EuroComply
Free assessment

EU AI Act · comparison

EU AI Act vs Colorado AI Act (SB 24-205): Comparison for Companies Selling in Both

Colorado’s AI Act targets algorithmic discrimination in consequential decisions; the EU AI Act regulates AI as a product across four risk tiers. Scope, duties, deadlines and how one file can serve both.

Classify my system in 3 minutes

The bottom line

If you comply with the EU AI Act for a high-risk system, you have most of what Colorado requires (risk management, impact assessment, documentation to deployers, notices to consumers, adverse-decision explanations). The reverse is not true: Colorado compliance covers none of the EU product-safety steps and nothing outside consequential decisions. Build the EU file first and derive the Colorado deliverables from it.

Colorado’s Artificial Intelligence Act (SB 24-205) is the first comprehensive US state AI law. After a legislative delay, it applies from 30 June 2026. It targets one thing: algorithmic discrimination by “high-risk AI systems” that make or substantially influence consequential decisions about education, employment, financial services, essential government services, healthcare, housing, insurance or legal services.

That list will look familiar to anyone who has read Annex III of the EU AI Act, and the overlap is intentional. The difference is breadth: Colorado stops at discrimination and disclosure duties for developers and deployers, while the EU law adds prohibited practices, transparency for chatbots and synthetic content, general-purpose model rules and a full product-safety regime with conformity assessment and CE marking.

Side by side

EU AI Act vs Colorado AI Act

DimensionEU AI ActColorado AI Act
Legal basisRegulation (EU) 2024/1689Colorado SB 24-205, C.R.S. 6-1-1701 et seq.
Application datePhased: Feb 2025 bans, Aug 2026 Art. 50, Dec 2027 Annex III, Aug 2028 Annex I30 June 2026 (delayed from 1 February 2026)
ScopeAll AI systems by risk tier, plus GPAI modelsHigh-risk AI systems making or substantially influencing consequential decisions
Harm addressedHealth, safety and fundamental rights broadly; specific prohibitionsAlgorithmic discrimination against protected classes
Developer dutiesFull provider regime: risk management, data governance, technical file, oversight design, conformity assessment, registrationReasonable care, documentation and disclosures to deployers, public statement of systems and risk management, notice of discovered discrimination to the Attorney General within 90 days
Deployer dutiesUse per instructions, human oversight, logs, worker information, fundamental rights impact assessment (some deployers)Risk management programme, annual impact assessment, consumer notices, adverse-decision explanation and appeal, public statement
Consumer transparencyDisclosure when interacting with AI; labels on synthetic content; explanation of high-risk decisionsNotice before a consequential decision; disclosure that a consumer is interacting with AI; explanation and correction/appeal rights on adverse decisions
Safe harbourPresumption of conformity via harmonised standardsRebuttable presumption of reasonable care if compliant with NIST AI RMF, ISO/IEC 42001 or an equivalent framework
EnforcementMarket surveillance authorities; fines up to €35M / 7%Colorado Attorney General only; no private right of action; civil penalties under the Colorado Consumer Protection Act
Small-business reliefProportionate fines and simplified documentation for SMEsDeployers with fewer than 50 employees exempt from some duties if they rely on the developer’s impact assessment
Prohibited practicesYes, Art. 5 listNone
Generative AI / chatbotsArt. 50 transparency, GPAI model dutiesOnly the “interacting with AI” disclosure

Reuse this

Where Colorado AI Act work counts toward the AI Act

  • The Art. 9 risk management file and the Art. 27 fundamental rights impact assessment map directly onto Colorado’s risk management programme and impact assessment.
  • Art. 13 instructions for use give deployers the information Colorado requires developers to provide (purpose, data summary, limitations, evaluation results).
  • Art. 86 right to explanation and the human oversight override satisfy Colorado’s adverse-decision explanation and appeal duties.
  • The Art. 50 “you are interacting with AI” notice is the same disclosure Colorado requires.
  • Because ISO/IEC 42001 and NIST AI RMF give a Colorado presumption of reasonable care, an AI Act quality management system built on either does double duty.

Still needed

What Colorado AI Act does not cover

  • Colorado has no conformity assessment, CE marking or registration; the EU steps must be done in addition.
  • Colorado does not regulate chatbots, recommenders or content generation beyond the interaction disclosure.
  • Colorado has no prohibited-practice list; the EU Art. 5 review is still required.
  • Colorado’s 90-day discrimination notice to the Attorney General has no EU equivalent, while the EU serious-incident reporting (Art. 73) has no Colorado equivalent.

Know exactly where you stand under the AI Act

Free 7-question assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.

Start free assessment

FAQ

Frequently asked questions

We only sell in the US. Does the EU AI Act still matter?

Only if your system is placed on the EU market or its output is used in the EU. If you have no EU users or customers, the EU law does not apply, but Colorado, plus similar bills in other states, does.

Does the Colorado safe harbour mean ISO 42001 is enough there?

It creates a rebuttable presumption that you used reasonable care, which is one element of the developer and deployer duties. The disclosure, notice and impact-assessment duties still have to be performed.

Is a hiring tool high-risk under both laws?

Yes. Employment is a consequential-decision area in Colorado and Annex III(4) in the EU. In the EU it carries the full provider regime; in Colorado it carries the discrimination-focused duties.

This page is general information, updated 2026-09-19. It is not legal advice; always check current guidance for both frameworks against your specific system.

Related use cases

High-risk

Recruitment & CV screening

Read →

High-risk

Credit scoring & lending

Read →

Depends on use

Insurance risk assessment & pricing

Read →