Does Colorado Conversational AI Service Operator Requirements (HB 26-1263) require Incident Reporting?
Colorado • enacted
Yes — 1 provision
Requirements at a glance
This regulation imposes 8 specific requirements for Incident Reporting across 1 provision:
- Annual filing — Annually report to the Attorney General's office on and after 2027-07-01 (§ 6-1-1708(6)(a))
- Referral count — Report the number of times the operator issued a crisis service provider referral notification in the preceding calendar year (§ 6-1-1708(6)(a)(I))
- Detection protocols — Report any protocols implemented to detect, remove, and respond to instances of suicidal ideation or self-harm by a user (§ 6-1-1708(6)(a)(II))
- Prevention protocols — Report any protocols implemented to prevent a service response about suicidal ideation or self-harm actions (§ 6-1-1708(6)(a)(III))
- Attorney-General-determined metrics — Report any additional metrics necessary to determine the efficacy and reliability of implemented safeguards or detection, removal, and response protocols, as determined by the Attorney General (§ 6-1-1708(6)(a)(IV))
- No personal information — The report must not include any identifiers or personal information about a user (§ 6-1-1708(6)(b))
- Public posting — The Attorney General's office posts data from the reports on its public website (§ 6-1-1708(6)(c))
- Evidence-based measurement — For the purpose of creating the report, the operator must use evidence-based methods for measuring suicidal ideation or self-harm (§ 6-1-1708(6)(d))
Annual Attorney General Reporting
This is a filing to a regulator, not a website self-disclosure — the contrast with Washington ESHB 2225 and Oregon, which require operators to publish crisis-referral counts themselves. It starts on 2027-07-01. The statute calls for the preceding calendar year's referral count but does not state an exact first filing date, so the first reporting period and its relationship to the 2027-01-01 protocol commencement remain unresolved. The Attorney General may expand the report by determining additional metrics necessary to judge the efficacy and reliability of safeguards, which is an open-ended content hook without a rulemaking procedure attached. Reports must exclude user identifiers and personal information, and measurement must use evidence-based methods.
Requirements
| Requirement | Details |
|---|---|
| Annual filing | Annually report to the Attorney General's office on and after 2027-07-01 (§ 6-1-1708(6)(a)) |
| Referral count | Report the number of times the operator issued a crisis service provider referral notification in the preceding calendar year (§ 6-1-1708(6)(a)(I)) |
| Detection protocols | Report any protocols implemented to detect, remove, and respond to instances of suicidal ideation or self-harm by a user (§ 6-1-1708(6)(a)(II)) |
| Prevention protocols | Report any protocols implemented to prevent a service response about suicidal ideation or self-harm actions (§ 6-1-1708(6)(a)(III)) |
| Attorney-General-determined metrics | Report any additional metrics necessary to determine the efficacy and reliability of implemented safeguards or detection, removal, and response protocols, as determined by the Attorney General (§ 6-1-1708(6)(a)(IV)) |
| No personal information | The report must not include any identifiers or personal information about a user (§ 6-1-1708(6)(b)) |
| Public posting | The Attorney General's office posts data from the reports on its public website (§ 6-1-1708(6)(c)) |
| Evidence-based measurement | For the purpose of creating the report, the operator must use evidence-based methods for measuring suicidal ideation or self-harm (§ 6-1-1708(6)(d)) |
Penalties
| Violation | Fine |
|---|---|
| Enforcement route | Current § 6-1-1706 assigns Part 17 enforcement exclusively to the Attorney General; from 2027-01-01, § 6-1-1706(1)-(2) directs Attorney General enforcement through the Colorado Consumer Protection Act. Application of the future developer/deployer cure wording to an operator is unresolved. |
| Civil penalty | HB 26-1263 sets no separate dollar figure. The general CCPA ceiling under § 6-1-112(1)(a) is up to USD 20,000 per violation, separately per consumer or transaction, in an Attorney General civil action. Future § 6-1-1706(3) has a 60-day cure notice when the Attorney General deems cure possible for a developer or deployer, subject to its knowing/repeated-violation exception; application to a distinct operator remains unresolved. |
| Private right of action | Part 17 creates no new private right of action; future § 6-1-1706(4) preserves existing state and federal rights and remedies. |