Colorado High-Risk AI Law
Tags: Regulatory
TL;DR
- Defines high-risk AI around “consequential decisions” (e.g., housing, jobs, healthcare) and assigns duties to Developers and Deployers.
- Requires risk assessments (initial, annual, and upon material changes) and consumer-facing disclosures, including opt-out info for profiling.
Why it matters for HK marketers: Global campaigns touch U.S. users and platforms; aligning to CO’s high‑risk, disclosure, and assessment model helps future‑proof governance.
What the law covers
- High-risk scope: AI is “high-risk” only when it materially affects access to essential services (housing, employment, healthcare, insurance, etc.). Most ad use cases are outside this—but edge cases can arise.
- Developer obligations: Exercise reasonable care to prevent algorithmic discrimination; publish documentation on purpose, instructions to deployers, training data, foreseeable uses/misuses, and bias assessment/governance steps.
- Deployer obligations: Conduct and refresh risk assessments; disclose system descriptions, impacted consequential decisions, access to system details, opt-out of profiling, types of high-risk systems in use, risk practices, and data sources.
Practical implications for advertising
- Typical ad targeting won’t be high-risk, but models touching eligibility for credit, housing or employment ad delivery criteria can drift into regulated territory.
- Documentation, bias testing, and opt-out language are becoming table stakes in contracts and product UX.
Guardrails to prioritize
- Build a standardized AI impact assessment that flags consequential decisions and profiling.
- Require vendors to provide purpose, data sources, and bias evaluation artifacts.
- Maintain an AI system inventory and change log for re‑assessments.
So what for marketers
Treat CO’s framework as a baseline for U.S. risk governance. Bake impact assessments, bias checks, and clear disclosures into any targeting or optimization that could influence access to essential services.
← Back to Knowledge Base