C.R.S. § 6-1-1702: Developer responsibilities - documentation. [Editor's note: This version of this section is effective January 1, 2027.]
Where this section sits in the code
- Title 6 - CONSUMER AND COMMERCIAL AFFAIRS
- Article 1 - Colorado Consumer Protection Act
- Part 17 - AUTOMATED DECISION-MAKING TECHNOLOGY IN CONSEQUENTIAL DECISIONS
(1) On and after January 1, 2027, a developer shall make available to each deployer of a covered ADMT developed by the developer, in a form and manner that is reasonably understandable to a deployer and that protects trade secrets or information protected from disclosure by state or federal law:
(a) A general statement describing the intended uses and known harmful or inappropriate uses of the covered ADMT;
(b) A description of the categories of data, including personal data, used to train the covered ADMT, to the extent known;
(c) Known limitations of the covered ADMT, including known risks and circumstances in which the covered ADMT should not be used;
(d) Instructions for the deployer's appropriate use, monitoring, and meaningful human review, where applicable;
(e) Information reasonably necessary for the deployer to comply with section 6-1-1704. If information is withheld, the developer shall notify the deployer.
(2) (a) A developer shall provide to each deployer of a covered ADMT developed by the developer a notice of material updates, intentional and substantial modifications, and changes to the intended use of, limitations for, or risk mitigation for the covered ADMT within a reasonable time.
(b) A developer may use public release notes containing the information required by subsection (2)(a) of this section to comply with this subsection (2) if the developer provides direct notice of the public release to each deployer of the covered ADMT.
(3) A developer is subject to the disclosure requirements described in subsections (1) and (2) of this section only for a deployer's use of a covered ADMT where the ADMT was marketed, advertised, configured, contracted, sold, or licensed to be used to materially influence a consequential decision.
(4) A developer shall retain, for not less than three years after the creation of a record required or created under this section or for a longer period if required by applicable state or federal law, records reasonably necessary to demonstrate compliance with this section. Records include system version identifiers, changelogs, and documentation and notices of material updates provided to deployers pursuant to subsection (2) of this section.
(5) This section applies when a developer creates a covered ADMT that is intended, documented, marketed, advertised, configured, or contracted to be used to make consequential decisions or when the developer becomes aware that the covered ADMT is being used to make consequential decisions in a manner consistent with the intended and contracted uses.
Collected 2026-09-14T18:37:45Z. Source file · JSON