Colorado is running a single rulemaking to implement two artificial intelligence statutes that both take effect on 1 January 2027. One of them instructs the Attorney General to write rules. The other says nothing of the kind. The Attorney General's office is writing rules for both, and it has said so in plain language on its own rulemaking page.

That asymmetry is not a procedural footnote. It determines where the operational compliance burden actually sits, how much of it will be visible before the statutes bite, and — if anyone eventually sues — which part of the framework presents the widest target.

Two statutes, and one of them is a rewrite

The first is the Automated Decision-Making Technology Act. Its lineage is worth getting right, because it is routinely described as new and it is not. Colorado passed Senate Bill 24-205 in 2024, creating protections against algorithmic discrimination in consequential decisions made by high-risk AI systems. Senate Bill 26-189, signed in May 2026, repeals and reenacts those provisions with new requirements. So the ADMT Act that takes effect on 1 January 2027 is a second-generation instrument replacing a first-generation one, not a first attempt.

It defines automated decision-making technology and imposes obligations on two distinct parties: developers of ADMT used to materially influence a consequential decision, and deployers who put it to use. It also gives consumers a right to request and correct inaccurate personal data used by such systems.

The second is House Bill 26-1263, the Chatbot Safety Act, passed in May 2026 and signed on 1 July 2026. It applies to operators of conversational AI services available to the general public. Its obligations include estimating the age of users, disclosing that a user is interacting with AI rather than a human, safeguarding teen users against sexually explicit content and against simulated emotional dependence, providing privacy and account-management tools for minor users, maintaining suicide and self-harm response protocols, and submitting an annual report to the Attorney General's office. It also prohibits presenting chatbot outputs as equivalent to licensed professional services.

Both take effect on the same day. Only one of them asked for rules.

Required rules and volunteered rules

The ADMT Act requires the Colorado Attorney General's Office to adopt rules to clarify and implement specific provisions of the law before January 1, 2027. While the Chatbot Safety Act does not require rulemaking, the Attorney General believes rulemaking would help ensure compliance obligations, including the content of the annual report, are clear. — Colorado Attorney General's Office, ADMT and Chatbot Safety Rulemaking page

Read that twice, because the two halves rest on different footings. For the ADMT Act, Attorney General Phil Weiser's office is discharging a statutory duty with a deadline attached. For the Chatbot Safety Act, it is exercising general authority because it has formed a view that compliance would otherwise be unclear.

An agency acting under an express legislative instruction operates from the strongest position available to it: the legislature said do this, by this date, for these provisions. An agency acting without one is on defensible but narrower ground. Its rules must stay tethered to what the statute actually says, because there is no delegation to point at when someone argues it has added an obligation the legislature did not enact.

Why the volunteered half was not really optional

Here is where the framing of discretionary rulemaking as a free choice breaks down, and the annual report is the cleanest illustration.

The Chatbot Safety Act requires operators to file an annual report with the Attorney General that includes, in the statute's words, 'any additional metrics necessary to determine the efficacy and reliability of implemented safeguards or detection, removal, and response protocols, as determined by the attorney general.' The Attorney General's own summary then observes that the Act 'does not provide further explanation or details on the content of these reports.'

So the legislature created a binding annual obligation and then conditioned its content on a determination by the Attorney General — without requiring the Attorney General to make one. A chatbot operator reading only the statute on 1 January 2027 would face a filing requirement whose contents are legally defined as whatever the AG decides, with nothing yet decided.

That is not an agency reaching for authority it was not given. It is an agency filling a hole the drafting left, in a provision that explicitly points at it. The distinction matters to the preemption argument below, and it is the opposite of the reading in which discretionary rulemaking is regulatory overreach.

The compliance work lives in the rules, not the statute

This is the general case, and age assurance is the sharpest example of it. A statute can say an operator must estimate the age of its users in a single clause. Everything that determines what building that costs is downstream: what evidence counts as an estimate, what confidence level is adequate, whether it must be re-run and on what cadence, what is retained afterwards and for how long, what happens when the estimate is wrong in each direction, and what documentation an enforcement officer can ask to see in two years.

None of that is in the statutory text, and all of it is the actual engineering and retention work. A product team that reads both Colorado statutes and budgets against them has scoped the smaller half of the problem.

The calendar, and why 23 September is the date to watch

The sequence is public and specific. The Department of Law ran a pre-rulemaking phase with a considerations paper and informal comments through 13 July 2026. On 11 August 2026 it filed the proposed Automated Decision-Making Technology and Conversational Artificial Intelligence Service rules with the Secretary of State, together with a notice of rulemaking and a statement of basis, authority and purpose.

Formal written comments are open from 11 August to 26 October 2026. A public hearing is set for 26 October 2026 in Denver and by videoconference; if it continues past that date, the comment period continues with it. And the interim milestone that most coverage has not flagged: comments submitted by 4 September 2026 were to be considered in a revised proposed rulemaking draft that the office has committed to circulate no later than 23 September 2026.

There is also a procedural lever that goes almost entirely unused. Under section 24-4-103(2.5), C.R.S., anyone may request a cost-benefit analysis of proposed rules within five days of their publication in the Colorado Register. That is a short window and a low bar, and it is one of the few mechanisms through which a small operator can force an accounting of what a rule costs.

The challenge nobody has filed

The strongest argument against Colorado's framework is federal preemption, and it deserves to be stated properly rather than dismissed.

It runs roughly as follows. A conversational AI service is inherently interstate; a Colorado user and a California server are one transaction. Requiring age assurance, disclosure formats, response protocols and annual reporting on a state-by-state basis produces a compliance patchwork that no national service can satisfy without effectively adopting the strictest state's rules everywhere — which makes one state's legislature the de facto national regulator. On this view, the volunteered chatbot rules are the most exposed part of the structure, because a rule the legislature never asked for is easier to characterise as the agency's policy preference rather than the state's enacted law.

Two honest qualifications. First, as argued above, the annual-report provision undercuts the cleanest version of this: the statute delegates its content to the Attorney General by its own terms, so rules on that point are implementing enacted text rather than supplementing it. Second, and more simply — nothing has been filed. There is no complaint against Colorado's framework. Reporting has described a federal interest in challenging state AI regimes, and that interest is real, but an interest is not a case. Any resolution through the courts would be a 2027 or 2028 matter, long after operators have had to decide what to build.

What this does not establish

The rules described here are proposed. None of them is law. Every obligation discussed as a rule rather than a statute is a draft that the 23 September revision, the 26 October hearing, or the final adoption can change or delete entirely. Nothing in this piece should be read as a description of a requirement currently in force.

The statutory obligations themselves — the ADMT Act's developer and deployer duties, the Chatbot Safety Act's disclosure, age-estimation, minor-protection, protocol and reporting requirements — are enacted and do take effect on 1 January 2027 whatever happens to the rules. The characterisation of each statute's obligations above follows the Attorney General's office's own published summary of them; anyone making build decisions should work from the enrolled bill text rather than any summary, including this one.

The argument that discretionary rulemaking is the most exposed surface for a preemption challenge is an inference about litigation strategy, not a prediction and not legal advice. No such challenge exists.