The law library · Colorado, United States · US state law
Colorado: HB 26-1263, conversational AI service operators
Concerning requirements for an operator of a conversational artificial intelligence service · signed 29 May 2026 · act effective 12 August 2026 · operator duties on and after 1 January 2027
Page verified 13 August 2026 against the Final Act text and bill record on leg.colorado.gov. Dates and duties below are read from the act itself.
Colorado’s chatbot law. It adds section 6-1-1708 to the Colorado Consumer Protection Act’s part 17: on and after 1 January 2027, an operator of a publicly accessible conversational AI service must clearly and conspicuously disclose that the service is artificial intelligence, protect known minors, run crisis protocols on suicidal-ideation and self-harm signals, and never claim its outputs come from a licensed professional. Annual reporting to the attorney general starts 1 July 2027.
Status
- 28 May 2026Final Act; signed by the Governor 29 May 2026 (bill record, leg.colorado.gov).
- 12 Aug 2026The act takes effect under its petition clause: 12:01 a.m. on the day following the expiration of the ninety-day period after final adjournment.
- 1 Jan 2027Operator duties attach: consumer disclosures, minors protections, false-representation ban.
- 1 Jul 2027Annual reporting to the attorney general’s office begins; the office posts report data on its public website.
Who it applies to
- DefinitionA “conversational artificial intelligence service” is an AI system accessible to the general public that primarily simulates human conversation and interaction through adaptive textual, visual or aural communications (new C.R.S. 6-1-1701(3.5)).
- Carve-outsNarrow-topic assistants, business-internal tools, commercial productivity systems, device voice assistants and constrained video-game dialogue are excluded, in each case only where they cannot generate sexually explicit content or maintain or encourage dialogue on suicidal ideation or self-harm.
What it requires
- DiscloseOn and after 1 January 2027, clearly and conspicuously disclose to every user that the service is artificial intelligence.
- MinorsWhere the operator knows a user is a minor (knowledge of the platform’s own age-range data counts), the operator owes disclosures to the minor and duties around privacy and account settings, and must not use engagement-reward mechanics on minors.
- CrisisProtocols for crisis indicators, including crisis service provider referral notifications and escalation procedures for repeated or severe indicators.
- No fake prosNo term, letter or phrase in advertising, interface or outputs stating that output data comes from a licensed professional.
- ReportFrom 1 July 2027, annual reports to the attorney general: the number of crisis referral notifications issued in the preceding year and the protocols in use, with no user personal information included.
What comes next
HB 26-1263 is inside the live Colorado rulemaking. On 11 August 2026 the Colorado Attorney General filed a Notice of Rulemaking Hearing with draft ADMT and Chatbot Safety Rules covering SB 26-189 and HB 26-1263 together; the comment window runs to 26 October 2026. The duties above are the statute’s own; the rules will add detail.
What the signed record shows
The annual report to the attorney general is a count of events. Counts come from records.
How many crisis referral notifications fired last year is answerable only from a record of each one, made at the time, that nobody could quietly edit afterwards. The same record proves the AI disclosure was shown and the minor protections were on. A signed, tamper-evident event record is the native format for every duty in 6-1-1708.
Sources
Related
- The law library · AI rules by country
- Colorado SB 26-189, the other half of the AG’s joint rulemaking
- China CAC Order No. 21 · Connecticut PA 26-15, the parallel companion-AI regimes
Checked against the source 13 August 2026: the Final Act text and the bill record on leg.colorado.gov. Information, not legal advice.
Information, not legal advice. Every entry is verified against the issuing body’s own document; where a source is reporting rather than the document, we say so.
