SourceX approaches state AI laws#

SourceX checks state AI laws during the Rights step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. Whether a law such as the Colorado AI Act may apply is assessed deal by deal with counsel, based on the records, the buyer's intended use and the law in force at signing.

Excluded high-risk uses are written into the permitted-use entry of the SourceX Evidence Packet. Its provenance and privacy record entries give a buyer the facts it may need for its own compliance work, without the supplier taking on the buyer's role.

Frequently asked questions

When does the Colorado AI Act take effect?

As reported in the source cited here, the narrower reenacted law signed in May 2026 takes effect on January 1, 2027. The law has already moved twice, from February 1, 2026 to June 30, 2026 and then to a rewritten version, so confirm the current date and text with counsel before relying on it.

Does the act apply if our company is not based in Colorado?

The 2024 text was framed around persons doing business in Colorado, so headquarters location alone does not settle it. A company with Colorado customers or operations should ask counsel whether it does business there, and then ask separately whether it acts as a developer or deployer.

Could licensing data make us liable for a buyer's biased model?

The act's duties fall on developers and deployers, not on data suppliers as such. Liability can still arise through contract, so representations about data quality and indemnities deserve close review. Avoid promising that records are free of bias or suitable for decisions about people.

Do other states have AI laws that reach training data?

Yes, with different scopes. California AB 2013, signed in September 2024, requires developers of generative AI systems to post training-data documentation, including whether datasets were purchased or licensed. That duty sits with the developer, but buyers may ask suppliers for facts to complete it.

Is the Colorado Privacy Act a separate issue?

Yes. The Colorado Privacy Act governs personal data of consumers and can apply whether or not the AI act does. Records containing personal data need their own privacy review and preparation regardless of the AI act analysis.

What if the law changes again after we sign a license?

A change-in-law clause gives both parties a path to revisit terms. Without one, the parties are left with the contract they signed. Suppliers should also keep their provenance and preparation documentation current, since buyers may request it again after a change.

Sources

  • SB 24-205 signed May 17, 2024, originally effective February 1, 2026; SB 25B-004 signed August 28, 2025 delayed it to June 30, 2026; SB 26-189 signed May 14, 2026 repealed and reenacted it in a narrower form effective January 1, 2027. Source
  • The Colorado Privacy Act protects residents acting in an individual or household context and does not cover individuals acting in a commercial or employment context. Source
  • California AB 2013, signed September 28, 2024, requires developers of generative AI systems to post training-data documentation, including whether datasets were purchased or licensed. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify