Does Colorado Conversational AI Service Operator Requirements (HB 26-1263) require Data Governance?

Colorado • enacted

Yes — 1 provision

Requirements at a glance

This regulation imposes 5 specific requirements for Data Governance across 1 provision:

Minor Privacy, Memory, and Parental Control Tools

Copy link to this provision

Obligation:
Data Governance
pending
Effective:
Jan 1, 2027
Risk tier:
limited-risk
Scope:
Operators that know an account holder or user is a minor (§ 6-1-1708(2)), plus their parents or guardians as tool recipients (§ 6-1-1708(2)(h)(II))
upcominghigh-impact
This provision requires specific minor privacy controls. The minor's own privacy tool must let the user turn off cross-session memory personalization — control over whether the service retains information from prior interactions or sessions to personalize future ones — and separately opt out of having their personal data used to train the service. The source review does not establish whether other states require similar controls. Subsection (2)(g) also bolts on compliance with part 13 of article 1 of title 6, Colorado's existing minor-data privacy regime, so the operator inherits that part's duties by reference rather than restating them.

Requirements

RequirementDetails
Part 13 complianceComply with part 13 of article 1 of title 6 regarding protecting the privacy and data of a minor (§ 6-1-1708(2)(g))
Minor privacy and account toolsOffer tools for the minor account holder or minor user to manage their privacy and account settings (§ 6-1-1708(2)(h)(I))
Memory personalization controlThose tools must include the ability to control whether the service retains information from prior interactions or sessions for the purpose of personalizing the content of future interactions (§ 6-1-1708(2)(h)(I))
Training-use controlThose tools must include the ability to control whether the minor's personal data is used for the purposes of training the conversational AI service (§ 6-1-1708(2)(h)(I))
Parent and guardian toolsOffer tools for a parent or guardian of the minor to manage the minor's privacy and account settings (§ 6-1-1708(2)(h)(II))

Penalties

ViolationFine
Enforcement routeCurrent § 6-1-1706 assigns Part 17 enforcement exclusively to the Attorney General; from 2027-01-01, § 6-1-1706(1)-(2) directs Attorney General enforcement through the Colorado Consumer Protection Act. Application of the future developer/deployer cure wording to an operator is unresolved.
Civil penaltyHB 26-1263 sets no separate dollar figure. The general CCPA ceiling under § 6-1-112(1)(a) is up to USD 20,000 per violation, separately per consumer or transaction, in an Attorney General civil action. Future § 6-1-1706(3) has a 60-day cure notice when the Attorney General deems cure possible for a developer or deployer, subject to its knowing/repeated-violation exception; application to a distinct operator remains unresolved.
Private right of actionPart 17 creates no new private right of action; future § 6-1-1706(4) preserves existing state and federal rights and remedies.
View full regulation View obligation Obligation matrix