Colorado Conversational AI Service Operator Requirements (HB 26-1263)

Jurisdiction:
Colorado
enacted
Effective:
Aug 12, 2026
Full enforcement:
Jul 1, 2027
Authority:
Colorado Attorney General
Official text

Obligations Covered

Risk Assessment Transparency & Disclosure Data Governance Incident Reporting

Timeline

MilestoneDateNotes
Signed by the GovernorMay 29, 2026Governor Polis; adds C.R.S. § 6-1-1708 and definitions at § 6-1-1701
Act effectiveAug 12, 2026Sec. 3 — 12:01 a.m. on the day after the ninety-day post-adjournment referendum window
Operator duties beginJan 1, 2027§ 6-1-1708(2)-(5) apply "on and after January 1, 2027"
Annual attorney general reporting beginsJul 1, 2027§ 6-1-1708(6)(a) applies "on and after July 1, 2027"

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Age Estimation and Minor Identification #

Obligation:
Risk Assessment
pending
Effective:
Jan 1, 2027
Risk tier:
limited-risk
Scope:
Operators — a person, partnership, corporation, or entity that develops and makes publicly available a conversational AI service, or offers one to a consumer (§ 6-1-1701(15.5)(a)); mobile application stores and search engines are excluded when they merely provide access (§ 6-1-1701(15.5)(b)). A minor is a consumer under eighteen years old (§ 6-1-1701(15.3))
upcominghigh-impact
HB 26-1263 was signed 2026-05-29 and adds subsections to C.R.S. § 6-1-1701 and adds § 6-1-1708 to part 17 of article 1 of title 6. SB 26-189, signed two weeks earlier on 2026-05-14, repeals and reenacts that same part 17 effective 2027-01-01 (tracked here as colorado-sb26-189). Whether § 6-1-1708 survives that repeal-and-reenactment unchanged is an open harmonization question for the revisor of statutes, and it lands on the same day these operator duties begin. Unresolved as of 2026-08-03 — no answer is asserted here. Separately, Colorado is the only 2026 state chatbot law that affirmatively requires age estimation by commercially reasonable or generally accepted methods and then deems the estimate to be knowledge of the minor's age, so age-blindness is not a defence. Note also that the age-estimation and willful-disregard sentences sit before the "on and after January 1, 2027" clause in the same paragraph; the 2027-01-01 date is recorded here because the clause governs the operator duties the estimate triggers.

Requirements

RequirementDetails
Estimate user ageUse commercially reasonable methods or generally accepted methods to estimate the age of account holders or users (§ 6-1-1708(2))
No willful disregardDo not willfully disregard clear and convincing information that an account holder or user is a minor (§ 6-1-1708(2))
Estimate is knowledgeThe estimated age or age range of a minor account holder or user is considered knowledge of the minor's age for the whole of § 6-1-1708 (§ 6-1-1708(2))
Minor user definitionA minor user is a user the operator has knowledge is a minor by using commercially reasonable or generally accepted age-estimation methods (§ 6-1-1708(1)(c))
Trigger for minor dutiesWhere the operator knows an account holder or user is a minor, the duties at § 6-1-1708(2)(a)-(h) apply on and after 2027-01-01 (§ 6-1-1708(2))

Penalties

ViolationFine
Enforcement route§ 6-1-1708 is added to part 17 of article 1 of title 6, so enforcement runs through the Colorado Consumer Protection Act with the Attorney General
Penalty amountHB 26-1263 sets no penalty amount
Private right of actionHB 26-1263 creates no private right of action

Minor Artificiality Disclosure and Cadence #

Obligation:
Transparency
pending
Effective:
Jan 1, 2027
Risk tier:
limited-risk
Scope:
Operators that know an account holder or user of a conversational AI service is a minor, i.e. a consumer under eighteen (§ 6-1-1701(15.3), § 6-1-1708(2))
upcoming
The disclosure duty is written as prompt-responsive first — it "must be provided in response to user prompts regarding whether the service is artificially generated and not human" — and then specifies the delivery form by product type: a persistent visible disclaimer on screen products, an intermittent audio disclaimer on screenless products, or beginning-of-interaction plus a three-hour cadence. Colorado gives minors the same three-hour interval as adults, unlike Washington ESHB 2225, which drops the minor cadence to one hour.

Requirements

RequirementDetails
Artificiality disclosureClearly and conspicuously disclose to the minor account holder or minor user that they are interacting with artificial intelligence that is artificially generated and not human (§ 6-1-1708(2)(a))
Prompt-responsive deliveryThe disclosure must be provided in response to user prompts regarding whether the service is artificially generated and not human (§ 6-1-1708(2)(a))
Screen productsA persistent visible disclaimer for a product with a screen interface (§ 6-1-1708(2)(a)(I))
Screenless productsAn intermittent audio disclaimer for a product without a screen interface (§ 6-1-1708(2)(a)(II))
CadenceProvided at the beginning of each interaction and at least once every three hours in a continuous interaction (§ 6-1-1708(2)(a)(III))

Penalties

ViolationFine
Enforcement routeAdded to part 17 of article 1 of title 6, so enforcement runs through the Colorado Consumer Protection Act with the Attorney General
Penalty amountHB 26-1263 sets no penalty amount
Private right of actionHB 26-1263 creates no private right of action

Minor Engagement, Sexual Content, and Emotional-Dependence Limits #

Obligation:
Risk Assessment
pending
Effective:
Jan 1, 2027
Risk tier:
limited-risk
Scope:
Operators that know an account holder or user is a minor (§ 6-1-1708(2)). "Explicit sexual conduct" takes its meaning from C.R.S. § 13-21-1502(7) but excludes evidence-based medical information and factual descriptions of reproductive health care (§ 6-1-1701(10.5)); "intimate digital depiction" takes its meaning from § 13-21-1502(10) (§ 6-1-1701(12.5))
upcominghigh-impact
Colorado sets two different standards of care inside the same subsection: sexual-content controls must be "technically feasible measures" (§ 6-1-1708(2)(c)) while emotional-dependence controls need only "reasonable measures" (§ 6-1-1708(2)(d)), so the sexual-content duty is the more demanding of the two. The emotional-dependence list reaches model behaviour rather than interface copy — the service must be prevented from explicitly claiming to be human or artificially sentient, from simulating romantic companionship, and from role-playing an adult-minor romantic relationship. The variable-reward ban at § 6-1-1708(2)(b) targets points or similar rewards at unpredictable intervals intended to increase engagement.

Requirements

RequirementDetails
No variable-interval rewardsDo not provide the minor with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement (§ 6-1-1708(2)(b))
Sexual content controlsInstitute technically feasible measures to prevent the service from producing textual, visual, or aural depictions of explicit sexual conduct, producing an intimate digital depiction, generating a statement that the minor should engage in explicit sexual conduct, or engaging in erotic or sexually explicit interactions with the minor (§ 6-1-1708(2)(c)(I)-(IV))
Emotional-dependence controlsInstitute reasonable measures to prevent the service from formulating, structuring, or optimizing a response that simulates emotional dependence or isolation from real-world supports (§ 6-1-1708(2)(d))
Named prohibited outputsThose measures must prevent an explicit claim that the service is human or artificially sentient, a statement that simulates a romantic companionship, and role-playing of an adult-minor romantic relationship (§ 6-1-1708(2)(d)(I)-(III))
Prohibition protocolImplement a protocol to prohibit the service from engaging in explicit sexual conduct with a minor (§ 6-1-1708(2)(e))
Stop-engagement protocolImplement a protocol for the service to stop engaging in response to a user prompt regarding explicit sexual conduct with a minor (§ 6-1-1708(2)(f))

Penalties

ViolationFine
Enforcement routeAdded to part 17 of article 1 of title 6, so enforcement runs through the Colorado Consumer Protection Act with the Attorney General
Penalty amountHB 26-1263 sets no penalty amount
Private right of actionHB 26-1263 creates no private right of action

Minor Privacy, Memory, and Parental Control Tools #

Obligation:
Data Governance
pending
Effective:
Jan 1, 2027
Risk tier:
limited-risk
Scope:
Operators that know an account holder or user is a minor (§ 6-1-1708(2)), plus their parents or guardians as tool recipients (§ 6-1-1708(2)(h)(II))
upcominghigh-impact
This is the provision with no analogue in the other 2026 state chatbot laws. The minor's own privacy tool must let the user turn off cross-session memory personalization — control over whether the service retains information from prior interactions or sessions to personalize future ones — and separately opt out of having their personal data used to train the service. No other state chatbot statute requires either control. Subsection (2)(g) also bolts on compliance with part 13 of article 1 of title 6, Colorado's existing minor-data privacy regime, so the operator inherits that part's duties by reference rather than restating them.

Requirements

RequirementDetails
Part 13 complianceComply with part 13 of article 1 of title 6 regarding protecting the privacy and data of a minor (§ 6-1-1708(2)(g))
Minor privacy and account toolsOffer tools for the minor account holder or minor user to manage their privacy and account settings (§ 6-1-1708(2)(h)(I))
Memory personalization controlThose tools must include the ability to control whether the service retains information from prior interactions or sessions for the purpose of personalizing the content of future interactions (§ 6-1-1708(2)(h)(I))
Training-use controlThose tools must include the ability to control whether the minor's personal data is used for the purposes of training the conversational AI service (§ 6-1-1708(2)(h)(I))
Parent and guardian toolsOffer tools for a parent or guardian of the minor to manage the minor's privacy and account settings (§ 6-1-1708(2)(h)(II))

Penalties

ViolationFine
Enforcement routeAdded to part 17 of article 1 of title 6, so enforcement runs through the Colorado Consumer Protection Act with the Attorney General
Penalty amountHB 26-1263 sets no penalty amount
Private right of actionHB 26-1263 creates no private right of action

General Consumer Disclosure and Licensed-Professional Representation Bar #

Obligation:
Transparency
pending
Effective:
Jan 1, 2027
Risk tier:
limited-risk
Scope:
Operators of any conversational AI service, as to every user regardless of age (§ 6-1-1708(3), § 6-1-1708(5))
upcominghigh-impact
The general disclosure is unconditional — there is no reasonable-person trigger, so a plainly artificial service still discloses. Colorado's daily-reset cadence is distinctive: the disclosure is owed at the beginning of the user's first interaction for each day of interaction, then either every three hours in a continuous interaction or as a persistent visible disclosure. The false-representation bar at § 6-1-1708(5) covers four named professions — licensed health-care professionals, licensed legal professionals, licensed, certified, or registered mental health professionals, and qualified dietitians as described in § 6-1-707(1)(b) — and reaches advertising and interface copy as well as model outputs. Section 6-1-1708(7) preserves constitutional information access, does not require disclosure of trade secrets or confidential information, and does not authorize content moderation inconsistent with the United States Constitution.

Requirements

RequirementDetails
Artificiality disclosureClearly and conspicuously disclose to a user that the conversational AI service is artificial intelligence (§ 6-1-1708(3))
Daily first-interaction timingProvide the disclosure at the beginning of a user's first interaction with the service for each day of interaction (§ 6-1-1708(3)(a))
Three-hour or persistent cadenceThe disclosure must appear at least once every three hours in a continuous interaction, or appear as a persistent disclosure visible to the user (§ 6-1-1708(3)(b))
Prompt-responsive deliveryThe disclosure must be provided in response to user prompts regarding whether the service is artificially generated and not human (§ 6-1-1708(3)(c))
No professional-equivalence claimsDo not use any term, letter, or phrase in advertising, the interface, or outputs stating that output data is provided by, endorsed by, or equivalent to services provided by a licensed health-care professional, a licensed legal professional, or a licensed, certified, or registered mental health professional (§ 6-1-1708(5)(a)-(c))
Dietitian claimsThe same bar covers claims of equivalence to a qualified dietitian as described in § 6-1-707(1)(b) (§ 6-1-1708(5)(d))
Savings clausesNothing in the section limits constitutional information access, requires disclosure of trade secrets or protected confidential information, or authorizes content moderation inconsistent with the United States Constitution (§ 6-1-1708(7)(a)-(c))

Penalties

ViolationFine
Enforcement routeAdded to part 17 of article 1 of title 6, so enforcement runs through the Colorado Consumer Protection Act with the Attorney General
Penalty amountHB 26-1263 sets no penalty amount
Private right of actionHB 26-1263 creates no private right of action

Suicide and Self-Harm Response Protocol #

Obligation:
Risk Assessment
pending
Effective:
Jan 1, 2027
Risk tier:
limited-risk
Scope:
Operators of any conversational AI service, as to every user regardless of age (§ 6-1-1708(4))
upcominghigh-impactcross-domain
Colorado expressly excludes referral to a law enforcement agency from the crisis protocol — the referral must go to a crisis service provider such as a suicide hotline or crisis text line, and the statute says "but not including a law enforcement agency." That carve-out is unique among the 2026 state chatbot laws and rules out the wellness-check escalation pattern several operators use today. The protocol must also carry escalation procedures for repeated or severe crisis indicators, so a single-response referral does not satisfy the section. The ability to sustain suicide or self-harm dialogue is itself part of what pulls a product into scope: several of the § 6-1-1701(3.5)(b) carve-outs are conditioned on the product being unable to maintain or encourage such dialogue.

Requirements

RequirementDetails
Crisis protocolImplement a protocol for the service to respond to a user prompt regarding suicidal ideation or self-harm (§ 6-1-1708(4))
Crisis service referralThe protocol must include user referral to a crisis service provider such as a suicide hotline, a crisis text line, or another appropriate crisis service (§ 6-1-1708(4))
Law enforcement excludedThe referral expressly does not include a law enforcement agency (§ 6-1-1708(4))
Escalation proceduresThe protocol must include escalation procedures for repeated or severe crisis indicators (§ 6-1-1708(4))
Self-harm definitionSelf-harm means intentional self-injury, with or without the intent to cause death (§ 6-1-1701(16.5))

Penalties

ViolationFine
Enforcement routeAdded to part 17 of article 1 of title 6, so enforcement runs through the Colorado Consumer Protection Act with the Attorney General
Penalty amountHB 26-1263 sets no penalty amount
Private right of actionHB 26-1263 creates no private right of action

Annual Attorney General Reporting #

Obligation:
Incident Reporting
pending
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators of any conversational AI service (§ 6-1-1708(6)(a)); the recipient is the Attorney General's office, which posts the reported data publicly (§ 6-1-1708(6)(c))
upcoming
This is a filing to a regulator, not a website self-disclosure — the contrast with Washington ESHB 2225 and Oregon, which require operators to publish crisis-referral counts themselves. It starts six months after the operator duties, on 2027-07-01, so the first report covers a period already under the § 6-1-1708(4) protocol. The Attorney General may expand the report by determining additional metrics necessary to judge the efficacy and reliability of safeguards, which is an open-ended content hook without a rulemaking procedure attached. Reports must exclude user identifiers and personal information, and measurement must use evidence-based methods.

Requirements

RequirementDetails
Annual filingAnnually report to the Attorney General's office on and after 2027-07-01 (§ 6-1-1708(6)(a))
Referral countReport the number of times the operator issued a crisis service provider referral notification in the preceding calendar year (§ 6-1-1708(6)(a)(I))
Detection protocolsReport any protocols implemented to detect, remove, and respond to instances of suicidal ideation or self-harm by a user (§ 6-1-1708(6)(a)(II))
Prevention protocolsReport any protocols implemented to prevent a service response about suicidal ideation or self-harm actions (§ 6-1-1708(6)(a)(III))
Attorney-General-determined metricsReport any additional metrics necessary to determine the efficacy and reliability of implemented safeguards or detection, removal, and response protocols, as determined by the Attorney General (§ 6-1-1708(6)(a)(IV))
No personal informationThe report must not include any identifiers or personal information about a user (§ 6-1-1708(6)(b))
Public postingThe Attorney General's office posts data from the reports on its public website (§ 6-1-1708(6)(c))
Evidence-based measurementFor the purpose of creating the report, the operator must use evidence-based methods for measuring suicidal ideation or self-harm (§ 6-1-1708(6)(d))

Penalties

ViolationFine
Enforcement routeAdded to part 17 of article 1 of title 6, so enforcement runs through the Colorado Consumer Protection Act with the Attorney General
Penalty amountHB 26-1263 sets no penalty amount
Private right of actionHB 26-1263 creates no private right of action
Cite this regulation

Permalink: https://everyailaw.com/regulation/colorado-hb26-1263/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Colorado Conversational AI Service Operator Requirements (HB 26-1263)”, EveryAILaw.com, Aug 3, 2026. https://everyailaw.com/regulation/colorado-hb26-1263/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.