Colorado defines the reviewer, then keeps records about the software

This is the legal reading. For what deployed agent software can actually produce against it, see Colorado: what your stack can show, which measures ten systems against the same rule and links Review and Check, both free and running in your browser.

From 1 January 2027, a deployer of automated decision-making technology in Colorado must give a consumer an opportunity for meaningful human review, and must keep records of compliance for three years. That date is eleven months before the EU AI Act's high-risk obligations apply. It is not the earliest right to human review, and this page said so until 12 September 2026. The United Kingdom has required a controller to enable a data subject to obtain human intervention in a significant automated decision since 5 February 2026, under Article 22C of the UK GDPR as substituted by section 80 of the Data (Use and Access) Act 2025, and requires no record of it whatsoever. What Colorado adds is the record. Though the United Kingdom's regulator has since asked for one anyway, which is the next section.

The United Kingdom is not the earliest either, and the honest version of this comparison has three entries rather than one. Article 22(3) of the General Data Protection Regulation has required a controller relying on contract or explicit consent to implement safeguards including “at least the right to obtain human intervention on the part of the controller” since 25 May 2018. Outside Europe, Quebec has required since 22 September 2023 that where a decision is based exclusively on automated processing of personal information, “the person concerned must be given the opportunity to submit observations to a member of the personnel of the enterprise who is in a position to review the decision”, under section 12.1 of the Act respecting the protection of personal information in the private sector as enacted by section 110 of Bill 64. Section 12.1 is one hundred and twenty nine words long and contains no occurrence of record, log, retain, retention, document or register. The act's one retention duty, added to section 11 by section 109 of the same bill, is that “the information used to make such a decision is kept for at least one year following the decision”, which keeps the inputs and says nothing about who was heard or whether anything changed.

So three jurisdictions reached the same shape independently, over five years, and not one of them asked for the record. That is what makes the Colorado rule worth reading closely rather than a local curiosity: it is the first of them to specify what a deployer has to be able to show. The consolidated Quebec act could not be read for this, because legisquebec.gouv.qc.ca returned a gateway error twice on 12 September 2026 and CanLII served no text, so every quotation above is from the enacting act as published by Publications Québec.

Senate Bill 26-189 was signed on 14 May 2026, repealing and replacing the Colorado AI Act. Much of the original went: the duty of care, the risk management programmes, the impact assessments. What survived is narrower and, for the question this site asks, considerably more interesting.

This reading is of the signed act. Every quotation below is from it and every section number is given, so a reader who thinks the reading is wrong can settle it without asking anybody.

The British regulator asks for the record the British statute does not

Articles 22A to 22D of the UK GDPR contain no occurrence of record, log, retain or retention. The Information Commissioner's Office, which enforces them, publishes guidance on what the safeguards require, and it says something the statute does not.

On what makes intervention real: “Like human involvement, human intervention cannot be tokenistic. Human reviewers should: assess and review any reconsideration of the decision before it is applied; have the ability to influence the outcome; have discretion and authority to alter the decision; be suitably trained and qualified to understand the system's outputs, limitations, and risks; and take into account the relevant data and factors that the decision was based on.”

“You should keep a record of how the human reviewed the decision.”

That sentence has no statutory basis in Articles 22A to 22D. It is a regulator's expectation rather than a legal duty, and it is live now rather than in 2027. Read beside the list above it describes substantially what Colorado's Rule 7.7 would require: a reviewer with authority to alter, trained and qualified, who took the relevant evidence into account, and a record of how they did it.

So two jurisdictions have arrived at the same specification from opposite directions. Colorado is writing it into a rule that takes effect on 1 January 2027. The United Kingdom has it in guidance today, resting on a statute that requires nothing of the kind.

The reviewer is defined more carefully than anywhere else

Section 6-1-1701(15) defines meaningful human review as review by an individual designated by the deployer who has authority to approve, modify, or override a consequential decision, and who:

  1. “CONSIDERS RELEVANT, AVAILABLE PRIMARY EVIDENCE”
  2. “IS TRAINED TO CONDUCT THE REVIEW”
  3. “DOES NOT DEFAULT TO THE SYSTEM OUTPUT”
  4. “HAS ACCESS TO SUFFICIENT INFORMATION TO UNDERSTAND” the output's intended use, material limitations and categories of inputs, and the principal factors used to generate it

That is six properties of one person: designated, authorised, evidence considering, trained, non-deferring and sufficiently informed. It is a more precise description of an approver than appears in the EU AI Act, in the ForHumanity certification criteria, in the CSA AI Controls Matrix or in the NIST AI Risk Management Framework. The third item is a statutory prohibition on rubber-stamping, which nothing else this project has read attempts at all.

The records are about the system

Section 6-1-1703, Deployer record keeping, is one sentence and a list:

“A DEPLOYER SHALL RETAIN, FOR NOT LESS THAN THREE YEARS AFTER THE DATE OF A CONSEQUENTIAL DECISION ... RECORDS REASONABLY NECESSARY TO DEMONSTRATE COMPLIANCE WITH THIS PART 17. RECORDS MAY INCLUDE, AS APPLICABLE, COVERED ADMT VERSION IDENTIFIERS, CHANGELOGS, AND DOCUMENTATION OF MATERIAL MITIGATION CHANGES.”

Version identifiers, changelogs and mitigation documentation. Every enumerated record is about the software. Not one of the six properties of the reviewer can be demonstrated from any of them.

A changelog cannot show that the reviewer was designated, or trained, or had authority to override. It cannot show that they considered the evidence, and it certainly cannot show that they did not default to the system output, which is the failure the definition was written to prevent.

What the act does not contain

The word reviewer does not appear in the act. Neither does natural person. The only occurrence of the phrase “name of” is “THE NAME OF THE COVERED ADMT”, which is the name of the system.

So a deployer can satisfy section 6-1-1703 completely, hand a regulator three years of version identifiers and changelogs, and be unable to establish that any particular decision received the review section 6-1-1701(15) defines.

Why this is a stronger finding than the European one

The reading of the EU AI Act found that the requirement to identify the person exists exactly once, in Article 12(3)(d), for remote biometric identification, and that Article 12(2) specifies no content at all for every other high-risk system. The drafters wrote the requirement and confined it.

Colorado does something different and, for this argument, worse. It defines the person in unusual detail and then enumerates the records that demonstrate compliance without reference to them. The care is spent on saying what the reviewer must be, and none of it on making that checkable afterwards.

The rules are written now, and they close the gap

Section 6-1-1705(3) required the Attorney General to adopt rules implementing these requirements. On 11 August 2026 the Department of Law filed them, 4 CCR 904-6, and they do the thing the act does not.

These are proposed, not law. A revised draft circulates on or about 23 September 2026, comments close on 26 October at 11:59pm MST and the hearing is that day, in person at 1300 Broadway Room 1D in Denver and by video conference. If adopted they take effect 1 January 2027 with the act. Everything below is a reading of the filing as it stands and will be re-read when it changes.

Rule 7.7 asks a record to show six things

Under Documentation:

“When a Meaningful Human Review is conducted, the Deployer must retain a record showing: The reviewer identity, authority, and relevant training; Review timestamps; Primary evidence available to the reviewer, including information provided by the Consumer; The reviewer's access to ADMTs intended use, limitations, inputs and principal factors; Whether the reviewer approved, modified, or overrode the output; and A written justification for the reviewer's decision to approve, modify, or override the output.”

That is the sentence the act was missing. The statute defines the reviewer in six properties and enumerates records about the software. This rule enumerates records about the review. As far as this project has been able to read, no other United States AI instrument requires a record that names who reviewed a decision about a person, so if Rule 7.7 stands, Colorado is the first.

Two more sentences in the same rule change what the record has to carry. An override that fully reverses a decision “indicates that human review was meaningful”, which keys an evidentiary conclusion to a distinction a record must be able to express. And “ADMT may not assist in the Meaningful Human Review”, which is a prohibition on how a review is conducted rather than on what is written down: nothing in a record establishes the absence of a tool.

Rule 7.7 is larger than its Documentation provision

The rule is headed Right to Meaningful Human Review and Reconsideration, and the six-item record above is one part of it. Reading only that part, and calling it Rule 7.7, understates what the rule does and what could be struck from it without the record changing at all.

Part of Rule 7.7What it governs
Requests for review and reconsiderationThe mechanism, and a consumer's ability to say why and contest specific information
Reconsideration of corrected dataRe-performing the decision on corrected personal data and sending the result
Reviewer StandardsWho the reviewer may be, what they must know, and what may not influence them
Types of meaningful human reviewWhat kind of review could change the outcome, and the full-reversal signal
Commercial ReasonablenessSeven factors deciding how far the right extends, and how the presumption is rebutted
DocumentationThe six things a retained record must show. The part read above

Reviewer Standards asks for things no record produces

The reviewer must be independent: one “who did not make the original decision and who is not a subordinate of the original decision-maker, whenever feasible”. They must have subject matter understanding “commensurate with the nature of, and negative consequences resulting from” the outcome, and training in accuracy and objectivity, in the factors the system considered, and in the subject matter itself.

And two conditions on the reviewer's freedom. The reviewer “must not be subject to steering by the upper management that would influence the reviewer's decision, and they must be shielded from potential retaliation”. Separately, “ADMT may not assist in the Meaningful Human Review”.

Independence, freedom from steering and a retaliation shield are properties of an employment relationship. They join designation, training and authority in the group this reading sets aside rather than reports as missing: no record format produces any of them and none should claim to. An earlier version of this page named three such properties. There are at least five.

Commercial Reasonableness is where feasibility already lives

This is the part that changes what the measurement on this page is for. The right to meaningful human review runs only “to the extent commercially reasonable”, and the rule sets out seven factors to be weighed together with none dispositive: the type of review required, the magnitude of harm, the reversibility of the outcome, the value of reviewing available primary evidence, the deployer's size and capacity, the marginal cost and technical feasibility of the review, and the availability of qualified reviewers.

Where the harm is a severe and irreversible denial of a basic human need, review is presumed commercially reasonable. That presumption is rebuttable, and the rule says how: by “evidence showing that the review is technically or financially impossible or could not change the Adverse Outcome”.

So the feasibility argument is not hypothetical and it is not something a commenter has to invent. It is drafted into the rule as a rebuttal, and a measurement that most deployed software cannot produce the record is exactly the evidence it invites.

That cuts both ways and the honest reading says so. The same measurement that shows the record is rarely producible today is available to a deployer arguing that review is technically impossible for them. What separates those two readings is whether the thing is impossible or merely absent, which is why AIUC-1 matters here rather than as a curiosity: a certification standard already requires the approver's identity, already audits it, and already has certificate holders. Technically impossible and not yet built are different claims, and only one of them rebuts the presumption.

Material influence is a rebuttable presumption, and the rebuttals are records

The Notice of Proposed Rulemaking does not only propose text. It asks the public to choose between two standards for when an output “Materially Influences” a decision. Both make it a presumption the deployer may rebut, and the Notice's own examples of rebutting evidence are claims about what a record can show:

“The decision maker recorded an independent judgment before the ADMT output was made available to the decision-maker; The decision maker did not view the ADMT output; The decision maker made a decision that was not consistent with the ADMT output”.

And among the factors for whether an output was merely de minimis: “Whether the Consequential Decision maker saw the primary evidence, or only the ADMT output in coming to the Consequential Decision.”

An identifier of the material establishes what was eligible to be shown. It does not establish attention. Two interfaces can cite the same underlying item while one displays a one-line score and the other displays the full supporting evidence, and produce identical records. A deployer asked to show which of those happened needs a record that binds what was displayed to the decision that followed, and not one that merely retains related inputs.

What a record can and cannot answer here

Of the fifteen obligations this project reads out of the filing, seven are not answerable from records at all, and saying so matters more than the eight that are. The reviewer's authority and training are attributes of a person held in an employer's HR and identity systems. Their access to the system's intended use and limitations is a fact about what a console showed somebody. The absence of ADMT assistance is an absence. No record format produces any of those and none should claim to.

The ordering rebuttal is the hardest of the eight and it is not solved here either. A judgment “recorded before” the output was available needs two records ordered against each other on a clock the deployer does not solely control, and every timestamp in every system this project has read is written by the party whose conduct is in question.

The objection this reading invites, and the answer to it

A measurement that most deployed software cannot produce the Rule 7.7 record can be read two ways. The reading here is that Colorado would be first and should draft accordingly. The other reading is that the provision asks for something the market cannot do and should be softened, and that is the argument a rulemaking usually hears.

It is worth knowing that the substance of what Rule 7.7 asks for is already required somewhere, audited, and certified against, with no law involved.

AIUC-1 is a private certification standard for AI agents, published openly, with 51 live controls. Control E015 is mandatory and applied every 12 months, and its agent-specific evidence requirement E015.2 asks for structured logs capturing “approver identity, timestamp, decision outcome” for authorization events, the standard's own worked example being human-in-the-loop approvals. E015.4 separately asks for write-once storage, cryptographic hashing of log entries and append-only settings. Certification follows a third-party audit, and certificates are held by KPMG, Cursor, Harvey and ElevenLabs.

So the gap this page reports is not between what Rule 7.7 asks and what is possible. It is between Rule 7.7 and general-purpose software bought before anybody asked for the field. That is a transition, and transitions have lead times; it is a different thing from a requirement nobody can meet.

Two limits, because this cuts both ways. AIUC-1 is not law and binds nobody who does not seek the certificate. And no certified product has been assessed here and none is named: whether any of them built that field by hand is not something this project has measured. The full clause-level reading, including what it does not establish, is at machinetestimony.org/aiuc-1/.

The other act in the same rulemaking

The filing at 4 CCR 904-6 implements two statutes, not one. Rules 9 to 14 implement House Bill 26-1263, the Chatbot Safety Act, which governs operators of Conversational Artificial Intelligence Services and the protection of minors: age estimation, a persistent disclosure that the user is talking to a machine rather than a person, handling of suicidal ideation and self-harm risk, compulsive-use design, and an annual report to the Attorney General. The same hearing on 26 October takes testimony on both.

Read against the same question as the rest of this page, those rules ask an operator to keep nothing. Across Rules 9 to 14 there are zero occurrences of log, logs or logging as words, zero of audit trail, and zero of audit. The seven apparent matches are all inside other words: login, technologies, psychologist, methodology. The three occurrences of retain are about the minor's own data, requiring that privacy settings let a minor stop the service retaining prior sessions and default to not retaining them.

Human review appears twice and both are descriptions of a method rather than records of an event. Rule 13 asks an operator to state, in its annual report, “Whether and at what point a situation is elevated to human review” and the criteria that decide it.

Rule 13.3 then reserves a power to check. The Department “may request that an Operator produce underlying documentation, source materials, records, or a demonstration sufficient to verify any element of the submission”, within 30 days. That is the only occurrence of record in the chatbot rules, and it is a demand power rather than a duty to keep anything.

So an operator states annually when a conversation with a minor is escalated to a person, and may be asked within 30 days to prove any element of that. Nothing in the rules requires it to have kept anything that would constitute proof, and Rule 11.5 pushes the other way by defaulting a minor's data to not being retained at all.

This is not an argument that the Chatbot Safety Act should require logs. A safety statute about minors has reasons to keep operators away from retaining conversations, and an outsider should be slow to second-guess them. The finding is a tension between two rules in the same filing, stated because both are defensible and nothing in the text says which gives way.

What this project has filed here

Three written comments are in the rulemaking record, and all written comments are published by the Department at comments.coag.gov. The first, 0000000606, filed 9 September 2026, reports item by item whether deployed software can produce what Rule 7.7 asks. The second corrects two statements in it that were stronger than the evidence behind them, found by re-reading rather than because anyone challenged them. The third, filed 12 September, is the AIUC-1 reading above.

None of the three proposes a format, record contents or a remedy, and they say so. Rule 7.7 already specifies the record, and a submission from an interested party offering to improve that is worth less than one that does not.

What this reading is not

It is not legal advice and it is not a compliance product. It is one reading of one act by one person, published so that it can be checked and, where wrong, corrected. If a provision has been missed, the correction is an email or an issue naming the section, and it changes this page and the date on it.

The signed act is published by the Colorado General Assembly at leg.colorado.gov/bills/sb26-189. The quotations above are from the signed version and retain its capitalisation, which is how Colorado prints newly enacted text. The rules are quoted as filed, in ordinary case, because a proposed rule is not enacted text and printing it as though it were would make a draft look settled.

The proposed rules, the Notice of Proposed Rulemaking and the comment form are published by the Department of Law at coag.gov/ai/. The extracted text of both documents is committed beside this reading, so a reader who thinks a quotation is wrong can settle it against the same bytes this page was written from.

Citing this

The readings are CC BY 4.0, which asks for attribution, so the reference is here rather than left to be composed. This block is generated from the page it sits on, so a date that moves here moves in the citation too.

Clifford, T. (2026). Colorado defines the reviewer and keeps records about the software. Machine Testimony. https://machinetestimony.org/colorado/
@misc{clifford2026colorado,
  author = {Clifford, Troy},
  title  = {Colorado defines the reviewer and keeps records about the software},
  year   = {2026},
  note   = {Machine Testimony, read 9 September 2026},
  url    = {https://machinetestimony.org/colorado/},
}

This page carries no DOI. It cites its dated URL, and saying so is the point: a citation naming a deposit that does not exist is worse than one naming a page that does.