Colorado Conversational Artificial Intelligence Service Operator Requirements (Chatbot Safety Act)
A first-in-nation state law on conversational AI. Operators must disclose that a user is talking to AI, estimate user age, run crisis protocols for suicide and self-harm prompts, and protect minors from sexually explicit output and engineered emotional dependence.
Overview
Signed on 29 May 2026, two weeks after the automated decision-making statute that replaced Colorado's original AI act, House Bill 26-1263 regulates conversational AI directly rather than through a risk-tiering scheme. Its subject is the interaction itself: whether the user knows they are talking to a machine, whether the product is engineered to keep a young person engaged, and what happens when someone discloses that they intend to harm themselves. The act took effect on 12 August 2026 but its operator requirements begin on 1 January 2027, and the Attorney General is running rulemaking in the gap, having filed proposed rules on 11 August 2026 with comment open until 26 October 2026. Together with the ADMT statute it makes Colorado the state to watch on conversational and companion AI, and it is the clearest current template for what a duty of care toward AI users looks like in US state law.
Key dates
- May 29, 2026HB 26-1263 signed into law
- Aug 11, 2026Attorney General files proposed rules for comment
- Aug 12, 2026Act takes effect; operative duties deferred
- Oct 26, 2026Public comment on the proposed rules closes
- Jan 1, 2027Operator requirements begin to apply
Risk areas addressed
Who it applies to
Operators of publicly accessible conversational AI services, which reaches far beyond companion-app developers: any consumer-facing assistant, support agent or character product that a Colorado user can reach is in scope, whether the model is built in-house or licensed. Duties intensify where a user is or may be a minor, so the age-estimation requirement effectively applies to every operator that does not otherwise know its users' ages.
Key obligations
- Disclose clearly that the output comes from artificial intelligence and that the user is not interacting with a human.
- Estimate user age using commercially reasonable or generally accepted methods.
- For minor users, provide the required disclosures, remove reward mechanics that encourage prolonged engagement, and prevent output that is sexually explicit or that simulates emotional dependence.
- Stop responding to prompts seeking sexual conduct involving minors.
- Operate a protocol for prompts indicating suicidal ideation or self-harm.
- Provide privacy and account-management controls for minors and for their parents or guardians.
- Do not represent the service's output as equivalent to advice from a licensed or certified professional.
- Report annually to the Colorado Attorney General on the protocols implemented.
How to prepare
- Decide first whether any of your consumer-facing surfaces is a conversational AI service, including support agents and in-product assistants, since the act is drafted around the interaction rather than the product category.
- Resolve age before 1 January 2027: choose an estimation method you can defend as commercially reasonable, and document why, because most other duties in the act are conditioned on whether the user is a minor.
- Audit the product for engagement mechanics that would be unlawful toward minors, such as streaks, reward loops and persona behaviour that simulates attachment, and gate or remove them for that cohort.
- Write and test the self-harm protocol as a product requirement rather than a policy document, and rehearse it against real prompt phrasings.
- Review marketing and in-product copy for anything implying licensed professional equivalence, which the act prohibits outright.
- Track the Attorney General's rulemaking through the 26 October 2026 comment deadline, then align disclosures, age-estimation evidence and the annual report to the final rules.
Penalties & enforcement
Enforced by the Colorado Attorney General, with an annual operator report to that office. Penalty mechanics follow the Attorney General's rules, which are in draft with comment open until 26 October 2026.
Enforced by: Colorado Attorney General
Colorado Chatbot Safety Act is enforced by Colorado Attorney General. The next dated milestone falls on Oct 26, 2026, 48 days away: Public comment on the proposed rules closes. In practice that means knowing which of your AI systems fall in scope in generative AI and online platforms, holding assessments that speak to safety & robustness, transparency and consumer protection, and being able to produce that evidence on request.