What is the difference between EU AI Act and Colorado AI Act?
The EU AI Act regulates the AI system: credit scoring of natural persons is "high-risk", so providers carry a full compliance regime and bank deployers must run human oversight, keep logs and complete a fundamental rights impact assessment, from December 2, 2027. Colorado's SB 26-189, effective January 1, 2027, regulates the decision instead: no impact assessment, but notice before use, a plain-language explanation within 30 days of an adverse outcome, data correction and human review; a lender's ECOA notice can satisfy the notice duties.[1][2][3]
| EU AI Act | Colorado | |
|---|---|---|
| Instrument | Regulation (EU) 2024/1689 (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI) | Colorado SB 24-205 (Colorado AI Act, 2024), repealed and reenacted by SB 26-189 (Automated Decision-Making Technology in Consequential Decisions, 2026) |
| Status | In force; Annex III high-risk duties apply from Dec 2, 2027 | SB 26-189 takes effect Jan 1, 2027; AG rules pending |
| In the tracker | Regulation (EU) 2024/1689 · Regulation (EU) 2026/1744 (Digital Omnibus on AI) Authority: EU AI Act | SB 24-205 · SB 25B-004 · SB 26-189 · Colorado AG proposed ADMT rules Authority: Colorado AI Act |
How do the EU AI Act and Colorado's law treat AI in credit decisions?
| Dimension | EU AI Act | Colorado |
|---|---|---|
| What triggers it | Annex III point 5(b): "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score" are high-risk.[1] | Covered ADMT: technology used to "materially influence" a consequential decision; consequential decisions include access to "a financial or lending service".[3] |
| What is excluded | Point 5(b) excepts "AI systems used for the purpose of detecting financial fraud".[1] | "Consequential decision" does not include activities relating to technologies for anti-money-laundering and counter-terrorist-financing controls, sanctions compliance, or "fraud prevention", nor advertising and marketing.[3] |
| Who is regulated | Providers (who develop a system and place it on the market "under its own name or trademark") and deployers (who use a system "under its authority"), including those outside the EU where "the output produced by the AI system is used in the Union".[1] | Developers and deployers "doing business in Colorado"; a deployer is a person doing business in Colorado "that deploys a covered ADMT".[3] |
| Duties on the builder | Provider obligations (Article 16) include meeting the high-risk requirements, a quality management system, documentation, logs and a conformity assessment; for Annex III points 2 to 8 that assessment is "based on internal control" without a notified body.[1] | From January 1, 2027 developers give deployers documentation of intended and "known harmful or inappropriate uses", categories of training data, limitations and instructions, and notice of material updates.[3] |
| Duties on the bank using it | Deployers use systems per the instructions, assign human oversight to people with "the necessary competence, training and authority", monitor operation and keep logs "of at least six months" (Article 26).[1] | Deployers give notice, provide post-adverse-outcome disclosures, honour correction and human-review requests, and retain compliance records "for not less than three years".[3] |
| Impact assessment | Deployers of Annex III point 5(b) and (c) systems "shall perform an assessment of the impact on fundamental rights" before deployment (Article 27).[1] | SB 26-189 contains no impact-assessment requirement. SB 24-205, which it replaced, required deployers to implement a risk management policy and program and to complete impact assessments.[3][4] |
| Notice to the applicant | Deployers of Annex III systems that make or assist decisions about natural persons "shall inform the natural persons that they are subject to the use of the high-risk AI system" (Article 26(11)).[1] | "Prior to" using covered ADMT, "a clear and conspicuous notice" that the deployer used or will use it, which a prominent public notice at points of consumer interaction can satisfy.[3] |
| Explaining a denial | Article 86: an affected person has the right to "clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken".[1] | Within thirty days after an adverse outcome, "a plain language description of the consequential decision and the role the covered ADMT played", and a process to request more information. A creditor's ECOA/Regulation B notice complies if it also satisfies these requirements.[3] |
| Human review | Human oversight is a design requirement (systems must be built so they "can be effectively overseen by natural persons", Article 14) and a deployer staffing duty (Article 26(2)); the applicant's individual right in Article 86 is to an explanation.[1] | The consumer may request "an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable".[3] |
| Banks' existing rules | For financial institutions, the deployer monitoring duty is "deemed to be fulfilled" by complying with EU financial-services governance rules, and the financial supervisor is the market surveillance authority (Article 74(6)).[1] | SB 24-205 deemed a bank or credit union "in full compliance" when examined by a prudential regulator under equivalent guidance; SB 26-189 contains no such provision.[4][3] |
| Enforcement and penalties | Breaching deployer obligations under Article 26 is subject to fines of up to EUR 15 000 000 or 3% of worldwide annual turnover, whichever is higher.[1] | The Attorney General enforces through the Colorado Consumer Protection Act; before January 1, 2030 a 60-day notice and cure applies where a cure is possible; no new private right of action.[3] |
| When it applies | Entered into force on the twentieth day after its July 12, 2024 publication; after the Digital Omnibus, high-risk rules apply from "2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III" (originally August 2, 2026).[1][2] | SB 26-189 "takes effect January 1, 2027". SB 24-205 was to apply from February 1, 2026, was delayed to June 30, 2026 by SB 25B-004, and was repealed and reenacted before taking effect.[3][4][5] |
What does a lender operating in both places need to do?
- Map roles per system: under the EU AI Act a bank using a vendor's credit-scoring model is a deployer; in Colorado the same bank is a deployer and the vendor a developer, with documentation owed to the bank from January 1, 2027.[1][3]
- Plan two explanation tracks: the EU Article 86 explanation of the AI system's role, and Colorado's 30-day plain-language disclosure, which an ECOA/Regulation B adverse-action notice satisfies only if it also meets Colorado's content requirements.[1][3]
- Budget a fundamental rights impact assessment for EU credit-scoring deployments before December 2, 2027; Colorado no longer requires an impact assessment.[1][2][3]
- Design human review twice: EU human oversight by competent, trained staff with authority, and a Colorado consumer-requested review by someone who "does not default to the system output".[1][3]
- Do not assume a bank exemption in Colorado: the prudential-supervision safe harbor in SB 24-205 did not carry into SB 26-189.[4][3]
- Watch the Colorado Attorney General's rules, which the statute requires by January 1, 2027; written comments on the proposed rules are open until October 26, 2026.[3][6]
When did each happen?
| Date | Instrument | Event |
|---|---|---|
| May 17, 2024 | Colorado | Colorado SB 24-205 (the Colorado AI Act) signed; requirements to start February 1, 2026.[4] |
| Jul 12, 2024 | EU AI Act | EU AI Act published in the Official Journal (Regulation (EU) 2024/1689); in force on the twentieth day after publication.[1] |
| Aug 28, 2025 | Colorado | SB 25B-004 approved: Colorado AI Act requirements moved to June 30, 2026.[5] |
| May 14, 2026 | Colorado | SB 26-189 signed: repeals and reenacts the Colorado AI Act as an automated decision-making technology law.[3] |
| Jul 24, 2026 | EU AI Act | Digital Omnibus on AI, Regulation (EU) 2026/1744, published; in force on the third day after publication.[2] |
| Aug 11, 2026 | Colorado | Colorado Department of Law files proposed ADMT and Chatbot Safety rules.[6] |
| Oct 26, 2026 | Colorado | Deadline for written comments on the proposed Colorado rules (extended if the hearing continues).pending[6] |
| Jan 1, 2027 | Colorado | SB 26-189 takes effect; Attorney General rules due by this date.pending[3] |
| Dec 2, 2027 | EU AI Act | High-risk obligations apply to Annex III systems, including credit scoring.pending[2] |
What is still open?
Is credit scoring high-risk under the EU AI Act?
Yes. Annex III point 5(b) lists AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, except systems used to detect financial fraud.[1]
When do the EU AI Act high-risk rules apply to credit scoring?
From December 2, 2027. Regulation (EU) 2026/1744 set that date for Annex III systems; the original date was August 2, 2026.[2]
When does the Colorado AI Act take effect?
The original Colorado AI Act (SB 24-205) never took effect: it was delayed to June 30, 2026 and then repealed and reenacted by SB 26-189, which takes effect January 1, 2027.[4][5][3]
Does Colorado's law apply to banks?
Yes. SB 26-189 covers consequential decisions about financial or lending services and has no counterpart to SB 24-205's full-compliance provision for banks and credit unions examined by a prudential regulator. A creditor's ECOA/Regulation B notice can satisfy the Colorado notice duties if it also meets them.[3][4]
Does Colorado require an AI impact assessment for lending?
Not any more. SB 24-205 required impact assessments; SB 26-189 replaced them with notice, disclosure, correction, human review and record-keeping duties.[4][3]
Does the EU AI Act give loan applicants a right to an explanation?
Yes. Article 86 gives a person affected by a decision based on an Annex III high-risk system the right to clear and meaningful explanations of the AI system's role and the main elements of the decision.[1]
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — Official Journal of the European Union (EUR-Lex), Jul 12, 2024 · tracker page
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689 — Official Journal of the European Union (EUR-Lex), Jul 24, 2026 · tracker page
- Colorado SB 26-189, Concerning the Use of Automated Decision-Making Technology in Consequential Decisions (signed act) — Colorado General Assembly, May 14, 2026 · tracker page
- Colorado SB 24-205, Consumer Protections for Artificial Intelligence (signed act) — Colorado General Assembly, May 17, 2024 · tracker page
- Colorado SB 25B-004, bill page — Colorado General Assembly, Aug 28, 2025 · tracker page
- Artificial Intelligence: ADMT Act and Chatbot Safety Act rulemaking — Colorado Attorney General, Aug 11, 2026 · tracker page
Every cell and answer on this page cites the official text it comes from; quotations are verbatim. Last reviewed Sep 24, 2026.
When either side of this comparison moves, the next morning's brief says so.
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning