Bunny Honey ClubBunny Honey/blog
Work with us
← back to indexblog / ai policy / colorado-chatbot-law-small-business
AI Policy

Does Colorado's Chatbot Law Cover Your Business?

Colorado passed two AI laws that start January 1, 2027. One skips your AI receptionist by name. The other doesn't care how small you are.

AH
Arthur HofFounder, Bunny Honey Club AI
publishedSep 19, 2026
read7 min
Does Colorado's Chatbot Law Cover Your Business?

Colorado passed two AI laws this spring, and most small businesses will assume both apply to them. The Colorado chatbot law probably doesn't touch you. House Bill 26-1263 was written for companion apps that act like your friend. An AI recep

Colorado passed two AI laws this spring, and most small businesses will assume both apply to them. The Colorado chatbot law probably doesn't touch you.

House Bill 26-1263 was written for companion apps that act like your friend. An AI receptionist that books appointments isn't one, and the bill's own exclusions say so in plain words.

The other law is the one to worry about, and it has nothing to do with chatbots.

Jan 1, 2027Both Colorado laws take effect
30 daysTo explain an adverse AI-assisted decision
60 daysCure window, if the AG deems a cure possible
3 yearsMinimum record retention for deployers

Colorado Wrote Two Laws That Cover Different Things

The Chatbot Safety Act, HB 26-1263, was signed May 29, 2026. It regulates "conversational AI services": AI systems open to the general public that primarily simulate human conversation.

The Automated Decision-Making Technology Act, SB 26-189, was signed May 14, 2026. It rewrites the state's 2024 AI Act and regulates AI that helps make decisions about people.

Headlines have blurred the two together. They shouldn't be. One asks what your software says. The other asks what your software decides.

Both start January 1, 2027. The Attorney General's office is still writing the implementing rules, so some details will shift before then.

Your Receptionist Sits Inside a Named Exclusion

Start with the chatbot law, because it's the easy one.

The bill defines a conversational AI service, then lists software that doesn't count. One entry excludes anything primarily designed to provide commerce-related or transactional assistance, "including product or service recommendations, shopping, ordering, payments, delivery, returns, customer support, or customer service."

That's your website chat widget. That's your AI phone receptionist. That's the bot that tells a caller your hours and books a Tuesday slot.

Another entry excludes tools built for a business's own operations and productivity, and another excludes software a business uses solely for internal purposes. HIPAA covered entities are excluded too.

Colorado isn't alone in drawing this line. California's new companion chatbot law carves out business bots the same way, which we broke down here. Texas's TRAIGA leaves private-business chatbots out of its disclosure duty entirely, as we covered in our TRAIGA breakdown.

The Exclusion Depends on What the Bot Is Designed to Do

Here's where a careless setup gets in trouble.

The exclusion says "primarily designed." It's a test of design and purpose, not of who deploys the bot. A receptionist built to answer calls and book jobs fits. A bot marketed as a friendly all-purpose assistant that chats about anything does not, even if it also takes bookings.

If a bot did fall inside the definition, the operator would owe real work. That means a clear AI disclosure at the start of a user's first interaction each day, repeated at least every three hours in a long session or shown persistently, and always in response to "am I talking to a person?" It also means age estimation, a self-harm protocol, and annual reports to the Attorney General starting July 1, 2027.

The bill also bars an operator's interface, advertising, or outputs from presenting the AI's answers as provided by, endorsed by, or equivalent to services from a licensed health-care, legal, or mental health professional, or a qualified dietitian.

The bill text sets no penalty schedule of its own. It sits inside Colorado's consumer protection statute, and the Attorney General is the office collecting the reports.

So the practical test for a business owner is simple. Ask what your bot was built to do, and whether your marketing says something different.

The Other Law Cares About Decisions, Not Conversations

SB 26-189 doesn't regulate chatbots. It regulates automated decision-making technology that materially influences a "consequential decision" about a person in seven areas: education, employment, residential real estate, financial or lending services, insurance, health care, and essential government services.

For a small business, three of those matter most: hiring, renting or selling homes, and anything that touches credit.

A "deployer" is any person doing business in Colorado that deploys such a tool. The definition has no headcount threshold and no revenue floor. The 2024 version of the law had a carve-out for smaller deployers, and this rewrite doesn't repeat it.

And "consumer" is broader than customers. The Act counts employees and Colorado-resident job applicants.

A chatbot tells people things. A decision tool does things to them. Colorado regulates the second one harder, and it doesn't care if you have four employees.

Arthur, Bunny Honey Club

The good news is how much the Act carves out. Its definition of a consequential decision excludes routine scheduling, customer service triage, communicating a decision that was already made, and workflow management. Advertising, marketing, differentiated product recommendations, and search are excluded too.

Booking an appointment and routing a caller to the right person isn't a consequential decision. Neither is answering "are you open Saturday?"

Where a Small Business Actually Crosses the Line

Look at what your tools do, not what they're called.

Résumé screening. An AI tool that scores, ranks, or filters applicants for a Colorado job is the textbook case for the employment category. That can be true even if a human clicks the final button, because the test is whether the tool's output is a non-de minimis factor that affects the outcome by ranking, scoring, or classifying.

Tenant screening. A property manager whose AI ranks rental applicants is in the residential real estate category. If your AI receptionist for property management only answers maintenance calls and books showings, you're fine. If it also decides which prospects get a callback, read the definitions again.

Lead qualification tied to credit. A bot that sorts financing applicants, or gives some people materially worse terms than others, is in financial-services territory.

The Act does exclude tools that communicate with consumers in natural language to give information, make referrals, or answer questions. But there's a condition that people miss. The tool can't be contracted, advertised, marketed, configured, or intended for use in a consequential decision, and it has to be covered by an acceptable use policy that prohibits that use.

Plug a general chat model into your applicant pipeline and you've configured it for a consequential decision. The exclusion is gone.

Health providers get a partial pass. HIPAA covered entities are largely outside the Act, except for consequential decisions about employment.

What Compliance Looks Like If You're In

If your tool is covered, the Act asks for four things.

Notice before use. You give consumers clear notice that you use or will use covered ADMT in a consequential decision affecting them. A prominent public notice reasonably close to the point of interaction counts, such as a link on the application page.

An explanation after a bad outcome. If the tool materially influenced an adverse decision, you have 30 days to send a plain-language description of the decision and the tool's role in it, plus a simple way to request more information.

Correction and human review. The consumer can ask you to correct factually incorrect personal data and can request meaningful human review of the decision, to the extent commercially reasonable. The Act defines meaningful human review: a trained person with authority to override, who doesn't just default to the system's output.

Records. You keep compliance records for at least three years.

Enforcement belongs exclusively to the Attorney General, as a deceptive trade practice. If the AG decides a violation can be cured, you get written notice and 60 days. If the AG can show the violation was knowing or repeated, there's no cure period. The cure provision sunsets on January 1, 2030.

There's no new private right of action. That doesn't make hiring risk go away, because the Act says a deployer or developer can still be sued under Colorado's existing anti-discrimination law over a decision the tool materially influenced.

One more detail matters to anyone buying software. The Act voids contract clauses that indemnify a party against that kind of anti-discrimination liability, with limited exceptions. If your AI vendor's terms say every outcome is your problem, Colorado has opinions about that.

The Rules Aren't Final, So Build Flexibly

The Attorney General filed proposed rules on August 11, 2026. According to a National Law Review summary, the formal hearing is October 26, 2026, and the final comment period runs through that day.

For hiring, the draft floats two competing thresholds for when a tool's output counts as materially influencing the decision, and asks for input on which to adopt. That's the line that decides who's covered, and it isn't settled.

So don't rebuild anything around draft language. Do the inventory now, because it's the same work either way.

What We Do When We Scope a Build

We build AI receptionists and automations, so weigh this as coming from a vendor. Here's how we sort the work.

Every workflow goes in one of two piles. Informational work answers, books, routes, and confirms. Decisional work ranks, scores, approves, or denies.

The AI receptionists we build live in the first pile, and they stay there. Each one opens by saying it's an AI, which we do on every call regardless of state, as we explained in our state-by-state disclosure guide. It costs one sentence and removes a whole category of caller suspicion.

When a client wants the bot to start ranking applicants or screening tenants, that's a different project. It needs a named human reviewer, a notice, a record of what the tool saw, and a way for someone to ask for a second look. Colorado now writes that list into law. Building it in from day one is cheaper than retrofitting it after an AG letter.

Your homework before January 1 is short. List every AI tool that touches a hiring, housing, lending, or insurance decision. For each one, write down who reviews its output and where a person would ask for that review. If you can't answer, you found the gap.

— share
— keep reading

Three more from the log.