HomeAI LawsColoradoBoulder

AI Laws in Boulder, Colorado

As of 2026-08-12, AI Laws USA tracks 24 AI rules that apply to people and businesses in Boulder, Colorado: 10+ federal protections, 13 Colorado state-level rules, and 1 local Boulder/county ordinance. Coverage is strongest on automated decision-making, consumer protection, AI disclosure and transparency, and AI hiring and employment. 8 of these rules are already in effect. Each entry below links to its official source.

Boulder local AI rules (and Boulder County)

1 local AI rule specific to Boulder, Colorado or Boulder County.

  1. In effect Moderate protection

    Boulder County CO Generative AI Use Policy

    Boulder County, CO · Effective 2025-05-13 · Boulder County Administrative Policy (2025) (2025-05-13)

    Boulder County adopted generative AI use policy: requires staff training, prohibits entry of confidential or PII data into public LLMs, requires disclosure when AI is used in resident-facing communications, and bans AI-only decisions on benefits or enforcement.

    View full entry →  ·  Official source ↗

Colorado-level AI rules most relevant to Boulder

13 Colorado state rules apply to residents and businesses in Boulder. Showing the 8 most relevant to Boulder's local picture; 5 more are on the Colorado jurisdiction page.

  1. Enacted (not yet in effect) Limited protection

    CO ADMT Act (SB 26-189, 2026)

    Colorado · Effective 2027-01-01 · Colo. SB 26-189 (2026), signed May 14, 2026, eff. January 1, 2027

    Colorado Governor Jared Polis signed SB 26-189 on May 14, 2026, repealing and replacing the original Colorado AI Act (SB 24-205) before it could take effect. The replacement law creates a disclosure-focused framework for 'Automated Decision-Making Technology' (ADMT) — a narrower category than the prior law's 'high-risk AI' — applicable to consequential decisions in employment, housing, healthcare, credit, education, insurance, and government services. The original Colorado AI Act had been blocked by a federal court on constitutional grounds days before the replacement was passed. The new ADMT Act takes effect January 1, 2027.

    View full entry →  ·  Official source ↗

  2. Repealed / replaced Limited protection

    Colorado AI Act (repealed)

    Colorado · Enacted 2024-05-17 · SB 24-205, Colo. Rev. Stat. § 6-1-1701 et seq. (repealed/replaced 2026)

    The first comprehensive US state AI law would have required developers and deployers of 'high-risk' AI systems to use reasonable care to prevent algorithmic discrimination in decisions about jobs, housing, lending, insurance, education, and healthcare. After repeated delays, it was repealed and replaced in May 2026 by a narrower transparency-focused law (SB 26-189) before it ever took effect.

    View full entry →  ·  Official source ↗

  3. Enacted (not yet in effect) Limited protection

    SB 26-189 (Colorado ADMT Law)

    Colorado · Effective 2027-01-01 · SB 26-189 (Colo. 2026)

    Colorado's replacement AI law focuses on transparency rather than broad anti-discrimination duties. Starting January 1, 2027, companies using automated decision-making technology to materially influence consequential decisions (employment, housing, lending, insurance, healthcare) must notify consumers before use and provide post-decision disclosures; developers must give deployers technical documentation.

    View full entry →  ·  Official source ↗

  4. Proposed / pending Limited protection

    Colorado Attorney General Rulemaking for the Automated Decis

    Colorado · Effective 2026-06-30 · Colorado Attorney General Rulemaking for the Automated Decision-Making Technology (ADMT) Act and Chatbot Safety Act

    The Colorado Attorney General's Office opened pre-rulemaking to write rules implementing the state's Automated Decision-Making Technology Act (algorithmic-discrimination protections for high-risk AI) and the Chatbot Safety Act, taking public comment through July 13, 2026 ahead of the laws' January 1, 2027 effective date.

    View full entry →  ·  Official source ↗

  5. In effect Limited protection

    CO SB 17-213 (AV statute)

    Colorado · Effective 2017-06-01 · Colo. Rev. Stat. § 42-4-242

    Colorado authorized automated driving systems, allowing AVs that can comply with all traffic laws to operate without a separate state authorization — but if the ADS cannot fully comply, the operator must coordinate with CDOT and the State Patrol before deployment.

    View full entry →  ·  Official source ↗

  6. Enacted (not yet in effect) Moderate protection

    CO AI Act (SB 24-205)

    CO · Effective 2027-01-01 · Colo. Rev. Stat. §§ 6-1-1701 to 6-1-1707; SB 24-205 (2024)

    Colorado was the first state to enact a comprehensive AI law regulating high-risk AI used to make consequential decisions about Coloradans — including credit, insurance, employment, housing, healthcare, and government services. It requires risk management, bias audits, and consumer disclosure; deceptive AI practices are deemed unfair under the Colorado Consumer Protection Act.

    View full entry →  ·  Official source ↗

  7. Repealed / replaced Unknown

    CO SB24-205 (original)

    CO · Effective 2026-02-01 · Colo. SB 24-205 (2024) — substantially superseded by SB 26-189 (May 14, 2026)

    Colorado SB24-205 was the first U.S. comprehensive high-risk AI statute (2024). The original framework was substantially rewritten by SB 26-189 after the 2026 special session — this entry is the historical record of the original law.

    View full entry →  ·  Official source ↗

  8. In effect Limited protection

    CO AG Weiser

    CO · Effective 2026-04-27 · CO AG Weiser — Suspension of Colorado AI Act Rulemaking and Enforcement (x.AI v. Weiser) (2026-04-27)

    AG entered joint motion to stay enforcement of SB 24-205 in xAI Corp. v. Weiser, No. 1:26-cv-01515-DDD-CYC (D. Colo.; Chief Judge Daniel D. Domenico; Magistrate Judge Cyrus Y. Chung). DOJ intervened on xAI's side April 24, 2026; federal court entered enforcement stay April 27, 2026. Colorado enacted SB 26-189 (signed May 14, 2026) to repeal and replace SB 24-205; enforcement suspended until rulemaking under new ADMT law by December 31, 2026.

    View full entry →  ·  Official source ↗

See all 13 Colorado AI rules →

Federal AI rules that apply in Boulder, Colorado

These federal protections apply everywhere in the United States, including Boulder, Colorado. Showing the 10 strongest and most recent.

  1. In effect Stronger protection

    Bartz v. Anthropic

    N.D. Cal. · Effective 2025-09-05 · Bartz v. Anthropic PBC, No. 3:24-cv-05417 (N.D. Cal.)

    Authors Andrea Bartz, Charles Graeber, and Kirk Wallace Johnson sued Anthropic over its use of pirated-book datasets to train Claude. In June 2025 Judge William Alsup ruled that training on lawfully purchased books was fair use. The piracy claims (LibGen ingestion) proceeded toward settlement; in September 2025 Anthropic agreed to a $1.5 billion class settlement covering ~500,000 works. Judge Alsup granted preliminary approval September 25, 2025 and final approval July 20, 2026. The appeal period runs through August 19, 2026; class members will not receive payments until at least end of 2026.

    View full entry →  ·  Official source ↗

  2. In effect Stronger protection

    Benavides v. Tesla (Autopilot)

    S.D. Fla. · Effective 2025-08-01 · Benavides v. Tesla, Inc., No. 1:21-cv-21940 (S.D. Fla. Aug. 1, 2025)

    A Florida federal jury found Tesla 33% liable in August 2025 for the 2019 death of Naibel Benavides Leon, in a crash involving Autopilot. The jury awarded $243M ($129M compensatory + $200M punitive); in February 2026 the court denied Tesla's post-trial motions and upheld the verdict in full — the first Autopilot wrongful-death verdict against Tesla.

    View full entry →  ·  Official source ↗

  3. In effect Stronger protection

    COPPA + 2025 Rule (childrens data)

    United States · Effective 2025-06-23 · 15 U.S.C. §§ 6501–6506; 16 C.F.R. Part 312

    COPPA requires online services aimed at children under 13 to get verifiable parental consent before collecting kids' personal data. The 2025 rule update — fully in effect since April 22, 2026 — adds biometric identifiers (like face templates and voiceprints, which matter for AI tools), requires separate parental consent before sharing children's data for targeted advertising, and tightens data retention limits.

    View full entry →  ·  Official source ↗

  4. In effect Stronger protection

    TAKE IT DOWN Act

    United States · Effective 2025-05-19 · Pub. L. No. 119-12 (S. 146)

    Makes it a federal crime to knowingly publish intimate images of someone without consent, including AI-generated deepfakes. Social media and similar platforms must give victims a way to request removal and must take the content (and known copies) down within 48 hours. The platform removal requirement became enforceable May 19, 2026, and the FTC has already begun enforcement.

    View full entry →  ·  Official source ↗

  5. Blocked / in litigation Stronger protection

    NetChoice v. Yost (Ohio)

    S.D. Ohio · Effective 2025-04-16 · NetChoice, LLC v. Yost, No. 2:24-cv-00047 (S.D. Ohio Apr. 16, 2025)

    Ohio's Social Media Parental Notification Act — requiring parental consent for minors' social-media use, including algorithmic feeds — was preliminarily enjoined on February 12, 2024, then permanently enjoined on April 16, 2025 when the district court granted summary judgment for NetChoice. The state appealed to the Sixth Circuit, which vacated the district court's injunction in 2026.

    View full entry →  ·  Official source ↗

  6. In effect Stronger protection

    Thaler v. Perlmutter (Copyright)

    D.C. Cir. · Effective 2025-03-18 · Thaler v. Perlmutter, 130 F.4th 1039 (D.C. Cir. 2025)

    The companion copyright case: Stephen Thaler sought to register a copyright with 'Creativity Machine' (his AI) as the author. The D.C. Circuit affirmed in March 2025 that the Copyright Act's human-authorship requirement is dispositive as a matter of statutory law. AI cannot be a copyright author under U.S. law.

    View full entry →  ·  Official source ↗

  7. In effect Stronger protection

    Thomson Reuters v. Ross

    D. Del. · Effective 2025-02-11 · Thomson Reuters Enterprise Centre GmbH v. Ross Intelligence, Inc., No. 1:20-cv-00613 (D. Del. Feb. 11, 2025)

    Thomson Reuters sued legal-research startup Ross Intelligence in 2020 for copying Westlaw headnotes to train a competing AI legal-research tool. In February 2025, Judge Stephanos Bibas (sitting by designation) granted summary judgment to Thomson Reuters on direct copyright infringement and rejected Ross's fair-use defense — the first definitive U.S. ruling on AI-training fair use. No jury trial occurred: a 2023 opinion had denied summary judgment and pointed toward trial, but the court invited renewed briefing and reversed course in the 2025 ruling.

    View full entry →  ·  Official source ↗

  8. In effect Stronger protection

    Louis v. SafeRent

    D. Mass. · Effective 2024-11-20 · Louis v. SafeRent Solutions, LLC, No. 1:22-cv-10800 (D. Mass.)

    SafeRent agreed in November 2024 to a $2.275M settlement and a five-year ban on using its 'SafeRent Score' for housing-voucher applicants, after a class action alleged its AI tenant-screening tool systematically denied housing to Black and Hispanic Section 8 voucher holders. The first major AI tenant-screening Fair Housing Act settlement.

    View full entry →  ·  Official source ↗

  9. In effect Stronger protection

    FTC Impersonation Rule (AI)

    United States · Effective 2024-04-01 · 16 C.F.R. Part 461; 89 Fed. Reg. 15017

    The FTC's Impersonation Rule lets the agency directly sue scammers who pretend to be a government agency or a real business — including those who use AI-cloned voices or generated images to do so. Civil penalties can reach $53,088 per violation. The FTC also issued a supplemental notice in February 2024 proposing to extend the rule to all individual impersonation.

    View full entry →  ·  Official source ↗

  10. In effect Stronger protection

    TCPA (AI voice calls)

    United States · Effective 2024-02-08 · 47 U.S.C. § 227; FCC 24-17

    Robocalls using AI-cloned or AI-generated voices are treated like other 'artificial voice' calls: callers need your prior express consent, must identify themselves, and must offer opt-outs for telemarketing. You can personally sue violators for $500 to $1,500 per illegal call.

    View full entry →  ·  Official source ↗

See all federal AI rules →

Frequently asked questions about AI laws in Boulder, Colorado

Are there AI laws in Boulder, Colorado?
Yes. We index 1 local AI rule that specifically apply in Boulder, Colorado, including Boulder County CO Generative AI Use Policy. On top of that, 13 Colorado state-level rules and 10+ federal AI protections apply throughout the city.
What federal AI rules apply in Boulder?
Every federal AI protection in our index applies in Boulder, Colorado. The highest-strength federal rules currently include Bartz v. Anthropic, Benavides v. Tesla (Autopilot), COPPA + 2025 Rule (childrens data). 10+ federal entries are tracked in total.
Does Colorado have an AI privacy law?
Colorado has 11 privacy- or automated-decision-related AI rules in our index, including CO AI Act (SB 24-205) and CO ADMT Act (SB 26-189, 2026). These apply to residents of Boulder.
Are deepfakes illegal in Colorado?
Colorado has 2 deepfake- or AI-image-related laws in our index, including CO Candidate Deepfake Disclosure Law and CO Intimate Digital Depictions Act (SB25-288). Additionally, the federal TAKE IT DOWN Act covers non-consensual intimate-image deepfakes nationwide.
Can my employer use AI to screen me for jobs in Boulder?
Employer use of AI to screen job applicants in Boulder, Colorado is governed by CO AI Act (SB 24-205) and CO ADMT Act (SB 26-189, 2026). Federal civil-rights and EEOC guidance also applies.
How do I report an AI law violation in Boulder?
Most AI rules are enforced by an agency listed on each individual entry. For Colorado state laws, the Colorado Attorney General's office is the usual starting point. For federal AI rules, file complaints with the relevant federal agency (FTC, EEOC, HUD, CFPB, etc.) named on each protection entry. We also accept tips at feedback@ailawsusa.com.
Are facial recognition cameras allowed in Boulder?
Boulder, Colorado has no facial-recognition-specific rule in our index. Use by private businesses is largely unregulated, while government use is governed by general Fourth Amendment and Colorado law.
Is Boulder regulated by Colorado's consumer privacy act?
Yes. Colorado state laws apply uniformly to residents and businesses operating in Boulder. See the Colorado jurisdiction page for the complete list of consumer-protection and privacy rules.

Compliance guides for Colorado businesses

Plain-English guides to the Colorado AI & data laws companies most often need to comply with:

Have we missed an AI rule in Boulder?

This page is generated from our open civic dataset. If you know of a Boulder ordinance, county rule, or local enforcement action we should add, email feedback@ailawsusa.com or submit a correction. Every entry must include a verifiable source.