Colorado ADMT law
Colorado SB26-189 repeals and reenacts the state's requirements for developers and deployers of high-risk automated decision-making technology. The replacement requirements take effect January 1, 2027.
The regulatory environment around AI is now concrete: named laws, effective dates, and enforcement calendars. Companies without a defensible governance layer are taking on real exposure.
Last reviewed August 8, 2026.
Colorado SB26-189 repeals and reenacts the state's requirements for developers and deployers of high-risk automated decision-making technology. The replacement requirements take effect January 1, 2027.
The EU AI Act uses a staged application schedule. Most provisions apply from August 2, 2026, while some obligations began earlier and others apply later.
The NIST AI Risk Management Framework provides a voluntary structure for managing AI risk. ISO/IEC 42001 defines requirements for an artificial intelligence management system.
These sources help teams frame governance work, but applicability and conformity decisions remain matters for qualified legal, compliance, and certification professionals.
Ovatio Comply provides enforceable controls at the point where AI meets your systems:
No software makes an organization compliant on its own, and Ovatio Comply is not a certification. What it provides is enforceable policy and tamper-evident evidence: the raw material of a defensible compliance posture. Your counsel and compliance team own the determination.