Colorado AI Act Obligations
Tags: Regulatory, Frameworks
TL;DR
- CAIA targets high‑risk AI tied to “consequential decisions” (e.g., housing, jobs, healthcare, lending).
- Developers must exercise reasonable care to prevent algorithmic discrimination and disclose system purpose, training data, foreseeable use/misuse, and bias assessment records.
- Deployers must run risk assessments (annually/after changes) and disclose purpose, impacted decisions, opt‑out info, data sources, and practices.
Why it matters for HK marketers: U.S. state rules can bind vendors and platforms you buy from, shaping product features, disclosures, and risk tests.
Scope and triggers
- High‑risk definition: Systems that play a key role in consequential decisions.
- Advertising generally isn’t covered unless it affects such outcomes.
Developer obligations (disclosures include)
- Intended purpose; instructions to deployers; training data used.
- Reasonably foreseeable uses and harmful/inappropriate uses.
- How discrimination was assessed; governance measures for bias.
Deployer obligations
- Conduct AI risk assessments annually and on material changes.
- Publicly disclose: system description and purpose; types of consequential decisions impacted; access to system details; right to opt‑out of profiling; high‑risk systems in use; risk practices; data sources.
So what for marketers
Ask U.S. vendors how they meet CAIA duties and request their risk assessments and disclosures. Align your procurement and transparency practices to those norms.
Sources:- IAB_AI_Governance_and_Risk_Management_Playbook_August_2025.pdf
← Back to Knowledge Base