Table of Content
Subscribe to our Newsletter
Get the latest from our team delivered to your inbox
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Ready to get started?
Try It Free
Colorado's AI insurance law just got a lot lighter. SB 26-189, effective January 1, 2027, repeals and reenacts the state's landmark AI Act (SB 24-205) and strips out its two heaviest requirements: the mandatory risk management program and the annual algorithmic discrimination impact assessment. For insurers and health plans that spent 2025 and 2026 building compliance infrastructure around those requirements, the instinct might be to stand down.
That instinct is wrong. The paperwork got lighter. The underlying expectation that a company can produce evidence of how an automated decision was made did not disappear. Insurers and health plans still owe general use notices and specific disclosures whenever AI decides coverage, underwriting, claims, or financial assistance eligibility, and now face a 30 day disclosure window after an adverse outcome. What changed is the format regulators want that evidence in, not whether they want it at all.
This post covers what SB 26-189 actually changes, who still has obligations under it, and what it takes to produce evidence of an automated decision on demand, regardless of which disclosure regime is in force this year or the next.
SB 26-189 replaces SB 24-205's prescriptive compliance structure with a lighter, disclosure first model. The core shift is away from ongoing, mandatory internal programs and toward point in time documentation and disclosure.
RequirementUnder SB 24-205Under SB 26-189Risk management programMandatory, ongoingRemovedAlgorithmic discrimination impact assessmentMandatory, annualRemovedDocumentation of automated decisionsDetailed impact assessmentBasic documentationAdverse outcome disclosureNot specifically timedRequired within 30 daysGeneral use noticeRequiredRequired
Insurers and health plans must still give general use notices and specific disclosures whenever AI decides coverage, underwriting, claims, or financial assistance eligibility. HIPAA covered entities and their business associates are now exempted from most developer and deployer obligations under SB 26-189, but that exemption does not extend to employment decisions, which stay fully in scope.
Colorado is not acting alone here. As Foundational covered when the EU AI Act's high-risk deadline moved, insurance underwriting is treated as a high-risk AI use case in multiple jurisdictions, and the NAIC Model Bulletin has already pushed similar general use and adverse decision disclosure expectations into most other states. A Colorado specific compliance program that does not generalize is a program insurers will be rebuilding again soon.
An algorithmic discrimination impact assessment is a formal, periodic analysis of whether an AI system produces unlawful differential treatment across protected classes. Under SB 24-205, Colorado insurers had to complete one annually for any AI system used in a consequential decision. SB 26-189 removes the mandatory version of this assessment, but insurers who already run one internally as part of model governance still produce a defensible answer to regulators and claimants who ask how a decision was made.
Foundational is the only data and AI governance platform that analyzes source code directly, producing deterministic lineage back to the exact model inputs, pipeline transformations, and data sources behind an automated insurance decision. That evidence trail does not depend on which state's disclosure format is current. It exists as a byproduct of how the AI system was built, not as a compliance artifact assembled after the fact.
Lemonade used this approach to significantly accelerate regulatory approval for AI-driven underwriting, because the lineage behind each decision was already documented rather than reconstructed under deadline. That is the difference between reacting to a new disclosure law and already having the answer on file.
Foundational's approach to what regulators actually require from data lineage applies directly here: regulators do not need a specific document format, they need proof of what happened and why, produced from the source, not reconstructed from memory.
No, not as a standalone mandatory filing. SB 26-189 removes the annual algorithmic discrimination impact assessment that SB 24-205 required. Insurers now owe basic documentation and a 30 day disclosure after an adverse outcome instead. Many insurers keep running an internal version of the assessment anyway, since it produces the evidence needed to answer disclosure requests under the new, lighter law.
SB 24-205 required a mandatory, ongoing risk management program and an annual algorithmic discrimination impact assessment for consequential AI decisions. SB 26-189 repeals and reenacts that law, dropping both requirements in favor of basic documentation and a 30 day disclosure window after an adverse outcome. General use notices and specific disclosures for coverage, underwriting, claims, and financial assistance decisions remain required under both versions.
Partially. HIPAA covered entities and their business associates are exempt from most developer and deployer obligations under SB 26-189. That exemption does not cover employment decisions, which stay fully in scope regardless of HIPAA status. Health plans making coverage, claims, or financial assistance decisions with AI should assume general use and adverse outcome disclosure obligations still apply.
Insurers need a decision trail that traces back to the exact source code, model inputs, and data transformations behind an AI decision, not just a policy document describing the process. Foundational's source code analysis produces this deterministic lineage automatically, so the evidence exists before a regulator or claimant asks for it, regardless of which state's disclosure format applies that year.
Colorado's SB 26-189 lightens the paperwork, not the underlying expectation. Insurers and health plans that can already produce deterministic lineage for their AI underwriting and claims decisions will not need to rebuild anything the next time a state revises its disclosure rules. See how Foundational's source code analysis gives insurers that evidence trail on a demo call.
See how Foundational's source code analysis gives insurers a ready evidence trail.
See how Foundational's source code analysis gives insurers a ready evidence trail.
See how Foundational's source code analysis gives insurers a ready evidence trail.