The Colorado AI Act impact assessment was the centerpiece compliance obligation imposed on businesses that deploy high-risk artificial intelligence systems for consequential decisions, including hiring, promotion, compensation, and termination decisions made in employment contexts. Signed into law by Governor Jared Polis on May 17, 2024, the Colorado AI Act (CAIA) was the first comprehensive state-level AI regulation in the United States, and its impact assessment requirement drew direct inspiration from the environmental impact assessment (EIA) model that emerged in the United States under the National Environmental Policy Act in the 1970s. The idea was simple in theory: before an organization deploys an automated system that could materially affect a person's access to employment, housing, financial services, healthcare, or education, that organization must document what the system does, how it works, what risks it poses, and what mitigations are in place.

For employers and HR teams, this translated into a recurring documentation exercise covering every algorithmic tool touching consequential employment decisions, including resume-screening software, video interview scoring platforms, scheduling optimization tools, and workforce analytics. However, the story did not end there. Through 2025 and into 2026, the Act was amended repeatedly, its effective date was delayed multiple times, and ultimately Senate Bill 26-189 repealed and reenacted the law under a substantially different framework that reduced obligations on employers. As of August 2026, any organization building a Colorado AI Act impact assessment program needs to understand both the original architecture of the requirement and the current post-SB 26-189 reality, because the documentation discipline the original law demanded remains best practice regardless of which version of the statute applies.

Also worth reading: What does a joint pay assessment under the EU Pay Transparency Directive actually involve, and how should employers build a compliant workflow? · What is the definitive Colorado AI Act compliance audit checklist for employers in 2026? · What do employers need to do to comply with the Colorado AI Act in 2026?

What the Impact Assessment Actually Required Under the Original CAIA

Under the original Colorado AI Act, a deployer of a high-risk artificial intelligence system had to complete and regularly update an impact assessment before deploying the system and at least annually thereafter. A high-risk system was defined as any artificial intelligence system that, when deployed, makes or is a substantial factor in making a consequential decision, meaning a decision that has a material legal or similarly significant effect on a consumer's life, rights, opportunities, or access to critical resources. Employment sat squarely within this category alongside lending, housing, insurance, healthcare services, education enrollment, and legal services.

The impact assessment itself had to document several specific elements: the purpose of the system and its intended benefits, the categories of data processed as inputs, the metrics used to evaluate the system's performance and limitations, whether the system was known or reasonably foreseeable to discriminate based on protected characteristics such as race, color, disability, sex, gender identity, sexual orientation, religion, national origin, age, or veteran status, and the steps taken to mitigate those risks. Deployers also had to provide notice to consumers subject to a consequential decision, give individuals an opportunity to correct inaccurate data, and offer an appeal process allowing review of adverse decisions. For HR use cases, this meant that if an applicant screening algorithm filtered out candidates, the employer needed to tell applicants that AI was involved, explain the role of the system, disclose the categories of data collected, and maintain a human review path for contested outcomes.

The assessment obligation applied differently depending on your role in the AI supply chain. Developers of high-risk systems had their own disclosure duties, including publishing documentation about training data, intended uses, and known limitations. Deployers bore the heavier operational burden because they were the ones actually making consequential decisions. Small businesses received some accommodations, but the core assessment duty applied broadly, which is why legal commentators at firms like Ogletree Deakins, Littler Mendelson, and Hunton Andrews Kurth published extensive guidance on scoping these assessments through 2024 and 2025.

Why Colorado Built Its Law Around Impact Assessments

Colorado's choice of an impact assessment model rather than a prohibition model reflected a deliberate regulatory philosophy. Rather than banning certain AI applications outright, the state chose to make organizations prove, on paper and on a recurring basis, that they understood their own systems. This mirrors the logic of the National Environmental Policy Act's environmental impact statements: the government does not necessarily stop a project, but it forces the sponsor to study consequences before acting and to document mitigation measures. Legislators reasoned that most AI-related harms in employment and other domains stem not from malicious design but from unexamined deployment, where bias in training data or proxy variables produces discriminatory outcomes nobody intended and nobody measured.

The recurring nature of the requirement mattered as much as the initial assessment. Systems drift, vendors update models, and the composition of job applicant pools changes. An annual reassessment cycle forced deployers to treat AI governance as ongoing operations rather than a one-time checkbox. Colorado also positioned itself as a first mover: Governor Polis signed the law on May 17, 2024, explicitly framing it as a template for other states, and Connecticut subsequently enacted its own AI framework while Colorado later scaled its law back, creating a patchwork of state approaches that compliance teams must track. Federal activity added another layer, including Defense Production Act requirements directing US companies to report information to the federal government when training certain high-impact AI models, which meant multistate employers faced overlapping federal and state reporting expectations.

How the Law Changed: Amendments, Delays, and SB 26-189

The original effective date of February 1, 2026 proved unrealistic almost immediately. Industry groups, civil society organizations, and legislators themselves recognized that deployers lacked mature tooling and that the statutory definitions created ambiguity. The Act was amended and its effective date delayed, first pushing compliance deadlines out and softening some obligations. Then came the decisive move: Senate Bill 26-189 repealed and reenacted the Colorado AI Act entirely, hitting reset on the state's approach to AI regulation. Law firm analyses from Crowell & Moring and ArentFox Schiff described SB 26-189 as creating a new framework for developers and deployers, while Littler Mendelson noted that the amended law substantially reduced obligations on employers specifically.

The practical consequence is that the heavy version of the impact assessment regime many employers spent 2024 and 2025 preparing for no longer exists in its original form. Under the reenacted framework, the burden distribution shifted, documentation requirements became more targeted, and the strictest employer-facing duties were pared down. At the same time, commentators pointed out that the repeal-and-reenact structure opened new trails for private AI litigation, meaning courts may still adjudicate AI-related discrimination claims even where statutory paperwork requirements eased. Employers should therefore resist the temptation to shred their existing assessment work product: documented diligence remains the strongest defense in litigation and audits, and other states' laws plus emerging federal expectations keep pressure on organizations that use AI in HR.

Practical Steps for Building an AI Impact Assessment Program Today

Even with softened statutory obligations, a disciplined program starts with inventorying every AI system that touches people decisions. Map each tool to the decision it influences: sourcing, resume ranking, interview scoring, skills testing, performance evaluation, promotion recommendation, compensation analysis, scheduling, attrition prediction, and termination support. Classify each by risk tier, reserving the highest scrutiny for systems that are a substantial factor in consequential decisions. For each high-risk system, assemble a written assessment covering purpose, input data categories, performance metrics, known limitations, foreseeable discrimination risks against protected characteristics, and mitigation controls such as human-in-the-loop review, bias testing cadence, and candidate notification procedures.

Vendor management is the second pillar. Most employers do not build their own hiring algorithms; they buy them. Your assessment depends on developer disclosures, so request documentation on training data, validation studies, adverse impact ratios, and intended-use boundaries from every vendor. Where a vendor refuses to provide adequate documentation, that refusal is itself a risk signal worth recording. Third, establish governance ownership: assign accountability to a named executive or committee, set an annual refresh cycle aligned to vendor model updates, and integrate findings with your broader EEO-1, OFCCP, and ADA accommodation compliance workflows. Finally, preserve records. Whether or not the current statute demands them, auditors, plaintiffs' attorneys, and future regulators will ask what you knew about your systems and when you knew it.

Comparing Compliance Approaches: Manual Documentation Versus Automated Platforms

Organizations approaching Colorado-style AI assessments generally choose between spreadsheet-driven manual programs and dedicated compliance platforms. Each has tradeoffs worth weighing honestly.

FeatureManual / Spreadsheet ApproachDedicated AI Compliance Platform
Upfront costLow; internal labor onlySubscription fees, typically thousands to tens of thousands annually depending on headcount and system count
Setup timeWeeks to months, dependent on internal expertiseFaster templated onboarding, often days to weeks
Version controlFragile; documents scattered across drivesCentralized audit trail with timestamps
Vendor disclosure trackingManual follow-up emails, easily lostStructured requests and reminders
Regulatory change monitoringRequires manual tracking of state legislationBuilt-in alerts for statutes like CAIA/SB 26-189, NYC Local Law 144, EU AI Act
Best fitVery small employers with one or two AI toolsMulti-state employers, staffing firms, enterprises with many HR tech vendors
Neither option eliminates judgment work. A platform cannot decide whether your screening model discriminates against older workers; it can only force the question to be asked, answered, and timestamped. Conversely, a well-run manual process at a small company may outperform a poorly configured enterprise tool. The deciding factors are volume of AI systems, number of states operated in, and litigation exposure. Given that patchwork AI hiring laws create rising compliance risks, as coverage in the National Law Review and IAPP has emphasized, organizations operating across jurisdictions increasingly find manual tracking untenable.

Common Mistakes That Undermine Assessment Programs

The most frequent error is treating the impact assessment as a vendor-provided form to sign rather than a deployer-owned analysis. Even when a supplier supplies documentation, the deployer remains responsible for evaluating fitness for its own use case, applicant population, and decision context. A second mistake is scoping too narrowly around hiring algorithms while ignoring adjacent systems: scheduling optimization that disproportionately burdens employees with caregiving responsibilities, productivity-monitoring analytics, and pay-equity modeling all touch consequential decisions and belong in scope. Third, many organizations write an assessment once and never revisit it, defeating the annual-cycle intent; a model updated by the vendor in March invalidates a January assessment.

A fourth mistake is confusing notification with transparency boilerplate. Telling candidates that AI is used satisfies little if the notice omits the data categories collected, the availability of human review, and correction or appeal mechanisms. Fifth, companies sometimes overcorrect after SB 26-189 and assume all obligations vanished, abandoning documentation entirely; given the law's history of repeal, amendment, and reenactment, plus active private litigation around algorithmic employment discrimination, discarding evidence of diligence is strategically reckless. Finally, organizations frequently fail to train recruiters and hiring managers, who remain the humans in the loop and whose overrides or blind acceptance of algorithmic rankings determine whether mitigations actually function.

When to Act and What It Costs

Act now regardless of statutory timing. The sequence of events since May 2024, signing, amendment, delay, and eventual repeal-and-reenactment via SB 26-189, demonstrates that Colorado's framework will continue evolving, and states like Connecticut are enacting parallel frameworks while federal reporting requirements for high-impact model training take shape under the Defense Production Act. Organizations that built assessment muscle during the original compliance window hold a durable advantage: their inventories, vendor files, and bias-testing baselines transfer directly to whatever framework emerges next, and to litigation defense today.

Costs vary widely. A small employer with two or three AI tools can run a credible manual program with 40 to 80 hours of combined HR, legal, and IT effort per year, effectively an internal cost of perhaps $10,000 to $25,000 annually at loaded rates. Mid-market and enterprise deployments typically add external bias audits ($15,000 to $75,000 per major system depending on complexity), legal review, and platform subscriptions ranging from roughly $5,000 to $100,000+ per year. Compare this against the alternative: a single adverse-action lawsuit involving an algorithmic hiring tool routinely costs multiples of a decade of compliance spend, before accounting for reputational damage and settlement terms. The economic case for documented diligence is straightforward even where the statute no longer strictly compels it.

The Bottom Line for HR and Compliance Leaders

The Colorado AI Act impact assessment began as the nation's most demanding template for proving that automated employment decisions are fair, transparent, and contestable. Its evolution through amendment, delay, and SB 26-189's repeal-and-reenactment reduced statutory obligations on employers, but it did not reduce the underlying stakes. Algorithmic hiring discrimination remains litigable, other states regulate independently, federal reporting expectations are expanding, and candidates and employees increasingly expect disclosure and appeal rights. The disciplined organizations are those that kept their inventories current, their vendor documentation complete, and their human-review pathways functional through every regulatory swing. Treat the impact assessment not as a dead requirement but as the permanent operating standard for anyone deploying AI in consequential people decisions.