A SaaS company whose software ranks job applicants or scores individual borrowers for customers in Colorado and the EU should write one document for those customers, to both laws' lists, before January 1, 2027, and a separate file for EU authorities before 2 December 2027.
Colorado's Attorney General says Senate Bill 26-189 was signed into law May 2026 and repeals and reenacts those provisions of the state's 2024 law, and that this new law and its provisions go into effect January 1, 2027. From that date the enacted act requires a developer whose technology is sold or licensed to materially influence a consequential decision to give each deployer, the business using it, intended uses and known harmful or inappropriate uses, categories of training data, known limitations, instructions for appropriate use, monitoring and human review, and what the deployer needs for its consumer notices. A consequential decision relates to an individual's access to, eligibility for or compensation in areas including employment and financial or lending services. The Attorney General enforces the act and, before January 1, 2030, must give 60 days to cure where a cure is deemed possible, unless the violation was knowing or repeated. No lender is exempt: a creditor's federal adverse action notice can cover only its own consumer notices.
The European Commission's notice on the Digital Omnibus on AI, in force since 27 July 2026, gives the date for high-risk AI systems in Annex III: Rules apply starting 2 December 2027. Annex III lists systems intended to be used for the recruitment or selection of natural persons, systems for decisions on promotion or termination, and systems that evaluate the creditworthiness of natural persons, with the exception of AI systems used for the purpose of detecting financial fraud.
The two laws ask for different documents. For high-risk systems put on the market from that date, the Commission lists detailed documentation providing all information necessary on the system and its purpose for authorities to assess its compliance and, as a separate item, clear and adequate information to the deployer. In the Colorado act, documentation goes to the deployer alone. Under Article 13, whose Service Desk page carries no amendment notice, the instructions for use given to deployers include intended purpose, limitations of performance, the human oversight measures referred to in Article 14 and, when appropriate, information on training, validation and testing data. The customer document should be written once, to both lists.
One entry for a candidate ranking might read: intended use, ordering applicants for a recruiter; training data, past applications and hiring outcomes; known limitation, weaker ordering for roles with few past hires; inappropriate use, roles it was not trained on; human review, a recruiter confirms each rejection before it is sent.
In the first month the chief product officer lists every feature that ranks, scores or filters a person, and general counsel marks those reaching Colorado or EU customers. In the second, product and data science leads write each entry. In the third, customer success sends the document to Colorado customers and logs each version, since developers must notify deployers of material updates or modifications to the covered ADMT. The Attorney General must adopt rules before January 1, 2027, so the document is checked against them once they are adopted.
The EU authorities' file comes after January 1, 2027. The Service Desk's Article 11 page, on technical documentation, still shows the 13 June 2024 text under a notice that the provision has been amended by the Digital Omnibus on AI and that the text displayed on this page has not yet been updated to reflect those amendments.