On August 11, 2026, the Colorado Department of Law released a single set of proposed rules substantially building out two 2026 statutes: the Automated Decision-Making Technology Act (“ADMT Act”) and the Conversational Artificial Intelligence Service Operator Requirements (the “Chatbot Safety Act”). Both laws take effect January 1, 2027, and the proposed rules would become effective the same day. The Rules are not yet final – for covered organizations and interested parties the weeks until September 4 are the time to submit comments to be considered for a redraft – and there is a specific ask to help shape the definition of covered ADMT.

The Automated Decision-Making Technology & Conversational Artificial Intelligence Services Rules (“Rules”) clarify open terms and add operational obligations, and they signal that Colorado’s revised AI framework may demand significantly more compliance infrastructure than the statutes alone suggest.

The ADMT Act governs automated decision-making technology used to materially influence consequential decisions; specifically, those affecting a consumer’s access to, eligibility for, or terms of education, employment, the lease or purchase of residential real estate in Colorado, financial or lending services, insurance, health-care services, and essential government services or public benefits. In the employment context, “consumer” reaches Colorado-resident employees and job applicants.

The Chatbot Safety Act is narrower in scope but operationally demanding for the operators it covers. It targets general-purpose, consumer-facing conversational AI services offered to the public, imposing age-estimation, disclosure, minor-protection, crisis-response, and annual-reporting duties. Notably, rulemaking is mandatory for the ADMT Act, but Chatbot Safety Act rulemaking is discretionary. Still, the Attorney General nonetheless chose to address in the same package to clarify operator obligations, including the content of the required annual report.

Key ADMT definitions

  • ADMT: Technology that processes personal data and uses computation to generate outputs – such as predictions, recommendations, classifications, rankings, or scores – that are used to make, guide, or assist decisions about individuals.
  • Covered ADMT: ADMT used to materially influence a consequential decision.
  • Excluded functions: The proposed rules carve out ordinary infrastructure and certain low-risk functions, including routing, translation, summarization, scheduling, customer-service triage, advertising, marketing, search, and content moderation.

The most important unresolved issue is when ADMT “materially influences” a decision. The proposed rules do not adopt a single definition of the term. Instead, the Department proposes two possible standards for determining whether an ADMT output is more than de minimis and asks the public which to adopt.

Both versions include a rebuttable presumption of material influence where the output 1) constrains the available options, sets a threshold, or produces a rank, score, classification, or inference that relates to the individual; and 2) is reviewed by the decision-maker or used to screen the data the decision-maker sees, and is consistent with the outcome. Similarly, either formulation could require organizations to preserve evidence that a human decision-maker exercised independent judgment or relied on other documented factors.

Adverse outcome notices (ADMT Act)

The Rules would require deployers to provide detailed disclosures within 30 days after a covered ADMT materially influences an adverse outcome. The notice must identify the decision, explain the purpose of the ADMT, describe the roles of the ADMT and any human reviewers, and state the principal reasons for the outcome with specificity. Generic references to internal policies would not suffice.

The rules also require additional explanation when a decision relies on an inference, profile, risk score, automatic-denial factor, or incomplete information. This could prove difficult in applicant-screening, lending, housing, insurance, and other contexts where systems automatically screen out incomplete or disqualifying applications. Organizations may need decision-level explainability and data lineage that they do not currently receive from vendors.

Consumer rights and request handling (ADMT Act)

The Rules would require deployers to make detailed information about the ADMT available to consumers. This includes the system name and version, the developer, and the types, categories, and sources of personal data used. If data was received through an intermediary, the deployer may need to identify both the intermediary and the original source. The requirement to name the original source behind brokered data may be particularly difficult where deployers receive information through aggregators or data brokers; and standard vendor representations that data was collected in compliance with applicable law do not answer the question. This level of traceability may require new vendor commitments and internal recordkeeping processes.

The timing requirements are equally demanding. Some information must be available immediately through designated channels, while other requests must be handled within short regulatory windows. Consumers may obtain the personal data used in the decision, including ranks, scores, classifications, recommendations, predictions, inferences, or other ADMT inputs relating to them. Information must be presented in a way that lets the consumer decide whether to seek correction or human review, rather than in unexplained internal codes.

Meaningful human review (ADMT Act)

The proposed rules would make human review a staffed, documented process. Where feasible, the reviewer must be independent of the original decision-maker and not that person’s subordinate, appropriately trained, authorized to change the outcome, and able to conduct the review without ADMT assistance. The statute allows review only to the extent commercially reasonable, but the proposed rules identify factors for assessing commercial reasonableness and create a presumption in favor of review where the adverse outcome involves the severe and irreversible denial of a basic human need. The rules instruct deployers to weigh the type of review required, the magnitude and reversibility of the harm, the value of reviewing available primary evidence, the deployer’s size and capacity, the cost and technical feasibility of review, and the availability of qualified reviewers, with no single factor controlling.

Deployers would need to acknowledge human-review requests within 10 days and complete the review within 45 days. Where possible, they must stay the adverse outcome while review is pending and while incorrect personal data is being corrected. They must also document the reviewer’s qualifications, the evidence considered, the disposition, and a written justification.

Chatbot Safety Act obligations

The Chatbot Safety Act is narrower but operationally significant for covered operators. Internal-only workforce deployments behind authentication appear to fall outside the general-public scope; and narrow, task-specific bots may remain outside the Act where they are limited to bounded functions. Covered consumer-facing conversational AI services would face age-assurance, disclosure, privacy, minor-protection, crisis-response, and reporting requirements.

The proposed rules would require age-assurance methods that go beyond self-declaration, prohibit government-issued identification from serving as the sole method, and require reassessment when new signals indicate a different likely age. Operators would also need to report metrics on age distributions, age-estimation methods, crisis-referral outcomes, resolution times, and changes in age determinations. Meeting these requirements may force product, engineering, privacy, and trust-and-safety teams to build measurement and reporting systems before the effective date.

Practical implications

The proposed rules would require far more than updated notices. Organizations using ADMT in covered domains should expect compliance work extending well beyond legal and privacy teams. Participation from product, HR, risk, compliance, data governance, security, and vendor management will be necessary to have an effective compliance posture.

Organizations using ADMT in covered domains should inventory covered use cases, map vendor systems and data inputs, confirm whether outputs materially influence decisions, build adverse-outcome notice templates, create consumer-request workflows, negotiate vendor support for decision-level explanations, and designate trained human reviewers. Covered chatbot operators may need to assess whether their services are within scope and, if so, build age-assurance, user-safeguard, and reporting capabilities.

Comment period is open…speak now or forever hold your peace

The Department’s comment portal is open from August 11 through October 26, 2026, with a public rulemaking hearing scheduled for October 26. The more immediate practical deadline is September 4, because comments submitted by then are expected to be considered for a revised draft; any interim updates to the proposed rules are expected to be posted by September 23. Organizations should consider commenting as the proposed rules require information that vendors may not provide, impose potentially impractical timelines, or create operational assumptions inconsistent with existing business processes.

Bottom line

Colorado’s revised AI law was expected to be a narrower disclosure and consumer-rights framework. The proposed rules suggest that compliance may still require significant infrastructure, including decision-level explainability, data-source traceability, staffed human-review processes, and chatbot safety reporting. Companies using ADMT or consumer-facing conversational AI should use the comment period to assess compliance gaps, engage vendors, and identify requirements may be difficult or impossible to implement as drafted.

Senior United States District Judge William H. Orrick, sitting in the Northern District of California, denied a motion to dismiss last week in an Automated License Plate Recognition (“ALPR”) matter, McGinty v. Reimagined Parking LLC, d/b/a Imperial Parking.[1] Judge Orrick held that the plaintiff plausibly alleged actionable harm based on his “right to know” about the use of ALPR systems in two garages. The order follows Bartholomew v. Parking Concepts, Inc.[2] and the guidance of Mata v. Digital Recognition Network, Inc.,[3] concluding that the California Supreme Court would likely recognize violation of a consumer’s “right to know” as actionable harm under California’s ALPR law if presented with the question.

Continue Reading Federal Court Follows Bartholomew Reasoning in Denying Motion to Dismiss ALPR Lawsuit

In this episode of Consumer Counterpoint, Kristine and Paul discuss the recent decision out of the Seventh Circuit that held that text messages do not count as “telephone calls” for purposes of a private right of action under Section 227(c) of the Telephone Consumer Protection Act and what this may mean for pending litigation alleging DNC violations based on texting campaigns.

Watch the Quick Take Here:

Subscribe to the Consumer Class Defense Blog today and get notified when each new vidcast goes live.

On July 21, 2026, the California Privacy Protection Agency, now branding itself publicly as CalPrivacy, announced that its Audits Division has launched its first formal privacy audit, focused on gig economy platforms operating in California. The audit is the first in a planned series of “sectoral audits” and will evaluate whether major gig platforms are complying with the California Consumer Privacy Act (CCPA), particularly with respect to consumers’ and workers’ rights to access and control personal information.

Although the audit is directed at app-based transportation, delivery, and task-service platforms, the broader message is important for any business collecting applicant, worker, contractor, geolocation, profiling, performance, biometric, communications data, or automated decision-making technology (ADMT) use in California. CalPrivacy’s focus on gig workers also reinforces a point that employers and workforce platforms should not underestimate: California privacy rights apply not only to traditional consumers, but also to employees, job applicants, and independent contractors.

Continue Reading California Privacy Regulator Launches First Sectoral Audit—Targets Gig Platforms

Episode 21 is now live. In this Consumer Counterpoint Quick Take, Kristine Argentine and Paul Yovanic discuss takeaways from a recent Ninth Circuit oral argument on arbitration provision enforceability.  

Watch Episode 21 Here:

Subscribe to the Consumer Class Defense Blog today and get notified when each new vidcast goes live.

Thursday, August 6, 2026
2:00 p.m. to 3:00 p.m. Eastern
1:00 p.m. to 2:00 p.m. Central
12:00 p.m. to 1:00 p.m. Mountain
11:00 a.m. to 12:00 p.m. Pacific

REGISTER HERE

About the Decoding Data Privacy Series

Data privacy and cybersecurity have become critical business risks for companies as they increasingly rely on technology to collect, store, monitor, and manage employee and customer information. From biometric data, workplace monitoring tools, marketing-based communication systems and connected tracking technologies, and AI-enabled technologies to vendor management, cross-border data transfers, and cyber incident response, companies face a rapidly evolving patchwork of legal obligations and litigation risks.

The Decoding Data Privacy webinar series will provide practical guidance on navigating today’s most pressing privacy and cybersecurity challenges, helping organizations protect sensitive workforce and consumer data, mitigate risk, and stay ahead of emerging regulatory and enforcement trends.

About the Program

Session 1: Vendor Contracting at the Intersection of Employment, Privacy, and Commercial Litigation

Companies increasingly depend on third-party providers to support nearly every aspect of the employment and business lifecycle, from payroll and benefits administration to recruiting platforms, timekeeping systems, workforce, consumer, and website analytics tools, customer relationship management, marketing and emerging AI technologies. As these vendors gain access to sensitive employee and business information, contractual decisions can create significant exposure not only under employment, privacy, and cybersecurity laws, but also in commercial disputes arising from data breaches, service failures, indemnification obligations, and allocation of risk.

In this practical discussion of how vendor agreements can serve as both a compliance tool and a critical risk-management mechanism, our experienced practitioners examine the provisions that matter most when evaluating technology and service vendors and discuss how thoughtful contracting can help organizations mitigate regulatory exposure, prepare for cyber incidents, comply with privacy obligations, and strengthen their position when disputes arise.

Topics include:

  • Managing risk through indemnification, insurance, limitations of liability, and dispute resolution provisions
  • Privacy, cybersecurity, and compliance obligations in vendor agreements
  • Contractual considerations for data maintenance and access, cyber incidents, and vendor accountability
  • Biometric technologies and emerging workplace and marketing technologies offered by third party service partners that create heightened legal and litigation risk
  • Structuring vendor relationships to better protect employee and business data
  • Key considerations for payroll, benefits, recruiting, and timekeeping vendors
  • Lessons learned from privacy, cybersecurity, and commercial disputes involving third-party providers

Speakers

Kristine Argentine, Partner, Seyfarth Shaw LLP
Ada Dolph, Partner, Seyfarth Shaw LLP
Paul Yovanic, Partner, Seyfarth Shaw LLP
Ala Salameh, Associate, Seyfarth Shaw LLP

REGISTER HERE

If you have any questions, please contact Kate Stacey at kstacey@seyfarth.com and reference this event.

Learn more about our DATA Law and Consumer Class Actions practices.

To comply with State CLE Requirements, CLE forms requesting credit in IL or CA must be received before the end of the month in which the program took place. Credit will not be issued for forms received after such date. For all other jurisdictions forms must be submitted within 10 business days of the program taking place or we will not be able to process the request.

Our live programming is accredited for CLE in CA, IL, and NY (for both newly admitted and experienced).  Credit will be applied as requested, but cannot be guaranteed for TX, NJ, GA, NC and WA. The following jurisdictions may accept reciprocal credit with our accredited states, and individuals can use the certificate they receive to gain CLE credit therein: AZ, AR, CT, HI and ME. For all other jurisdictions, a general certificate of attendance and the necessary materials will be issued that can be used for self-application. CLE decisions are made by each local board, and can take up to 12 weeks to process. If you have questions about jurisdictions, please email CLE@seyfarth.com.

Please note that programming under 60 minutes of CLE content is not eligible for credit in GA. programs that are not open to the public are not eligible for credit in NC.

In this Consumer Counterpoint: Quick Take, Kristine Argentine and Paul Yovanic discuss California Senate Bill 690 and its proposed amendments to the California Invasion of Privacy Act (CIPA). They examine the bill’s latest effort to restrict private lawsuits involving alleged pen-register or trap-and-trace violations arising from websites and mobile applications, shift enforcement authority to the California Attorney General, and address certain pending claims retroactively. They also explore what the proposal could mean for businesses navigating the continuing wave of CIPA litigation.

Watch the Quick Take Here:

Subscribe to the Consumer Class Defense Blog today and get notified when each new vidcast goes live.

Episode 20 is now live. In this episode of Consumer Counterpoint, Kristine Argentine and Paul Yovanic provide a mid-year review on wiretapping and pixel tracking litigation under the California Invasion of Privacy Act and similar statutes, including recent court decisions and what to expect later this year.

Watch Episode 20 Here:

Subscribe to the Consumer Class Defense Blog today and get notified when each new vidcast goes live.

Episode 19 is now live. In this episode of Consumer Counterpoint, we discuss a trend of TCPA cases involving violations based on numbers that have been reassigned or were incorrectly input at the consent stage such that there may not be prior express consent from the recipient of the call or text. This episode explores both defenses and strategies available in these litigations as well as best practices for marketing in order to mitigate against the risk of these types of cases. 

Watch Episode 19 Here:

Subscribe to the Consumer Class Defense Blog today and get notified when each new vidcast goes live.

Episode 18 is now live. In this episode of Consumer Counterpoint, Kristine Argentine and Paul Yovanic examine the evolving landscape of arbitration and what it means for businesses today. The discussion explores recent developments in litigation strategy, shifting judicial perspectives, and the growing use of coordinated mass filings. They offer practical insights into when arbitration provisions still make sense—and when companies may want to rethink their approach in light of current risks and trends.

Watch Episode 18 Here:

Subscribe to the Consumer Class Defense Blog today and get notified when each new vidcast goes live.