High-Risk AI Impact Assessment
Deployers would have been required to complete an impact assessment for each covered high-risk artificial intelligence system, repeat it at least annually and after intentional and substantial modifications, and retain the assessment records. The obligation was enacted in Colorado SB 24-205 but never became operative because the statute was superseded before its delayed effective date.
What Counts
- Initial assessment of purpose, use context, benefits, inputs, outputs, performance, limitations, and discrimination risks
- Annual reassessment while the high-risk system remains deployed
- Reassessment within ninety days after an intentional and substantial modification
- Documentation of transparency measures, safeguards, monitoring, and risk mitigation
- Retention of current and prior assessments for the statutory period
What Does Not Count
- Treating the enacted assessment mandate as currently operative after SB 24-205 was superseded
- A one-time assessment with no annual or modification-triggered review
- An assessment that omits reasonably foreseeable algorithmic-discrimination risks
- Generic system documentation that does not evaluate the deployer's actual deployment context
Implementing Legal Instruments
| Legal Instrument | Scope | Status | Provisions |
|---|---|---|---|
| Colorado SB 24-205 (2024) — Consumer Protections for Interactions with Artificial Intelligence Systems | us-co | superseded | 1 |