AI Regulation Tracker · Compare · EU AI Act vs Colorado AI Act

EU AI Act vs Colorado AI Act: AI in Credit Decisions

Published Sep 24, 2026 · Last reviewed Sep 24, 2026 · 6 sources

What is the difference between EU AI Act and Colorado AI Act?

The EU AI Act regulates the AI system: credit scoring of natural persons is "high-risk", so providers carry a full compliance regime and bank deployers must run human oversight, keep logs and complete a fundamental rights impact assessment, from December 2, 2027. Colorado's SB 26-189, effective January 1, 2027, regulates the decision instead: no impact assessment, but notice before use, a plain-language explanation within 30 days of an adverse outcome, data correction and human review; a lender's ECOA notice can satisfy the notice duties.[1][2][3]

EU AI ActColorado
InstrumentRegulation (EU) 2024/1689 (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)Colorado SB 24-205 (Colorado AI Act, 2024), repealed and reenacted by SB 26-189 (Automated Decision-Making Technology in Consequential Decisions, 2026)
StatusIn force; Annex III high-risk duties apply from Dec 2, 2027SB 26-189 takes effect Jan 1, 2027; AG rules pending
In the trackerRegulation (EU) 2024/1689 · Regulation (EU) 2026/1744 (Digital Omnibus on AI)
Authority: EU AI Act
SB 24-205 · SB 25B-004 · SB 26-189 · Colorado AG proposed ADMT rules
Authority: Colorado AI Act

How do the EU AI Act and Colorado's law treat AI in credit decisions?

DimensionEU AI ActColorado
What triggers itAnnex III point 5(b): "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score" are high-risk.[1]Covered ADMT: technology used to "materially influence" a consequential decision; consequential decisions include access to "a financial or lending service".[3]
What is excludedPoint 5(b) excepts "AI systems used for the purpose of detecting financial fraud".[1]"Consequential decision" does not include activities relating to technologies for anti-money-laundering and counter-terrorist-financing controls, sanctions compliance, or "fraud prevention", nor advertising and marketing.[3]
Who is regulatedProviders (who develop a system and place it on the market "under its own name or trademark") and deployers (who use a system "under its authority"), including those outside the EU where "the output produced by the AI system is used in the Union".[1]Developers and deployers "doing business in Colorado"; a deployer is a person doing business in Colorado "that deploys a covered ADMT".[3]
Duties on the builderProvider obligations (Article 16) include meeting the high-risk requirements, a quality management system, documentation, logs and a conformity assessment; for Annex III points 2 to 8 that assessment is "based on internal control" without a notified body.[1]From January 1, 2027 developers give deployers documentation of intended and "known harmful or inappropriate uses", categories of training data, limitations and instructions, and notice of material updates.[3]
Duties on the bank using itDeployers use systems per the instructions, assign human oversight to people with "the necessary competence, training and authority", monitor operation and keep logs "of at least six months" (Article 26).[1]Deployers give notice, provide post-adverse-outcome disclosures, honour correction and human-review requests, and retain compliance records "for not less than three years".[3]
Impact assessmentDeployers of Annex III point 5(b) and (c) systems "shall perform an assessment of the impact on fundamental rights" before deployment (Article 27).[1]SB 26-189 contains no impact-assessment requirement. SB 24-205, which it replaced, required deployers to implement a risk management policy and program and to complete impact assessments.[3][4]
Notice to the applicantDeployers of Annex III systems that make or assist decisions about natural persons "shall inform the natural persons that they are subject to the use of the high-risk AI system" (Article 26(11)).[1]"Prior to" using covered ADMT, "a clear and conspicuous notice" that the deployer used or will use it, which a prominent public notice at points of consumer interaction can satisfy.[3]
Explaining a denialArticle 86: an affected person has the right to "clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken".[1]Within thirty days after an adverse outcome, "a plain language description of the consequential decision and the role the covered ADMT played", and a process to request more information. A creditor's ECOA/Regulation B notice complies if it also satisfies these requirements.[3]
Human reviewHuman oversight is a design requirement (systems must be built so they "can be effectively overseen by natural persons", Article 14) and a deployer staffing duty (Article 26(2)); the applicant's individual right in Article 86 is to an explanation.[1]The consumer may request "an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable".[3]
Banks' existing rulesFor financial institutions, the deployer monitoring duty is "deemed to be fulfilled" by complying with EU financial-services governance rules, and the financial supervisor is the market surveillance authority (Article 74(6)).[1]SB 24-205 deemed a bank or credit union "in full compliance" when examined by a prudential regulator under equivalent guidance; SB 26-189 contains no such provision.[4][3]
Enforcement and penaltiesBreaching deployer obligations under Article 26 is subject to fines of up to EUR 15 000 000 or 3% of worldwide annual turnover, whichever is higher.[1]The Attorney General enforces through the Colorado Consumer Protection Act; before January 1, 2030 a 60-day notice and cure applies where a cure is possible; no new private right of action.[3]
When it appliesEntered into force on the twentieth day after its July 12, 2024 publication; after the Digital Omnibus, high-risk rules apply from "2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III" (originally August 2, 2026).[1][2]SB 26-189 "takes effect January 1, 2027". SB 24-205 was to apply from February 1, 2026, was delayed to June 30, 2026 by SB 25B-004, and was repealed and reenacted before taking effect.[3][4][5]

What does a lender operating in both places need to do?

  • Map roles per system: under the EU AI Act a bank using a vendor's credit-scoring model is a deployer; in Colorado the same bank is a deployer and the vendor a developer, with documentation owed to the bank from January 1, 2027.[1][3]
  • Plan two explanation tracks: the EU Article 86 explanation of the AI system's role, and Colorado's 30-day plain-language disclosure, which an ECOA/Regulation B adverse-action notice satisfies only if it also meets Colorado's content requirements.[1][3]
  • Budget a fundamental rights impact assessment for EU credit-scoring deployments before December 2, 2027; Colorado no longer requires an impact assessment.[1][2][3]
  • Design human review twice: EU human oversight by competent, trained staff with authority, and a Colorado consumer-requested review by someone who "does not default to the system output".[1][3]
  • Do not assume a bank exemption in Colorado: the prudential-supervision safe harbor in SB 24-205 did not carry into SB 26-189.[4][3]
  • Watch the Colorado Attorney General's rules, which the statute requires by January 1, 2027; written comments on the proposed rules are open until October 26, 2026.[3][6]

When did each happen?

DateInstrumentEvent
May 17, 2024ColoradoColorado SB 24-205 (the Colorado AI Act) signed; requirements to start February 1, 2026.[4]
Jul 12, 2024EU AI ActEU AI Act published in the Official Journal (Regulation (EU) 2024/1689); in force on the twentieth day after publication.[1]
Aug 28, 2025ColoradoSB 25B-004 approved: Colorado AI Act requirements moved to June 30, 2026.[5]
May 14, 2026ColoradoSB 26-189 signed: repeals and reenacts the Colorado AI Act as an automated decision-making technology law.[3]
Jul 24, 2026EU AI ActDigital Omnibus on AI, Regulation (EU) 2026/1744, published; in force on the third day after publication.[2]
Aug 11, 2026ColoradoColorado Department of Law files proposed ADMT and Chatbot Safety rules.[6]
Oct 26, 2026ColoradoDeadline for written comments on the proposed Colorado rules (extended if the hearing continues).pending[6]
Jan 1, 2027ColoradoSB 26-189 takes effect; Attorney General rules due by this date.pending[3]
Dec 2, 2027EU AI ActHigh-risk obligations apply to Annex III systems, including credit scoring.pending[2]

What is still open?

  • Colorado's implementing rules are still in rulemaking; the final text, due by January 1, 2027, will define the post-adverse-outcome disclosures.[3][6]
  • The EU dates have already moved once: the Digital Omnibus replaced August 2, 2026 with December 2, 2027 for Annex III systems.[2]

Is credit scoring high-risk under the EU AI Act?

Yes. Annex III point 5(b) lists AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, except systems used to detect financial fraud.[1]

When do the EU AI Act high-risk rules apply to credit scoring?

From December 2, 2027. Regulation (EU) 2026/1744 set that date for Annex III systems; the original date was August 2, 2026.[2]

When does the Colorado AI Act take effect?

The original Colorado AI Act (SB 24-205) never took effect: it was delayed to June 30, 2026 and then repealed and reenacted by SB 26-189, which takes effect January 1, 2027.[4][5][3]

Does Colorado's law apply to banks?

Yes. SB 26-189 covers consequential decisions about financial or lending services and has no counterpart to SB 24-205's full-compliance provision for banks and credit unions examined by a prudential regulator. A creditor's ECOA/Regulation B notice can satisfy the Colorado notice duties if it also meets them.[3][4]

Does Colorado require an AI impact assessment for lending?

Not any more. SB 24-205 required impact assessments; SB 26-189 replaced them with notice, disclosure, correction, human review and record-keeping duties.[4][3]

Does the EU AI Act give loan applicants a right to an explanation?

Yes. Article 86 gives a person affected by a decision based on an Annex III high-risk system the right to clear and meaningful explanations of the AI system's role and the main elements of the decision.[1]

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — Official Journal of the European Union (EUR-Lex), Jul 12, 2024 · tracker page
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689 — Official Journal of the European Union (EUR-Lex), Jul 24, 2026 · tracker page
  3. Colorado SB 26-189, Concerning the Use of Automated Decision-Making Technology in Consequential Decisions (signed act) — Colorado General Assembly, May 14, 2026 · tracker page
  4. Colorado SB 24-205, Consumer Protections for Artificial Intelligence (signed act) — Colorado General Assembly, May 17, 2024 · tracker page
  5. Colorado SB 25B-004, bill page — Colorado General Assembly, Aug 28, 2025 · tracker page
  6. Artificial Intelligence: ADMT Act and Chatbot Safety Act rulemaking — Colorado Attorney General, Aug 11, 2026 · tracker page

Every cell and answer on this page cites the official text it comes from; quotations are verbatim. Last reviewed Sep 24, 2026.

When either side of this comparison moves, the next morning's brief says so.

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning