On 6 October 2026 the Colorado Department of Law posted an interim draft of its ADMT and Chatbot Safety Rules (4 CCR 904-6), implementing SB 26-189 and HB 26-1263. Public comments run through 26 October 2026, or longer if the formal rulemaking hearing continues past that date, and the rules are stated to take effect 1 January 2027.
Where The Rulemaking Stands
- 11 August 2026: the Department filed the proposed rules with the Colorado Secretary of State.
- 6 October 2026: the Department released the interim draft as a redline, with a cover page of additional considerations.
- 26 October 2026: written comments close, unless the hearing continues beyond that day. The formal rulemaking hearing is set for 10:00 a.m. Mountain Time at 1300 Broadway, Room 1D, Denver, with virtual attendance by registration.
- 1 January 2027: the draft's stated effective date, the same day the ADMT Act and the Chatbot Safety Act provisions take effect.
The Department of Law rulemaking page carries the comment form, the hearing registration link, and a link to the written comments posted so far.
Who Counts As A Developer
The draft treats a company that builds an upstream Covered ADMT into its own product and supplies it to others as a Developer, which must retain the upstream Developer's documentation and pass it, with its own, to downstream Developers and Deployers. Where a third party runs Covered ADMT on a Deployer's behalf and the Deployer makes the consequential decision, the Deployer remains responsible for all Deployer obligations.
Tools used solely to summarize, organize, translate, draft, route or present information for human review are excluded from ADMT.
In the draft's adverse-outcome example, a Deployer that receives a consumer's request for more information by calling a toll-free number responds within 15 days.
Chatbot Safeguards After Launch
HB 26-1263 requires chatbot operators to file an annual report with the Attorney General, including metrics on the efficacy and reliability of their safeguards. The interim draft spells out what that report covers. An operator must describe how it evaluates whether its safety protocols continue to perform reliably over time and after material changes to the service. Where applicable, it must report metrics from structured testing, post-deployment monitoring or review, multi-turn interactions, and performance after material changes to the model, safeguards or service.
For each material metric, the operator gives the reporting period or test date, the model or service version evaluated where that matters, and whether the evaluation ran before or after deployment. The Department may ask for documentation, records or a demonstration to verify any part of the report, and the operator has 30 days to comply.
What The Draft Does Not Settle
- This is an interim draft. The adopted rules may differ after the comment period and the hearing.
- The redline marks changes against the August text. This note describes the interim draft as it now reads and does not list what was removed.
Related: The United States jurisdiction page carries the Colorado dates alongside other state AI laws, and the deployer assurance checklist carries a note on the draft's Developer and Deployer split.