Colorado and Connecticut reshape state AI rules
Colorado and Connecticut have enacted major AI laws that show how state regulation is becoming more varied and complex. Colorado replaced its earlier broad duty-of-care model with a narrower framework centered on automated decision-making technology used in consequential decisions, including employment, housing, financial services, insurance, healthcare, education, and public benefits.
Colorado’s revised law focuses on documentation from developers and notice obligations from deployers when automated tools materially influence decisions affecting consumers. Deployers must also explain adverse outcomes and provide information about rights related to personal data, human review, and reconsideration where commercially reasonable. Enforcement sits with the Colorado Attorney General, and violations are treated as deceptive trade practices.
Connecticut took a wider approach. Its new law adds notice rules for automated employment-related decisions while also covering AI companions, subscription-based AI tools, generative AI provenance, algorithmic content for minors, frontier AI whistleblower protections, AI-related layoff disclosures, and state AI governance initiatives.
Other states are pursuing their own models, with California and Illinois focusing heavily on automated decision systems, employment, privacy, and discrimination risks. The expanding state patchwork leaves AI developers and deployers facing inconsistent requirements while federal proposals could still reshape the balance between state and national oversight.